Dimanche 16 Février 2025
Trojan TR/Hiloti.A

Un ordinateur qui ralentit, des écrans publicitaires qui apparaissent, des applications qui refusent de démarrer ou encore votre navigateur qui s'obstine à ouvrir une page douteuse sont autant d'éléments qui indiquent que l'intégrité de votre ordinateur est menacée par un virus. Vous trouverez dans ce forum quelques conseils et logiciels pour surfer tranquillement.
Trojan TR/Hiloti.A

Message le 19 Fév 2011 11:45

Bonjour ,

J'ai un petit probleme avec ce cheval de trojan TR/Hiloti.A .
Avira antivir n'arrête pas de me demander que faire j'ai donc mis bloquer .

Et depuis toute les 10 seconde ce message d'erreur apparait .

Comment supprimer le tojan ou eviter que mon pc affiche un message d'erreur toutes les 10 secondes .

merci de votre aide
Apprenti(e) Expert(e)
Apprenti(e) Expert(e)
Messages: 126
Inscription: 15 Jan 2011 20:42

Re: Trojan TR/Hiloti.A

Message le 19 Fév 2011 12:20

Hello Nous allons regarder sa ;)

Fais ceci stp ...

Image Télécharge ZHPDiag par Nicolas Coolman et sauvegarde-le sur le Bureau.

* Double-clique sur ZHPDiag.exe.
* clique sur le bouton Lancer le diagnostic
* Lorsque l'analyse sera terminée, un fichier au format texte s'affiche dans la zone résultat du bas.
* Clique sur le bouton Copier dans le presse papier
* Colle le résultat de l'analyse dans ta réponse en faisant un copier/coller.

Image -Si le rapport est trop long tu peut l'heberger >>>ici<<<

@ ++
Avatar de l'utilisateur
Messages: 1833
Inscription: 08 Juin 2009 06:46
Localisation: Nord-(59)

Message le 19 Fév 2011 16:20

Code: Tout sélectionner
Contact :

---\\ Web Browser
MSIE: Internet Explorer v8.0.7600.16385
GCIE: Google Chrome v9.0.597.98

---\\ System Information
Windows 7 Ultimate Edition, 64-bit  (Build 7600)
Processor: Intel64 Family 6 Model 30 Stepping 5, GenuineIntel
Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2039 MB (49% free)
System Restore: Activé (Enable)
System drive C: has 417 GB (88%) free of 470 GB

---\\ Logged in mode
Computer Name: SON-PC
User Name: Son
All Users Names: Son, HomeGroupUser$, Guest, Administrator,
Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator

---\\ Environnement Variables
%StartMenu%=C:\Users\Son\AppData\Roaming\Microsoft\Windows\Start Menu

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 417 Go of 470 Go)
D:\ CD-ROM drive (Free 0 Go of 1 Go)
E:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
F:\ Hard drive, Flash drive, Thumb drive (Free 173 Go of 462 Go)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
I:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
J:\ CD-ROM drive (Not Inserted)
K:\ CD-ROM drive (Not Inserted)
L:\ Hard drive, Flash drive, Thumb drive (Free 369 Go of 466 Go)

---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK

---\\ Search Generic System Files
[MD5.9AAAEC8DAC27AA17B053E6352AD233AE] - (.Microsoft Corporation - Explorateur Windows.) (.31/10/2009 07:34:59.) -- C:\Windows\Explorer.exe [2870272]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]

---\\ Running Processes
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - (.Unknown owner - No comment.) -- C:\Windows\SysWOW64\rundll32.exe   [44544]
[MD5.9DFEDA54BFFC1D6AE84279CC24E27574] - (.Unknown owner - WlanCU MFC Application.) -- C:\Program Files\TRENDnet\TEW-623PI\WlanCU.exe   [499712]
[MD5.407811B64B588FE80FA2E27E783B41EA] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe   [421160]
[MD5.BAD6BEA0DE1F69C82BDB74378CE0C20A] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe   [932288]
[MD5.29680A793F690EEF4AAA68479D2A6DF8] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe   [209153]
[MD5.E49D562B17CBB3E9C1EB95D180763023] - (.ManyCam LLC - ManyCam Application.) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe   [1713448]
[MD5.DE93885641D5C4F7EA7563A08137B218] - (.Adobe Systems Incorporated - AAM Updates Notifier Application.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe   [311760]
[MD5.C3F6AF1D18ADF78E8735D9D3B0D8D7ED] - (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre6\bin\javaw.exe   [145184]
[MD5.0E20A3213ED010FC4997D1EF48082ABC] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe   [912344]
[MD5.8EDAC4D2659E1F525D432D991BF97C53] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe   [630784]

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.dll
P2 - FPN: [HKCU] [ Update;version=8] - (.Google Inc. - Google Update.) -- C:\Users\Son\AppData\Local\Google\Update\\npGoogleOneClick8.dll
M2 - MFEP: prefs.js [Son - jd7e39ai.default\] [foxdie] Foxdie v3.6.4 (.John Locke.)
M2 - MFEP: prefs.js [Son - jd7e39ai.default\] [foxdie] Foxdie for Firefox v3.6.4 (.John Locke.)
M2 - MFEP: prefs.js [Son - jd7e39ai.default\{b1d89840-39fe-11db-a98b-0800200c9a66}] [] JeuxVideo.Fox v0.51 (.Anonymous59.)

---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2)
G1 - GCS: Preference [User Data\Default] None
G0 - GCSP: Preference [User Data\Default][HomePage]

---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKUS\S-1-5-21-3288069001-1371707216-755054012-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R1 - HKUS\S-1-5-21-3288069001-1371707216-755054012-1001\Software\Microsoft\Internet Explorer\Main,Search Page =
R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\System32\ieframe.dll
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1

---\\ Changed inifile Value, Mapped to Registry (F2)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe

---\\ Browser Helper Objects (O2)
O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL

---\\ Auto loading programs from Registry and folders (O4)
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Son\AppData\Local\Google\Update\GoogleUpdate.exe
O4 - HKCU\..\Run: [Bhanagecagu] . (.Greatis Software - RunGuard file checker.) -- C:\Users\Son\AppData\Local\minroms.dll
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Wow6432Node\Run: [SwitchBoard] . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Wow6432Node\Run: [AdobeCS5ServiceManager] . (.Adobe Systems Incorporated - Adobe CS5 Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-21-3288069001-1371707216-755054012-1001\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKUS\S-1-5-21-3288069001-1371707216-755054012-1001\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Son\AppData\Local\Google\Update\GoogleUpdate.exe
O4 - HKUS\S-1-5-21-3288069001-1371707216-755054012-1001\..\Run: [Bhanagecagu] . (.Greatis Software - RunGuard file checker.) -- C:\Users\Son\AppData\Local\minroms.dll
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)
O4 - Global Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wireless Configuration Utility.lnk . (...)  -- C:\Program Files\TRENDnet\TEW-623PI\WlanCU.exe

---\\ Other User Links (O4)
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk . (.Microsoft Corporation.)  -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.)  -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\Son\Desktop\Adobe Photoshop CS5.lnk . (...)  -- C:\Program Files (x86)\Adobe\Adobe Photoshop CS5 (64 Bit)\Photoshop.exe (.not file.)
O4 - Global Startup: C:\Users\Son\Desktop\iSkysoft SyncPod.lnk . (...)  -- C:\Program Files (x86)\iSkysoft\SyncPod\SyncPod.exe
O4 - Global Startup: C:\Users\Son\Desktop\JDownloader.lnk . (.AppWork UG (haftungsbeschränkt).)  -- C:\Program Files (x86)\JDownloader\JDownloader.exe
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.)  -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.)  -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - Orphean Key
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VDownloader.lnk . (.Vitzo.)  -- C:\Program Files (x86)\VDownloader\VDownloader.exe
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - Orphean Key
O4 - Global Startup: C:\Users\Son\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk . (.BitTorrent, Inc..)  -- C:\Program Files (x86)\uTorrent\uTorrent.exe

---\\ Extra items in the IE right-click menu (O8)
O8 - Extra context menu item: &Envoyer à OneNote . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Excel.) -- C:\PROGRA~1\MICROS~2\Office14\EXCEL.exe

---\\ Extra buttons on main IE button toolbar, or extra items in IE 'Tools' menu (O9)
O9 - Extra button: &Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll
O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\PROGRA~1\MICROS~2\Office14\ONBTTN~1.dll

---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
O10 - WLSP:\000000000009\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll

---\\ Hijackers (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A14864FD-E327-4EE2-AE12-7706815810D2}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\..\{D2A67D26-C521-4C9E-9718-C0D4FD470457}: DhcpNameServer =
O17 - HKLM\System\CS1\Services\Tcpip\..\{A14864FD-E327-4EE2-AE12-7706815810D2}: DhcpNameServer =
O17 - HKLM\System\CS1\Services\Tcpip\..\{D2A67D26-C521-4C9E-9718-C0D4FD470457}: DhcpNameServer =
O17 - HKLM\System\CS2\Services\Tcpip\..\{A14864FD-E327-4EE2-AE12-7706815810D2}: DhcpNameServer =
O17 - HKLM\System\CS2\Services\Tcpip\..\{D2A67D26-C521-4C9E-9718-C0D4FD470457}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =

---\\ ShellServiceObjectDelayLoad (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

---\\ non Microsoft non disabled Windows XP/NT/2000 Services (O23)
O23 - Service: C:\Windows\system32\Alg.exe (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\system32\atiesrxx.exe
O23 - Service:  (AntiVirMailService) . (.Avira GmbH - Antivirus MailScanner Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service:  (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service:  (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service:  (AntiVirWebService) . (.Avira GmbH - AntiVir WebGuard Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.exe
O23 - Service:  (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service:  (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service:  (iPod Service) . (.Apple Inc. - iPodService Module (64-bit).) - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service:  (KMService) . (.Unknown owner - No comment.) - C:\Windows\system32\srvany.exe
O23 - Service:  (Microsoft SharePoint Workspace Audit Service) - Orphean Key
O23 - Service:  (SwitchBoard) . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service:  (wlidsvc) . (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.exe
O23 - Service:  (X6va003) . (.Unknown owner - No comment.) - C:\Users\Son\AppData\Local\Temp\003A2A4.tmp

---\\ Windows Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(.Unknown owner - No comment.) -  (.not file.)

---\\ Task Planned Automatically(039)
O39 - APT:Automatic Planified Task  - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3288069001-1371707216-755054012-1001Core.job
O39 - APT:Automatic Planified Task  - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3288069001-1371707216-755054012-1001UA.job
[MD5.BB7481A1306823D1B6592263F1AB8DD7] [APT] [AdobeAAMUpdater-1.0-Son-PC-Son] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskUserS-1-5-21-3288069001-1371707216-755054012-1001Core] (.Google Inc..) -- C:\Users\Son\AppData\Local\Google\Update\GoogleUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskUserS-1-5-21-3288069001-1371707216-755054012-1001UA] (.Google Inc..) -- C:\Users\Son\AppData\Local\Google\Update\GoogleUpdate.exe

---\\ Drivers launched at startup (O41)
O41 - Driver: C:\Windows\system32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver:  (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\system32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys
O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\system32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver:  (dtsoftbus01) . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) - C:\Windows\System32\DRIVERS\dtsoftbus01.sys
O41 - Driver:  (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys
O41 - Driver:  (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\system32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\system32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\system32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver:  (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver:  (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver:  (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\system32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver:  (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
O41 - Driver: Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0 (ws2ifsl) . (.Microsoft Corporation - Couche IFS Winsock2.) - C:\Windows\system32\drivers\ws2ifsl.sys

---\\ Software installed (O42)
O42 - Logiciel: 7-Zip 9.20 - (.Unknown owner.) [HKLM][64Bits] -- 7-Zip
O42 - Logiciel: ATI AVIVO64 Codecs - (.ATI Technologies Inc..) [HKLM] -- {19BDBFE9-0B6A-37F2-80F6-48AFD1EA582D}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- Adobe AIR
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- {A2BCA9F1-566C-4805-97D1-7FDC93386723}
O42 - Logiciel: Adobe Community Help - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
O42 - Logiciel: Adobe Community Help - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {F302F4F0-588D-6501-1ACF-BE3FDCC9135D}
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Photoshop CS5 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {15FEDA5F-141C-4127-8D7E-B962D1742728}
O42 - Logiciel: Adobe Photoshop Lightroom 3.3 64-bit - (.Adobe.) [HKLM] -- {CFFF260C-F510-45BB-8F8E-1D4AC1232786}
O42 - Logiciel: Adobe Reader 9.4.1 - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-A94000000001}
O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player
O42 - Logiciel: Akamai NetSession Interface - (.Unknown owner.) [HKLM][64Bits] -- Akamai
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM][64Bits] -- {DAEAFD68-BB4A-4507-A241-C8804D2EA66D}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {33EB1061-ABF1-4470-A540-32E97A610536}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {C41300B9-185D-475E-BFEC-39EF732F19B1}
O42 - Logiciel: Avira AntiVir Premium - (.Avira GmbH.) [HKLM][64Bits] -- Avira AntiVir Desktop
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {41BF0DE4-5BAE-4B88-AFD3-86A30B222186}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] -- {CF929EEB-CE39-4F06-B1BF-F51FC617A2B2}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite
O42 - Logiciel: Definition update for Microsoft Office 2010 (KB982726) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{88A32273-E9DF-4EAE-B266-A4D92FB7FB33}
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU] -- Google Chrome
O42 - Logiciel: HydraVision - (.ATI Technologies Inc..) [HKLM][64Bits] -- {A1A9A33E-F1E5-FBF4-8D72-E90BEAC7108A}
O42 - Logiciel: ImgBurn - (.LIGHTNING UK!.) [HKLM][64Bits] -- ImgBurn
O42 - Logiciel: JDownloader - (.AppWork UG (haftungsbeschränkt).) [HKLM][64Bits] -- JDownloader
O42 - Logiciel: Java(TM) 6 Update 15 - (.Sun Microsystems, Inc..) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83216015FF}
O42 - Logiciel: Logiciel d'archivage WinRAR - (.Unknown owner.) [HKLM][64Bits] -- WinRAR archiver
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM][64Bits] -- {40719211-D09A-11DF-BA30-0013D3D69929}
O42 - Logiciel: ManyCam 2.5.74 (remove only) - (.ManyCam LLC.) [HKLM][64Bits] -- ManyCam
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
O42 - Logiciel: Microsoft Office Access MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0015-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Excel MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Groove MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00BA-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0044-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Office 32-bit Components 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0043-0000-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office OneNote MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Professionnel Plus 2010 - (.Microsoft Corporation.) [HKLM] -- Office14.PROPLUS
O42 - Logiciel: Microsoft Office Proof (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0401-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Dutch) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0413-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0409-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (German) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0407-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0C0A-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared 32-bit MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0043-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {B6E3757B-5E77-3915-866A-CCFC4B8D194C}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable (x64) - (.Microsoft Corporation.) [HKLM] -- {071c9b48-7c32-4621-a0ac-3f809523288f}
O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM][64Bits] -- {002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475}
O42 - Logiciel: Microsoft_VC80_ATL_x86 - (.Adobe.) [HKLM][64Bits] -- {0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
O42 - Logiciel: Microsoft_VC80_ATL_x86_x64 - (.Adobe.) [HKLM] -- {925D058B-564A-443A-B4B2-7E90C6432E55}
O42 - Logiciel: Microsoft_VC80_CRT_x86 - (.Adobe.) [HKLM][64Bits] -- {92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
O42 - Logiciel: Microsoft_VC80_CRT_x86_x64 - (.Adobe.) [HKLM] -- {4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
O42 - Logiciel: Microsoft_VC80_MFCLOC_x86 - (.Adobe.) [HKLM][64Bits] -- {D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
O42 - Logiciel: Microsoft_VC80_MFCLOC_x86_x64 - (.Adobe.) [HKLM] -- {1E9FC118-651D-4934-97BE-E53CAE5C7D45}
O42 - Logiciel: Microsoft_VC80_MFC_x86 - (.Adobe.) [HKLM][64Bits] -- {D1A19B02-817E-4296-A45B-07853FD74D57}
O42 - Logiciel: Microsoft_VC80_MFC_x86_x64 - (.Adobe.) [HKLM] -- {C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
O42 - Logiciel: Microsoft_VC90_ATL_x86 - (.Adobe.) [HKLM][64Bits] -- {033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
O42 - Logiciel: Microsoft_VC90_ATL_x86_x64 - (.Adobe.) [HKLM] -- {8557397C-A42D-486F-97B3-A2CBC2372593}
O42 - Logiciel: Microsoft_VC90_CRT_x86 - (.Adobe.) [HKLM][64Bits] -- {08D2E121-7F6A-43EB-97FD-629B44903403}
O42 - Logiciel: Microsoft_VC90_CRT_x86_x64 - (.Adobe.) [HKLM] -- {92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
O42 - Logiciel: Microsoft_VC90_MFC_x86 - (.Adobe.) [HKLM][64Bits] -- {635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
O42 - Logiciel: Microsoft_VC90_MFC_x86_x64 - (.Adobe.) [HKLM] -- {A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
O42 - Logiciel: Mozilla Firefox (3.6.13) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox (3.6.13)
O42 - Logiciel: PDF Settings CS5 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {A78FE97A-C0C8-49CE-89D0-EDD524A17392}
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM][64Bits] -- {E7004147-2CCA-431C-AA05-2AB166B9785D}
O42 - Logiciel: RocketDock 1.3.5 - (.Punk Software.) [HKLM][64Bits] -- RocketDock_is1
O42 - Logiciel: S4 League_EU - (.Unknown owner.) [HKLM][64Bits] -- {6C304A4C-38D1-4954-A79E-BD9F68402F61}
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2160841
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2289078) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{416C3BAC-567F-4E84-9E3B-E98970E2603B}
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2289161) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{B3DFFE7D-FAA1-4B0D-AB1A-AF140A56BD84}
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2289161) - (.Microsoft.) [HKLM] -- {90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{B3DFFE7D-FAA1-4B0D-AB1A-AF140A56BD84}
O42 - Logiciel: Security Update for Microsoft Publisher 2010 (KB2409055) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{DED7FBC4-7528-4C64-9F94-8174AC522A33}
O42 - Logiciel: Security Update for Microsoft Word 2010 (KB2345000) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{FAE58C3D-8C0C-41D7-B95B-507B84ACB0C6}
O42 - Logiciel: SmartSound Quicktracks for Premiere Elements 9.0 - (.SmartSound Software Inc.) [HKLM][64Bits] -- InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}
O42 - Logiciel: SmartSound Quicktracks for Premiere Elements 9.0 - (.SmartSound Software Inc.) [HKLM][64Bits] -- {6748E773-5DA0-4D19-8AA5-273B4133A09B}
O42 - Logiciel: TRENDnet TEW-623PI Wireless PCI Adapter - (.TRENDnet.) [HKLM][64Bits] -- {76418E9D-ECFD-4F35-B8FB-771B0EF3EA9E}
O42 - Logiciel: UltraStar Deluxe - (.USDX Team.) [HKLM][64Bits] -- UltraStar Deluxe
O42 - Logiciel: Update for Microsoft Office 2010 (KB2202188) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{139222A0-48AF-44FF-BC3B-2112086FAF18}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2413186) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{276D6229-D1A9-4A22-BD8A-7E043897E230}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2413186) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{B4B16F09-574E-448C-BC90-DC8DF2ECA01E}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2413186) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{BC4F8B0E-191C-4226-8016-01EF1D0294FF}
O42 - Logiciel: Update for Microsoft OneNote 2010 (KB2433299) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A87E3880-C502-4939-9F54-4FF2772D58F2}
O42 - Logiciel: Update for Microsoft Outlook Social Connector (KB2289116) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{97B083AF-B1CB-4F60-8DFF-93B76D58E570}
O42 - Logiciel: VDownloader 2.10.509.2 - (.Vitzo Limited.) [HKLM][64Bits] -- {A7E19604-93AF-4611-8C9F-CE509C2B286E}_is1
O42 - Logiciel: VLC media player 1.1.4 - (.VideoLAN.) [HKLM][64Bits] -- VLC media player
O42 - Logiciel: Vegas Pro 10.0 - (.Sony.) [HKLM][64Bits] -- {3CD46E1E-D09A-11DF-A391-0013D3D69929}
O42 - Logiciel: Windows Driver Package - Ralink Technology, Corp. (netr28x) Net  (06/09/2008 - (.Ralink Technology, Corp..) [HKLM] -- B11F4646B81834F391632980B23E5C8088ED25D6
O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM][64Bits] -- WinLiveSuite
O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM][64Bits] -- {34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM][64Bits] -- {D45240D3-B6B3-4FF9-B243-54ECE3E10066}
O42 - Logiciel: Windows Live Essentials - (.Microsoft Corporation.) [HKLM][64Bits] -- {FE044230-9CA5-43F7-9B58-5AC5A28A1F33}
O42 - Logiciel: Windows Live ID Sign-in Assistant - (.Microsoft Corporation.) [HKLM] -- {1B8ABA62-74F0-47ED-B18C-A43128E591B8}
O42 - Logiciel: Windows Live Installer - (.Microsoft Corporation.) [HKLM][64Bits] -- {0B0F231F-CE6A-483D-AA23-77B364F75917}
O42 - Logiciel: Windows Live Language Selector - (.Microsoft Corporation.) [HKLM] -- {5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM][64Bits] -- {6057E21C-ABE9-4059-AE3E-3BEB9925E660}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM][64Bits] -- {80956555-A512-4190-9CAD-B000C36D6B6B}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM][64Bits] -- {EB4DF488-AAEF-406F-A341-CB2AAA315B90}
O42 - Logiciel: Windows Live PIMT Platform - (.Microsoft Corporation.) [HKLM][64Bits] -- {4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}
O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM][64Bits] -- {A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM][64Bits] -- {C893D8C0-1BA0-4517-B11C-E89B65E72F70}
O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM][64Bits] -- {D436F577-1695-4D2F-8B44-AC76C99E0002}
O42 - Logiciel: Windows Live SOXE - (.Microsoft Corporation.) [HKLM][64Bits] -- {682B3E4F-696A-42DE-A41C-4C07EA1678B4}
O42 - Logiciel: Windows Live SOXE Definitions - (.Microsoft Corporation.) [HKLM][64Bits] -- {200FEC62-3C34-4D60-9CE8-EC372E01C08F}
O42 - Logiciel: Windows Live UX Platform - (.Microsoft Corporation.) [HKLM][64Bits] -- {CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {09F56A49-A7B1-4AAB-95B9-D13094254AD1}
O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {6A05FEDF-662E-46BF-8A25-010E3F1C9C69}
O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM][64Bits] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
O42 - Logiciel: adsl TV - (.adsl TV / FM.) [HKLM][64Bits] -- {3AFDD2C6-8663-46B5-B195-6CEB00D44768}
O42 - Logiciel: iSkysoft SyncPod(Build - (.iSkysoft SyncPod.) [HKLM][64Bits] -- iSkysoft SyncPod_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {104FB32A-7CE3-4C4B-B2AA-70C613FF9DFA}
O42 - Logiciel: µTorrent - (.Unknown owner.) [HKLM][64Bits] -- uTorrent

---\\ HKCU & HKLM Software Keys
[HKCU\Software\Adobe Lightroom]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\DT Soft]
[HKCU\Software\IM Providers]
[HKCU\Software\Sony Creative Software]
[HKCU\Software\WinRAR SFX]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\GEAR Software]

---\\ Contents of the Common Files folders (O43)
O43 - CFD: 05/02/2011 - 17:38:14 ----D- C:\Program Files\Adobe
O43 - CFD: 29/10/2010 - 13:08:18 ----D- C:\Program Files\ATI
O43 - CFD: 29/10/2010 - 13:17:14 ----D- C:\Program Files\ATI Technologies
O43 - CFD: 29/10/2010 - 14:26:52 ----D- C:\Program Files\Bonjour
O43 - CFD: 05/11/2010 - 17:26:18 ----D- C:\Program Files\CCleaner
O43 - CFD: 09/01/2011 - 16:49:38 ----D- C:\Program Files\Common Files
O43 - CFD: 12/01/2011 - 20:00:48 ----D- C:\Program Files\DIFX
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files\DVD Maker
O43 - CFD: 11/02/2011 - 13:53:32 ----D- C:\Program Files\Internet Explorer
O43 - CFD: 29/10/2010 - 14:29:02 ----D- C:\Program Files\iPod
O43 - CFD: 29/10/2010 - 14:29:06 ----D- C:\Program Files\iTunes
O43 - CFD: 21/11/2010 - 10:45:42 ----D- C:\Program Files\Microsoft Analysis Services
O43 - CFD: 14/07/2009 - 08:46:54 ----D- C:\Program Files\Microsoft Games
O43 - CFD: 21/11/2010 - 10:48:00 ----D- C:\Program Files\Microsoft Office
O43 - CFD: 21/11/2010 - 10:47:58 ----D- C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 21/11/2010 - 10:47:58 ----D- C:\Program Files\Microsoft Sync Framework
O43 - CFD: 21/11/2010 - 10:48:22 ----D- C:\Program Files\Microsoft Synchronization Services
O43 - CFD: 14/07/2009 - 06:32:40 ----D- C:\Program Files\MSBuild
O43 - CFD: 14/07/2009 - 06:32:40 ----D- C:\Program Files\Reference Assemblies
O43 - CFD: 30/01/2011 - 15:17:22 ----D- C:\Program Files\TRENDnet
O43 - CFD: 14/07/2009 - 06:09:28 --H-D- C:\Program Files\Uninstall Information
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files\Windows Defender
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files\Windows Journal
O43 - CFD: 16/12/2010 - 17:18:20 ----D- C:\Program Files\Windows Mail
O43 - CFD: 30/10/2010 - 07:55:12 ----D- C:\Program Files\Windows Media Player
O43 - CFD: 14/07/2009 - 06:32:40 ----D- C:\Program Files\Windows NT
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files\Windows Photo Viewer
O43 - CFD: 14/07/2009 - 06:32:40 ----D- C:\Program Files\Windows Portable Devices
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files\Windows Sidebar
O43 - CFD: 27/01/2011 - 20:06:00 ----D- C:\Program Files\Common Files\Adobe
O43 - CFD: 29/10/2010 - 14:26:58 ----D- C:\Program Files\Common Files\Apple
O43 - CFD: 29/10/2010 - 13:16:46 ----D- C:\Program Files\Common Files\ATI Technologies
O43 - CFD: 21/11/2010 - 10:48:54 ----D- C:\Program Files\Common Files\DESIGNER
O43 - CFD: 29/10/2010 - 20:53:32 ----D- C:\Program Files\Common Files\logishrd
O43 - CFD: 21/11/2010 - 10:48:54 ----D- C:\Program Files\Common Files\Microsoft Shared
O43 - CFD: 14/07/2009 - 04:20:10 ----D- C:\Program Files\Common Files\Services
O43 - CFD: 14/07/2009 - 04:20:10 ----D- C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 21/11/2010 - 10:46:12 ----D- C:\Program Files\Common Files\System
O43 - CFD: 27/01/2011 - 20:06:00 ----D- C:\ProgramData\Adobe
O43 - CFD: 29/10/2010 - 14:34:44 ----D- C:\ProgramData\Apple
O43 - CFD: 29/10/2010 - 14:29:00 ----D- C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:08:58 -SH-D- C:\ProgramData\Application Data
O43 - CFD: 29/10/2010 - 13:50:10 ----D- C:\ProgramData\ATI
O43 - CFD: 23/11/2010 - 18:27:58 ----D- C:\ProgramData\Avira
O43 - CFD: 09/01/2011 - 14:08:28 ----D- C:\ProgramData\DAEMON Tools Lite
O43 - CFD: 14/07/2009 - 06:08:58 -SH-D- C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:08:58 -SH-D- C:\ProgramData\Documents
O43 - CFD: 09/01/2011 - 14:23:48 ----D- C:\ProgramData\eSellerate
O43 - CFD: 14/07/2009 - 06:08:58 -SH-D- C:\ProgramData\Favorites
O43 - CFD: 14/11/2010 - 15:29:32 ----D- C:\ProgramData\McAfee
O43 - CFD: 21/11/2010 - 10:47:58 -S--D- C:\ProgramData\Microsoft
O43 - CFD: 10/02/2011 - 17:35:14 ----D- C:\ProgramData\Microsoft Help
O43 - CFD: 09/01/2011 - 16:56:04 ----D- C:\ProgramData\
O43 - CFD: 09/01/2011 - 14:24:06 ----D- C:\ProgramData\SmartSound Software Inc
O43 - CFD: 09/01/2011 - 15:35:50 ----D- C:\ProgramData\Sony
O43 - CFD: 12/01/2011 - 19:42:28 ----D- C:\ProgramData\Spybot - Search & Destroy
O43 - CFD: 14/07/2009 - 06:08:58 -SH-D- C:\ProgramData\Start Menu
O43 - CFD: 14/07/2009 - 06:08:58 -SH-D- C:\ProgramData\Templates
O43 - CFD: 04/02/2011 - 22:34:12 ----D- C:\Users\Son\AppData\Roaming\Adobe
O43 - CFD: 29/10/2010 - 17:09:40 ----D- C:\Users\Son\AppData\Roaming\Apple Computer
O43 - CFD: 29/10/2010 - 13:50:10 ----D- C:\Users\Son\AppData\Roaming\ATI
O43 - CFD: 07/01/2011 - 17:22:22 ----D- C:\Users\Son\AppData\Roaming\Avira
O43 - CFD: 09/01/2011 - 14:10:26 ----D- C:\Users\Son\AppData\Roaming\DAEMON Tools Lite
O43 - CFD: 09/01/2011 - 14:48:40 ----D- C:\Users\Son\AppData\Roaming\Download Manager
O43 - CFD: 29/10/2010 - 13:04:48 ----D- C:\Users\Son\AppData\Roaming\Identities
O43 - CFD: 28/12/2010 - 12:00:52 ----D- C:\Users\Son\AppData\Roaming\ImgBurn
O43 - CFD: 30/01/2011 - 15:17:04 ----D- C:\Users\Son\AppData\Roaming\InstallShield
O43 - CFD: 29/10/2010 - 14:05:30 ----D- C:\Users\Son\AppData\Roaming\Macromedia
O43 - CFD: 31/10/2010 - 14:51:06 ----D- C:\Users\Son\AppData\Roaming\ManyCam
O43 - CFD: 14/07/2009 - 08:45:16 ----D- C:\Users\Son\AppData\Roaming\Media Center Programs
O43 - CFD: 29/12/2010 - 21:24:34 -S--D- C:\Users\Son\AppData\Roaming\Microsoft
O43 - CFD: 29/10/2010 - 13:17:12 ----D- C:\Users\Son\AppData\Roaming\Mozilla
O43 - CFD: 09/01/2011 - 15:52:20 ----D- C:\Users\Son\AppData\Roaming\Publish Providers
O43 - CFD: 09/01/2011 - 15:52:18 ----D- C:\Users\Son\AppData\Roaming\Sony
O43 - CFD: 09/01/2011 - 16:23:16 ----D- C:\Users\Son\AppData\Roaming\Sony Creative Software Inc
O43 - CFD: 16/01/2011 - 14:40:28 ----D- C:\Users\Son\AppData\Roaming\ultrastardx
O43 - CFD: 16/02/2011 - 21:22:54 ----D- C:\Users\Son\AppData\Roaming\uTorrent
O43 - CFD: 31/10/2010 - 21:50:00 ----D- C:\Users\Son\AppData\Roaming\VDownloader
O43 - CFD: 10/01/2011 - 08:23:28 ----D- C:\Users\Son\AppData\Roaming\vlc
O43 - CFD: 30/10/2010 - 09:47:10 ----D- C:\Users\Son\AppData\Roaming\WinRAR
O43 - CFD: 09/11/2010 - 17:47:20 ----D- C:\Program Files (x86)\7-Zip
O43 - CFD: 09/01/2011 - 16:50:58 ----D- C:\Program Files (x86)\Adobe
O43 - CFD: 04/12/2010 - 19:43:48 ----D- C:\Program Files (x86)\adslTV
O43 - CFD: 28/11/2010 - 19:11:20 ----D- C:\Program Files (x86)\alaplaya
O43 - CFD: 29/10/2010 - 14:27:02 ----D- C:\Program Files (x86)\Apple Software Update
O43 - CFD: 29/10/2010 - 13:15:50 ----D- C:\Program Files (x86)\ATI Technologies
O43 - CFD: 23/11/2010 - 18:27:58 ----D- C:\Program Files (x86)\Avira
O43 - CFD: 29/10/2010 - 14:26:52 ----D- C:\Program Files (x86)\Bonjour
O43 - CFD: 09/01/2011 - 15:12:04 ----D- C:\Program Files (x86)\Common Files
O43 - CFD: 09/01/2011 - 14:08:48 ----D- C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD: 28/12/2010 - 11:55:10 ----D- C:\Program Files (x86)\ImgBurn
O43 - CFD: 30/01/2011 - 15:17:22 --H-D- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 11/02/2011 - 13:53:32 ----D- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 29/10/2010 - 14:31:18 ----D- C:\Program Files (x86)\iSkysoft
O43 - CFD: 29/10/2010 - 14:29:06 ----D- C:\Program Files (x86)\iTunes
O43 - CFD: 29/10/2010 - 20:08:52 ----D- C:\Program Files (x86)\Java
O43 - CFD: 19/02/2011 - 14:24:48 ----D- C:\Program Files (x86)\JDownloader
O43 - CFD: 31/10/2010 - 14:50:58 ----D- C:\Program Files (x86)\ManyCam
O43 - CFD: 21/11/2010 - 10:45:42 ----D- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 21/11/2010 - 10:45:04 ----D- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 06/01/2011 - 17:47:00 ----D- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 21/11/2010 - 10:46:50 ----D- C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD: 21/11/2010 - 10:47:58 ----D- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 11/12/2010 - 15:39:46 ----D- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 21/11/2010 - 10:48:12 ----D- C:\Program Files (x86)\MSBuild
O43 - CFD: 04/11/2010 - 20:40:30 ----D- C:\Program Files (x86)\QuickTime
O43 - CFD: 14/07/2009 - 06:32:40 ----D- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 28/11/2010 - 11:30:34 ----D- C:\Program Files (x86)\RocketDock
O43 - CFD: 09/01/2011 - 14:23:48 ----D- C:\Program Files (x86)\SmartSound Software
O43 - CFD: 09/01/2011 - 15:35:50 ----D- C:\Program Files (x86)\Sony
O43 - CFD: 21/11/2010 - 16:34:42 ----D- C:\Program Files (x86)\Spybot - Search & Destroy
O43 - CFD: 16/01/2011 - 13:38:44 ----D- C:\Program Files (x86)\UltraStar Deluxe
O43 - CFD: 14/07/2009 - 05:57:08 --H-D- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 30/10/2010 - 09:05:32 ----D- C:\Program Files (x86)\uTorrent
O43 - CFD: 31/10/2010 - 21:49:52 ----D- C:\Program Files (x86)\VDownloader
O43 - CFD: 30/10/2010 - 16:59:52 ----D- C:\Program Files (x86)\VideoLAN
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files (x86)\Windows Defender
O43 - CFD: 29/10/2010 - 14:10:38 ----D- C:\Program Files (x86)\Windows Live
O43 - CFD: 16/12/2010 - 17:18:20 ----D- C:\Program Files (x86)\Windows Mail
O43 - CFD: 30/10/2010 - 07:55:14 ----D- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - 06:32:40 ----D- C:\Program Files (x86)\Windows NT
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 14/07/2009 - 06:32:42 ----D- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 29/10/2010 - 13:57:02 ----D- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 30/10/2010 - 09:38:08 ----D- C:\Program Files (x86)\WinRAR
O43 - CFD: 19/02/2011 - 16:15:08 ----D- C:\Program Files (x86)\ZHPDiag
O43 - CFD: 27/01/2011 - 20:06:00 ----D- C:\Program Files\Common Files\Adobe
O43 - CFD: 29/10/2010 - 14:26:58 ----D- C:\Program Files\Common Files\Apple
O43 - CFD: 29/10/2010 - 13:16:46 ----D- C:\Program Files\Common Files\ATI Technologies
O43 - CFD: 21/11/2010 - 10:48:54 ----D- C:\Program Files\Common Files\DESIGNER
O43 - CFD: 29/10/2010 - 20:53:32 ----D- C:\Program Files\Common Files\logishrd
O43 - CFD: 21/11/2010 - 10:48:54 ----D- C:\Program Files\Common Files\Microsoft Shared
O43 - CFD: 14/07/2009 - 04:20:10 ----D- C:\Program Files\Common Files\Services
O43 - CFD: 14/07/2009 - 04:20:10 ----D- C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 21/11/2010 - 10:46:12 ----D- C:\Program Files\Common Files\System

---\\ Last modified or created files under Windows and System32 (O44)
O44 - LFC:[MD5.532F3E7C41715DA3071738E7920444CA] - 19/02/2011 - 16:02:18 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI   [1549700]
O44 - LFC:[MD5.D778FA37A52DC5E37B0D1AB9A567B3BB] - 19/02/2011 - 16:02:18 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat   [106316]
O44 - LFC:[MD5.766DCB6F3695CBF3FFC8772AAD19E2B8] - 19/02/2011 - 16:02:18 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat   [130068]
O44 - LFC:[MD5.5D9F0E30ACF3A77183174C1B8B1BBFA7] - 19/02/2011 - 16:02:18 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat   [623940]
O44 - LFC:[MD5.BAB2703DDECBFB2E60C32FDB3311810A] - 19/02/2011 - 16:02:18 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat   [702362]
O44 - LFC:[MD5.05BC668A0E49F9FED28B96163DA69EE9] - 19/02/2011 - 15:04:27 ---A- . (...) -- C:\Windows\setupact.log   [17040]
O44 - LFC:[MD5.0B000000000000000000000054EE1800] - 19/02/2011 - 14:41:23 ---A- . (...) -- C:\Windows\WindowsUpdate.log   [1382251]
O44 - LFC:[MD5.6C200CD92B9F70F816C36B7E8060EE66] - 19/02/2011 - 11:18:03 -S-A- . (...) -- C:\Windows\bootstat.dat   [67584]
O44 - LFC:[MD5.6E27146F3765D48961CBC9DEC512012D] - 18/02/2011 - 21:54:41 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0   [14416]
O44 - LFC:[MD5.6E27146F3765D48961CBC9DEC512012D] - 18/02/2011 - 21:54:41 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0   [14416]
O44 - LFC:[MD5.7FCC8441FBEBFC9C8AED25DC162E7E56] - 11/02/2011 - 13:55:12 ---A- . (...) -- C:\Windows\SysNative\FNTCACHE.DAT   [4972368]
O44 - LFC:[MD5.158D85C26868E8A9903A726CE145F66B] - 09/02/2011 - 16:01:35 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\SysNative\atmlib.dll   [46080]
O44 - LFC:[MD5.BF973CEDCD012D23F194BBF0A9B218E6] - 09/02/2011 - 16:01:35 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\SysNative\atmfd.dll   [366080]
O44 - LFC:[MD5.BF973CEDCD012D23F194BBF0A9B218E6] - 09/02/2011 - 16:01:35 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll   [294400]
O44 - LFC:[MD5.158D85C26868E8A9903A726CE145F66B] - 09/02/2011 - 16:01:34 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll   [34304]
O44 - LFC:[MD5.535DC363026747266D59D86F46CD3B47] - 30/01/2011 - 15:17:46 ---A- . (...) -- C:\Windows\DPINST.LOG   [17568]

---\\ Operations and functions at Windows Explorer startup (O46)
O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook [64Bits] - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL

---\\ Local Security Authority-LSA Deny (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll

---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"vidc.i420"="lvcod64.dll" . (.Logitech Inc. - Video Codec.) -- (.not file.)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

---\\ ShareTools MSconfig StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\BCSSync  [Key] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe
O53 - SMSR:HKLM\...\startupreg\DAEMON Tools Lite  [Key] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
O53 - SMSR:HKLM\...\startupreg\ManyCam  [Key] . (.ManyCam LLC - ManyCam Application.) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe
O53 - SMSR:HKLM\...\startupreg\QuickTime Task  [Key] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe

---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll

---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0

---\\ System Drivers List (SDL) (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys   [491088]
O58 - SDL:[MD5.597F78224EE9224EA1A13D6350CED962] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys   [339536]
O58 - SDL:[MD5.E109549C90F62FB570B9540C4B148E54] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\system32\drivers\adpu320.sys   [182864]
O58 - SDL:[MD5.5812713A477A3AD7363C7438CA2EE038] - 14/07/2009 - 02:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys   [15440]
O58 - SDL:[MD5.7A4B413614C055935567CF88A9734D38] - 14/07/2009 - 02:52:21 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\system32\drivers\amdsata.sys   [106576]
O58 - SDL:[MD5.F67F933E79241ED32FF46A4F29B5120B] - 14/07/2009 - 02:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\system32\drivers\amdsbs.sys   [194128]
O58 - SDL:[MD5.B4AD0CACBAB298671DD6F6EF7E20679D] - 14/07/2009 - 02:52:21 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\system32\drivers\amdxata.sys   [28752]
O58 - SDL:[MD5.C484F8CEB1717C540242531DB7845C4E] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys   [87632]
O58 - SDL:[MD5.019AF6924AEFE7839F61C830227FE79C] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys   [97856]
O58 - SDL:[MD5.03B7145C889603537E9FFEABB1AD1089] - 29/03/2005 - 00:30:38 ---A- . (.Unknown owner - ATK0110 ACPI Utility.) -- C:\Windows\system32\drivers\ASACPI.sys   [8192]
O58 - SDL:[MD5.506934DF94E3197F4A1BBE8FBEAB0CCD] - 23/08/2009 - 15:02:30 ---A- . (.ATI Technologies, Inc. - ATI High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\AtiHdmi.sys   [120336]
O58 - SDL:[MD5.79CEB8D4F25CABE69F3762C90F5B06B8] - 19/09/2009 - 05:32:36 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\system32\drivers\atikmdag.sys   [6170624]
O58 - SDL:[MD5.C30B5FC0ADCDFBA7668E99BAF0CBF58E] - 24/11/2010 - 08:25:32 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- C:\Windows\system32\drivers\avgntflt.sys   [74880]
O58 - SDL:[MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - 10/06/2009 - 21:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\system32\drivers\b57nd60a.sys   [270848]
O58 - SDL:[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - 10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys   [18432]
O58 - SDL:[MD5.B114D3098E9BDB8BEA8B053685831BE6] - 10/06/2009 - 21:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys   [8704]
O58 - SDL:[MD5.43BEA8D483BF1870F018E2D02E06A5BD] - 14/07/2009 - 02:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys   [286720]
O58 - SDL:[MD5.A6ECA2151B08A09CACECA35C07F05B42] - 10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys   [47104]
O58 - SDL:[MD5.B79968002C277E869CF38BD22CD61524] - 10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys   [14976]
O58 - SDL:[MD5.A87528880231C54E75EA7A44943B38BF] - 10/06/2009 - 21:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys   [14720]
O58 - SDL:[MD5.3E5B191307609F7514148C6832BB0842] - 10/06/2009 - 21:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\system32\drivers\bxvbda.sys   [468480]
O58 - SDL:[MD5.E19D3F095812725D88F9001985B94EDD] - 14/07/2009 - 02:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys   [17488]
O58 - SDL:[MD5.9F98D7AFA293947A0DFC6FFD4671FE70] - 09/01/2011 - 14:08:47 ---A- . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\system32\drivers\dtsoftbus01.sys   [254528]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys   [530496]
O58 - SDL:[MD5.DC5D737F51BE844D8C82C695EB17372F] - 10/06/2009 - 21:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\system32\drivers\evbda.sys   [3286016]
O58 - SDL:[MD5.E403AACF8C7BB11375122D2464560311] - 18/05/2009 - 12:17:08 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys   [34152]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\system32\drivers\hcw85cir.sys   [31232]
O58 - SDL:[MD5.0886D440058F203EBA0E1825E4355914] - 14/07/2009 - 02:47:48 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\system32\drivers\HpSAMD.sys   [77888]
O58 - SDL:[MD5.D83EFB6FD45DF9D55E9A1AFC63640D50] - 14/07/2009 - 02:48:04 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\system32\drivers\iaStorV.sys   [410688]
O58 - SDL:[MD5.5C18831C61933628F5BB0EA2675B9D21] - 14/07/2009 - 02:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys   [44112]
O58 - SDL:[MD5.1A93E54EB0ECE102495A51266DCDB6A6] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys   [114752]
O58 - SDL:[MD5.1047184A9FDC8BDBFF857175875EE810] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys   [106560]
O58 - SDL:[MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas2.sys   [65600]
O58 - SDL:[MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys   [115776]
O58 - SDL:[MD5.BFBA84B8A9C233AE42B11CF7BDFC6C01] - 27/07/2010 - 07:14:24 ---A- . (.Logitech Inc. - Logitech USB Video Class Driver.) -- C:\Windows\system32\drivers\lvuvc64.sys   [6465632]
O58 - SDL:[MD5.A55805F747C6EDB6A9080D7C633BD0F4] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\system32\drivers\megasas.sys   [35392]
O58 - SDL:[MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - 14/07/2009 - 02:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys   [284736]
O58 - SDL:[MD5.307BC83250FC8E3B2878D81E7D760299] - 19/04/2010 - 19:29:18 ---A- . (.Apple Inc. - Apple Mobile Device Ethernet.) -- C:\Windows\system32\drivers\netaapl64.sys   [22528]
O58 - SDL:[MD5.D66596DB0A0739A89C25B590CE36D628] - 19/06/2009 - 06:56:08 ---A- . (.Ralink Technology, Corp. - Ralink 802.11 Wireless Adapter Driver.) -- C:\Windows\system32\drivers\netr28x.sys   [712704]
O58 - SDL:[MD5.77889813BE4D166CDAB78DDBA990DA92] - 14/07/2009 - 02:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys   [51264]
O58 - SDL:[MD5.3E38712941E9BB4DDBEE00AFFE3FED3D] - 14/07/2009 - 02:48:27 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys   [149056]
O58 - SDL:[MD5.477DC4D6DEB99BE37084C9AC6D013DA1] - 14/07/2009 - 02:45:45 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys   [167488]
O58 - SDL:[MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - 14/07/2009 - 02:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys   [1524816]
O58 - SDL:[MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - 14/07/2009 - 02:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys   [128592]
O58 - SDL:[MD5.BAEFEE35D27A5440D35092CE10267BEC] - 10/06/2009 - 21:35:42 ---A- . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS 6.20 64-bit Driver.) -- C:\Windows\system32\drivers\Rt64win7.sys   [187392]
O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 10/06/2009 - 21:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys   [23040]
O58 - SDL:[MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - 14/07/2009 - 02:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys   [43584]
O58 - SDL:[MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - 14/07/2009 - 02:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys   [80464]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise  SuperTrak EX Series Driver for Windows.) -- C:\Windows\system32\drivers\stexstor.sys   [24656]
O58 - SDL:[MD5.CD03479F2DA26500B203ED075C146A7A] - 19/04/2010 - 19:47:42 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\system32\drivers\usbaapl64.sys   [50688]
O58 - SDL:[MD5.E5689D93FFE4E5D66C0178761240DD54] - 14/07/2009 - 02:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys   [17488]
O58 - SDL:[MD5.5E2016EA6EBACA03C04FEAC5F330D997] - 14/07/2009 - 02:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys   [161872]
O58 - SDL:[MD5.3AD0362CF68DE3AC500E981700242CCA] - 11/05/2009 - 09:11:52 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\Windows\SysWOW64\drivers\ssmdrv.sys   [28520]

---\\ List all tools cleaner (LATC) (O63)
O63 - Logiciel: ZHPDiag 1.27 - (.Nicolas Coolman.) [HKLM][64Bits] -- ZHPDiag_is1

---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Son\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) -
O69 - SBI: SearchScopes [HKCU] {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} - (Bing) -

---\\ Search Particular Root Folder (SPRF) (O84)
[MD5.C9C30A1981A9220DBE1C3A03D74C8289] [SPRF] (.Greatis Software - RunGuard file checker.) -- C:\Users\Son\AppData\Local\minroms.dll   [86528]
[MD5.415F8B11C71D91034EEB2F170D63DA97] [SPRF] (.Unknown owner - No comment.) -- C:\Users\Son\AppData\Local\Temp\arcewnomsx.exe   [74752]
[MD5.CAD9D11FC1690BBBD550DA2E4DC2CD2E] [SPRF] (.Greatis Software - RunGuard file checker.) -- C:\Users\Son\AppData\Local\Temp\eacomnxswr.exe   [86528]

---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\spoolsv.exe (.not file.)
O87 - FAEL: "FPS-SpoolSvc-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\spoolsv.exe (.not file.)
O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" |Out - Domain - P6 - TRUE | .(...) -- C:\Windows\system32\lsass.exe (.not file.)
O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\services.exe (.not file.)
O87 - FAEL: "RemoteSvcAdmin-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\services.exe (.not file.)
O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "MCX-Prov-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - MCX2 Provisioning library.) -- C:\Windows\ehome\mcx2prov.exe
O87 - FAEL: "MCX-McrMgr-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Media Center Extender Manager.) -- C:\Windows\ehome\mcrmgr.exe
O87 - FAEL: "{34C8F4BE-1A36-4560-82B6-A897EE36018F}" |In - Private - P6 - TRUE | .(...) -- C:\Windows\system32\spoolsv.exe (.not file.)
O87 - FAEL: "{24FA0356-BD80-4048-9763-F2323B7D6CF5}" | In - None - P6 - TRUE | .(.Microsoft Corporation - Windows Live Communications Platform.) -- C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
O87 - FAEL: "{9B151CA8-B55C-42D3-A39E-615E1E86CD43}" | In - None - P6 - TRUE | .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O87 - FAEL: "{213F922D-ACA9-4D6E-B4F6-4676C8DE65A1}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{6E507445-4445-466A-9D40-74793221EB9F}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{C9B71814-6259-4DDE-A1F3-046D2117AA4A}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe
O87 - FAEL: "TCP Query User{1F1DF335-FF2E-4216-BFB7-96043E2E944A}C:\program files (x86)\java\jre6\bin\javaw.exe" | In - Private - P6 - TRUE | .(.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\program files (x86)\java\jre6\bin\javaw.exe
O87 - FAEL: "UDP Query User{B6DD59EC-A7B6-418A-AB91-8A6E01401818}C:\program files (x86)\java\jre6\bin\javaw.exe" | In - Private - P17 - TRUE | .(.Sun Microsystems, Inc..) -- C:\program files (x86)\java\jre6\bin\javaw.exe
O87 - FAEL: "{D52A62A2-BBD9-4449-91C7-FE509EC9989B}" | In - None - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
O87 - FAEL: "{E05E3251-CC89-495F-B6DD-131232D34258}" | In - None - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
O87 - FAEL: "TCP Query User{3365AA6D-28E2-4CF1-8906-968B9CFD41CF}C:\users\son\downloads\bo pc\black ops\blackopsmp.exe" |In - Private - P6 - TRUE | .(...) -- C:\users\son\downloads\bo pc\black ops\blackopsmp.exe (.not file.)
O87 - FAEL: "UDP Query User{DFCC2C26-7DCB-4069-B659-0F7290E0C898}C:\users\son\downloads\bo pc\black ops\blackopsmp.exe" |In - Private - P17 - TRUE | .(...) -- C:\users\son\downloads\bo pc\black ops\blackopsmp.exe (.not file.)
O87 - FAEL: "TCP Query User{8D181E70-3831-4002-906E-A4B862C00ABB}C:\users\son\downloads\bo pc\black ops\blackops.exe" |In - Private - P6 - TRUE | .(...) -- C:\users\son\downloads\bo pc\black ops\blackops.exe (.not file.)
O87 - FAEL: "UDP Query User{2D5B9424-CD5F-48FF-A93A-BFD08D7543D5}C:\users\son\downloads\bo pc\black ops\blackops.exe" |In - Private - P17 - TRUE | .(...) -- C:\users\son\downloads\bo pc\black ops\blackops.exe (.not file.)
O87 - FAEL: "{D13C7800-A7F3-4009-AAC4-00DDE5DC3F04}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Microsoft SharePoint Workspace.) -- C:\Program Files\Microsoft Office\Office14\GROOVE.exe
O87 - FAEL: "{4D483CCC-473C-4E3D-A46F-D86D18D42BB0}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Microsoft SharePoint Workspace.) -- C:\Program Files\Microsoft Office\Office14\GROOVE.exe
O87 - FAEL: "{EAC5D626-B02B-4C0A-8340-86B532BA91F6}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Microsoft OneNote.) -- C:\Program Files\Microsoft Office\Office14\ONENOTE.exe
O87 - FAEL: "{CAC29755-6902-40E3-A7F3-BC5E758D1503}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Microsoft OneNote.) -- C:\Program Files\Microsoft Office\Office14\ONENOTE.exe
O87 - FAEL: "{E9DCCD0A-0A04-4DE9-96C5-F793B19E143B}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Microsoft Outlook.) -- C:\Program Files\Microsoft Office\Office14\outlook.exe
O87 - FAEL: "{7D5E2E11-8AE8-40FD-9687-882D3A5609F3}" | In - Private - P6 - TRUE | .(.adsl TV / FM - No comment.) -- C:\Program Files (x86)\adslTV\adsltv.exe
O87 - FAEL: "{27895B8F-E412-4157-B5BA-EDDB905D282B}" | In - Private - P17 - TRUE | .(.adsl TV / FM - No comment.) -- C:\Program Files (x86)\adslTV\adsltv.exe
O87 - FAEL: "{B933B5C4-86F1-4D73-97EC-331C56B105C8}" | In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\adslTV\VLC\vlc.exe
O87 - FAEL: "{E3F00AB2-1BEF-4BC7-881E-60EE8F692EA9}" | In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\adslTV\VLC\vlc.exe
O87 - FAEL: "TCP Query User{4CF87B79-FF35-4B27-A751-E1E1E7BA180A}C:\program files (x86)\videolan\vlc\vlc.exe" | In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\videolan\vlc\vlc.exe
O87 - FAEL: "UDP Query User{2A3213CA-C9CE-4284-BE74-D2A944857773}C:\program files (x86)\videolan\vlc\vlc.exe" | In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\videolan\vlc\vlc.exe
O87 - FAEL: "TCP Query User{68E47429-AEA3-4DF2-B566-4C8C998B117C}C:\program files (x86)\java\jre6\bin\javaw.exe" | In - Public - P6 - TRUE | .(.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\program files (x86)\java\jre6\bin\javaw.exe
O87 - FAEL: "UDP Query User{B9A93370-2907-4DBF-8D2A-F8569F640FAB}C:\program files (x86)\java\jre6\bin\javaw.exe" | In - Public - P17 - TRUE | .(.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\program files (x86)\java\jre6\bin\javaw.exe
O87 - FAEL: "TCP Query User{B833FB39-4991-4CC7-A4B9-620757AB4BA6}C:\program files (x86)\mozilla firefox\firefox.exe" | In - Private - P6 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files (x86)\mozilla firefox\firefox.exe
O87 - FAEL: "UDP Query User{4FFCB15F-CC01-49AC-85C1-7327938ED9D0}C:\program files (x86)\mozilla firefox\firefox.exe" | In - Private - P17 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files (x86)\mozilla firefox\firefox.exe

---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto  0 |  (AMD External Events Utility) . (.AMD.) - C:\Windows\system32\atiesrxx.exe
SR - | Auto 11/05/2009 194817 |  (AntiVirMailService) . (.Avira GmbH.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
SR - | Auto 13/05/2009 108289 |  (AntiVirSchedulerService) . (.Avira GmbH.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 21/07/2009 185089 |  (AntiVirService) . (.Avira GmbH.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 12/05/2009 434945 |  (AntiVirWebService) . (.Avira GmbH.) - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.exe
SR - | Auto 13/08/2010 144672 |  (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 27/07/2010 345376 |  (Bonjour Service) . (.Apple Inc..) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
SR - | Demand 24/09/2010 932640 |  (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 18/04/2003 8192 |  (KMService) . (.Unknown owner.) - C:\Windows\system32\srvany.exe
SS - | Demand 19/02/2010 517096 |  (SwitchBoard) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe
SS - | Demand 14/07/2009 0 |  (X6va003) . (.Unknown owner.) - C:\Users\Son\AppData\Local\Temp\003A2A4.tmp

---\\ Search Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer,
Run by Son at 19/02/2011 16:15:43

device: opened successfully
user: error reading MBR

Disk trace:
error: Read  Descripteur non valide
kernel: error reading MBR

---\\ Search Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Son at 19/02/2011 16:15:43
Use the desktop link 'MBRCheck' to have full report

---\\ List of CD/DVD Emulators (MBR Hook)
O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite

End of the scan (827 lines in 00mn 44s)(0)

J'espere que c'est sa ^^ merci pour votre aide ;)
Apprenti(e) Expert(e)
Apprenti(e) Expert(e)
Messages: 126
Inscription: 15 Jan 2011 20:42

Re: Trojan TR/Hiloti.A

Message le 19 Fév 2011 17:09

On va faire un scan avec MBAM puis NOD32 , puis je te file un Script....


Image Malwarebytes' Antimalware par Marcin Kleczynski

*** Met-le à jour puis choisi, Exécuter un examen complet

*** Si une infection est trouvée, coche la case a coté et valides avec l’Onglet Supprimer la sélection

Poste le rapport final.

*** il est conseillé de désactivé Tea-Timer si tu as Spybot-S&D juste le temps du scan.

Voici comment faire: Lancez Spybot-S&D, passez en Mode avancé via le Menu Mode (en haut) ? cliquez sur Oui--> choisissez Outils dans la barre de navigation sur la gauche -->Résident et là vous pouvez décocher les cases situées devant les deux outils.


Scan en ligne avec -> NOD32

_->Cliquez sur le bouton vert Eset Online Scanner
_->Accepter les conditions d’utilisation, pour cela, cochez la case « Oui, j’accepte les termes du contrat de licence »
_->Cliquez ensuite sur le bouton Start
_->Acceptez l’installation de l’ActiveX NOD32
_->Le téléchargement des définitions virales s’effectuent, cela peut prendre du temps selon la vitesse de connexion.
_->Cocher la case "Supprimer les menaces détectées"
_->Clique sur le bouton Démarrer pour lancer le scan
_->Le scan du PC se lance, les menaces détectées apparaissent dans la liste en dessous de la barre de progression.
_->Laissez l’analyse s’effectuer entièrement
_->Cliquer sur le bouton « liste des menaces » permettant d’exporter la liste dans un fichier texte
_->Enregistrer celui-ci sur votre bureau par exemple

Poste moi le rapport ;)

Surtout prend bien ton temps pour lire et effectuer les étapes énoncer ... :)
Avatar de l'utilisateur
Messages: 1833
Inscription: 08 Juin 2009 06:46
Localisation: Nord-(59)

Re: Trojan TR/Hiloti.A

Message le 19 Fév 2011 18:36

Mince j'ai fais une bêtise :roll:
A la fin du premier "scan" il y a eu le fichier .txt qui s'est affiché et j'ai pas eu le temps de l'afficher j'ai cliquer sur redémarrer
et au deuxième scan il n'a rien détecté (le fichier .txt ne s'est pas affiché) comme j'avais tout supprimé sur le premier ( 10 trucs infecté) .

Et "NOD32" n'a rien trouvé .

Apprenti(e) Expert(e)
Apprenti(e) Expert(e)
Messages: 126
Inscription: 15 Jan 2011 20:42

Re: Trojan TR/Hiloti.A

Message le 19 Fév 2011 20:14

Bonsoir , :)

Relance Malwarebytes et clique dans l'onglet "Rapport/Logs" tu y retrouveras le rapport effectuer ;)
Poste le moi stp...
Avatar de l'utilisateur
Messages: 1833
Inscription: 08 Juin 2009 06:46
Localisation: Nord-(59)

Re: Trojan TR/Hiloti.A

Message le 21 Fév 2011 18:01

Code: Tout sélectionner
Malwarebytes' Anti-Malware

Version de la base de données: 5810

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

19/02/2011 17:35:55
mbam-log-2011-02-19 (17-35-55).txt

Type d'examen: Examen complet (C:\|F:\|L:\|)
Elément(s) analysé(s): 302346
Temps écoulé: 19 minute(s), 47 seconde(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 9

Processus mémoire infecté(s):
c:\Windows\kmservice.exe (RiskWare.Tool.CK) -> 1864 -> Unloaded process successfully.

Module(s) mémoire infecté(s):
c:\Users\Son\AppData\Local\minroms.dll (Trojan.Hiloti.Gen) -> Delete on reboot.

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Bhanagecagu (Trojan.Hiloti.Gen) -> Value: Bhanagecagu -> Delete on reboot.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\Windows\kmservice.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\Users\Son\AppData\Local\minroms.dll (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
c:\Users\Son\AppData\Local\Temp\arcewnomsx.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\Son\AppData\Local\Temp\eacomnxswr.exe (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
f:\logiciels\multimédia\office pro plus\office_pro_plus_2010_x64_64bits_fr\mini-kms_activator_v1.052\mini-kms_activator_v1.052.exe (Riskware.Keygen) -> Quarantined and deleted successfully.
f:\logiciels\multimédia\photoshop cs5\adobe_ps_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
f:\logiciels\multimédia\sony vegas pro 10\sony vegas 10 crack + keygen\Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
l:\Logiciel\photoshop\adobe_ps_cs5_keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
l:\Logiciel\sony vegas 10 crack + keygen\Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

Voila :D
Apprenti(e) Expert(e)
Apprenti(e) Expert(e)
Messages: 126
Inscription: 15 Jan 2011 20:42

Re: Trojan TR/Hiloti.A

Message le 21 Fév 2011 19:03

Bonsoir , :)

Très bien , Malwarebytes a bien fais son boulot :D
Peut tu refaire un ZHPDiag comme tu la fais la première fois stp pour vérifier si éventuellement il ne reste
plus de petites infections à virer .. ;)

Sinon comment se comporte le pc depuis le nettoyage de MBAM ?

Bonne soirée
Avatar de l'utilisateur
Messages: 1833
Inscription: 08 Juin 2009 06:46
Localisation: Nord-(59)

