Rapport zhpdiag suite redirection njksearch

Fermé
boris06 Messages postés 12 Date d'inscription mardi 27 septembre 2011 Statut Membre Dernière intervention 2 octobre 2011 - 27 sept. 2011 à 16:00
 Utilisateur anonyme - 27 sept. 2011 à 17:09
Bonjour,

Voici mon rapport suite à mùa demande de ce matin.

Merci pour votre aide

Rapport de ZHPDiag v1.28.1354 par Nicolas Coolman, Update du 25/09/2011
Run by station at 27/09/2011 11:13:08
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html


---\\ Web Browser
MSIE: Internet Explorer v8.0.6001.18702 (Defaut)

---\\ Windows Product Information
Windows XP Professional Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
Windows Genuine Advantage : OK

---\\ System Information
~ Processor: x86 Family 15 Model 6 Stepping 4, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 997.9 MB (18% free)
System Restore: Activé (Enable)
System drive C: has 24 GB (60%) free of 39 GB

---\\ Logged in mode
~ Computer Name: COMMERCIAL
~ User Name: station
~ All Users Names: SUPPORT_388945a0, station, HelpAssistant, ASPNET, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Documents and Settings\station\Application Data\
~ %Desktop% : C:\Documents and Settings\station\Bureau\
~ %Favorites% : C:\Documents and Settings\station\Favoris\
~ %LocalAppData% : C:\Documents and Settings\station\Local Settings\Application Data\
~ %StartMenu% : C:\Documents and Settings\station\Menu Démarrer\
~ %Windir% : C:\WINDOWS\
~ %System% : C:\WINDOWS\system32\

---\\ DOS/Devices
A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
C:\ Hard drive, Flash drive, Thumb drive (Free 24 Go of 39 Go)
D:\ CD-ROM drive (Not Inserted)
E:\ Hard drive, Flash drive, Thumb drive (Free 37 Go of 37 Go)



---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
~ Scan Security Center in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\Explorer.exe [1037824]
[MD5.93AD0B78C7357A05F50E594EC7C22300] - (....) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\rundll32.exe [33792]
[MD5.3008D2F793F23FF0DDBC5A1FB9F8374F] - (.Microsoft Corporation - Internet Extensions for Win32.) (.27/09/2011 - 19:31:31.) -- C:\WINDOWS\system32\wininet.dll [916480]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]
~ Scan Generic Processes in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
Mes images (My Pictures) : 6/6 (Modified)
Mes musiques (My Musics) : 17/17 (Modified)
~ Mes Videos (My Video) : 0/0
~ Mes Favoris (My Favorites) : 79/86
Mes Documents (My Documents) : 51/51 (Modified)
~ Mon Bureau (My Desktop) : 23/1840
Menu demarrer (Programs) : 27/27 (Modified)
~ Scan Hidden Files in 00mn 08s



---\\ Processus lancés
[MD5.C0393EB99A6C72C6BEF9BFC4A72B33A6] - (.SUPERAntiSpyware.com - Core Service.) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608] [PID.]
[MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664] [PID.]
[MD5.77AC10DB097DFD0CD3071465B644D0AB] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376] [PID.]
[MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [322120] [PID.]
[MD5.C1C3BAF078BE5A14384A4BA2D730817D] - (.Nuance Communications, Inc. - PDFPro IFilter Service.) -- C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672] [PID.]
[MD5.B60DDDD2D63CE41CB8C487FCFBB6419E] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [638816] [PID.3412]
[MD5.D30EB2F98504F30ECAAEEF90DDC7DE98] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [2122752] [PID.1960]
[MD5.5E9A6658A2A69AE7EB195113B7A2E7A9] - (.Microsoft Corporation - Application Layer Gateway Service.) -- C:\WINDOWS\System32\alg.exe [44544] [PID.]
~ Scan Processes Running in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50917.0.) -- C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
~ Scan Firefox Browser in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww7.wuuta.com
R0 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = https://www.google.com/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = https://www.google.com/?gws_rd=ssl
R1 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = google
R1 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = https://www.google.com/?gws_rd=ssl
R1 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask.com - Ask.com Toolbar.) (5.6.12.178) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.19098 (longhorn_ie8_gdr.110617-1715)) -- C:\WINDOWS\system32\ieframe.dll
R3 - URLSearchHook: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} . (.Conduit Ltd. - Conduit Toolbar.) (6.3.4.1) -- C:\Program Files\uTorrentBar_FR\prxtbuTor.dll
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s



---\\ Redirection du fichier Hosts (O1)
O1 - Hosts: 95.64.61.141 www.google.com
O1 - Hosts: 95.64.61.142 www.bing.com
~ Scan Hosts File in 00mn 00s



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} Clé orpheline
~ Scan BHO in 00mn 00s



---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [KernelFaultCheck] Clé orpheline
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe (.not file.)
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
~ Scan Application in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\Assistance à distance.lnk . (.Microsoft Corporation.) -- C:\WINDOWS\system32\rcimlby.exe
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\Lecteur Windows Media.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\POST-NET.LNK . (.Contact: Jeux.cartes@free.fr.) -- C:\Program Files\POST-NET\Post-Net.exe
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\SAV+.LNK . (.INFOVAB.) -- C:\SaveW\SaveW.exe
~ Scan Global Startup in 00mn 00s



---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.exe
O8 - Extra context menu item: Google Sidewiki... . (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll
O8 - Extra context menu item: Ouvrir avec PDF Viewer Plus . (.Zeon Corporation - PlusIEContextMenu.dll.) -- C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
~ Scan IE Menu Contextuel in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
O9 - Extra button: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} . (...) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (...) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
~ Scan IE Extra Buttons in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
~ Scan Winsock in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1282739186109
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1282739171546
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} (HPSDDX Class) - http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
~ Scan Objets ActiveX in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A354028D-8CDD-4454-ABD7-8A70FC4AEBA0}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{A354028D-8CDD-4454-ABD7-8A70FC4AEBA0}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{A354028D-8CDD-4454-ABD7-8A70FC4AEBA0}: DhcpNameServer = 192.168.1.1
~ Scan Domain in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} . (.Microsoft Corporation - Microsoft Office Web Components 2003.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll
O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
~ Scan Protocole Additionnel in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: !SASWinLogon . (.SUPERAntiSpyware.com - SUPERAntiSpyware WinLogon Processor.) -- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\WINDOWS\system32\igfxdev.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\WINDOWS\system32\WgaLogon.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
~ Scan Winlogon in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll
~ Scan SSODL in 00mn 00s



---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
~ Scan STS/SSO in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: SAS Core Service (!SASCORE) . (.SUPERAntiSpyware.com - Core Service.) - C:\Program Files\SUPERAntiSpyware\SASCORE.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PDFProFiltSrvPP (PDFProFiltSrvPP) . (.Nuance Communications, Inc. - PDFPro IFilter Service.) - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
~ Scan Services in 00mn 00s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.exe
~ Scan Desktop Component in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{3EA7F0F1-F2E8-4AD7-9E21-82D2CB33E9D0}.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{62306650-42CC-41BC-AF20-38C50B7C6823}.job
[MD5.00000000000000000000000000000000] [APT] [Ad-Aware Update (Weekly)] (...) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe (.not file.)
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.9309B115B18C5D132203FA3BBD4A4FA1] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files\Ask.com\UpdateTask.exe
~ Scan Scheduled Task in 00mn 00s



---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys
O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\WINDOWS\system32\DRIVERS\intelppm.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
O41 - Driver: (kbdhid) . (.Microsoft Corporation - Pilote de filtre souris HID.) - C:\WINDOWS\system32\DRIVERS\kbdhid.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys
O41 - Driver: (ovfsthjewnirqtkfrhctsymovgtgeppixbxqxf) . (. - .) - C:\WINDOWS\system32\drivers\ovfsthbogrcdevsppabaiyotxdmenwktafydqv.sys (.not file.)
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\WINDOWS\system32\DRIVERS\redbook.sys
O41 - Driver: (SASDIFSV) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV.SYS.) - C:\Program Files\SUPERAntiSpyware\SASDIFSV.sys
O41 - Driver: (SASKUTIL) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL.SYS.) - C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\WINDOWS\system32\DRIVERS\serial.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys
O41 - Driver: Carte vidéo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
~ Scan Drivers in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {2614F54E-A828-49FA-93BA-45A3F756BFAA}
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Reader 9.1 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A91000000001}
O42 - Logiciel: Adobe SVG Viewer 3.0 - (.Pas de propriétaire.) [HKLM] -- Adobe SVG Viewer
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {6A3F9D74-BB80-4451-8CA1-4B3A857F1359}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {C23CD6DA-1958-43A5-ADD0-59396572E02E}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE}
O42 - Logiciel: Brother MFL-Pro Suite MFC-9460CDN - (.Brother Industries, Ltd..) [HKLM] -- {979742CC-2CBB-49D8-9BEE-C2F7875F5393}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CleanUp! - (.Pas de propriétaire.) [HKLM] -- CleanUp!
O42 - Logiciel: Conduit Engine - (.Conduit Ltd..) [HKLM] -- conduitEngine
O42 - Logiciel: DVD Solution - (.Pas de propriétaire.) [HKLM] -- {B97CF5C3-0487-11D8-A36E-0050BAE317E1}
O42 - Logiciel: EPSON Easy Photo Print - (.Pas de propriétaire.) [HKLM] -- {BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}
O42 - Logiciel: EPSON Logiciel imprimante - (.Pas de propriétaire.) [HKLM] -- EPSON Printer and Utilities
O42 - Logiciel: EPSON Scan - (.Pas de propriétaire.) [HKLM] -- EPSON Scanner
O42 - Logiciel: FFT - (.Pas de propriétaire.) [HKLM] -- ST6UNST #3
O42 - Logiciel: FFT\) - (.Pas de propriétaire.) [HKLM] -- ST6UNST #2
O42 - Logiciel: Fiche fin de travaux - (.Pas de propriétaire.) [HKLM] -- ST6UNST #1
O42 - Logiciel: Finance - (.Pas de propriétaire.) [HKLM] -- ST6UNST #4
O42 - Logiciel: Financier HUIT - (.Pas de propriétaire.) [HKLM] -- Financier HUIT
O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {B131E59D-202C-43C6-84C9-68F0C37541F1}
O42 - Logiciel: Gestion 8 - (.Pas de propriétaire.) [HKLM] -- Gestion 8
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {18455581-E099-4BA8-BC6B-F34B2F06600C}
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}
O42 - Logiciel: Intel Audio Studio 2.0 - (.Intel Corporation.) [HKLM] -- {2205E3A5-DCDC-461D-8ED6-D6F2341D3B64}
O42 - Logiciel: Intel(R) Active Client Manager 2.0 HECI Driver - (.Pas de propriétaire.) [HKLM] -- HECI
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Pas de propriétaire.) [HKLM] -- HDMI
O42 - Logiciel: Intel(R) PRO Network Connections - (.Intel.) [HKLM] -- {0A0873E1-D9BA-4994-B85D-A0A331EF1F0C}
O42 - Logiciel: Java(TM) 6 Update 18 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216018FF}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {E2DFE069-083E-4631-9B6C-43C48E991DE5}
O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM] -- Windows Media Player
O42 - Logiciel: LiveUpdate 3.1 (Symantec Corporation) - (.Symantec Corporation.) [HKLM] -- LiveUpdate
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
O42 - Logiciel: MSXML 4.0 SP2 (KB927978) - (.Microsoft Corporation.) [HKLM] -- {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC}
O42 - Logiciel: MSXML 4.0 SP3 Parser (KB973685) - (.Microsoft Corporation.) [HKLM] -- {859DFA95-E4A6-48CD-B88E-A3E483E89B44}
O42 - Logiciel: MSXML 4.0 SP3 Parser - (.Microsoft Corporation.) [HKLM] -- {196467F1-C11F-4F76-858B-5812ADC83B94}
O42 - Logiciel: Malwarebytes' Anti-Malware version 1.51.2.1300 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Malwarebytes' RogueRemover - (.Malwarebytes.) [HKLM] -- Malwarebytes' RogueRemover FREE_is1
O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
O42 - Logiciel: Microsoft .NET Framework 1.1 French Language Pack - (.Microsoft.) [HKLM] -- {9A394342-4A68-4EBA-85A6-55B559F4E700}
O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB2416447) - (.Pas de propriétaire.) [HKLM] -- M2416447
O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
O42 - Logiciel: Microsoft Office Professional Edition 2003 - (.Microsoft Corporation.) [HKLM] -- {9011040C-6000-11D3-8CFE-0150048383C9}
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5}
O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c}
O42 - Logiciel: Multi Virus Cleaner 2011 - (.AxBx.) [HKLM] -- Multi Virus Cleaner 2011_is1
O42 - Logiciel: Multimedia Launcher - (.Pas de propriétaire.) [HKLM] -- {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}
O42 - Logiciel: Nuance PDF Viewer Plus - (.Nuance Communications, Inc.) [HKLM] -- {28656860-4728-433C-8AD4-D1A930437BC8}
O42 - Logiciel: Nuance PaperPort 12 - (.Nuance Communications, Inc..) [HKLM] -- {6C0A559F-8583-4B5A-8B50-20BEE15D8E64}
O42 - Logiciel: POST-NET - (.Pas de propriétaire.) [HKLM] -- ST5UNST #1
O42 - Logiciel: PaperPort Image Printer - (.Nuance Communications, Inc..) [HKLM] -- {6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}
O42 - Logiciel: PowerDVD - (.CyberLink Corporation.) [HKLM] -- {6811CAA0-BF12-11D4-9EA1-0050BAE317E1}
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {C9E14402-3631-4182-B377-6B0DFB1C0339}
O42 - Logiciel: SUPERAntiSpyware - (.SUPERAntiSpyware.com.) [HKLM] -- {CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
O42 - Logiciel: Sage Apinégoce Financier Standard - (.Pas de propriétaire.) [HKLM] -- APISOFT Financier HUIT
O42 - Logiciel: Sage Apinégoce Gestion Commerciale Standard - (.Pas de propriétaire.) [HKLM] -- APISOFT Gestion HUIT
O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
O42 - Logiciel: SigmaTel Audio - (.SigmaTel.) [HKLM] -- {A462213D-EED4-42C2-9A60-7BDD4D4B0B17}
O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1
O42 - Logiciel: SweetIM For Internet Explorer 3.0b - (.Macrogaming LTD..) [HKLM] -- {F6D63A65-BD23-46F3-B9A3-87F442423481}
O42 - Logiciel: Toolbar Cleaner 1.0 - (.Visicom Media Inc..) [HKLM] -- Toolbar Cleaner
O42 - Logiciel: Toolbar Uninstaller 1.0.0.1 - (.Decomputeur.nl.) [HKLM] -- Toolbar Uninstaller_is1
O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- WGA
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3B4E636E-9D65-4D67-BA61-189800823F52}
O42 - Logiciel: Windows Live Contrôle parental - (.Microsoft Corporation.) [HKLM] -- {D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {5DD76286-9BE7-4894-A990-E905E91AC818}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}
O42 - Logiciel: Windows Live Toolbar - (.Microsoft Corporation.) [HKLM] -- {F7D27C70-90F5-49B9-B188-0A133C0CE353}
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {4634B21A-CC07-4396-890C-2B8168661FEA}
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM] -- Windows Media Format Runtime
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11
O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {69995C7A-062A-4A90-A4DF-8C22895DF522}
O42 - Logiciel: uTorrentBar_FR Toolbar - (.uTorrentBar_FR.) [HKLM] -- uTorrentBar_FR Toolbar

---\\ HKCU & HKLM Software Keys
[HKCU\Software\3M]
[HKCU\Software\ABBYY]
[HKCU\Software\Adobe]
[HKCU\Software\Apisoft]
[HKCU\Software\AppDataLow\AskToolbarInfo]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Ask.com]
[HKCU\Software\AskToolbar]
[HKCU\Software\Auslogics]
[HKCU\Software\Brother]
[HKCU\Software\Classes]
[HKCU\Software\Conduit]
[HKCU\Software\Crystal Office]
[HKCU\Software\Cyberlink]
[HKCU\Software\DevNet]
[HKCU\Software\EA Games]
[HKCU\Software\EPSON]
[HKCU\Software\FLEXnet]
[HKCU\Software\Folder Manager]
[HKCU\Software\GameHouse]
[HKCU\Software\Google]
[HKCU\Software\HARVEST S.A.]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\IM Providers]
[HKCU\Software\INFOVAB]
[HKCU\Software\Illysoft]
[HKCU\Software\IncrediMail]
[HKCU\Software\InstallCore]
[HKCU\Software\InstallShield]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\KAZAA]
[HKCU\Software\Lake]
[HKCU\Software\Macromedia]
[HKCU\Software\Magnet]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\Netscape]
[HKCU\Software\NetworkTools]
[HKCU\Software\Northcode Inc]
[HKCU\Software\Nuance]
[HKCU\Software\ODBC]
[HKCU\Software\Opendisc]
[HKCU\Software\Pilote PDF API 2.5]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\PriceGong]
[HKCU\Software\SEIKO EPSON]
[HKCU\Software\SUPERAntiSpyware.com]
[HKCU\Software\SWEETIE]
[HKCU\Software\Safer Networking Limited]
[HKCU\Software\ScanSoft]
[HKCU\Software\Seagate Software]
[HKCU\Software\Skype]
[HKCU\Software\Softonic]
[HKCU\Software\Sophos]
[HKCU\Software\Sysinternals]
[HKCU\Software\TetraConcept]
[HKCU\Software\ToolbarCleaner]
[HKCU\Software\Trolltech]
[HKCU\Software\VB and VBA Program Settings]
[HKCU\Software\Visioneer]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\Windows Live Writer]
[HKCU\Software\YahooPartnerToolbar]
[HKCU\Software\Zeon]
[HKCU\Software\ahead]
[HKCU\Software\apasscracker]
[HKCU\Software\conduitEngine]
[HKCU\Software\stevengould.org]
[HKCU\Software\uTorrentBar_FR]
[HKLM\Software\ABBYY]
[HKLM\Software\APISOFT]
[HKLM\Software\APLOGISTIQUE]
[HKLM\Software\AVAST Software]
[HKLM\Software\Adobe]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Babylon]
[HKLM\Software\Brother Industries, Ltd.]
[HKLM\Software\Brother]
[HKLM\Software\BrowserChoice]
[HKLM\Software\C07ft5Y]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Conduit]
[HKLM\Software\Conexant]
[HKLM\Software\CyberLink]
[HKLM\Software\DevNet]
[HKLM\Software\EPSON]
[HKLM\Software\EURATEC]
[HKLM\Software\GEAR Software]
[HKLM\Software\GameHouse]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\HP]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\Illysoft]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel Corporation]
[HKLM\Software\Intel]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Lavasoft]
[HKLM\Software\Licenses]
[HKLM\Software\Macrogaming]
[HKLM\Software\Macromedia]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\MimarSinan]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\NetworkTools]
[HKLM\Software\Nuance]
[HKLM\Software\ODBC]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Reviversoft]
[HKLM\Software\SUPERAntiSpyware.com]
[HKLM\Software\Safer Networking Limited]
[HKLM\Software\Sage Apinégoce]
[HKLM\Software\Sage]
[HKLM\Software\ScanSoft]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\SigmaTel]
[HKLM\Software\Sophos]
[HKLM\Software\Symantec]
[HKLM\Software\System]
[HKLM\Software\TetraConcept]
[HKLM\Software\Uniblue]
[HKLM\Software\Visioneer]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Wow6432Node]
[HKLM\Software\ZEON]
[HKLM\Software\mozilla.org]
[HKLM\Software\uTorrentBar_FR]
~ Scan Softwares in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 24/06/2009 - 11:01:00 - [158573932] --H-D- C:\Program Files\Adobe
O43 - CFD: 29/09/2008 - 11:54:22 - [6370155] --H-D- C:\Program Files\API
O43 - CFD: 17/06/2008 - 11:09:02 - [5906] --H-D- C:\Program Files\APISOFT
O43 - CFD: 21/07/2011 - 08:26:34 - [2428606] --H-D- C:\Program Files\Apple Software Update
O43 - CFD: 25/07/2011 - 12:18:02 - [1674307] --H-D- C:\Program Files\Ask.com
O43 - CFD: 14/09/2011 - 11:47:10 - [107227904] --H-D- C:\Program Files\AVAST Software
O43 - CFD: 20/09/2011 - 18:29:08 - [51679851] ----D- C:\Program Files\AxBx
O43 - CFD: 30/11/2010 - 17:12:02 - [20429166] --H-D- C:\Program Files\Brother
O43 - CFD: 30/11/2010 - 17:12:06 - [15012572] --H-D- C:\Program Files\Browny02
O43 - CFD: 20/09/2011 - 12:20:20 - [4118120] --H-D- C:\Program Files\CCleaner
O43 - CFD: 20/09/2011 - 13:43:34 - [529077] --H-D- C:\Program Files\CleanUp!
O43 - CFD: 16/11/2006 - 16:30:26 - [0] --H-D- C:\Program Files\ComPlus Applications
O43 - CFD: 25/07/2011 - 12:29:42 - [1274048] --H-D- C:\Program Files\Conduit
O43 - CFD: 25/07/2011 - 12:29:40 - [4844061] --H-D- C:\Program Files\ConduitEngine
O43 - CFD: 30/11/2010 - 17:12:06 - [39352022] --H-D- C:\Program Files\ControlCenter4
O43 - CFD: 16/11/2006 - 17:12:22 - [61440] --H-D- C:\Program Files\CyberLink
O43 - CFD: 16/11/2006 - 17:12:20 - [32892472] --H-D- C:\Program Files\CyberLink DVD Solution
O43 - CFD: 16/09/2011 - 08:24:38 - [84551667] --H-D- C:\Program Files\epson
O43 - CFD: 27/01/2011 - 12:21:52 - [26256951] --H-D- C:\Program Files\FFT
O43 - CFD: 21/09/2011 - 15:13:48 - [412308052] --H-D- C:\Program Files\Fichiers communs
O43 - CFD: 04/04/2011 - 18:18:56 - [19347077] --H-D- C:\Program Files\Finance
O43 - CFD: 14/09/2011 - 18:06:14 - [0] --H-D- C:\Program Files\Free PDF to Word Doc Converter
O43 - CFD: 14/09/2011 - 17:57:48 - [18902054] --H-D- C:\Program Files\Google
O43 - CFD: 25/05/2010 - 14:28:40 - [1093728] --H-D- C:\Program Files\Hi-ToolKit for Home
O43 - CFD: 01/10/2010 - 10:04:24 - [15469284] --H-D- C:\Program Files\HP
O43 - CFD: 16/09/2011 - 08:24:28 - [26986332] --H-D- C:\Program Files\InstallShield Installation Information
O43 - CFD: 16/11/2006 - 17:00:42 - [7281513] --H-D- C:\Program Files\Intel
O43 - CFD: 16/02/2010 - 12:53:22 - [15748907] --H-D- C:\Program Files\Intel Audio Studio
O43 - CFD: 20/09/2011 - 12:22:24 - [6716912] --H-D- C:\Program Files\Internet Explorer
O43 - CFD: 06/09/2011 - 09:29:12 - [1868883] --H-D- C:\Program Files\iPod
O43 - CFD: 06/09/2011 - 09:30:34 - [124246827] --H-D- C:\Program Files\iTunes
O43 - CFD: 25/07/2011 - 12:15:32 - [80995612] --H-D- C:\Program Files\Java
O43 - CFD: 22/09/2011 - 09:23:58 - [1159232] ----D- C:\Program Files\Lavasoft
O43 - CFD: 25/07/2011 - 13:56:30 - [13] --H-D- C:\Program Files\LimeWire
O43 - CFD: 05/02/2008 - 12:16:00 - [3063441] --H-D- C:\Program Files\Macrogaming
O43 - CFD: 27/09/2011 - 10:21:44 - [7003980] --H-D- C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 16/02/2010 - 12:53:22 - [2157699] --H-D- C:\Program Files\Messenger
O43 - CFD: 01/10/2010 - 10:37:04 - [854520] --H-D- C:\Program Files\Microsoft
O43 - CFD: 26/08/2010 - 09:00:10 - [800662] --H-D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
O43 - CFD: 16/11/2006 - 16:36:26 - [0] --H-D- C:\Program Files\microsoft frontpage
O43 - CFD: 20/11/2006 - 15:13:28 - [8242002] --H-D- C:\Program Files\Microsoft IntelliType Pro
O43 - CFD: 20/11/2006 - 15:12:56 - [20951114] --H-D- C:\Program Files\Microsoft IntelliType Pro 5.5
O43 - CFD: 01/10/2010 - 10:48:10 - [275781409] --H-D- C:\Program Files\Microsoft Office
O43 - CFD: 01/10/2010 - 09:08:40 - [38360699] --H-D- C:\Program Files\Microsoft Silverlight
O43 - CFD: 17/09/2009 - 13:54:18 - [1829877] --H-D- C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 17/09/2009 - 13:55:22 - [2188837] --H-D- C:\Program Files\Microsoft Sync Framework
O43 - CFD: 20/11/2006 - 14:33:14 - [14904] --H-D- C:\Program Files\Microsoft Visual Studio
O43 - CFD: 01/10/2010 - 10:48:10 - [315392] --H-D- C:\Program Files\Microsoft.NET
O43 - CFD: 04/10/2010 - 16:39:04 - [10374874] --H-D- C:\Program Files\Movie Maker
O43 - CFD: 26/08/2010 - 10:16:40 - [25757] --H-D- C:\Program Files\MSBuild
O43 - CFD: 16/11/2006 - 16:29:20 - [0] --H-D- C:\Program Files\MSN
O43 - CFD: 16/11/2006 - 16:30:00 - [8745735] --H-D- C:\Program Files\MSN Gaming Zone
O43 - CFD: 30/11/2010 - 16:44:16 - [154033] --H-D- C:\Program Files\MSXML 4.0
O43 - CFD: 15/01/2009 - 12:10:38 - [3285523] --H-D- C:\Program Files\NetMeeting
O43 - CFD: 30/11/2010 - 17:10:06 - [237305106] --H-D- C:\Program Files\Nuance
O43 - CFD: 15/12/2010 - 17:29:38 - [4379321] --H-D- C:\Program Files\Outlook Express
O43 - CFD: 26/09/2007 - 10:32:00 - [45890] --H-D- C:\Program Files\POST IT
O43 - CFD: 22/09/2010 - 09:31:16 - [1142016] --H-D- C:\Program Files\POST-NET
O43 - CFD: 06/09/2011 - 09:13:20 - [75697179] --H-D- C:\Program Files\QuickTime
O43 - CFD: 26/08/2010 - 10:16:32 - [36400897] --H-D- C:\Program Files\Reference Assemblies
O43 - CFD: 16/09/2011 - 09:19:12 - [1772001] --H-D- C:\Program Files\RogueRemover FREE
O43 - CFD: 16/11/2006 - 16:34:32 - [1025] --H-D- C:\Program Files\Services en ligne
O43 - CFD: 16/11/2006 - 16:58:02 - [47539080] --H-D- C:\Program Files\SigmaTel
O43 - CFD: 14/09/2011 - 18:53:14 - [53804108] --H-D- C:\Program Files\Spybot - Search & Destroy
O43 - CFD: 20/09/2011 - 18:11:38 - [69107870] ----D- C:\Program Files\SUPERAntiSpyware
O43 - CFD: 21/09/2011 - 15:13:26 - [10408534] --H-D- C:\Program Files\Symantec
O43 - CFD: 21/09/2011 - 16:35:32 - [658557] ----D- C:\Program Files\Toolbar Cleaner
O43 - CFD: 22/09/2011 - 08:50:54 - [1585284] ----D- C:\Program Files\Toolbar Uninstaller
O43 - CFD: 16/11/2006 - 16:40:36 - [0] --H-D- C:\Program Files\Uninstall Information
O43 - CFD: 25/07/2011 - 12:29:38 - [4855597] --H-D- C:\Program Files\uTorrentBar_FR
O43 - CFD: 01/10/2010 - 10:07:36 - [139063786] --H-D- C:\Program Files\Windows Live
O43 - CFD: 16/02/2010 - 12:53:24 - [3600014] --H-D- C:\Program Files\Windows Media Connect 2
O43 - CFD: 01/10/2010 - 15:12:44 - [7512329] --H-D- C:\Program Files\Windows Media Player
O43 - CFD: 15/01/2009 - 12:10:34 - [3942655] --H-D- C:\Program Files\Windows NT
O43 - CFD: 16/11/2006 - 16:34:38 - [0] --H-D- C:\Program Files\WindowsUpdate
O43 - CFD: 16/11/2006 - 16:36:26 - [0] --H-D- C:\Program Files\xerox
O43 - CFD: 27/09/2011 - 11:13:20 - [6396226] ----D- C:\Program Files\ZHPDiag
O43 - CFD: 24/06/2009 - 11:01:10 - [9667173] --H-D- C:\Program Files\Fichiers Communs\Adobe
O43 - CFD: 18/10/2010 - 16:20:30 - [13287713] --H-D- C:\Program Files\Fichiers Communs\Aplogistique
O43 - CFD: 06/09/2011 - 09:29:10 - [102608648] --H-D- C:\Program Files\Fichiers Communs\Apple
O43 - CFD: 01/10/2010 - 10:48:28 - [86016] --H-D- C:\Program Files\Fichiers Communs\DESIGNER
O43 - CFD: 20/11/2006 - 13:19:14 - [270336] --H-D- C:\Program Files\Fichiers Communs\Hewlett-Packard
O43 - CFD: 07/02/2007 - 14:07:52 - [12400653] --H-D- C:\Program Files\Fichiers Communs\InstallShield
O43 - CFD: 25/07/2011 - 12:16:16 - [1228747] --H-D- C:\Program Files\Fichiers Communs\Java
O43 - CFD: 01/10/2010 - 10:49:10 - [114746918] --H-D- C:\Program Files\Fichiers Communs\Microsoft Shared
O43 - CFD: 16/11/2006 - 16:32:18 - [284160] --H-D- C:\Program Files\Fichiers Communs\MSSoap
O43 - CFD: 16/11/2006 - 17:19:56 - [0] --H-D- C:\Program Files\Fichiers Communs\ODBC
O43 - CFD: 30/11/2010 - 17:08:14 - [3483840] --H-D- C:\Program Files\Fichiers Communs\ScanSoft Shared
O43 - CFD: 16/11/2006 - 16:32:30 - [8106] --H-D- C:\Program Files\Fichiers Communs\Services
O43 - CFD: 16/11/2006 - 17:19:52 - [3787229] --H-D- C:\Program Files\Fichiers Communs\SpeechEngines
O43 - CFD: 20/11/2006 - 12:21:54 - [192512] --H-D- C:\Program Files\Fichiers Communs\SWF Studio
O43 - CFD: 01/10/2010 - 10:48:16 - [19947471] --H-D- C:\Program Files\Fichiers Communs\System
O43 - CFD: 17/09/2009 - 13:26:12 - [130308530] --H-D- C:\Program Files\Fichiers Communs\Windows Live
O43 - CFD: 26/09/2007 - 10:41:56 - [22855] --H-D- C:\Documents and Settings\station\Application Data\3M
O43 - CFD: 13/09/2011 - 09:25:20 - [52486105] --H-D- C:\Documents and Settings\station\Application Data\Adobe
O43 - CFD: 13/05/2008 - 10:35:46 - [82] --H-D- C:\Documents and Settings\station\Application Data\AdobeUM
O43 - CFD: 14/11/2007 - 18:25:24 - [0] --H-D- C:\Documents and Settings\station\Application Data\Ahead
O43 - CFD: 12/09/2011 - 14:53:58 - [1958932930] --H-D- C:\Documents and Settings\station\Application Data\Apple Computer
O43 - CFD: 25/07/2011 - 12:19:48 - [70] --H-D- C:\Documents and Settings\station\Application Data\AskToolbar
O43 - CFD: 26/02/2010 - 12:00:02 - [0] --H-D- C:\Documents and Settings\station\Application Data\Auslogics
O43 - CFD: 25/07/2011 - 12:28:56 - [2089] --H-D- C:\Documents and Settings\station\Application Data\Babylon
O43 - CFD: 30/11/2010 - 17:40:42 - [56] RSH-D- C:\Documents and Settings\station\Application Data\Brother
O43 - CFD: 30/11/2010 - 17:15:36 - [23391] --H-D- C:\Documents and Settings\station\Application Data\ControlCenter4
O43 - CFD: 16/11/2006 - 17:27:22 - [2560] --H-D- C:\Documents and Settings\station\Application Data\CyberLink
O43 - CFD: 02/11/2007 - 11:11:32 - [732] --H-D- C:\Documents and Settings\station\Application Data\EPSON
O43 - CFD: 30/11/2010 - 17:15:36 - [574] --H-D- C:\Documents and Settings\station\Application Data\FLEXnet
O43 - CFD: 14/01/2009 - 15:15:18 - [295606] --H-D- C:\Documents and Settings\station\Application Data\GameHouse
O43 - CFD: 14/11/2007 - 11:07:58 - [826] --H-D- C:\Documents and Settings\station\Application Data\Google
O43 - CFD: 21/05/2007 - 14:58:06 - [28186] --H-D- C:\Documents and Settings\station\Application Data\HARVEST S.A
O43 - CFD: 05/04/2007 - 09:57:20 - [0] --H-D- C:\Documents and Settings\station\Application Data\Help
O43 - CFD: 20/11/2006 - 13:31:04 - [151] --H-D- C:\Documents and Settings\station\Application Data\HP
O43 - CFD: 22/02/2011 - 10:32:10 - [7788] --H-D- C:\Documents and Settings\station\Application Data\Icones
O43 - CFD: 16/11/2006 - 16:40:38 - [0] --H-D- C:\Documents and Settings\station\Application Data\Identities
O43 - CFD: 30/11/2010 - 16:57:56 - [0] --H-D- C:\Documents and Settings\station\Application Data\InstallShield
O43 - CFD: 27/11/2006 - 17:39:40 - [1529087] --H-D- C:\Documents and Settings\station\Application Data\Macromedia
O43 - CFD: 01/04/2009 - 09:54:52 - [7941] --H-D- C:\Documents and Settings\station\Application Data\Malwarebytes
O43 - CFD: 16/02/2010 - 16:30:28 - [14798447] -S--D- C:\Documents and Settings\station\Application Data\Microsoft
O43 - CFD: 25/07/2011 - 12:18:40 - [0] --H-D- C:\Documents and Settings\station\Application Data\Mozilla
O43 - CFD: 30/11/2010 - 17:18:22 - [7113] --H-D- C:\Documents and Settings\station\Application Data\Nuance
O43 - CFD: 08/12/2010 - 09:38:18 - [174] --H-D- C:\Documents and Settings\station\Application Data\PC-FAX TX
O43 - CFD: 21/09/2011 - 14:45:30 - [1923880] --H-D- C:\Documents and Settings\station\Application Data\PriceGong
O43 - CFD: 12/05/2011 - 12:34:24 - [642149] --H-D- C:\Documents and Settings\station\Application Data\Reviversoft
O43 - CFD: 04/03/2009 - 11:22:02 - [2057135] --H-D- C:\Documents and Settings\station\Application Data\Skype
O43 - CFD: 02/03/2009 - 17:03:26 - [42384] --H-D- C:\Documents and Settings\station\Application Data\skypePM
O43 - CFD: 14/01/2009 - 15:25:34 - [923670] --H-D- C:\Documents and Settings\station\Application Data\Sun
O43 - CFD: 20/09/2011 - 18:11:38 - [4434743] ----D- C:\Documents and Settings\station\Application Data\SUPERAntiSpyware.com
O43 - CFD: 05/05/2009 - 15:20:44 - [0] --H-D- C:\Documents and Settings\station\Application Data\U3
O43 - CFD: 27/07/2011 - 09:51:58 - [8100] --H-D- C:\Documents and Settings\station\Application Data\uTorrent
O43 - CFD: 14/01/2009 - 15:18:44 - [93668] --H-D- C:\Documents and Settings\station\Application Data\Wildfire
O43 - CFD: 20/04/2010 - 15:12:32 - [0] --H-D- C:\Documents and Settings\station\Application Data\Windows Live Writer
O43 - CFD: 30/11/2010 - 17:18:34 - [5343] --H-D- C:\Documents and Settings\station\Application Data\Zeon
O43 - CFD: 24/09/2008 - 11:01:32 - [47907785] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Adobe
O43 - CFD: 15/05/2007 - 11:21:12 - [1950597] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Ahead
O43 - CFD: 04/12/2006 - 17:11:24 - [4858731] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\APLOGISTIQUE
O43 - CFD: 03/01/2011 - 16:14:04 - [0] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Apple
O43 - CFD: 03/01/2011 - 16:17:32 - [3011912] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Apple Computer
O43 - CFD: 30/09/2009 - 08:43:06 - [13042] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\ApplicationHistory
O43 - CFD: 25/07/2011 - 13:51:32 - [3078098] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\AskToolbar
O43 - CFD: 25/07/2011 - 12:28:56 - [3911963] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Babylon
O43 - CFD: 25/07/2011 - 12:29:36 - [209360] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Conduit
O43 - CFD: 19/09/2011 - 08:38:02 - [4915758] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\ConduitEngine
O43 - CFD: 14/09/2011 - 18:32:28 - [830316] --H-D- C:\Documents and Settings\station\Local Settings\Appl

3 réponses

Utilisateur anonyme
27 sept. 2011 à 16:06
bonjour,

est ce que tu peux envoyer le hébergé via Cijoint ?

il est incomplet !

0
boris06 Messages postés 12 Date d'inscription mardi 27 septembre 2011 Statut Membre Dernière intervention 2 octobre 2011
27 sept. 2011 à 16:14
Merci pour ton aide
Rapport de ZHPDiag v1.28.1354 par Nicolas Coolman, Update du 25/09/2011
Run by station at 27/09/2011 11:13:08
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html


---\\ Web Browser
MSIE: Internet Explorer v8.0.6001.18702 (Defaut)

---\\ Windows Product Information
Windows XP Professional Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
Windows Genuine Advantage : OK

---\\ System Information
~ Processor: x86 Family 15 Model 6 Stepping 4, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 997.9 MB (18% free)
System Restore: Activé (Enable)
System drive C: has 24 GB (60%) free of 39 GB

---\\ Logged in mode
~ Computer Name: COMMERCIAL
~ User Name: station
~ All Users Names: SUPPORT_388945a0, station, HelpAssistant, ASPNET, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Documents and Settings\station\Application Data\
~ %Desktop% : C:\Documents and Settings\station\Bureau\
~ %Favorites% : C:\Documents and Settings\station\Favoris\
~ %LocalAppData% : C:\Documents and Settings\station\Local Settings\Application Data\
~ %StartMenu% : C:\Documents and Settings\station\Menu Démarrer\
~ %Windir% : C:\WINDOWS\
~ %System% : C:\WINDOWS\system32\

---\\ DOS/Devices
A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
C:\ Hard drive, Flash drive, Thumb drive (Free 24 Go of 39 Go)
D:\ CD-ROM drive (Not Inserted)
E:\ Hard drive, Flash drive, Thumb drive (Free 37 Go of 37 Go)



---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
~ Scan Security Center in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\Explorer.exe [1037824]
[MD5.93AD0B78C7357A05F50E594EC7C22300] - (....) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\rundll32.exe [33792]
[MD5.3008D2F793F23FF0DDBC5A1FB9F8374F] - (.Microsoft Corporation - Internet Extensions for Win32.) (.27/09/2011 - 19:31:31.) -- C:\WINDOWS\system32\wininet.dll [916480]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.27/09/2011 - 13:00:00.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]
~ Scan Generic Processes in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
Mes images (My Pictures) : 6/6 (Modified)
Mes musiques (My Musics) : 17/17 (Modified)
~ Mes Videos (My Video) : 0/0
~ Mes Favoris (My Favorites) : 79/86
Mes Documents (My Documents) : 51/51 (Modified)
~ Mon Bureau (My Desktop) : 23/1840
Menu demarrer (Programs) : 27/27 (Modified)
~ Scan Hidden Files in 00mn 08s



---\\ Processus lancés
[MD5.C0393EB99A6C72C6BEF9BFC4A72B33A6] - (.SUPERAntiSpyware.com - Core Service.) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608] [PID.]
[MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664] [PID.]
[MD5.77AC10DB097DFD0CD3071465B644D0AB] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376] [PID.]
[MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [322120] [PID.]
[MD5.C1C3BAF078BE5A14384A4BA2D730817D] - (.Nuance Communications, Inc. - PDFPro IFilter Service.) -- C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672] [PID.]
[MD5.B60DDDD2D63CE41CB8C487FCFBB6419E] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [638816] [PID.3412]
[MD5.D30EB2F98504F30ECAAEEF90DDC7DE98] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [2122752] [PID.1960]
[MD5.5E9A6658A2A69AE7EB195113B7A2E7A9] - (.Microsoft Corporation - Application Layer Gateway Service.) -- C:\WINDOWS\System32\alg.exe [44544] [PID.]
~ Scan Processes Running in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50917.0.) -- C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
~ Scan Firefox Browser in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww7.wuuta.com
R0 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = https://www.google.com/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = https://www.google.com/?gws_rd=ssl
R1 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = google
R1 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = https://www.google.com/?gws_rd=ssl
R1 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask.com - Ask.com Toolbar.) (5.6.12.178) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.19098 (longhorn_ie8_gdr.110617-1715)) -- C:\WINDOWS\system32\ieframe.dll
R3 - URLSearchHook: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} . (.Conduit Ltd. - Conduit Toolbar.) (6.3.4.1) -- C:\Program Files\uTorrentBar_FR\prxtbuTor.dll
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s



---\\ Redirection du fichier Hosts (O1)
O1 - Hosts: 95.64.61.141 www.google.com
O1 - Hosts: 95.64.61.142 www.bing.com
~ Scan Hosts File in 00mn 00s



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} Clé orpheline
~ Scan BHO in 00mn 00s



---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [KernelFaultCheck] Clé orpheline
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe (.not file.)
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-21-329068152-823518204-725345543-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
~ Scan Application in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\Assistance à distance.lnk . (.Microsoft Corporation.) -- C:\WINDOWS\system32\rcimlby.exe
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\Lecteur Windows Media.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\POST-NET.LNK . (.Contact: Jeux.cartes@free.fr.) -- C:\Program Files\POST-NET\Post-Net.exe
O4 - Global Startup: C:\Documents And Settings\station\Menu Démarrer\Programmes\SAV+.LNK . (.INFOVAB.) -- C:\SaveW\SaveW.exe
~ Scan Global Startup in 00mn 00s



---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.exe
O8 - Extra context menu item: Google Sidewiki... . (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll
O8 - Extra context menu item: Ouvrir avec PDF Viewer Plus . (.Zeon Corporation - PlusIEContextMenu.dll.) -- C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
~ Scan IE Menu Contextuel in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
O9 - Extra button: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} . (...) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (...) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
~ Scan IE Extra Buttons in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
~ Scan Winsock in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1282739186109
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1282739171546
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} (HPSDDX Class) - http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
~ Scan Objets ActiveX in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A354028D-8CDD-4454-ABD7-8A70FC4AEBA0}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{A354028D-8CDD-4454-ABD7-8A70FC4AEBA0}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{A354028D-8CDD-4454-ABD7-8A70FC4AEBA0}: DhcpNameServer = 192.168.1.1
~ Scan Domain in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} . (.Microsoft Corporation - Microsoft Office Web Components 2003.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll
O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
~ Scan Protocole Additionnel in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: !SASWinLogon . (.SUPERAntiSpyware.com - SUPERAntiSpyware WinLogon Processor.) -- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\WINDOWS\system32\igfxdev.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\WINDOWS\system32\WgaLogon.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
~ Scan Winlogon in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll
~ Scan SSODL in 00mn 00s



---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
~ Scan STS/SSO in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: SAS Core Service (!SASCORE) . (.SUPERAntiSpyware.com - Core Service.) - C:\Program Files\SUPERAntiSpyware\SASCORE.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PDFProFiltSrvPP (PDFProFiltSrvPP) . (.Nuance Communications, Inc. - PDFPro IFilter Service.) - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
~ Scan Services in 00mn 00s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.exe
~ Scan Desktop Component in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{3EA7F0F1-F2E8-4AD7-9E21-82D2CB33E9D0}.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{62306650-42CC-41BC-AF20-38C50B7C6823}.job
[MD5.00000000000000000000000000000000] [APT] [Ad-Aware Update (Weekly)] (...) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe (.not file.)
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.9309B115B18C5D132203FA3BBD4A4FA1] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files\Ask.com\UpdateTask.exe
~ Scan Scheduled Task in 00mn 00s



---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys
O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\WINDOWS\system32\DRIVERS\intelppm.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
O41 - Driver: (kbdhid) . (.Microsoft Corporation - Pilote de filtre souris HID.) - C:\WINDOWS\system32\DRIVERS\kbdhid.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys
O41 - Driver: (ovfsthjewnirqtkfrhctsymovgtgeppixbxqxf) . (. - .) - C:\WINDOWS\system32\drivers\ovfsthbogrcdevsppabaiyotxdmenwktafydqv.sys (.not file.)
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\WINDOWS\system32\DRIVERS\redbook.sys
O41 - Driver: (SASDIFSV) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV.SYS.) - C:\Program Files\SUPERAntiSpyware\SASDIFSV.sys
O41 - Driver: (SASKUTIL) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL.SYS.) - C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\WINDOWS\system32\DRIVERS\serial.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys
O41 - Driver: Carte vidéo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
~ Scan Drivers in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {2614F54E-A828-49FA-93BA-45A3F756BFAA}
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Reader 9.1 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A91000000001}
O42 - Logiciel: Adobe SVG Viewer 3.0 - (.Pas de propriétaire.) [HKLM] -- Adobe SVG Viewer
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {6A3F9D74-BB80-4451-8CA1-4B3A857F1359}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {C23CD6DA-1958-43A5-ADD0-59396572E02E}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE}
O42 - Logiciel: Brother MFL-Pro Suite MFC-9460CDN - (.Brother Industries, Ltd..) [HKLM] -- {979742CC-2CBB-49D8-9BEE-C2F7875F5393}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: CleanUp! - (.Pas de propriétaire.) [HKLM] -- CleanUp!
O42 - Logiciel: Conduit Engine - (.Conduit Ltd..) [HKLM] -- conduitEngine
O42 - Logiciel: DVD Solution - (.Pas de propriétaire.) [HKLM] -- {B97CF5C3-0487-11D8-A36E-0050BAE317E1}
O42 - Logiciel: EPSON Easy Photo Print - (.Pas de propriétaire.) [HKLM] -- {BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}
O42 - Logiciel: EPSON Logiciel imprimante - (.Pas de propriétaire.) [HKLM] -- EPSON Printer and Utilities
O42 - Logiciel: EPSON Scan - (.Pas de propriétaire.) [HKLM] -- EPSON Scanner
O42 - Logiciel: FFT - (.Pas de propriétaire.) [HKLM] -- ST6UNST #3
O42 - Logiciel: FFT\) - (.Pas de propriétaire.) [HKLM] -- ST6UNST #2
O42 - Logiciel: Fiche fin de travaux - (.Pas de propriétaire.) [HKLM] -- ST6UNST #1
O42 - Logiciel: Finance - (.Pas de propriétaire.) [HKLM] -- ST6UNST #4
O42 - Logiciel: Financier HUIT - (.Pas de propriétaire.) [HKLM] -- Financier HUIT
O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {B131E59D-202C-43C6-84C9-68F0C37541F1}
O42 - Logiciel: Gestion 8 - (.Pas de propriétaire.) [HKLM] -- Gestion 8
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {18455581-E099-4BA8-BC6B-F34B2F06600C}
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}
O42 - Logiciel: Intel Audio Studio 2.0 - (.Intel Corporation.) [HKLM] -- {2205E3A5-DCDC-461D-8ED6-D6F2341D3B64}
O42 - Logiciel: Intel(R) Active Client Manager 2.0 HECI Driver - (.Pas de propriétaire.) [HKLM] -- HECI
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Pas de propriétaire.) [HKLM] -- HDMI
O42 - Logiciel: Intel(R) PRO Network Connections - (.Intel.) [HKLM] -- {0A0873E1-D9BA-4994-B85D-A0A331EF1F0C}
O42 - Logiciel: Java(TM) 6 Update 18 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216018FF}
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {E2DFE069-083E-4631-9B6C-43C48E991DE5}
O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM] -- Windows Media Player
O42 - Logiciel: LiveUpdate 3.1 (Symantec Corporation) - (.Symantec Corporation.) [HKLM] -- LiveUpdate
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
O42 - Logiciel: MSXML 4.0 SP2 (KB927978) - (.Microsoft Corporation.) [HKLM] -- {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC}
O42 - Logiciel: MSXML 4.0 SP3 Parser (KB973685) - (.Microsoft Corporation.) [HKLM] -- {859DFA95-E4A6-48CD-B88E-A3E483E89B44}
O42 - Logiciel: MSXML 4.0 SP3 Parser - (.Microsoft Corporation.) [HKLM] -- {196467F1-C11F-4F76-858B-5812ADC83B94}
O42 - Logiciel: Malwarebytes' Anti-Malware version 1.51.2.1300 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Malwarebytes' RogueRemover - (.Malwarebytes.) [HKLM] -- Malwarebytes' RogueRemover FREE_is1
O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
O42 - Logiciel: Microsoft .NET Framework 1.1 French Language Pack - (.Microsoft.) [HKLM] -- {9A394342-4A68-4EBA-85A6-55B559F4E700}
O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB2416447) - (.Pas de propriétaire.) [HKLM] -- M2416447
O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
O42 - Logiciel: Microsoft Office Professional Edition 2003 - (.Microsoft Corporation.) [HKLM] -- {9011040C-6000-11D3-8CFE-0150048383C9}
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5}
O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c}
O42 - Logiciel: Multi Virus Cleaner 2011 - (.AxBx.) [HKLM] -- Multi Virus Cleaner 2011_is1
O42 - Logiciel: Multimedia Launcher - (.Pas de propriétaire.) [HKLM] -- {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}
O42 - Logiciel: Nuance PDF Viewer Plus - (.Nuance Communications, Inc.) [HKLM] -- {28656860-4728-433C-8AD4-D1A930437BC8}
O42 - Logiciel: Nuance PaperPort 12 - (.Nuance Communications, Inc..) [HKLM] -- {6C0A559F-8583-4B5A-8B50-20BEE15D8E64}
O42 - Logiciel: POST-NET - (.Pas de propriétaire.) [HKLM] -- ST5UNST #1
O42 - Logiciel: PaperPort Image Printer - (.Nuance Communications, Inc..) [HKLM] -- {6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}
O42 - Logiciel: PowerDVD - (.CyberLink Corporation.) [HKLM] -- {6811CAA0-BF12-11D4-9EA1-0050BAE317E1}
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {C9E14402-3631-4182-B377-6B0DFB1C0339}
O42 - Logiciel: SUPERAntiSpyware - (.SUPERAntiSpyware.com.) [HKLM] -- {CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
O42 - Logiciel: Sage Apinégoce Financier Standard - (.Pas de propriétaire.) [HKLM] -- APISOFT Financier HUIT
O42 - Logiciel: Sage Apinégoce Gestion Commerciale Standard - (.Pas de propriétaire.) [HKLM] -- APISOFT Gestion HUIT
O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
O42 - Logiciel: SigmaTel Audio - (.SigmaTel.) [HKLM] -- {A462213D-EED4-42C2-9A60-7BDD4D4B0B17}
O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1
O42 - Logiciel: SweetIM For Internet Explorer 3.0b - (.Macrogaming LTD..) [HKLM] -- {F6D63A65-BD23-46F3-B9A3-87F442423481}
O42 - Logiciel: Toolbar Cleaner 1.0 - (.Visicom Media Inc..) [HKLM] -- Toolbar Cleaner
O42 - Logiciel: Toolbar Uninstaller 1.0.0.1 - (.Decomputeur.nl.) [HKLM] -- Toolbar Uninstaller_is1
O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- WGA
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3B4E636E-9D65-4D67-BA61-189800823F52}
O42 - Logiciel: Windows Live Contrôle parental - (.Microsoft Corporation.) [HKLM] -- {D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {5DD76286-9BE7-4894-A990-E905E91AC818}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}
O42 - Logiciel: Windows Live Toolbar - (.Microsoft Corporation.) [HKLM] -- {F7D27C70-90F5-49B9-B188-0A133C0CE353}
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {4634B21A-CC07-4396-890C-2B8168661FEA}
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM] -- Windows Media Format Runtime
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11
O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {69995C7A-062A-4A90-A4DF-8C22895DF522}
O42 - Logiciel: uTorrentBar_FR Toolbar - (.uTorrentBar_FR.) [HKLM] -- uTorrentBar_FR Toolbar

---\\ HKCU & HKLM Software Keys
[HKCU\Software\3M]
[HKCU\Software\ABBYY]
[HKCU\Software\Adobe]
[HKCU\Software\Apisoft]
[HKCU\Software\AppDataLow\AskToolbarInfo]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Ask.com]
[HKCU\Software\AskToolbar]
[HKCU\Software\Auslogics]
[HKCU\Software\Brother]
[HKCU\Software\Classes]
[HKCU\Software\Conduit]
[HKCU\Software\Crystal Office]
[HKCU\Software\Cyberlink]
[HKCU\Software\DevNet]
[HKCU\Software\EA Games]
[HKCU\Software\EPSON]
[HKCU\Software\FLEXnet]
[HKCU\Software\Folder Manager]
[HKCU\Software\GameHouse]
[HKCU\Software\Google]
[HKCU\Software\HARVEST S.A.]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\IM Providers]
[HKCU\Software\INFOVAB]
[HKCU\Software\Illysoft]
[HKCU\Software\IncrediMail]
[HKCU\Software\InstallCore]
[HKCU\Software\InstallShield]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\KAZAA]
[HKCU\Software\Lake]
[HKCU\Software\Macromedia]
[HKCU\Software\Magnet]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\Netscape]
[HKCU\Software\NetworkTools]
[HKCU\Software\Northcode Inc]
[HKCU\Software\Nuance]
[HKCU\Software\ODBC]
[HKCU\Software\Opendisc]
[HKCU\Software\Pilote PDF API 2.5]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\PriceGong]
[HKCU\Software\SEIKO EPSON]
[HKCU\Software\SUPERAntiSpyware.com]
[HKCU\Software\SWEETIE]
[HKCU\Software\Safer Networking Limited]
[HKCU\Software\ScanSoft]
[HKCU\Software\Seagate Software]
[HKCU\Software\Skype]
[HKCU\Software\Softonic]
[HKCU\Software\Sophos]
[HKCU\Software\Sysinternals]
[HKCU\Software\TetraConcept]
[HKCU\Software\ToolbarCleaner]
[HKCU\Software\Trolltech]
[HKCU\Software\VB and VBA Program Settings]
[HKCU\Software\Visioneer]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\Windows Live Writer]
[HKCU\Software\YahooPartnerToolbar]
[HKCU\Software\Zeon]
[HKCU\Software\ahead]
[HKCU\Software\apasscracker]
[HKCU\Software\conduitEngine]
[HKCU\Software\stevengould.org]
[HKCU\Software\uTorrentBar_FR]
[HKLM\Software\ABBYY]
[HKLM\Software\APISOFT]
[HKLM\Software\APLOGISTIQUE]
[HKLM\Software\AVAST Software]
[HKLM\Software\Adobe]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Babylon]
[HKLM\Software\Brother Industries, Ltd.]
[HKLM\Software\Brother]
[HKLM\Software\BrowserChoice]
[HKLM\Software\C07ft5Y]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Conduit]
[HKLM\Software\Conexant]
[HKLM\Software\CyberLink]
[HKLM\Software\DevNet]
[HKLM\Software\EPSON]
[HKLM\Software\EURATEC]
[HKLM\Software\GEAR Software]
[HKLM\Software\GameHouse]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\HP]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\Illysoft]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel Corporation]
[HKLM\Software\Intel]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lake]
[HKLM\Software\Lavasoft]
[HKLM\Software\Licenses]
[HKLM\Software\Macrogaming]
[HKLM\Software\Macromedia]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\MimarSinan]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\NetworkTools]
[HKLM\Software\Nuance]
[HKLM\Software\ODBC]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Reviversoft]
[HKLM\Software\SUPERAntiSpyware.com]
[HKLM\Software\Safer Networking Limited]
[HKLM\Software\Sage Apinégoce]
[HKLM\Software\Sage]
[HKLM\Software\ScanSoft]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\SigmaTel]
[HKLM\Software\Sophos]
[HKLM\Software\Symantec]
[HKLM\Software\System]
[HKLM\Software\TetraConcept]
[HKLM\Software\Uniblue]
[HKLM\Software\Visioneer]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Wow6432Node]
[HKLM\Software\ZEON]
[HKLM\Software\mozilla.org]
[HKLM\Software\uTorrentBar_FR]
~ Scan Softwares in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 24/06/2009 - 11:01:00 - [158573932] --H-D- C:\Program Files\Adobe
O43 - CFD: 29/09/2008 - 11:54:22 - [6370155] --H-D- C:\Program Files\API
O43 - CFD: 17/06/2008 - 11:09:02 - [5906] --H-D- C:\Program Files\APISOFT
O43 - CFD: 21/07/2011 - 08:26:34 - [2428606] --H-D- C:\Program Files\Apple Software Update
O43 - CFD: 25/07/2011 - 12:18:02 - [1674307] --H-D- C:\Program Files\Ask.com
O43 - CFD: 14/09/2011 - 11:47:10 - [107227904] --H-D- C:\Program Files\AVAST Software
O43 - CFD: 20/09/2011 - 18:29:08 - [51679851] ----D- C:\Program Files\AxBx
O43 - CFD: 30/11/2010 - 17:12:02 - [20429166] --H-D- C:\Program Files\Brother
O43 - CFD: 30/11/2010 - 17:12:06 - [15012572] --H-D- C:\Program Files\Browny02
O43 - CFD: 20/09/2011 - 12:20:20 - [4118120] --H-D- C:\Program Files\CCleaner
O43 - CFD: 20/09/2011 - 13:43:34 - [529077] --H-D- C:\Program Files\CleanUp!
O43 - CFD: 16/11/2006 - 16:30:26 - [0] --H-D- C:\Program Files\ComPlus Applications
O43 - CFD: 25/07/2011 - 12:29:42 - [1274048] --H-D- C:\Program Files\Conduit
O43 - CFD: 25/07/2011 - 12:29:40 - [4844061] --H-D- C:\Program Files\ConduitEngine
O43 - CFD: 30/11/2010 - 17:12:06 - [39352022] --H-D- C:\Program Files\ControlCenter4
O43 - CFD: 16/11/2006 - 17:12:22 - [61440] --H-D- C:\Program Files\CyberLink
O43 - CFD: 16/11/2006 - 17:12:20 - [32892472] --H-D- C:\Program Files\CyberLink DVD Solution
O43 - CFD: 16/09/2011 - 08:24:38 - [84551667] --H-D- C:\Program Files\epson
O43 - CFD: 27/01/2011 - 12:21:52 - [26256951] --H-D- C:\Program Files\FFT
O43 - CFD: 21/09/2011 - 15:13:48 - [412308052] --H-D- C:\Program Files\Fichiers communs
O43 - CFD: 04/04/2011 - 18:18:56 - [19347077] --H-D- C:\Program Files\Finance
O43 - CFD: 14/09/2011 - 18:06:14 - [0] --H-D- C:\Program Files\Free PDF to Word Doc Converter
O43 - CFD: 14/09/2011 - 17:57:48 - [18902054] --H-D- C:\Program Files\Google
O43 - CFD: 25/05/2010 - 14:28:40 - [1093728] --H-D- C:\Program Files\Hi-ToolKit for Home
O43 - CFD: 01/10/2010 - 10:04:24 - [15469284] --H-D- C:\Program Files\HP
O43 - CFD: 16/09/2011 - 08:24:28 - [26986332] --H-D- C:\Program Files\InstallShield Installation Information
O43 - CFD: 16/11/2006 - 17:00:42 - [7281513] --H-D- C:\Program Files\Intel
O43 - CFD: 16/02/2010 - 12:53:22 - [15748907] --H-D- C:\Program Files\Intel Audio Studio
O43 - CFD: 20/09/2011 - 12:22:24 - [6716912] --H-D- C:\Program Files\Internet Explorer
O43 - CFD: 06/09/2011 - 09:29:12 - [1868883] --H-D- C:\Program Files\iPod
O43 - CFD: 06/09/2011 - 09:30:34 - [124246827] --H-D- C:\Program Files\iTunes
O43 - CFD: 25/07/2011 - 12:15:32 - [80995612] --H-D- C:\Program Files\Java
O43 - CFD: 22/09/2011 - 09:23:58 - [1159232] ----D- C:\Program Files\Lavasoft
O43 - CFD: 25/07/2011 - 13:56:30 - [13] --H-D- C:\Program Files\LimeWire
O43 - CFD: 05/02/2008 - 12:16:00 - [3063441] --H-D- C:\Program Files\Macrogaming
O43 - CFD: 27/09/2011 - 10:21:44 - [7003980] --H-D- C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 16/02/2010 - 12:53:22 - [2157699] --H-D- C:\Program Files\Messenger
O43 - CFD: 01/10/2010 - 10:37:04 - [854520] --H-D- C:\Program Files\Microsoft
O43 - CFD: 26/08/2010 - 09:00:10 - [800662] --H-D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
O43 - CFD: 16/11/2006 - 16:36:26 - [0] --H-D- C:\Program Files\microsoft frontpage
O43 - CFD: 20/11/2006 - 15:13:28 - [8242002] --H-D- C:\Program Files\Microsoft IntelliType Pro
O43 - CFD: 20/11/2006 - 15:12:56 - [20951114] --H-D- C:\Program Files\Microsoft IntelliType Pro 5.5
O43 - CFD: 01/10/2010 - 10:48:10 - [275781409] --H-D- C:\Program Files\Microsoft Office
O43 - CFD: 01/10/2010 - 09:08:40 - [38360699] --H-D- C:\Program Files\Microsoft Silverlight
O43 - CFD: 17/09/2009 - 13:54:18 - [1829877] --H-D- C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 17/09/2009 - 13:55:22 - [2188837] --H-D- C:\Program Files\Microsoft Sync Framework
O43 - CFD: 20/11/2006 - 14:33:14 - [14904] --H-D- C:\Program Files\Microsoft Visual Studio
O43 - CFD: 01/10/2010 - 10:48:10 - [315392] --H-D- C:\Program Files\Microsoft.NET
O43 - CFD: 04/10/2010 - 16:39:04 - [10374874] --H-D- C:\Program Files\Movie Maker
O43 - CFD: 26/08/2010 - 10:16:40 - [25757] --H-D- C:\Program Files\MSBuild
O43 - CFD: 16/11/2006 - 16:29:20 - [0] --H-D- C:\Program Files\MSN
O43 - CFD: 16/11/2006 - 16:30:00 - [8745735] --H-D- C:\Program Files\MSN Gaming Zone
O43 - CFD: 30/11/2010 - 16:44:16 - [154033] --H-D- C:\Program Files\MSXML 4.0
O43 - CFD: 15/01/2009 - 12:10:38 - [3285523] --H-D- C:\Program Files\NetMeeting
O43 - CFD: 30/11/2010 - 17:10:06 - [237305106] --H-D- C:\Program Files\Nuance
O43 - CFD: 15/12/2010 - 17:29:38 - [4379321] --H-D- C:\Program Files\Outlook Express
O43 - CFD: 26/09/2007 - 10:32:00 - [45890] --H-D- C:\Program Files\POST IT
O43 - CFD: 22/09/2010 - 09:31:16 - [1142016] --H-D- C:\Program Files\POST-NET
O43 - CFD: 06/09/2011 - 09:13:20 - [75697179] --H-D- C:\Program Files\QuickTime
O43 - CFD: 26/08/2010 - 10:16:32 - [36400897] --H-D- C:\Program Files\Reference Assemblies
O43 - CFD: 16/09/2011 - 09:19:12 - [1772001] --H-D- C:\Program Files\RogueRemover FREE
O43 - CFD: 16/11/2006 - 16:34:32 - [1025] --H-D- C:\Program Files\Services en ligne
O43 - CFD: 16/11/2006 - 16:58:02 - [47539080] --H-D- C:\Program Files\SigmaTel
O43 - CFD: 14/09/2011 - 18:53:14 - [53804108] --H-D- C:\Program Files\Spybot - Search & Destroy
O43 - CFD: 20/09/2011 - 18:11:38 - [69107870] ----D- C:\Program Files\SUPERAntiSpyware
O43 - CFD: 21/09/2011 - 15:13:26 - [10408534] --H-D- C:\Program Files\Symantec
O43 - CFD: 21/09/2011 - 16:35:32 - [658557] ----D- C:\Program Files\Toolbar Cleaner
O43 - CFD: 22/09/2011 - 08:50:54 - [1585284] ----D- C:\Program Files\Toolbar Uninstaller
O43 - CFD: 16/11/2006 - 16:40:36 - [0] --H-D- C:\Program Files\Uninstall Information
O43 - CFD: 25/07/2011 - 12:29:38 - [4855597] --H-D- C:\Program Files\uTorrentBar_FR
O43 - CFD: 01/10/2010 - 10:07:36 - [139063786] --H-D- C:\Program Files\Windows Live
O43 - CFD: 16/02/2010 - 12:53:24 - [3600014] --H-D- C:\Program Files\Windows Media Connect 2
O43 - CFD: 01/10/2010 - 15:12:44 - [7512329] --H-D- C:\Program Files\Windows Media Player
O43 - CFD: 15/01/2009 - 12:10:34 - [3942655] --H-D- C:\Program Files\Windows NT
O43 - CFD: 16/11/2006 - 16:34:38 - [0] --H-D- C:\Program Files\WindowsUpdate
O43 - CFD: 16/11/2006 - 16:36:26 - [0] --H-D- C:\Program Files\xerox
O43 - CFD: 27/09/2011 - 11:13:20 - [6396226] ----D- C:\Program Files\ZHPDiag
O43 - CFD: 24/06/2009 - 11:01:10 - [9667173] --H-D- C:\Program Files\Fichiers Communs\Adobe
O43 - CFD: 18/10/2010 - 16:20:30 - [13287713] --H-D- C:\Program Files\Fichiers Communs\Aplogistique
O43 - CFD: 06/09/2011 - 09:29:10 - [102608648] --H-D- C:\Program Files\Fichiers Communs\Apple
O43 - CFD: 01/10/2010 - 10:48:28 - [86016] --H-D- C:\Program Files\Fichiers Communs\DESIGNER
O43 - CFD: 20/11/2006 - 13:19:14 - [270336] --H-D- C:\Program Files\Fichiers Communs\Hewlett-Packard
O43 - CFD: 07/02/2007 - 14:07:52 - [12400653] --H-D- C:\Program Files\Fichiers Communs\InstallShield
O43 - CFD: 25/07/2011 - 12:16:16 - [1228747] --H-D- C:\Program Files\Fichiers Communs\Java
O43 - CFD: 01/10/2010 - 10:49:10 - [114746918] --H-D- C:\Program Files\Fichiers Communs\Microsoft Shared
O43 - CFD: 16/11/2006 - 16:32:18 - [284160] --H-D- C:\Program Files\Fichiers Communs\MSSoap
O43 - CFD: 16/11/2006 - 17:19:56 - [0] --H-D- C:\Program Files\Fichiers Communs\ODBC
O43 - CFD: 30/11/2010 - 17:08:14 - [3483840] --H-D- C:\Program Files\Fichiers Communs\ScanSoft Shared
O43 - CFD: 16/11/2006 - 16:32:30 - [8106] --H-D- C:\Program Files\Fichiers Communs\Services
O43 - CFD: 16/11/2006 - 17:19:52 - [3787229] --H-D- C:\Program Files\Fichiers Communs\SpeechEngines
O43 - CFD: 20/11/2006 - 12:21:54 - [192512] --H-D- C:\Program Files\Fichiers Communs\SWF Studio
O43 - CFD: 01/10/2010 - 10:48:16 - [19947471] --H-D- C:\Program Files\Fichiers Communs\System
O43 - CFD: 17/09/2009 - 13:26:12 - [130308530] --H-D- C:\Program Files\Fichiers Communs\Windows Live
O43 - CFD: 26/09/2007 - 10:41:56 - [22855] --H-D- C:\Documents and Settings\station\Application Data\3M
O43 - CFD: 13/09/2011 - 09:25:20 - [52486105] --H-D- C:\Documents and Settings\station\Application Data\Adobe
O43 - CFD: 13/05/2008 - 10:35:46 - [82] --H-D- C:\Documents and Settings\station\Application Data\AdobeUM
O43 - CFD: 14/11/2007 - 18:25:24 - [0] --H-D- C:\Documents and Settings\station\Application Data\Ahead
O43 - CFD: 12/09/2011 - 14:53:58 - [1958932930] --H-D- C:\Documents and Settings\station\Application Data\Apple Computer
O43 - CFD: 25/07/2011 - 12:19:48 - [70] --H-D- C:\Documents and Settings\station\Application Data\AskToolbar
O43 - CFD: 26/02/2010 - 12:00:02 - [0] --H-D- C:\Documents and Settings\station\Application Data\Auslogics
O43 - CFD: 25/07/2011 - 12:28:56 - [2089] --H-D- C:\Documents and Settings\station\Application Data\Babylon
O43 - CFD: 30/11/2010 - 17:40:42 - [56] RSH-D- C:\Documents and Settings\station\Application Data\Brother
O43 - CFD: 30/11/2010 - 17:15:36 - [23391] --H-D- C:\Documents and Settings\station\Application Data\ControlCenter4
O43 - CFD: 16/11/2006 - 17:27:22 - [2560] --H-D- C:\Documents and Settings\station\Application Data\CyberLink
O43 - CFD: 02/11/2007 - 11:11:32 - [732] --H-D- C:\Documents and Settings\station\Application Data\EPSON
O43 - CFD: 30/11/2010 - 17:15:36 - [574] --H-D- C:\Documents and Settings\station\Application Data\FLEXnet
O43 - CFD: 14/01/2009 - 15:15:18 - [295606] --H-D- C:\Documents and Settings\station\Application Data\GameHouse
O43 - CFD: 14/11/2007 - 11:07:58 - [826] --H-D- C:\Documents and Settings\station\Application Data\Google
O43 - CFD: 21/05/2007 - 14:58:06 - [28186] --H-D- C:\Documents and Settings\station\Application Data\HARVEST S.A
O43 - CFD: 05/04/2007 - 09:57:20 - [0] --H-D- C:\Documents and Settings\station\Application Data\Help
O43 - CFD: 20/11/2006 - 13:31:04 - [151] --H-D- C:\Documents and Settings\station\Application Data\HP
O43 - CFD: 22/02/2011 - 10:32:10 - [7788] --H-D- C:\Documents and Settings\station\Application Data\Icones
O43 - CFD: 16/11/2006 - 16:40:38 - [0] --H-D- C:\Documents and Settings\station\Application Data\Identities
O43 - CFD: 30/11/2010 - 16:57:56 - [0] --H-D- C:\Documents and Settings\station\Application Data\InstallShield
O43 - CFD: 27/11/2006 - 17:39:40 - [1529087] --H-D- C:\Documents and Settings\station\Application Data\Macromedia
O43 - CFD: 01/04/2009 - 09:54:52 - [7941] --H-D- C:\Documents and Settings\station\Application Data\Malwarebytes
O43 - CFD: 16/02/2010 - 16:30:28 - [14798447] -S--D- C:\Documents and Settings\station\Application Data\Microsoft
O43 - CFD: 25/07/2011 - 12:18:40 - [0] --H-D- C:\Documents and Settings\station\Application Data\Mozilla
O43 - CFD: 30/11/2010 - 17:18:22 - [7113] --H-D- C:\Documents and Settings\station\Application Data\Nuance
O43 - CFD: 08/12/2010 - 09:38:18 - [174] --H-D- C:\Documents and Settings\station\Application Data\PC-FAX TX
O43 - CFD: 21/09/2011 - 14:45:30 - [1923880] --H-D- C:\Documents and Settings\station\Application Data\PriceGong
O43 - CFD: 12/05/2011 - 12:34:24 - [642149] --H-D- C:\Documents and Settings\station\Application Data\Reviversoft
O43 - CFD: 04/03/2009 - 11:22:02 - [2057135] --H-D- C:\Documents and Settings\station\Application Data\Skype
O43 - CFD: 02/03/2009 - 17:03:26 - [42384] --H-D- C:\Documents and Settings\station\Application Data\skypePM
O43 - CFD: 14/01/2009 - 15:25:34 - [923670] --H-D- C:\Documents and Settings\station\Application Data\Sun
O43 - CFD: 20/09/2011 - 18:11:38 - [4434743] ----D- C:\Documents and Settings\station\Application Data\SUPERAntiSpyware.com
O43 - CFD: 05/05/2009 - 15:20:44 - [0] --H-D- C:\Documents and Settings\station\Application Data\U3
O43 - CFD: 27/07/2011 - 09:51:58 - [8100] --H-D- C:\Documents and Settings\station\Application Data\uTorrent
O43 - CFD: 14/01/2009 - 15:18:44 - [93668] --H-D- C:\Documents and Settings\station\Application Data\Wildfire
O43 - CFD: 20/04/2010 - 15:12:32 - [0] --H-D- C:\Documents and Settings\station\Application Data\Windows Live Writer
O43 - CFD: 30/11/2010 - 17:18:34 - [5343] --H-D- C:\Documents and Settings\station\Application Data\Zeon
O43 - CFD: 24/09/2008 - 11:01:32 - [47907785] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Adobe
O43 - CFD: 15/05/2007 - 11:21:12 - [1950597] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Ahead
O43 - CFD: 04/12/2006 - 17:11:24 - [4858731] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\APLOGISTIQUE
O43 - CFD: 03/01/2011 - 16:14:04 - [0] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Apple
O43 - CFD: 03/01/2011 - 16:17:32 - [3011912] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Apple Computer
O43 - CFD: 30/09/2009 - 08:43:06 - [13042] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\ApplicationHistory
O43 - CFD: 25/07/2011 - 13:51:32 - [3078098] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\AskToolbar
O43 - CFD: 25/07/2011 - 12:28:56 - [3911963] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Babylon
O43 - CFD: 25/07/2011 - 12:29:36 - [209360] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Conduit
O43 - CFD: 19/09/2011 - 08:38:02 - [4915758] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\ConduitEngine
O43 - CFD: 14/09/2011 - 18:32:28 - [830316] --H-D- C:\Documents and Settings\station\Local Settings\Application Data\Google
O43 - CFD: 05/04/2007 - 09:57:20 - [0] --H-D- C:\Documents and Settings\st
0
Utilisateur anonyme
27 sept. 2011 à 17:09
* Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
* Héberge le rapport ZHPDiag.txt sur Cijoint, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum :
http://www.cijoint.fr/
ou :
http://dl.free.fr
ou :
http://ww38.toofiles.com/fr/documents-upload.html
ou :
https://www.terafiles.net/
0