Posté le 11 juillet 2012
Télécharger | Reposter | Largeur fixe

Rapport de ZHPDiag v1.31.105 par Nicolas Coolman, Update du 25/06/2012
Run by cyrille at 10/07/2012 19:46:58
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Web site : http://nicolascoolman.skyrock.com/
State : Version à jour.


---\\ Web Browser
MSIE: Internet Explorer v8.0.6001.18702
MFIE: Mozilla Firefox 13.0.1 v13.0.1 (Defaut)
GCIE: Google Chrome v20.0.1132.47

---\\ Windows Product Information
~ Langage: Français
Windows XP Professional Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
Windows Genuine Advantage : OK

---\\ System Information
~ Processor: x86 Family 15 Model 127 Stepping 1, AuthenticAMD
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 895 MB (12% free)
System Restore: Activé (Enable)
System drive C: has 1 GB (2%) free of 50 GB

---\\ Logged in mode
~ Computer Name: CYRILLE-87B4804
~ User Name: cyrille
~ All Users Names: SUPPORT_388945a0, HelpAssistant, cyrille, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Documents and Settings\cyrille\Application Data\
~ %Desktop% : C:\Documents and Settings\cyrille\Bureau\
~ %Favorites% : C:\Documents and Settings\cyrille\Favoris\
~ %LocalAppData% : C:\Documents and Settings\cyrille\Local Settings\Application Data\
~ %StartMenu% : C:\Documents and Settings\cyrille\Menu Démarrer\
~ %Windir% : C:\WINDOWS\
~ %System% : C:\WINDOWS\system32\

---\\ DOS/Devices
A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
C:\ Hard drive, Flash drive, Thumb drive (Free 1 Go of 50 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 6 Go of 50 Go)
E:\ CD-ROM drive (Not Inserted)



---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Scan Security Center in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\Explorer.exe [1037824]
[MD5.1A5B88015B3823D31C5842DE0DBFE842] - (.Microsoft Corporation - Internet Extensions for Win32.) (.16/05/2012 - 16:06:36.) -- C:\WINDOWS\system32\wininet.dll [916992]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/08/2011 - 14:49:54.) -- C:\WINDOWS\system32\Drivers\AFD.sys [138496]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512]
[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Cdfs.sys [63744]
[MD5.4B0A100EAF5C49EF3CCA8C641431EACC] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.02/05/2008 - 11:49:39.) -- C:\WINDOWS\system32\Drivers\Cdrom.sys [62976]
[MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Fips.sys [44672]
[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\HDAudBus.sys [144384]
[MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - (.Microsoft Corporation - Pilote de port i8042.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\i8042prt.sys [54144]
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Imapi.sys [42112]
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\IpNat.sys [152832]
[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\IPSec.sys [75264]
[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/07/2011 - 14:29:31.) -- C:\WINDOWS\system32\Drivers\MRxSmb.sys [456320]
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\netBT.sys [162816]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976]
[MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Parport.sys [80384]
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Rasl2tp.sys [51328]
[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/04/2008 - 10:32:52.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224]
[MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) (.13/04/2008 - 19:57:36.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58752]
[MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53376]
~ Scan Generic Processes in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/4
~ Mes musiques (My Musics) : 1/752
~ Mes Videos (My Videos) : 2/31
~ Mes Favoris (My Favorites) : 1/19
~ Mes Documents (My Documents) : 3/1335
~ Mon Bureau (My Desktop) : 6/858
~ Menu demarrer (Programs) : 1/38
~ Scan Hidden Files in 00mn 29s



---\\ Processus lancés
[MD5.400D95445C593D4C089013729D0DA0B3] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 267.2.) -- C:\WINDOWS\system32\nvsvc32.exe [156776] [PID.]
[MD5.465A17095EB3B9E101429B669F495D01] - (.AVAST Software - avast! firewall service.) -- C:\Program Files\AVAST Software\Avast\afwServ.exe [133912] [PID.]
[MD5.2F7C0F3E39C45E0127FB78B2F18A41F3] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808] [PID.]
[MD5.F401929EE0CC92BFE7F15161CA535383] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184] [PID.]
[MD5.C2C1660DDCC9BD67EB98D6D5F91C107F] - (.Oracle Corporation - Java(TM) Quick Starter Service.) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [161664] [PID.]
[MD5.BA400ED640BCA1EAE5C727AE17C10207] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [654408] [PID.]
[MD5.34086F1DBB4065047EA3671CB70505CC] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [421776] [PID.]
[MD5.20C4535969F2006F6082CDF146CD95C4] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe [4273976] [PID.]
[MD5.0EC18F61E86F87C0ADE782920B403D9A] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\program files\real\realplayer\update\realsched.exe [296056] [PID.]
[MD5.7AEA4DF1CA68FD45DD4BBE1F0243CE7F] - (...) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096] [PID.]
[MD5.1B82BCF0B8F9228B39F75B0DFA079A21] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [462408] [PID.]
[MD5.6E95474CB9E22BC9768EFA176C6A0A29] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208] [PID.]
[MD5.995BEB69AE5C50D354894354F5A6CD5A] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [252296] [PID.]
[MD5.BF147446809517043C56426CB0DCEFEE] - (.Hewlett-Packard Co. - ScanToPCActivationApp.) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe [1804648] [PID.]
[MD5.CB4A9ABA55F2AA98265BA3D8AE029A6B] - (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe [880496] [PID.]
[MD5.4C4CF9220E628D1378F9807EC5175488] - (.Microsoft Corporation - ActiveSync Connection Manager.) -- D:\Wcescomm.exe [1289000] [PID.]
[MD5.3E24FD32D5E2B20177CEF2D985D2AA19] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHJE.exe [208384] [PID.]
[MD5.DCFC84480C76D862D9BFD386EA6E8DE7] - (.Microsoft Corporation - ActiveSync RAPI Manager.) -- D:\rapimgr.exe [199464] [PID.]
[MD5.E6BE7A41A28D8F2DB174957454D32448] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [821648] [PID.]
[MD5.2E0B0A051FFAA86E358465BB0880D453] - (.Microsoft Corporation - Windows Update.) -- C:\WINDOWS\system32\wuauclt.exe [53784] [PID.]
[MD5.D3C0837346C49095B8AF9EF54AD7E90A] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [913888] [PID.]
[MD5.41623176FEF9DF3C113EAADADBB5FB42] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [16864] [PID.]
[MD5.BE955BAB4EFC2A28BE2692D102FFC85A] - (...) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [3838464] [PID.]
[MD5.76435797185A73349D8F10B15A5AC81D] - (.Hewlett-Packard Co. - HPNetworkCommunicator.) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPNetworkCommunicator.exe [643944] [PID.]
[MD5.5E9A6658A2A69AE7EB195113B7A2E7A9] - (.Microsoft Corporation - Application Layer Gateway Service.) -- C:\WINDOWS\System32\alg.exe [44544] [PID.]
~ Scan Processes Running in 00mn 05s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Documents and Settings\cyrille\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
~ Scan Google Browser in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Documents and Settings\cyrille\Application Data\Mozilla\Firefox\Profiles\ixj76y8o.default\prefs.js
C:\Documents and Settings\cyrille\Application Data\Mozilla\Firefox\Profiles\ixj76y8o.default\user.js
M3 - MFPP: Plugins - [cyrille] -- C:\Documents and Settings\cyrille\Application Data\Mozilla\Firefox\Profiles\ixj76y8o.default\searchplugins\Search_Results.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
M3 - MFPP: Plugins - [cyrille] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
M0 - MFSP: prefs.js [cyrille - ixj76y8o.default] http://www.searchnu.com
M2 - MFEP: prefs.js [cyrille - ixj76y8o.default\plugin@yontoo.com] [] Yontoo v1.20.00 (.Yontoo LLC.)
M2 - MFEP: prefs.js [cyrille - ixj76y8o.default\specialsavings@superfish.com] [] SpecialSavings v1.2.0.13 (.SpecialSavings.)
M2 - MFEP: prefs.js [cyrille - ixj76y8o.default\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}] [] Garmin Communicator v4.0.1.0 (.Garmin International.)
M2 - MFEP: prefs.js [cyrille - ixj76y8o.default\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}] [] WinZipBar Community Toolbar v3.13.0.6 (.Conduit Ltd..)
M2 - MFEP: prefs.js [cyrille - ixj76y8o.default\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] [] DVDVideoSoftTB Community Toolbar v3.14.1.0 (.Conduit Ltd..)
M2 - MFEP: prefs.js [cyrille - ixj76y8o.default\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] [] Free YouTube Download (Free Studio) Menu v3.14.1.0 (.DVDVideoSoft Ltd..)
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.3.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Mozilla Firefox\Plugins\nppl3260.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Mozilla Firefox\Plugins\nprjplug.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - 15.0.2.72.) -- C:\Program Files\Mozilla Firefox\Plugins\nprpjplug.dll
P2 - FPN:Firefox Plugin Navigator . (.vShare.tv - vShare.tv plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npvsharetvplg.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@garmin.com/GpsControl] - (.GARMIN Corp. - Garmin Communicator Plug-In 4.0.1.0.) -- C:\Program Files\Garmin GPS Plugin\npGarmin.dll
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.5.1] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\WINDOWS\system32\npDeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.5.1] - (.Oracle Corporation - Next Generation Java Plug-in 10.5.1 for Mozilla browsers.) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@ma-config.com/HardwareDetection] - (.Cybelsoft - Plugin NPAPI Ma-Config.com.) -- C:\Program Files\ma-config.com\nphardwaredetection.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.1.10329.0.) -- C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@real.com/nppl3260;version=15.0.2.72] - (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- c:\program files\real\realplayer\Netscape6\nppl3260.dll
P2 - FPN: [HKLM] [@real.com/nprjplug;version=15.0.2.72] - (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- c:\program files\real\realplayer\Netscape6\nprjplug.dll
P2 - FPN: [HKLM] [@real.com/nprpchromebrowserrecordext;version=15.0.2.72] - (.RealNetworks, Inc. - RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlug
P2 - FPN: [HKLM] [@real.com/nprphtml5videoshim;version=15.0.2.72] - (.RealNetworks, Inc. - RealPlayer(tm) HTML5VideoShim Plug-In.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videosh
P2 - FPN: [HKLM] [@real.com/nprpjplug;version=15.0.2.72] - (.RealNetworks, Inc. - 15.0.2.72.) -- c:\program files\real\realplayer\Netscape6\nprpjplug.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.1] - (.VideoLAN - VLC media player Web Plugin 2.0.0.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.3.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
~ Scan Firefox Browser in 00mn 08s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchnu.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} . (.Conduit Ltd. - Conduit Toolbar.) (6.4.0.0) -- C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll
R3 - URLSearchHook: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} . (.Conduit Ltd. - Conduit Toolbar.) (6.4.0.0) -- C:\Program Files\uTorrentBar_FR\prxtbuTor.dll
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.19258 (longhorn_ie8_gdr.120423-1946)) -- C:\WINDOWS\system32\ieframe.dll
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: USERINIT=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s



---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 20



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\uTorrentBar_FR\prxtbuTor.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (.RealPlayer - RealPlayer Download and Record Plugin.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordP
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: DVDVideoSoftTB - {872b5b88-9db5-4310-bdd0-ac189557e5f5} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - avast! WebRep Plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} . (...) -- C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll (.not file.)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} . (.Yontoo LLC - Yontoo Runtime.) -- C:\Program Files\Yontoo\YontooIEClient.dll
~ Scan BHO in 00mn 01s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: avast! WebRep - [HKLM]{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - avast! WebRep Plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Searchqu Toolbar - [HKLM]{99079a25-328f-4bd4-be04-00955acaa0a7} . (...) -- C:\Program Files\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll
O3 - Toolbar: uTorrentBar_FR Toolbar - [HKLM]{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\uTorrentBar_FR\prxtbuTor.dll
~ Scan Toolbar in 00mn 00s



---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe
O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\program files\real\realplayer\update\realsched.exe
O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\WINDOWS\system32\NvCpl.dll
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
O4 - HKLM\..\RunOnce: [removeSearchqudatamngr] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\WINDOWS\system32\cmd.exe
O4 - HKLM\..\RunOnce: [removeSearchqutoolbar] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\WINDOWS\system32\cmd.exe
O4 - HKCU\..\Run: [HP Deskjet 3070 B611 series (NET)] . (.Hewlett-Packard Co. - ScanToPCActivationApp.) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe
O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] . (.Microsoft Corporation - ActiveSync Connection Manager.) -- D:\Wcescomm.exe
O4 - HKCU\..\Run: [EPSON SX130 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHJE.exe
O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-21-854245398-1326574676-1801674531-1003\..\Run: [HP Deskjet 3070 B611 series (NET)] . (.Hewlett-Packard Co. - ScanToPCActivationApp.) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe
O4 - HKUS\S-1-5-21-854245398-1326574676-1801674531-1003\..\Run: [uTorrent] . (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe
O4 - HKUS\S-1-5-21-854245398-1326574676-1801674531-1003\..\Run: [H/PC Connection Agent] . (.Microsoft Corporation - ActiveSync Connection Manager.) -- D:\Wcescomm.exe
O4 - HKUS\S-1-5-21-854245398-1326574676-1801674531-1003\..\Run: [EPSON SX130 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHJE.exe
O4 - HKUS\S-1-5-21-854245398-1326574676-1801674531-1003\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
~ Scan Application in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Reader X.lnk . (...) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AA1000000001}\SC_Reader.ico
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Apple Software Update.lnk . (...) -- C:\WINDOWS\Installer\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}\AppleSoftwareUpdateIco.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Audacity.lnk . (.The Audacity Team.) -- C:\Program Files\Audacity\audacity.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\CDBurnerXP.lnk . (.Canneverbe Limited.) -- C:\Program Files\CDBurnerXP\cdbxpp.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Microsoft ActiveSync.lnk . (...) -- C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\MSN.lnk . (.Microsoft Corporation.) -- C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Live ID.lnk . (.Microsoft Corporation.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\SIGNINOPTIONS.EXE
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Messenger.lnk . (.Microsoft Corporation.) -- C:\Program Files\Messenger\msmsgs.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Movie Maker.lnk . (.Microsoft Corporation.) -- C:\Program Files\Movie Maker\moviemk.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Application Data\Microsoft\Internet Explorer\Quick Launch\Free FLV Converter.lnk . (.Koyote Soft.) -- C:\Program Files\Free FLV Converter\FreeFLVConverter.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Assistance à distance.lnk . (.Microsoft Corporation.) -- C:\WINDOWS\system32\rcimlby.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Lecteur Windows Media.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Outlook Express.lnk . (.Microsoft Corporation.) -- C:\Program Files\Outlook Express\msimn.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Reader X.lnk . (...) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AA1000000001}\SC_Reader.ico
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Apple Software Update.lnk . (...) -- C:\WINDOWS\Installer\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}\AppleSoftwareUpdateIco.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Audacity.lnk . (.The Audacity Team.) -- C:\Program Files\Audacity\audacity.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\CDBurnerXP.lnk . (.Canneverbe Limited.) -- C:\Program Files\CDBurnerXP\cdbxpp.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Microsoft ActiveSync.lnk . (...) -- C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\MSN.lnk . (.Microsoft Corporation.) -- C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Live ID.lnk . (.Microsoft Corporation.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\SIGNINOPTIONS.EXE
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Messenger.lnk . (.Microsoft Corporation.) -- C:\Program Files\Messenger\msmsgs.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Movie Maker.lnk . (.Microsoft Corporation.) -- C:\Program Files\Movie Maker\moviemk.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Application Data\Microsoft\Internet Explorer\Quick Launch\Free FLV Converter.lnk . (.Koyote Soft.) -- C:\Program Files\Free FLV Converter\FreeFLVConverter.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Assistance à distance.lnk . (.Microsoft Corporation.) -- C:\WINDOWS\system32\rcimlby.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Lecteur Windows Media.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Documents And Settings\cyrille\Menu Démarrer\Programmes\Outlook Express.lnk . (.Microsoft Corporation.) -- C:\Program Files\Outlook Express\msimn.exe
~ Scan Global Startup in 00mn 06s



---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\Program Files\MICROS~2\Office12\EXCEL.exe
O8 - Extra context menu item: Free YouTube to MP3 Converter . (...) -- C:\Documents and Settings\cyrille\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
~ Scan IE Menu Contextuel in 00mn 01s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} . (.Microsoft Corporation - ActiveSync Favorite Synchronization.) -- D:\INetRepl.dll
O9 - Extra button: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} . (.Microsoft Corporation - ActiveSync Favorite Synchronization.) -- D:\INetRepl.dll
O9 - Extra button: Créer un Favori de l'appareil mobile... - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
~ Scan IE Extra Buttons in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
~ Scan Winsock in 00mn 00s



---\\ Onglet supplémentaire dans les options avancées d'Internet Explorer (O11)
O11 - Options group: [java_sun] Java (Oracle). (.Oracle Corporation - Java(TM) Deployment Library .) - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\deploy.dll
O11 - Options group: [java_vm] Java (Oracle). (.Oracle Corporation - Java(TM) Deployment Library .) - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\deploy.dll
~ Scan IE Plugins in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://www.darty.com/dartybox/scanner/wwwroot/ols/fscax.cab
~ Scan Objets ActiveX in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{B53EAB09-04F0-473F-A421-9DE52E6EBFE7}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{B53EAB09-04F0-473F-A421-9DE52E6EBFE7}: DhcpDomain = dartybox.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{B53EAB09-04F0-473F-A421-9DE52E6EBFE7}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{B53EAB09-04F0-473F-A421-9DE52E6EBFE7}: DhcpDomain = dartybox.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{B53EAB09-04F0-473F-A421-9DE52E6EBFE7}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{B53EAB09-04F0-473F-A421-9DE52E6EBFE7}: DhcpDomain = dartybox.com
~ Scan Domain in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype for COM API.) -- C:\Program Files\Fichiers communs\Skype\Skype4COM.dll
O18 - Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.dll
~ Scan Protocole Additionnel in 00mn 02s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\WINDOWS\system32\WgaLogon.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
~ Scan Winlogon in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (...) - C:\WINDOWS\system32\protector.dll
~ Scan AppInit DLL in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
~ Scan SSODL in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall (avast! Firewall) . (.AVAST Software - avast! firewall service.) - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Oracle Corporation - Java(TM) Quick Starter Service.) - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccess (NMSAccess) . (...) - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 267.2.) - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
~ Scan Services in 00mn 01s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\Office12\WINWORD.exe
O24 - Desktop General: BackupWallPaper - .(...) - C:\Documents and Settings\cyrille\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop General: WallPaper - .(...) - C:\Documents and Settings\cyrille\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
~ Scan Desktop Component in 00mn 00s



---\\ BootExecute (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ Scan Keys in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At1.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At2.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At3.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At4.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At5.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At6.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At7.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At8.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\avast! Emergency Update.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-854245398-1326574676-1801674531-1003.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-854245398-1326574676-1801674531-1003.job
[MD5.00000000000000000000000000000000] [APT] [Ad-Aware Update (Weekly)] (...) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe (.not file.)
[MD5.990DC6EDC9F933194D7CD4E65146BC94] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
[MD5.EFB437D5DEB333C698E85D4912B7872D] [APT] [At1] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe
[MD5.EFB437D5DEB333C698E85D4912B7872D] [APT] [At2] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe
[MD5.EFB437D5DEB333C698E85D4912B7872D] [APT] [At3] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe
[MD5.EFB437D5DEB333C698E85D4912B7872D] [APT] [At4] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe
[MD5.A39A9122BD4456B1B8AA1BF90D02031E] [APT] [At5] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPCustPartic.exe
[MD5.A39A9122BD4456B1B8AA1BF90D02031E] [APT] [At6] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPCustPartic.exe
[MD5.A39A9122BD4456B1B8AA1BF90D02031E] [APT] [At7] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPCustPartic.exe
[MD5.A39A9122BD4456B1B8AA1BF90D02031E] [APT] [At8] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPCustPartic.exe
[MD5.5A7E85100ACB28FBA8A81181A06C52D7] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.8535493AB374BE5B1B3A34671F42CCB3] [APT] [RealUpgradeLogonTaskS-1-5-21-854245398-1326574676-1801674531-1003] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\realupgrade.exe
[MD5.8535493AB374BE5B1B3A34671F42CCB3] [APT] [RealUpgradeScheduledTaskS-1-5-21-854245398-1326574676-1801674531-1003] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\realupgrade.exe
~ Scan Scheduled Task in 00mn 05s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Internet Explorer Version Update - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} . (.Microsoft Corporation - IE Per User Active Setup Uninstall Utility.) -- C:\WINDOWS\system32\ieudinit.exe
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitaire d'installation du Lecteur Windows Media Microsoft.) -- C:\WINDOWS\inf\unregmp2.exe
O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\system32\ie4uinit.exe.mui
O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - IEAK branding.) -- C:\WINDOWS\system32\iedkcs32.dll
O40 - ASIC: Outlook Express - >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} . (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe
O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\regutils.dll
O40 - ASIC: Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} . (.Microsoft Corporation - Windows Media 6.4 Player Shim.) -- C:\WINDOWS\system32\wmpdxm.dll
O40 - ASIC: Lecteur Windows Media Microsoft 6.4 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media 6.4 Player Shim.) -- C:\WINDOWS\system32\wmpdxm.dll
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\WINDOWS\system32\themeui.dll
O40 - ASIC: Microsoft Outlook Express 6 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Bibliothèque d'installation Outlook Express.) -- C:\Program Files\Outlook Express\setup50.exe
O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (...) -- C:\WINDOWS\INF\msnetmtg.inf
O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (...) -- C:\WINDOWS\INF\msmsgs.inf
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\WINDOWS\system32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (...) -- C:\WINDOWS\INF\wmp.inf
O40 - ASIC: Carnet d'adresses 6 - {7790769C-0471-11d2-AF11-00C04FA35D02} . (.Microsoft Corporation - Bibliothèque d'installation Outlook Express.) -- C:\Program Files\Outlook Express\setup50.exe
O40 - ASIC: Mise à jour du Bureau Windows - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\system32\ie4uinit.exe.mui
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\WINDOWS\system32\mscories.dll
~ Scan Active Setup in 00mn 01s



---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys
O41 - Driver: (Processor) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\WINDOWS\system32\DRIVERS\processr.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\WINDOWS\system32\DRIVERS\redbook.sys
O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\WINDOWS\system32\DRIVERS\serial.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
O41 - Driver: (WmiAcpi) . (.Microsoft Corporation - Windows Management Interface for ACPI.) - C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
~ Scan Drivers in 00mn 01s



---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Reader X (10.1.3) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {122ADF8C-DDA1-480C-9936-C88F2825B265}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {C6579A65-9CAE-4B31-8B6B-3306E0630A66}
O42 - Logiciel: Audacity 2.0 - (.Audacity Team.) [HKLM] -- Audacity_is1
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1
O42 - Logiciel: Coojah6 - (.Pas de propriétaire.) [HKLM] -- {1E02991C-2C62-4F84-AE49-2F61892060E5}
O42 - Logiciel: CopyTrans Suite désinstallation uniquement - (.WindSolutions.) [HKCU] -- CopyTrans Suite
O42 - Logiciel: DVDVideoSoftTB Toolbar - (.DVDVideoSoftTB.) [HKLM] -- DVDVideoSoftTB Toolbar
O42 - Logiciel: DiskAid 5.3 - (.DigiDNA.) [HKLM] -- DiskAid_is1
O42 - Logiciel: Driver Genius Professional Edition - (.Driver-Soft Inc..) [HKLM] -- Driver Genius Professional Edition_is1
O42 - Logiciel: EPSON SX130 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON SX130 Series
O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM] -- EPSON Scanner
O42 - Logiciel: Free FLV Converter V 7.4.0 - (.Koyote Soft.) [HKLM] -- Free FLV Converter_is1
O42 - Logiciel: Free Mp3 Wma Converter V 2.2 - (.Koyote Soft.) [HKLM] -- Free Mp3 Wma Converter_is1
O42 - Logiciel: Free YouTube to MP3 Converter version 3.11.25.627 - (.DVDVideoSoft Ltd..) [HKLM] -- Free YouTube to MP3 Converter_is1
O42 - Logiciel: Garmin Communicator Plugin - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {17079027-EB8A-42C6-9BF8-825B78889F6A}
O42 - Logiciel: Garmin USB Drivers - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: HP Deskjet 1050 J410 series - Enquête sur l'amélioration du produit - (.Hewlett-Packard Co..) [HKLM] -- {2E59544C-AB84-42C5-864D-EC2A0989893D}
O42 - Logiciel: HP Deskjet 1050 J410 series Aide - (.Hewlett Packard.) [HKLM] -- {5C90D8CF-F12A-41C6-9007-3B651A1F0D78}
O42 - Logiciel: HP Deskjet 3070 B611 series - Enquête sur l'amélioration du produit - (.Hewlett-Packard Co..) [HKLM] -- {1F48D922-91D7-407A-965D-EF7B96D0C30D}
O42 - Logiciel: HP Deskjet 3070 B611 series Aide - (.Hewlett Packard.) [HKLM] -- {9F20CE56-3828-432D-A3C5-3EC6A2ED93C6}
O42 - Logiciel: HP Photo Creations - (.HP Photo Creations Powered by RocketLife.) [HKLM] -- HP Photo Creations
O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {85DF2EED-08BC-46FB-90DA-28B0D0A8E8A8}
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5
O42 - Logiciel: ImageShack Uploader 2.2.0 - (.ImageShack Corp..) [HKLM] -- {8BCD7AE7-F713-4D50-BAB9-7839B9386870}
O42 - Logiciel: Java(TM) 6 Update 29 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216024FF}
O42 - Logiciel: Java(TM) 7 Update 5 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217005FF}
O42 - Logiciel: JavaFX 2.1.1 - (.Oracle Corporation.) [HKLM] -- {1111706F-666A-4037-7777-211328764D10}
O42 - Logiciel: Logiciel d'archivage WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
O42 - Logiciel: Logiciel de base du périphérique HP Deskjet 1050 J410 series - (.Hewlett-Packard Co..) [HKLM] -- {C77A23B1-712E-4C6A-A97D-C0B1568EBC9E}
O42 - Logiciel: Logiciel de base du périphérique HP Deskjet 3070 B611 series - (.Hewlett-Packard Co..) [HKLM] -- {8B640DF0-1DC9-473D-A1D5-C26E69E0310F}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Ma-Config.com - (.Cybelsoft.) [HKLM] -- {0810B8B7-7539-41D3-983E-6127FCF1CC9E}
O42 - Logiciel: Malwarebytes Anti-Malware version 1.61.0.1400 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
O42 - Logiciel: Microsoft ActiveSync - (.Microsoft Corporation.) [HKLM] -- {99052DB7-9592-4522-A558-5417BBAD48EE}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{8283FD64-6A3B-4104-9E12-7CA25EF29A1A}
O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office File Validation Add-In - (.Microsoft Corporation.) [HKLM] -- {90140000-2005-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 - (.Microsoft Corporation.) [HKLM] -- {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM] -- {9BE518E6-ECC6-35A9-88E4-87755C07200F}
O42 - Logiciel: Mozilla Firefox 13.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 13.0.1 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: NVIDIA Drivers - (.NVIDIA Corporation.) [HKLM] -- NVIDIA Drivers
O42 - Logiciel: NVIDIA Pilote graphique 267.24 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver
O42 - Logiciel: NVIDIA nView 135.50 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView
O42 - Logiciel: NVIDIA nView Desktop Manager - (.NVIDIA Corporation.) [HKLM] -- NVIDIA nView Desktop Manager
O42 - Logiciel: PhotoFiltre - (.Pas de propriétaire.) [HKCU] -- PhotoFiltre
O42 - Logiciel: Pinnacle VideoSpin - (.Pinnacle Systems.) [HKLM] -- {FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}
O42 - Logiciel: PlayerPlus - (.Pas de propriétaire.) [HKLM] -- PlayerPlus
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {7BE15435-2D3E-4B58-867F-9C75BED0208C}
O42 - Logiciel: RAD Video Tools - (.Pas de propriétaire.) [HKLM] -- RADVideo
O42 - Logiciel: RadioSure - (.Pas de propriétaire.) [HKCU] -- RadioSure
O42 - Logiciel: RealNetworks - Microsoft Visual C++ 2008 Runtime - (.RealNetworks, Inc.) [HKLM] -- {7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}
O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 15.0
O42 - Logiciel: RealUpgrade 1.1 - (.RealNetworks, Inc..) [HKLM] -- {28C2DED6-325B-4CC7-983A-1777C8F7FBAB}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5C497F0B-2061-4CC9-A61C-6B45B867354D}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CD769337-C8AC-46DB-A7DC-643E50089263}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553089) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{01D4CA59-7070-4420-9BCC-0EFA7C5D76BE}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553090) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{643C12A2-AF9A-4712-B8BE-3B7650AFE00A}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2584063) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BF3F1CBD-B05C-4644-AE43-6EE0FCC227A4}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7F207DCA-3399-40CB-A968-6E5991B1421A}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5DD3FF90-B302-45B2-A188-C5EA7ACD5D46}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A0D5F849-D9D5-48ED-99D0-C74D7BFA6A09}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{E34960DB-2A93-45DB-A208-02650F7AB09C}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{293FB6BE-D3EB-4162-B522-F9108040B9FE}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{31C0F635-15AD-4AA3-A3C6-B542B403D0EE}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3069CE04-082C-4669-9BA1-E6AA66330C1F}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{2B3C041A-A7F2-4A24-968D-4BEB6A123D15}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{ABB5F56F-FC55-4C7E-9622-B8A1E670BAFC}
O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A4E43D5-858F-49BD-BA72-8F30E1793060}
O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{B4C12F08-B0EF-4CC4-AD5F-381DD62BF640}
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB2510061) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5D930261-AA5B-48D1-931F-425C9D767490}
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edi - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{AEA16A27-0B97-4670-818F-A98D06EC0A6F}
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edi - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0EF0D4FB-BB23-4515-AAEA-1240AC2DA525}
O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edit - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A8732F0-C20F-4A9B-A2A9-66FE7A586C35}
O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{075C2272-0881-46D3-B3A5-1D83D6940270}
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
O42 - Logiciel: Skype™ 5.9 - (.Skype Technologies S.A..) [HKLM] -- {EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}
O42 - Logiciel: SpywareBlaster 4.5 - (.Javacool Software LLC.) [HKLM] -- SpywareBlaster_is1
O42 - Logiciel: Uninstall 1.0.0.1 - (.Pas de propriétaire.) [HKLM] -- Uninstall_is1
O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
O42 - Logiciel: Update for Microsoft Office 2007 System (KB2539530) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B4CEEAE-AA88-490C-BCB2-AAC3421981A4}
O42 - Logiciel: Update for Microsoft Office Outlook 2007 (KB2583910) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BDC21583-5601-4B2B-88F3-7919F6DE8FB1}
O42 - Logiciel: Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687267) 32-B - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{B5B7C5DB-74C3-43E0-8413-0C6C1CA4DED0}
O42 - Logiciel: VLC media player 2.0.1 - (.VideoLAN.) [HKLM] -- VLC media player
O42 - Logiciel: Visual C++ 2008 x86 Runtime - (v9.0.30729) - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}
O42 - Logiciel: Visual C++ 2008 x86 Runtime - v9.0.30729.01 - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01
O42 - Logiciel: Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0 - (.Garmin.) [HKLM] -- 49CF605F02C7954F4E139D18828DE298CD59217C
O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- KB892130
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
O42 - Logiciel: Windows Live ID Sign-in Assistant - (.Microsoft Corporation.) [HKLM] -- {0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
O42 - Logiciel: Yontoo 1.10.02 - (.Yontoo LLC.) [HKLM] -- {889DF117-14D1-44EE-9F31-C5FB5D47F68B}
O42 - Logiciel: avast! Internet Security v7.0.1456.0 - (.AVAST Software.) [HKLM] -- avast
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}
O42 - Logiciel: uTorrentBar_FR Toolbar - (.uTorrentBar_FR.) [HKLM] -- uTorrentBar_FR Toolbar
O42 - Logiciel: vShare.tv plugin 1.3 - (.vShare.tv, Inc..) [HKLM] -- vShare.tv plugin
O42 - Logiciel: µTorrent - (.Pas de propriétaire.) [HKLM] -- uTorrent

---\\ HKCU & HKLM Software Keys
[HKCU\Software\1ClickDownload]
[HKCU\Software\AVAST Software]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\FSOLS.Fscax.3]
[HKCU\Software\AppDataLow\RealNetworks]
[HKCU\Software\AppDataLow\Software\Conduit]
[HKCU\Software\AppDataLow\Software\Microsoft]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Audacity]
[HKCU\Software\BitTorrent]
[HKCU\Software\CDDB]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\ConduitSearchScopes]
[HKCU\Software\Conduit]
[HKCU\Software\Cygwin]
[HKCU\Software\DSNR Labs]
[HKCU\Software\DVDVideoSoftTB]
[HKCU\Software\DVDVideoSoft]
[HKCU\Software\Datamngr]
[HKCU\Software\DivXNetworks]
[HKCU\Software\EPSON]
[HKCU\Software\ESET]
[HKCU\Software\EasyBits]
[HKCU\Software\F-Secure]
[HKCU\Software\Garmin]
[HKCU\Software\Google]
[HKCU\Software\HP]
[HKCU\Software\Hensense.com]
[HKCU\Software\ImageShack Corp.]
[HKCU\Software\ImageShack]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lavalys]
[HKCU\Software\Lavasoft]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\NVIDIA Corporation]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\OfferBox]
[HKCU\Software\Pinnacle Systems]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RAD Game Tools]
[HKCU\Software\RealNetworks]
[HKCU\Software\Realtek]
[HKCU\Software\Skype]
[HKCU\Software\Smartbar]
[HKCU\Software\StartSearch]
[HKCU\Software\SweetIM]
[HKCU\Software\Trolltech]
[HKCU\Software\Visan]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\YahooPartnerToolbar]
[HKCU\Software\Yahoo]
[HKCU\Software\bProtector]
[HKCU\Software\cybelsoft]
[HKCU\Software\uTorrentBar_FR]
[HKCU\Software\vShare.tv]
[HKLM\Software\8ec]
[HKLM\Software\AVAST Software]
[HKLM\Software\Adobe]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Boxore]
[HKLM\Software\BrowserChoice]
[HKLM\Software\Bunndle]
[HKLM\Software\C07ft5Y]
[HKLM\Software\CDDB]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Conduit]
[HKLM\Software\Creative Tech]
[HKLM\Software\Cygwin]
[HKLM\Software\DVDVideoSoftTB]
[HKLM\Software\DVDVideoSoft]
[HKLM\Software\DivX]
[HKLM\Software\Driver-Soft]
[HKLM\Software\EPSON]
[HKLM\Software\ESET]
[HKLM\Software\FAST Multimedia]
[HKLM\Software\GEAR Software]
[HKLM\Software\Garmin]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\HP]
[HKLM\Software\Hensence.com]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\Iminent]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Khronos]
[HKLM\Software\Lavasoft]
[HKLM\Software\Licenses]
[HKLM\Software\Macromedia]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\MimarSinan]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\NVIDIA Corporation]
[HKLM\Software\ODBC]
[HKLM\Software\OfferBox]
[HKLM\Software\Oracle]
[HKLM\Software\Pegasus Imaging]
[HKLM\Software\PegasusImaging]
[HKLM\Software\Pinnacle Systems]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\RAD Game Tools]
[HKLM\Software\RealNetworks]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\RocketLife]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\SharingMax]
[HKLM\Software\Skype]
[HKLM\Software\Software]
[HKLM\Software\SpywareBlaster]
[HKLM\Software\SweetIM]
[HKLM\Software\Tarma Installer]
[HKLM\Software\VideoLAN]
[HKLM\Software\Visan]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Windows]
[HKLM\Software\Xing Technology Corp.]
[HKLM\Software\YoutubeDownloader]
[HKLM\Software\cybelsoft]
[HKLM\Software\instinno]
[HKLM\Software\mozilla.org]
[HKLM\Software\uTorrentBar_FR]
~ Scan Softwares in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 17/01/2012 - 19:44:02 - [0,691] ----D C:\Program Files\1ClickDownload
O43 - CFD: 26/06/2011 - 09:10:20 - [158,860] ----D C:\Program Files\Adobe
O43 - CFD: 28/06/2011 - 06:54:52 - [2,201] ----D C:\Program Files\Apple Software Update
O43 - CFD: 29/06/2012 - 17:34:59 - [42,369] ----D C:\Program Files\Audacity
O43 - CFD: 08/07/2011 - 09:08:48 - [438,476] ----D C:\Program Files\AVAST Software
O43 - CFD: 01/07/2012 - 10:04:50 - [1,137] ----D C:\Program Files\Boxore
O43 - CFD: 09/04/2011 - 12:23:43 - [3,058] ----D C:\Program Files\CCleaner
O43 - CFD: 01/06/2011 - 06:31:55 - [16,587] ----D C:\Program Files\CDBurnerXP
O43 - CFD: 08/04/2011 - 23:36:31 - [0] ----D C:\Program Files\ComPlus Applications
O43 - CFD: 15/12/2011 - 14:25:49 - [0,609] ----D C:\Program Files\Conduit
O43 - CFD: 04/02/2012 - 15:22:15 - [0,290] ----D C:\Program Files\DIFX
O43 - CFD: 06/07/2012 - 08:42:44 - [18,662] ----D C:\Program Files\DigiDNA
O43 - CFD: 09/04/2011 - 11:37:13 - [22,032] ----D C:\Program Files\Driver-Soft
O43 - CFD: 29/06/2012 - 16:50:28 - [15,011] ----D C:\Program Files\DVDVideoSoft
O43 - CFD: 15/12/2011 - 14:25:46 - [4,794] ----D C:\Program Files\DVDVideoSoftTB
O43 - CFD: 25/11/2011 - 16:28:08 - [7,972] ----D C:\Program Files\epson
O43 - CFD: 11/04/2011 - 01:17:42 - [0] ----D C:\Program Files\eRightSoft
O43 - CFD: 15/12/2011 - 13:52:18 - [0,001] ----D C:\Program Files\Feneris
O43 - CFD: 10/07/2012 - 02:00:50 - [453,588] ----D C:\Program Files\Fichiers communs
O43 - CFD: 06/07/2012 - 19:52:19 - [15,175] ----D C:\Program Files\Free FLV Converter
O43 - CFD: 29/06/2012 - 17:05:29 - [25,856] ----D C:\Program Files\Free mp3 Wma Converter
O43 - CFD: 15/12/2011 - 17:43:31 - [0,048] ----D C:\Program Files\Free Video Converter
O43 - CFD: 04/02/2012 - 15:22:11 - [0,117] ----D C:\Program Files\Garmin
O43 - CFD: 04/02/2012 - 15:22:19 - [14,677] ----D C:\Program Files\Garmin GPS Plugin
O43 - CFD: 01/06/2011 - 06:36:53 - [293,012] ----D C:\Program Files\Google
O43 - CFD: 15/03/2012 - 21:02:12 - [6,687] ----D C:\Program Files\Hensence.com
O43 - CFD: 16/01/2012 - 23:46:38 - [1,601] ----D C:\Program Files\Hewlett-Packard
O43 - CFD: 16/01/2012 - 23:45:00 - [114,424] ----D C:\Program Files\HP
O43 - CFD: 13/04/2011 - 01:16:16 - [0,352] ----D C:\Program Files\HP Photo Creations
O43 - CFD: 10/04/2011 - 13:32:13 - [26,352] ----D C:\Program Files\ImageShack Uploader
O43 - CFD: 15/03/2012 - 21:02:11 - [6,491] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 14/06/2012 - 03:17:01 - [5,560] ----D C:\Program Files\Internet Explorer
O43 - CFD: 13/06/2012 - 10:22:40 - [2,259] ----D C:\Program Files\iPod
O43 - CFD: 13/06/2012 - 10:24:01 - [149,583] ----D C:\Program Files\iTunes
O43 - CFD: 10/07/2012 - 01:57:25 - [169,626] ----D C:\Program Files\Java
O43 - CFD: 04/05/2011 - 18:09:27 - [0,000] ----D C:\Program Files\Lavalys
O43 - CFD: 10/04/2011 - 08:38:18 - [5,395] ----D C:\Program Files\ma-config.com
O43 - CFD: 25/06/2012 - 08:42:09 - [11,560] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 09/04/2011 - 11:37:48 - [2,073] ----D C:\Program Files\Messenger
O43 - CFD: 05/05/2012 - 15:16:05 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 08/04/2011 - 23:40:14 - [0] ----D C:\Program Files\microsoft frontpage
O43 - CFD: 10/04/2011 - 18:24:12 - [545,487] ----D C:\Program Files\Microsoft Office
O43 - CFD: 13/05/2012 - 09:40:39 - [36,641] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 10/04/2011 - 18:24:05 - [0,014] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 10/04/2011 - 18:17:40 - [1,323] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 18/04/2011 - 05:15:38 - [3,554] ----D C:\Program Files\Microsoft Works
O43 - CFD: 10/04/2011 - 18:22:30 - [7,774] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 09/04/2011 - 11:28:06 - [9,894] ----D C:\Program Files\Movie Maker
O43 - CFD: 16/06/2012 - 23:37:21 - [38,995] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 17/06/2012 - 08:43:16 - [0,195] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 12/04/2011 - 08:56:43 - [0,025] ----D C:\Program Files\MSBuild
O43 - CFD: 08/04/2011 - 23:35:14 - [18,385] ----D C:\Program Files\MSN
O43 - CFD: 08/04/2011 - 23:36:03 - [8,341] ----D C:\Program Files\MSN Gaming Zone
O43 - CFD: 12/04/2011 - 02:35:39 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 08/04/2011 - 23:37:51 - [3,133] ----D C:\Program Files\NetMeeting
O43 - CFD: 10/04/2011 - 08:43:24 - [246,454] ----D C:\Program Files\NVIDIA Corporation
O43 - CFD: 22/04/2011 - 11:22:44 - [0,091] ----D C:\Program Files\OfferBox
O43 - CFD: 08/04/2011 - 23:36:20 - [0,002] ----D C:\Program Files\Online Services
O43 - CFD: 10/07/2012 - 01:59:19 - [33,205] ----D C:\Program Files\Oracle
O43 - CFD: 09/04/2011 - 11:28:30 - [4,176] ----D C:\Program Files\Outlook Express
O43 - CFD: 10/04/2011 - 13:29:25 - [3,652] ----D C:\Program Files\PhotoFiltre
O43 - CFD: 10/04/2011 - 13:23:20 - [141,115] ----D C:\Program Files\Pinnacle
O43 - CFD: 26/04/2012 - 10:56:37 - [57,977] ----D C:\Program Files\PlayerPlus
O43 - CFD: 26/11/2011 - 20:41:08 - [72,431] ----D C:\Program Files\QuickTime
O43 - CFD: 11/04/2011 - 12:53:04 - [1,788] ----D C:\Program Files\RADVideo
O43 - CFD: 16/03/2012 - 11:10:33 - [95,236] ----D C:\Program Files\Real
O43 - CFD: 09/04/2011 - 09:16:24 - [67,853] ----D C:\Program Files\Realtek
O43 - CFD: 12/04/2011 - 08:56:37 - [34,726] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 05/03/2012 - 17:08:01 - [0] ----D C:\Program Files\rkfree
O43 - CFD: 10/07/2012 - 19:35:24 - [0,801] ----D C:\Program Files\Searchqu Toolbar
O43 - CFD: 08/04/2011 - 23:38:51 - [0,001] ----D C:\Program Files\Services en ligne
O43 - CFD: 16/06/2012 - 18:32:32 - [16,787] R---D C:\Program Files\Skype
O43 - CFD: 01/07/2012 - 10:39:16 - [0,023] ----D C:\Program Files\Software
O43 - CFD: 02/02/2012 - 09:52:13 - [5,402] ----D C:\Program Files\SpywareBlaster
O43 - CFD: 08/04/2011 - 23:44:19 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 20/05/2012 - 16:13:09 - [0,840] ----D C:\Program Files\uTorrent
O43 - CFD: 20/05/2012 - 16:07:00 - [4,795] ----D C:\Program Files\uTorrentBar_FR
O43 - CFD: 10/04/2011 - 10:14:34 - [89,877] ----D C:\Program Files\VideoLAN
O43 - CFD: 21/09/2011 - 19:13:16 - [0,396] ----D C:\Program Files\vShare.tv plugin
O43 - CFD: 08/04/2011 - 23:39:59 - [3,089] ----D C:\Program Files\Windows Media Player
O43 - CFD: 08/04/2011 - 23:35:46 - [3,760] ----D C:\Program Files\Windows NT
O43 - CFD: 08/04/2011 - 23:38:53 - [0] --H-D C:\Program Files\WindowsUpdate
O43 - CFD: 08/04/2011 - 23:54:33 - [3,703] ----D C:\Program Files\WinRAR
O43 - CFD: 08/04/2011 - 23:40:14 - [0] ----D C:\Program Files\xerox
O43 - CFD: 17/01/2012 - 19:45:05 - [0,186] ----D C:\Program Files\Yontoo
O43 - CFD: 10/07/2012 - 19:47:49 - [12,845] ----D C:\Program Files\ZHPDiag
O43 - CFD: 26/06/2011 - 09:10:38 - [3,591] ----D C:\Program Files\Fichiers communs\Adobe
O43 - CFD: 13/06/2012 - 10:22:36 - [122,789] ----D C:\Program Files\Fichiers communs\Apple
O43 - CFD: 10/04/2011 - 18:24:04 - [0,089] ----D C:\Program Files\Fichiers communs\DESIGNER
O43 - CFD: 29/06/2012 - 16:51:25 - [65,664] ----D C:\Program Files\Fichiers communs\DVDVideoSoft
O43 - CFD: 25/11/2011 - 19:49:23 - [0,263] ----D C:\Program Files\Fichiers communs\EPSON
O43 - CFD: 09/04/2011 - 09:15:31 - [3,452] ----D C:\Program Files\Fichiers communs\InstallShield
O43 - CFD: 10/07/2012 - 02:00:50 - [1,181] ----D C:\Program Files\Fichiers communs\Java
O43 - CFD: 07/03/2012 - 09:25:28 - [210,532] ----D C:\Program Files\Fichiers communs\Microsoft Shared
O43 - CFD: 08/04/2011 - 23:37:43 - [0,271] ----D C:\Program Files\Fichiers communs\MSSoap
O43 - CFD: 09/04/2011 - 01:23:23 - [0] ----D C:\Program Files\Fichiers communs\ODBC
O43 - CFD: 08/04/2011 - 23:37:49 - [0,008] ----D C:\Program Files\Fichiers communs\Services
O43 - CFD: 16/06/2012 - 18:32:28 - [2,056] ----D C:\Program Files\Fichiers communs\Skype
O43 - CFD: 09/04/2011 - 01:23:21 - [3,612] ----D C:\Program Files\Fichiers communs\SpeechEngines
O43 - CFD: 18/04/2011 - 05:14:09 - [39,442] ----D C:\Program Files\Fichiers communs\System
O43 - CFD: 16/03/2012 - 11:10:27 - [0,336] ----D C:\Program Files\Fichiers communs\xing shared
O43 - CFD: 10/04/2011 - 13:23:20 - [0,302] ----D C:\Program Files\Fichiers communs\Yahoo!
O43 - CFD: 01/07/2012 - 10:39:16 - [637,195] R-H-D C:\Documents and Settings\All Users\Application Data
O43 - CFD: 10/07/2012 - 19:44:56 - [0,019] ----D C:\Documents and Settings\All Users\Bureau
O43 - CFD: 10/04/2011 - 13:23:20 - [40,473] R---D C:\Documents and Settings\All Users\Documents
O43 - CFD: 08/04/2011 - 23:39:50 - [0,003] -SH-D C:\Documents and Settings\All Users\DRM
O43 - CFD: 09/04/2011 - 01:23:01 - [0] ----D C:\Documents and Settings\All Users\Favoris
O43 - CFD: 15/03/2012 - 17:45:28 - [0,193] R---D C:\Documents and Settings\All Users\Menu Démarrer
O43 - CFD: 25/11/2011 - 16:29:36 - [0,000] --H-D C:\Documents and Settings\All Users\Modèles
O43 - CFD: 10/04/2011 - 18:34:24 - [24,384] ----D C:\Documents and Settings\cyrille\Application Data\Adobe
O43 - CFD: 18/11/2011 - 12:36:18 - [-1853,963] ----D C:\Documents and Settings\cyrille\Application Data\Apple Computer
O43 - CFD: 06/07/2012 - 17:43:18 - [0,002] ----D C:\Documents and Settings\cyrille\Application Data\Audacity
O43 - CFD: 01/06/2011 - 06:33:06 - [0,001] ----D C:\Documents and Settings\cyrille\Application Data\Canneverbe Limited
O43 - CFD: 06/07/2012 - 08:43:30 - [4,946] ----D C:\Documents and Settings\cyrille\Application Data\DiskAid
O43 - CFD: 12/11/2011 - 13:41:18 - [0,000] ----D C:\Documents and Settings\cyrille\Application Data\dvdcss
O43 - CFD: 29/06/2012 - 16:49:22 - [1,516] ----D C:\Documents and Settings\cyrille\Application Data\DVDVideoSoft
O43 - CFD: 12/01/2012 - 17:09:18 - [0,000] ----D C:\Documents and Settings\cyrille\Application Data\DVDVideoSoftIEHelpers
O43 - CFD: 05/05/2012 - 15:17:39 - [0] ----D C:\Documents and Settings\cyrille\Application Data\file2linktemplate
O43 - CFD: 29/06/2012 - 17:12:26 - [0,000] ----D C:\Documents and Settings\cyrille\Application Data\FreeAudioPack
O43 - CFD: 06/07/2012 - 19:45:43 - [0,000] ----D C:\Documents and Settings\cyrille\Application Data\FreeFLVConverter
O43 - CFD: 07/12/2011 - 19:48:35 - [0,001] ----D C:\Documents and Settings\cyrille\Application Data\FreeVideoConverter
O43 - CFD: 04/02/2012 - 15:23:30 - [0] ----D C:\Documents and Settings\cyrille\Application Data\Garmin
O43 - CFD: 29/06/2012 - 17:24:29 - [0] ----D C:\Documents and Settings\cyrille\Application Data\GetRightToGo
O43 - CFD: 15/03/2012 - 21:02:57 - [0,000] ----D C:\Documents and Settings\cyrille\Application Data\Hensense.com
O43 - CFD: 13/04/2011 - 01:16:07 - [0] ----D C:\Documents and Settings\cyrille\Application Data\HpUpdate
O43 - CFD: 08/04/2011 - 23:44:21 - [0] ----D C:\Documents and Settings\cyrille\Application Data\Identities
O43 - CFD: 09/04/2011 - 00:16:17 - [0,001] ----D C:\Documents and Settings\cyrille\Application Data\Macromedia
O43 - CFD: 23/03/2012 - 03:04:38 - [1,613] ----D C:\Documents and Settings\cyrille\Application Data\Malwarebytes
O43 - CFD: 19/01/2012 - 16:57:36 - [8,623] -S--D C:\Documents and Settings\cyrille\Application Data\Microsoft
O43 - CFD: 09/04/2011 - 11:59:10 - [107,999] ----D C:\Documents and Settings\cyrille\Application Data\Mozilla
O43 - CFD: 21/04/2011 - 10:22:14 - [0,258] ----D C:\Documents and Settings\cyrille\Application Data\OfferBox
O43 - CFD: 01/06/2011 - 06:31:43 - [1,118] ----D C:\Documents and Settings\cyrille\Application Data\OpenCandy
O43 - CFD: 10/07/2012 - 01:58:54 - [0] ----D C:\Documents and Settings\cyrille\Application Data\Oracle
O43 - CFD: 10/04/2011 - 13:29:44 - [0,001] ----D C:\Documents and Settings\cyrille\Application Data\PhotoFiltre
O43 - CFD: 02/06/2012 - 11:52:12 - [20,523] ----D C:\Documents and Settings\cyrille\Application Data\Real
O43 - CFD: 18/11/2011 - 13:05:14 - [0] ----D C:\Documents and Settings\cyrille\Application Data\searchquband
O43 - CFD: 27/06/2012 - 13:13:14 - [9,127] ----D C:\Documents and Settings\cyrille\Application Data\Skype
O43 - CFD: 29/07/2011 - 08:00:46 - [0,025] ----D C:\Documents and Settings\cyrille\Application Data\skypePM
O43 - CFD: 08/04/2011 - 23:57:40 - [10,339] ----D C:\Documents and Settings\cyrille\Application Data\Sun
O43 - CFD: 05/12/2011 - 15:20:44 - [0,105] ----D C:\Documents and Settings\cyrille\Application Data\U3
O43 - CFD: 10/07/2012 - 19:49:11 - [2,688] ----D C:\Documents and Settings\cyrille\Application Data\uTorrent
O43 - CFD: 07/07/2012 - 15:43:49 - [1,353] ----D C:\Documents and Settings\cyrille\Application Data\vlc
O43 - CFD: 18/11/2011 - 15:57:15 - [31,379] ----D C:\Documents and Settings\cyrille\Application Data\WindSolutions
O43 - CFD: 09/04/2011 - 09:14:44 - [0,000] ----D C:\Documents and Settings\cyrille\Application Data\WinRAR
O43 - CFD: 10/04/2011 - 18:34:24 - [15,226] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Adobe
O43 - CFD: 12/01/2012 - 03:33:53 - [0,164] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\APN
O43 - CFD: 10/04/2011 - 10:13:15 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Apple
O43 - CFD: 24/04/2011 - 08:41:54 - [135,234] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Apple Computer
O43 - CFD: 15/03/2012 - 17:47:08 - [0,219] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Conduit
O43 - CFD: 10/04/2011 - 13:21:18 - [134,535] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Downloaded Installations
O43 - CFD: 11/01/2012 - 12:11:10 - [4,681] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\DVDVideoSoftTB
O43 - CFD: 01/03/2012 - 01:55:14 - [0,905] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\fontconfig
O43 - CFD: 23/07/2011 - 07:43:02 - [51,690] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Google
O43 - CFD: 16/01/2012 - 23:57:25 - [0,232] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\HP
O43 - CFD: 22/06/2012 - 19:57:41 - [33,895] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Microsoft
O43 - CFD: 10/04/2011 - 18:15:54 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Microsoft Help
O43 - CFD: 09/04/2011 - 11:59:02 - [55,051] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Mozilla
O43 - CFD: 27/12/2011 - 13:58:03 - [0,904] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\MPlayer
O43 - CFD: 01/06/2011 - 10:09:14 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\OpenCandy
O43 - CFD: 13/05/2012 - 09:45:22 - [0,347] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\PCHealth
O43 - CFD: 10/05/2012 - 21:33:49 - [6,406] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\RadioSure
O43 - CFD: 01/06/2011 - 06:47:50 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Real
O43 - CFD: 21/12/2011 - 00:22:29 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Software
O43 - CFD: 10/07/2012 - 10:34:40 - [0,000] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Sun
O43 - CFD: 29/04/2011 - 18:37:53 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Sunbelt Software
O43 - CFD: 19/06/2012 - 21:39:17 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\Temp
O43 - CFD: 20/05/2012 - 16:07:04 - [4,447] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\uTorrentBar_FR
O43 - CFD: 05/02/2012 - 01:28:54 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\WinZip Courier
O43 - CFD: 12/04/2011 - 01:39:17 - [0] ----D C:\Documents and Settings\cyrille\Local Settings\Application Data\WMTools Downloaded Files
O43 - CFD: 08/04/2011 - 23:44:23 - [0,014] R---D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 14/10/2011 - 09:54:51 - [0,001] ----D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\Accessories
O43 - CFD: 11/04/2011 - 12:54:46 - [0,001] ----D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\Bink and Smacker
O43 - CFD: 15/05/2011 - 01:07:30 - [0,003] ----D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\CopyTrans Suite
O43 - CFD: 26/06/2012 - 14:00:15 - [0,001] R---D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 10/04/2011 - 13:24:46 - [0,000] R---D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\Outils d'administration
O43 - CFD: 10/04/2011 - 13:29:25 - [0,003] ----D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\PhotoFiltre
O43 - CFD: 21/12/2011 - 00:22:10 - [0,003] ----D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\PlayerPlus
O43 - CFD: 10/05/2012 - 21:33:35 - [0,002] ----D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\RadioSure
O43 - CFD: 08/04/2011 - 23:54:33 - [0,002] ----D C:\Documents and Settings\cyrille\Menu Démarrer\Programmes\WinRAR
~ Scan Program Folder in 01mn 28s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.256AA382F488F0EF7220F0CBC38C4B77] - 10/07/2012 - 18:45:19 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1778858]
O44 - LFC:[MD5.4322D982E8518BD7391F11669F4ADFAF] - 10/07/2012 - 18:23:58 ---A- . (...) -- C:\WINDOWS\system32\wpa.dbl [13646]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10/07/2012 - 18:23:55 ---A- . (...) -- C:\WINDOWS\0.log [0]
O44 - LFC:[MD5.ED70281F9B1C651D45039EA9F463EE5B] - 10/07/2012 - 18:23:29 ---A- . (...) -- C:\WINDOWS\wiadebug.log [157]
O44 - LFC:[MD5.A66639F39B6676036619B397034C5288] - 10/07/2012 - 18:23:20 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 10/07/2012 - 18:22:08 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.A04F0159CD47B5DEAB761254B4DBDB71] - 10/07/2012 - 18:20:54 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32402]
O44 - LFC:[MD5.F73DEDFCA6252B8431C1FFD3661809AB] - 10/07/2012 - 00:58:36 ---A- . (.Oracle Corporation - Java(TM) Web Start Launcher.) -- C:\WINDOWS\system32\javaws.exe [227720]
O44 - LFC:[MD5.7A1E2AF50DDCDD49C114C1099DBEF6E1] - 10/07/2012 - 00:58:36 ---A- . (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(T.) -- C:\WINDOWS\system32\npDeployJava1.dll [772504]
O44 - LFC:[MD5.892A789EB58FCEA322E86B239D641668] - 10/07/2012 - 00:57:44 ---A- . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\WINDOWS\system32\javaw.exe [174064]
O44 - LFC:[MD5.62BC16D94E8FD4751CF9A5A12AFC6163] - 10/07/2012 - 00:57:43 ---A- . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\WINDOWS\system32\java.exe [174064]
O44 - LFC:[MD5.9681A655BE1D8AFF0D1A352504E4AF0C] - 07/07/2012 - 21:12:18 ---A- . (...) -- C:\WINDOWS\system32\CONFIG.NT [3120]
O44 - LFC:[MD5.9676D719827A0DEF706FC0C631F51DCE] - 06/07/2012 - 18:45:57 ---A- . (.FLV.com - Free FLV Converter - Tube Finder.) -- C:\WINDOWS\system32\TubeFinder.exe [360448]
O44 - LFC:[MD5.7109A9AA551F37CD168C02368465957E] - 03/07/2012 - 17:21:54 ---A- . (.AVAST Software - avast! TDI Filter Driver.) -- C:\WINDOWS\system32\Drivers\aswTdi.sys [54232]
O44 - LFC:[MD5.1C1F3D6DDDC046C920C493A779649F66] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! File System Access Blocking Driver.) -- C:\WINDOWS\system32\Drivers\aswFsBlk.sys [21256]
O44 - LFC:[MD5.CBBAD43B0DED13F5F3784B9BA7F220AE] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! File System Filter Driver for Window.) -- C:\WINDOWS\system32\Drivers\aswmon.sys [89624]
O44 - LFC:[MD5.9E912FE7B41650701EF2B227ACA440F3] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! File System Filter Driver for Window.) -- C:\WINDOWS\system32\Drivers\aswmon2.sys [97608]
O44 - LFC:[MD5.0127263DFC8C4216C085338CE0C047C3] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! Filtering NDIS driver.) -- C:\WINDOWS\system32\Drivers\aswNdis2.sys [202928]
O44 - LFC:[MD5.088BE3EC42010310FE867F874B6FEDF2] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! Keyboard Filter Driver.) -- C:\WINDOWS\system32\Drivers\aswKbd.sys [18544]
O44 - LFC:[MD5.982E275D1C5801042FE94209FB0160FB] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! TDI Redirect Driver.) -- C:\WINDOWS\system32\Drivers\aswRdr.sys [35928]
O44 - LFC:[MD5.73DBCF808E00580F2A47F93DD9B03876] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\WINDOWS\system32\Drivers\aswSnx.sys [721000]
O44 - LFC:[MD5.6CBD7D3A33F498D09C831CDD732DA2E0] - 03/07/2012 - 17:21:53 ---A- . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\system32\Drivers\aswSP.sys [353688]
O44 - LFC:[MD5.0B27AE82C113D3687024D18459440426] - 03/07/2012 - 17:21:52 ---A- . (.AVAST Software - avast! Base Kernel-Mode Device Driver for W.) -- C:\WINDOWS\system32\Drivers\aavmker4.sys [25256]
O44 - LFC:[MD5.B5AAA12631877731A253E44202FFC5BC] - 03/07/2012 - 17:21:52 ---A- . (.AVAST Software - avast! Filtering TDI driver.) -- C:\WINDOWS\system32\Drivers\aswFW.sys [113776]
O44 - LFC:[MD5.7946D9F881715414B9F5D80D16752664] - 03/07/2012 - 17:21:32 ---A- . (.AVAST Software - avast! Screen Saver stub.) -- C:\WINDOWS\avastSS.scr [41224]
O44 - LFC:[MD5.011A849235BACE60852566530B52AF91] - 03/07/2012 - 17:21:28 ---A- . (.AVAST Software - avast! start-up scanner.) -- C:\WINDOWS\system32\aswBoot.exe [227648]
O44 - LFC:[MD5.A1478D7DFE4091265DD13DDE3A943B7B] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\FaxSetup.log [419684]
O44 - LFC:[MD5.2465A7C938BB3A92B11791E23FE9D025] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\MedCtrOC.log [29551]
O44 - LFC:[MD5.5C03F6C89EC43E43662061304285265A] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\comsetup.log [139726]
O44 - LFC:[MD5.8A764D1A678166B59DBD414C2C9709D3] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\iis6.log [482668]
O44 - LFC:[MD5.CA81E3EBA5B040D0F800D1E090113FEE] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\imsins.log [4507]
O44 - LFC:[MD5.1C049541B735A7073B39DF9D308506AC] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\msgsocm.log [21441]
O44 - LFC:[MD5.74FA28D513EFAB48CEF3D485EF537F80] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\ntdtcsetup.log [85839]
O44 - LFC:[MD5.8A5C1C703CAE05EAC08092D2910B6961] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\ocgen.log [212334]
O44 - LFC:[MD5.2829CF18FFFF2723736FEC3CAAB220AE] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\ocmsn.log [23584]
O44 - LFC:[MD5.26B9DC7E14A6BF158DC39AA713BF0AA5] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\tabletoc.log [20837]
O44 - LFC:[MD5.6EC30635164F69E28CB4C2014781E9E8] - 01/07/2012 - 09:19:14 ---A- . (...) -- C:\WINDOWS\tsoc.log [196101]
O44 - LFC:[MD5.98FFDEA44080FFECFF6A1F38ED603160] - 01/07/2012 - 09:19:10 ---A- . (...) -- C:\WINDOWS\system32\PerfStringBackup.INI [1102588]
O44 - LFC:[MD5.9440AA839694A47A00D61BB24CA5C882] - 01/07/2012 - 09:19:10 ---A- . (...) -- C:\WINDOWS\system32\perfc009.dat [68638]
O44 - LFC:[MD5.AD6A3A5985F0D8E143E00855973CDB1E] - 01/07/2012 - 09:19:10 ---A- . (...) -- C:\WINDOWS\system32\perfc00C.dat [81868]
O44 - LFC:[MD5.65A4BFD9496887B24A9E88D1FF821439] - 01/07/2012 - 09:19:10 ---A- . (...) -- C:\WINDOWS\system32\perfh009.dat [435742]
O44 - LFC:[MD5.B5FBD56532158526DAE0B7EA3B409B56] - 01/07/2012 - 09:19:10 ---A- . (...) -- C:\WINDOWS\system32\perfh00C.dat [503720]
O44 - LFC:[MD5.5F77C92445ABFF2B9546D915E60BEF14] - 01/07/2012 - 09:19:08 ---A- . (...) -- C:\WINDOWS\netfxocm.log [74148]
O44 - LFC:[MD5.6FACB094B3F0A36F1FF7EEAAAA9EDE64] - 01/07/2012 - 09:19:04 ---A- . (...) -- C:\WINDOWS\msmqinst.log [134072]
O44 - LFC:[MD5.FB90377D215934BFFD9A38389FB2A686] - 01/07/2012 - 09:09:59 ---A- . (...) -- C:\WINDOWS\setupapi.log [328629]
O44 - LFC:[MD5.10659CDC617FF6D97BDCEA5EFCF5906D] - 29/06/2012 - 16:06:42 ---A- . (...) -- C:\WINDOWS\KB932716-v2.log [7621]
O44 - LFC:[MD5.839BB22A2FEB1DE057931A1A90FAB91D] - 29/06/2012 - 16:06:25 ---A- . (...) -- C:\WINDOWS\imsins.BAK [1374]
O44 - LFC:[MD5.574A95719EE48EBD34F9A83D28B6FF0C] - 29/06/2012 - 16:05:09 ---A- . (.NCT Company Ltd. - NCTAudioPlayer2 ActiveX DLL.) -- C:\WINDOWS\system32\AudPlayer.dll [458752]
O44 - LFC:[MD5.6321037C8D5703E17C4F28A0AD1C5EB9] - 29/06/2012 - 16:05:09 ---A- . (.NCT Company Ltd. - NCTAudioRecord2 ActiveX DLL.) -- C:\WINDOWS\system32\AudioRecord.dll [454656]
O44 - LFC:[MD5.CE83F378B9F3B3F81D9D73092015F398] - 29/06/2012 - 16:05:09 ---A- . (.NCT Company Ltd. - NCTAudioVisualization2 ActiveX DLL.) -- C:\WINDOWS\system32\AudioVisu.dll [479232]
O44 - LFC:[MD5.D34D1DB92FF97C4E477DC0EC8DE3CF96] - 29/06/2012 - 16:05:09 ---A- . (.NCT Company Ltd. - NCTWMAFile2 ActiveX DLL.) -- C:\WINDOWS\system32\WMAFile.dll [348160]
O44 - LFC:[MD5.4C5AA05EFBDF6B9F62909E10B7DE3BF8] - 29/06/2012 - 16:05:08 ---A- . (.NCT Company Ltd. - NCTAudioFile2 ActiveX DLL.) -- C:\WINDOWS\system32\AudFile.dll [1986560]
O44 - LFC:[MD5.D872D2F8F9065E34E8F286E81EF38BB6] - 29/06/2012 - 16:05:08 ---A- . (.NCT Company Ltd. - NCTAudioInformation2 ActiveX DLL.) -- C:\WINDOWS\system32\AudioInfos.dll [1212416]
O44 - LFC:[MD5.79DC363E87A956674BAD0776DA4FE952] - 29/06/2012 - 16:05:07 ---A- . (.NCT Company Ltd. - NCTAudioDesign2 ActiveX DLL.) -- C:\WINDOWS\system32\AudDesign.dll [2084864]
O44 - LFC:[MD5.6BF03A6229A9F7C93DA246D5DBE26396] - 29/06/2012 - 16:05:07 ---A- . (.NCT Company Ltd. - NCTAudioDisplay2 ActiveX DLL.) -- C:\WINDOWS\system32\AudDisplay.dll [417792]
O44 - LFC:[MD5.C9DD76D0EF94637C77FF8CA5E0FB0684] - 26/06/2012 - 12:58:07 ---A- . (...) -- C:\WINDOWS\system.ini [227]
O44 - LFC:[MD5.4AFA13250192D2297FA9868F72807D6B] - 26/06/2012 - 12:58:07 ---A- . (...) -- C:\WINDOWS\win.ini [710]
O44 - LFC:[MD5.775E188DD15C9AC9E735A556FB95578E] - 26/06/2012 - 12:58:07 -SH-- . (...) -- C:\boot.ini [212]
O44 - LFC:[MD5.7B948E3657BEA62E437BC46CA6EF6012] - 25/06/2012 - 17:44:07 ---A- . (.ALWIL Software - avast! Filtering NDIS driver.) -- C:\WINDOWS\system32\Drivers\aswNdis.sys [12112]
O44 - LFC:[MD5.74389CED6AC7242167ABB3050DC26C96] - 25/06/2012 - 07:40:21 ---A- . (.Pas de propriétaire - Setup/Uninstall.) -- C:\WINDOWS\isRS-000.tmp [711240]
O44 - LFC:[MD5.AFCEE5019BBD61BAD791127CA4060686] - 23/06/2012 - 00:35:50 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\WINDOWS\system32\FlashPlayerApp.exe [426184]
O44 - LFC:[MD5.DBD17494F0BAD9B99EE249AC830F5772] - 23/06/2012 - 00:35:49 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl [70344]
O44 - LFC:[MD5.85BE7C03FAAA62EB112D72AD494D670B] - 22/06/2012 - 15:32:30 ---A- . (.Newtonsoft - Newtonsoft Json.NET .NET 2.0.) -- C:\WINDOWS\system32\Newtonsoft.Json.Net20.dll [405144]
O44 - LFC:[MD5.70D352CAB6E012DC8046A16BA6F9ECE1] - 14/06/2012 - 09:39:49 ---A- . (...) -- C:\WINDOWS\system32\FNTCACHE.DAT [278944]
O44 - LFC:[MD5.1F8AF474D49FCCC168743E6465E517F6] - 14/06/2012 - 02:37:09 ---A- . (...) -- C:\WINDOWS\KB2707511.log [18365]
O44 - LFC:[MD5.DEA7665EC6A11DD4EFE72814A5A90C68] - 14/06/2012 - 02:17:39 ---A- . (...) -- C:\WINDOWS\KB2699988-IE8.log [15548]
O44 - LFC:[MD5.9AEC5CB6F160E0F47998FC55D4C2AB2B] - 14/06/2012 - 02:16:55 ---A- . (...) -- C:\WINDOWS\updspapi.log [57194]
O44 - LFC:[MD5.E13B08F6B3DE929994CF18C8D0939188] - 14/06/2012 - 02:15:44 ---A- . (...) -- C:\WINDOWS\KB2685939.log [7078]
O44 - LFC:[MD5.2C0DA8310627BF17C2A761465EE4584D] - 14/06/2012 - 02:02:27 ---A- . (...) -- C:\WINDOWS\KB2709162.log [12155]
O44 - LFC:[MD5.D06A088218F88C5D2D77FAC1765E47BA] - 29/09/2011 - 13:20:34 ---A- . (...) -- C:\WINDOWS\system32\lame_enc.dll [484352]
O44 - LFC:[MD5.62483DA3D985156FCFE0E9960B1A06ED] - 29/09/2011 - 13:20:32 ---A- . (...) -- C:\WINDOWS\system32\NCTWMAProfiles.prx [116296]
O44 - LFC:[MD5.E4F856D2E8DE64B5B099E1A59AAD25A1] - 28/09/2011 - 08:18:00 ---A- . (...) -- C:\WINDOWS\system32\ControlSubX.ocx [24576]
O44 - LFC:[MD5.944418C4D8FE165A45FFDEF408B3EDF1] - 28/09/2011 - 08:18:00 ---A- . (...) -- C:\WINDOWS\system32\PropertyGrid.ocx [364544]
O44 - LFC:[MD5.54993305992877F9515D01CDC6BEE4C9] - 28/09/2011 - 08:18:00 ---A- . (...) -- C:\WINDOWS\system32\ReyXpBasics.tlb [208500]
~ Scan Files in 00mn 22s



---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll
~ Scan ShellExecuteHooks in 00mn 00s



---\\ Export de clé d'application autorisée (O47)
O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "C:\Program Files\ma-config.com\maconfservice.exe" [Enabled] .(.CybelSoft - Service de détection matériel.) -- C:\Program Files\ma-config.com\maconfservice.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe" [Enabled] .(.Pinnacle Systems - Render Manager.) -- C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe" [Enabled] .(.Pinnacle Systems - umi.) -- C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe" [Enabled] .(.Pinnacle Systems - Pinnacle VideoSpin program file.) -- C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Office Outlook.) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe" [Enabled] .(.Hewlett-Packard Co. - USBSetup.exe.) -- C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
O47 - AAKE:Key Export SP - "C:\Program Files\uTorrent\uTorrent.exe" [Enabled] .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files\uTorrent\uTorrent.exe
O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\dpvsetup.exe" [Enabled] .(.Microsoft Corporation - Microsoft DirectPlay Voice Test.) -- C:\WINDOWS\system32\dpvsetup.exe
O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\rundll32.exe" [Enabled] Clé orpheline
O47 - AAKE:Key Export SP - "D:\rapimgr.exe" [Enabled] .(.Microsoft Corporation - ActiveSync RAPI Manager.) -- D:\rapimgr.exe
O47 - AAKE:Key Export SP - "D:\wcescomm.exe" [Enabled] .(.Microsoft Corporation - ActiveSync Connection Manager.) -- D:\wcescomm.exe
O47 - AAKE:Key Export SP - "D:\WCESMgr.exe" [Enabled] .(.Microsoft Corporation - ActiveSync Application.) -- D:\WCESMgr.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\DeviceSetup.exe" [Enabled] .(.Hewlett-Packard Co. - DeviceSetup.exe.) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\DeviceSetup.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPNetworkCommunicator.exe" [Enabled] .(.Hewlett-Packard Co. - HPNetworkCommunicator.) -- C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPNetworkCommunicator.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Fichiers communs\Apple\Apple Application Support\WebKit2WebProcess.exe" [Enabled] .(.Apple Inc..) -- C:\Program Files\Fichiers communs\Apple\Apple Application Support\WebKit2WebProcess.exe
O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Skype\Phone\Skype.exe" [Enabled] .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export DP - "D:\rapimgr.exe" [Enabled] .(.Microsoft Corporation - ActiveSync RAPI Manager.) -- D:\rapimgr.exe
O47 - AAKE:Key Export DP - "D:\wcescomm.exe" [Enabled] .(.Microsoft Corporation - ActiveSync Connection Manager.) -- D:\wcescomm.exe
O47 - AAKE:Key Export DP - "D:\WCESMgr.exe" [Enabled] .(.Microsoft Corporation - ActiveSync Application.) -- D:\WCESMgr.exe
~ Scan Keys in 00mn 21s



---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\WINDOWS\system32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Kerberos Security Package.) -- C:\WINDOWS\system32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\WINDOWS\system32\wdigest.dll
~ Scan Keys in 00mn 00s



---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ip6fw.sys . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- C:\WINDOWS\system32\Drivers\ip6fw.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\system32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpcdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\WINDOWS\system32\Drivers\rdpcdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- C:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpwd.sys . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- C:\WINDOWS\system32\Drivers\rdpwd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdpipe.sys . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdpipe.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdtcp.sys . (.Microsoft Corporation - TCP Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdtcp.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
~ Scan CSB in 00mn 00s



---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - (no data)
~ Scan IFEO in 00mn 00s



---\\ MountPoints2 Shell Key (O51)
O51 - MPSK:{8fdf090b-ffb9-11e0-975b-002354d8ac2f}\AutoRun\command. (...) -- F:\LaunchU3.exe (.not file.)
~ Scan Keys in 00mn 00s



---\\ Trojan Driver Search Data (HKLM) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\system32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\system32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\system32\ir41_32.ax
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\system32\ir50_32.dll
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.mjpg"="pvmjpg30.dll" . (.Pegasus Imaging Corporation - PICVideo M-JPEG 3 codec.) -- C:\WINDOWS\system32\pvmjpg30.dll
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \drivers.desc\"pvmjpg30.dll"="PICVideo 3 M-JPEG VfW Codec" . (.Pegasus Imaging Corporation - PICVideo M-JPEG 3 codec.) -- C:\WINDOWS\system32\pvmjpg30.dll
~ Scan Keys in 00mn 01s



---\\ ShareTools MSconfig StartupReg (O53) (None)

---\\ Microsoft Control Security Providers (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll
~ Scan Keys in 00mn 00s



---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
~ Scan Keys in 00mn 00s



---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
O56 - MWPE:[HKLM\...\policies\Explorer] - "HonorAutoRunSetting"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveTypeAutoRun"=28
~ Scan Keys in 00mn 00s



---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.0B27AE82C113D3687024D18459440426] - 03/07/2012 - 17:21:52 ---A- . (.AVAST Software - avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP.) -- C:\WINDOWS\system32\Drivers\aavmker4.sys [25256]
O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9037]
~ Scan Drivers in 00mn 00s



---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 1.31 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ Scan ADS in 00mn 00s



---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe
~ Scan Keys in 00mn 00s



---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe (.not file.)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\WINDOWS\system32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe (.not file.)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\WINDOWS\system32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe (.not file.)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\WINDOWS\system32\ie4uinit.exe (.not file.)
~ Scan Keys in 00mn 00s



---\\ Search Browser Infection (O69)
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050..clientLogIsEnabled", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050..clientLogServiceUrl", "http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050..uninstallLogServiceUrl", "http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.BrowserCompStateIsOpen_129681780741097243", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.BrowserCompStateIsOpen_129853623028165512", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.CTID", "CT2269050");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.CurrentServerDate", "10-7-2012");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.DSInstall", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.DialogsAlignMode", "LTR");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.DialogsGetterLastCheckTime", "Tue Jul 10 2012 11:11:29 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.DownloadReferralCookieData", "");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.EMailNotifierPollDate", "Thu Dec 15 2011 13:46:48 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.FirstServerDate", "15-12-2011");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.FirstTime", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.FirstTimeFF3", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.FixPageNotFoundErrors", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.GroupingServerCheckInterval", 1440);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.GroupingServiceUrl", "http://grouping.services.conduit.com/");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.HPInstall", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.HasUserGlobalKeys", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.HomePageProtectorEnabled", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.HomepageBeforeUnload", "http://search.conduit.com/?ctid=CT2269050&SearchSource=13");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.Initialize", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.InitializeCommonPrefs", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.InstallationAndCookieDataSentCount", 3);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.InstallationType", "UnknownIntegration");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.InstalledDate", "Thu Dec 15 2011 13:26:46 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.InvalidateCache", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.IsGrouping", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.IsInitSetupIni", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.IsMulticommunity", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.IsOpenThankYouPage", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.IsOpenUninstallPage", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.IsProtectorsInit", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LanguagePackLastCheckTime", "Tue Jul 10 2012 11:11:29 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LastLogin_3.12.0.7", "Thu Apr 26 2012 07:56:14 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LastLogin_3.12.2.3", "Tue May 29 2012 21:25:14 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LastLogin_3.13.0.6", "Wed Jun 27 2012 09:50:44 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LastLogin_3.14.1.0", "Tue Jul 10 2012 17:23:41 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LastLogin_3.8.1.0", "Thu Dec 15 2011 13:26:48 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.LatestVersion", "3.13.0.6");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.Locale", "en");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.MCDetectTooltipHeight", "83");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.MCDetectTooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.MCDetectTooltipWidth", "295");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.MyStuffEnabledAtInstallation", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.OriginalFirstVersion", "3.8.1.0");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.RadioLastCheckTime", "Thu Dec 15 2011 13:26:48 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.RadioLastUpdateIPServer", "3");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.RadioShrinkedFromSetup", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SavedHomepage", "http://www.searchqu.com/414");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchCaption", "DVDVideoSoftTB Customized Web Search");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchEngineBeforeUnload", "DVDVideoSoftTB Customized Web Search");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchFromAddressBarIsInit", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchInNewTabEnabled", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchInNewTabLastCheckTime", "Tue Jul 10 2012 11:11:15 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchInNewTabUsageUrl", "http://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchProtectorEnabled", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SearchProtectorToolbarDisabled", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SendProtectorDataViaLogin", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ServiceMapLastCheckTime", "Tue Jul 10 2012 11:11:14 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SettingsLastCheckTime", "Tue Jul 10 2012 17:23:27 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.SettingsLastUpdate", "1341904940");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.TBHomePageUrl", "http://search.conduit.com/?ctid=CT2269050&SearchSource=13");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Thu Dec 15 2011 13:26:43 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1312887586");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ToolbarShrinkedFromSetup", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.TrusteLinkUrl", "http://trust.conduit.com/CT2269050");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolb[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.UserID", "UN55617627680784489");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ValidationData_Search", 0);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.ValidationData_Toolbar", 0);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.WeatherNetwork", "");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.WeatherPollDate", "Thu Dec 15 2011 13:26:48 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.WeatherUnit", "C");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.alertChannelId", "666138");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.autoDisableScopes", -1);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.backendstorage.cb_firstuse0100", "31");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.backendstorage.cbfirsttime", "5468752044656320313520323031312031333A32363A353120474D542B30313030");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.backendstorage.shoppingapp.gk.exipres", "5475652044656320323020323031312031333A32363A353020474D542B30313030")[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.backendstorage.shoppingapp.gk.geolocation", "6672616E6365");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.backendstorage.url_history", "687474703A2F2F7777772E66616365626F6F6B2E636F6D2F3F7265663D746E5F746E6D6E");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.backendstorage.url_history_time", "31333233393533303232343237");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;se[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Fri Dec 16 2011 01:26:44 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.homepageProtectorEnableByLogin", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.initDone", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.isAppTrackingManagerOn", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.isFirstRadioInstallation", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.myStuffEnabled", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.myStuffPublihserMinWidth", 400);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.myStuffSearchUrl", "http://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&oct[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.myStuffServiceUrl", "http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.revertSettingsEnabled", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.searchProtectorDialogDelayInSec", 10);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.searchProtectorEnableByLogin", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.testingCtid", "");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Tue Jul 10 2012 11:11:29 GMT+0200");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Thu Dec 15 2011 13:26:48 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT2269050.usagesFlag", 2);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777..clientLogServiceUrl", "http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777..uninstallLogServiceUrl", "http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.GroupingServiceUrl", "http://grouping.services.conduit.com/");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.HomepageBeforeUnload", "http://search.conduit.com/?ctid=CT3106777&SearchSource=13");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.InstallationId", "ConduitNSISIntegration");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.InstallationType", "ConduitXPEIntegration");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3106777&SearchSource=2&q=");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.TBHomePageUrl", "http://search.conduit.com/?ctid=CT3106777&SearchSource=13");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.TrusteLinkUrl", "http://trust.conduit.com/CT3106777");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolb[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;se[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.myStuffSearchUrl", "http://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&oct[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CT3106777.myStuffServiceUrl", "http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ConduitHomepagesList", "http://search.conduit.com/?ctid=CT2269050&SearchSource=13,http://search.condui[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ConduitSearchList", "DVDVideoSoftTB Customized Web Search,WinZipBar Customized Web Search");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://Settings.toolbar.search.conduit.com/root/CT2269050/CT2269050", "\"738287f2566cc1c3c91104fc[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://Settings.toolbar.search.conduit.com/root/CT3106777/CT3106777", "\"a3601f516e8d94304bcd0d51[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/1500748/1496227/FR", "\"0\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/666138/661999/FR", "\"0\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", "\"1341904856\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://appsmetadata.toolbar.conduit-services.com/?ctid=CT3106777", "\"1322168536\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "wVmmvqqOMqrv5xct1cJ[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "0uSPYx+Kl2jpu8sJZMeH[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlU[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "K4Vqu91uAzWURlxJRdXJOg[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"4bb1de6bebc9cc1:0\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.0.7", "\"4ead38b3e6bcd1:0\"")[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\"")[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:0\"")[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0d648794549cd1:0\"")[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.1.0", "\"80ee9485875dcc1:0\"")[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.0.3", "\"6a637346d78ccc1:0\"")[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://servicemap.conduit-services.com/Toolbar/?ownerId=CT2269050", "\"5a3bfb736bf65ca0cca630a3f0[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://servicemap.conduit-services.com/Toolbar/?ownerId=CT3106777", "\"5a3bfb736bf65ca0cca630a3f0[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer_dead.gif", "\"0a8c48d3330c81:[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.gif", "\"0e2106f3030c81:0\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif", "\"0f475394430c81:0\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif", "\"08d9ef44430c81:0\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif", "\"066e8863030c81:0\"");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://translation.toolbar.conduit-services.com/?locale=EB_LOCALE", "\"ad9cd3b32c68906c8c16d35d5f[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ETag.http://translation.toolbar.conduit-services.com/?locale=en", "\"21ba1682b5b6825cbfd420592a540476\[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\cyrille\\Application Data\\Mozilla\\Firefox\\Pro[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "http://dts.search-results.com/sr?src=ffb&appid=0&systemid=414&sr=0&q="[...]
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ToolbarsList", "CT2269050,CT3106777");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ToolbarsList2", "CT2269050,CT3106777");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.ToolbarsList4", "CT2269050,CT3106777");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.globalUserId", "6ff895df-79c5-44de-8184-2a06fb29853d");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3106777");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Feb 05 2012 00:23:38 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Feb 05 2012 00:23:45 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.clientsServerUrl", "http://alert.client.conduit.com");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.locale", "en");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Feb 05 2012 00:23:31 GMT+0100");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.servicesServerUrl", "http://alert.services.conduit.com");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.showTrayIcon", false);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.notifications.userId", "d5fe0332-b3fc-40ce-a2d6-2492e0ea6374");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.originalHomepage", "http://www.searchqu.com/414");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("CommunityToolbar.originalSearchEngine", "Google");
O69 - SBI: prefs.js [cyrille - ixj76y8o.default] user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3106777&SearchSource=3&q={searchTerms}");
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - () - http://search.live.com
O69 - SBI: SearchScopes [HKCU] {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} - (Search The Web) - http://search.etype.com
O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} - (Search Results) - http://dts.search-results.com
O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2413} [DefaultScope] - (Search Results) - http://dts.search-results.com
O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2414} - (Search Results) - http://dts.search-results.com
O69 - SBI: SearchScopes [HKCU] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (uTorrentBar_FR Customized Web Search) - http://search.conduit.com
O69 - SBI: SearchScopes [HKCU] {D9A4AA19-285D-4ABB-8E0A-3582297354C0} - (Ask Search) - http://websearch.ask.com
~ Scan Keys in 00mn 00s



---\\ Recherche des services démarrés par Svchost (O83)
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\WINDOWS\system32\appmgmts.dll [176640]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496]
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [77824]
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464]
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - DLL Service gestionnaire de disque logique.) -- C:\WINDOWS\system32\dmserver.dll [24576]
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Service client DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [127488]
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040]
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - Pas de description.) -- C:\WINDOWS\system32\es.dll [253952]
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: HidServ (HidServ) . (...) -- C:\WINDOWS\system32\hidserv.dll [0]
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [99840]
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096]
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792]
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gestionnaire de connexions réseau.) -- C:\WINDOWS\system32\netman.dll [198144]
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll [247808]
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gestionnaire de stockage amovible.) -- C:\WINDOWS\system32\ntmssvc.dll [438272]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248]
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Moteur du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [194560]
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\WINDOWS\system32\seclogon.dll [18944]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\WINDOWS\system32\ipnathlp.dll [332800]
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Service de restauration du système.) -- C:\WINDOWS\system32\srsvc.dll [171520]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\WINDOWS\system32\tapisrv.dll [249856]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112]
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Service de temps Windows.) -- C:\WINDOWS\system32\w32time.dll [178176]
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Service configuration automatique sans fil.) -- C:\WINDOWS\system32\wzcsvc.dll [483840]
O83 - Search Svchost Services: Wmi (Wmi) . (.Microsoft Corporation - API avancées Windows 32.) -- C:\WINDOWS\system32\advapi32.dll [685568]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [145408]
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896]
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024]
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Exécution du service Agent de quarantaine.) -- C:\WINDOWS\system32\qagentrt.dll [293376]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\system32\kmsvc.dll [61440]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\WINDOWS\system32\qmgr.dll [409088]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400]
O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Fournisseur de services de périphérique multimédia Microsoft.) -- C:\WINDOWS\system32\mspmsnsv.dll [52736]
~ Scan Services in 00mn 01s



---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.7FCCC7583AD2833E350C843507E50C56] [SPRF][12/02/2011] (.Kaspersky Lab - Programme d'installation de Kaspersky Internet Security 2011.) -- C:\Documents and Settings\cyrille\Bureau\Kaspersky Internet Security 2011 11.0.2.556 CF2.exe [116357184]
[MD5.C4E12970865FC1C5CEDE8358DA3A865D] [SPRF][27/02/2008] (.F-Secure Corporation - F-Secure Automatic Update Agent API DLL.) -- C:\WINDOWS\Downloaded Program Files\auc_lib.dll [290816]
[MD5.3B07863E5916FCD8E6557406AF8BE02E] [SPRF][27/02/2008] (.F-Secure Corporation - daas.) -- C:\WINDOWS\Downloaded Program Files\daas_s.dll [495616]
[MD5.DA4CB993C1FC5217C55902CBB0551DCD] [SPRF][27/02/2008] (.F-Secure Corporation - fscax module.) -- C:\WINDOWS\Downloaded Program Files\fscax.dll [262144]
[MD5.2D3ECC25B42D7A9C6C20B613C1F93407] [SPRF][27/02/2008] (.F-Secure Corporation - F-Secure GateLauncher.) -- C:\WINDOWS\Downloaded Program Files\gatelauncher.exe [588392]
~ Scan Files in 00mn 03s



---\\ Scan Additionnel (O88)
Database Version : 9170 - (25/06/2012)
Clés trouvées (Keys found) : 56
Valeurs trouvées (Values found) : 2
Dossiers trouvés (Folders found) : 11
Fichiers trouvés (Files found) : 0

[HKLM\Software\Classes\AppID\YontooIEClient.DLL] =>Toolbar.Agent
[HKLM\Software\Classes\Toolbar.CT2269050] =>Toolbar.Agent
[HKLM\Software\Classes\YontooIEClient.Api] =>Toolbar.Agent
[HKLM\Software\Classes\YontooIEClient.Api.1] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}] =>Toolbar.AskTBar
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}] =>Adware.Agent
[HKLM\Software\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}] =>Adware.Agent
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}] =>Toolbar.Agent
[HKLM\Software\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}] =>Adware.IMBooster
[HKLM\Software\Classes\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}] =>Adware. BullseyeToolbar
[HKLM\Software\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}] =>Adware.Bandoo
[HKLM\Software\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}] =>Adware.Bandoo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}] =>Adware.Bandoo
[HKLM\Software\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}] =>Adware.Bandoo
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}] =>Adware.Bandoo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}] =>Adware.Bandoo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}] =>Toolbar.Conduit
[HKLM\Software\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}] =>Toolbar.Babylon
[HKLM\Software\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Toolbar.AskSBar
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Toolbar.AskSBar
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] =>Toolbar.Agent
[HKLM\Software\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C}] =>Hijacker.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}] =>Adware.SocialSkinz
[HKLM\Software\Google\Chrome\Extensions\bjeikeheijdjdfjbmknpefojickbkmom] =>PUP.OfferBox
[HKLM\Software\Boxore] =>Spyware.Boxore
[HKCU\Software\ConduitSearchScopes] =>Toolbar.Conduit
[HKCU\Software\DataMngr] =>Adware.Bandoo
[HKLM\Software\Iminent] =>Adware.IMBooster
[HKCU\Software\OfferBox] =>PUP.OfferBox
[HKLM\Software\OfferBox] =>PUP.OfferBox
[HKCU\Software\StartSearch] =>Hijacker.Agent
[HKCU\Software\SweetIM] =>Toolbar.SweetIM
[HKLM\Software\SweetIM] =>Toolbar.SweetIM
[HKCU\Software\uTorrentBar_FR] =>Toolbar.Conduit
[HKLM\Software\uTorrentBar_FR] =>Toolbar.Conduit
[HKCU\Software\vShare.tv] =>PUP.VShareRedir
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\vShare.tv plugin] =>PUP.VShareRedir
[HKLM\Software\Classes\Toolbar.CT3106777] =>Toolbar.Agent
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{99079A25-328F-4BD4-BE04-00955ACAA0A7} =>Adware.Bandoo
[HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440} =>Toolbar.AskSBar
C:\Program Files\Conduit =>Toolbar.Conduit
C:\Program Files\OfferBox =>PUP.OfferBox
C:\Program Files\rkfree =>Keylogger.Logixoft
C:\Program Files\Searchqu Toolbar =>Adware.Bandoo
C:\Program Files\uTorrentBar_FR =>Toolbar.Conduit
C:\Documents and Settings\cyrille\Application Data\OfferBox =>PUP.OfferBox
C:\Documents and Settings\cyrille\Application Data\OpenCandy =>Adware.OpenCandy
C:\Documents and Settings\cyrille\Application Data\searchquband =>Adware.Bandoo
C:\Documents and Settings\cyrille\Local Settings\Application Data\Conduit =>Toolbar.Conduit
C:\Documents and Settings\cyrille\Local Settings\Application Data\OpenCandy =>Adware.OpenCandy
C:\Documents and Settings\cyrille\Local Settings\Application Data\uTorrentBar_FR =>Toolbar.Conduit
~ Scan Additionnel in 00mn 14s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 23/06/2012 250056 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 24/05/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 03/07/2012 44808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 03/07/2012 133912 | (avast! Firewall) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\afwServ.exe
SS - | Demand 14/04/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe
SS - | Demand 0 | (EverestDriver) . (...) - C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt
SS - | Auto 01/06/2011 136176 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 01/06/2011 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SR - | Demand 07/06/2012 821648 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 04/05/2012 161664 | (JavaQuickStarterService) . (.Oracle Corporation.) - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
SS - | Demand 10/03/2011 311744 | (maconfservice) . (.CybelSoft.) - C:\Program Files\ma-config.com\maconfservice.exe
SR - | Auto 04/04/2012 654408 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
SS - | Demand 16/06/2012 113120 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SR - | Auto 71096 | (NMSAccess) . (...) - C:\Program Files\CDBurnerXP\NMSAccessU.exe
SR - | Auto 23/02/2011 156776 | (NVSvc) . (.NVIDIA Corporation.) - C:\WINDOWS\system32\nvsvc32.exe
SS - | Auto 05/06/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
~ Scan Services in 00mn 17s



End of the scan (1636 lines in 03mn 58s)(0)

x
Éditer le texte

Merci d'entrer le mot de passe que vous avez indiqué à la création du texte.

x
Télécharger le texte

Merci de choisir le format du fichier à télécharger.