Pc veroler

Bonjouvoila depuis certain jours jai remarquer que mon pc buger a repetion et en plus de sa il ram enormement jai lanser un scan avec malwhare mais cela na rien donner jai lancer un scan avec spybot et rien du tout donc jai lancer avast 5 et il na rien trouver aussi je ne ses plus quoi fair aider moi svp

8 réponses

  1. salut pour commencer vire spybot

    ensuite :

    Télécharge ici :OTL

    ▶ enregistre le sur ton Bureau.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    ▶ Coche les 2 cases Lop et Purity

    ▶ Coche la case devant tous les utilisateurs

    ▶ règle age du fichier sur "60 jours"

    ▶ dans la moitié gauche , mets tout sur "tous"

    ne modifie pas ceci :

    "fichiers créés" et "fichiers Modifiés"


    ▶Clic sur Analyse.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
    1. bsr merci de ton aide jai suivie a la lettres ce que tu ma dit de fair j espere que tu a recut mes fichier du scan de otl ? que fair maintent ?
      1. juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

        ? Copie ce lien dans ta réponse.

        ?? Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
        1. ▶ Télécharge ici : Ad-remover sur ton bureau :

          ▶ Déconnecte toi et ferme toutes applications en cours !

          si tu as XP => double clique
          si tu as Vista ou windows 7 => clic droit "executer en tant que...."


          ▶ sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

          ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

          ▶ Au menu principal choisis "option Nettoyer" et tape sur [entrée] .

          ▶ Laisse travailler l'outil et ne touche à rien ...

          ▶ Poste le rapport qui apparait à la fin , sur le forum ...

          ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
          ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

          ▶ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          ensuite :

          relance ad-remover , puis desinstalle-le

          ensuite :

          * Télécharge ici : USBFIX sur ton bureau

          /!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

          si tu as XP => double clique
          si tu as Vista ou windows 7 => clic droit "executer en tant que...."


          sur l'icône Usbfix située sur ton Bureau.
          Sur la page, clique sur le bouton :

          « Recherche »

          /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

          - puis clique sur OK
          - Laisse travailler l'outil.
          - Poste le rapport qui apparaît à la fin.
          le rapport se trouve sur C:\ UsbFix.txt

          Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
          1. OTL logfile created on: 07/09/2010 00:52:29 - Run 1
            OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\$\Bureau
            Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
            Internet Explorer (Version = 8.0.6001.18702)
            Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

            2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 60,00% Memory free
            4,00 Gb Paging File | 3,00 Gb Available in Paging File | 84,00% Paging File free
            Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

            %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
            Drive C: | 115,14 Gb Total Space | 59,97 Gb Free Space | 52,08% Space Free | Partition Type: NTFS
            Drive D: | 111,74 Gb Total Space | 110,15 Gb Free Space | 98,58% Space Free | Partition Type: NTFS
            Drive E: | 5,99 Gb Total Space | 3,64 Gb Free Space | 60,78% Space Free | Partition Type: FAT32
            F: Drive not present or media not loaded
            G: Drive not present or media not loaded
            H: Drive not present or media not loaded
            I: Drive not present or media not loaded

            Computer Name: OEM-2B7087C8C3D
            Current User Name: $
            Logged in as Administrator.

            Current Boot Mode: Normal
            Scan Mode: All users
            Company Name Whitelist: Off
            Skip Microsoft Files: Off
            File Age = 60 Days
            Output = Standard

            [color=#E56717]========== Processes (SafeList) ==========[/color]

            PRC - [2010/09/07 00:51:13 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
            PRC - [2010/07/11 23:22:34 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            PRC - [2010/06/28 22:57:18 | 002,837,864 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
            PRC - [2010/06/28 22:57:15 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
            PRC - [2010/03/25 01:17:31 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
            PRC - [2010/03/04 23:38:02 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
            PRC - [2009/10/15 10:53:54 | 000,959,808 | ---- | M] (SFR) -- C:\Program Files\SFR\Kit\9props.exe
            PRC - [2009/09/30 20:58:42 | 000,026,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
            PRC - [2009/03/31 09:39:36 | 000,233,472 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
            PRC - [2008/04/14 04:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
            PRC - [2005/12/13 10:45:34 | 000,176,128 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
            PRC - [2005/10/12 13:30:24 | 000,086,140 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
            PRC - [2004/04/02 14:31:06 | 000,086,016 | ---- | M] (ICSI Technology Ltd.) -- C:\WINDOWS\Dit.exe
            PRC - [2001/11/12 13:31:48 | 000,020,480 | ---- | M] (X10) -- C:\Program Files\Common Files\X10\Common\X10nets.exe

            [color=#E56717]========== Modules (All) ==========[/color]

            MOD - [2010/09/07 00:51:13 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
            MOD - [2010/07/27 08:30:01 | 008,518,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll
            MOD - [2009/12/08 11:24:28 | 000,474,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shlwapi.dll
            MOD - [2009/11/21 17:58:49 | 000,471,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\AppPatch\aclayers.dll
            MOD - [2009/06/25 10:26:32 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\secur32.dll
            MOD - [2009/04/15 16:53:29 | 000,585,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll
            MOD - [2009/03/21 16:07:58 | 001,054,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kernel32.dll
            MOD - [2009/02/27 06:57:11 | 000,177,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msctfime.ime
            MOD - [2009/02/09 12:53:55 | 000,739,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntdll.dll
            MOD - [2009/02/09 12:53:55 | 000,685,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advapi32.dll
            MOD - [2008/10/23 14:36:51 | 000,286,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\gdi32.dll
            MOD - [2008/04/14 04:34:34 | 000,146,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winspool.drv
            MOD - [2008/04/14 04:33:48 | 000,734,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\userenv.dll
            MOD - [2008/04/14 04:33:48 | 000,579,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\user32.dll
            MOD - [2008/04/14 04:33:48 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\uxtheme.dll
            MOD - [2008/04/14 04:33:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wldap32.dll
            MOD - [2008/04/14 04:33:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\version.dll
            MOD - [2008/04/14 04:33:46 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srclient.dll
            MOD - [2008/04/14 04:33:41 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shimeng.dll
            MOD - [2008/04/14 04:33:39 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\samlib.dll
            MOD - [2008/04/14 04:33:38 | 001,287,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ole32.dll
            MOD - [2008/04/14 04:33:38 | 000,551,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oleaut32.dll
            MOD - [2008/04/14 04:33:38 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\olepro32.dll
            MOD - [2008/04/14 04:33:38 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\psapi.dll
            MOD - [2008/04/14 04:33:36 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntmarta.dll
            MOD - [2008/04/14 04:33:33 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcrt.dll
            MOD - [2008/04/14 04:33:30 | 000,297,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msctf.dll
            MOD - [2008/04/14 04:33:26 | 000,110,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\imm32.dll
            MOD - [2008/04/14 04:33:25 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll
            MOD - [2008/04/14 04:33:21 | 000,851,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comres.dll
            MOD - [2008/04/14 04:33:21 | 000,498,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\clbcatq.dll
            MOD - [2008/04/14 04:33:21 | 000,281,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comdlg32.dll
            MOD - [2008/04/14 04:33:19 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\apphelp.dll
            MOD - [2008/04/14 04:32:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
            MOD - [2008/04/14 04:30:54 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
            MOD - [2008/04/13 20:33:42 | 001,005,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\setupapi.dll

            [color=#E56717]========== Win32 Services (SafeList) ==========[/color]

            SRV - [2010/06/28 22:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
            SRV - [2010/06/28 22:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
            SRV - [2010/06/28 22:57:15 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
            SRV - [2010/03/04 23:38:02 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
            SRV - [2009/03/31 09:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
            SRV - [2008/04/07 09:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
            SRV - [2005/12/13 10:45:34 | 000,176,128 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -- (ELService)
            SRV - [2005/10/12 13:30:24 | 000,086,140 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMon) Intel(R)
            SRV - [2005/10/06 18:12:44 | 000,856,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Connect 2\wmccds.exe -- (WMConnectCDS)
            SRV - [2005/04/04 01:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
            SRV - [2001/11/12 13:31:48 | 000,020,480 | ---- | M] (X10) [Auto | Running] -- C:\Program Files\Common Files\X10\Common\X10nets.exe -- (x10nets)

            [color=#E56717]========== Driver Services (All) ==========[/color]

            DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (ViaIde)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys -- (USBModem)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys -- (UsbDiag)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgusbbus.sys -- (usbbus)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (ultra)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (TosIde)
            DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\TfSysMon.sys -- (TfSysMon)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\TfNetMon.sys -- (TfNetMon)
            DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\TfFsMon.sys -- (TfFsMon)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (symc8xx)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (symc810)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (sym_u3)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (sym_hi)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (Sparrow)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (Simbad)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (ql1280)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (ql1240)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (ql12160)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (Ql10wnt)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (ql1080)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (perc2hib)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (perc2)
            DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
            DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
            DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
            DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
            DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (mraid35x)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgvmodem.sys -- (LGVMODEM)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgbtbus.sys -- (lgbusenum)
            DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgbtport.sys -- (LgBttPort)
            DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (IntelIde)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (ini910u)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (i2omp)
            DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (hpn)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (dpti2o)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (dac960nt)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (Cpqarray)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (CmdIde)
            DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (cd20xrnt)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (Atdisk)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (asc3550)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (asc3350p)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (asc)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (amsint)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (AliIde)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (aic78xx)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (aic78u2)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (Aha154x)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (adpu160m)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (abp480n5)
            DRV - File not found [Kernel | Disabled | Stopped] -- -- (Abiosdsk)
            DRV - [2010/09/06 10:09:48 | 000,013,440 | ---- | M] (ICSI Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBCRFT.SYS -- (CardReaderFilter)
            DRV - [2010/06/28 22:37:52 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
            DRV - [2010/06/28 22:37:30 | 000,165,456 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
            DRV - [2010/06/28 22:33:13 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
            DRV - [2010/06/28 22:32:45 | 000,100,176 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
            DRV - [2010/06/28 22:32:33 | 000,017,744 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
            DRV - [2010/06/28 22:32:16 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
            DRV - [2010/06/21 17:27:11 | 000,354,304 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\srv.sys -- (Srv)
            DRV - [2010/02/24 15:11:07 | 000,455,680 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\mrxsmb.sys -- (MRxSmb)
            DRV - [2009/12/19 13:39:59 | 000,047,360 | ---- | M] (VSO Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pcouffin.sys -- (pcouffin)
            DRV - [2009/12/19 13:12:39 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
            DRV - [2009/10/20 18:20:16 | 000,265,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\http.sys -- (HTTP)
            DRV - [2009/06/24 13:18:41 | 000,092,928 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\ksecdd.sys -- (KSecDD)
            DRV - [2009/05/18 15:17:00 | 000,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
            DRV - [2009/04/28 22:20:06 | 000,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
            DRV - [2009/03/31 09:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
            DRV - [2009/03/20 10:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
            DRV - [2009/03/20 10:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
            DRV - [2009/03/20 10:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
            DRV - [2008/08/14 12:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\afd.sys -- (AFD)
            DRV - [2008/06/20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip.sys -- (Tcpip)
            DRV - [2008/05/06 08:01:50 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
            DRV - [2008/04/14 04:34:54 | 000,139,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\rdpwd.sys -- (RDPWD)
            DRV - [2008/04/14 04:34:53 | 000,021,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\tdtcp.sys -- (TDTCP)
            DRV - [2008/04/14 04:34:52 | 000,040,840 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\termdd.sys -- (TermDD)
            DRV - [2008/04/14 04:34:52 | 000,012,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\tdpipe.sys -- (TDPIPE)
            DRV - [2008/04/14 04:10:03 | 000,073,600 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sr.sys -- (sr)
            DRV - [2008/04/14 04:09:53 | 000,120,576 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\pcmcia.sys -- (Pcmcia)
            DRV - [2008/04/14 04:09:47 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\pci.sys -- (PCI)
            DRV - [2008/04/14 04:09:40 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\parport.sys -- (Parport)
            DRV - [2008/04/14 04:05:15 | 000,014,720 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid)
            DRV - [2008/04/14 04:05:14 | 000,025,216 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kbdclass.sys -- (Kbdclass)
            DRV - [2008/04/14 04:05:12 | 000,154,496 | ---- | M] (Microsoft Corp., Veritas Software) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\dmio.sys -- (dmio)
            DRV - [2008/04/14 04:05:07 | 000,800,256 | ---- | M] (Microsoft Corp., Veritas Software) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\dmboot.sys -- (dmboot)
            DRV - [2008/04/14 04:04:35 | 000,037,632 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\isapnp.sys -- (isapnp)
            DRV - [2008/04/14 04:03:26 | 000,040,576 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\intelppm.sys -- (intelppm)
            DRV - [2008/04/14 04:00:52 | 000,054,144 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\i8042prt.sys -- (i8042prt)
            DRV - [2008/04/14 04:00:08 | 000,066,048 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\serial.sys -- (Serial)
            DRV - [2008/04/14 03:57:38 | 000,044,672 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\fips.sys -- (Fips)
            DRV - [2008/04/14 03:57:34 | 000,058,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\redbook.sys -- (redbook)
            DRV - [2008/04/14 03:56:04 | 000,053,376 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\volsnap.sys -- (VolSnap)
            DRV - [2008/04/14 03:53:18 | 000,023,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mouclass.sys -- (Mouclass)
            DRV - [2008/04/14 03:53:05 | 000,030,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\modem.sys -- (Modem)
            DRV - [2008/04/14 03:52:42 | 000,188,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ACPI.sys -- (ACPI)
            DRV - [2008/04/13 21:28:39 | 000,175,744 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\rdbss.sys -- (Rdbss)
            DRV - [2008/04/13 21:21:00 | 000,162,816 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\netbt.sys -- (NetBT)
            DRV - [2008/04/13 21:20:42 | 000,091,520 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ndiswan.sys -- (NdisWan)
            DRV - [2008/04/13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\ndis.sys -- (NDIS)
            DRV - [2008/04/13 21:19:48 | 000,048,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\raspptp.sys -- (PptpMiniport) Miniport réseau étendu (PPTP)
            DRV - [2008/04/13 21:19:43 | 000,051,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rasl2tp.sys -- (Rasl2tp) Miniport réseau étendu (L2TP)
            DRV - [2008/04/13 21:19:42 | 000,075,264 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ipsec.sys -- (IPSec)
            DRV - [2008/04/13 21:17:18 | 000,083,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wdmaud.sys -- (wdmaud)
            DRV - [2008/04/13 21:17:05 | 000,105,344 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\System32\drivers\mup.sys -- (Mup)
            DRV - [2008/04/13 21:15:55 | 000,060,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sysaudio.sys -- (sysaudio)
            DRV - [2008/04/13 21:15:53 | 000,574,976 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\ntfs.sys -- (Ntfs)
            DRV - [2008/04/13 21:14:29 | 000,143,744 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\fastfat.sys -- (Fastfat)
            DRV - [2008/04/13 21:14:21 | 000,063,744 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\cdfs.sys -- (Cdfs)
            DRV - [2008/04/13 20:57:32 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\raspppoe.sys -- (RasPppoe)
            DRV - [2008/04/13 20:57:29 | 000,040,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ndproxy.sys -- (NDProxy)
            DRV - [2008/04/13 20:57:27 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\asyncmac.sys -- (AsyncMac)
            DRV - [2008/04/13 20:57:27 | 000,010,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ndistapi.sys -- (NdisTapi)
            DRV - [2008/04/13 20:57:21 | 000,034,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanarp.sys -- (Wanarp)
            DRV - [2008/04/13 20:57:15 | 000,152,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ipnat.sys -- (IpNat)
            DRV - [2008/04/13 20:57:07 | 000,020,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipinip.sys -- (IpInIp)
            DRV - [2008/04/13 20:56:32 | 000,035,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msgpc.sys -- (Gpc)
            DRV - [2008/04/13 20:56:02 | 000,034,688 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\netbios.sys -- (NetBIOS)
            DRV - [2008/04/13 20:55:58 | 000,014,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ndisuio.sys -- (Ndisuio)
            DRV - [2008/04/13 20:54:28 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irenum.sys -- (IRENUM)
            DRV - [2008/04/13 20:53:34 | 000,036,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ip6fw.sys -- (Ip6Fw)
            DRV - [2008/04/13 20:51:25 | 000,061,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nic1394.sys -- (NIC1394)
            DRV - [2008/04/13 20:51:25 | 000,060,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\arp1394.sys -- (Arp1394)
            DRV - [2008/04/13 20:51:25 | 000,059,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atmarpc.sys -- (Atmarpc)
            DRV - [2008/04/13 20:46:25 | 000,085,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nabtsfec.sys -- (NABTSFEC)
            DRV - [2008/04/13 20:46:24 | 000,019,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wstcodec.sys -- (WSTCODEC)
            DRV - [2008/04/13 20:46:23 | 000,017,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdecode.sys -- (CCDECODE)
            DRV - [2008/04/13 20:46:23 | 000,011,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\slip.sys -- (SLIP)
            DRV - [2008/04/13 20:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
            DRV - [2008/04/13 20:46:22 | 000,010,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ndisip.sys -- (NdisIP)
            DRV - [2008/04/13 20:46:21 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\streamip.sys -- (streamip)
            DRV - [2008/04/13 20:46:18 | 000,061,696 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ohci1394.sys -- (ohci1394)
            DRV - [2008/04/13 20:45:39 | 000,032,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbccgp.sys -- (usbccgp)
            DRV - [2008/04/13 20:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbstor.sys -- (USBSTOR)
            DRV - [2008/04/13 20:45:37 | 000,059,520 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbhub.sys -- (usbhub)
            DRV - [2008/04/13 20:45:35 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbehci.sys -- (usbehci)
            DRV - [2008/04/13 20:45:35 | 000,020,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbuhci.sys -- (usbuhci)
            DRV - [2008/04/13 20:45:34 | 000,015,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbscan.sys -- (usbscan)
            DRV - [2008/04/13 20:45:27 | 000,010,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hidusb.sys -- (hidusb)
            DRV - [2008/04/13 20:45:13 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\drmkaud.sys -- (drmkaud) Filtre de décodeur DRM (Noyau Microsoft)
            DRV - [2008/04/13 20:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) Pilote USB audio (WDM)
            DRV - [2008/04/13 20:45:09 | 000,172,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\kmixer.sys -- (kmixer)
            DRV - [2008/04/13 20:45:09 | 000,056,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\swmidi.sys -- (swmidi)
            DRV - [2008/04/13 20:45:07 | 000,006,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\splitter.sys -- (splitter)
            DRV - [2008/04/13 20:45:01 | 000,052,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dmusic.sys -- (DMusic)
            DRV - [2008/04/13 20:44:40 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\vga.sys -- (VgaSave)
            DRV - [2008/04/13 20:40:58 | 000,042,112 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\imapi.sys -- (Imapi)
            DRV - [2008/04/13 20:40:49 | 000,019,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\partmgr.sys -- (PartMgr)
            DRV - [2008/04/13 20:40:48 | 000,011,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\sfloppy.sys -- (Sfloppy)
            DRV - [2008/04/13 20:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\disk.sys -- (Disk)
            DRV - [2008/04/13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cdrom.sys -- (Cdrom)
            DRV - [2008/04/13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\atapi.sys -- (atapi)
            DRV - [2008/04/13 20:40:25 | 000,027,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fdc.sys -- (Fdc)
            DRV - [2008/04/13 20:40:25 | 000,020,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\flpydisk.sys -- (Flpydisk)
            DRV - [2008/04/13 20:40:12 | 000,015,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\serenum.sys -- (serenum)
            DRV - [2008/04/13 20:39:53 | 000,004,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\swenum.sys -- (swenum)
            DRV - [2008/04/13 20:39:52 | 000,007,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mskssrv.sys -- (MSKSSRV)
            DRV - [2008/04/13 20:39:51 | 000,004,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mspqm.sys -- (MSPQM)
            DRV - [2008/04/13 20:39:50 | 000,005,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mstee.sys -- (MSTEE)
            DRV - [2008/04/13 20:39:50 | 000,005,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mspclock.sys -- (MSPCLOCK)
            DRV - [2008/04/13 20:39:46 | 000,384,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\update.sys -- (Update)
            DRV - [2008/04/13 20:39:46 | 000,042,368 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\mountmgr.sys -- (MountMgr)
            DRV - [2008/04/13 20:36:46 | 000,015,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mssmbios.sys -- (mssmbios)
            DRV - [2008/04/13 20:32:59 | 000,129,792 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\fltmgr.sys -- (FltMgr)
            DRV - [2008/04/13 20:32:51 | 000,196,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rdpdr.sys -- (rdpdr)
            DRV - [2008/04/13 20:32:44 | 000,180,608 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mrxdav.sys -- (MRxDAV)
            DRV - [2008/04/13 20:32:39 | 000,030,848 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\npfs.sys -- (Npfs)
            DRV - [2008/04/13 20:32:39 | 000,019,072 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\msfs.sys -- (Msfs)
            DRV - [2008/04/13 20:32:36 | 000,066,048 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\udfs.sys -- (Udfs)
            DRV - [2008/04/13 18:39:23 | 000,142,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aec.sys -- (aec) Suppresseur d'écho acoustique (Noyau Microsoft)
            DRV - [2008/04/13 18:39:15 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
            DRV - [2008/04/13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
            DRV - [2008/01/14 12:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ManyCam.sys -- (ManyCam)
            DRV - [2007/10/25 17:26:10 | 000,005,632 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
            DRV - [2007/09/17 15:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
            DRV - [2006/03/17 17:24:10 | 001,520,640 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
            DRV - [2005/12/13 10:45:20 | 000,007,808 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ELacpi.sys -- (ELacpi)
            DRV - [2005/12/13 10:45:18 | 000,007,040 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELmon.sys -- (ELmon)
            DRV - [2005/12/13 10:45:00 | 000,006,912 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELkbd.sys -- (ELkbd)
            DRV - [2005/12/13 10:44:58 | 000,006,528 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELmou.sys -- (ELmou)
            DRV - [2005/12/13 10:44:56 | 000,010,112 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELhid.sys -- (ELhid)
            DRV - [2005/12/06 12:16:20 | 000,826,752 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid)
            DRV - [2005/10/12 13:07:12 | 000,874,240 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iastor)
            DRV - [2005/06/13 11:50:38 | 000,007,040 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\x10hid.sys -- (X10Hid)
            DRV - [2005/05/12 14:39:56 | 001,287,296 | ---- | M] (C-Media Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmudax.sys -- (cmudax)
            DRV - [2005/03/05 01:10:38 | 000,157,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e100b325.sys -- (E100B) Intel(R)
            DRV - [2004/08/10 14:00:00 | 000,126,080 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ftdisk.sys -- (Ftdisk)
            DRV - [2004/08/10 14:00:00 | 000,032,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipfltdrv.sys -- (IpFilterDriver)
            DRV - [2004/08/10 14:00:00 | 000,032,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkfwd.sys -- (NwlnkFwd)
            DRV - [2004/08/10 14:00:00 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\cdaudio.sys -- (Cdaudio)
            DRV - [2004/08/10 14:00:00 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
            DRV - [2004/08/10 14:00:00 | 000,016,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\raspti.sys -- (Raspti)
            DRV - [2004/08/10 14:00:00 | 000,013,952 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\cbidf2k.sys -- (cbidf2k)
            DRV - [2004/08/10 14:00:00 | 000,012,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkflt.sys -- (NwlnkFlt)
            DRV - [2004/08/10 14:00:00 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mouhid.sys -- (mouhid)
            DRV - [2004/08/10 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\ws2ifsl.sys -- (WS2IFSL)
            DRV - [2004/08/10 14:00:00 | 000,012,032 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\acpiec.sys -- (ACPIEC)
            DRV - [2004/08/10 14:00:00 | 000,008,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\rasacd.sys -- (RasAcd)
            DRV - [2004/08/10 14:00:00 | 000,006,912 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\parvdm.sys -- (ParVdm)
            DRV - [2004/08/10 14:00:00 | 000,005,888 | ---- | M] (Microsoft Corp., Veritas Software.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\dmload.sys -- (dmload)
            DRV - [2004/08/10 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\rdpcdd.sys -- (RDPCDD)
            DRV - [2004/08/10 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\mnmdd.sys -- (mnmdd)
            DRV - [2004/08/10 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\beep.sys -- (Beep)
            DRV - [2004/08/10 14:00:00 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\null.sys -- (Null)
            DRV - [2004/08/10 03:45:04 | 000,011,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mhndrv.sys -- (MHNDRV)
            DRV - [2004/03/17 16:10:40 | 000,113,664 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
            DRV - [2004/01/21 03:14:46 | 000,005,915 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
            DRV - [2004/01/21 03:14:42 | 000,271,360 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LV302AV.SYS -- (PID_08A0) Labtec WebCam Pro(PID_08A0)
            DRV - [2001/08/23 17:15:46 | 000,003,328 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\pciide.sys -- (PCIIde)
            DRV - [2001/08/17 23:59:44 | 000,003,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\audstub.sys -- (audstub)

            [color=#E56717]========== Standard Registry (SafeList) ==========[/color]

            [color=#E56717]========== Internet Explorer ==========[/color]

            IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

            IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

            IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/
            IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
            IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f
            IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
            IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://gppgle.com/
            IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
            IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

            [color=#E56717]========== FireFox ==========[/color]

            FF - prefs.js..browser.search.defaultengine: "Ask.com"
            FF - prefs.js..browser.search.defaultenginename: "Rechercher MyStart"
            FF - prefs.js..browser.search.defaultthis.engineName: "PHPNukeFR Customized Web Search"
            FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2102473&SearchSource=3&q={searchTerms}"
            FF - prefs.js..browser.search.order.1: "Ask.com"
            FF - prefs.js..browser.search.param.yahooÅ"÷-fr: "chr-greentree_ff&type=867034"
            FF - prefs.js..browser.search.selectedEngine: "Rechercher MyStart"
            FF - prefs.js..browser.search.useDBForOrder: true
            FF - prefs.js..browser.startup.homepage: "https://www.google.fr/?client=firefox-a&rls=org.mozilla:fr:official&gws_rd=ssl"
            FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.2
            FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
            FF - prefs.js..extensions.enabledItems: radiobar@toolbar:1.0.0
            FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.0.232
            FF - prefs.js..keyword.URL: "http://redirecterror.sfr.fr/?q="

            FF - user.js..keyword.URL: "http://redirecterror.sfr.fr/?q="

            FF - HKLM\software\mozilla\Firefox\extensions\\FFToolbar@bitdefender.com: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\
            FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/20 16:54:47 | 000,000,000 | ---D | M]
            FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/11 23:23:59 | 000,000,000 | ---D | M]

            [2009/12/18 21:44:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Mozilla\Extensions
            [2010/09/06 10:24:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\extensions
            [2010/01/04 12:08:01 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
            [2010/05/02 11:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\extensions\radiobar@toolbar
            [2010/07/22 01:00:36 | 000,002,393 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\searchplugins\askcom.xml
            [2010/06/09 10:23:59 | 000,002,650 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\searchplugins\bing.xml
            [2009/07/01 15:25:00 | 000,000,880 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\searchplugins\conduit.xml
            [2010/08/02 00:24:19 | 000,002,139 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\searchplugins\MyStart Search.xml
            [2010/09/06 10:24:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
            [2010/01/12 18:23:17 | 000,000,000 | ---D | M] (PHPNukeFR Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{1c491116-c175-45e1-a570-6fb14fea8b7b}
            [2010/07/31 13:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
            [2010/03/15 12:24:33 | 000,001,516 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
            [2010/03/15 12:24:33 | 000,001,822 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
            [2010/03/15 12:24:33 | 000,000,757 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
            [2010/03/15 12:24:33 | 000,001,426 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
            [2010/03/25 01:17:32 | 000,000,956 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml

            O1 HOSTS File: ([2010/09/06 12:23:04 | 000,417,917 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
            O1 - Hosts: 127.0.0.1 localhost
            O1 - Hosts: 127.0.0.1 www.007guard.com
            O1 - Hosts: 127.0.0.1 007guard.com
            O1 - Hosts: 127.0.0.1 008i.com
            O1 - Hosts: 127.0.0.1 www.008k.com
            O1 - Hosts: 127.0.0.1 008k.com
            O1 - Hosts: 127.0.0.1 www.00hq.com
            O1 - Hosts: 127.0.0.1 00hq.com
            O1 - Hosts: 127.0.0.1 010402.com
            O1 - Hosts: 127.0.0.1 www.032439.com
            O1 - Hosts: 127.0.0.1 032439.com
            O1 - Hosts: 127.0.0.1 www.0scan.com
            O1 - Hosts: 127.0.0.1 0scan.com
            O1 - Hosts: 127.0.0.1 1000gratisproben.com
            O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
            O1 - Hosts: 127.0.0.1 1001namen.com
            O1 - Hosts: 127.0.0.1 www.1001namen.com
            O1 - Hosts: 127.0.0.1 100888290cs.com
            O1 - Hosts: 127.0.0.1 www.100888290cs.com
            O1 - Hosts: 127.0.0.1 www.100sexlinks.com
            O1 - Hosts: 127.0.0.1 100sexlinks.com
            O1 - Hosts: 127.0.0.1 10sek.com
            O1 - Hosts: 127.0.0.1 www.10sek.com
            O1 - Hosts: 127.0.0.1 www.1-2005-search.com
            O1 - Hosts: 127.0.0.1 1-2005-search.com
            O1 - Hosts: 14420 more lines...
            O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
            O2 - BHO: (Objet d'aide à la navigation SFR) - {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll (SFR)
            O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
            O3 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
            O3 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
            O3 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
            O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
            O4 - HKLM..\Run: [Cmaudio] File not found
            O4 - HKLM..\Run: [Dit] C:\WINDOWS\Dit.exe (ICSI Technology Ltd.)
            O4 - HKLM..\Run: [eorezo] File not found
            O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
            O4 - HKLM..\Run: [KernelFaultCheck] File not found
            O4 - HKLM..\Run: [NPSStartup] File not found
            O4 - HKLM..\Run: [Raccourci vers la page des propriétés de High Definition Audio] C:\WINDOWS\System32\Hdaudpropshortcut.exe (Windows (R) Server 2003 DDK provider)
            O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
            O4 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
            O4 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005..\Run: [Connexion SFR 9props.exe] C:\Program Files\SFR\Kit\9props.exe (SFR)
            O4 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
            O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
            O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
            O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
            O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
            O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
            O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
            O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
            O7 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
            O9 - Extra Button: PMU Poker - {06568ceb-5721-47d4-9d93-7e604fcbaeab} - C:\Program Files\PMU\PMUPoker\RunApp.exe File not found
            O9 - Extra 'Tools' menuitem : PMU Poker - {06568ceb-5721-47d4-9d93-7e604fcbaeab} - C:\Program Files\PMU\PMUPoker\RunApp.exe File not found
            O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/... (WUWebControl Class)
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/... (MUWebControl Class)
            O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
            O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
            O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
            O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
            O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
            O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
            O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
            O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
            O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
            O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
            O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
            O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
            O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
            O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
            O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
            O24 - Desktop WallPaper: C:\Documents and Settings\$\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
            O24 - Desktop BackupWallPaper: C:\Documents and Settings\$\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
            O32 - HKLM CDRom: AutoRun - 1
            O32 - AutoRun File - [2006/04/28 09:29:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
            O32 - AutoRun File - [2009/11/24 12:21:24 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
            O32 - AutoRun File - [2009/11/24 11:21:26 | 000,000,000 | RHSD | M] - E:\autorun.inf -- [ FAT32 ]
            O33 - MountPoints2\{1ed882c4-2ced-11df-bd69-0016175c9a93}\Shell - "" = AutoRun
            O33 - MountPoints2\{4b9bd5da-8365-11df-be39-0016175c9a93}\Shell\AutoRun\command - "" = G:\start.exe -- File not found
            O34 - HKLM BootExecute: (autocheck autochk *) - File not found
            O35 - HKLM\..comfile [open] -- "%1" %*
            O35 - HKLM\..exefile [open] -- "%1" %*
            O37 - HKLM\...com [@ = comfile] -- "%1" %*
            O37 - HKLM\...exe [@ = exefile] -- "%1" %*

            [color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

            [2010/09/07 00:50:38 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
            [2010/09/06 11:55:55 | 000,165,456 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
            [2010/09/06 11:55:55 | 000,017,744 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
            [2010/09/06 11:55:54 | 000,100,176 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
            [2010/09/06 11:55:54 | 000,094,544 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
            [2010/09/06 11:55:54 | 000,046,672 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
            [2010/09/06 11:55:54 | 000,028,880 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
            [2010/09/06 11:55:54 | 000,023,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
            [2010/09/06 11:55:43 | 000,165,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
            [2010/09/06 11:55:43 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\WINDOWS\avastSS.scr
            [2010/09/04 20:41:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\ESET
            [2010/09/04 18:36:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Local Settings\Application Data\ESET
            [2010/08/31 14:05:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\$\Recent
            [2010/08/21 02:07:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TrackMania
            [2010/08/13 20:20:38 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\$\Application Data\SecuROM
            [2010/08/13 13:37:53 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
            [2010/08/08 01:26:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Lavasoft
            [2010/08/01 17:58:43 | 000,000,000 | ---D | C] -- C:\Program Files\PMU
            [2010/07/27 19:42:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\Nouveau dossier
            [2010/07/26 15:25:17 | 000,000,000 | ---D | C] -- C:\Program Files\Xenocode
            [2010/07/26 15:25:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Local Settings\Application Data\Xenocode
            [2010/07/25 14:15:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\PhotoFiltre
            [2010/07/22 18:35:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\My Art
            [2010/07/22 16:19:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\NPS
            [2010/07/22 16:17:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Suite
            [2010/07/22 16:17:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\PC Suite
            [2010/07/22 16:15:00 | 000,090,624 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcls.dll
            [2010/07/22 16:14:58 | 000,021,632 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\pccsmcfd.sys
            [2010/07/22 16:14:48 | 000,121,856 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdm.sys
            [2010/07/22 16:14:48 | 000,090,112 | ---- | C] (MCCI) -- C:\WINDOWS\System32\drivers\ss_bbus.sys
            [2010/07/22 16:14:48 | 000,014,976 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdfl.sys
            [2010/07/22 16:14:48 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcmnt.sys
            [2010/07/22 16:14:48 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcm.sys
            [2010/07/22 16:14:47 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwhnt.sys
            [2010/07/22 16:14:47 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwh.sys
            [2010/07/22 16:12:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Samsung_USB_Drivers
            [2010/07/22 16:12:55 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
            [2010/07/22 16:12:15 | 000,233,472 | ---- | C] (Teruten) -- C:\WINDOWS\System32\FsUsbExService.Exe
            [2010/07/22 16:12:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\My NPS Files
            [2010/07/22 16:12:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Samsung
            [2010/07/22 16:11:50 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
            [2010/07/22 16:11:48 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution
            [2010/07/22 16:11:17 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
            [2010/07/22 14:50:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS
            [2010/07/22 14:50:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS\0207030.022
            [2010/07/17 16:56:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec
            [2010/07/17 16:56:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
            [2010/07/17 16:56:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
            [2010/07/17 16:26:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Camfrog
            [2010/07/17 16:26:17 | 000,000,000 | ---D | C] -- C:\Program Files\Camfrog
            [2010/07/11 23:23:07 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\xing shared
            [2009/12/19 13:39:59 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\$\Application Data\pcouffin.sys
            [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
            [3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

            [color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

            [2010/09/07 00:51:13 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
            [2010/09/06 21:47:02 | 000,042,056 | ---- | M] () -- C:\Documents and Settings\$\Bureau\Prior-Mercedes-E-Class-5-500x375.jpg
            [2010/09/06 21:43:34 | 000,092,692 | ---- | M] () -- C:\Documents and Settings\$\Bureau\Prior-Mercedes-E-Class-8.jpg
            [2010/09/06 20:41:51 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-619478507-2902194733-1154510819-1005.job
            [2010/09/06 20:41:47 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
            [2010/09/06 20:41:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
            [2010/09/06 20:41:09 | 2145,898,496 | -HS- | M] () -- C:\hiberfil.sys
            [2010/09/06 19:42:34 | 009,699,328 | ---- | M] () -- C:\Documents and Settings\$\ntuser.dat
            [2010/09/06 19:42:34 | 000,000,184 | -HS- | M] () -- C:\Documents and Settings\$\ntuser.ini
            [2010/09/06 12:23:04 | 000,417,917 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
            [2010/09/06 12:15:03 | 004,843,148 | -H-- | M] () -- C:\Documents and Settings\$\Local Settings\Application Data\IconCache.db
            [2010/09/06 11:55:55 | 000,001,704 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\avast! Free Antivirus.lnk
            [2010/09/06 11:55:54 | 000,003,121 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
            [2010/09/06 10:09:48 | 000,013,440 | ---- | M] (ICSI Technology Lt
            1. ############################## | UsbFix 7.023 | [Recherche]

              Utilisateur: $ (Administrateur) # OEM-2B7087C8C3D [ ]
              Mis à jour le 02/09/10 par El Desaparecido / C_XX
              Lancé à 01:26:51 | 07/09/2010
              Site Web: http://www.teamxscript.org
              Contact: FindyKill.Contact@gmail.com

              CPU: Intel(R) Pentium(R) D CPU 3.00GHz
              CPU 2: Intel(R) Pentium(R) D CPU 3.00GHz
              Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
              Internet Explorer 8.0.6001.18702

              Pare-feu Windows: Désactivé /!\
              Antivirus: avast! Antivirus 5.0.83886674 [(!) Disabled | Updated]
              RAM -> 2046 Mo
              C:\ (%systemdrive%) -> Disque fixe # 115 Go (60 Go libre(s) - 52%) [BOOT] # NTFS
              D:\ -> Disque fixe # 112 Go (110 Go libre(s) - 99%) [BACKUP] # NTFS
              E:\ -> Disque fixe # 6 Go (4 Go libre(s) - 61%) [RECOVER] # FAT32
              F:\ -> CD-ROM
              J:\ -> CD-ROM

              ################## | Éléments infectieux |

              Présent! C:\Documents and Settings\$\Application Data\SQLite3.dll

              ################## | Registre |

              Présent! HKCU\Software\JRMX9X1GML
              Présent! HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHNAS
              Présent! HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SSHNAS
              Présent! HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS

              ################## | Mountpoints2 |

              HKCU\.\.\.\.\Explorer\MountPoints2\{4b9bd5da-8365-11df-be39-0016175c9a93}
              Shell\AutoRun\Command = G:\start.exe

              ################## | Vaccin |

              (!) Cet ordinateur n'est pas vacciné!

              ################## | E.O.F |