O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} Clé orpheline
[HKCU\Software\AGProtect]
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) -
http://search.imgag.com O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) -
http://search.imgag.com O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe
O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe
O87 - FAEL: "TCP Query User{3D5A5C82-7B18-448E-BFCC-316398F2FE99}C:\users\action cynophile\appdata\local\temp\khvcol.exe" |In - Public - P6 - TRUE | .(...) -- C:\users\action cynophile\appdata\local\temp\khvcol.exe (.not file.)
O87 - FAEL: "UDP Query User{E40B7D1C-FE87-4C76-9A3A-6B10DCDD92FC}C:\users\action cynophile\appdata\local\temp\khvcol.exe" |In - Public - P17 - TRUE | .(...) -- C:\users\action cynophile\appdata\local\temp\khvcol.exe (.not file.)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{49783ED4-258D-4f9f-BE11-137C18D3E543}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{49783ED4-258D-4f9f-BE11-137C18D3E543}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}]
[HKCU\Software\AppDataLow\LastScanTime]
[MD5.00000000000000000000000000000000] [APT] [{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}] (.Pas de propriétaire.) -- C:\Users\action cynophile\AppData\Local\Temp\Hmq.exe (.not file.)
O51 - MPSK:{607804ba-1fd5-11e0-bf38-001d72ba8e66}\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{ae8285d4-d22b-11df-b88f-001d72ba8e66}\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{ae8285e4-d22b-11df-b88f-001d72ba8e66}\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- G:\AutoRun.exe (.not file.)
[MD5.48DB6F937FDAD5FA5FDEA98007FDBE07] [SPRF] (.Symantec Corporation - Symantec Symevent Installer.) -- C:\Users\action cynophile\AppData\Local\Temp\SEVINST.EXE [832904]
[MD5.EF11B309855FB142952890CA1715BBB9] [SPRF] (.Symantec Corporation - Norton Internet Security.) -- C:\Users\action cynophile\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_NIS.exe [987136]
O64 - Services: CurCS - (.not file.) - bamxj (bamxj) .(...) - LEGACY_BAMXJ
O41 - Driver: (SymIM) . (. - .) - C:\Windows\System32\DRIVERS\SymIMv.sys (.not file.)
[HKCU\Software\Cote dAzur Palace Casino]
[HKLM\Software\Cote dAzur Palace Casino]
O43 - CFD: 18/03/2010 - 20:33:02 - [1320] --H-D- C:\Program Files\PokerStars
O43 - CFD: 22/11/2009 - 19:05:42 - [488031] --H-D- C:\Users\action cynophile\Appdata\Local\FullTiltPoker
O43 - CFD: 10/03/2010 - 11:13:54 - [4058573] --H-D- C:\Users\action cynophile\Appdata\Local\PokerStars
O4 - HKLM\..\Run: [eRecoveryService] Clé orpheline
O4 - HKLM\..\Run: [UpdatePSTShortCut] Clé orpheline
O4 - HKLM\..\Run: [NPSStartup] Clé orpheline
O4 - HKCU\..\Run: [jksuuw] C:\Users\action cynophile\jksuuw.exe (.not file.)
O4 - HKUS\S-1-5-21-813577986-875259167-3730179392-1000\..\Run: [jksuuw] C:\Users\action cynophile\jksuuw.exe (.not file.)
O42 - Logiciel: Kiwee Chatbar - (.AG Interactive.) [HKLM] -- {1793bdb7-d5c1-33be-97e2-7c3e60b6ab43}
O42 - Logiciel: Kiwee Toolbar for Firefox - (.AG Interactive.) [HKLM] -- {10deb052-db5d-32a6-9ff2-200e810d1a7b}
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKLM\Software\Eobqwguf]
O2 - BHO: (no name) - {4EFCFF2B-CF31-44E1-0D8B-70D525449A07} . (.Pas de propriétaire - Pas de description.) -- c:\windows\system32\vzsmjwv.dll
EmptyFlash
Emptytemp