Virus potentiel non detecté

Votre ordinateur est infecté? vous avez un doute ? c'est ici

Virus potentiel non detecté

Messagepar Squall » Jeu 26 Mai 2011 20:32

Bonjours tout le monde , voilà il y a quelque jours au redemarage de l'ordinateur j'ai u le droit a une sorte de pop-up asser convaincant a l'ouverture de windows qui me conseillé de faire un scan pour internet , biensure j'ai pas clické dessu j'ai fait click droit et fermer ( vue que je le voyais pas ds les proccessus ouvert )

Mais ajd mon winamp a planté j'ai du le reinstallé j'ai u un message derreur qui me disait ceci ( voir en bas a droite ) :

Image

mais j'ai vraiment l'impression d'avoir chopper quelque chose , j'ai fais 2 scan avec eset nod 32 smart security un local et un avec leur scan en ligne , et un avec malwarebytes' ils ne m'on rien trouver ... du coup je viens posté ici avec le c/c du rapport fait avec HijackThis .
Je préferes etre sur , mon PC est neuf il a une bonne configue je comprends pas ce bug et le fait d'avoir ce genre de "pop-up" au démarage de windows ne me rassure pas du tout :) ( je les u qu'une seul fois )

Donc voila le rapport :



Code: Tout sélectionner
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:22:57, on 26/05/2011
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\vVX3000.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\MagicTune Premium\GammaTray.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
C:\Program Files (x86)\Razer\Lachesis\OSD.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Razer\Lachesis\razertra.exe
C:\Program Files (x86)\Razer\Lachesis\razerofa.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
D:\Users\adrien\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_m3910&r=17360111d606pe4e5v125w4791u093
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_m3910&r=17360111d606pe4e5v125w4791u093
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_m3910&r=17360111d606pe4e5v125w4791u093
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_m3910&r=17360111d606pe4e5v125w4791u093
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Lachesis] C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
O4 - Global Startup: GammaTray.lnk = ?
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: USBS3S4Detection - Unknown owner - C:\OEM\USBDECTION\USBS3S4Detection.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9170 bytes


Je vous remercie d'avance pour votre aide et je me vois désolé pour mon incapacité a resoudre le probléme seul et pour mon orthographe pitoyable par moment : )
Squall
 
Messages: 7
Inscription: Jeu 26 Mai 2011 20:24

Re: Virus potentiel non detecté

Messagepar breizhspotlight » Jeu 26 Mai 2011 20:53

bonsoir,

Je déplace ton sujet dans la section désinfection Un Helper va prendre le problème en charge.

@+
Image
Image
En cas de problème constaté sur un sujet, contactez un modérateur par MP. N'intervenez pas vous-même. Merci
Avatar de l’utilisateur
breizhspotlight
 
Messages: 2935
Inscription: Dim 11 Jan 2009 14:50
Localisation: France, Cesson Sévigné

Re: Virus potentiel non detecté

Messagepar Squall » Jeu 26 Mai 2011 20:59

merci dsl , pas cool de donné du taff au modo :D
Squall
 
Messages: 7
Inscription: Jeu 26 Mai 2011 20:24

Re: Virus potentiel non detecté

Messagepar breizhspotlight » Jeu 26 Mai 2011 21:11

Déplacer un sujet prend 5 secondes...
Image
Image
En cas de problème constaté sur un sujet, contactez un modérateur par MP. N'intervenez pas vous-même. Merci
Avatar de l’utilisateur
breizhspotlight
 
Messages: 2935
Inscription: Dim 11 Jan 2009 14:50
Localisation: France, Cesson Sévigné

Re: Virus potentiel non detecté

Messagepar nardino » Jeu 26 Mai 2011 23:10

Bonsoir,
Pour faire un premier diagnostic, applique les deux propositions ci-dessous.

1- Image Télécharge et installe Malwarebytes Anti-Malware de RubbeR DuckY

Image Double-clique sur le fichier mbam-setup-1.50.exe (sous Vista et 7 autorise les modifications)
A la fin de l'installation, veille à ce que les options suivantes soient cochées
    -Mettre à jour Malwarebytes' Anti-Malware
    -Exécuter Malwarebytes' Anti-Malware
Image Clique sur Terminer
Une fenêtre Mise à jour de Malwarebytes' Anti-Malware va s'ouvrir avec une barre de progression.
Puis une autre annonçant le succès de la mise à jour de la base de données. Clique sur OK.
Le programme s'ouvre sur l'onglet Recherche.
Coche Image Exécuter un examen rapide, clique sur le bouton Image

Image A la fin du scan, sélectionne tout et clique sur Supprimer la sélection

Image Poste le rapport qui s'ouvre après cette suppression.
Redémarre le pc si cela est demandé
Tu peux retrouver le rapport dans l'onglet Rapports/Logs avec la date et l'heure d'exécution.

2- Image Télécharge ZHPDiag de Nicolas Coolman sur ton bureau.

Explication en images

Si besoin est, nous ferons appel à d'autres outils.

@+
Image
En cas de problème constaté sur un sujet, contactez un modérateur par MP. N'intervenez pas vous-même. Merci
Avatar de l’utilisateur
nardino
 
Messages: 6344
Inscription: Dim 11 Jan 2009 16:03
Localisation: Reims

Re: Virus potentiel non detecté

Messagepar Squall » Jeu 26 Mai 2011 23:34

Je vais faire ça mais je sais pas si tu a vue en dessou de la screen , j'ai déja fais un scan avec malwarebytes :) je vais qdmm suivre t'es indication


j'ai aussi c/c le rapport de HijackThis en dessou de la screen ( dsl ma screen est grande le paint de windows Seven ne redimensione pas automatiquement :( )
Dernière édition par Squall le Jeu 26 Mai 2011 23:43, édité 1 fois.
Squall
 
Messages: 7
Inscription: Jeu 26 Mai 2011 20:24

Re: Virus potentiel non detecté

Messagepar Squall » Jeu 26 Mai 2011 23:38

Code: Tout sélectionner
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 6686

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

26/05/2011 23:37:37
mbam-log-2011-05-26 (23-37-37).txt

Type d'examen: Examen rapide
Elément(s) analysé(s): 157206
Temps écoulé: 2 minute(s), 4 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Squall
 
Messages: 7
Inscription: Jeu 26 Mai 2011 20:24

Re: Virus potentiel non detecté

Messagepar Squall » Jeu 26 Mai 2011 23:47

Le diagnostic avec ZHPDiag

Code: Tout sélectionner
Rapport de ZHPDiag v1.27.214 par Nicolas Coolman, Update du 25/05/2011
Run by adrien at 26/05/2011 23:50:18
Web site :  http://www.premiumorange.com/zeb-help-process/zhpdiag.html


---\\ Web Browser
MSIE: Internet Explorer v9.0.8112.16421
MFIE: Mozilla Firefox 4.0.1 v4.0.1 (Defaut)

---\\ System Information
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Processor: Intel64 Family 6 Model 37 Stepping 2, GenuineIntel
Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4023 MB (45% free)
System Restore: Activé (Enable)
System drive C: has 394 GB (86%) free of 456 GB

---\\ Logged in mode
Computer Name: ADRIEN-PC
User Name: adrien
All Users Names: adrien, Administrateur,
Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator

---\\ Environnement Variables
%AppData%=C:\Users\adrien\AppData\Roaming
%LocalAppData%=C:\Users\adrien\AppData\Local
%StartMenu%=C:\Users\adrien\AppData\Roaming\Microsoft\Windows\Start Menu

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 394 Go of 456 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 304 Go of 457 Go)
E:\ CD-ROM drive (Not Inserted)
F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
I:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
J:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
K:\ CD-ROM drive (Not Inserted)



---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified



---\\ Recherche particulière de fichiers génériques
[MD5.AC4C51EB24AA95B77F705AB159189E24] - (.Microsoft Corporation - Explorateur Windows.) (.20/11/2010 14:24:45.) -- C:\Windows\Explorer.exe [2872320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 02:14:45.) -- C:\Windows\system32\Wininit.exe [96256]
[MD5.A1236375B74EA63C75657D564890C436] - (.Microsoft Corporation - Internet Extensions for Win32.) (.13/04/2011 18:12:23.) -- C:\Windows\system32\wininet.dll [1126912]



---\\ Processus lancés
[MD5.69764A6475A4C54732E6A07CE6EF8BE2] - (.Microsoft Corporation - Microsoft LifeCam Device Application.) -- C:\Windows\vVX3000.exe   [762736]
[MD5.3DD25048297A24AB4B3BFC17ABA5D0DB] - (.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\Steam.exe   [1242448]
[MD5.61CFEDAF9C527A1463F34F71240F9BB5] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe   [15026056]
[MD5.E8F8C367B07E2212ADBCCDC2594446F1] - (.Pas de propriétaire - GammaTray MFC ?? ????.) -- C:\Program Files (x86)\MagicTune Premium\GammaTray.exe   [36864]
[MD5.0540C38069CD5212B241E62AC1990201] - (.Pas de propriétaire - Hotkey Utility.) -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe   [611872]
[MD5.4A73AB8412D3AA6CFAD24051FF9DBFA7] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe   [283160]
[MD5.11B04297452A96941CA4C50F323CD671] - (.Pas de propriétaire - razerhid MFC Application.) -- C:\Program Files (x86)\Razer\Lachesis\razerhid.exe   [248320]
[MD5.53AD70854369C3F0BD386131C42D3EE3] - (.razercfg MFC Application - OSD.) -- C:\Program Files (x86)\Razer\Lachesis\OSD.exe   [274432]
[MD5.CC88929757FCA1B2D732A1B891C72A52] - (.Pas de propriétaire - razertra MFC Application.) -- C:\Program Files (x86)\Razer\Lachesis\razertra.exe   [143360]
[MD5.6F6AF7DB6CE5F39FF5B7F2014F5307DB] - (.Razer Inc. - Razer OFA - On-the-Fly Sensitivity Adjustme.) -- C:\Program Files (x86)\Razer\Lachesis\razerofa.exe   [163840]
[MD5.2CE8F1C52F490875592166316C512B6F] - (.Skype Technologies - Skype Extras Manager.) -- C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe   [80256]
[MD5.2098CCF443433129B556C2849FE99E26] - (.Valve - Half-Life Launcher.) -- c:\program files (x86)\steam\steamapps\squallss\counter-strike\hl.exe   [86077]
[MD5.5A183A49234A1B08455C198BB7C68D24] - (.Valve Corporation - gameoverlayui.exe (buildbot_winslave01_stea.) -- C:\Program Files (x86)\Steam\GameOverlayUI.exe   [71464]
[MD5.E83508D9A0F0D0D8449317DC6A4C5E02] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe   [924632]
[MD5.3B2CC09944488DB5ED5DFDC315C9AB57] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe   [16856]
[MD5.A588671AF9BE28C22B4BEDE74F60DEE9] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe   [657408]



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions  (P2,M0,M1,M2,M3)
M3 - MFPP: Plugins - [adrien] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\amazon-france.xml
M3 - MFPP: Plugins - [adrien] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\bing.xml
M3 - MFPP: Plugins - [adrien] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
M3 - MFPP: Plugins - [adrien] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\eBay-france.xml
M3 - MFPP: Plugins - [adrien] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [adrien] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\wikipedia-fr.xml
M3 - MFPP: Plugins - [adrien] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\yahoo-france.xml
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.4.4".) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (.Nullsoft, Inc. - Winamp Application Detector.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npwachk.dll
M0 - MFSP: prefs.js [adrien - tvakycqm.default] google.com



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com
R0 - HKUS\S-1-5-21-1042130008-158272769-3281409368-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKUS\S-1-5-21-1042130008-158272769-3281409368-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)) -- C:\Windows\System32\ieframe.dll
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll



---\\ ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Windows Live ID Sign-in Helper [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEHelperStub [64Bits] - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll



---\\ ---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\Run: [egui] . (.ESET - ESET GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
O4 - HKLM\..\Run: [VX3000] . (.Microsoft Corporation - Microsoft LifeCam Device Application.) -- C:\Windows\vVX3000.exe
O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\steam.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKLM\..\Wow6432Node\Run: [Hotkey Utility] . (.Pas de propriétaire - Hotkey Utility.) -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Wow6432Node\Run: [IAStorIcon] . (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Wow6432Node\Run: [Lachesis] . (.Pas de propriétaire - razerhid MFC Application.) -- C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Wow6432Node\Run: [ATICustomerCare] . (.Advanced Micro Devices, Inc. - ATI Customer Care.) -- C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-21-1042130008-158272769-3281409368-1000\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKUS\S-1-5-21-1042130008-158272769-3281409368-1000\..\Run: [Steam] . (.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\steam.exe
O4 - HKUS\S-1-5-21-1042130008-158272769-3281409368-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - HKUS\S-1-5-21-1042130008-158272769-3281409368-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)
O4 - Global Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.lnk . (...)  -- C:\Program Files (x86)\MagicTune Premium\GammaTray.exe



---\\ ---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Users\adrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk . (.Microsoft Corporation.)  -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\adrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.)  -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\adrien\Desktop\Garena.lnk . (.Garena Online PTE LTD.)  -- C:\Program Files (x86)\Garena\Garena.exe
O4 - Global Startup: C:\Users\adrien\Desktop\Heroes of Newerth.lnk . (.S2 Games.)  -- C:\Program Files (x86)\Heroes of Newerth\hon.exe
O4 - Global Startup: C:\Users\adrien\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk . (.S2 Games.)  -- C:\Program Files (x86)\Heroes of Newerth\hon.exe
O4 - Global Startup: C:\Users\adrien\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.)  -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\adrien\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.)  -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Users\adrien\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk . (.Nullsoft, Inc..)  -- C:\Program Files (x86)\Winamp\winamp.exe



---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: Google Sidewiki... - (.not file.) - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{F037E7A1-FD3B-4EFF-A644-019C59AA830E}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{F037E7A1-FD3B-4EFF-A644-019C59AA830E}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{F037E7A1-FD3B-4EFF-A644-019C59AA830E}: DhcpNameServer = 89.2.0.1 89.2.0.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{F037E7A1-FD3B-4EFF-A644-019C59AA830E}: DhcpDomain = dartybox.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{F037E7A1-FD3B-4EFF-A644-019C59AA830E}: DhcpDomain = dartybox.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{F037E7A1-FD3B-4EFF-A644-019C59AA830E}: DhcpDomain = dartybox.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: C:\Windows\system32\Alg.exe (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\system32\atiesrxx.exe
O23 - Service:  (EhttpSrv) . (.ESET - ESET HTTP Server Service.) - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service:  (ekrn) . (.ESET - ESET Service.) - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service:  (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service:  (MagicTuneEngine) . (...) - C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: Nero BackItUp Scheduler 4.0 (Nero BackItUp Scheduler 4.0) . (.Nero AG - Nero BackItUp.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service:  (Steam Client Service) . (.Valve Corporation - Steam Client Service (buildbot_winslave01_s.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service:  (USBS3S4Detection) . (.Pas de propriétaire - USB S3S4 Detection.) - C:\OEM\USBDECTION\USBS3S4Detection.exe
O23 - Service:  (wlidsvc) . (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.exe



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) -  (.not file.)



---\\ Tâches planifiées en automatique (O39)
[MD5.61CFEDAF9C527A1463F34F71240F9BB5] [APT] [{289480A7-7C75-4602-870B-E60467BBD8E0}] (.Skype Technologies S.A..) -- C:\Program Files (x86)\Skype\Phone\Skype.exe



---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: C:\Windows\system32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\DRIVERS\blbdrive.sys
O41 - Driver:  (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\system32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver:  (ehdrv) . (.ESET - ESET Helper driver.) - C:\Windows\System32\DRIVERS\ehdrv.sys
O41 - Driver:  (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver:  (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\system32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\system32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\system32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver:  (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: C:\Windows\system32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver:  (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys



---\\ Logiciels installés (O42)
O42 - Logiciel: AMD Drag and Drop Transcoding - (.ATI Technologies Inc..) [HKLM] -- {FFC78632-282D-133C-3774-EECACF17FD0F}
O42 - Logiciel: ATI AVIVO64 Codecs - (.ATI Technologies Inc..) [HKLM] -- {E7DA67AE-5A56-75D1-C76E-821217C4FEB9}
O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM] -- {AE57C044-8912-A181-A0E4-BC2DAB3A092A}
O42 - Logiciel: ATI Catalyst Registration - (.ATI Technologies Inc..) [HKLM][64Bits] -- {11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}
O42 - Logiciel: ATI Problem Report Wizard - (.ATI Technologies.) [HKLM] -- {2FF804EA-34D7-B18B-CF46-2DF3B7117AF0}
O42 - Logiciel: ATI Stream SDK v2 Developer - (.ATI Technologies Inc..) [HKLM] -- {22441735-5983-AD2A-5CC5-FA2CCD7EF732}
O42 - Logiciel: Acer eRecovery Management - (.Acer Incorporated.) [HKLM][64Bits] -- {7F811A54-5A09-4579-90E1-C93498E230D9}
O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {287ECFA4-719A-2143-A09B-D6A12DE54E40}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- Adobe AIR
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- {A2BCA9F1-566C-4805-97D1-7FDC93386723}
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Reader 9.4.4 MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-A91000000001}
O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM][64Bits] -- {B2EC4A38-B545-4A00-8214-13FE0E915E6D}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] -- {5FD89EA1-99C2-40EE-BBF5-20F8991ED756}
O42 - Logiciel: Counter-Strike - (.Valve.) [HKLM][64Bits] -- Steam App 10
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite
O42 - Logiciel: Defraggler - (.Piriform.) [HKLM] -- Defraggler
O42 - Logiciel: DiRT2 - (.Codemasters.) [HKLM][64Bits] -- {52D1D62C-FEAB-4580-849E-1DB624BADBBD}
O42 - Logiciel: Détection de l'application Winamp - (.Nullsoft, Inc.) [HKCU] -- Winamp Detect
O42 - Logiciel: EVEREST Ultimate Edition v5.50 - (.Lavalys, Inc..) [HKLM][64Bits] -- EVEREST Ultimate Edition_is1
O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM][64Bits] -- {488F0347-C4A7-4374-91A7-30818BEDA710}
O42 - Logiciel: Garena 2010 - (.Garena Online Pte Ltd..) [HKLM][64Bits] -- Garena
O42 - Logiciel: Haali Media Splitter - (.Pas de propriétaire.) [HKLM][64Bits] -- HaaliMkx
O42 - Logiciel: Heroes of Newerth - (.S2 Games.) [HKLM][64Bits] -- hon
O42 - Logiciel: Hotkey Utility - (.Acer Incorporated.) [HKLM][64Bits] -- Hotkey Utility
O42 - Logiciel: HydraVision - (.ATI Technologies Inc..) [HKLM][64Bits] -- {2E5AC744-87A6-CAC6-F992-515806007F1E}
O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Logiciel d'archivage WinRAR - (.Pas de propriétaire.) [HKLM][64Bits] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: MagicTune Premium - (.Samsung Electronics Co. Ltd..) [HKLM][64Bits] -- {D6044256-A309-43B5-9833-D3FAFE2AD24D}
O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Microsoft Corporation - (.Microsoft Corporation.) [HKLM] -- {9C5A08BF-BB99-4998-81BD-F6CC32483B34}
O42 - Logiciel: Microsoft Corporation - (.Microsoft Corporation.) [HKLM][64Bits] -- {B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}
O42 - Logiciel: Microsoft Games for Windows - LIVE - (.Microsoft Corporation.) [HKLM][64Bits] -- {2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}
O42 - Logiciel: Microsoft Games for Windows - LIVE Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}
O42 - Logiciel: Microsoft LifeCam - (.Microsoft Corporation.) [HKLM] -- {6965A8D2-465D-4F98-9FAA-0E9E2348F329}
O42 - Logiciel: Microsoft Office 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {95140000-0070-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM][64Bits] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {7299052b-02a4-4627-81f2-1818da5d550d}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - KB2467175 - (.Microsoft Corporation.) [HKLM][64Bits] -- {a0fe116e-9a8a-466f-aee0-625cb7c207e3}
O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {EE936C7A-EA40-31D5-9B65-8E3E089C3828}
O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM][64Bits] -- {002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 - (.Microsoft Corporation.) [HKLM] -- {8338783A-0968-3B85-AFC7-BAAE0A63DC50}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 - (.Microsoft Corporation.) [HKLM][64Bits] -- {86CE85E6-DBAC-3FFD-B977-E4B79F83C909}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {8220EEFE-38CD-377E-8595-13398D740ACE}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475}
O42 - Logiciel: Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 - (.Microsoft Corporation.) [HKLM] -- {DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}
O42 - Logiciel: MotioninJoy ds3 driver version 0.6.0001 - (.www.motioninjoy.com.) [HKLM] -- {330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1
O42 - Logiciel: Mozilla Firefox 4.0.1 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 4.0.1 (x86 fr)
O42 - Logiciel: Need for Speed(TM) Hot Pursuit - (.Electronic Arts.) [HKLM][64Bits] -- {83A606F5-BF6F-42ED-9F33-B9F74297CDED}
O42 - Logiciel: Nero 9 Essentials - (.Nero AG.) [HKLM][64Bits] -- {8f9d5e25-6d54-4b98-a0fd-c0e10f922788}
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}
O42 - Logiciel: Nero DiscSpeed - (.Nero AG.) [HKLM][64Bits] -- {869200DB-287A-4DC0-B02B-2B6787FBCD4C}
O42 - Logiciel: Nero DiscSpeed Help - (.Nero AG.) [HKLM][64Bits] -- {CC019E3F-59D2-4486-8D4B-878105B62A71}
O42 - Logiciel: Nero DriveSpeed - (.Nero AG.) [HKLM][64Bits] -- {33CF58F5-48D8-4575-83D6-96F574E4D83A}
O42 - Logiciel: Nero DriveSpeed Help - (.Nero AG.) [HKLM][64Bits] -- {E5C7D048-F9B4-4219-B323-8BDB01A2563D}
O42 - Logiciel: Nero Express Help - (.Nero AG.) [HKLM][64Bits] -- {83202942-84B3-4C50-8622-B8C0AA2D2885}
O42 - Logiciel: Nero InfoTool - (.Nero AG.) [HKLM][64Bits] -- {FBCDFD61-7DCF-4E71-9226-873BA0053139}
O42 - Logiciel: Nero InfoTool Help - (.Nero AG.) [HKLM][64Bits] -- {20400DBD-E6DB-45B8-9B6B-1DD7033818EC}
O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM][64Bits] -- {E8A80433-302B-4FF1-815D-FCC8EAC482FF}
O42 - Logiciel: Nero Online Upgrade - (.Nero AG.) [HKLM][64Bits] -- {C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}
O42 - Logiciel: Nero StartSmart - (.Nero AG.) [HKLM][64Bits] -- {7748AC8C-18E3-43BB-959B-088FAEA16FB2}
O42 - Logiciel: Nero StartSmart Help - (.Nero AG.) [HKLM][64Bits] -- {2348B586-C9AE-46CE-936C-A68E9426E214}
O42 - Logiciel: Nero StartSmart OEM - (.Nero AG.) [HKLM][64Bits] -- {4D43D635-6FDA-4FA5-AA9B-23CF73D058EA}
O42 - Logiciel: NeroExpress - (.Nero AG.) [HKLM][64Bits] -- {595A3116-40BB-4E0F-A2E8-D7951DA56270}
O42 - Logiciel: OpenAL - (.Pas de propriétaire.) [HKLM][64Bits] -- OpenAL
O42 - Logiciel: REALTEK Wireless LAN Driver - (.REALTEK Semiconductor Corp..) [HKLM][64Bits] -- {46710AEB-ACE9-4386-9DFB-8B65153BFA74}
O42 - Logiciel: Rapture3D 2.3.22 Game - (.Blue Ripple Sound.) [HKLM][64Bits] -- {D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1
O42 - Logiciel: Razer Lachesis - (.Razer USA Ltd..) [HKLM][64Bits] -- {CB4532F7-A1BD-46D2-9938-3E7D4656FB18}
O42 - Logiciel: Realtek Ethernet Controller Driver For Windows 7 - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Runtime Files Pack 3 (C:\Windows\system32\) #3 - (.Pas de propriétaire.) [HKLM][64Bits] -- ST4UNST #4
O42 - Logiciel: Runtime Files Pack 3 (C:\Windows\system32\) #4 - (.Pas de propriétaire.) [HKLM][64Bits] -- ST4UNST #5
O42 - Logiciel: Runtime Files Pack 3 (C:\Windows\system32\) - (.Pas de propriétaire.) [HKLM][64Bits] -- ST4UNST #3
O42 - Logiciel: Runtime Files Pack 3 - (.Pas de propriétaire.) [HKLM][64Bits] -- ST4UNST #2
O42 - Logiciel: Samsung_MonSetup - (.Samsung.) [HKLM][64Bits] -- {8EA79DBF-D637-448A-89D6-410A087A4493}
O42 - Logiciel: Skype™ 5.1 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- {048298C9-A4D3-490B-9FF9-AB023A9238F3}
O42 - Logiciel: TeamSpeak 3 Client - (.TeamSpeak Systems GmbH.) [HKCU] -- TeamSpeak 3 Client
O42 - Logiciel: VLC media player 1.1.5 - (.VideoLAN.) [HKLM][64Bits] -- VLC media player
O42 - Logiciel: Ventrilo Client - (.Flagship Industries, Inc..) [HKLM][64Bits] -- {789289CA-F73A-4A16-A331-54D498CE069F}
O42 - Logiciel: Ventrilo Client for Windows x64 - (.Flagship Industries, Inc..) [HKLM] -- {EEB3F6BB-318D-4CE5-989F-8191FCBFB578}
O42 - Logiciel: Visual Basic 4 Runtime Files - (.Pas de propriétaire.) [HKLM][64Bits] -- ST4UNST #1
O42 - Logiciel: WMV9/VC-1 Video Playback - (.ATI Technologies Inc..) [HKLM] -- {79BA5437-10FE-2C63-C864-6CB814CDFEAF}
O42 - Logiciel: Warcraft III - (.Blizzard Entertainment.) [HKLM][64Bits] -- Warcraft III
O42 - Logiciel: Winamp - (.Nullsoft, Inc.) [HKLM][64Bits] -- Winamp
O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM][64Bits] -- WinLiveSuite
O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM][64Bits] -- {34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM][64Bits] -- {D45240D3-B6B3-4FF9-B243-54ECE3E10066}
O42 - Logiciel: Windows Live ID Sign-in Assistant - (.Microsoft Corporation.) [HKLM] -- {1B8ABA62-74F0-47ED-B18C-A43128E591B8}
O42 - Logiciel: Windows Live Installer - (.Microsoft Corporation.) [HKLM][64Bits] -- {0B0F231F-CE6A-483D-AA23-77B364F75917}
O42 - Logiciel: Windows Live Language Selector - (.Microsoft Corporation.) [HKLM] -- {D07A61E5-A59C-433C-BCBD-22025FA2287B}
O42 - Logiciel: Windows Live MIME IFilter - (.Microsoft Corporation.) [HKLM] -- {DA54F80E-261C-41A2-A855-549A144F2F59}
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM][64Bits] -- {9D56775A-93F3-44A3-8092-840E3826DE30}
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM][64Bits] -- {9FAE6E8D-E686-49F5-A574-0A58DFD9580C}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM][64Bits] -- {6057E21C-ABE9-4059-AE3E-3BEB9925E660}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM][64Bits] -- {EB4DF488-AAEF-406F-A341-CB2AAA315B90}
O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM][64Bits] -- {6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}
O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM][64Bits] -- {92EA4134-10D1-418A-91E1-5A0453131A38}
O42 - Logiciel: Windows Live PIMT Platform - (.Microsoft Corporation.) [HKLM][64Bits] -- {83C292B7-38A5-440B-A731-07070E81A64F}
O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM][64Bits] -- {A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM][64Bits] -- {C893D8C0-1BA0-4517-B11C-E89B65E72F70}
O42 - Logiciel: Windows Live Photo Gallery - (.Microsoft Corporation.) [HKLM][64Bits] -- {3336F667-9049-4D46-98B6-4C743EEBC5B1}
O42 - Logiciel: Windows Live SOXE - (.Microsoft Corporation.) [HKLM][64Bits] -- {682B3E4F-696A-42DE-A41C-4C07EA1678B4}
O42 - Logiciel: Windows Live SOXE Definitions - (.Microsoft Corporation.) [HKLM][64Bits] -- {200FEC62-3C34-4D60-9CE8-EC372E01C08F}
O42 - Logiciel: Windows Live UX Platform - (.Microsoft Corporation.) [HKLM][64Bits] -- {CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {05E379CC-F626-4E7D-8354-463865B303BF}
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM][64Bits] -- {3B9A92DA-6374-4872-B646-253F18624D5F}
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM][64Bits] -- {A726AE06-AAA3-43D1-87E3-70F510314F04}
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM][64Bits] -- {AAAFC670-569B-4A2F-82B4-42945E0DE3EF}
O42 - Logiciel: Windows Live Writer Resources - (.Microsoft Corporation.) [HKLM][64Bits] -- {62687B11-58B5-4A18-9BC3-9DF4CE03F194}
O42 - Logiciel: neroxml - (.Nero AG.) [HKLM][64Bits] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Squall
 
Messages: 7
Inscription: Jeu 26 Mai 2011 20:24

Re: Virus potentiel non detecté

Messagepar Squall » Jeu 26 Mai 2011 23:52

La suite du diagnostic :

Code: Tout sélectionner
---\\ HKCU & HKLM Software Keys
[HKCU\Software\AMD]
[HKCU\Software\ATI]
[HKCU\Software\Acer]
[HKCU\Software\Adobe]
[HKCU\Software\Alcohol Soft]
[HKCU\Software\AppDataLow\Software\Google]
[HKCU\Software\AppDataLow\Software\Microsoft]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Battle.net]
[HKCU\Software\Blizzard Entertainment]
[HKCU\Software\BlueRippleSound]
[HKCU\Software\CDDB]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\ESET]
[HKCU\Software\Electronic Arts]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\Haali]
[HKCU\Software\Heroes of Newerth]
[HKCU\Software\IGA]
[HKCU\Software\IM Providers]
[HKCU\Software\ImgBurn]
[HKCU\Software\Lavalys]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\Macromedia]
[HKCU\Software\Magic Tune]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Notausgang]
[HKCU\Software\OEM]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\Raptr]
[HKCU\Software\Razer]
[HKCU\Software\Realtek]
[HKCU\Software\Skype]
[HKCU\Software\StarSynergy]
[HKCU\Software\TeamViewer]
[HKCU\Software\Trolltech]
[HKCU\Software\Valve]
[HKCU\Software\Ventrilo]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Winamp]
[HKCU\Software\Wow6432Node]
[HKCU\Software\kde.org]
[HKLM\Software\AMD]
[HKLM\Software\ATI Technologies]
[HKLM\Software\ATI]
[HKLM\Software\Acer Incorporated]
[HKLM\Software\AcerUtil]
[HKLM\Software\Adobe]
[HKLM\Software\America Online]
[HKLM\Software\Audible]
[HKLM\Software\Blizzard Entertainment]
[HKLM\Software\BlueRippleSound]
[HKLM\Software\CDDB]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Codemasters]
[HKLM\Software\CyberLink]
[HKLM\Software\Cyberlink]
[HKLM\Software\DT Soft]
[HKLM\Software\ESET]
[HKLM\Software\Electronic Arts]
[HKLM\Software\Gabest]
[HKLM\Software\Google]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\Khronos]
[HKLM\Software\Macromedia]
[HKLM\Software\Magic Tune]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\McAfee.com]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Nullsoft]
[HKLM\Software\ODBC]
[HKLM\Software\OEM]
[HKLM\Software\OOBEOffer]
[HKLM\Software\OemSetup]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\REALTEK Semiconductor Corp.]
[HKLM\Software\RTLSetup]
[HKLM\Software\Razer USA Ltd.]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SRS Labs]
[HKLM\Software\Samsung Electronics Co. Ltd.]
[HKLM\Software\Samsung]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\TeamSpeak 3 Client]
[HKLM\Software\TeamViewer]
[HKLM\Software\Trad-FR]
[HKLM\Software\TrendMicro]
[HKLM\Software\Valve]
[HKLM\Software\VideoLAN]
[HKLM\Software\Volatile]
[HKLM\Software\Waves Audio]
[HKLM\Software\WinRAR]
[HKLM\Software\Wow6432Node]
[HKLM\Software\mozilla.org]



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 14/01/2011 - 21:23:26 - [14189687] ----D- C:\Program Files\Acer
O43 - CFD: 11/01/2011 - 18:54:18 - [252757] ----D- C:\Program Files\Acer Accessory Store
O43 - CFD: 17/09/2010 - 08:55:44 - [23445921] ----D- C:\Program Files\ATI
O43 - CFD: 09/03/2011 - 16:46:42 - [28] ----D- C:\Program Files\ATI Technologies
O43 - CFD: 16/01/2011 - 22:47:42 - [6905128] ----D- C:\Program Files\CCleaner
O43 - CFD: 11/01/2011 - 22:14:36 - [43613998] ----D- C:\Program Files\Common Files
O43 - CFD: 14/01/2011 - 21:34:44 - [8540016] ----D- C:\Program Files\Defraggler
O43 - CFD: 13/04/2011 - 19:23:00 - [4891318] ----D- C:\Program Files\DVD Maker
O43 - CFD: 15/01/2011 - 16:56:26 - [70467404] ----D- C:\Program Files\ESET
O43 - CFD: 11/01/2011 - 18:53:54 - [0] -SH-D- C:\Program Files\Fichiers communs
O43 - CFD: 14/01/2011 - 22:01:16 - [0] ----D- C:\Program Files\Google
O43 - CFD: 13/04/2011 - 19:27:34 - [5964382] ----D- C:\Program Files\Internet Explorer
O43 - CFD: 14/01/2011 - 18:58:32 - [34291204] ----D- C:\Program Files\Microsoft LifeCam
O43 - CFD: 19/01/2011 - 14:53:14 - [3268798] ----D- C:\Program Files\MotioninJoy
O43 - CFD: 14/07/2009 - 07:32:40 - [25757] ----D- C:\Program Files\MSBuild
O43 - CFD: 12/05/2010 - 14:15:06 - [1825075] ----D- C:\Program Files\Preload
O43 - CFD: 17/09/2010 - 09:00:48 - [14796896] ----D- C:\Program Files\Realtek
O43 - CFD: 14/07/2009 - 07:32:40 - [36813993] ----D- C:\Program Files\Reference Assemblies
O43 - CFD: 14/07/2009 - 07:09:28 - [0] --H-D- C:\Program Files\Uninstall Information
O43 - CFD: 14/01/2011 - 19:20:34 - [6858068] ----D- C:\Program Files\Ventrilo
O43 - CFD: 13/04/2011 - 19:22:56 - [4039680] ----D- C:\Program Files\Windows Defender
O43 - CFD: 21/05/2011 - 03:51:06 - [43896] ----D- C:\Program Files\Windows Live
O43 - CFD: 13/04/2011 - 19:23:00 - [6667776] ----D- C:\Program Files\Windows Mail
O43 - CFD: 13/04/2011 - 19:23:00 - [7687085] ----D- C:\Program Files\Windows Media Player
O43 - CFD: 11/01/2011 - 18:53:54 - [12627636] ----D- C:\Program Files\Windows NT
O43 - CFD: 13/04/2011 - 19:23:00 - [5516056] ----D- C:\Program Files\Windows Photo Viewer
O43 - CFD: 13/04/2011 - 19:23:00 - [244736] ----D- C:\Program Files\Windows Portable Devices
O43 - CFD: 13/04/2011 - 19:23:00 - [7044767] ----D- C:\Program Files\Windows Sidebar
O43 - CFD: 11/01/2011 - 22:14:36 - [5391624] ----D- C:\Program Files\Common Files\ATI Technologies
O43 - CFD: 21/05/2011 - 03:50:42 - [25416613] ----D- C:\Program Files\Common Files\Microsoft Shared
O43 - CFD: 14/07/2009 - 05:20:10 - [2702] ----D- C:\Program Files\Common Files\Services
O43 - CFD: 14/07/2009 - 05:20:10 - [608768] ----D- C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 08/09/2010 - 16:47:46 - [12194291] ----D- C:\Program Files\Common Files\System
O43 - CFD: 14/01/2011 - 21:23:26 - [160] ----D- C:\ProgramData\Acer
O43 - CFD: 31/03/2011 - 14:56:44 - [767] ----D- C:\ProgramData\Adobe
O43 - CFD: 14/07/2009 - 07:08:58 - [0] -SH-D- C:\ProgramData\Application Data
O43 - CFD: 16/01/2011 - 22:11:58 - [0] ----D- C:\ProgramData\ASign
O43 - CFD: 09/03/2011 - 16:48:06 - [188] ----D- C:\ProgramData\ATI
O43 - CFD: 11/01/2011 - 18:53:54 - [0] -SH-D- C:\ProgramData\Bureau
O43 - CFD: 19/01/2011 - 00:58:34 - [2097036390] ----D- C:\ProgramData\Codemasters
O43 - CFD: 14/01/2011 - 21:22:06 - [3142] ----D- C:\ProgramData\CyberLink
O43 - CFD: 19/01/2011 - 00:20:48 - [1577] ----D- C:\ProgramData\DAEMON Tools Lite
O43 - CFD: 14/07/2009 - 07:08:58 - [0] -SH-D- C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 07:08:58 - [0] -SH-D- C:\ProgramData\Documents
O43 - CFD: 17/01/2011 - 17:49:18 - [0] ----D- C:\ProgramData\EA Core
O43 - CFD: 17/01/2011 - 17:49:18 - [60169] ----D- C:\ProgramData\Electronic Arts
O43 - CFD: 15/01/2011 - 16:56:26 - [78492195] ----D- C:\ProgramData\ESET
O43 - CFD: 12/05/2010 - 14:15:46 - [420] ----D- C:\ProgramData\eSobi
O43 - CFD: 11/01/2011 - 18:53:54 - [0] -SH-D- C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 07:08:58 - [0] -SH-D- C:\ProgramData\Favorites
O43 - CFD: 14/01/2011 - 22:16:02 - [509552] ----D- C:\ProgramData\Google
O43 - CFD: 14/01/2011 - 15:26:52 - [54192] ----D- C:\ProgramData\InstallShield
O43 - CFD: 26/05/2011 - 12:10:40 - [6752702] ----D- C:\ProgramData\Malwarebytes
O43 - CFD: 11/01/2011 - 19:24:38 - [14342] ----D- C:\ProgramData\McAfee
O43 - CFD: 11/01/2011 - 18:53:54 - [0] -SH-D- C:\ProgramData\Menu Démarrer
O43 - CFD: 21/05/2011 - 03:51:30 - [1318961367] -S--D- C:\ProgramData\Microsoft
O43 - CFD: 11/01/2011 - 18:53:54 - [0] -SH-D- C:\ProgramData\Modèles
O43 - CFD: 12/05/2010 - 14:23:06 - [11083261] ----D- C:\ProgramData\Nero
O43 - CFD: 11/01/2011 - 18:55:42 - [141] ----D- C:\ProgramData\OEM
O43 - CFD: 14/01/2011 - 22:01:16 - [1311] ----D- C:\ProgramData\Partner
O43 - CFD: 15/01/2011 - 15:58:56 - [5819] ----D- C:\ProgramData\Razer
O43 - CFD: 11/01/2011 - 19:16:00 - [24369033] ----D- C:\ProgramData\Skype
O43 - CFD: 17/01/2011 - 17:35:32 - [0] ----D- C:\ProgramData\Solidshield
O43 - CFD: 14/07/2009 - 07:08:58 - [0] -SH-D- C:\ProgramData\Start Menu
O43 - CFD: 17/09/2010 - 09:07:50 - [163911] ----D- C:\ProgramData\Temp
O43 - CFD: 14/07/2009 - 07:08:58 - [0] -SH-D- C:\ProgramData\Templates
O43 - CFD: 06/02/2011 - 03:55:06 - [4108093] ----D- C:\Users\adrien\AppData\Roaming\Adobe
O43 - CFD: 11/01/2011 - 18:56:18 - [0] ----D- C:\Users\adrien\AppData\Roaming\ATI
O43 - CFD: 11/01/2011 - 20:25:58 - [0] ----D- C:\Users\adrien\AppData\Roaming\CyberLink
O43 - CFD: 16/01/2011 - 22:10:32 - [3545] ----D- C:\Users\adrien\AppData\Roaming\DAEMON Tools Lite
O43 - CFD: 15/01/2011 - 16:58:08 - [0] ----D- C:\Users\adrien\AppData\Roaming\ESET
O43 - CFD: 11/01/2011 - 19:00:36 - [0] ----D- C:\Users\adrien\AppData\Roaming\Google
O43 - CFD: 11/01/2011 - 18:55:16 - [0] ----D- C:\Users\adrien\AppData\Roaming\Identities
O43 - CFD: 16/01/2011 - 21:51:34 - [1528] ----D- C:\Users\adrien\AppData\Roaming\ImgBurn
O43 - CFD: 15/01/2011 - 15:58:10 - [0] ----D- C:\Users\adrien\AppData\Roaming\InstallShield
O43 - CFD: 15/01/2011 - 16:07:44 - [678] ----D- C:\Users\adrien\AppData\Roaming\Intel Corporation
O43 - CFD: 11/01/2011 - 18:55:36 - [10058] ----D- C:\Users\adrien\AppData\Roaming\Macromedia
O43 - CFD: 26/05/2011 - 12:12:52 - [2120] ----D- C:\Users\adrien\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 09:44:40 - [0] ----D- C:\Users\adrien\AppData\Roaming\Media Center Programs
O43 - CFD: 07/05/2011 - 04:36:18 - [0] ----D- C:\Users\adrien\AppData\Roaming\Media Player Classic
O43 - CFD: 15/05/2011 - 21:13:12 - [1184761] -S--D- C:\Users\adrien\AppData\Roaming\Microsoft
O43 - CFD: 19/01/2011 - 14:42:10 - [6053] ----D- C:\Users\adrien\AppData\Roaming\MotioninJoy
O43 - CFD: 11/01/2011 - 19:02:48 - [32179019] ----D- C:\Users\adrien\AppData\Roaming\Mozilla
O43 - CFD: 16/01/2011 - 21:46:04 - [240] ----D- C:\Users\adrien\AppData\Roaming\Nero
O43 - CFD: 11/01/2011 - 18:55:38 - [0] ----D- C:\Users\adrien\AppData\Roaming\OEM
O43 - CFD: 15/01/2011 - 16:01:42 - [1669] ----D- C:\Users\adrien\AppData\Roaming\Raptr
O43 - CFD: 15/01/2011 - 16:07:34 - [11632] ----D- C:\Users\adrien\AppData\Roaming\Razer
O43 - CFD: 26/05/2011 - 23:40:12 - [20077471] ----D- C:\Users\adrien\AppData\Roaming\Skype
O43 - CFD: 26/05/2011 - 21:35:50 - [81200] ----D- C:\Users\adrien\AppData\Roaming\skypePM
O43 - CFD: 26/05/2011 - 23:20:04 - [287558] ----D- C:\Users\adrien\AppData\Roaming\TS3Client
O43 - CFD: 14/01/2011 - 19:21:34 - [5087] ----D- C:\Users\adrien\AppData\Roaming\Ventrilo
O43 - CFD: 14/04/2011 - 22:23:10 - [1045892] ----D- C:\Users\adrien\AppData\Roaming\vlc
O43 - CFD: 26/05/2011 - 17:05:48 - [1755541] ----D- C:\Users\adrien\AppData\Roaming\Winamp
O43 - CFD: 11/01/2011 - 19:25:22 - [12] ----D- C:\Users\adrien\AppData\Roaming\WinRAR
O43 - CFD: 14/03/2011 - 02:46:34 - [489537] ----D- C:\Users\adrien\Appdata\Local\Adobe
O43 - CFD: 11/01/2011 - 18:54:00 - [0] -SH-D- C:\Users\adrien\Appdata\Local\Application Data
O43 - CFD: 26/01/2011 - 15:25:44 - [0] ----D- C:\Users\adrien\Appdata\Local\Apps
O43 - CFD: 11/01/2011 - 18:56:18 - [61886] ----D- C:\Users\adrien\Appdata\Local\ATI
O43 - CFD: 24/03/2011 - 17:06:38 - [1109225] ----D- C:\Users\adrien\Appdata\Local\Citrix
O43 - CFD: 14/01/2011 - 21:20:44 - [0] ----D- C:\Users\adrien\Appdata\Local\Cyberlink
O43 - CFD: 13/03/2011 - 02:47:46 - [0] ----D- C:\Users\adrien\Appdata\Local\Diagnostics
O43 - CFD: 11/01/2011 - 18:55:36 - [181] ----D- C:\Users\adrien\Appdata\Local\EgisTec IPS
O43 - CFD: 27/04/2011 - 00:55:18 - [470826] ----D- C:\Users\adrien\Appdata\Local\ElevatedDiagnostics
O43 - CFD: 14/01/2011 - 21:26:10 - [0] ----D- C:\Users\adrien\Appdata\Local\Google
O43 - CFD: 11/01/2011 - 18:54:00 - [0] -SH-D- C:\Users\adrien\Appdata\Local\Historique
O43 - CFD: 21/05/2011 - 03:55:12 - [276731291] ----D- C:\Users\adrien\Appdata\Local\Microsoft
O43 - CFD: 11/01/2011 - 19:02:44 - [1080099343] ----D- C:\Users\adrien\Appdata\Local\Mozilla
O43 - CFD: 19/05/2011 - 01:23:02 - [10600] ----D- C:\Users\adrien\Appdata\Local\Sidebar7
O43 - CFD: 14/01/2011 - 19:14:34 - [36741940] ----D- C:\Users\adrien\Appdata\Local\TeamSpeak 3 Client
O43 - CFD: 26/05/2011 - 23:48:22 - [108912045] ----D- C:\Users\adrien\Appdata\Local\Temp
O43 - CFD: 11/01/2011 - 18:54:00 - [0] -SH-D- C:\Users\adrien\Appdata\Local\Temporary Internet Files
O43 - CFD: 12/01/2011 - 02:51:34 - [19426] ----D- C:\Users\adrien\Appdata\Local\VirtualStore
O43 - CFD: 21/05/2011 - 17:30:54 - [28672] ----D- C:\Users\adrien\Appdata\Local\Windows Live
O43 - CFD: 11/01/2011 - 19:09:16 - [0] ----D- C:\Users\adrien\Appdata\Local\Xenocode
O43 - CFD: 14/01/2011 - 22:12:46 - [9767773] ----D- C:\Program Files (x86)\Acer
O43 - CFD: 12/05/2010 - 14:26:16 - [688367463] ----D- C:\Program Files (x86)\Adobe
O43 - CFD: 17/01/2011 - 17:29:32 - [0] ----D- C:\Program Files (x86)\Alcohol Soft
O43 - CFD: 09/03/2011 - 16:46:46 - [556132] ----D- C:\Program Files (x86)\ATI
O43 - CFD: 09/03/2011 - 16:46:48 - [54221243] ----D- C:\Program Files (x86)\ATI Stream
O43 - CFD: 09/03/2011 - 16:46:40 - [66365802] ----D- C:\Program Files (x86)\ATI Technologies
O43 - CFD: 19/01/2011 - 00:29:38 - [10006181] ----D- C:\Program Files (x86)\BRS
O43 - CFD: 24/03/2011 - 17:06:38 - [0] ----D- C:\Program Files (x86)\Citrix
O43 - CFD: 19/01/2011 - 00:21:24 - [10928441591] ----D- C:\Program Files (x86)\Codemasters
O43 - CFD: 09/03/2011 - 17:03:34 - [635059669] ----D- C:\Program Files (x86)\Common Files
O43 - CFD: 18/01/2011 - 22:13:58 - [17092840] ----D- C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD: 17/01/2011 - 17:37:50 - [8259330836] ----D- C:\Program Files (x86)\Electronic Arts
O43 - CFD: 31/01/2011 - 20:47:18 - [30797248] ----D- C:\Program Files (x86)\Garena
O43 - CFD: 14/01/2011 - 22:16:02 - [0] ----D- C:\Program Files (x86)\Google
O43 - CFD: 17/09/2010 - 09:06:02 - [5280787] ----D- C:\Program Files (x86)\Haali
O43 - CFD: 21/05/2011 - 16:20:18 - [780205526] ----D- C:\Program Files (x86)\Heroes of Newerth
O43 - CFD: 07/03/2011 - 17:42:08 - [64729553] --H-D- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 15/01/2011 - 15:52:48 - [20551633] ----D- C:\Program Files (x86)\Intel
O43 - CFD: 13/04/2011 - 19:27:32 - [4917287] ----D- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 06/04/2011 - 15:32:28 - [16714600] ----D- C:\Program Files (x86)\Lavalys
O43 - CFD: 07/03/2011 - 17:42:14 - [66783981] ----D- C:\Program Files (x86)\MagicTune Premium
O43 - CFD: 26/05/2011 - 12:10:40 - [4935589] ----D- C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 16/01/2011 - 22:19:16 - [11785929] ----D- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
O43 - CFD: 14/01/2011 - 18:58:34 - [29375744] ----D- C:\Program Files (x86)\Microsoft LifeCam
O43 - CFD: 17/09/2010 - 09:09:00 - [6423243] ----D- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 21/04/2011 - 18:36:30 - [38388859] ----D- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 17/09/2010 - 09:11:20 - [1829877] ----D- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 07/03/2011 - 17:40:58 - [5103166] ----D- C:\Program Files (x86)\MonitorDriver
O43 - CFD: 03/05/2011 - 00:28:50 - [32795377] ----D- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 14/07/2009 - 07:32:40 - [25757] ----D- C:\Program Files (x86)\MSBuild
O43 - CFD: 11/01/2011 - 20:28:48 - [0] ----D- C:\Program Files (x86)\MSXML 4.0
O43 - CFD: 12/05/2010 - 14:23:34 - [377644899] ----D- C:\Program Files (x86)\Nero
O43 - CFD: 19/01/2011 - 00:29:24 - [809560] ----D- C:\Program Files (x86)\OpenAL
O43 - CFD: 15/01/2011 - 16:01:42 - [562688] ----D- C:\Program Files (x86)\Raptr
O43 - CFD: 15/01/2011 - 15:58:20 - [16327047] ----D- C:\Program Files (x86)\Razer
O43 - CFD: 17/09/2010 - 09:00:42 - [5494426] ----D- C:\Program Files (x86)\Realtek
O43 - CFD: 17/09/2010 - 08:58:36 - [7708650] ----D- C:\Program Files (x86)\REALTEK Wireless LAN Driver
O43 - CFD: 14/07/2009 - 07:32:40 - [39159041] ----D- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 09/03/2011 - 17:03:34 - [19143029] R---D- C:\Program Files (x86)\Skype
O43 - CFD: 26/05/2011 - 23:12:40 - [1020905497] ----D- C:\Program Files (x86)\Steam
O43 - CFD: 17/09/2010 - 09:00:52 - [0] --H-D- C:\Program Files (x86)\Temp
O43 - CFD: 14/07/2009 - 06:57:08 - [0] --H-D- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 24/05/2011 - 13:40:50 - [5736788] ----D- C:\Program Files (x86)\Ventrilo
O43 - CFD: 11/01/2011 - 19:30:24 - [80532470] ----D- C:\Program Files (x86)\VideoLAN
O43 - CFD: 16/05/2011 - 00:16:26 - [1321602213] ----D- C:\Program Files (x86)\Warcraft III
O43 - CFD: 26/05/2011 - 11:52:32 - [38524021] ----D- C:\Program Files (x86)\Winamp
O43 - CFD: 26/05/2011 - 11:52:28 - [155364] ----D- C:\Program Files (x86)\Winamp Detect
O43 - CFD: 08/09/2010 - 16:47:46 - [524800] ----D- C:\Program Files (x86)\Windows Defender
O43 - CFD: 21/05/2011 - 03:52:32 - [143692232] ----D- C:\Program Files (x86)\Windows Live
O43 - CFD: 13/04/2011 - 19:23:06 - [6181376] ----D- C:\Program Files (x86)\Windows Mail
O43 - CFD: 13/04/2011 - 19:23:06 - [5024017] ----D- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - 07:32:40 - [12197556] ----D- C:\Program Files (x86)\Windows NT
O43 - CFD: 13/04/2011 - 19:23:06 - [4417800] ----D- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 13/04/2011 - 19:23:06 - [189952] ----D- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 13/04/2011 - 19:23:06 - [5994626] ----D- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 11/01/2011 - 19:11:44 - [3887186] ----D- C:\Program Files (x86)\WinRAR
O43 - CFD: 11/01/2011 - 19:09:16 - [0] ----D- C:\Program Files (x86)\Xenocode
O43 - CFD: 26/05/2011 - 23:50:22 - [3960559] ----D- C:\Program Files (x86)\ZHPDiag
O43 - CFD: 31/03/2011 - 13:21:20 - [16460255] ----D- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 12/05/2010 - 14:26:14 - [31787256] ----D- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 11/01/2011 - 22:16:10 - [197896] ----D- C:\Program Files (x86)\Common Files\ATI Technologies
O43 - CFD: 11/01/2011 - 23:25:58 - [1030875] ----D- C:\Program Files (x86)\Common Files\Blizzard Entertainment
O43 - CFD: 14/01/2011 - 21:21:06 - [2106564] ----D- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 21/05/2011 - 03:50:42 - [11063434] ----D- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 12/05/2010 - 14:24:18 - [123576475] ----D- C:\Program Files (x86)\Common Files\Nero
O43 - CFD: 12/05/2010 - 14:08:18 - [354896] ----D- C:\Program Files (x86)\Common Files\Oberon Media
O43 - CFD: 15/05/2011 - 12:29:20 - [4780336] ----D- C:\Program Files (x86)\Common Files\PX Storage Engine
O43 - CFD: 14/07/2009 - 05:20:10 - [2702] ----D- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 09/03/2011 - 17:03:34 - [2254216] ----D- C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 14/07/2009 - 05:20:10 - [41103783] ----D- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 26/05/2011 - 13:54:00 - [403240] ----D- C:\Program Files (x86)\Common Files\Steam
O43 - CFD: 08/09/2010 - 16:47:46 - [10245619] ----D- C:\Program Files (x86)\Common Files\System
O43 - CFD: 17/09/2010 - 09:09:40 - [381903066] ----D- C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD: 24/05/2011 - 13:40:32 - [7789056] ----D- C:\Program Files (x86)\Common Files\Wise Installation Wizard



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.E99F5BA909D0DB0CA8352F2A2243FB13] - 26/05/2011 - 22:42:46 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin   [512]
O44 - LFC:[MD5.10000000000000000000000054EF1800] - 26/05/2011 - 21:13:03 ---A- . (...) -- C:\Windows\WindowsUpdate.log   [1968298]
O44 - LFC:[MD5.609B6A45D7AC985FFD4095E07EEFAC61] - 26/05/2011 - 20:42:32 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0   [9920]
O44 - LFC:[MD5.609B6A45D7AC985FFD4095E07EEFAC61] - 26/05/2011 - 20:42:32 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0   [9920]
O44 - LFC:[MD5.B365A3FA489E9E19541AE449113CAFB0] - 26/05/2011 - 20:41:21 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI   [1524562]
O44 - LFC:[MD5.90635ABBE060D029E9BB4EA839EF60E5] - 26/05/2011 - 20:41:21 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat   [103370]
O44 - LFC:[MD5.AE3B79DF50BD742848C36E9028268DBE] - 26/05/2011 - 20:41:21 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat   [127478]
O44 - LFC:[MD5.557A6711D334E9EDB444E838BD9C0546] - 26/05/2011 - 20:41:21 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat   [606992]
O44 - LFC:[MD5.73E2D02657FF45ABD5BB643AF1B1BBD2] - 26/05/2011 - 20:41:21 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat   [694766]
O44 - LFC:[MD5.B41356BBA27A66A97E59498B41FA712F] - 26/05/2011 - 20:35:22 ---A- . (...) -- C:\Windows\setupact.log   [1680]
O44 - LFC:[MD5.A75574C3CCB43FD09F8AB63F9A209484] - 26/05/2011 - 20:35:21 -S-A- . (...) -- C:\Windows\bootstat.dat   [67584]
O44 - LFC:[MD5.7D2E75FF8C18C88B4131278F1EA47787] - 26/05/2011 - 12:10:10 ---A- . (...) -- C:\Windows\PFRO.log   [1112]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 24/05/2011 - 19:25:14 ---A- . (...) -- C:\Windows\setuperr.log   [0]
O44 - LFC:[MD5.8D0944E48D8F8F1FDFE9653A6E155807] - 24/05/2011 - 12:40:50 ---A- . (...) -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini   [268]



---\\ MountPoints2 Shell Key (O51)
O51 - MPSK:{e1addec2-1dc2-11e0-8fd5-4487fcf26fcd}\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- L:\LaunchU3.exe (.not file.)



---\\ Trojan Driver Search Data (HKLM) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm



---\\ ShareTools MSconfig StartupReg (O53)
O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher  [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O53 - SMSR:HKLM\...\startupreg\ArcadeMovieService  [Key] . (...) -- C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\DAEMON Tools Lite  [Key] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
O53 - SMSR:HKLM\...\startupreg\DS3 Tool  [Key] . (.www.motioninjoy.com - DS3_Tool.) -- C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe
O53 - SMSR:HKLM\...\startupreg\EgisTecPMMUpdate  [Key] . (...) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\EgisUpdate  [Key] . (...) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\LifeCam  [Key] . (.Microsoft Corporation - LifeExp.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
O53 - SMSR:HKLM\...\startupreg\MDS_Menu  [Key] . (...) -- C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exerLink\MediaShow Espresso\5.6 (.not file.)
O53 - SMSR:HKLM\...\startupreg\mwlDaemon  [Key] . (...) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\NortonOnlineBackupReminder  [Key] . (...) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\SuiteTray  [Key] . (...) -- C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\VX3000  [Key] . (.Microsoft Corporation - Microsoft LifeCam Device Application.) -- C:\Windows\vVX3000.exe
O53 - SMSR:HKLM\...\startupreg\WinampAgent  [Key] . (.Nullsoft, Inc. - Winamp Agent.) -- C:\Program Files (x86)\Winamp\winampa.exe



---\\ Microsoft Control Security Providers (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll



---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0



---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0



---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys   [491088]
O58 - SDL:[MD5.597F78224EE9224EA1A13D6350CED962] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys   [339536]
O58 - SDL:[MD5.E109549C90F62FB570B9540C4B148E54] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\system32\drivers\adpu320.sys   [182864]
O58 - SDL:[MD5.5812713A477A3AD7363C7438CA2EE038] - 14/07/2009 - 02:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys   [15440]
O58 - SDL:[MD5.6EC6D772EAE38DC17C14AED9B178D24B] - 20/11/2010 - 14:32:46 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\system32\drivers\amdsata.sys   [107904]
O58 - SDL:[MD5.F67F933E79241ED32FF46A4F29B5120B] - 14/07/2009 - 02:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\system32\drivers\amdsbs.sys   [194128]
O58 - SDL:[MD5.1142A21DB581A84EA5597B03A26EBAA0] - 20/11/2010 - 14:32:47 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\system32\drivers\amdxata.sys   [27008]
O58 - SDL:[MD5.C484F8CEB1717C540242531DB7845C4E] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys   [87632]
O58 - SDL:[MD5.019AF6924AEFE7839F61C830227FE79C] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys   [97856]
O58 - SDL:[MD5.FB7602C5C508BE281368AAE0B61B51C6] - 30/09/2009 - 02:34:30 ---A- . (.ATI Technologies, Inc. - ATI High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\AtiHdmi.sys   [121872]
O58 - SDL:[MD5.4BF5BCA6E2608CD8A00BC4A6673A9F47] - 17/11/2010 - 13:04:32 ---A- . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\AtihdW76.sys   [115216]
O58 - SDL:[MD5.DCC8177244FE79C61C4E73C65E63922A] - 27/01/2011 - 00:37:20 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\system32\drivers\atikmdag.sys   [9085952]
O58 - SDL:[MD5.7FE67D107329DC2CF89136A8E19BCEB7] - 27/01/2011 - 23:13:32 ---A- . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\system32\drivers\atikmpag.sys   [299520]
O58 - SDL:[MD5.9673319070166E26660EBA4EDF316FA2] - 13/01/2010 - 15:26:00 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\system32\drivers\atipmdag.sys   [6327296]
O58 - SDL:[MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - 10/06/2009 - 21:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\system32\drivers\b57nd60a.sys   [270848]
O58 - SDL:[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - 10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys   [18432]
O58 - SDL:[MD5.B114D3098E9BDB8BEA8B053685831BE6] - 10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys   [8704]
O58 - SDL:[MD5.43BEA8D483BF1870F018E2D02E06A5BD] - 14/07/2009 - 02:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys   [286720]
O58 - SDL:[MD5.A6ECA2151B08A09CACECA35C07F05B42] - 10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys   [47104]
O58 - SDL:[MD5.B79968002C277E869CF38BD22CD61524] - 10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys   [14976]
O58 - SDL:[MD5.A87528880231C54E75EA7A44943B38BF] - 10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys   [14720]
O58 - SDL:[MD5.3E5B191307609F7514148C6832BB0842] - 10/06/2009 - 21:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\system32\drivers\bxvbda.sys   [468480]
O58 - SDL:[MD5.E19D3F095812725D88F9001985B94EDD] - 14/07/2009 - 02:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys   [17488]
O58 - SDL:[MD5.55851F4864F8AD6E98B02307ECA29DB4] - 14/05/2009 - 15:41:14 ---A- . (.ESET - Amon monitor.) -- C:\Windows\system32\drivers\eamon.sys   [142776]
O58 - SDL:[MD5.62C96B617AC7C4C8A9C29D57A36AA874] - 14/05/2009 - 15:47:16 ---A- . (.ESET - ESET Helper driver.) -- C:\Windows\system32\drivers\ehdrv.sys   [134024]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys   [530496]
O58 - SDL:[MD5.9C4476159CCDEF1A9B3F91DC580F1C46] - 14/05/2009 - 15:49:48 ---A- . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\system32\drivers\epfw.sys   [165960]
O58 - SDL:[MD5.34F666BF6387210034E4BCC5BE6A3E45] - 14/05/2009 - 15:49:50 ---A- . (.ESET - ESET Personal Firewall NDIS filter.) -- C:\Windows\system32\drivers\epfwndis.sys   [33608]
O58 - SDL:[MD5.BF2CB1EFB98A888D6F676683CD48936F] - 14/05/2009 - 15:49:54 ---A- . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\system32\drivers\epfwwfp.sys   [44944]
O58 - SDL:[MD5.DC5D737F51BE844D8C82C695EB17372F] - 10/06/2009 - 21:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\system32\drivers\evbda.sys   [3286016]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\system32\drivers\hcw85cir.sys   [31232]
O58 - SDL:[MD5.39D2ABCD392F3D8A6DCE7B60AE7B8EFC] - 20/11/2010 - 14:33:35 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\system32\drivers\HpSAMD.sys   [78720]
O58 - SDL:[MD5.D7921D5A870B11CC1ADAB198A519D50A] - 06/11/2010 - 23:45:48 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\Windows\system32\drivers\iaStor.sys   [438808]
O58 - SDL:[MD5.3DF4395A7CF8B7A72A5F4606366B8C2D] - 20/11/2010 - 14:33:38 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\system32\drivers\iaStorV.sys   [410496]
O58 - SDL:[MD5.5C18831C61933628F5BB0EA2675B9D21] - 14/07/2009 - 02:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys   [44112]
O58 - SDL:[MD5.18436F7006443FB76145B3D35162A810] - 16/10/2009 - 21:09:14 ---A- . (.Razer (Asia-Pacific) Pte Ltd - Lachesis USB Optical Mouse Driver.) -- C:\Windows\system32\drivers\Lachesis.sys   [29952]
O58 - SDL:[MD5.1A93E54EB0ECE102495A51266DCDB6A6] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys   [114752]
O58 - SDL:[MD5.1047184A9FDC8BDBFF857175875EE810] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys   [106560]
O58 - SDL:[MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas2.sys   [65600]
O58 - SDL:[MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys   [115776]
O58 - SDL:[MD5.3D3C4B63F11F63F50253E734F0ACE9F2] - 20/12/2010 - 17:08:40 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbam.sys   [24152]
O58 - SDL:[MD5.A55805F747C6EDB6A9080D7C633BD0F4] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\system32\drivers\megasas.sys   [35392]
O58 - SDL:[MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys   [284736]
O58 - SDL:[MD5.16F9F464DA6E02A020BCE626C56A1797] - 21/10/2010 - 15:11:04 ---A- . (.MotioninJoy - MotioninJoy DS3 driver.) -- C:\Windows\system32\drivers\MijXfilt.sys   [97552]
O58 - SDL:[MD5.6FFECC25B39DC7652A0CEC0ADA9DB589] - 03/06/2009 - 03:15:30 ---A- . (.Egis Technology Inc. - PSD Filter Driver.) -- C:\Windows\system32\drivers\mwlPSDFilter.sys   [22576]
O58 - SDL:[MD5.0BEFE32CA56D6EE89D58175725596A85] - 03/06/2009 - 03:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Named Pipe Driver.) -- C:\Windows\system32\drivers\mwlPSDNserv.sys   [20016]
O58 - SDL:[MD5.D43BC633B8660463E446E28E14A51262] - 03/06/2009 - 03:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Virtual Disk Driver.) -- C:\Windows\system32\drivers\mwlPSDVDisk.sys   [60464]
O58 - SDL:[MD5.77889813BE4D166CDAB78DDBA990DA92] - 14/07/2009 - 02:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys   [51264]
O58 - SDL:[MD5.5D9FD91F3D38DC9DA01E3CB5FA89CD48] - 20/11/2010 - 14:33:48 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys   [148352]
O58 - SDL:[MD5.F7CD50FE7139F07E77DA8AC8033D1832] - 20/11/2010 - 14:33:48 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys   [166272]
O58 - SDL:[MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - 14/07/2009 - 02:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys   [1524816]
O58 - SDL:[MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - 14/07/2009 - 02:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys   [128592]
O58 - SDL:[MD5.7EA8D2EB9BBFD2AB8A3117A1E96D3B3A] - 04/03/2010 - 14:43:00 ---A- . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver.) -- C:\Windows\system32\drivers\Rt64win7.sys   [346144]
O58 - SDL:[MD5.DCF6AFBA140AF3F880A427C2656BE44D] - 24/02/2010 - 12:25:08 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\RTKVHD64.sys   [2217504]
O58 - SDL:[MD5.20B6F5D595FBB4C15AD4815187AC4A82] - 03/07/2009 - 05:06:38 ---A- . (.Realtek Semiconductor Corporation - Realtek RTL819xP NDIS Driverr.) -- C:\Windows\system32\drivers\rtl819xp.sys   [607232]
O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 10/06/2009 - 21:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys   [23040]
O58 - SDL:[MD5.C1D8E28B2C2ADFAEC4BA89E9FDA69BD6] - 14/07/2009 - 01:00:40 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\serial.sys   [94208]
O58 - SDL:[MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - 14/07/2009 - 02:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys   [43584]
O58 - SDL:[MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - 14/07/2009 - 02:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys   [80464]
O58 - SDL:[MD5.08000000000000000000000054EF1800] - 18/01/2011 - 00:00:00 ---A- . (...) -- C:\Windows\system32\drivers\sptd.sys   [513080]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise  SuperTrak EX Series Driver for Windows.) -- C:\Windows\system32\drivers\stexstor.sys   [24656]
O58 - SDL:[MD5.B1D1FE35303E3AEE6D5AF69F09F12E87] - 24/08/2010 - 09:45:08 ---A- . (.Motorola - UsbIsp.) -- C:\Windows\system32\drivers\usbicp.sys   [20480]
O58 - SDL:[MD5.E5689D93FFE4E5D66C0178761240DD54] - 14/07/2009 - 02:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys   [17488]
O58 - SDL:[MD5.5E2016EA6EBACA03C04FEAC5F330D997] - 14/07/2009 - 02:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys   [161872]
O58 - SDL:[MD5.D68E165C3123ABA3B1282EDDB4213BD8] - 20/12/2010 - 17:09:00 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\SysWOW64\drivers\mbamswissarmy.sys   [38224]
O58 - SDL:[MD5.F650EAD361BCAD08D544DB5BBE7E8F35] - 04/06/2009 - 13:53:04 ---A- . (.Samsung Electronics, Inc. - MagicTunePremium Driver.) -- C:\Windows\SysWOW64\drivers\MTiCtwl.sys   [14080]



---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: HijackThis 2.0.2 - (.TrendMicro.) [HKLM][64Bits] -- HijackThis
O63 - Logiciel: ZHPDiag 1.27 - (.Nicolas Coolman.) [HKLM][64Bits] -- ZHPDiag_is1



---\\ Liste des services Legacy (O64)
O64 - Services: CurCS - 30/12/1899 - C:\Windows\System32\DRIVERS\atikmdag.sys - amdkmdag(amdkmdag)  .(.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) - LEGACY_AMDKMDAG
O64 - Services: CurCS - C:\Windows\system32\Drivers\BEEP.sys - (.not file.) - Beep (Beep)  .(...) - LEGACY_BEEP
O64 - Services: CurCS - (.not file.) - McAfee Inc. cfwids (cfwids)  .(...) - LEGACY_CFWIDS
O64 - Services: CurCS - 30/12/1899 - C:\Windows\System32\DRIVERS\eamon.sys - eamon(eamon)  .(.ESET - Amon monitor.) - LEGACY_EAMON
O64 - Services: CurCS - 30/12/1899 - C:\Windows\System32\DRIVERS\ehdrv.sys - ehdrv(ehdrv)  .(.ESET - ESET Helper driver.) - LEGACY_EHDRV
O64 - Services: CurCS - 30/12/1899 - C:\Windows\System32\DRIVERS\epfw.sys - epfw(epfw)  .(.ESET - ESET Personal Firewall driver.) - LEGACY_EPFW
O64 - Services: CurCS - 30/12/1899 - C:\Windows\System32\DRIVERS\epfwwfp.sys - epfwwfp(epfwwfp)  .(.ESET - ESET Personal Firewall driver.) - LEGACY_EPFWWFP
O64 - Services: CurCS - (.not file.) - epfwwfpr (epfwwfpr)  .(...) - LEGACY_EPFWWFPR
O64 - Services: CurCS - C:\Windows\system32\Drivers\FASTFAT.sys - (.not file.) - FAT12/16/32 File System Driver (fastfat)  .(...) - LEGACY_FASTFAT
O64 - Services: CurCS - C:\Windows\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec)  .(...) - LEGACY_FS_REC
O64 - Services: CurCS - C:\Program Files (x86)\Garena\safedrv.sys (.not file.) - GGSAFER Driver (GGSAFERDriver)  .(...) - LEGACY_GGSAFERDRIVER
O64 - Services: CurCS - (.not file.) - McAfee Inc. mfeapfk (mfeapfk)  .(...) - LEGACY_MFEAPFK
O64 - Services: CurCS - (.not file.) - McAfee Inc. mfeavfk (mfeavfk)  .(...) - LEGACY_MFEAVFK
O64 - Services: CurCS - (.not file.) - McAfee Inc. (mfeavfk01)  .(...) - LEGACY_MFEAVFK01
O64 - Services: CurCS - (.not file.) - McAfee Inc. mfefirek (mfefirek)  .(...) - LEGACY_MFEFIREK
O64 - Services: CurCS - (.not file.) - McAfee Inc. mfehidk (mfehidk)  .(...) - LEGACY_MFEHIDK
O64 - Services: CurCS - (.not file.) - McAfee Inc. mfewfpk (mfewfpk)  .(...) - LEGACY_MFEWFPK
O64 - Services: CurCS - C:\Windows\system32\Drivers\MSFS.sys - Msfs (Msfs)  .(...) - LEGACY_MSFS
O64 - Services: CurCS - C:\Windows\system32\Drivers\MWLPSDFILTER.sys - mwlPSDFilter (mwlPSDFilter)  .(...) - LEGACY_MWLPSDFILTER
O64 - Services: CurCS - C:\Windows\system32\Drivers\MWLPSDNSERV.sys - mwlPSDNServ (mwlPSDNServ)  .(...) - LEGACY_MWLPSDNSERV
O64 - Services: CurCS - C:\Windows\system32\Drivers\MWLPSDVDISK.sys - mwlPSDVDisk (mwlPSDVDisk)  .(...) - LEGACY_MWLPSDVDISK
O64 - Services: CurCS - C:\Windows\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy)  .(...) - LEGACY_NDPROXY
O64 - Services: CurCS - C:\Windows\system32\Drivers\NPFS.sys - Npfs (Npfs)  .(...) - LEGACY_NPFS
O64 - Services: CurCS - C:\Windows\system32\Drivers\NTFS.sys - Ntfs (Ntfs)  .(...) - LEGACY_NTFS
O64 - Services: CurCS - C:\Windows\system32\Drivers\NULL.sys - Null (Null)  .(...) - LEGACY_NULL
O64 - Services: CurCS - (.not file.) - SCDEmu (SCDEmu)  .(...) - LEGACY_SCDEMU
O64 - Services: CurCS - C:\Windows\system32\Drivers\SECDRV.sys - (.not file.) - Security Driver (secdrv)  .(...) - LEGACY_SECDRV
O64 - Services: CurCS - C:\Windows\system32\Drivers\SPLDR.sys - (.not file.) - Security Processor Loader Driver (spldr)  .(...) - LEGACY_SPLDR
O64 - Services: CurCS - C:\Windows\system32\Drivers\sptd.sys - sptd (sptd)  .(...) - LEGACY_SPTD



---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <ChromeHTML>[HKLM\..\open\Command] (.Not Key.)
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe



---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe



---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {67A2568C-7A0A-4EED-AECC-B5405DE63B64} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com



---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\spoolsv.exe (.not file.)
O87 - FAEL: "FPS-SpoolSvc-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\spoolsv.exe (.not file.)
O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" |Out - Domain - P6 - TRUE | .(...) -- C:\Windows\system32\lsass.exe (.not file.)
O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\services.exe (.not file.)
O87 - FAEL: "RemoteSvcAdmin-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\services.exe (.not file.)
O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "TCP Query User{7EB7837D-DB3F-4F85-88CA-8072E918B0DB}C:\program files (x86)\winamp\winamp.exe" | In - Public - P6 - TRUE | .(.Nullsoft, Inc. - Winamp.) -- C:\program files (x86)\winamp\winamp.exe
O87 - FAEL: "UDP Query User{ECEC03D7-C782-4572-AF4F-4838CEC21A10}C:\program files (x86)\winamp\winamp.exe" | In - Public - P17 - TRUE | .(.Nullsoft, Inc. - Winamp.) -- C:\program files (x86)\winamp\winamp.exe
O87 - FAEL: "{61169303-BF8C-4885-B0D5-350B3B21099A}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O87 - FAEL: "TCP Query User{8B5FA058-2899-4B05-8985-6769A6FE6DE4}C:\program files (x86)\warcraft iii\war3.exe" | In - Public - P6 - TRUE | .(.Blizzard Entertainment - Warcraft III.) -- C:\program files (x86)\warcraft iii\war3.exe
O87 - FAEL: "UDP Query User{B1193B64-A714-4A0C-9D2F-DA186B957317}C:\program files (x86)\warcraft iii\war3.exe" | In - Public - P17 - TRUE | .(.Blizzard Entertainment - Warcraft III.) -- C:\program files (x86)\warcraft iii\war3.exe
O87 - FAEL: "{E75170EE-B2F8-492B-A102-415D6BF31F3B}" | In - Public - P6 - TRUE | .(.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\Steam.exe
O87 - FAEL: "{9B6B82D3-1C12-4677-9828-4395F959FCA5}" | In - Public - P17 - TRUE | .(.Valve Corporation - Steam.) -- C:\Program Files (x86)\Steam\Steam.exe
O87 - FAEL: "{26E0638C-BB74-49F7-8805-4ADFBC79CCBA}" | In - Public - P6 - TRUE | .(.Microsoft Corporation - LifeCam.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
O87 - FAEL: "{41E89724-64A4-4A35-AAFE-3883D252DD78}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - LifeCam.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
O87 - FAEL: "{43147582-87DC-4AA6-A8CC-218951CC15B1}" | In - Public - P6 - TRUE | .(.Microsoft Corporation - LifeEnC2.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
O87 - FAEL: "{B331466A-9FAD-419C-9305-3CDF35EA5D40}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - LifeEnC2.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
O87 - FAEL: "{E81D94BA-1FE0-4D17-9960-21C0A9D4BFEB}" | In - Public - P6 - TRUE | .(.Microsoft Corporation - LifeExp.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
O87 - FAEL: "{2F35A1BC-EDB6-42F1-9419-CE739E5035D8}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - LifeExp.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
O87 - FAEL: "{F8309D85-B41E-4AD1-9946-7302F2C91E18}" | In - Public - P6 - TRUE | .(.Microsoft Corporation - LifeTray.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
O87 - FAEL: "{C5B1BBE7-6D25-4CA5-B551-1AA2DD3A329F}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - LifeTray.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
O87 - FAEL: "{0618900E-8E25-4176-874E-F514F11FB1EE}" | In - Public - P6 - TRUE | .(.Flagship Industries, Inc. - Ventrilo Client Program.) -- C:\Program Files\Ventrilo\Ventrilo.exe
O87 - FAEL: "{FDD86332-846D-4D9C-8BFA-A16A446DB2E4}" | In - Public - P17 - TRUE | .(.Flagship Industries, Inc. - Ventrilo Client Program.) -- C:\Program Files\Ventrilo\Ventrilo.exe
O87 - FAEL: "{5E39F95D-D244-4CE8-AA84-31D510FD67AB}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\Raptr\raptr.exe (.not file.)
O87 - FAEL: "{F06F9E40-7EA1-4332-89E7-B2F19133A570}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files (x86)\Raptr\raptr.exe (.not file.)
O87 - FAEL: "{4AAE37E4-BD74-4465-AF14-3BF75DAD5DB7}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\Raptr\raptr_im.exe (.not file.)
O87 - FAEL: "{AE8ABC17-7A7E-4E61-9678-04D964FC4729}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files (x86)\Raptr\raptr_im.exe (.not file.)
O87 - FAEL: "{BD895666-80F4-4F2D-9C26-ACC2D2B98875}" | In - Public - P6 - TRUE | .(.Electronic Arts - Need for Speed(TM) Hot Pursuit Launcher.) -- C:\Program Files (x86)\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe
O87 - FAEL: "{D55C53A7-2A76-4D0B-9A10-F221384B2C2B}" | In - Public - P17 - TRUE | .(.Electronic Arts - Need for Speed(TM) Hot Pursuit Launcher.) -- C:\Program Files (x86)\Electronic Arts\Need for Speed(TM) Hot Pursuit\Launcher.exe
O87 - FAEL: "{0D5F4FDD-76B2-40F0-B9B9-563B939468AA}" | In - Public - P6 - TRUE | .(.Codemasters - DiRT2 Executable.) -- C:\Program Files (x86)\Codemasters\DiRT2\dirt2_game.exe
O87 - FAEL: "{D7CD73E7-B86B-4FCF-A417-2AFCABC4290A}" | In - Public - P17 - TRUE | .(.Codemasters - DiRT2 Executable.) -- C:\Program Files (x86)\Codemasters\DiRT2\dirt2_game.exe
O87 - FAEL: "{1A99B967-55D2-4C52-A266-CBED49FE9D85}" | In - Public - P6 - TRUE | .(.S2 Games - Heroes of Newerth.) -- C:\Program Files (x86)\Heroes of Newerth\hon.exe
O87 - FAEL: "{095A02E6-A376-4261-B41F-A243896449EE}" | In - Public - P17 - TRUE | .(.S2 Games - Heroes of Newerth.) -- C:\Program Files (x86)\Heroes of Newerth\hon.exe
O87 - FAEL: "{F2C7467C-C1C0-4DDE-801C-D7BEAD9D4EE9}" | In - Domain - P6 - FALSE | .(.S2 Games - Heroes of Newerth.) -- C:\Program Files (x86)\Heroes of Newerth\hon.exe
O87 - FAEL: "{6CC31CA1-C4A2-43E2-936A-BFF939F583BE}" | In - Domain - P17 - FALSE | .(.S2 Games - Heroes of Newerth.) -- C:\Program Files (x86)\Heroes of Newerth\hon.exe
O87 - FAEL: "{EDA9874D-01E8-4DE6-AB64-7138E2BEF01A}" | In - Domain - P17 - TRUE | .(.Skype Technologies - Skype Extras Manager.) -- C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
O87 - FAEL: "{B40D39AE-7BDC-4E5B-A966-FEEA43C5C2D2}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files\ma-config.com\x64\maconfservice.exe (.not file.)
O87 - FAEL: "{8E5D8C76-CB70-483B-A37B-7CC23FC4A05E}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files\ma-config.com\x64\maconfservice.exe (.not file.)
O87 - FAEL: "{4F65C9F4-EA7A-4874-BCF3-AE002A264984}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O87 - FAEL: "{A705C166-7689-4403-B65E-2C72202A0F6F}" | In - Public - P6 - TRUE | .(.Flagship Industries, Inc. - Ventrilo Client Program.) -- C:\Program Files (x86)\Ventrilo\Ventrilo.exe
O87 - FAEL: "{3D09FB38-40C4-40D6-9BDB-7FBD2B843134}" | In - Public - P17 - TRUE | .(.Flagship Industries, Inc. - Ventrilo Client Program.) -- C:\Program Files (x86)\Ventrilo\Ventrilo.exe
O87 - FAEL: "{4916F2CE-F0C3-4413-A47A-3B95BFE552DB}" | In - Public - P6 - TRUE | .(.Valve - Half-Life Launcher.) -- C:\Program Files (x86)\Steam\steamapps\squallss\counter-strike\hl.exe
O87 - FAEL: "{F0DAD5FF-1240-416F-AB2B-2D2303CD3858}" | In - Public - P17 - TRUE | .(.Valve - Half-Life Launcher.) -- C:\Program Files (x86)\Steam\steamapps\squallss\counter-strike\hl.exe



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto  0 |  (AMD External Events Utility) . (.AMD.) - C:\Windows\system32\atiesrxx.exe
SS - | Demand 14/05/2009 23296 |  (EhttpSrv) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
SR - | Auto 14/05/2009 731840 |  (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
SR - | Auto 06/11/2010 13336 |  (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
SR - | Auto 23/08/2007 45056 |  (MagicTuneEngine) . (...) - C:\Program Files (x86)\MagicTune Premium\MagicTuneEngine.exe
SS - | Demand 15/01/2010 935208 | Nero BackItUp Scheduler 4.0 (Nero BackItUp Scheduler 4.0) . (.Nero AG.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
SR - | Demand 13/05/2011 403240 |  (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
SS - | Demand 09/12/2009 76320 |  (USBS3S4Detection) . (...) - C:\OEM\USBDECTION\USBS3S4Detection.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe



---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by adrien at 26/05/2011 23:50:38

device: opened successfully
user: error reading MBR

Disk trace:
error: Read  Descripteur non valide
kernel: error reading MBR



---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by adrien at 26/05/2011 23:50:40

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin



---\\ Liste des émulateurs de CD/DVD (Hook du MBR)
O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite
O58 - SDL:[MD5.08000000000000000000000054EF1800] - 18/01/2011 - 00:00:00 ---A- . (...) -- C:\Windows\system32\drivers\sptd.sys   [513080]



End of the scan (1020 lines in 00mn 22s)(0)

Il ne ma rien trouvé je penses
Squall
 
Messages: 7
Inscription: Jeu 26 Mai 2011 20:24

Re: Virus potentiel non detecté

Messagepar nardino » Ven 27 Mai 2011 09:40

Bonjour
Héberge le rapport ZHPDiag.txt sur Cjoint et poste le lien
Tutoriel Cjoint
@+
Image
En cas de problème constaté sur un sujet, contactez un modérateur par MP. N'intervenez pas vous-même. Merci
Avatar de l’utilisateur
nardino
 
Messages: 6344
Inscription: Dim 11 Jan 2009 16:03
Localisation: Reims

Suivante

Retourner vers Désinfection

Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 0 invités

Livre photo