d'impossible de trouver fichier programme files %crystaldisqueinfo% Disque.exe
j'ai essayer pas mal de fois de insatller et dessinatles ses porammes mais

est ce que la formatage de pc est elle la meilleur solution
![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Rapport de ZHPDiag v1.30.13 par Nicolas Coolman, Update du 19/04/2012
Run by dell at 20/04/2012 21:22:42
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Web site : http://nicolascoolman.skyrock.com/
State : Nouvelle version disponible
---\\ Web Browser
MSIE: Internet Explorer v8.0.7600.16385
OPIE: Opera v11.10
---\\ Windows Product Information
~ Langage: Français
Windows 7 Business Edition, 64-bit (Build 7600)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 733WD
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ System Information
~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4078 MB (71% free)
System Restore: Activé (Enable)
System drive C: has 135 GB (69%) free of 195 GB
---\\ Logged in mode
~ Computer Name: DELL-PC
~ User Name: dell
~ All Users Names: dell, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O82,O89
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\dell\AppData\Roaming\
~ %Desktop% : C:\Users\dell\Desktop\
~ %Favorites% : C:\Users\dell\Favorites\
~ %LocalAppData% : C:\Users\dell\AppData\Local\
~ %StartMenu% : C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 135 Go of 195 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 269 Go of 270 Go)
E:\ CD-ROM drive (Not Inserted)
F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
I:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
J:\ Floppy drive, Flash card reader, USB Key (Free 11 Go of 15 Go)
K:\ CD-ROM drive (Not Inserted)
---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyComputer: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Scan Security Center in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.9AAAEC8DAC27AA17B053E6352AD233AE] - (.Microsoft Corporation - Explorateur Windows.) (.31/10/2009 - 07:34:59.) -- C:\Windows\Explorer.exe [2870272]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.B1037F0131C9A010D611F6914E03CD92] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.14/07/2009 - 02:41:56.) -- C:\Windows\System32\wininet.dll [1193472]
[MD5.DA3E2A6FA9660CC75B471530CE88453A] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.28/10/2009 - 07:24:40.) -- C:\Windows\System32\Winlogon.exe [389632]
[MD5.75341574F21E766748732BDF530C74BD] - (.Microsoft Corporation - Bibliothèque de licences.) (.14/07/2009 - 02:41:54.) -- C:\Windows\System32\sppcomapi.dll [231936]
[MD5.DB9D6C6B2CD95A9CA414D045B627422E] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:11.) -- C:\Windows\system32\Drivers\AFD.sys [499200]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.83D2D75E1EFB81B3450C18131443F7DB] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.14/07/2009 - 00:19:54.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9C253CE7311CA60FC11C774692A13208] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.27/04/2011 - 03:57:40.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.0A49913402747A0B67DE940FB42CBDBB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.14/07/2009 - 01:06:13.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.040D62A9D8AD28922632137ACDD984F2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.04/05/2011 - 03:51:08.) -- C:\Windows\system32\Drivers\MRxSmb.sys [157696]
[MD5.9162B273A44AB9DCE5B44362731D062A] - (.Microsoft Corporation - MBT Transport driver.) (.14/07/2009 - 00:21:29.) -- C:\Windows\system32\Drivers\netBT.sys [259072]
[MD5.356698A13C4630D5B31C37378D469196] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.14/07/2009 - 02:48:27.) -- C:\Windows\system32\Drivers\ntfs.sys [1659984]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.87A6E852A22991580D6D39ADC4790463] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 01:10:12.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [130048]
[MD5.9706B84DBABFC4B4CA46C5A82B14DFA3] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.14/07/2009 - 01:18:02.) -- C:\Windows\system32\Drivers\rdpdr.sys [165376]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.079125C4B17B01FCAEEBCE0BCB290C0F] - (.Microsoft Corporation - TDI Translation Driver.) (.14/07/2009 - 00:21:15.) -- C:\Windows\system32\Drivers\tdx.sys [99840]
[MD5.58F82EED8CA24B461441F9C3E4F0BF5C] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.14/07/2009 - 02:45:55.) -- C:\Windows\system32\Drivers\volsnap.sys [294992]
~ Scan Generic Processes in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : Non accessible (Not found)
~ Mes Videos (My Videos) : Non accessible (Not found)
~ Mes Favoris (My Favorites) : 2/18
~ Mes Documents (My Documents) : 1/179
~ Mon Bureau (My Desktop) : 7/479
~ Menu demarrer (Programs) : 6/39
~ Scan Hidden Files in 00mn 00s
---\\ Processus lancés
[MD5.A1F86A5A0DA1BEC12B7DD19C6234BB15] - (...) -- C:\Users\dell\Local Settings\Apps\F.lux\flux.exe [966656] [PID.]
[MD5.25B2E79C22171A84B1A4C339C3DA5DF7] - (.Avira Operations GmbH & Co. KG - Avira System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [258512] [PID.]
[MD5.4C94AA41D8136726E07113780D90B887] - (...) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [4506624] [PID.]
[MD5.D2CA88EDB24BB59A830EB2D404C1915C] - (.Avira Operations GmbH & Co. KG - Avira Scheduler.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224] [PID.]
[MD5.DBB40B2415E5422C12C9976A1F50E68B] - (.Avira Operations GmbH & Co. KG - Avira On-Access Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032] [PID.]
[MD5.73686FE0B2E0469F89FD2075BE724704] - (.Apple Computer, Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376] [PID.]
[MD5.B0BCA3B6A95D02287BB9A48224E39B5A] - (.Avira Operations GmbH & Co. KG - Avira MailGuard Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [342480] [PID.]
~ Scan Processes Running in 00mn 00s
---\\ Opera, Plugins,Démarrage,Recherche (P1,B0,B1)
P1 - OPN:Opera Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPOFF12.DLL
P1 - OPN:Opera Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Opera\Program\Plugins\NPOFF12.DLL
~ Scan Opera Browser in 00mn 00s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\dell\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default] None
G0 - GCSP: Preference [User Data\Default][HomePage] http://www.google.com
G2 - GCE: Preference [User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] AdBlock v.2.5.31 (Activé)
~ Scan Google Browser in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
M3 - MFPP: Plugins - [dell] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\avg-secure-search.xml
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\np-mswmp.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.5.1".) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\NPSWF32.dll
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems, Inc. - Adobe Flash Player Helper 9.0 r45.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\NPSWF32_FlashUtil.exe
P2 - FPN: [HKLM] [@ma-config.com/HardwareDetection] - (.Cybelsoft - Plugin NPAPI Ma-Config.com # win64 # 5.2.2.0.) -- C:\Program Files\ma-config.com\x64\nphardwaredetection.dll
P2 - FPN: [HKLM] [@microsoft.com/OfficeAuthz,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\Program Files\Microsoft Office\Office14\NPAUTHZ.dll
~ Scan Firefox Browser in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\SysWOW64\ieframe.dll
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0
~ Scan IE Browser in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s
---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Scan Keys in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 21
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office\Office14\URLREDIR.dll
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub [64Bits] - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.dll
~ Scan BHO in 00mn 00s
---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [F.lux] . (...) -- C:\Users\dell\Local Settings\Apps\F.lux\flux.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Wow6432Node\Run: [AMD AVT] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\Cmd.exe
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-21-3990501594-3456977767-1360621759-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-21-3990501594-3456977767-1360621759-1000\..\Run: [F.lux] . (...) -- C:\Users\dell\Local Settings\Apps\F.lux\flux.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
~ Scan Application in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Logon Background Changer.lnk . (...) -- C:\Users\dell\AppData\Roaming\Microsoft\Installer\{3EBEF7BA-49A1-4EF5-9F42-1FF9644F8F37}\_B7A2742D5F53377685E428.e
O4 - Global Startup: C:\Users\dell\Desktop\Connexion réseau sans fil - Raccourci.lnk - Clé orpheline
O4 - Global Startup: C:\Users\dell\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 7.lnk . (.ashampoo Technology GmbH & Co. KG.) -- C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 7\burningstudio.exe
O4 - Global Startup: C:\Users\dell\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Scan Global Startup in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ Scan IE Control Panel in 00mn 00s
---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: &Envoyer à OneNote . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files (x86)\MICROS~1\Office14\ONBttnIE.dll
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Excel.) -- C:\Program Files (x86)\MICROS~1\Office14\EXCEL.exe
O8 - Extra context menu item: Télécharger avec IDM . (...) -- C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM . (...) -- C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
~ Scan IE Menu Contextuel in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~1\Office14\ONBttnIE.dll
O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~1\Office14\ONBTTN~1.dll
~ Scan IE Extra Buttons in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Computer, Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll
~ Scan Winsock in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{9FAB96E7-A5FE-4AF1-9511-C1CE5988D20C}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{C883C75D-C813-43FF-94CC-250817483E02}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{9FAB96E7-A5FE-4AF1-9511-C1CE5988D20C}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{C883C75D-C813-43FF-94CC-250817483E02}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{9FAB96E7-A5FE-4AF1-9511-C1CE5988D20C}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{C883C75D-C813-43FF-94CC-250817483E02}: DhcpNameServer = 192.168.1.1
~ Scan Domain in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: skype4com [64Bits] - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype for COM API.) -- C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: deflate [64Bits] - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Filter: gzip [64Bits] - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll
~ Scan Protocole Additionnel in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe
O23 - Service: Avira Mail Protection (AntiVirMailService) . (.Avira Operations GmbH & Co. KG - Avira MailGuard Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Avira Scheduler.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG - Avira On-Access Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB (Bonjour Service) . (.Apple Computer, Inc. - Bonjour Service.) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) . (...) - D:\tuneup2012\TuneUpUtilitiesService64.exe (.not file.)
~ Scan Services in 00mn 00s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s
---\\ BootExecute (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ Scan Keys in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\SystemToolsDailyTest.job
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.0F334B40D2D274E2CA5E5A61BC70BD27] [APT] [PCDEventLauncher] (.PC-Doctor, Inc..) -- C:\Program Files\Dell Support Center\sessionchecker.exe
[MD5.229122522D455B2B2B0BE57C5716B7DF] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\Dell Support Center\uaclauncher.exe
[MD5.229122522D455B2B2B0BE57C5716B7DF] [APT] [SystemToolsDailyTest] (.PC-Doctor, Inc..) -- C:\Program Files\Dell Support Center\uaclauncher.exe
[MD5.00000000000000000000000000000000] [APT] [TuneUpUtilities_Task_BkGndMaintenance2012] (...) -- D:\tuneup2012\OneClick.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [{06247684-C6EB-4CA6-B176-F19C803CA934}] (...) -- C:\Program Files (x86)\TuneUp Utilities 2012\Integrator.exe (.not file.)
~ Scan Scheduled Task in 00mn 00s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Internet Explorer [64Bits] - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Browser Customizations [64Bits] - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\System32\iedkcs32.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\System32\wmp.dll
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Scan Active Setup in 00mn 00s
---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (avipbb) . (.Avira GmbH - Avira Driver for Security Enhancement.) - C:\Windows\System32\DRIVERS\avipbb.sys
O41 - Driver: (avkmgr) . (.Avira GmbH - Avira Manager Driver.) - C:\Windows\System32\DRIVERS\avkmgr.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\System32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (dtsoftbus01) . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) - C:\Windows\System32\DRIVERS\dtsoftbus01.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
O41 - Driver: Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0 (ws2ifsl) . (.Microsoft Corporation - Couche IFS Winsock2.) - C:\Windows\system32\drivers\ws2ifsl.sys
~ Scan Drivers in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: AHV content for Acrobat and Flash - (.Adobe Systems Incorporated.) [HKLM] -- {6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
O42 - Logiciel: AMD APP SDK Runtime - (.Advanced Micro Devices Inc..) [HKLM] -- {503F672D-6C84-448A-8F8F-4BC35AC83441}
O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM] -- {3987279A-3504-2916-D063-741B910F0747}
O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM] -- {90CB2C55-426D-0752-968D-9B0F1110202A}
O42 - Logiciel: AMD Drag and Drop Transcoding - (.Advanced Micro Devices, Inc..) [HKLM] -- {06DB2C4C-DC29-DA42-3B00-5581CBF545BB}
O42 - Logiciel: AMD Media Foundation Decoders - (.Advanced Micro Devices, Inc..) [HKLM] -- {7C5CAFD6-F51C-0011-410B-001EF3E342A7}
O42 - Logiciel: ATI AVIVO64 Codecs - (.ATI Technologies Inc..) [HKLM] -- {83CB95E0-5518-AAC2-9B63-1FDBB4D51263}
O42 - Logiciel: Adobe Anchor Service CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {90176341-0A8B-4CCC-A78D-F862228A6B95}
O42 - Logiciel: Adobe Asset Services CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
O42 - Logiciel: Adobe Bridge CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {9C9824D9-9000-4373-A6A5-D0E5D4831394}
O42 - Logiciel: Adobe Bridge Start Meeting - (.Adobe Systems Incorporated.) [HKLM] -- {08B32819-6EEF-4057-AEDA-5AB681A36A23}
O42 - Logiciel: Adobe BridgeTalk Plugin CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
O42 - Logiciel: Adobe CMaps - (.Adobe Systems Incorporated.) [HKLM] -- {A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
O42 - Logiciel: Adobe Camera Raw 4.0 - (.Adobe Systems Incorporated.) [HKLM] -- {B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
O42 - Logiciel: Adobe Color - Photoshop Specific - (.Adobe Systems Incorporated.) [HKLM] -- {A2D81E70-2A98-4A08-A628-94388B063C5E}
O42 - Logiciel: Adobe Color Common Settings - (.Adobe Systems Incorporated.) [HKLM] -- {DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
O42 - Logiciel: Adobe Color EU Recommended Settings - (.Adobe Systems Incorporated.) [HKLM] -- {73B5D990-04EA-4751-B10F-5534770B91F2}
O42 - Logiciel: Adobe Color JA Extra Settings - (.Adobe Systems Incorporated.) [HKLM] -- {DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
O42 - Logiciel: Adobe Color NA Extra Settings - (.Adobe Systems Incorporated.) [HKLM] -- {FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
O42 - Logiciel: Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM] -- {B1EF7B00-8FCC-4209-BFB6-37C50B354B2A}
O42 - Logiciel: Adobe Default Language CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
O42 - Logiciel: Adobe Device Central CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
O42 - Logiciel: Adobe Dreamweaver CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {4BDB76C6-902E-41D5-9064-68768E02886B}
O42 - Logiciel: Adobe ExtendScript Toolkit 2 - (.Adobe Systems Incorporated.) [HKLM] -- {C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
O42 - Logiciel: Adobe Extension Manager CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {BE5F3842-8309-4754-92D5-83E02E6077A3}
O42 - Logiciel: Adobe Flash Player 9 ActiveX - (.Adobe Systems, Inc..) [HKLM] -- {BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
O42 - Logiciel: Adobe Flash Player 9 Plugin - (.Adobe Systems, Inc..) [HKLM] -- {88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {6ABE0BEE-D572-4FE8-B434-9E72A289431B}
O42 - Logiciel: Adobe Help Viewer CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {7ACFB90E-8FD0-4397-AD3A-5195412623A3}
O42 - Logiciel: Adobe InDesign CS3 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
O42 - Logiciel: Adobe Linguistics CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {54793AA1-5001-42F4-ABB6-C364617C6078}
O42 - Logiciel: Adobe MotionPicture Color Files - (.Adobe Systems Incorporated.) [HKLM] -- {6B708481-748A-4EB4-97C1-CD386244FF77}
O42 - Logiciel: Adobe PDF Library Files - (.Adobe Systems Incorporated.) [HKLM] -- {D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
O42 - Logiciel: Adobe Photoshop CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {C1FA4B3B-1625-4922-9C9D-780E8FCE161A}
O42 - Logiciel: Adobe Reader 9.5.1 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A95000000001}
O42 - Logiciel: Adobe SING CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B671CBFD-4109-4D35-9252-3062D3CCB7B2}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {9D3F3D5A-BE6D-48C4-B51E-E2D6753ABCDE}
O42 - Logiciel: Adobe Stock Photos CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {29E5EA97-5F74-4A57-B8B2-D4F169117183}
O42 - Logiciel: Adobe Type Support - (.Adobe Systems Incorporated.) [HKLM] -- {8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
O42 - Logiciel: Adobe Update Manager CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {E69AE897-9E0B-485C-8552-7841F48D42D8}
O42 - Logiciel: Adobe Version Cue CS3 Client - (.Adobe Systems Incorporated.) [HKLM] -- {D0DFF92A-492E-4C40-B862-A74A173C25C5}
O42 - Logiciel: Adobe WAS CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {C5BD220A-EFE8-48A5-B70E-9503D535FACE}
O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
O42 - Logiciel: Adobe XMP Panels CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {D5A31AB1-345D-47C7-A87B-036A669F6DF1}
O42 - Logiciel: Ajouter ou supprimer Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_e79070e1ef25043cbd93191267ecaf0
O42 - Logiciel: Ashampoo Burning Studio 7.21 - (.ashampoo GmbH & Co. KG.) [HKLM] -- Ashampoo Burning Studio 7_is1
O42 - Logiciel: Avira Antivirus Premium 2012 - (.Avira.) [HKLM] -- Avira AntiVir Desktop
O42 - Logiciel: BurnInTest v7.0 Standard - (.Passmark Software.) [HKLM] -- BurnInTest_is1
O42 - Logiciel: CPUID CPU-Z 1.59 - (.Pas de propriétaire.) [HKLM] -- CPUID CPU-Z_is1
O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM] -- {BBC2068D-CE9C-48F5-A6EA-4B44B9DB14A5}
O42 - Logiciel: CrystalDiskInfo 4.6.0 - (.Crystal Dew World.) [HKLM] -- CrystalDiskInfo_is1
O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM] -- DAEMON Tools Lite
O42 - Logiciel: Dell Support Center - (.Dell Inc..) [HKLM] -- Dell Support Center
O42 - Logiciel: Dell Support Center - (.PC-Doctor, Inc..) [HKLM] -- {0090A87C-3E0E-43D4-AA71-A71B06563A4A}
O42 - Logiciel: DriverMax 6 - (.Innovative Solutions.) [HKLM] -- DMX5_is1
O42 - Logiciel: EVEREST Home Edition v2.20 - (.Lavalys Inc.) [HKLM] -- EVEREST Home Edition_is1
O42 - Logiciel: F.lux - (.Pas de propriétaire.) [HKCU] -- Flux
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: HDD Health v3.3 Beta - (.Pas de propriétaire.) [HKLM] -- HDD Health_is1
O42 - Logiciel: Internet Download Manager - (.Pas de propriétaire.) [HKLM] -- Internet Download Manager
O42 - Logiciel: LinuxLive USB Creator - (.Thibaut Lauziere.) [HKLM] -- LinuxLive USB Creator
O42 - Logiciel: Ma-Config.com (64 bits) - (.Cybelsoft.) [HKLM] -- {812489B5-A2A9-474B-9BE7-55410E0E1DB4}
O42 - Logiciel: Macromedia Dreamweaver 8 - (..) [HKLM] -- {5FD788ED-1A37-4496-9BDD-463F493B27FA}
O42 - Logiciel: Macromedia Extension Manager - (.Nom de votre société.) [HKLM] -- {3C8C9FB3-5FDF-40B4-B314-EAD722728C76}
O42 - Logiciel: Malwarebytes Anti-Malware version 1.60.1.1000 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile FRA Language Pack - (.Microsoft Corporation.) [HKLM] -- {4B5F58F7-C7D1-3CE3-9B37-B657F0852643}
O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Extended
O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}
O42 - Logiciel: Microsoft .NET Framework 4 Extended FRA Language Pack - (.Microsoft Corporation.) [HKLM] -- {A39AE3AE-9808-39D2-AB7B-FF5F0335095E}
O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Access MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0015-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Excel MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Office 64-bit Components 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002A-0000-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Office 64-bit Components 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002A-0000-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office OneNote MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Professionnel 2010 - (.Microsoft Corporation.) [HKLM] -- Office14.SingleImage
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Dutch) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0413-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (German) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0407-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002A-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002A-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Single Image 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-003D-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
O42 - Logiciel: Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 - (.Microsoft Corporation.) [HKLM] -- {DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
O42 - Logiciel: Module linguistique Microsoft .NET Framework 4 Client Profile FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile FRA Language Pack
O42 - Logiciel: Module linguistique Microsoft .NET Framework 4 Extended FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Extended FRA Language Pack
O42 - Logiciel: Nero 7 Premium - (.Nero AG.) [HKLM] -- {4908C75E-E5E2-43F7-B1DF-023CBA831036}
O42 - Logiciel: OCCT 4.0.0 - (.Ocbase.com.) [HKLM] -- OCCT
O42 - Logiciel: Opera 11.10 - (.Opera Software ASA.) [HKLM] -- Opera 11.10.2092
O42 - Logiciel: PDF Settings - (.Adobe Systems Incorporated.) [HKLM] -- {AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
O42 - Logiciel: Pro Evolution Soccer 2012 - (.KONAMI.) [HKLM] -- {E737A098-F161-4B6F-AF22-86AAE34F6FBD}
O42 - Logiciel: Revo Uninstaller 1.93 - (.VS Revo Group.) [HKLM] -- Revo Uninstaller
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2518870
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2572078
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2633870
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2656351
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Extended (KB2487367) - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2487367
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Extended (KB2656351) - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2656351
O42 - Logiciel: Security Update for Module linguistique Microsoft .NET Framework 4 Client Profile FRA (KB2518870) - (.Microsoft Corporation.) [HKLM] -- {4B5F58F7-C7D1-3CE3-9B37-B657F0852643}.KB2518870
O42 - Logiciel: Skype™ 4.0 - (.Skype Technologies S.A..) [HKLM] -- {24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
O42 - Logiciel: TeraCopy 2.27 - (.Code Sector.) [HKLM] -- TeraCopy_is1
O42 - Logiciel: VLC media player 1.0.1 - (.VideoLAN Team.) [HKLM] -- VLC media player
O42 - Logiciel: WhoCrashed 3.04 - (.Resplendence Software Projects Sp..) [HKLM] -- WhoCrashed_is1
O42 - Logiciel: WinRAR 4.11 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver
O42 - Logiciel: Windows 7 Logon Background Changer - (.Julien MANICI.) [HKLM] -- {3EBEF7BA-49A1-4EF5-9F42-1FF9644F8F37}
O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
O42 - Logiciel: µTorrent - (.Pas de propriétaire.) [HKLM] -- uTorrent
---\\ HKCU & HKLM Software Keys
[HKCU\Software\1ClickDownload]
[HKCU\Software\ALWIL Software]
[HKCU\Software\AMD]
[HKCU\Software\ATI]
[HKCU\Software\AVAST Software]
[HKCU\Software\Adobe]
[HKCU\Software\Ahead]
[HKCU\Software\AppDataLow\Software\PriceGong]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Ashampoo]
[HKCU\Software\Avira]
[HKCU\Software\BitTorrent]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Code Sector]
[HKCU\Software\DT Soft]
[HKCU\Software\DownloadManager]
[HKCU\Software\Google]
[HKCU\Software\IGearSettings]
[HKCU\Software\IncrediMail]
[HKCU\Software\Innovative Solutions]
[HKCU\Software\Lavalys]
[HKCU\Software\LinuxLive]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\Michael Herf]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\Opera Software]
[HKCU\Software\Policies]
[HKCU\Software\Resplendence Sp]
[HKCU\Software\Skype]
[HKCU\Software\SysInternals]
[HKCU\Software\TAdvCheckList]
[HKCU\Software\TuneUp]
[HKCU\Software\Usbfix]
[HKCU\Software\VB and VBA Program Settings]
[HKCU\Software\VSRevoGroup]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Wow6432Node]
[HKCU\Software\cybelsoft]
[HKCU\Software\drpsu]
[HKLM\Software\AMD]
[HKLM\Software\ATI Technologies]
[HKLM\Software\ATI]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Ashampoo]
[HKLM\Software\Avira]
[HKLM\Software\Bunndle]
[HKLM\Software\CPUID]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Code Sector]
[HKLM\Software\Conduit]
[HKLM\Software\DT Soft]
[HKLM\Software\Dell]
[HKLM\Software\Eset]
[HKLM\Software\Google]
[HKLM\Software\Innovative Solutions]
[HKLM\Software\Intel]
[HKLM\Software\KONAMI]
[HKLM\Software\Khronos]
[HKLM\Software\Licenses]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\MimarSinan]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Nero]
[HKLM\Software\Netscape]
[HKLM\Software\ODBC]
[HKLM\Software\OldTimer Tools]
[HKLM\Software\Opera Software]
[HKLM\Software\PC-Doctor]
[HKLM\Software\Policies]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Safer Networking Limited]
[HKLM\Software\Skype]
[HKLM\Software\Sonic]
[HKLM\Software\TuneUp]
[HKLM\Software\Uniblue]
[HKLM\Software\VideoLAN]
[HKLM\Software\Volatile]
[HKLM\Software\WinRAR]
[HKLM\Software\Wow6432Node]
[HKLM\Software\X-AVCSD]
[HKLM\Software\ahead]
[HKLM\Software\cybelsoft]
[HKLM\Software\mozilla.org]
~ Scan Softwares in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 16/04/2012 - 19:51:14 - [833,540] ----D C:\Program Files (x86)\Adobe
O43 - CFD: 07/04/2012 - 12:49:02 - [2,324] ----D C:\Program Files (x86)\AMD APP
O43 - CFD: 07/04/2012 - 12:57:27 - [5,936] ----D C:\Program Files (x86)\AMD AVT
O43 - CFD: 07/04/2012 - 09:39:59 - [53,275] ----D C:\Program Files (x86)\Ashampoo
O43 - CFD: 05/04/2012 - 17:35:37 - [62,727] ----D C:\Program Files (x86)\ATI Technologies
O43 - CFD: 11/04/2012 - 14:51:26 - [0] ----D C:\Program Files (x86)\Auralog
O43 - CFD: 11/04/2012 - 11:57:15 - [177,470] ----D C:\Program Files (x86)\Avira
O43 - CFD: 07/04/2012 - 09:50:33 - [0,309] ----D C:\Program Files (x86)\Bonjour
O43 - CFD: 06/04/2012 - 17:09:28 - [16,254] ----D C:\Program Files (x86)\BurnInTest
O43 - CFD: 20/04/2012 - 16:47:32 - [1080,281] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 20/04/2012 - 17:58:33 - [2,913] ----D C:\Program Files (x86)\CrystalDiskInfo
O43 - CFD: 11/04/2012 - 14:49:19 - [24,755] ----D C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD: 06/04/2012 - 09:31:39 - [222,266] ----D C:\Program Files (x86)\EasyPHP-5.3.8.0
O43 - CFD: 14/04/2012 - 23:15:19 - [0,198] ----D C:\Program Files (x86)\fbphotozoom
O43 - CFD: 05/04/2012 - 09:10:15 - [5,305] ----D C:\Program Files (x86)\Google
O43 - CFD: 18/04/2012 - 14:12:59 - [2,767] ----D C:\Program Files (x86)\HDD Health
O43 - CFD: 11/04/2012 - 00:24:28 - [14,313] ----D C:\Program Files (x86)\Innovative Solutions
O43 - CFD: 06/04/2012 - 21:24:29 - [9,248] ----D C:\Program Files (x86)\Internet Download Manager
O43 - CFD: 05/04/2012 - 16:03:50 - [4,263] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 14/04/2012 - 18:44:20 - [0,374] ----D C:\Program Files (x86)\Julien MANICI
O43 - CFD: 07/04/2012 - 10:33:02 - [-786,721] ----D C:\Program Files (x86)\KONAMI
O43 - CFD: 11/04/2012 - 23:27:45 - [6,498] ----D C:\Program Files (x86)\Lavalys
O43 - CFD: 19/04/2012 - 22:51:32 - [84,164] ----D C:\Program Files (x86)\LinuxLive USB Creator
O43 - CFD: 06/04/2012 - 14:28:19 - [154,214] ----D C:\Program Files (x86)\Macromedia
O43 - CFD: 06/04/2012 - 23:05:33 - [11,417] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 20/04/2012 - 16:44:27 - [38,002] ----D C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 20/04/2012 - 16:47:26 - [1236,597] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 05/04/2012 - 09:29:34 - [0,014] ----D C:\Program Files (x86)\Microsoft Visual Studio
O43 - CFD: 05/04/2012 - 09:27:57 - [1,323] ----D C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD: 05/04/2012 - 09:29:41 - [3,032] ----D C:\Program Files (x86)\Microsoft Works
O43 - CFD: 07/04/2012 - 19:40:10 - [7,797] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 17/04/2012 - 16:41:36 - [2,959] ----D C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 05/04/2012 - 09:29:36 - [0,025] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 05/04/2012 - 10:18:18 - [352,282] ----D C:\Program Files (x86)\Nero
O43 - CFD: 07/04/2012 - 13:51:59 - [18,017] ----D C:\Program Files (x86)\OCCTPT
O43 - CFD: 05/04/2012 - 09:25:08 - [30,232] ----D C:\Program Files (x86)\Opera
O43 - CFD: 14/07/2009 - 06:32:38 - [36,809] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 17/04/2012 - 08:08:11 - [0,001] ----D C:\Program Files (x86)\Seagate
O43 - CFD: 05/04/2012 - 09:25:16 - [26,829] R---D C:\Program Files (x86)\Skype
O43 - CFD: 11/04/2012 - 17:30:04 - [2,214] ----D C:\Program Files (x86)\Spybot - Search & Destroy
O43 - CFD: 08/04/2012 - 10:27:37 - [0,101] ----D C:\Program Files (x86)\stinger
O43 - CFD: 20/04/2012 - 18:46:42 - [0] ----D C:\Program Files (x86)\Uniblue
O43 - CFD: 14/07/2009 - 05:57:06 - [0] ----D C:\Program Files (x86)\Uninstall Information
O43 - CFD: 14/04/2012 - 23:18:42 - [0,839] ----D C:\Program Files (x86)\uTorrent
O43 - CFD: 05/04/2012 - 09:25:24 - [71,017] ----D C:\Program Files (x86)\VideoLAN
O43 - CFD: 11/04/2012 - 16:09:45 - [6,502] ----D C:\Program Files (x86)\VS Revo Group
O43 - CFD: 05/04/2012 - 16:03:50 - [0,500] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 16/04/2012 - 23:00:26 - [5,895] ----D C:\Program Files (x86)\Windows Mail
O43 - CFD: 16/04/2012 - 23:00:18 - [4,896] ----D C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - 06:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 05/04/2012 - 16:03:50 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 14/07/2009 - 06:32:40 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 05/04/2012 - 16:03:50 - [6,039] ----D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 06/04/2012 - 14:11:34 - [3,965] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 20/04/2012 - 21:22:44 - [11,404] ----D C:\Program Files (x86)\ZHPDiag
O43 - CFD: 19/04/2012 - 18:47:50 - [6,348] ----D C:\Program Files (x86)\ZHPFix
O43 - CFD: 16/04/2012 - 19:51:14 - [544,630] ----D C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 05/04/2012 - 10:19:06 - [82,715] ----D C:\Program Files (x86)\Common Files\Ahead
O43 - CFD: 20/04/2012 - 14:28:04 - [0] ----D C:\Program Files (x86)\Common Files\AltrixSoft
O43 - CFD: 07/04/2012 - 12:57:23 - [2,704] ----D C:\Program Files (x86)\Common Files\ATI Technologies
O43 - CFD: 20/04/2012 - 16:47:32 - [0,095] ----D C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 06/04/2012 - 14:27:53 - [2,250] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 06/04/2012 - 14:28:47 - [0,957] ----D C:\Program Files (x86)\Common Files\Macromedia
O43 - CFD: 07/04/2012 - 09:43:18 - [0,625] ----D C:\Program Files (x86)\Common Files\Macrovision Shared
O43 - CFD: 20/04/2012 - 16:47:49 - [363,362] ----D C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 14/07/2009 - 04:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 05/04/2012 - 09:25:16 - [1,853] ----D C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 14/07/2009 - 04:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 16/04/2012 - 23:00:29 - [41,888] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 15/04/2012 - 18:35:39 - [125,516] ----D C:\ProgramData\Adobe
O43 - CFD: 20/04/2012 - 12:55:29 - [0] ----D C:\ProgramData\AltrixSoft
O43 - CFD: 05/04/2012 - 09:09:46 - [11,449] ----D C:\ProgramData\Alwil Software
O43 - CFD: 07/04/2012 - 12:57:28 - [14,843] ----D C:\ProgramData\AMD
O43 - CFD: 14/07/2009 - 06:08:56 - [0] ----D C:\ProgramData\Application Data
O43 - CFD: 07/04/2012 - 09:40:05 - [0,314] ----D C:\ProgramData\ashampoo
O43 - CFD: 07/04/2012 - 12:59:19 - [0,000] ----D C:\ProgramData\ATI
O43 - CFD: 11/04/2012 - 11:57:23 - [62,590] ----D C:\ProgramData\Avira
O43 - CFD: 04/04/2012 - 19:57:15 - [0] ----D C:\ProgramData\Bureau
O43 - CFD: 05/04/2012 - 21:50:23 - [0,000] ----D C:\ProgramData\Common Files
O43 - CFD: 11/04/2012 - 14:49:01 - [0,001] ----D C:\ProgramData\DAEMON Tools Lite
O43 - CFD: 18/04/2012 - 12:22:30 - [0,215] ----D C:\ProgramData\Dell
O43 - CFD: 14/07/2009 - 06:08:56 - [0] ----D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:08:56 - [0] ----D C:\ProgramData\Documents
O43 - CFD: 04/04/2012 - 19:57:15 - [0] ----D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 06:08:56 - [0] ----D C:\ProgramData\Favorites
O43 - CFD: 06/04/2012 - 21:47:12 - [0,014] ----D C:\ProgramData\FLEXnet
O43 - CFD: 07/04/2012 - 10:33:02 - [43,596] ----D C:\ProgramData\KONAMI
O43 - CFD: 05/04/2012 - 21:42:31 - [1,291] ----D C:\ProgramData\ma-config.com
O43 - CFD: 06/04/2012 - 14:28:19 - [0,002] ----D C:\ProgramData\Macromedia
O43 - CFD: 06/04/2012 - 23:05:32 - [16,189] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 04/04/2012 - 19:57:16 - [0] ----D C:\ProgramData\Menu Démarrer
O43 - CFD: 20/04/2012 - 16:45:33 - [192,727] -S--D C:\ProgramData\Microsoft
O43 - CFD: 20/04/2012 - 16:49:00 - [0,075] ----D C:\ProgramData\Microsoft Help
O43 - CFD: 04/04/2012 - 19:57:16 - [0] ----D C:\ProgramData\Modèles
O43 - CFD: 05/04/2012 - 10:18:18 - [2,708] ----D C:\ProgramData\Nero
O43 - CFD: 11/04/2012 - 17:31:25 - [0,006] ----D C:\ProgramData\Norton
O43 - CFD: 06/04/2012 - 17:09:28 - [0,001] ----D C:\ProgramData\PassMark
O43 - CFD: 20/04/2012 - 02:29:22 - [15,361] ----D C:\ProgramData\PCDr
O43 - CFD: 05/04/2012 - 09:25:16 - [19,108] ----D C:\ProgramData\Skype
O43 - CFD: 11/04/2012 - 17:30:03 - [0,020] ----D C:\ProgramData\Spybot - Search & Destroy
O43 - CFD: 14/07/2009 - 06:08:56 - [0] ----D C:\ProgramData\Start Menu
O43 - CFD: 14/07/2009 - 06:08:56 - [0] ----D C:\ProgramData\Templates
O43 - CFD: 11/04/2012 - 17:52:54 - [6,898] ----D C:\ProgramData\TuneUp Software
O43 - CFD: 06/04/2012 - 22:23:51 - [22,936] -S--D C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
O43 - CFD: 20/04/2012 - 18:45:41 - [0,022] ----D C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
O43 - CFD: 15/04/2012 - 12:16:18 - [8,482] ----D C:\Users\dell\AppData\Roaming\Adobe
O43 - CFD: 07/04/2012 - 10:28:48 - [0,043] ----D C:\Users\dell\AppData\Roaming\Ahead
O43 - CFD: 07/04/2012 - 09:40:29 - [0,211] ----D C:\Users\dell\AppData\Roaming\Ashampoo
O43 - CFD: 05/04/2012 - 17:39:05 - [0] ----D C:\Users\dell\AppData\Roaming\ATI
O43 - CFD: 11/04/2012 - 11:58:36 - [0] ----D C:\Users\dell\AppData\Roaming\Avira
O43 - CFD: 11/04/2012 - 14:50:52 - [0,842] ----D C:\Users\dell\AppData\Roaming\DAEMON Tools Lite
O43 - CFD: 16/04/2012 - 01:05:22 - [0,004] ----D C:\Users\dell\AppData\Roaming\Dell
O43 - CFD: 20/04/2012 - 20:06:24 - [0] ----D C:\Users\dell\AppData\Roaming\DMCache
O43 - CFD: 11/04/2012 - 17:09:40 - [0] ----D C:\Users\dell\AppData\Roaming\GetRightToGo
O43 - CFD: 04/04/2012 - 19:57:49 - [0] ----D C:\Users\dell\AppData\Roaming\Identities
O43 - CFD: 12/04/2012 - 15:35:13 - [106,079] ----D C:\Users\dell\AppData\Roaming\IDM
O43 - CFD: 06/04/2012 - 14:29:50 - [2,144] ----D C:\Users\dell\AppData\Roaming\Macromedia
O43 - CFD: 06/04/2012 - 23:05:37 - [0,305] ----D C:\Users\dell\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 08:45:37 - [0] ----D C:\Users\dell\AppData\Roaming\Media Center Programs
O43 - CFD: 17/04/2012 - 18:02:59 - [2,223] -S--D C:\Users\dell\AppData\Roaming\Microsoft
O43 - CFD: 05/04/2012 - 09:25:09 - [0,208] ----D C:\Users\dell\AppData\Roaming\Opera
O43 - CFD: 16/04/2012 - 00:58:42 - [62,403] ----D C:\Users\dell\AppData\Roaming\PCDr
O43 - CFD: 20/04/2012 - 15:14:38 - [0,030] ----D C:\Users\dell\AppData\Roaming\RegistryKeys
O43 - CFD: 19/04/2012 - 00:18:51 - [1,629] ----D C:\Users\dell\AppData\Roaming\Skype
O43 - CFD: 19/04/2012 - 00:15:15 - [0,026] ----D C:\Users\dell\AppData\Roaming\skypePM
O43 - CFD: 07/04/2012 - 10:19:02 - [0,045] ----D C:\Users\dell\AppData\Roaming\TeraCopy
O43 - CFD: 06/04/2012 - 22:24:17 - [0,108] ----D C:\Users\dell\AppData\Roaming\TuneUp Software
O43 - CFD: 20/04/2012 - 18:51:33 - [1,355] ----D C:\Users\dell\AppData\Roaming\uTorrent
O43 - CFD: 08/04/2012 - 00:15:18 - [0,456] ----D C:\Users\dell\AppData\Roaming\vlc
O43 - CFD: 06/04/2012 - 14:11:45 - [0,000] ----D C:\Users\dell\AppData\Roaming\WinRAR
O43 - CFD: 17/04/2012 - 16:45:11 - [154,252] ----D C:\Users\dell\AppData\Local\Adobe
O43 - CFD: 05/04/2012 - 19:00:34 - [0,023] ----D C:\Users\dell\AppData\Local\Ahead
O43 - CFD: 04/04/2012 - 19:57:22 - [0] ----D C:\Users\dell\AppData\Local\Application Data
O43 - CFD: 13/04/2012 - 22:13:49 - [1,559] ----D C:\Users\dell\AppData\Local\Apps
O43 - CFD: 07/04/2012 - 09:40:05 - [0,314] ----D C:\Users\dell\AppData\Local\ashampoo
O43 - CFD: 05/04/2012 - 17:39:05 - [0,064] ----D C:\Users\dell\AppData\Local\ATI
O43 - CFD: 17/04/2012 - 20:35:40 - [4,229] ----D C:\Users\dell\AppData\Local\CrashDumps
O43 - CFD: 11/04/2012 - 17:42:35 - [2,787] ----D C:\Users\dell\AppData\Local\Diagnostics
O43 - CFD: 16/04/2012 - 01:03:36 - [0,817] ----D C:\Users\dell\AppData\Local\ElevatedDiagnostics
O43 - CFD: 11/04/2012 - 23:25:00 - [0,003] ----D C:\Users\dell\AppData\Local\Facebook
O43 - CFD: 05/04/2012 - 21:27:50 - [767,800] ----D C:\Users\dell\AppData\Local\Google
O43 - CFD: 04/04/2012 - 19:57:22 - [0] ----D C:\Users\dell\AppData\Local\Historique
O43 - CFD: 14/04/2012 - 18:44:41 - [0,000] ----D C:\Users\dell\AppData\Local\http___www.julien-manici
O43 - CFD: 05/04/2012 - 21:53:20 - [57,205] ----D C:\Users\dell\AppData\Local\Innovative Solutions
O43 - CFD: 17/04/2012 - 18:02:59 - [146,182] ----D C:\Users\dell\AppData\Local\Microsoft
O43 - CFD: 05/04/2012 - 09:27:40 - [0] ----D C:\Users\dell\AppData\Local\Microsoft Help
O43 - CFD: 05/04/2012 - 16:05:57 - [0] ----D C:\Users\dell\AppData\Local\Mozilla
O43 - CFD: 11/04/2012 - 17:39:52 - [4,518] ----D C:\Users\dell\AppData\Local\NPE
O43 - CFD: 07/04/2012 - 13:53:18 - [0,009] ----D C:\Users\dell\AppData\Local\OCCT
O43 - CFD: 05/04/2012 - 09:25:09 - [3,157] ----D C:\Users\dell\AppData\Local\Opera
O43 - CFD: 20/04/2012 - 14:35:08 - [0] ----D C:\Users\dell\AppData\Local\PackageAware
O43 - CFD: 20/04/2012 - 21:22:26 - [700,157] ----D C:\Users\dell\AppData\Local\Temp
O43 - CFD: 04/04/2012 - 19:57:22 - [0] ----D C:\Users\dell\AppData\Local\Temporary Internet Files
O43 - CFD: 10/04/2012 - 19:23:19 - [0,219] ----D C:\Users\dell\AppData\Local\VirtualStore
O43 - CFD: 14/07/2009 - 05:54:32 - [0,014] R---D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 16/04/2012 - 23:02:55 - [0,000] R---D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 13/04/2012 - 22:13:51 - [0,004] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
O43 - CFD: 05/04/2012 - 21:31:02 - [0,004] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 06/04/2012 - 21:24:01 - [0,006] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 19/04/2012 - 22:51:26 - [0,002] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LinuxLive USB Creator
O43 - CFD: 14/07/2009 - 05:49:38 - [0,001] R---D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 07/04/2012 - 13:51:59 - [0] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OCCT
O43 - CFD: 11/04/2012 - 16:09:46 - [0,005] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
O43 - CFD: 19/04/2012 - 01:20:25 - [0] R---D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 06/04/2012 - 14:11:35 - [0,003] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 16/04/2012 - 19:51:14 - [833,540] ----D C:\Program Files (x86)\Adobe
O43 - CFD: 07/04/2012 - 12:49:02 - [2,324] ----D C:\Program Files (x86)\AMD APP
O43 - CFD: 07/04/2012 - 12:57:27 - [5,936] ----D C:\Program Files (x86)\AMD AVT
O43 - CFD: 07/04/2012 - 09:39:59 - [53,275] ----D C:\Program Files (x86)\Ashampoo
O43 - CFD: 05/04/2012 - 17:35:37 - [62,727] ----D C:\Program Files (x86)\ATI Technologies
O43 - CFD: 11/04/2012 - 14:51:26 - [0] ----D C:\Program Files (x86)\Auralog
O43 - CFD: 11/04/2012 - 11:57:15 - [177,470] ----D C:\Program Files (x86)\Avira
O43 - CFD: 07/04/2012 - 09:50:33 - [0,309] ----D C:\Program Files (x86)\Bonjour
O43 - CFD: 06/04/2012 - 17:09:28 - [16,254] ----D C:\Program Files (x86)\BurnInTest
O43 - CFD: 20/04/2012 - 16:47:32 - [1080,281] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 20/04/2012 - 17:58:33 - [2,913] ----D C:\Program Files (x86)\CrystalDiskInfo
O43 - CFD: 11/04/2012 - 14:49:19 - [24,755] ----D C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD: 06/04/2012 - 09:31:39 - [222,266] ----D C:\Program Files (x86)\EasyPHP-5.3.8.0
O43 - CFD: 14/04/2012 - 23:15:19 - [0,198] ----D C:\Program Files (x86)\fbphotozoom
O43 - CFD: 05/04/2012 - 09:10:15 - [5,305] ----D C:\Program Files (x86)\Google
O43 - CFD: 18/04/2012 - 14:12:59 - [2,767] ----D C:\Program Files (x86)\HDD Health
O43 - CFD: 11/04/2012 - 00:24:28 - [14,313] ----D C:\Program Files (x86)\Innovative Solutions
O43 - CFD: 06/04/2012 - 21:24:29 - [9,248] ----D C:\Program Files (x86)\Internet Download Manager
O43 - CFD: 05/04/2012 - 16:03:50 - [4,263] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 14/04/2012 - 18:44:20 - [0,374] ----D C:\Program Files (x86)\Julien MANICI
O43 - CFD: 07/04/2012 - 10:33:02 - [-786,721] ----D C:\Program Files (x86)\KONAMI
O43 - CFD: 11/04/2012 - 23:27:45 - [6,498] ----D C:\Program Files (x86)\Lavalys
O43 - CFD: 19/04/2012 - 22:51:32 - [84,164] ----D C:\Program Files (x86)\LinuxLive USB Creator
O43 - CFD: 06/04/2012 - 14:28:19 - [154,214] ----D C:\Program Files (x86)\Macromedia
O43 - CFD: 06/04/2012 - 23:05:33 - [11,417] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 20/04/2012 - 16:44:27 - [38,002] ----D C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 20/04/2012 - 16:47:26 - [1236,597] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 05/04/2012 - 09:29:34 - [0,014] ----D C:\Program Files (x86)\Microsoft Visual Studio
O43 - CFD: 05/04/2012 - 09:27:57 - [1,323] ----D C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD: 05/04/2012 - 09:29:41 - [3,032] ----D C:\Program Files (x86)\Microsoft Works
O43 - CFD: 07/04/2012 - 19:40:10 - [7,797] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 17/04/2012 - 16:41:36 - [2,959] ----D C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 05/04/2012 - 09:29:36 - [0,025] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 05/04/2012 - 10:18:18 - [352,282] ----D C:\Program Files (x86)\Nero
O43 - CFD: 07/04/2012 - 13:51:59 - [18,017] ----D C:\Program Files (x86)\OCCTPT
O43 - CFD: 05/04/2012 - 09:25:08 - [30,232] ----D C:\Program Files (x86)\Opera
O43 - CFD: 14/07/2009 - 06:32:38 - [36,809] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 17/04/2012 - 08:08:11 - [0,001] ----D C:\Program Files (x86)\Seagate
O43 - CFD: 05/04/2012 - 09:25:16 - [26,829] R---D C:\Program Files (x86)\Skype
O43 - CFD: 11/04/2012 - 17:30:04 - [2,214] ----D C:\Program Files (x86)\Spybot - Search & Destroy
O43 - CFD: 08/04/2012 - 10:27:37 - [0,101] ----D C:\Program Files (x86)\stinger
O43 - CFD: 20/04/2012 - 18:46:42 - [0] ----D C:\Program Files (x86)\Uniblue
O43 - CFD: 14/07/2009 - 05:57:06 - [0] ----D C:\Program Files (x86)\Uninstall Information
O43 - CFD: 14/04/2012 - 23:18:42 - [0,839] ----D C:\Program Files (x86)\uTorrent
O43 - CFD: 05/04/2012 - 09:25:24 - [71,017] ----D C:\Program Files (x86)\VideoLAN
O43 - CFD: 11/04/2012 - 16:09:45 - [6,502] ----D C:\Program Files (x86)\VS Revo Group
O43 - CFD: 05/04/2012 - 16:03:50 - [0,500] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 16/04/2012 - 23:00:26 - [5,895] ----D C:\Program Files (x86)\Windows Mail
O43 - CFD: 16/04/2012 - 23:00:18 - [4,896] ----D C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - 06:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 05/04/2012 - 16:03:50 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 14/07/2009 - 06:32:40 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 05/04/2012 - 16:03:50 - [6,039] ----D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 06/04/2012 - 14:11:34 - [3,965] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 20/04/2012 - 21:22:44 - [11,404] ----D C:\Program Files (x86)\ZHPDiag
O43 - CFD: 19/04/2012 - 18:47:50 - [6,348] ----D C:\Program Files (x86)\ZHPFix
O43 - CFD: 16/04/2012 - 19:51:14 - [544,630] ----D C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 05/04/2012 - 10:19:06 - [82,715] ----D C:\Program Files (x86)\Common Files\Ahead
O43 - CFD: 20/04/2012 - 14:28:04 - [0] ----D C:\Program Files (x86)\Common Files\AltrixSoft
O43 - CFD: 07/04/2012 - 12:57:23 - [2,704] ----D C:\Program Files (x86)\Common Files\ATI Technologies
O43 - CFD: 20/04/2012 - 16:47:32 - [0,095] ----D C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 06/04/2012 - 14:27:53 - [2,250] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 06/04/2012 - 14:28:47 - [0,957] ----D C:\Program Files (x86)\Common Files\Macromedia
O43 - CFD: 07/04/2012 - 09:43:18 - [0,625] ----D C:\Program Files (x86)\Common Files\Macrovision Shared
O43 - CFD: 20/04/2012 - 16:47:49 - [363,362] ----D C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 14/07/2009 - 04:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 05/04/2012 - 09:25:16 - [1,853] ----D C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 14/07/2009 - 04:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 16/04/2012 - 23:00:29 - [41,888] ----D C:\Program Files (x86)\Common Files\System
~ Scan Program Folder in 00mn 01s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.37811A93F6153625ED29A906BB5B2472] - 20/04/2012 - 21:20:50 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1665467]
O44 - LFC:[MD5.605C05C93A358F4FE8E3E68A3EF653CB] - 20/04/2012 - 21:17:45 ---A- . (...) -- C:\Windows\setupact.log [32366]
O44 - LFC:[MD5.8A98E2B4D2A23A59CE59068E0E1E30FD] - 20/04/2012 - 21:17:42 . (...) -- C:\Windows\System32\FNTCACHE.DAT [2338768]
O44 - LFC:[MD5.8A98E2B4D2A23A59CE59068E0E1E30FD] - 20/04/2012 - 21:17:42 ---A- . (...) -- C:\Windows\SysNative\FNTCACHE.DAT [2338768]
O44 - LFC:[MD5.BA684C21431AEEF46BE4D82F41C92E7F] - 20/04/2012 - 21:17:39 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.B04C339D200551752090DF9BEEBAB81B] - 20/04/2012 - 21:17:25 ---A- . (...) -- C:\Windows\PFRO.log [272154]
O44 - LFC:[MD5.7D8AB03838C3AF396AD0DD1002AA2365] - 20/04/2012 - 19:48:51 . (...) -- C:\Windows\System32\perfc009.dat [121082]
O44 - LFC:[MD5.D1D7B4F87AB6FF8B81F3F722CAA0E9AA] - 20/04/2012 - 19:48:51 . (...) -- C:\Windows\System32\perfc00C.dat [148786]
O44 - LFC:[MD5.740102F2AF7BD03B74BF425C41017BBC] - 20/04/2012 - 19:48:51 . (...) -- C:\Windows\System32\perfh009.dat [652150]
O44 - LFC:[MD5.D48A7E213F89EC6A9F1E77A22682FED0] - 20/04/2012 - 19:48:51 . (...) -- C:\Windows\System32\perfh00C.dat [745268]
O44 - LFC:[MD5.A8DA48633200B1EBF3894DEBEF7C1FFF] - 20/04/2012 - 19:48:51 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1662566]
O44 - LFC:[MD5.7D8AB03838C3AF396AD0DD1002AA2365] - 20/04/2012 - 19:48:51 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [121082]
O44 - LFC:[MD5.D1D7B4F87AB6FF8B81F3F722CAA0E9AA] - 20/04/2012 - 19:48:51 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [148786]
O44 - LFC:[MD5.740102F2AF7BD03B74BF425C41017BBC] - 20/04/2012 - 19:48:51 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [652150]
O44 - LFC:[MD5.D48A7E213F89EC6A9F1E77A22682FED0] - 20/04/2012 - 19:48:51 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [745268]
O44 - LFC:[MD5.A8DA48633200B1EBF3894DEBEF7C1FFF] - 20/04/2012 - 19:48:51 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1662566]
O44 - LFC:[MD5.7D74A033206B2833FAF0402B50A8B869] - 19/04/2012 - 18:30:09 ---A- . (...) -- C:\UsbFix.txt [3663]
O44 - LFC:[MD5.C08063F052308B6F5882482615387F30] - 19/04/2012 - 13:45:40 . (.CPUID - CPUID Driver.) -- C:\Windows\System32\Drivers\cpuz135_x64.sys [21992]
O44 - LFC:[MD5.327FB56C39457EC6BFCB02E3C18B7811] - 19/04/2012 - 01:22:49 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.8BD25A34DA5E53AE115977DD1E15AB3C] - 16/04/2012 - 20:19:49 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\SysNative\atmlib.dll [46080]
O44 - LFC:[MD5.8BD25A34DA5E53AE115977DD1E15AB3C] - 16/04/2012 - 20:19:49 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [46080]
O44 - LFC:[MD5.EFC5353E4F513DEF55ED7B7872363957] - 16/04/2012 - 20:19:49 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\SysNative\atmfd.dll [367104]
O44 - LFC:[MD5.EFC5353E4F513DEF55ED7B7872363957] - 16/04/2012 - 20:19:49 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [367104]
O44 - LFC:[MD5.36932522D014499D7F7B1BB921D05842] - 15/04/2012 - 00:29:35 ---A- . (.InstallShield Software Corporation - InstallShield® unInstaller.) -- C:\Windows\IsUn040c.exe [327168]
O44 - LFC:[MD5.47EB3D64B9BE141DA6385B46E9E6302D] - 12/04/2012 - 15:52:32 ---A- . (...) -- C:\UsbFix_Upload_Me_DELL-PC.zip [667279301]
O44 - LFC:[MD5.159AC04C9635671BD25ADA1CBA173E9D] - 11/04/2012 - 17:53:39 ---A- . (...) -- C:\Windows\ntbtlog.txt [310910]
O44 - LFC:[MD5.505FA3D516C6D9694A0D2A3AF2D04CDE] - 11/04/2012 - 14:51:39 ---A- . (...) -- C:\Windows\err.txt [600]
O44 - LFC:[MD5.9373ECAB76CD68B232972E0749369335] - 11/04/2012 - 14:51:31 ----- . (...) -- C:\trace.ini [11]
O44 - LFC:[MD5.46571ED73AE84469DCA53081D33CF3C8] - 11/04/2012 - 14:49:18 . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\Drivers\dtsoftbus01.sys [283200]
O44 - LFC:[MD5.852E3C0A60D368C487949E55AD52A47F] - 11/04/2012 - 12:05:20 . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\Windows\System32\Drivers\avipbb.sys [132320]
O44 - LFC:[MD5.248DB59FC86DE44D2779F4C7FB1A567D] - 11/04/2012 - 11:57:16 . (.Avira GmbH - Avira Manager Driver.) -- C:\Windows\System32\Drivers\avkmgr.sys [27760]
O44 - LFC:[MD5.AA8F79A1BDFC03B3BC70C44AB00589B4] - 11/04/2012 - 11:57:16 . (.Avira GmbH - Avira Minifilter Driver.) -- C:\Windows\System32\Drivers\avgntflt.sys [97312]
O44 - LFC:[MD5.F11B376A27E94E5F2A0E34A4FCC70A88] - 08/04/2012 - 10:22:51 ---A- . (.McAfee, Inc. - McAfee Labs® GetSusp™ Utility Driver.) -- C:\Windows\stinger.sys [16200]
O44 - LFC:[MD5.767EE8126468D91C5119F25714D78DAF] - 07/04/2012 - 19:36:39 ---A- . (.Microsoft Corporation - Bibliothèque d'assistance au déploiement de.) -- C:\Windows\SysNative\dfshim.dll [1942856]
O44 - LFC:[MD5.767EE8126468D91C5119F25714D78DAF] - 07/04/2012 - 19:36:39 ---A- . (.Microsoft Corporation - Bibliothèque d'assistance au déploiement de.) -- C:\Windows\System32\dfshim.dll [1942856]
O44 - LFC:[MD5.5B475A5D98F71974850DCC5C2177C03B] - 07/04/2012 - 13:51:21 ---A- . (...) -- C:\Windows\DirectX.log [160220]
O44 - LFC:[MD5.79DA94B35371B9E7104460C7693DCB2C] - 06/04/2012 - 23:05:32 . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23152]
O44 - LFC:[MD5.BD9CC8E7FFE14527496E1C0B13660E4E] - 05/04/2012 - 17:43:11 . (.AVAST Software - avast! start-up scanner.) -- C:\Windows\System32\aswBoot.exe [258520]
O44 - LFC:[MD5.BD9CC8E7FFE14527496E1C0B13660E4E] - 05/04/2012 - 17:43:11 ---A- . (.AVAST Software - avast! start-up scanner.) -- C:\Windows\SysNative\aswBoot.exe [258520]
O44 - LFC:[MD5.03CF68DDE2311640AB2723B3AAFE16D9] - 05/04/2012 - 17:40:00 ----- . (.AVAST Software - avast! antivirus Update.) -- C:\Pr [6426672]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 05/04/2012 - 17:38:32 ---A- . (...) -- C:\Windows\ativpsrm.bin [0]
O44 - LFC:[MD5.2B73EAC8728D3799B62095D56B017DF8] - 05/04/2012 - 17:34:44 . (.AMD - CoInstaller DLL.) -- C:\Windows\System32\coinst.dll [58880]
O44 - LFC:[MD5.C05718CCC34B0DCB60DB26784A75AEAF] - 05/04/2012 - 17:34:44 . (.ATI Technologies, Inc. - ATI Desktop CWDDEDI DLL.) -- C:\Windows\System32\atipdl64.dll [423424]
O44 - LFC:[MD5.2B73EAC8728D3799B62095D56B017DF8] - 05/04/2012 - 17:34:44 ---A- . (.AMD - CoInstaller DLL.) -- C:\Windows\SysNative\coinst.dll [58880]
O44 - LFC:[MD5.C05718CCC34B0DCB60DB26784A75AEAF] - 05/04/2012 - 17:34:44 ---A- . (.ATI Technologies, Inc. - ATI Desktop CWDDEDI DLL.) -- C:\Windows\SysNative\atipdl64.dll [423424]
O44 - LFC:[MD5.749584902AE80A53EFDA4F8FA03E1713] - 05/04/2012 - 17:34:43 . (.Advanced Micro Devices, Inc. - ATIBRTMON.) -- C:\Windows\System32\atibtmon.exe [118784]
O44 - LFC:[MD5.A6BAAA6608A9B00220E9D5C023FC53D1] - 05/04/2012 - 17:34:43 . (.Advanced Micro Devices, Inc. - ATIODCLI Application.) -- C:\Windows\System32\ATIODCLI.exe [51200]
O44 - LFC:[MD5.463FFBD3350E3EB57F7D5746EBD233CA] - 05/04/2012 - 17:34:43 . (.Advanced Micro Devices, Inc. - ATIODE Application.) -- C:\Windows\System32\ATIODE.exe [332800]
O44 - LFC:[MD5.749584902AE80A53EFDA4F8FA03E1713] - 05/04/2012 - 17:34:43 ---A- . (.Advanced Micro Devices, Inc. - ATIBRTMON.) -- C:\Windows\SysNative\atibtmon.exe [118784]
O44 - LFC:[MD5.A6BAAA6608A9B00220E9D5C023FC53D1] - 05/04/2012 - 17:34:43 ---A- . (.Advanced Micro Devices, Inc. - ATIODCLI Application.) -- C:\Windows\SysNative\ATIODCLI.exe [51200]
O44 - LFC:[MD5.463FFBD3350E3EB57F7D5746EBD233CA] - 05/04/2012 - 17:34:43 ---A- . (.Advanced Micro Devices, Inc. - ATIODE Application.) -- C:\Windows\SysNative\ATIODE.exe [332800]
O44 - LFC:[MD5.50A043BF2CC639A8A95A4DED17AB8961] - 05/04/2012 - 12:11:20 . (.TuneUp Software - TuneUp Registry Optimization Boot Applicati.) -- C:\Windows\System32\TURegOpt.exe [34624]
O44 - LFC:[MD5.50A043BF2CC639A8A95A4DED17AB8961] - 05/04/2012 - 12:11:20 ---A- . (.TuneUp Software - TuneUp Registry Optimization Boot Applicati.) -- C:\Windows\SysNative\TURegOpt.exe [34624]
O44 - LFC:[MD5.601A5CCF88FC66F13631C80F6EB4C69F] - 05/04/2012 - 12:11:20 ---A- . (.TuneUp Software - TuneUp Theme Extension.) -- C:\Windows\SysNative\uxtuneup.dll [35648]
O44 - LFC:[MD5.601A5CCF88FC66F13631C80F6EB4C69F] - 05/04/2012 - 12:11:20 ---A- . (.TuneUp Software - TuneUp Theme Extension.) -- C:\Windows\System32\uxtuneup.dll [35648]
O44 - LFC:[MD5.F01E49C5E49359B5B1BD3779813C772B] - 05/04/2012 - 12:11:20 ---A- . (.TuneUp Software - TuneUp WinLogon Extension.) -- C:\Windows\SysNative\authuitu.dll [25920]
O44 - LFC:[MD5.F01E49C5E49359B5B1BD3779813C772B] - 05/04/2012 - 12:11:20 ---A- . (.TuneUp Software - TuneUp WinLogon Extension.) -- C:\Windows\System32\authuitu.dll [25920]
O44 - LFC:[MD5.2465EBC8CD6E412CDC1AB9FEF40BCAE6] - 05/04/2012 - 09:27:50 ---A- . (...) -- C:\Windows\win.ini [478]
O44 - LFC:[MD5.E3AA12FAA3192D1090B9069C3925373B] - 05/04/2012 - 08:59:52 . (.Realtek - Realtek 8136/8168/8169 NDIS6 64-bit Driver.) -- C:\Windows\System32\Drivers\Rtlh64.sys [404584]
O44 - LFC:[MD5.92C704590FCEDDA971B7A77945DCCDA4] - 05/04/2012 - 08:59:50 . (.Pas de propriétaire - About Page.) -- C:\Windows\System32\RtNicProp64.dll [74272]
O44 - LFC:[MD5.49A88E6CD77939F5F7D443628A18A317] - 05/04/2012 - 08:59:50 . (.Realtek Semiconductor Corporation - RTNUninst.) -- C:\Windows\System32\RTNUninst64.dll [107552]
O44 - LFC:[MD5.92C704590FCEDDA971B7A77945DCCDA4] - 05/04/2012 - 08:59:50 ---A- . (.Pas de propriétaire - About Page.) -- C:\Windows\SysNative\RtNicProp64.dll [74272]
O44 - LFC:[MD5.49A88E6CD77939F5F7D443628A18A317] - 05/04/2012 - 08:59:50 ---A- . (.Realtek Semiconductor Corporation - RTNUninst.) -- C:\Windows\SysNative\RTNUninst64.dll [107552]
O44 - LFC:[MD5.4473EDCA3345EB34E8857FF4A8F372CC] - 04/04/2012 - 19:49:14 ---A- . (...) -- C:\Windows\SysNative\license.rtf [57694]
O44 - LFC:[MD5.4473EDCA3345EB34E8857FF4A8F372CC] - 04/04/2012 - 19:49:14 ---A- . (...) -- C:\Windows\System32\license.rtf [57694]
O44 - LFC:[MD5.22CB2F7BA66CAE13572422169EF2DE6E] - 04/04/2012 - 19:48:52 ---A- . (...) -- C:\Windows\DtcInstall.log [1774]
O44 - LFC:[MD5.442445122D77B5C3E66FCA1429F599C4] - 04/04/2012 - 19:48:47 ---A- . (...) -- C:\Windows\TSSysprep.log [1313]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 04/04/2012 - 19:48:00 . (...) -- C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf [0]
~ Scan Files in 00mn 03s
---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
~ Scan Keys in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ Scan CSB in 00mn 00s
---\\ MountPoints2 Shell Key (O51) (None)
---\\ Trojan Driver Search Data (HKLM) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ Scan Keys in 00mn 00s
---\\ ShareTools MSconfig StartupReg (O53)
O53 - SMSR:HKLM\...\startupreg\adm_tray.exe [Key] . (...) -- C:\Program Files (x86)\Acronis\DriveMonitor\adm_tray.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Adobe ARM [Key] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O53 - SMSR:HKLM\...\startupreg\DAEMON Tools Lite [Key] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
O53 - SMSR:HKLM\...\startupreg\DriverMax [Key] . (.Innovative Solutions - DriverMax.) -- C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe
O53 - SMSR:HKLM\...\startupreg\IDMan [Key] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
O53 - SMSR:HKLM\...\startupreg\Malwarebytes' Anti-Malware [Key] . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
O53 - SMSR:HKLM\...\startupreg\Service Planificateur2 Acronis [Key] . (...) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O53 - SMSR:HKLM\...\startupreg\StartCCC [Key] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O53 - SMSR:HKLM\...\startupreg\vProt [Key] . (...) -- C:\Program Files (x86)\AVG Secure Search\vprot.exe (.not file.)
~ Scan SMSR Keys in 00mn 00s
---\\ Microsoft Control Security Providers (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ Scan Keys in 00mn 00s
---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ Scan Keys in 00mn 00s
--\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveAutoRun"=3
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveAutoRun"=3
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveTypeAutoRun"=0
~ Scan Keys in 00mn 00s
---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
O58 - SDL:[MD5.597F78224EE9224EA1A13D6350CED962] - 14/07/2009 - 02:52:21 . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [339536]
O58 - SDL:[MD5.E109549C90F62FB570B9540C4B148E54] - 14/07/2009 - 02:52:21 . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\Drivers\adpu320.sys [182864]
O58 - SDL:[MD5.5812713A477A3AD7363C7438CA2EE038] - 14/07/2009 - 02:52:21 . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [15440]
O58 - SDL:[MD5.7A4B413614C055935567CF88A9734D38] - 14/07/2009 - 02:52:21 . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [106576]
O58 - SDL:[MD5.F67F933E79241ED32FF46A4F29B5120B] - 14/07/2009 - 02:52:20 . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\System32\Drivers\amdsbs.sys [194128]
O58 - SDL:[MD5.B4AD0CACBAB298671DD6F6EF7E20679D] - 14/07/2009 - 02:52:21 . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [28752]
O58 - SDL:[MD5.C484F8CEB1717C540242531DB7845C4E] - 14/07/2009 - 02:52:21 . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [87632]
O58 - SDL:[MD5.019AF6924AEFE7839F61C830227FE79C] - 14/07/2009 - 02:52:21 . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [97856]
O58 - SDL:[MD5.2B3B05C0A7768BF033217EB8F33F9C35] - 05/12/2011 - 20:47:30 . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\AtihdW76.sys [95248]
O58 - SDL:[MD5.BFA5E854959D5546D8834CA61F4AD075] - 09/03/2012 - 07:28:08 . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\Drivers\atikmdag.sys [10857984]
O58 - SDL:[MD5.92D664FFFCD9E742FB25254F7F458D88] - 09/03/2012 - 04:58:02 . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\Drivers\atikmpag.sys [328704]
O58 - SDL:[MD5.AA8F79A1BDFC03B3BC70C44AB00589B4] - 15/12/2011 - 15:08:00 . (.Avira GmbH - Avira Minifilter Driver.) -- C:\Windows\System32\Drivers\avgntflt.sys [97312]
O58 - SDL:[MD5.852E3C0A60D368C487949E55AD52A47F] - 11/04/2012 - 12:05:20 . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\Windows\System32\Drivers\avipbb.sys [132320]
O58 - SDL:[MD5.248DB59FC86DE44D2779F4C7FB1A567D] - 15/12/2011 - 15:08:01 . (.Avira GmbH - Avira Manager Driver.) -- C:\Windows\System32\Drivers\avkmgr.sys [27760]
O58 - SDL:[MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - 10/06/2009 - 21:34:23 . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\System32\Drivers\b57nd60a.sys [270848]
O58 - SDL:[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - 10/06/2009 - 21:41:06 . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [18432]
O58 - SDL:[MD5.B114D3098E9BDB8BEA8B053685831BE6] - 10/06/2009 - 21:41:06 . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [8704]
O58 - SDL:[MD5.43BEA8D483BF1870F018E2D02E06A5BD] - 14/07/2009 - 02:19:07 . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [286720]
O58 - SDL:[MD5.A6ECA2151B08A09CACECA35C07F05B42] - 10/06/2009 - 21:41:10 . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [47104]
O58 - SDL:[MD5.B79968002C277E869CF38BD22CD61524] - 10/06/2009 - 21:41:10 . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [14976]
O58 - SDL:[MD5.A87528880231C54E75EA7A44943B38BF] - 10/06/2009 - 21:41:10 . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [14720]
O58 - SDL:[MD5.3E5B191307609F7514148C6832BB0842] - 10/06/2009 - 21:34:28 . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbda.sys [468480]
O58 - SDL:[MD5.E19D3F095812725D88F9001985B94EDD] - 14/07/2009 - 02:52:31 . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [17488]
O58 - SDL:[MD5.C08063F052308B6F5882482615387F30] - 21/09/2011 - 10:25:54 . (.CPUID - CPUID Driver.) -- C:\Windows\System32\Drivers\cpuz135_x64.sys [21992]
O58 - SDL:[MD5.46571ED73AE84469DCA53081D33CF3C8] - 11/04/2012 - 14:49:18 . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\Drivers\dtsoftbus01.sys [283200]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.DC5D737F51BE844D8C82C695EB17372F] - 10/06/2009 - 21:34:33 . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbda.sys [3286016]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.0886D440058F203EBA0E1825E4355914] - 14/07/2009 - 02:47:48 . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [77888]
O58 - SDL:[MD5.D83EFB6FD45DF9D55E9A1AFC63640D50] - 14/07/2009 - 02:48:04 . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStorV.sys [410688]
O58 - SDL:[MD5.5534E14EF27EBE8563CDBCE6B88501A3] - 08/02/2012 - 03:13:32 . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [149640]
O58 - SDL:[MD5.5C18831C61933628F5BB0EA2675B9D21] - 14/07/2009 - 02:48:04 . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [44112]
O58 - SDL:[MD5.1A93E54EB0ECE102495A51266DCDB6A6] - 14/07/2009 - 02:48:04 . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [114752]
O58 - SDL:[MD5.1047184A9FDC8BDBFF857175875EE810] - 14/07/2009 - 02:48:04 . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [106560]
O58 - SDL:[MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - 14/07/2009 - 02:48:04 . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [65600]
O58 - SDL:[MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - 14/07/2009 - 02:48:04 . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [115776]
O58 - SDL:[MD5.79DA94B35371B9E7104460C7693DCB2C] - 10/12/2011 - 15:24:08 . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23152]
O58 - SDL:[MD5.A55805F747C6EDB6A9080D7C633BD0F4] - 14/07/2009 - 02:48:04 . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\System32\Drivers\megasas.sys [35392]
O58 - SDL:[MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - 14/07/2009 - 02:48:04 . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [284736]
O58 - SDL:[MD5.77889813BE4D166CDAB78DDBA990DA92] - 14/07/2009 - 02:48:26 . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [51264]
O58 - SDL:[MD5.3E38712941E9BB4DDBEE00AFFE3FED3D] - 14/07/2009 - 02:48:27 . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [149056]
O58 - SDL:[MD5.477DC4D6DEB99BE37084C9AC6D013DA1] - 14/07/2009 - 02:45:45 . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [167488]
O58 - SDL:[MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - 14/07/2009 - 02:45:46 . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1524816]
O58 - SDL:[MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - 14/07/2009 - 02:45:45 . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [128592]
O58 - SDL:[MD5.98EB56776F2E3F5EC9B4EABA63A60687] - 16/12/2009 - 08:13:16 . (.Realtek Semiconductor Corporation - Realtek RTL8187B NDIS Driver.) -- C:\Windows\System32\Drivers\RTL8187B.sys [446976]
O58 - SDL:[MD5.E3AA12FAA3192D1090B9069C3925373B] - 22/02/2011 - 19:21:54 . (.Realtek - Realtek 8136/8168/8169 NDIS6 64-bit Driver.) -- C:\Windows\System32\Drivers\Rtlh64.sys [404584]
O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 10/06/2009 - 21:37:19 . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [23040]
O58 - SDL:[MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - 14/07/2009 - 02:45:45 . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [43584]
O58 - SDL:[MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - 14/07/2009 - 02:45:46 . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [80464]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.E5689D93FFE4E5D66C0178761240DD54] - 14/07/2009 - 02:45:55 . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [17488]
O58 - SDL:[MD5.5E2016EA6EBACA03C04FEAC5F330D997] - 14/07/2009 - 02:45:55 . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [161872]
~ Scan Drivers in 00mn 00s
---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: UsbFix By El Desaparecido - (.El Desaparecido.) [HKLM] -- Usbfix
O63 - Logiciel: ZHPDiag 1.30 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
O63 - Logiciel: ZHPFix 1.12 - (.Nicolas Coolman.) [HKLM] -- ZHPFix_is1
~ Scan ADS in 00mn 00s
---\\ Liste des services Legacy (O64)
O64 - Services: CurCS - 28/12/2011 - C:\Windows\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD
O64 - Services: CurCS - 09/03/2012 - C:\Windows\System32\DRIVERS\atikmdag.sys (amdkmdag) .(.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) - LEGACY_AMDKMDAG
O64 - Services: CurCS - 15/12/2011 - C:\Windows\System32\DRIVERS\avgntflt.sys (avgntflt) .(.Avira GmbH - Avira Minifilter Driver.) - LEGACY_AVGNTFLT
O64 - Services: CurCS - 11/04/2012 - C:\Windows\System32\DRIVERS\avipbb.sys (avipbb) .(.Avira GmbH - Avira Driver for Security Enhancement.) - LEGACY_AVIPBB
O64 - Services: CurCS - 15/12/2011 - C:\Windows\System32\DRIVERS\avkmgr.sys (avkmgr) .(.Avira GmbH - Avira Manager Driver.) - LEGACY_AVKMGR
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\clfs.sys (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS
O64 - Services: CurCS - 17/11/2011 - C:\Windows\System32\Drivers\cng.sys (CNG) .(.Microsoft Corporation - Kernel Cryptography, Next Generation.) - LEGACY_CNG
O64 - Services: CurCS - 21/09/2011 - C:\Windows\system32\drivers\cpuz135_x64.sys (cpuz135) .(.CPUID - CPUID Driver.) - LEGACY_CPUZ135
O64 - Services: CurCS - 21/07/2011 - C:\Program Files\ma-config.com\Drivers\driverhardwarev2x64.sys (driverhardwarev2x64) .(.CybelSoft - Driver NT Ma-Config.com.) - LEGACY_DRIVERHARDWAREV2X64
O64 - Services: CurCS - 02/10/2009 - C:\Windows\system32\drivers\dxgkrnl.sys (DXGKrnl) .(.Microsoft Corporation - DirectX Graphics Kernel.) - LEGACY_DXGKRNL
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Microsoft Corporation - BitLocker Drive Encryption Driver.) - LEGACY_FVEVOL
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Microsoft Corporation - Hardware Policy Driver.) - LEGACY_HWPOLICY
O64 - Services: CurCS - 08/02/2012 - C:\Windows\System32\DRIVERS\idmwfp.sys (IDMWFP) .(.Tonec Inc. - Internet Download Manager WFP Driver.) - LEGACY_IDMWFP
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\lltdio.sys (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO
O64 - Services: CurCS - 10/12/2011 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) - LEGACY_MBAMPROTECTOR
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\wkssvc.dll (mrxsmb20) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB20
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\ndis.sys (NDIS) .(.Microsoft Corporation - Pilote NDIS 6.20.) - LEGACY_NDIS
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT
O64 - Services: CurCS - 10/04/2012 - c:\program files\dell support center\pcdsrvc_x64.pkms (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) .(.PC-Doctor, Inc. - Kernel Driver.) - LEGACY_PCDSRVC{1E208CE0-FB7451FF-06020101}_0
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\drivers\pacer.sys (Psched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\rspndr.sys (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR
O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\srvnet.sys (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\vmstorfltres.dll (storflt) .(.Microsoft Corporation - Fichier DLL de ressources du filtre de stoc.) - LEGACY_STORFLT
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\volsnap.sys (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\rascfg.dll (Wanarpv6) .(.Microsoft Corporation - Objets de configuration RAS.) - LEGACY_WANARPV6
~ Scan Services in 00mn 00s
---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <Opera.HTML>[HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Opera.exe
O67 - Shell Spawning: <.js> <jsfile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCR\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: <.js> <jsfile>[HKCR\..\open\Command] (.Adobe Systems, Inc. - Adobe Dreamweaver CS3.) -- C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS3\dreamweaver.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
~ Scan Keys in 00mn 00s
---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: <chrome.exe> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <Opera.exe> <Opera>[HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Opera.exe
O68 - StartMenuInternet: <chrome.exe> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: <Opera.exe> <Opera>[HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Opera.exe
O68 - StartMenuInternet: <chrome.exe> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: <Opera.exe> <Opera>[HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Opera.exe
O68 - StartMenuInternet: <chrome.exe> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\dell\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: <Opera.exe> <Opera>[HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Opera.exe
~ Scan Keys in 00mn 00s
---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] ${searchCLSID} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {95B7759C-8C7F-4BF1-B163-73684A933233} [DefaultScope] - (AVG Secure Search) - http://isearch.avg.com
~ Scan Keys in 00mn 00s
---\\ Recherche des services démarrés par Svchost (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [776192]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [845824]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [676864]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [343552]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316416]
O83 - Search Svchost Services: UxTuneUp (UxTuneUp) . (.TuneUp Software - TuneUp Theme Extension.) -- C:\Windows\System32\uxtuneup.dll [35648]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [706560]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2418176]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [848384]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [369664]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [565760]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [104960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136192]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1114624]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [208384]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864]
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [193536]
~ Scan Services in 00mn 00s
---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.1829BEA055E50AEC58AA1C7FFAF6C00C] [SPRF][10/04/2012] (...) -- C:\ProgramData\ezsidmv.dat [48]
[MD5.7E219B4449A9F46032581775BCA5B8AD] [SPRF][12/01/2010] (.AltrixSoft - Installation utulity Dynamic Link Library.) -- C:\Users\dell\AppData\Local\Temp\Utils.dll [94432]
[MD5.E152C2E083BB18DF3770DE4040E3F391] [SPRF][12/04/2012] (...) -- C:\Users\dell\AppData\Roaming\SetValue.bat [35]
~ Scan Files in 00mn 00s
---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "WMPNSS-In-UDP-NoScope" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-UDP-NoScope" |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-In-UDP" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-UDP" |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "{67763F89-0B85-47C3-9C03-637784D033FF}" | In - Public - P6 - TRUE | .(.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\opera.exe
O87 - FAEL: "{CB1BE4FE-8D31-495F-A4F5-4330CD012670}" | In - Public - P17 - TRUE | .(.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\opera.exe
O87 - FAEL: "{7DA46A72-3DB4-4D9F-B7FE-C65628EC4F98}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O87 - FAEL: "{93447DB6-FD75-4759-B35B-737F42DCC3E1}" | In - Private - P6 - TRUE | .(.CybelSoft - Service de détection matériel.) -- C:\Program Files\ma-config.com\x64\maconfservice.exe
O87 - FAEL: "{A4E05381-4550-414A-83AD-A8AA1160A6DC}" | In - Private - P17 - TRUE | .(.CybelSoft - Service de détection matériel.) -- C:\Program Files\ma-config.com\x64\maconfservice.exe
O87 - FAEL: "TCP Query User{3E464DC3-4E6F-417B-B91D-4A092994BC00}C:\program files (x86)\opera\opera.exe" | In - Private - P6 - TRUE | .(.Opera Software - Opera Internet Browser.) -- C:\program files (x86)\opera\opera.exe
O87 - FAEL: "UDP Query User{37D7BFE7-1978-4CCD-965A-E25CD116C078}C:\program files (x86)\opera\opera.exe" | In - Private - P17 - TRUE | .(.Opera Software - Opera Internet Browser.) -- C:\program files (x86)\opera\opera.exe
O87 - FAEL: "TCP Query User{4FE6C1B1-A8ED-43DD-A451-955706245E55}C:\users\dell\appdata\local\google\chrome\application\chrome.exe" | In - Private - P6 - TRUE | .(.Google Inc..) -- C:\users\dell\appdata\local\google\chrome\application\chrome.exe
O87 - FAEL: "UDP Query User{C4FFB222-260C-4D52-B984-BC4659557AD6}C:\users\dell\appdata\local\google\chrome\application\chrome.exe" | In - Private - P17 - TRUE | .(.Google Inc..) -- C:\users\dell\appdata\local\google\chrome\application\chrome.exe
O87 - FAEL: "{0B81E780-D7EF-4AD3-9226-E7022C3F3FC7}" | In - None - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
O87 - FAEL: "{074C6A88-8ED9-4969-B363-B86D506CA651}" | In - None - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
O87 - FAEL: "TCP Query User{BF04D15B-AD5E-483F-BA81-30ECB81BD119}C:\users\dell\downloads\programs\utorrent.exe" | In - Private - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\users\dell\downloads\programs\utorrent.exe
O87 - FAEL: "UDP Query User{6843BAC4-C97C-470A-8581-98A165F2C6F8}C:\users\dell\downloads\programs\utorrent.exe" | In - Private - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\users\dell\downloads\programs\utorrent.exe
~ Scan Firewall in 00mn 00s
---\\ Scan Additionnel (O88)
Database Version : 9092 - (19/04/2012)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 0
[HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong
C:\Users\dell\AppData\LocalLow\PriceGong =>Adware.PriceGong
~ Scan Additionnel in 00mn 04s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 09/03/2012 235520 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 15/12/2011 342480 | (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
SR - | Auto 15/12/2011 86224 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 15/12/2011 110032 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SS - | Demand 15/12/2011 463824 | (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.exe
SR - | Auto 28/02/2006 229376 | ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) . (.Apple Computer, Inc..) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
SS - | Demand 07/04/2012 654848 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 05/04/2012 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 05/04/2012 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 25/11/2011 427640 | (maconfservice) . (.CybelSoft.) - C:\Program Files\ma-config.com\x64\maconfservice.exe
SS - | Disabled 13/01/2012 652360 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SS - | Demand 10/11/2006 774144 | (NBService) . (.Nero AG.) - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
SS - | Demand 10/04/2012 25072 | (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) . (.PC-Doctor, Inc..) - c:\program files\dell support center\pcdsrvc_x64.pkms
SS - | Auto 0 | (TuneUp.UtilitiesSvc) . (...) - D:\tuneup2012\TuneUpUtilitiesService64.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\uxtuneup.dll (UxTuneUp) . (.TuneUp Software.) - C:\Windows\System32\svchost.exe
SS - | Disabled 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
~ Scan Services in 00mn 05s
---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by dell at 20/04/2012 21:23:01
device: opened successfully
user: error reading MBR
Disk trace:
error: Read Descripteur non valide
kernel: error reading MBR
~ Scan MBR in 00mn 02s
---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by dell at 20/04/2012 21:23:03
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ Scan MBR in 00mn 04s
---\\ Liste des émulateurs de CD/DVD (Hook du MBR)
O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM] -- DAEMON Tools Lite
~ Scan Emulateurs in 00mn 04s
End of the scan (1347 lines in 00mn 20s)(0)
RogueKiller V7.3.2 [20/03/2012] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Blog: http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows 7 (6.1.7600 ) 64 bits version
Demarrage : Mode normal
Utilisateur: dell [Droits d'admin]
Mode: Suppression -- Date: 20/04/2012 21:25:49
¤¤¤ Processus malicieux: 0 ¤¤¤
¤¤¤ Entrees de registre: 0 ¤¤¤
¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤
¤¤¤ Driver: [NON CHARGE] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ Fichier HOSTS: ¤¤¤
¤¤¤ MBR Verif: ¤¤¤
+++++ PhysicalDrive0: ST3500413AS ATA Device +++++
--- User ---
[MBR] 327fb56c39457ec6bfcb02e3c18b7811
[BSP] e642fc0fd565a80a5dea47e79df01f7d : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 199900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409602048 | Size: 276938 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Termine : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V7.3.2 [20/03/2012] par Tigzy
mail: tigzyRK<at>gmail<dot>com
Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Blog: http://tigzyrk.blogspot.com
Systeme d'exploitation: Windows 7 (6.1.7600 ) 64 bits version
Demarrage : Mode normal
Utilisateur: dell [Droits d'admin]
Mode: Raccourcis RAZ -- Date: 21/04/2012 13:16:55
¤¤¤ Processus malicieux: 0 ¤¤¤
¤¤¤ Driver: [NON CHARGE] ¤¤¤
¤¤¤ Attributs de fichiers restaures: ¤¤¤
Bureau: Success 0 / Fail 0
Lancement rapide: Success 0 / Fail 0
Programmes: Success 0 / Fail 0
Menu demarrer: Success 0 / Fail 0
Dossier utilisateur: Success 19 / Fail 0
Mes documents: Success 0 / Fail 0
Mes favoris: Success 0 / Fail 0
Mes images: Success 0 / Fail 0
Ma musique: Success 0 / Fail 0
Mes videos: Success 0 / Fail 0
Disques locaux: Success 25 / Fail 0
Sauvegarde: [NOT FOUND]
Lecteurs:
[C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
[E:] \Device\CdRom0 -- 0x5 --> Skipped
[F:] \Device\HarddiskVolume4 -- 0x2 --> Restored
[G:] \Device\HarddiskVolume5 -- 0x2 --> Restored
[H:] \Device\HarddiskVolume6 -- 0x2 --> Restored
[I:] \Device\HarddiskVolume7 -- 0x2 --> Restored
[J:] \Device\HarddiskVolume8 -- 0x2 --> Restored
[K:] \Device\CdRom1 -- 0x5 --> Skipped
¤¤¤ Infection : ¤¤¤
Termine : << RKreport[1].txt >>
RKreport[1].txt
13:18:31.0678 2824 TDSS rootkit removing tool 2.7.31.0 Apr 20 2012 19:49:47
13:18:31.0896 2824 ============================================================
13:18:31.0896 2824 Current date / time: 2012/04/21 13:18:31.0896
13:18:31.0896 2824 SystemInfo:
13:18:31.0896 2824
13:18:31.0896 2824 OS Version: 6.1.7600 ServicePack: 0.0
13:18:31.0896 2824 Product type: Workstation
13:18:31.0896 2824 ComputerName: DELL-PC
13:18:31.0896 2824 UserName: dell
13:18:31.0896 2824 Windows directory: C:\Windows
13:18:31.0896 2824 System windows directory: C:\Windows
13:18:31.0896 2824 Running under WOW64
13:18:31.0896 2824 Processor architecture: Intel x64
13:18:31.0896 2824 Number of processors: 4
13:18:31.0896 2824 Page size: 0x1000
13:18:31.0896 2824 Boot type: Normal boot
13:18:31.0896 2824 ============================================================
13:18:33.0175 2824 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:18:33.0191 2824 Drive \Device\Harddisk5\DR5 - Size: 0x3C7800000 (15.12 Gb), SectorSize: 0x200, Cylinders: 0x7B5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:18:33.0191 2824 \Device\Harddisk0\DR0:
13:18:33.0191 2824 MBR partitions:
13:18:33.0191 2824 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:18:33.0191 2824 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1866E000
13:18:33.0191 2824 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x186A0800, BlocksNum 0x21CE5000
13:18:33.0191 2824 \Device\Harddisk5\DR5:
13:18:33.0207 2824 MBR partitions:
13:18:33.0207 2824 \Device\Harddisk5\DR5\Partition0: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0x1E3BFE0
13:18:33.0222 2824 C: <-> \Device\Harddisk0\DR0\Partition1
13:18:33.0331 2824 D: <-> \Device\Harddisk0\DR0\Partition2
13:18:33.0331 2824 Initialize success
13:18:33.0331 2824 ============================================================
13:18:37.0996 3340 ============================================================
13:18:37.0996 3340 Scan started
13:18:37.0996 3340 Mode: Manual;
13:18:37.0996 3340 ============================================================
13:18:39.0587 3340 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
13:18:39.0603 3340 1394ohci - ok
13:18:39.0649 3340 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
13:18:39.0665 3340 ACPI - ok
13:18:39.0681 3340 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
13:18:39.0696 3340 AcpiPmi - ok
13:18:39.0727 3340 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
13:18:39.0743 3340 adp94xx - ok
13:18:39.0774 3340 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
13:18:39.0774 3340 adpahci - ok
13:18:39.0790 3340 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
13:18:39.0805 3340 adpu320 - ok
13:18:39.0821 3340 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
13:18:39.0821 3340 AeLookupSvc - ok
13:18:39.0868 3340 AFD (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
13:18:39.0868 3340 AFD - ok
13:18:39.0899 3340 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
13:18:39.0899 3340 agp440 - ok
13:18:39.0930 3340 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
13:18:39.0930 3340 ALG - ok
13:18:39.0946 3340 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
13:18:39.0946 3340 aliide - ok
13:18:39.0993 3340 AMD External Events Utility (2aed9a422ea1574c7d7ef9359a417718) C:\Windows\system32\atiesrxx.exe
13:18:39.0993 3340 AMD External Events Utility - ok
13:18:40.0055 3340 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
13:18:40.0149 3340 amdide - ok
13:18:40.0227 3340 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
13:18:40.0242 3340 AmdK8 - ok
13:18:40.0617 3340 amdkmdag (bfa5e854959d5546d8834ca61f4ad075) C:\Windows\system32\DRIVERS\atikmdag.sys
13:18:40.0819 3340 amdkmdag - ok
13:18:40.0866 3340 amdkmdap (92d664fffcd9e742fb25254f7f458d88) C:\Windows\system32\DRIVERS\atikmpag.sys
13:18:40.0882 3340 amdkmdap - ok
13:18:40.0929 3340 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
13:18:40.0960 3340 AmdPPM - ok
13:18:40.0975 3340 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
13:18:40.0975 3340 amdsata - ok
13:18:40.0991 3340 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
13:18:41.0007 3340 amdsbs - ok
13:18:41.0022 3340 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
13:18:41.0022 3340 amdxata - ok
13:18:41.0100 3340 AntiVirMailService (b0bca3b6a95d02287bb9a48224e39b5a) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
13:18:41.0100 3340 AntiVirMailService - ok
13:18:41.0131 3340 AntiVirSchedulerService (d2ca88edb24bb59a830eb2d404c1915c) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
13:18:41.0147 3340 AntiVirSchedulerService - ok
13:18:41.0178 3340 AntiVirService (dbb40b2415e5422c12c9976a1f50e68b) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
13:18:41.0178 3340 AntiVirService - ok
13:18:41.0209 3340 AntiVirWebService (834070ebf5d387cf22df76ec2e30e899) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
13:18:41.0225 3340 AntiVirWebService - ok
13:18:41.0303 3340 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
13:18:41.0319 3340 AppID - ok
13:18:41.0350 3340 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
13:18:41.0365 3340 AppIDSvc - ok
13:18:41.0381 3340 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
13:18:41.0397 3340 Appinfo - ok
13:18:41.0428 3340 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
13:18:41.0443 3340 AppMgmt - ok
13:18:41.0475 3340 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
13:18:41.0475 3340 arc - ok
13:18:41.0490 3340 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
13:18:41.0490 3340 arcsas - ok
13:18:41.0568 3340 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:18:41.0615 3340 aspnet_state - ok
13:18:41.0709 3340 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
13:18:41.0740 3340 AsyncMac - ok
13:18:41.0771 3340 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
13:18:41.0771 3340 atapi - ok
13:18:41.0833 3340 AtiHDAudioService (2b3b05c0a7768bf033217eb8f33f9c35) C:\Windows\system32\drivers\AtihdW76.sys
13:18:41.0849 3340 AtiHDAudioService - ok
13:18:41.0911 3340 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
13:18:42.0005 3340 AudioEndpointBuilder - ok
13:18:42.0021 3340 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
13:18:42.0036 3340 AudioSrv - ok
13:18:42.0114 3340 avgntflt (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\Windows\system32\DRIVERS\avgntflt.sys
13:18:42.0114 3340 avgntflt - ok
13:18:42.0145 3340 avipbb (852e3c0a60d368c487949e55ad52a47f) C:\Windows\system32\DRIVERS\avipbb.sys
13:18:42.0161 3340 avipbb - ok
13:18:42.0177 3340 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
13:18:42.0177 3340 avkmgr - ok
13:18:42.0208 3340 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
13:18:42.0223 3340 AxInstSV - ok
13:18:42.0270 3340 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
13:18:42.0535 3340 b06bdrv - ok
13:18:42.0847 3340 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
13:18:42.0863 3340 b57nd60a - ok
13:18:42.0894 3340 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
13:18:42.0910 3340 BDESVC - ok
13:18:42.0925 3340 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
13:18:42.0925 3340 Beep - ok
13:18:42.0957 3340 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
13:18:42.0972 3340 BFE - ok
13:18:43.0003 3340 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
13:18:43.0019 3340 BITS - ok
13:18:43.0035 3340 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
13:18:43.0050 3340 blbdrive - ok
13:18:43.0081 3340 Bonjour Service (73686fe0b2e0469f89fd2075be724704) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
13:18:43.0097 3340 Bonjour Service - ok
13:18:43.0113 3340 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
13:18:43.0128 3340 bowser - ok
13:18:43.0144 3340 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:18:43.0144 3340 BrFiltLo - ok
13:18:43.0159 3340 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:18:43.0159 3340 BrFiltUp - ok
13:18:43.0175 3340 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
13:18:43.0191 3340 Browser - ok
13:18:43.0206 3340 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
13:18:43.0222 3340 Brserid - ok
13:18:43.0222 3340 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
13:18:43.0237 3340 BrSerWdm - ok
13:18:43.0237 3340 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:18:43.0237 3340 BrUsbMdm - ok
13:18:43.0253 3340 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
13:18:43.0253 3340 BrUsbSer - ok
13:18:43.0269 3340 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
13:18:43.0269 3340 BTHMODEM - ok
13:18:43.0284 3340 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
13:18:43.0300 3340 bthserv - ok
13:18:43.0315 3340 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
13:18:43.0315 3340 cdfs - ok
13:18:43.0378 3340 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
13:18:43.0393 3340 cdrom - ok
13:18:43.0425 3340 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
13:18:43.0425 3340 CertPropSvc - ok
13:18:43.0440 3340 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
13:18:43.0440 3340 circlass - ok
13:18:43.0471 3340 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
13:18:43.0471 3340 CLFS - ok
13:18:43.0534 3340 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:18:43.0549 3340 clr_optimization_v2.0.50727_32 - ok
13:18:43.0581 3340 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:18:43.0581 3340 clr_optimization_v2.0.50727_64 - ok
13:18:43.0643 3340 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:18:43.0659 3340 clr_optimization_v4.0.30319_32 - ok
13:18:43.0674 3340 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:18:43.0690 3340 clr_optimization_v4.0.30319_64 - ok
13:18:43.0752 3340 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
13:18:43.0783 3340 CmBatt - ok
13:18:43.0815 3340 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
13:18:43.0830 3340 cmdide - ok
13:18:43.0877 3340 CNG (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
13:18:43.0908 3340 CNG - ok
13:18:43.0924 3340 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
13:18:43.0924 3340 Compbatt - ok
13:18:43.0955 3340 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
13:18:43.0955 3340 CompositeBus - ok
13:18:43.0971 3340 COMSysApp - ok
13:18:44.0017 3340 cpuz135 (c08063f052308b6f5882482615387f30) C:\Windows\system32\drivers\cpuz135_x64.sys
13:18:44.0017 3340 cpuz135 - ok
13:18:44.0033 3340 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
13:18:44.0049 3340 crcdisk - ok
13:18:44.0080 3340 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
13:18:44.0080 3340 CryptSvc - ok
13:18:44.0127 3340 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
13:18:44.0142 3340 CSC - ok
13:18:44.0173 3340 CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
13:18:44.0189 3340 CscService - ok
13:18:44.0220 3340 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
13:18:44.0236 3340 DcomLaunch - ok
13:18:44.0251 3340 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
13:18:44.0267 3340 defragsvc - ok
13:18:44.0298 3340 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
13:18:44.0298 3340 DfsC - ok
13:18:44.0329 3340 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
13:18:44.0345 3340 Dhcp - ok
13:18:44.0361 3340 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
13:18:44.0361 3340 discache - ok
13:18:44.0392 3340 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
13:18:44.0392 3340 Disk - ok
13:18:44.0423 3340 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
13:18:44.0423 3340 Dnscache - ok
13:18:44.0485 3340 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
13:18:44.0485 3340 dot3svc - ok
13:18:44.0517 3340 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
13:18:44.0517 3340 DPS - ok
13:18:44.0563 3340 driverhardwarev2x64 (b28c853770c995552b9f5760d8245f44) C:\Program Files\ma-config.com\Drivers\driverhardwarev2x64.sys
13:18:44.0563 3340 driverhardwarev2x64 - ok
13:18:44.0595 3340 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
13:18:44.0595 3340 drmkaud - ok
13:18:44.0626 3340 dtsoftbus01 (46571ed73ae84469dca53081d33cf3c8) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
13:18:44.0641 3340 dtsoftbus01 - ok
13:18:44.0688 3340 DXGKrnl (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
13:18:44.0688 3340 DXGKrnl - ok
13:18:44.0719 3340 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
13:18:44.0719 3340 EapHost - ok
13:18:44.0797 3340 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
13:18:44.0875 3340 ebdrv - ok
13:18:45.0000 3340 EFS (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
13:18:45.0000 3340 EFS - ok
13:18:45.0047 3340 ehRecvr (b91d81b3b54a54ccafc03733dbc2e29e) C:\Windows\ehome\ehRecvr.exe
13:18:45.0063 3340 ehRecvr - ok
13:18:45.0094 3340 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
13:18:45.0094 3340 ehSched - ok
13:18:45.0156 3340 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
13:18:45.0172 3340 elxstor - ok
13:18:45.0187 3340 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
13:18:45.0203 3340 ErrDev - ok
13:18:45.0234 3340 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
13:18:45.0234 3340 EventSystem - ok
13:18:45.0281 3340 EverestDriver - ok
13:18:45.0297 3340 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
13:18:45.0312 3340 exfat - ok
13:18:45.0328 3340 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
13:18:45.0328 3340 fastfat - ok
13:18:45.0359 3340 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
13:18:45.0375 3340 Fax - ok
13:18:45.0390 3340 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
13:18:45.0390 3340 fdc - ok
13:18:45.0406 3340 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
13:18:45.0421 3340 fdPHost - ok
13:18:45.0437 3340 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
13:18:45.0437 3340 FDResPub - ok
13:18:45.0499 3340 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
13:18:45.0499 3340 FileInfo - ok
13:18:45.0515 3340 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
13:18:45.0515 3340 Filetrace - ok
13:18:45.0593 3340 FLEXnet Licensing Service (227846995afeefa70d328bf5334a86a5) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
13:18:45.0609 3340 FLEXnet Licensing Service - ok
13:18:45.0671 3340 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
13:18:45.0671 3340 flpydisk - ok
13:18:45.0687 3340 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
13:18:45.0702 3340 FltMgr - ok
13:18:45.0749 3340 FontCache (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll
13:18:45.0765 3340 FontCache - ok
13:18:45.0811 3340 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:18:45.0811 3340 FontCache3.0.0.0 - ok
13:18:45.0858 3340 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
13:18:45.0858 3340 FsDepends - ok
13:18:45.0905 3340 Fs_Rec (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
13:18:45.0905 3340 Fs_Rec - ok
13:18:45.0936 3340 fvevol (b8b2a6e1558f8f5de5ce431c5b2c7b09) C:\Windows\system32\DRIVERS\fvevol.sys
13:18:45.0952 3340 fvevol - ok
13:18:45.0967 3340 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:18:45.0967 3340 gagp30kx - ok
13:18:46.0014 3340 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
13:18:46.0014 3340 gpsvc - ok
13:18:46.0123 3340 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:18:46.0123 3340 gupdate - ok
13:18:46.0139 3340 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:18:46.0139 3340 gupdatem - ok
13:18:46.0155 3340 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
13:18:46.0155 3340 hcw85cir - ok
13:18:46.0186 3340 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
13:18:46.0201 3340 HdAudAddService - ok
13:18:46.0217 3340 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
13:18:46.0217 3340 HDAudBus - ok
13:18:46.0233 3340 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
13:18:46.0233 3340 HidBatt - ok
13:18:46.0248 3340 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
13:18:46.0264 3340 HidBth - ok
13:18:46.0279 3340 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
13:18:46.0295 3340 HidIr - ok
13:18:46.0311 3340 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
13:18:46.0326 3340 hidserv - ok
13:18:46.0357 3340 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
13:18:46.0357 3340 HidUsb - ok
13:18:46.0373 3340 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
13:18:46.0373 3340 hkmsvc - ok
13:18:46.0435 3340 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
13:18:46.0435 3340 HomeGroupListener - ok
13:18:46.0482 3340 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
13:18:46.0498 3340 HomeGroupProvider - ok
13:18:46.0560 3340 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
13:18:46.0591 3340 HpSAMD - ok
13:18:46.0669 3340 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
13:18:46.0685 3340 HTTP - ok
13:18:46.0701 3340 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
13:18:46.0701 3340 hwpolicy - ok
13:18:46.0732 3340 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
13:18:46.0747 3340 i8042prt - ok
13:18:46.0779 3340 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
13:18:46.0794 3340 iaStorV - ok
13:18:46.0841 3340 IDMWFP (5534e14ef27ebe8563cdbce6b88501a3) C:\Windows\system32\DRIVERS\idmwfp.sys
13:18:46.0857 3340 IDMWFP - ok
13:18:46.0919 3340 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:18:46.0950 3340 idsvc - ok
13:18:46.0981 3340 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
13:18:46.0997 3340 iirsp - ok
13:18:47.0028 3340 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
13:18:47.0044 3340 IKEEXT - ok
13:18:47.0059 3340 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
13:18:47.0059 3340 intelide - ok
13:18:47.0091 3340 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
13:18:47.0091 3340 intelppm - ok
13:18:47.0153 3340 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
13:18:47.0153 3340 IPBusEnum - ok
13:18:47.0184 3340 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:18:47.0200 3340 IpFilterDriver - ok
13:18:47.0231 3340 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
13:18:47.0262 3340 iphlpsvc - ok
13:18:47.0293 3340 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
13:18:47.0496 3340 IPMIDRV - ok
13:18:47.0621 3340 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
13:18:47.0637 3340 IPNAT - ok
13:18:47.0668 3340 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
13:18:47.0699 3340 IRENUM - ok
13:18:47.0730 3340 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
13:18:47.0746 3340 isapnp - ok
13:18:47.0777 3340 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
13:18:47.0793 3340 iScsiPrt - ok
13:18:47.0824 3340 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
13:18:47.0824 3340 kbdclass - ok
13:18:47.0855 3340 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
13:18:47.0855 3340 kbdhid - ok
13:18:47.0871 3340 KeyIso (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
13:18:47.0871 3340 KeyIso - ok
13:18:47.0917 3340 KSecDD (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
13:18:47.0917 3340 KSecDD - ok
13:18:47.0933 3340 KSecPkg (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
13:18:47.0933 3340 KSecPkg - ok
13:18:47.0964 3340 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
13:18:47.0964 3340 ksthunk - ok
13:18:47.0995 3340 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
13:18:48.0011 3340 KtmRm - ok
13:18:48.0042 3340 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
13:18:48.0042 3340 LanmanServer - ok
13:18:48.0058 3340 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
13:18:48.0058 3340 LanmanWorkstation - ok
13:18:48.0105 3340 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
13:18:48.0105 3340 lltdio - ok
13:18:48.0151 3340 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
13:18:48.0183 3340 lltdsvc - ok
13:18:48.0214 3340 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
13:18:48.0229 3340 lmhosts - ok
13:18:48.0261 3340 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:18:48.0261 3340 LSI_FC - ok
13:18:48.0276 3340 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:18:48.0292 3340 LSI_SAS - ok
13:18:48.0292 3340 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:18:48.0307 3340 LSI_SAS2 - ok
13:18:48.0307 3340 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:18:48.0323 3340 LSI_SCSI - ok
13:18:48.0339 3340 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
13:18:48.0339 3340 luafv - ok
13:18:48.0432 3340 maconfservice (06f1ef410df186cfd4dedf5974f48c65) C:\Program Files\ma-config.com\x64\maconfservice.exe
13:18:48.0463 3340 maconfservice - ok
13:18:48.0526 3340 MBAMProtector (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
13:18:48.0526 3340 MBAMProtector - ok
13:18:48.0573 3340 MBAMService (056b19651bd7b7ce5f89a3ac46dbdc08) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
13:18:48.0588 3340 MBAMService - ok
13:18:48.0635 3340 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
13:18:48.0635 3340 Mcx2Svc - ok
13:18:48.0666 3340 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
13:18:48.0666 3340 megasas - ok
13:18:48.0697 3340 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
13:18:48.0713 3340 MegaSR - ok
13:18:48.0729 3340 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:18:48.0729 3340 MMCSS - ok
13:18:48.0900 3340 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
13:18:48.0916 3340 Modem - ok
13:18:48.0963 3340 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
13:18:48.0963 3340 monitor - ok
13:18:48.0994 3340 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
13:18:49.0009 3340 mouclass - ok
13:18:49.0025 3340 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
13:18:49.0041 3340 mouhid - ok
13:18:49.0056 3340 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
13:18:49.0072 3340 mountmgr - ok
13:18:49.0103 3340 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
13:18:49.0103 3340 mpio - ok
13:18:49.0119 3340 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
13:18:49.0119 3340 mpsdrv - ok
13:18:49.0150 3340 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
13:18:49.0150 3340 MpsSvc - ok
13:18:49.0165 3340 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
13:18:49.0181 3340 MRxDAV - ok
13:18:49.0197 3340 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:18:49.0197 3340 mrxsmb - ok
13:18:49.0212 3340 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:18:49.0228 3340 mrxsmb10 - ok
13:18:49.0243 3340 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:18:49.0243 3340 mrxsmb20 - ok
13:18:49.0275 3340 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
13:18:49.0275 3340 msahci - ok
13:18:49.0290 3340 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
13:18:49.0306 3340 msdsm - ok
13:18:49.0321 3340 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
13:18:49.0337 3340 MSDTC - ok
13:18:49.0384 3340 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
13:18:49.0384 3340 Msfs - ok
13:18:49.0415 3340 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
13:18:49.0415 3340 mshidkmdf - ok
13:18:49.0415 3340 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
13:18:49.0431 3340 msisadrv - ok
13:18:49.0462 3340 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
13:18:49.0477 3340 MSiSCSI - ok
13:18:49.0493 3340 msiserver - ok
13:18:49.0524 3340 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
13:18:49.0540 3340 MSKSSRV - ok
13:18:49.0555 3340 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
13:18:49.0587 3340 MSPCLOCK - ok
13:18:49.0602 3340 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
13:18:49.0618 3340 MSPQM - ok
13:18:49.0665 3340 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
13:18:49.0680 3340 MsRPC - ok
13:18:49.0743 3340 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
13:18:49.0743 3340 mssmbios - ok
13:18:49.0758 3340 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
13:18:49.0758 3340 MSTEE - ok
13:18:49.0774 3340 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
13:18:49.0774 3340 MTConfig - ok
13:18:49.0789 3340 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
13:18:49.0789 3340 Mup - ok
13:18:49.0867 3340 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
13:18:49.0867 3340 napagent - ok
13:18:49.0899 3340 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
13:18:49.0914 3340 NativeWifiP - ok
13:18:50.0086 3340 NBService (87a00faedd703d8d2bdcb29ce5eeea6b) C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
13:18:50.0101 3340 NBService - ok
13:18:50.0179 3340 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
13:18:50.0211 3340 NDIS - ok
13:18:50.0226 3340 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
13:18:50.0226 3340 NdisCap - ok
13:18:50.0273 3340 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
13:18:50.0273 3340 NdisTapi - ok
13:18:50.0289 3340 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
13:18:50.0289 3340 Ndisuio - ok
13:18:50.0304 3340 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
13:18:50.0320 3340 NdisWan - ok
13:18:50.0335 3340 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
13:18:50.0351 3340 NDProxy - ok
13:18:50.0367 3340 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
13:18:50.0367 3340 NetBIOS - ok
13:18:50.0382 3340 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
13:18:50.0382 3340 NetBT - ok
13:18:50.0413 3340 Netlogon (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
13:18:50.0413 3340 Netlogon - ok
13:18:50.0445 3340 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
13:18:50.0445 3340 Netman - ok
13:18:50.0507 3340 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:18:50.0538 3340 NetMsmqActivator - ok
13:18:50.0554 3340 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:18:50.0554 3340 NetPipeActivator - ok
13:18:50.0616 3340 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
13:18:50.0663 3340 netprofm - ok
13:18:50.0741 3340 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:18:50.0741 3340 NetTcpActivator - ok
13:18:50.0757 3340 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:18:50.0757 3340 NetTcpPortSharing - ok
13:18:50.0803 3340 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
13:18:50.0803 3340 nfrd960 - ok
13:18:50.0850 3340 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
13:18:50.0866 3340 NlaSvc - ok
13:18:50.0881 3340 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
13:18:50.0897 3340 Npfs - ok
13:18:50.0913 3340 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
13:18:50.0913 3340 nsi - ok
13:18:50.0928 3340 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
13:18:50.0928 3340 nsiproxy - ok
13:18:50.0991 3340 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
13:18:51.0022 3340 Ntfs - ok
13:18:51.0084 3340 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
13:18:51.0084 3340 Null - ok
13:18:51.0100 3340 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
13:18:51.0115 3340 nvraid - ok
13:18:51.0115 3340 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
13:18:51.0131 3340 nvstor - ok
13:18:51.0147 3340 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
13:18:51.0162 3340 nv_agp - ok
13:18:51.0287 3340 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:18:51.0303 3340 odserv - ok
13:18:51.0381 3340 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
13:18:51.0396 3340 ohci1394 - ok
13:18:51.0490 3340 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:18:51.0537 3340 ose - ok
13:18:51.0895 3340 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
13:18:52.0036 3340 osppsvc - ok
13:18:52.0145 3340 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:18:52.0145 3340 p2pimsvc - ok
13:18:52.0161 3340 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
13:18:52.0176 3340 p2psvc - ok
13:18:52.0192 3340 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
13:18:52.0207 3340 Parport - ok
13:18:52.0223 3340 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
13:18:52.0223 3340 partmgr - ok
13:18:52.0239 3340 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
13:18:52.0254 3340 PcaSvc - ok
13:18:52.0707 3340 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 (7317a0b550f7ac0223b7070897670476) c:\program files\dell support center\pcdsrvc_x64.pkms
13:18:52.0769 3340 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - ok
13:18:53.0143 3340 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
13:18:53.0143 3340 pci - ok
13:18:53.0159 3340 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
13:18:53.0159 3340 pciide - ok
13:18:53.0175 3340 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
13:18:53.0190 3340 pcmcia - ok
13:18:53.0190 3340 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
13:18:53.0190 3340 pcw - ok
13:18:53.0206 3340 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
13:18:53.0221 3340 PEAUTH - ok
13:18:53.0284 3340 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
13:18:53.0299 3340 PeerDistSvc - ok
13:18:53.0362 3340 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
13:18:53.0362 3340 PerfHost - ok
13:18:53.0424 3340 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
13:18:53.0471 3340 pla - ok
13:18:53.0518 3340 PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
13:18:53.0533 3340 PlugPlay - ok
13:18:53.0549 3340 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
13:18:53.0549 3340 PNRPAutoReg - ok
13:18:53.0565 3340 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:18:53.0580 3340 PNRPsvc - ok
13:18:53.0627 3340 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
13:18:53.0643 3340 PolicyAgent - ok
13:18:53.0705 3340 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
13:18:53.0705 3340 Power - ok
13:18:53.0752 3340 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
13:18:53.0752 3340 PptpMiniport - ok
13:18:53.0783 3340 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
13:18:53.0799 3340 Processor - ok
13:18:53.0830 3340 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
13:18:53.0845 3340 ProfSvc - ok
13:18:53.0877 3340 ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
13:18:53.0877 3340 ProtectedStorage - ok
13:18:53.0892 3340 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
13:18:53.0892 3340 Psched - ok
13:18:53.0955 3340 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
13:18:54.0001 3340 ql2300 - ok
13:18:54.0017 3340 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
13:18:54.0033 3340 ql40xx - ok
13:18:54.0048 3340 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
13:18:54.0064 3340 QWAVE - ok
13:18:54.0079 3340 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
13:18:54.0079 3340 QWAVEdrv - ok
13:18:54.0095 3340 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
13:18:54.0095 3340 RasAcd - ok
13:18:54.0126 3340 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:18:54.0142 3340 RasAgileVpn - ok
13:18:54.0157 3340 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
13:18:54.0157 3340 RasAuto - ok
13:18:54.0173 3340 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:18:54.0189 3340 Rasl2tp - ok
13:18:54.0204 3340 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
13:18:54.0220 3340 RasMan - ok
13:18:54.0220 3340 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
13:18:54.0235 3340 RasPppoe - ok
13:18:54.0251 3340 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
13:18:54.0251 3340 RasSstp - ok
13:18:54.0267 3340 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
13:18:54.0282 3340 rdbss - ok
13:18:54.0282 3340 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
13:18:54.0282 3340 rdpbus - ok
13:18:54.0298 3340 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:18:54.0298 3340 RDPCDD - ok
13:18:54.0329 3340 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
13:18:54.0329 3340 RDPDR - ok
13:18:54.0345 3340 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
13:18:54.0345 3340 RDPENCDD - ok
13:18:54.0345 3340 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
13:18:54.0345 3340 RDPREFMP - ok
13:18:54.0391 3340 RDPWD (074ac702d8b8b660b0e1371555995386) C:\Windows\system32\drivers\RDPWD.sys
13:18:54.0407 3340 RDPWD - ok
13:18:54.0423 3340 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
13:18:54.0438 3340 rdyboost - ok
13:18:54.0469 3340 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
13:18:54.0469 3340 RemoteAccess - ok
13:18:54.0485 3340 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
13:18:54.0501 3340 RemoteRegistry - ok
13:18:54.0516 3340 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
13:18:54.0532 3340 RpcEptMapper - ok
13:18:54.0547 3340 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
13:18:54.0547 3340 RpcLocator - ok
13:18:54.0579 3340 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
13:18:54.0579 3340 RpcSs - ok
13:18:54.0594 3340 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
13:18:54.0610 3340 rspndr - ok
13:18:54.0641 3340 RTL8169 (e3aa12faa3192d1090b9069c3925373b) C:\Windows\system32\DRIVERS\Rtlh64.sys
13:18:54.0641 3340 RTL8169 - ok
13:18:54.0688 3340 RTL8187B (98eb56776f2e3f5ec9b4eaba63a60687) C:\Windows\system32\DRIVERS\RTL8187B.sys
13:18:54.0703 3340 RTL8187B - ok
13:18:54.0735 3340 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
13:18:54.0735 3340 s3cap - ok
13:18:54.0766 3340 SamSs (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
13:18:54.0766 3340 SamSs - ok
13:18:54.0797 3340 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
13:18:54.0797 3340 sbp2port - ok
13:18:54.0828 3340 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
13:18:54.0828 3340 SCardSvr - ok
13:18:54.0844 3340 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
13:18:54.0844 3340 scfilter - ok
13:18:54.0891 3340 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
13:18:54.0906 3340 Schedule - ok
13:18:54.0922 3340 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
13:18:54.0922 3340 SCPolicySvc - ok
13:18:54.0953 3340 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
13:18:54.0953 3340 SDRSVC - ok
13:18:54.0969 3340 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
13:18:54.0984 3340 secdrv - ok
13:18:55.0000 3340 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
13:18:55.0000 3340 seclogon - ok
13:18:55.0031 3340 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
13:18:55.0031 3340 SENS - ok
13:18:55.0093 3340 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
13:18:55.0093 3340 SensrSvc - ok
13:18:55.0109 3340 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
13:18:55.0125 3340 Serenum - ok
13:18:55.0140 3340 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
13:18:55.0156 3340 Serial - ok
13:18:55.0171 3340 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
13:18:55.0187 3340 sermouse - ok
13:18:55.0203 3340 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
13:18:55.0203 3340 SessionEnv - ok
13:18:55.0218 3340 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
13:18:55.0218 3340 sffdisk - ok
13:18:55.0234 3340 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
13:18:55.0234 3340 sffp_mmc - ok
13:18:55.0249 3340 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
13:18:55.0249 3340 sffp_sd - ok
13:18:55.0249 3340 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
13:18:55.0249 3340 sfloppy - ok
13:18:55.0281 3340 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
13:18:55.0281 3340 SharedAccess - ok
13:18:55.0296 3340 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
13:18:55.0312 3340 ShellHWDetection - ok
13:18:55.0327 3340 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:18:55.0327 3340 SiSRaid2 - ok
13:18:55.0327 3340 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
13:18:55.0343 3340 SiSRaid4 - ok
13:18:55.0359 3340 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
13:18:55.0374 3340 Smb - ok
13:18:55.0405 3340 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
13:18:55.0405 3340 SNMPTRAP - ok
13:18:55.0421 3340 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
13:18:55.0421 3340 spldr - ok
13:18:55.0468 3340 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
13:18:55.0483 3340 Spooler - ok
13:18:55.0702 3340 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
13:18:55.0749 3340 sppsvc - ok
13:18:55.0795 3340 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
13:18:55.0811 3340 sppuinotify - ok
13:18:55.0842 3340 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
13:18:55.0858 3340 srv - ok
13:18:55.0873 3340 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
13:18:55.0873 3340 srv2 - ok
13:18:55.0889 3340 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
13:18:55.0905 3340 srvnet - ok
13:18:55.0936 3340 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
13:18:55.0951 3340 SSDPSRV - ok
13:18:55.0951 3340 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
13:18:55.0967 3340 SstpSvc - ok
13:18:55.0983 3340 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
13:18:55.0998 3340 stexstor - ok
13:18:56.0045 3340 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
13:18:56.0061 3340 stisvc - ok
13:18:56.0076 3340 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
13:18:56.0092 3340 storflt - ok
13:18:56.0107 3340 StorSvc (c40841817ef57d491f22eb103da587cc) C:\Windows\system32\storsvc.dll
13:18:56.0107 3340 StorSvc - ok
13:18:56.0123 3340 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
13:18:56.0123 3340 storvsc - ok
13:18:56.0139 3340 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
13:18:56.0154 3340 swenum - ok
13:18:56.0185 3340 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
13:18:56.0201 3340 swprv - ok
13:18:56.0248 3340 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
13:18:56.0263 3340 SysMain - ok
13:18:56.0279 3340 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
13:18:56.0279 3340 TabletInputService - ok
13:18:56.0295 3340 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
13:18:56.0310 3340 TapiSrv - ok
13:18:56.0326 3340 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
13:18:56.0326 3340 TBS - ok
13:18:56.0388 3340 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
13:18:56.0419 3340 Tcpip - ok
13:18:56.0466 3340 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
13:18:56.0482 3340 TCPIP6 - ok
13:18:56.0529 3340 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
13:18:56.0529 3340 tcpipreg - ok
13:18:56.0544 3340 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
13:18:56.0560 3340 TDPIPE - ok
13:18:56.0575 3340 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
13:18:56.0575 3340 TDTCP - ok
13:18:56.0591 3340 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
13:18:56.0607 3340 tdx - ok
13:18:56.0622 3340 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
13:18:56.0622 3340 TermDD - ok
13:18:56.0653 3340 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
13:18:56.0669 3340 TermService - ok
13:18:56.0685 3340 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
13:18:56.0685 3340 Themes - ok
13:18:56.0716 3340 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:18:56.0716 3340 THREADORDER - ok
13:18:56.0794 3340 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
13:18:56.0809 3340 TrkWks - ok
13:18:56.0872 3340 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
13:18:56.0872 3340 TrustedInstaller - ok
13:18:56.0950 3340 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:18:56.0950 3340 tssecsrv - ok
13:18:56.0965 3340 TuneUp.UtilitiesSvc - ok
13:18:56.0981 3340 TuneUpUtilitiesDrv - ok
13:18:56.0997 3340 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
13:18:57.0012 3340 tunnel - ok
13:18:57.0028 3340 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
13:18:57.0028 3340 uagp35 - ok
13:18:57.0059 3340 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
13:18:57.0059 3340 udfs - ok
13:18:57.0090 3340 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
13:18:57.0106 3340 UI0Detect - ok
13:18:57.0137 3340 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
13:18:57.0137 3340 uliagpkx - ok
13:18:57.0168 3340 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
13:18:57.0168 3340 umbus - ok
13:18:57.0184 3340 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
13:18:57.0184 3340 UmPass - ok
13:18:57.0215 3340 UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
13:18:57.0215 3340 UmRdpService - ok
13:18:57.0246 3340 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
13:18:57.0246 3340 upnphost - ok
13:18:57.0262 3340 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
13:18:57.0277 3340 usbccgp - ok
13:18:57.0293 3340 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
13:18:57.0293 3340 usbcir - ok
13:18:57.0402 3340 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
13:18:57.0449 3340 usbehci - ok
13:18:57.0667 3340 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
13:18:57.0683 3340 usbhub - ok
13:18:57.0699 3340 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
13:18:57.0699 3340 usbohci - ok
13:18:57.0714 3340 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
13:18:57.0714 3340 usbprint - ok
13:18:57.0730 3340 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:18:57.0745 3340 USBSTOR - ok
13:18:57.0761 3340 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
13:18:57.0761 3340 usbuhci - ok
13:18:57.0777 3340 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
13:18:57.0777 3340 UxSms - ok
13:18:57.0839 3340 UxTuneUp (601a5ccf88fc66f13631c80f6eb4c69f) C:\Windows\System32\uxtuneup.dll
13:18:57.0839 3340 UxTuneUp - ok
13:18:57.0870 3340 VaultSvc (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
13:18:57.0870 3340 VaultSvc - ok
13:18:57.0886 3340 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
13:18:57.0901 3340 vdrvroot - ok
13:18:57.0917 3340 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
13:18:57.0917 3340 vds - ok
13:18:57.0933 3340 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
13:18:57.0948 3340 vga - ok
13:18:57.0964 3340 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
13:18:57.0964 3340 VgaSave - ok
13:18:57.0995 3340 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
13:18:57.0995 3340 vhdmp - ok
13:18:58.0011 3340 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
13:18:58.0026 3340 viaide - ok
13:18:58.0042 3340 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
13:18:58.0057 3340 vmbus - ok
13:18:58.0089 3340 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
13:18:58.0089 3340 VMBusHID - ok
13:18:58.0104 3340 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
13:18:58.0120 3340 volmgr - ok
13:18:58.0120 3340 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
13:18:58.0135 3340 volmgrx - ok
13:18:58.0167 3340 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
13:18:58.0182 3340 volsnap - ok
13:18:58.0213 3340 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
13:18:58.0213 3340 vsmraid - ok
13:18:58.0260 3340 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
13:18:58.0291 3340 VSS - ok
13:18:58.0307 3340 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
13:18:58.0307 3340 vwifibus - ok
13:18:58.0370 3340 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
13:18:58.0370 3340 vwififlt - ok
13:18:58.0401 3340 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
13:18:58.0416 3340 W32Time - ok
13:18:58.0448 3340 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
13:18:58.0448 3340 WacomPen - ok
13:18:58.0479 3340 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
13:18:58.0479 3340 WANARP - ok
13:18:58.0494 3340 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
13:18:58.0494 3340 Wanarpv6 - ok
13:18:58.0541 3340 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
13:18:58.0604 3340 WatAdminSvc - ok
13:18:58.0650 3340 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
13:18:58.0682 3340 wbengine - ok
13:18:58.0713 3340 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
13:18:58.0728 3340 WbioSrvc - ok
13:18:58.0728 3340 wcncsvc (8321c2ca3b62b61b293cda3451984468) C:\Windows\System32\wcncsvc.dll
13:18:58.0744 3340 wcncsvc - ok
13:18:58.0760 3340 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
13:18:58.0760 3340 WcsPlugInService - ok
13:18:58.0791 3340 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
13:18:58.0806 3340 Wd - ok
13:18:58.0822 3340 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
13:18:58.0838 3340 Wdf01000 - ok
13:18:58.0869 3340 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:18:58.0884 3340 WdiServiceHost - ok
13:18:58.0884 3340 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:18:58.0884 3340 WdiSystemHost - ok
13:18:58.0900 3340 WebClient (8a438cbb8c032a0c798b0c642ffbe572) C:\Windows\System32\webclnt.dll
13:18:58.0900 3340 WebClient - ok
13:18:58.0916 3340 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
13:18:58.0931 3340 Wecsvc - ok
13:18:58.0947 3340 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
13:18:58.0947 3340 wercplsupport - ok
13:18:58.0962 3340 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
13:18:58.0978 3340 WerSvc - ok
13:18:58.0978 3340 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
13:18:58.0978 3340 WfpLwf - ok
13:18:59.0009 3340 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
13:18:59.0009 3340 WIMMount - ok
13:18:59.0025 3340 WinDefend - ok
13:18:59.0040 3340 WinHttpAutoProxySvc - ok
13:18:59.0087 3340 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
13:18:59.0103 3340 Winmgmt - ok
13:18:59.0165 3340 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
13:18:59.0212 3340 WinRM - ok
13:18:59.0243 3340 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
13:18:59.0243 3340 Wlansvc - ok
13:18:59.0274 3340 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
13:18:59.0274 3340 WmiAcpi - ok
13:18:59.0321 3340 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
13:18:59.0337 3340 wmiApSrv - ok
13:18:59.0352 3340 WMPNetworkSvc - ok
13:18:59.0368 3340 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
13:18:59.0368 3340 WPCSvc - ok
13:18:59.0430 3340 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
13:18:59.0430 3340 WPDBusEnum - ok
13:18:59.0477 3340 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
13:18:59.0493 3340 ws2ifsl - ok
13:18:59.0508 3340 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
13:18:59.0508 3340 wscsvc - ok
13:18:59.0524 3340 WSearch - ok
13:18:59.0680 3340 wuauserv (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
13:18:59.0711 3340 wuauserv - ok
13:18:59.0789 3340 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
13:18:59.0805 3340 WudfPf - ok
13:18:59.0836 3340 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:18:59.0836 3340 WUDFRd - ok
13:18:59.0867 3340 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
13:18:59.0867 3340 wudfsvc - ok
13:18:59.0883 3340 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
13:18:59.0883 3340 WwanSvc - ok
13:18:59.0914 3340 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:18:59.0992 3340 \Device\Harddisk0\DR0 - ok
13:18:59.0992 3340 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk5\DR5
13:19:01.0412 3340 \Device\Harddisk5\DR5 - ok
13:19:01.0412 3340 Boot (0x1200) (7e2d015fda7336a4cd2cd2b22c0d83d3) \Device\Harddisk0\DR0\Partition0
13:19:01.0427 3340 \Device\Harddisk0\DR0\Partition0 - ok
13:19:01.0443 3340 Boot (0x1200) (b6932d6fb1c9847ca4326f5bf51aab05) \Device\Harddisk0\DR0\Partition1
13:19:01.0443 3340 \Device\Harddisk0\DR0\Partition1 - ok
13:19:01.0474 3340 Boot (0x1200) (190e16c61639f238a634392fb5776fa4) \Device\Harddisk0\DR0\Partition2
13:19:01.0505 3340 \Device\Harddisk0\DR0\Partition2 - ok
13:19:01.0505 3340 Boot (0x1200) (bc713ba66da1fd6ff55acade8a3b8223) \Device\Harddisk5\DR5\Partition0
13:19:01.0505 3340 \Device\Harddisk5\DR5\Partition0 - ok
13:19:01.0505 3340 ============================================================
13:19:01.0505 3340 Scan finished
13:19:01.0505 3340 ============================================================
13:19:01.0521 3552 Detected object count: 0
13:19:01.0521 3552 Actual detected object count: 0
O4 - HKUS\S-1-5-21-3990501594-3456977767-1360621759-1000\..\Run: [F.lux] . (...) -- C:\Users\dell\Local Settings\Apps\F.lux\flux.exe
O4 - Global Startup: C:\Users\dell\Desktop\Connexion réseau sans fil - Raccourci.lnk - Clé orpheline
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) . (...) - D:\tuneup2012\TuneUpUtilitiesService64.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [TuneUpUtilities_Task_BkGndMaintenance2012] (...) -- D:\tuneup2012\OneClick.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [{06247684-C6EB-4CA6-B176-F19C803CA934}] (...) -- C:\Program Files (x86)\TuneUp Utilities 2012\Integrator.exe (.not file.)
O42 - Logiciel: F.lux - (.Pas de propriétaire.) [HKCU] -- Flux
O43 - CFD: 06/04/2012 - 22:23:51 - [22,936] -S--D C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
O43 - CFD: 20/04/2012 - 18:45:41 - [0,022] ----D C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
O43 - CFD: 14/04/2012 - 18:44:41 - [0,000] ----D C:\Users\dell\AppData\Local\http___www.julien-manici
O43 - CFD: 13/04/2012 - 22:13:51 - [0,004] ----D C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
O44 - LFC:[MD5.37811A93F6153625ED29A906BB5B2472] - 20/04/2012 - 21:20:50 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1665467]
O44 - LFC:[MD5.605C05C93A358F4FE8E3E68A3EF653CB] - 20/04/2012 - 21:17:45 ---A- . (...) -- C:\Windows\setupact.log [32366]
O44 - LFC:[MD5.159AC04C9635671BD25ADA1CBA173E9D] - 11/04/2012 - 17:53:39 ---A- . (...) -- C:\Windows\ntbtlog.txt [310910]
O44 - LFC:[MD5.505FA3D516C6D9694A0D2A3AF2D04CDE] - 11/04/2012 - 14:51:39 ---A- . (...) -- C:\Windows\err.txt [600]
O53 - SMSR:HKLM\...\startupreg\adm_tray.exe [Key] . (...) -- C:\Program Files (x86)\Acronis\DriveMonitor\adm_tray.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Service Planificateur2 Acronis [Key] . (...) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\vProt [Key] . (...) -- C:\Program Files (x86)\AVG Secure Search\vprot.exe (.not file.)
[MD5.1829BEA055E50AEC58AA1C7FFAF6C00C] [SPRF][10/04/2012] (...) -- C:\ProgramData\ezsidmv.dat [48]
O87 - FAEL: %µ£WMPNSS-In-UDP-NoScope%µ£ |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: %µ£WMPNSS-Out-UDP-NoScope%µ£ |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: %µ£WMPNSS-In-TCP-NoScope%µ£ |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: %µ£WMPNSS-Out-TCP-NoScope%µ£ |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: %µ£WMPNSS-In-UDP%µ£ |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: %µ£WMPNSS-Out-UDP%µ£ |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: %µ£WMPNSS-In-TCP%µ£ |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: %µ£WMPNSS-Out-TCP%µ£ |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
[HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong
C:\Users\dell\AppData\LocalLow\PriceGong =>Adware.PriceGong
emptytemp
emptyflash
Rapport de ZHPFix 1.12.3378 par Nicolas Coolman, Update du 10/01/2011
Fichier d'export Registre :
Run by dell at 21/04/2012 16:26:27
Windows 7 Business Edition, 64-bit (Build 7600)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Web site : http://nicolascoolman.skyrock.com/
========== Logiciel(s) ==========
ABSENT Uninstall Process: c:\users\dell\local settings\apps\f.lux\uninstall.exe
========== Clé(s) du Registre ==========
SUPPRIME [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flux]
SUPPRIME Key: Service: TuneUp.UtilitiesSvc
SUPPRIME Key**: StartupReg: adm_tray.exe
SUPPRIME Key**: StartupReg: Service Planificateur2 Acronis
SUPPRIME Key**: StartupReg: vProt
SUPPRIME Key: HKCU\Software\AppDataLow\Software\PriceGong
========== Valeur(s) du Registre ==========
SUPPRIME RunValue: F.lux
ABSENT µ£WMPNSS-In-UDP-NoScope%µ£ |In - Domain - P17 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
ABSENT µ£WMPNSS-Out-UDP-NoScope%µ£ |Out - Domain - P17 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
ABSENT µ£WMPNSS-In-TCP-NoScope%µ£ |In - Domain - P6 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
ABSENT µ£WMPNSS-Out-TCP-NoScope%µ£ |Out - Domain - P6 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
ABSENT µ£WMPNSS-In-UDP%µ£ |In - Public - P17 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
ABSENT µ£WMPNSS-Out-UDP%µ£ |Out - Public - P17 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
ABSENT µ£WMPNSS-In-TCP%µ£ |In - Public - P6 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
ABSENT µ£WMPNSS-Out-TCP%µ£ |Out - Public - P6 - FALSE | .(...) -- C:/Program Files (x86)/Windows Media Player/wmpnetwk.exe (.not file.)
========== Dossier(s) ==========
SUPPRIME Folder: C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
SUPPRIME Folder: C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
SUPPRIME Folder: C:\Users\dell\AppData\Local\http___www.julien-manici
SUPPRIME Folder: C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
SUPPRIME Folder: c:\users\dell\appdata\locallow\pricegong
SUPPRIME Temporaires Windows: : 168
SUPPRIME Flash Cookies: 7
========== Fichier(s) ==========
SUPPRIME Reboot c:\users\dell\local settings\apps\f.lux\flux.exe
SUPPRIME File: c:\users\dell\desktop\connexion réseau sans fil - raccourci.lnk
ABSENT File: d:\tuneup2012\tuneuputilitiesservice64.exe
SUPPRIME Reboot c:\windows\windowsupdate.log
SUPPRIME File: c:\windows\setupact.log
SUPPRIME File: c:\windows\ntbtlog.txt
SUPPRIME File: c:\windows\err.txt
ABSENT File: c:\program files (x86)\acronis\drivemonitor\adm_tray.exe
SUPPRIME File: C:\ProgramData\ezsidmv.dat
SUPPRIME Temporaires Windows: : 236
SUPPRIME Flash Cookies: 7
========== Tache planifiée ==========
SUPPRIME Task: TuneUpUtilities_Task_BkGndMaintenance2012
SUPPRIME Task: {06247684-C6EB-4CA6-B176-F19C803CA934}
========== Récapitulatif ==========
6 : Clé(s) du Registre
9 : Valeur(s) du Registre
7 : Dossier(s)
11 : Fichier(s)
1 : Logiciel(s)
2 : Tache planifiée
End of clean in 00mn 05s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 19/04/2012 18:48:39 [2326]
C:\ZHP\ZHPFix[R2].txt - 19/04/2012 21:38:52 [2378]
C:\ZHP\ZHPFix[R3].txt - 20/04/2012 12:50:53 [2323]
C:\ZHP\ZHPFix[R4].txt - 21/04/2012 16:26:27 [3576]
MER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-04-21 16:35:20
Windows 6.1.7600
Running: 3rnr2f8k.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Carte réseau USB\x00a02.0 Realtek RTL8187B sans fil 802.11b/g 54\xa0Mbits/s 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Carte réseau USB\x00a02.0 Realtek RTL8187B sans fil 802.11b/g 54\xa0Mbits/s 1?
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Bibliothèque multimédia Microsoft.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Bibliothèque multimédia Microsoft.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Certificat numérique pour les projets VBA.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Certificat numérique pour les projets VBA.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Microsoft Office 2010 Centre de téléchargement.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Microsoft Office 2010 Centre de téléchargement.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Microsoft Office Picture Manager.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Microsoft Office Picture Manager.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Office Anytime Upgrade.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Office Anytime Upgrade.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\Users\dell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Préférences de langue de Microsoft Office 2010.lnk 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts@C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Outils Microsoft Office\x00a02010\Préférences de langue de Microsoft Office 2010.lnk 1
---- EOF - GMER 1.0.15 ----
Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 12 invités
![]() .: Nous contacter :: Flux RSS :: Données personnelles :. ![]() |