Virus imitant la gendarmerie nationale

Laura - 15 déc. 2011 à 10:09
 Utilisateur anonyme - 15 déc. 2011 à 19:02

en allant regarder une série, mon ordi a été bloqué par ce fameux virus de la "gendarmerie".
Je voudrais bien évidemment m'en débarasser, le soucis est que je suis au niveau 0 (voire inférieur) en informatique et surtout que j'ai des documents très importants (pour mon travail) que je ne peux pas perdre.
Sachant que l'image est bloqué, je n'accède à rien, merci de m'aider s'il vous plait.
ps : j'ai bien lu les autres forums mais ne s'applique pas à mon cas :-/

Utilisateur anonyme
15 déc. 2011 à 10:16

Ton PC démarre t' il en mode sans echec avec prise en charge réseau?

Je n'ai aucune notion info :s désolée...
comment démarrer en mode sans échec ?
Utilisateur anonyme
15 déc. 2011 à 10:20
Tu suis le lien en bleu dans mon précédent post.

je n'avais pas vu le lien
à quel moment je dois appuyer sur f8 ? (j'ai vista)
alors j'ai appuyer sur f8 tout le long du démarrage et rien ne s'est passé
Utilisateur anonyme
15 déc. 2011 à 10:33

Prend le temps de lire cette astuce
"bios" je ne vois pas à quoi ça correspond...
parce que meme si j'avais appuyé trop tôt, l'ordi aurait affiché quelque chose mais là aucune réaction
à tous les niveaux, je suis perdue... :s
Utilisateur anonyme
15 déc. 2011 à 10:53

Tu postes à partir d'un autre PC?

A partir de ce dernier ;tu vas télécharger et graver un CDlive.

Télécharge OTLPENet sur le bureau.
Double clique ou clic droit sous Vista ou Seven pour lancer l'application.
On va te demander si tu veux graver ...
Prépare un CD vierge et lance OTLPENet, cela va te permettre de graver une image iso.
Note : Le CD gravé, il faut maintenant redémarrer la machine sur le lecteur CDROM
Pour se faire suivre ce lien : Booter sur un CD

Tu lances l'iso d'OTLPENet que tu as gravé.
* une fois le bureau de reatogo chargé , tu lances OTLPE , l'icône jaune

* Double-clique sur l'icone OTLPE
* quand demandé "Do you wish to load the remote registry", select Yes
* quand demandé "Do you wish to load remote user profile(s) for scanning", select Yes
* vérifier que "Automatically Load All Remaining Users" est sélectionné et press OK
* sous Custom Scan box
1) copie_colle le contenu du cadre ci dessous:

%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles

* copie colle ce texte dans un fichier texte|bloc note que tu enregistres sur clé usb que tu brancheras sous reatogo tu pourras alors facilement le copier\coller.

* 2) Clic Run Scan pour démarrer le scan.
* Une fois terminé , le fichier se trouve là C:\OTL.txt
* Copie_colle le contenu dans ta prochaine réponse.

Je fais cette manip sur un autre pc c'est bien ça ?
j'ai lancé OTLPENet, accueil, je fais quoi ?
Utilisateur anonyme
15 déc. 2011 à 11:29
Tu lis correctement mon précédent post.

Tu télécharges et ensuite tu graves et ensuite...

message à l'insertion de mon disque : "le disque que vous avez inséré est vierge. Insérer un autre disque dans le lecteur TSSTcorp DVDRW DL (E:)"
Utilisateur anonyme
15 déc. 2011 à 11:42

Es tu sur de l'avoir gravé?
Procède à un essai sur ce PC qui fonctionne ,tu seras fixé.

mais je suis déjà sur le pc qui fonctionne :s
il est vierge mais c'est bien ce qu'il fallait non ?!
j'essaie de comprendre mais...
Utilisateur anonyme
15 déc. 2011 à 11:47

Tu viens de mettre un disque vide;très bien ;-)

Maintenant tu procèdes a la gravure de ce CD


Utilisateur anonyme
15 déc. 2011 à 14:33

Choisis restaurer le système

Choisis bien une date antérieure à ton problème.

Tiens moi au courant;ce n'est pas fini...

mon pc s'est rallumé et pas de virus d'affiché !!! :) : ) :)
Utilisateur anonyme
15 déc. 2011 à 14:47

Super ;-)

Vérifions ce PC si tu veux bien.

Ouvre ce lien et télécharge ZHPDiag de Nicolas Coolman :


Serveur N°2

en bas de la page ZHP avec un numéro de version.

Une fois le téléchargement achevé, dé zippe le fichier obtenu et place ZHPDiag.exe sur ton Bureau.

Double-clique sur l'icône pour lancer le programme. Sous Vista ou Seven clic droit « exécuter en tant que administrateur »

Clique sur la loupe pour lancer l'analyse.

Laisse l'outil travailler, il peut être assez long.

Ferme ZHPDiag en fin d'analyse.

Pour transmettre le rapport clique sur ce lien :

Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).

Sélectionne le fichier ZHPDiag.txt.

Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

est ajouté dans la page.

Copie ce lien dans ta réponse.


ouhla je pense que je suis de retour dans une demie-heure avec tout ça (rires)
je n'ai plus d'antivirus depuis quelques temps donc ça ne doit pas être joli :-/
Utilisateur anonyme
15 déc. 2011 à 14:54
On verra ça à ton retour ;-)
l'analyse est terminée mais je ne comprends pas ce que je dois faire ensuite
Utilisateur anonyme
15 déc. 2011 à 15:20

Il suffit de lire:

Pour transmettre le rapport clique sur ce lien :

Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).

Sélectionne le fichier ZHPDiag.txt.

Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

est ajouté dans la page.

Copie ce lien dans ta réponse.

il y a plusieurs lignes qui correspondent... j'ai pris celle dite "légitime"
Utilisateur anonyme
15 déc. 2011 à 15:28
Tu postes le rapport en entier;merci
Utilisateur anonyme
15 déc. 2011 à 15:33
Tu l'a mis sur quel lien demandé?
voila la liste qui peut correspondre :

PROGRAMDIR\ZHPDIAG2.EXE 20 64b3802e26149


PROGRAMDIR\ZHPDIAGE\ZHPDIAG.EXE 4 ZHPDiag_m9v6e7c6s14p9m12w12e5o15g5v11r15v11b13v10d


ProgramDir\zhpdiag\zhpdiag.exe 14846 ZHPDiag_s13w8o9w7z12l5t10z12j6c8k8c15g15m10l9n8d13


PROGRAMDIR\ZHPDIAG\ZHPDIAG\ZHPDIAG.EXE 22 ZHPDiag_n8p8f10g12f7t6x57u13g6d5j13s14t15c1210m14u

PROGRAMDIR\ZHPDIAG\ZHPFIX.EXE 263 ZHPDiag_l5y15z12k6p15x9k14g13s5e15e9v7y11u5n12m10e

Utilisateur anonyme
15 déc. 2011 à 15:41
Ce rapport ZHPDiag.txt.

tu le mets sur un de ces sites en procédant comme cela:

Pour transmettre le rapport clique sur ce lien :
Sélectionne le fichier ZHPDiag.txt.

Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

est ajouté dans la page.

Copie ce lien dans ta réponse.

C'est simple,non?

oui c'est simple, à l'exception du fait que je ne trouve pas ce fameux fichier
j'ai la liste précédemment écrite
Utilisateur anonyme
15 déc. 2011 à 15:47
sur ton bureau peut être?
Lance une recherche sur ton PC.

Rapport de ZHPDiag v1.28.266 par Nicolas Coolman, Update du 12/12/2011
Run by LAURA at 15/12/2011 15:07:41
Web site :
State : Version à jour.

---\\ Web Browser
MSIE: Internet Explorer v7.0.6001.18000 (Defaut)
MFIE: Mozilla Firefox 8.0.1 v8.0.1
GCIE: Google Chrome v15.0.874.121

---\\ Windows Product Information
~ Langage: Français
Windows Vista Home Premium Edition, 64-bit Service Pack 1 (Build 6001)
Windows Server License Manager Script : OK
~ Vista, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : RJ34F
Windows License : OK
Windows Automatic Updates : OK

---\\ System Information
~ Processor: Intel64 Family 6 Model 23 Stepping 6, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 4059 MB (50% free)
System Restore: Activé (Enable)
System drive C: has 60 GB (25%) free of 233 GB

---\\ Logged in mode
~ Computer Name: PC-DE-LAURA
~ User Name: LAURA
~ All Users Names: LAURA, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O82,O89
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\LAURA\AppData\Roaming\
~ %Desktop% : C:\Users\LAURA\Desktop\
~ %Favorites% : C:\Users\LAURA\Favorites\
~ %LocalAppData% : C:\Users\LAURA\AppData\Local\
~ %StartMenu% : C:\Users\LAURA\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\system32\

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 60 Go of 233 Go)
E:\ Hard drive, Flash drive, Thumb drive (Free 217 Go of 231 Go)
F:\ CD-ROM drive (Not Inserted)

---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyComputer: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Scan Security Center in 00mn 00s

---\\ Recherche particulière de fichiers génériques
[MD5.BBD8E74F23D7605CB0CDB57A1B25D826] - (.Microsoft Corporation - Explorateur Windows.) (.05/06/2009 - 07:49:22.) -- C:\Windows\Explorer.exe [3080704]
[MD5.10446646D128E580C46615338E74E672] - (....) (.02/11/2006 - 12:16:05.) -- C:\Windows\system32\rundll32.exe [46592]
[MD5.117EA87DF785CA1B9D821F6F213DCE07] - (.Microsoft Corporation - Application de démarrage de Windows.) (.21/01/2008 - 03:50:23.) -- C:\Windows\system32\Wininit.exe [123904]
[MD5.6010EE8354DE6249041CDDD6ADAC4C01] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.11/02/2011 - 17:08:20.) -- C:\Windows\system32\wininet.dll [1032704]
[MD5.856491FCED98093D824B9EB2892F564A] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.21/01/2008 - 03:49:47.) -- C:\Windows\system32\Winlogon.exe [406016]
[MD5.7C42D832F43C74A707E11AA6BB53F6D2] - (....) (.21/01/2008 - 10:54:41.) -- C:\Windows\system32\fr-FR\user32.dll.mui [19968]
[MD5.DB37041AB857ABC7E179E856D8E1582C] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.21/01/2008 - 03:48:18.) -- C:\Windows\system32\drivers\AFD.sys [408064]
[MD5.B388797CAAB36D523840347CC6A39B96] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.05/06/2009 - 05:12:37.) -- C:\Windows\system32\drivers\atapi.sys [22584]
[MD5.B4D787DB8D30793A4D4DF9FEED18F136] - (.Microsoft Corporation - CD-ROM File System Driver.) (.21/01/2008 - 03:50:39.) -- C:\Windows\system32\drivers\Cdfs.sys [90624]
[MD5.3B2FB35363423ED60C8FBF15FC8680BD] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/01/2008 - 03:46:54.) -- C:\Windows\system32\drivers\Cdrom.sys [79872]
[MD5.BD4ACC56E477AD7419CBE90FCEEB621B] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/01/2008 - 03:49:58.) -- C:\Windows\system32\drivers\DfsC.sys [97792]
[MD5.0C0D0F8A3FF09ECC81963D09EC6A0A84] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/01/2008 - 03:46:51.) -- C:\Windows\system32\drivers\HDAudBus.sys [50688]
[MD5.CBB597659A2713CE0C9CC20C88C7591F] - (.Microsoft Corporation - Pilote de port i8042.) (.21/01/2008 - 03:47:27.) -- C:\Windows\system32\drivers\i8042prt.sys [64000]
[MD5.B7E6212F581EA5F6AB0C3A6CEEEB89BE] - (.Microsoft Corporation - IP Network Address Translator.) (.21/01/2008 - 03:48:45.) -- C:\Windows\system32\drivers\IpNat.sys [115712]
[MD5.937512D4321B4F5218AD5A0AEBF2B5CC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.19/04/2010 - 12:46:43.) -- C:\Windows\system32\drivers\MRxSmb.sys [135168]
[MD5.7A29CA243A629230799754162D80120F] - (.Microsoft Corporation - MBT Transport driver.) (.21/01/2008 - 03:50:11.) -- C:\Windows\system32\drivers\netBT.sys [250368]
[MD5.FE86BA5AC3B50E2CA911E9C60C07B638] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.21/01/2008 - 03:50:39.) -- C:\Windows\system32\drivers\ntfs.sys [1540152]
[MD5.AECD57F94C887F58919F307C35498EA0] - (.Microsoft Corporation - Pilote de port parallèle.) (.02/11/2006 - 10:37:57.) -- C:\Windows\system32\drivers\Parport.sys [96768]
[MD5.3B9085F91EF00ABD15A6F36570E90E12] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/01/2008 - 03:49:59.) -- C:\Windows\system32\drivers\Rasl2tp.sys [124928]
[MD5.C045D1FB111C28DF0D1BE8D4BDA22C06] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.21/01/2008 - 03:46:51.) -- C:\Windows\system32\drivers\rdpdr.sys [314368]
[MD5.41EB2E8E005FEEDCAFCE301983EFF932] - (.Microsoft Corporation - SMB Transport driver.) (.21/01/2008 - 03:50:11.) -- C:\Windows\system32\drivers\smb.sys [88064]
[MD5.8C39C72E0E853DE04748C0337D9B9216] - (.Microsoft Corporation - TDI Translation Driver.) (.21/01/2008 - 03:49:53.) -- C:\Windows\system32\drivers\tdx.sys [94208]
[MD5.DE4307412D98050239026E56A7DFF3C0] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/01/2008 - 03:47:03.) -- C:\Windows\system32\drivers\volsnap.sys [271416]
~ Scan Generic Processes in 00mn 00s

---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 8/1507
~ Mes musiques (My Musics) : 85/338
~ Mes Videos (My Videos) : 1/4
~ Mes Favoris (My Favorites) : 2/27
~ Mes Documents (My Documents) : 5/10980
~ Mon Bureau (My Desktop) : 2/554
~ Menu demarrer (Programs) : 6/22
~ Scan Hidden Files in 00mn 13s

---\\ Processus lancés
[MD5.89F7C30A91E5581BDF14C62AB46A2B2D] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [255536] [PID.3700]
[MD5.C5B2679B0AE204FDD0415199B7AFEF20] - (.TOSHIBA CORPORATION - KeNotify MFC Application.) -- C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe [34088] [PID.3916]
[MD5.B98FFA8288EFAABC436C30D198608345] - (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre6\bin\jusched.exe [136600] [PID.3964]
[MD5.C08EEB50B0CA00F7D272AE94B1531F7D] - (.TOSHIBA - Pas de description.) -- C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCamera.exe [2513472] [PID.3504]
[MD5.884E15C0CBF4DB145FD1F7FB790A9799] - (.TOSHIBA Corporation - TRCMan.exe.) -- C:\Program Files (x86)\Toshiba\TRCMan\TRCMan.exe [701752] [PID.1612]
[MD5.E09B922FB422AEFD1493E0657669BD8B] - (.TOSHIBA CORPORATION - ConfigFree Task Tray Menu.) -- C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe [299008] [PID.3144]
[MD5.F1802594C34904C57A33E0C759AEE056] - (.ALWIL Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2743104] [PID.4104]
[MD5.3249EB15DFC4E07E6971C666E3711D18] - (.France Telecom SA - Pas de description.) -- C:\Program Files (x86)\OrangeHSS\Launcher\Launcher.exe [602864] [PID.4224]
[MD5.DDACBCA1D0E66BBA5C984842F372A6D4] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [421160] [PID.4252]
[MD5.66C25F8876357948D480FD7625A8B84E] - (.France Telecom SA - Pas de description.) -- C:\PROGRA~2\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe [90112] [PID.4124]
[MD5.EFEF12A9393C54BCD9D31AFEBB7FDB83] - (.TOSHIBA CORPORATION - ConfigFree Switch Manager Process.) -- C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe [62848] [PID.4152]
[MD5.6F74DB36565B470BB734ACD5C03CDBBA] - (.TOSHIBA Corporation. - SoundChanger.exe.) -- C:\Program Files\TOSHIBA\HDMICtrlMan\HCMSoundChanger.exe [700416] [PID.1500]
[MD5.DBE1C76A41A7420277E41EABB15A7BFE] - (.France Telecom SA - Pas de description.) -- C:\Program Files (x86)\OrangeHSS\systray\systrayapp.exe [147456] [PID.4876]
[MD5.FDBDE019EEA70B33B891DBE2A1E33BDD] - (...) -- C:\Program Files (x86)\OrangeHSS\Deskboard\deskboard.exe [1040384] [PID.3176]
[MD5.A4C96A5BD0FF75926EF09873764187BD] - (.France Telecom SA - Pas de description.) -- C:\Program Files (x86)\OrangeHSS\connectivity\connectivitymanager.exe [712704] [PID.4948]
[MD5.E57908F55D26E60F929DA530FE4FFAB0] - (.France Telecom SA - Pas de description.) -- C:\Program Files (x86)\OrangeHSS\connectivity\CoreCom\CoreCom.exe [364544] [PID.4996]
[MD5.823FD44EB11A91578923D0F0702D75B8] - (.France Telecom SA - Pas de description.) -- C:\Program Files (x86)\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe [28672] [PID.4660]
[MD5.261359D05A7FBF6E87335675AD902D47] - (.France Telecom SA - Pas de description.) -- C:\PROGRA~2\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe [65536] [PID.1328]
[MD5.5B2E1C16A2C420F60CD391B666003F14] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEUser.exe [299520] [PID.3408]
[MD5.B0636722344F5D0A65331ED12CE5E2E3] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe [307376] [PID.5076]
[MD5.4319F2A5C725D9E0B9E01744E02D32BE] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe [634648] [PID.6020]
[MD5.BB646927C878EF8B966ED168D4C712AE] - (.Adobe Systems, Inc. - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10w_ActiveX.exe [243360] [PID.5804]
[MD5.9DE46C958C1E7D398040345380AB8B4C] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [2210304] [PID.6808]
[MD5.8AAA93CD13E379EB76FBEF56AC77D4D4] - (.ALWIL Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384] [PID.]
[MD5.70D7BE78061126DD0C3ACCDB7E129017] - (.Apple Inc. - Apple Mobile Device Service.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [144672] [PID.]
[MD5.673CF4F6BB1FBE09331B526802FBB892] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe [345376] [PID.]
[MD5.F1140ED3A1E1D6824A63F27AFD9EEF32] - (.TOSHIBA - Pas de description.) -- C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe [20544] [PID.]
[MD5.BCF2C3177E4777E3793310BAC0244C1A] - (.TOSHIBA CORPORATION - ConfigFree Gadget Process Service.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [36864] [PID.]
[MD5.CAB0EEAF5295FC96DDD3E19DCE27E131] - (.TOSHIBA CORPORATION - ConfigFree Service Process.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [46448] [PID.]
[MD5.20DFB4BD5DE8585FDDA02F4C9D00308C] - (.France Telecom SA - Pas de description.) -- C:\PROGRA~2\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [65536] [PID.]
[MD5.22BC804EFE155F54252F389B0781D7F2] - (.TOSHIBA Corporation - TOSHIBA Navi Support Service.) -- C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe [83312] [PID.]
~ Scan Processes Running in 00mn 00s

---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\LAURA\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default] None
G0 - GCSP: Preference [User Data\Default][HomePage]
~ Scan Google Browser in 00mn 00s

---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: (no name) [64Bits] - {08C06D61-F1F3-4799-86F8-BE1A89362C85} . (...) (No version) -- (.not file.)
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2
~ Scan IE Browser in 00mn 00s

---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s

---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s

---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s

---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
O2 - BHO: Google Toolbar Notifier BHO [64Bits] - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll
O2 - BHO: AcroIEHelperStub [64Bits] - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) [64Bits] - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin
O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO [64Bits] - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
~ Scan BHO in 00mn 00s

---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Google Toolbar [64Bits] - {2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
~ Scan Toolbar in 00mn 00s

---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [Windows Defender] . (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\Run: [Skytel] . (.Realtek Semiconductor Corp. - Realtek Voice Manager.) -- C:\Program Files\Realtek\Audio\HDA\SkyTel.exe
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SmartFaceVWatcher] . (.TOSHIBA Corporation - SmartFaceVWatcher.) -- C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
O4 - HKLM\..\Run: [TosSENotify] . (.TOSHIBA Corporation - TosSENotify.exe.mui.) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
O4 - HKLM\..\Run: [SmoothView] . (.TOSHIBA Corporation - SmoothView.) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [TPwrMain] . (.TOSHIBA Corporation - TOSHIBA Power Saver.) -- C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
O4 - HKLM\..\Run: [HSON] . (.TOSHIBA Corporation - HotStartOn.) -- C:\Program Files\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [00TCrdMain] . (.TOSHIBA Corporation - TOSHIBA Flash Cards.) -- C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [ThpSrv] Clé orpheline
O4 - HKLM\..\Run: [Teco] . (.TOSHIBA Corporation - TOSHIBA eco Utility.) -- C:\Program Files\TOSHIBA\TECO\Teco.exe
O4 - HKLM\..\Run: [HDMICtrlMan] . (.TOSHIBA Corporation. - HDMICtrlMan.exe.) -- C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
O4 - HKLM\..\Run: [TPCHWMsg] . (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) -- C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
O4 - HKLM\..\Run: [Toshiba Registration] . (.Toshiba Europe GmbH - Toshiba Notebook Registration Reminder.) -- C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe
O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKLM\..\Wow6432Node\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [TUSBSleepChargeSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
O4 - HKLM\..\Wow6432Node\Run: [HWSetup] . (.TOSHIBA Electronics, Inc. - HWSetup.) -- C:\Program Files\TOSHIBA\Utilities\HWSetup.exe
O4 - HKLM\..\Wow6432Node\Run: [SVPWUTIL] . (.TOSHIBA - SVPWUTIL Application.) -- C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe
O4 - HKLM\..\Wow6432Node\Run: [KeNotify] . (.TOSHIBA CORPORATION - KeNotify MFC Application.) -- C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Wow6432Node\Run: [TWebCamera] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Wow6432Node\Run: [ToshibaServiceStation] Clé orpheline
O4 - HKLM\..\Wow6432Node\Run: [TRCMan] . (.TOSHIBA Corporation - TRCMan.exe.) -- C:\Program Files (x86)\Toshiba\TRCMan\TRCMan.exe
O4 - HKLM\..\Wow6432Node\Run: [NDSTray.exe] . (.TOSHIBA CORPORATION - ConfigFree Task Tray Menu.) -- C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe
O4 - HKLM\..\Wow6432Node\Run: [cfFncEnabler.exe] . (.Toshiba Corporation - cfFncEnabler.) -- C:\Program Files (x86)\Toshiba\ConfigFree\cfFncEnabler.exe
O4 - HKLM\..\Wow6432Node\Run: [avast5] . (.ALWIL Software - avast! Antivirus.) -- C:\Program Files\ALWILS~1\Avast5\avastUI.exe
O4 - HKLM\..\Wow6432Node\Run: [ORAHSSSessionManager] . (.France Telecom SA - Pas de description.) -- C:\Program Files (x86)\OrangeHSS\SessionManager\SessionManager.exe
O4 - HKLM\..\Wow6432Node\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] . (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files (x86)\Toshiba\Toshiba Online Product Information\TOPI.exe
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] . (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files (x86)\Toshiba\Toshiba Online Product Information\TOPI.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-21-2380837334-1416610126-997751992-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe
O4 - HKUS\S-1-5-21-2380837334-1416610126-997751992-1000\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
~ Scan Application in 00mn 00s

---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Users\LAURA\Desktop\Installation du Contrôle Parental.lnk . (.InstallShield Software Corporation.) -- C:\Program Files (x86)\Securitoo\Contrôle Parental\securitoo_controle_parental.exe
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk . (.Google Inc..) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Users\LAURA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
~ Scan Global Startup in 00mn 00s

---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - (.not file.) - C:\Windows\system32\GPhotos.scr
O8 - Extra context menu item: E&xporter vers Microsoft Excel - (.not file.) - C:\Program Files\MICROS~2\Office12\EXCEL.exe
~ Scan IE Menu Contextuel in 00mn 00s

---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll
~ Scan Winsock in 00mn 00s

---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
O15 - Trusted Zone: [HKCU\...\Domains]
O15 - Trusted Zone: [HKCU\...\Domains\www]
O15 - Trusted Zone: [HKCU\...\Domains]
O15 - Trusted Zone: [HKCU\...\Domains\www]
~ Scan IE Zone Confiance in 00mn 00s

---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D0C214C-F575-462B-9245-E1A89990D262}: DhcpNameServer =
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D0C214C-F575-462B-9245-E1A89990D262}: DhcpNameServer =
O17 - HKLM\System\CS2\Services\Tcpip\..\{0D0C214C-F575-462B-9245-E1A89990D262}: DhcpNameServer =
O17 - HKLM\System\CS3\Services\Tcpip\..\{0D0C214C-F575-462B-9245-E1A89990D262}: DhcpNameServer =
~ Scan Domain in 00mn 00s

---\\ Protocole additionnel (O18)
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: livecall [64Bits] - {828030A1-22C1-4009-854F-8E305202313F} . (...) --
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (...) --
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: ms-itss [64Bits] - {0A9007C0-4076-11D3-8789-0000F8105754} . (...) --
O18 - Handler: msnim [64Bits] - {828030A1-22C1-4009-854F-8E305202313F} . (...) --
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
O18 - Filter: deflate [64Bits] - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Filter: gzip [64Bits] - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
~ Scan Protocole Additionnel in 00mn 00s

---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\System32\webcheck.dll
~ Scan SSODL in 00mn 00s

---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: Component Categories cache daemon [64Bits] - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll
~ Scan STS/SSO in 00mn 00s

---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus (avast! Antivirus) . (.ALWIL Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: TOSHIBA Web Camera Service (camsvc) . (.TOSHIBA - Pas de description.) - C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe
O23 - Service: ConfigFree Gadget Service (ConfigFree Gadget Service) . (.TOSHIBA CORPORATION - ConfigFree Gadget Process Service.) - C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe
O23 - Service: ConfigFree Service (ConfigFree Service) . (.TOSHIBA CORPORATION - ConfigFree Service Process.) - C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) . (.France Telecom SA - Pas de description.) - C:\Program Files (x86)\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) . (.TOSHIBA Corporation - TOSHIBA HDD Protection Service.) - C:\Windows\system32\ThpSrv.exe
O23 - Service: TMachInfo (TMachInfo) . (.TOSHIBA Corporation - TSS TMachInfo Service.) - C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) . (.TOSHIBA Corporation - TOSHIBA Navi Support Service.) - C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation - TDCSrv Application.) - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) . (.TOSHIBA Corporation - TOSHIBA Power Saver.) - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service (TOSHIBA Bluetooth Service) . (...) - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (.not file.)
O23 - Service: TOSHIBA eco Utility Service (TOSHIBA eco Utility Service) . (.TOSHIBA Corporation - TOSHIBA eco Utility Service.) - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: Service TOSHIBA HDD SSD Alert (TOSHIBA HDD SSD Alert Service) . (.TOSHIBA Corporation - TosSmartSrv.exe.) - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) . (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
~ Scan Services in 00mn 00s

---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s

---\\ BootExecute (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ Scan Keys in 00mn 00s

---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[MD5.8F0DE4FEF8201E306F9938B0905AC96A] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.8F0DE4FEF8201E306F9938B0905AC96A] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.187E0D2AB859AD03393DDD731076BE81] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
~ Scan Scheduled Task in 00mn 03s

---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitaire d'installation du Lecteur Windows Media de Microsoft.) -- C:\Windows\system32\unregmp2.exe
O40 - ASIC: Internet Explorer [64Bits] - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe
O40 - ASIC: Browser Customizations [64Bits] - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - Personnalisation d'IEAK.) -- C:\Windows\system32\iedkcs32.dll
O40 - ASIC: Microsoft Windows Media Player 11.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\system32\wmp.dll
O40 - ASIC: Internet Explorer [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Scan Active Setup in 00mn 00s

---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\system32\Drivers\dfsc.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\system32\DRIVERS\i8042prt.sys
O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\system32\DRIVERS\kbdclass.sys
O41 - Driver: (kbdhid) . (.Microsoft Corporation - Pilote de filtre clavier HID.) - C:\Windows\system32\DRIVERS\kbdhid.sys
O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\system32\DRIVERS\mouclass.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\system32\DRIVERS\netbios.sys
O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\system32\DRIVERS\netbt.sys
O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\system32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\system32\DRIVERS\rasacd.sys
O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\system32\DRIVERS\smb.sys
O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Tcpip) . (.Microsoft Corporation - TCP/IP Driver.) - C:\Windows\system32\drivers\tcpip.sys
O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\system32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys
~ Scan Drivers in 00mn 00s

---\\ Logiciels installés (O42)
O42 - Logiciel: Activation Assistant for the 2007 Microsoft Office suites - (.Microsoft Corporation.) [HKLM] -- Activation Assistant for the 2007 Microsoft Office suites
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Reader 9 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A90000000001}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {DAEAFD68-BB4A-4507-A241-C8804D2EA66D}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {33EB1061-ABF1-4470-A540-32E97A610536}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {C41300B9-185D-475E-BFEC-39EF732F19B1}
O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
O42 - Logiciel: Bluetooth Stack for Windows by Toshiba - (.TOSHIBA CORPORATION.) [HKLM] -- {CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {41BF0DE4-5BAE-4B88-AFD3-86A30B222186}
O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {3D0DC563-4C99-4AB1-8C22-514940666938}
O42 - Logiciel: ENE CIR Receiver Driver - (.ENE.) [HKLM] -- 703AB19C282B6ED3F1D3CE92F8DAA864B68A7C91
O42 - Logiciel: EPSON Logiciel imprimante - (.Pas de propriétaire.) [HKLM] -- EPSON Printer and Utilities
O42 - Logiciel: EPSON Scan - (.Pas de propriétaire.) [HKLM] -- EPSON Scanner
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {18455581-E099-4BA8-BC6B-F34B2F06600C}
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}
O42 - Logiciel: HDMI Control Manager - (.TOSHIBA.) [HKLM] -- InstallShield_{63DA1F6A-2E65-4367-99B9-9E39FADEC446}
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}
O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}
O42 - Logiciel: JMicron Flash Media Controller Driver - (.JMicron Technology Corp..) [HKLM] -- {26604C7E-A313-4D12-867F-7C6E7820BE4C}
O42 - Logiciel: Java(TM) 6 Update 11 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF}
O42 - Logiciel: Jeux WildTangent - (.WildTangent.) [HKLM] -- WildTangent toshiba Master Uninstall
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
O42 - Logiciel: MSXML 4.0 SP2 (KB941833) - (.Microsoft Corporation.) [HKLM] -- {C523D256-313D-4866-B36A-F3DE528246EF}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Manuels TOSHIBA - (.TOSHIBA.) [HKLM] -- {5B0202A8-CC6B-4443-AD73-FE9DF1FC1622}
O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM] -- McAfee Security Scan
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
O42 - Logiciel: Microsoft Office 2000 CD-ROM 2 - (.Microsoft Corporation.) [HKLM] -- {0004040C-78E1-11D2-B60F-006097C998E7}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-002A-040C-1000-0000000FF1CE}_HOMESTUDENTR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_HOMESTUDENTR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-00A1-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Home and Student 2007 - (.Microsoft Corporation.) [HKLM] -- HOMESTUDENTR
O42 - Logiciel: Microsoft Office Home and Student 2007 - (.Microsoft Corporation.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Office 64-bit Components 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002A-0000-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office OneNote MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-00A1-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint Viewer 2007 (French) - (.Microsoft Corporation.) [HKLM] -- {95120000-00AF-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_HOMESTUDENTR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002A-040C-1000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {B6E3757B-5E77-3915-866A-CCFC4B8D194C}
O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable (x64) - (.Microsoft Corporation.) [HKLM] -- {071c9b48-7c32-4621-a0ac-3f809523288f}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {3B160861-7250-451E-B5EE-8B92BF30A710}
O42 - Logiciel: Module de compatibilité pour Microsoft Office System 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-040C-0000-0000000FF1CE}
O42 - Logiciel: Mozilla Firefox 8.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 8.0.1 (x86 fr)
O42 - Logiciel: Orange - Logiciels Internet - (.Pas de propriétaire.) [HKLM] -- {ORAHSS}.UninstallSuite
O42 - Logiciel: Orange WebTV Player 1.29418 - (.Orange.) [HKLM] -- Orange WebTV Player_is1
O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3
O42 - Logiciel: PlayReady PC runtime - (.Microsoft Corporation.) [HKLM] -- {704ABF63-B0B1-446B-9D92-C5D06AFCE7B6}
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {EB900AF8-CC61-4E15-871B-98D1EA3E8025}
O42 - Logiciel: Realtek 8136 8168 8169 Ethernet Driver - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: ResultBar 1.0 build 115 - (.Pas de propriétaire.) [HKLM] -- ResultBar
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{5C497F0B-2061-4CC9-A61C-6B45B867354D}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CD769337-C8AC-46DB-A7DC-643E50089263}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{536FB502-775F-4494-BACE-C02CC90B7A5B}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2466156) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CEF209AB-F96D-404F-B5CC-44057C057CA3}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2509488) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{AD0DE453-0804-4495-9C91-33D0F9AA5463}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{7F207DCA-3399-40CB-A968-6E5991B1421A}
O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2464583) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{151E2FEA-C3A6-4CB6-BE6B-16651FDF04BE}
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2464594) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E6B7C11E-21E9-4BA0-9677-29AD603B953C}
O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: TOSHIBA ConfigFree - (.TOSHIBA Corporation.) [HKLM] -- {F0A386D2-6E15-4A8F-A04E-87CE9BED0D48}
O42 - Logiciel: TOSHIBA DVD PLAYER - (.TOSHIBA Corporation.) [HKLM] -- {6C5F3BDC-0A1B-4436-A696-5939629D5C31}
O42 - Logiciel: TOSHIBA Disc Creator - (.TOSHIBA Corporation.) [HKLM] -- {5DA0E02F-970B-424B-BF41-513A5018E4C0}
O42 - Logiciel: TOSHIBA Extended Tiles for Windows Mobility Center - (.Pas de propriétaire.) [HKLM] -- InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}
O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM] -- InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}
O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM] -- {F67FA545-D8E5-4209-86B1-AEE045D1003F}
O42 - Logiciel: TOSHIBA Flash Cards Support Utility - (.TOSHIBA CORPORATION.) [HKLM] -- InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}
O42 - Logiciel: TOSHIBA Flash Cards Support Utility - (.TOSHIBA CORPORATION.) [HKLM] -- {620BBA5E-F848-4D56-8BDA-584E44584C5E}
O42 - Logiciel: TOSHIBA HDD Protection - (.TOSHIBA Corporation.) [HKLM] -- {94A90C69-71C1-470A-88F5-AA47ECC96B40}
O42 - Logiciel: TOSHIBA HDD/SSD Alert - (.TOSHIBA Corporation.) [HKLM] -- InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}
O42 - Logiciel: TOSHIBA HDD/SSD Alert - (.TOSHIBA Corporation.) [HKLM] -- {D4322448-B6AF-4316-B859-D8A0E84DCB38}
O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA CORPORATION.) [HKLM] -- InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}
O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA CORPORATION.) [HKLM] -- {5279374D-87FE-4879-9385-F17278EBB9D3}
O42 - Logiciel: TOSHIBA Mot de passe responsable - (.TOSHIBA CORPORATION.) [HKLM] -- InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}
O42 - Logiciel: TOSHIBA PC Health Monitor - (.TOSHIBA Corporation.) [HKLM] -- {9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}
O42 - Logiciel: TOSHIBA Recovery Disc Creator - (.TOSHIBA.) [HKLM] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}
O42 - Logiciel: TOSHIBA Recovery Disk Creator Reminder - (.TOSHIBA.) [HKLM] -- InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}
O42 - Logiciel: TOSHIBA Remote Control Manager - (.TOSHIBA.) [HKLM] -- {FEB650EB-7639-444E-9FC2-C33EE6ED1A37}
O42 - Logiciel: TOSHIBA SD Memory Utilities - (.TOSHIBA.) [HKLM] -- {EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}
O42 - Logiciel: TOSHIBA Service Station - (.TOSHIBA.) [HKLM] -- {AC6569FA-6919-442A-8552-073BE69E247A}
O42 - Logiciel: TOSHIBA Supervisor Password - (.TOSHIBA CORPORATION.) [HKLM] -- {51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}
O42 - Logiciel: TOSHIBA USB Sleep and Charge Utility - (.TOSHIBA Corporation.) [HKLM] -- {E487EE7D-EAAA-4E2A-9116-E3B477D8A74F}
O42 - Logiciel: TOSHIBA Value Added Package - (.TOSHIBA Corporation.) [HKLM] -- InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}
O42 - Logiciel: TOSHIBA Web Camera Application - (.TOSHIBA Corporation.) [HKLM] -- {5E6F6CF3-BACC-4144-868C-E14622C658F3}
O42 - Logiciel: TOSHIBA eco Utility - (.TOSHIBA Corporation.) [HKLM] -- InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}
O42 - Logiciel: TOSHIBA eco Utility - (.TOSHIBA Corporation.) [HKLM] -- {B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}
O42 - Logiciel: TRORDCLauncher - (.TOSHIBA.) [HKLM] -- InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}
O42 - Logiciel: Toshiba Assist - (.TOSHIBA.) [HKLM] -- {1B87C40B-A60B-4EF3-9A68-706CF4B69978}
O42 - Logiciel: Toshiba Online Product Information - (.TOSHIBA.) [HKLM] -- {2290A680-4083-410A-ADCC-7092C67FC052}
O42 - Logiciel: Téléphone sur PC 1.0.2 - (.France Telecom R&D.) [HKLM] -- Téléphone sur PC
O42 - Logiciel: Update for 2007 Microsoft Office System (KB2284654) - (.Microsoft.) [HKLM] -- {90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{FB166E7C-8AA6-48C8-B726-1F25BEE7825A}
O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
O42 - Logiciel: Update for Microsoft Office 2007 (KB2508958) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}
O42 - Logiciel: Update for Microsoft Office OneNote 2007 (KB980729) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{329050A9-EF80-40F9-B633-74508F54C1FF}
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {ED00D08A-3C5F-488D-93A0-A04F21F23956}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}
O42 - Logiciel: avast! Free Antivirus - (.Alwil Software.) [HKLM] -- avast5
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {5F02C14D-A630-4771-8409-0BA89FCCA8D6}
O42 - Logiciel: myphotobook 3.65 - (.myphotobook.) [HKLM] -- myphotobook

---\\ HKCU & HKLM Software Keys
[HKCU\Software\ALWIL Software]
Utilisateur anonyme
15 déc. 2011 à 15:58

Le rapport n'est pas complet.

Un petit effort...
Fait ce qu'il t'est demandée;merci

je ne trouve pas comment faire
Utilisateur anonyme
15 déc. 2011 à 16:08
Ce rapport ZHPDiag.txt est situé ou sur ton PC?

Je ne te demande pas de l'ouvrir
la suite :

---\\ HKCU & HKLM Software Keys
[HKCU\Software\ALWIL Software]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Farm Mania]
[HKCU\Software\IM Providers]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKLM\Software\ALWIL Software]
[HKLM\Software\ATI Technologies]
[HKLM\Software\America Online]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\GEAR Software]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\SRS Labs]
[HKLM\Software\TOSHIBA Corporation]
[HKLM\Software\Waves Audio]
~ Scan Softwares in 00mn 00s

---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 22/01/2010 - 21:11:16 - [121,843] ----D- C:\Program Files\Alwil Software
O43 - CFD: 05/09/2009 - 15:38:40 - [18,106] ----D- C:\Program Files\ATI
O43 - CFD: 19/09/2010 - 19:32:52 - [0,187] ----D- C:\Program Files\Bonjour
O43 - CFD: 19/09/2010 - 19:33:02 - [213,029] ----D- C:\Program Files\Common Files
O43 - CFD: 05/09/2009 - 15:51:10 - [0,887] ----D- C:\Program Files\DIFX
O43 - CFD: 05/06/2009 - 14:57:02 - [0,353] ----D- C:\Program Files\eBay
O43 - CFD: 12/09/2009 - 16:34:52 - [12,919] ----D- C:\Program Files\EPSON
O43 - CFD: 05/09/2009 - 18:16:38 - [0] -SH-D- C:\Program Files\Fichiers communs
O43 - CFD: 06/11/2009 - 13:59:10 - [3,103] ----D- C:\Program Files\Google
O43 - CFD: 13/02/2011 - 01:12:32 - [1,565] ----D- C:\Program Files\Internet Explorer
O43 - CFD: 19/09/2010 - 19:36:34 - [1,848] ----D- C:\Program Files\iPod
O43 - CFD: 19/09/2010 - 19:37:10 - [2,237] ----D- C:\Program Files\iTunes
O43 - CFD: 02/11/2006 - 16:07:28 - [89,589] ----D- C:\Program Files\Microsoft Games
O43 - CFD: 05/06/2009 - 14:59:54 - [1,089] ----D- C:\Program Files\Microsoft Office
O43 - CFD: 25/09/2010 - 11:04:42 - [110,801] ----D- C:\Program Files\Movie Maker
O43 - CFD: 02/11/2006 - 16:07:28 - [0,025] ----D- C:\Program Files\MSBuild
O43 - CFD: 05/06/2009 - 14:00:46 - [1,288] ----D- C:\Program Files\PlayReady
O43 - CFD: 05/06/2009 - 14:20:52 - [12,250] ----D- C:\Program Files\Realtek
O43 - CFD: 02/11/2006 - 16:07:28 - [33,814] ----D- C:\Program Files\Reference Assemblies
O43 - CFD: 05/06/2009 - 14:23:08 - [21,664] ----D- C:\Program Files\Synaptics
O43 - CFD: 05/09/2009 - 15:54:46 - [296,971] ----D- C:\Program Files\TOSHIBA
O43 - CFD: 02/11/2006 - 16:44:56 - [0] --H-D- C:\Program Files\Uninstall Information
O43 - CFD: 21/01/2008 - 04:09:42 - [1,242] ----D- C:\Program Files\Windows Calendar
O43 - CFD: 21/01/2008 - 04:09:38 - [2,861] ----D- C:\Program Files\Windows Collaboration
O43 - CFD: 21/01/2008 - 04:09:30 - [6,100] ----D- C:\Program Files\Windows Defender
O43 - CFD: 21/01/2008 - 04:09:36 - [9,208] ----D- C:\Program Files\Windows Journal
O43 - CFD: 16/12/2010 - 13:18:14 - [9,178] ----D- C:\Program Files\Windows Mail
O43 - CFD: 16/10/2010 - 14:42:42 - [4,900] ----D- C:\Program Files\Windows Media Player
O43 - CFD: 05/09/2009 - 18:16:38 - [7,669] ----D- C:\Program Files\Windows NT
O43 - CFD: 21/01/2008 - 04:09:36 - [15,597] ----D- C:\Program Files\Windows Photo Gallery
O43 - CFD: 21/01/2008 - 04:09:38 - [7,898] ----D- C:\Program Files\Windows Sidebar
O43 - CFD: 19/09/2010 - 19:33:02 - [4,869] ----D- C:\Program Files\Common Files\Apple
O43 - CFD: 09/11/2009 - 20:54:34 - [198,220] ----D- C:\Program Files\Common Files\Microsoft Shared
O43 - CFD: 02/11/2006 - 14:33:54 - [0,003] ----D- C:\Program Files\Common Files\Services
O43 - CFD: 02/11/2006 - 14:33:54 - [0,580] ----D- C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 21/01/2008 - 04:09:30 - [9,109] ----D- C:\Program Files\Common Files\System
O43 - CFD: 05/09/2009 - 15:53:32 - [0,248] ----D- C:\Program Files\Common Files\TOSHIBA Shared
O43 - CFD: 22/09/2011 - 15:46:18 - [0] ----D- C:\ProgramData\2DBoy
O43 - CFD: 05/06/2009 - 14:49:54 - [0,001] ----D- C:\ProgramData\Adobe
O43 - CFD: 22/01/2010 - 21:09:04 - [61,110] ----D- C:\ProgramData\Alwil Software
O43 - CFD: 06/11/2011 - 18:19:18 - [27,821] ----D- C:\ProgramData\Apple
O43 - CFD: 19/09/2010 - 19:36:28 - [61,929] ----D- C:\ProgramData\Apple Computer
O43 - CFD: 02/11/2006 - 16:42:18 - [0] -SH-D- C:\ProgramData\Application Data
O43 - CFD: 05/09/2009 - 15:41:50 - [0,000] ----D- C:\ProgramData\ATI
O43 - CFD: 05/09/2009 - 18:16:38 - [0] -SH-D- C:\ProgramData\Bureau
O43 - CFD: 02/11/2006 - 16:42:18 - [0] -SH-D- C:\ProgramData\Desktop
O43 - CFD: 02/11/2006 - 16:42:18 - [0] -SH-D- C:\ProgramData\Documents
O43 - CFD: 18/09/2010 - 18:06:58 - [0] ----D- C:\ProgramData\EPtemp
O43 - CFD: 05/09/2009 - 18:16:38 - [0] -SH-D- C:\ProgramData\Favoris
O43 - CFD: 02/11/2006 - 16:42:18 - [0] -SH-D- C:\ProgramData\Favorites
O43 - CFD: 05/06/2009 - 14:54:02 - [0,514] ----D- C:\ProgramData\Google
O43 - CFD: 13/09/2011 - 13:45:02 - [0,149] ----D- C:\ProgramData\McAfee
O43 - CFD: 15/12/2011 - 23:41:00 - [0,001] ----D- C:\ProgramData\McAfee Security Scan
O43 - CFD: 05/09/2009 - 18:16:38 - [0] -SH-D- C:\ProgramData\Menu Démarrer
O43 - CFD: 09/11/2009 - 20:51:54 - [250,075] -S--D- C:\ProgramData\Microsoft
O43 - CFD: 17/04/2011 - 17:58:54 - [0,055] ----D- C:\ProgramData\Microsoft Help
O43 - CFD: 05/09/2009 - 18:16:38 - [0] -SH-D- C:\ProgramData\Modèles
O43 - CFD: 19/11/2009 - 12:36:30 - [0,023] ----D- C:\ProgramData\Orange
O43 - CFD: 15/05/2010 - 17:31:18 - [0] ----D- C:\ProgramData\PlayFirst
O43 - CFD: 24/12/2010 - 20:23:32 - [0,047] ----D- C:\ProgramData\ResultBar
O43 - CFD: 05/10/2009 - 08:05:08 - [8,458] ----D- C:\ProgramData\SBT
O43 - CFD: 05/06/2009 - 14:53:26 - [0,000] ----D- C:\ProgramData\SiteAdvisor
O43 - CFD: 02/11/2006 - 16:42:18 - [0] -SH-D- C:\ProgramData\Start Menu
O43 - CFD: 02/11/2006 - 16:42:18 - [0] -SH-D- C:\ProgramData\Templates
O43 - CFD: 05/09/2009 - 16:04:22 - [5,026] ----D- C:\ProgramData\TOSHIBA
O43 - CFD: 05/09/2009 - 18:20:36 - [0,001] ----D- C:\ProgramData\ToshibaEurope
O43 - CFD: 15/06/2009 - 13:25:16 - [0,037] ----D- C:\ProgramData\Vista32
O43 - CFD: 15/06/2009 - 13:25:16 - [0,013] ----D- C:\ProgramData\Vista64
O43 - CFD: 22/09/2011 - 16:33:00 - [645,692] ----D- C:\ProgramData\WildTangent
O43 - CFD: 05/06/2009 - 14:44:04 - [0,055] ----D- C:\ProgramData\XP
O43 - CFD: 05/06/2009 - 15:02:10 - [6,585] ----D- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
O43 - CFD: 19/09/2010 - 19:37:10 - [0,853] ----D- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
O43 - CFD: 27/11/2009 - 19:30:46 - [6,514] ----D- C:\Users\LAURA\AppData\Roaming\Adobe
O43 - CFD: 20/09/2010 - 15:07:26 - [0,395] ----D- C:\Users\LAURA\AppData\Roaming\Apple Computer
O43 - CFD: 05/09/2009 - 18:25:48 - [0] ----D- C:\Users\LAURA\AppData\Roaming\ATI
O43 - CFD: 06/09/2009 - 09:38:28 - [5,018] ----D- C:\Users\LAURA\AppData\Roaming\Farm Mania
O43 - CFD: 05/09/2009 - 19:35:08 - [0,091] ----D- C:\Users\LAURA\AppData\Roaming\Google
O43 - CFD: 05/09/2009 - 18:24:56 - [0] ----D- C:\Users\LAURA\AppData\Roaming\Identities
O43 - CFD: 04/11/2009 - 16:29:38 - [3,125] ----D- C:\Users\LAURA\AppData\Roaming\Macromedia
O43 - CFD: 02/11/2006 - 16:07:26 - [0] ----D- C:\Users\LAURA\AppData\Roaming\Media Center Programs
O43 - CFD: 16/12/2010 - 23:26:36 - [3,869] -S--D- C:\Users\LAURA\AppData\Roaming\Microsoft
O43 - CFD: 05/10/2009 - 08:04:24 - [0] ----D- C:\Users\LAURA\AppData\Roaming\Microsoft Web Folders
O43 - CFD: 02/04/2011 - 14:45:04 - [25,885] ----D- C:\Users\LAURA\AppData\Roaming\Mozilla
O43 - CFD: 27/09/2009 - 09:41:34 - [18,000] ----D- C:\Users\LAURA\AppData\Roaming\myphotobook
O43 - CFD: 15/05/2010 - 17:31:18 - [0,064] ----D- C:\Users\LAURA\AppData\Roaming\PlayFirst
O43 - CFD: 19/11/2009 - 12:36:28 - [0,005] ----D- C:\Users\LAURA\AppData\Roaming\Telephone sur PC
O43 - CFD: 05/09/2009 - 19:53:28 - [0,013] ----D- C:\Users\LAURA\AppData\Roaming\Template
O43 - CFD: 15/05/2010 - 18:35:46 - [0,000] ----D- C:\Users\LAURA\AppData\Roaming\TOSHIBA
O43 - CFD: 05/09/2009 - 20:46:40 - [0,001] ----D- C:\Users\LAURA\AppData\Roaming\WildTangent
O43 - CFD: 22/09/2011 - 15:46:18 - [0,000] ----D- C:\Users\LAURA\AppData\Local\2DBoy
O43 - CFD: 13/07/2011 - 19:56:58 - [2,892] ----D- C:\Users\LAURA\AppData\Local\Adobe
O43 - CFD: 19/09/2010 - 19:35:16 - [0] ----D- C:\Users\LAURA\AppData\Local\Apple
O43 - CFD: 28/09/2010 - 16:29:54 - [2,199] ----D- C:\Users\LAURA\AppData\Local\Apple Computer
O43 - CFD: 05/09/2009 - 18:20:20 - [0] -SH-D- C:\Users\LAURA\AppData\Local\Application Data
O43 - CFD: 05/09/2009 - 18:25:48 - [0,061] ----D- C:\Users\LAURA\AppData\Local\ATI
O43 - CFD: 07/12/2011 - 16:58:14 - [240,373] ----D- C:\Users\LAURA\AppData\Local\Google
O43 - CFD: 05/09/2009 - 18:20:20 - [0] -SH-D- C:\Users\LAURA\AppData\Local\Historique
O43 - CFD: 30/01/2011 - 12:15:26 - [221,377] ----D- C:\Users\LAURA\AppData\Local\Microsoft
O43 - CFD: 02/11/2009 - 23:04:28 - [1,585] ----D- C:\Users\LAURA\AppData\Local\Microsoft Games
O43 - CFD: 02/04/2011 - 14:44:58 - [796,524] ----D- C:\Users\LAURA\AppData\Local\Mozilla
O43 - CFD: 15/12/2011 - 15:09:26 - [274,155] ----D- C:\Users\LAURA\AppData\Local\Temp
O43 - CFD: 05/09/2009 - 18:20:20 - [0] -SH-D- C:\Users\LAURA\AppData\Local\Temporary Internet Files
O43 - CFD: 05/09/2009 - 18:25:50 - [0] ----D- C:\Users\LAURA\AppData\Local\Toshiba
O43 - CFD: 27/09/2009 - 09:41:26 - [25,432] ----D- C:\Users\LAURA\AppData\Local\VirtualStore
O43 - CFD: 05/06/2009 - 15:02:10 - [12,096] ----D- C:\Program Files (x86)\Activation Assistant for the 2007 Microsoft Office suites
O43 - CFD: 05/06/2009 - 14:49:40 - [225,396] ----D- C:\Program Files (x86)\Adobe
O43 - CFD: 19/09/2010 - 19:35:14 - [2,200] ----D- C:\Program Files (x86)\Apple Software Update
O43 - CFD: 05/09/2009 - 15:39:48 - [79,942] ----D- C:\Program Files (x86)\ATI Technologies
O43 - CFD: 19/09/2010 - 19:32:52 - [0,588] ----D- C:\Program Files (x86)\Bonjour
O43 - CFD: 19/09/2010 - 19:32:38 - [597,613] ----D- C:\Program Files (x86)\Common Files
O43 - CFD: 18/09/2010 - 18:07:04 - [5,608] ----D- C:\Program Files (x86)\epson
O43 - CFD: 11/11/2011 - 09:32:10 - [383,121] ----D- C:\Program Files (x86)\Google
O43 - CFD: 18/09/2010 - 18:41:06 - [110,847] --H-D- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 05/06/2009 - 14:17:06 - [46,421] ----D- C:\Program Files (x86)\Intel
O43 - CFD: 13/02/2011 - 01:12:32 - [2,537] ----D- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 19/09/2010 - 19:37:10 - [114,432] ----D- C:\Program Files (x86)\iTunes
O43 - CFD: 05/06/2009 - 14:44:42 - [85,147] ----D- C:\Program Files (x86)\Java
O43 - CFD: 05/06/2009 - 14:38:34 - [1,714] ----D- C:\Program Files (x86)\JMicron
O43 - CFD: 16/09/2011 - 13:49:58 - [9,260] ----D- C:\Program Files (x86)\McAfee Security Scan
O43 - CFD: 09/11/2009 - 20:55:16 - [0,216] ----D- C:\Program Files (x86)\Microsoft
O43 - CFD: 05/10/2009 - 08:05:18 - [444,225] ----D- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 16/12/2010 - 13:00:20 - [138,685] ----D- C:\Program Files (x86)\Microsoft Works
O43 - CFD: 05/06/2009 - 15:01:06 - [7,774] ----D- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 23/11/2011 - 20:21:32 - [36,391] ----D- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 02/11/2006 - 16:07:28 - [0,025] ----D- C:\Program Files (x86)\MSBuild
O43 - CFD: 05/06/2009 - 12:46:46 - [0] ----D- C:\Program Files (x86)\MSXML 4.0
O43 - CFD: 05/06/2009 - 14:54:26 - [19,624] ----D- C:\Program Files (x86)\myphotobook
O43 - CFD: 11/11/2009 - 19:07:42 - [41,346] ----D- C:\Program Files (x86)\Orange
O43 - CFD: 19/09/2010 - 11:06:02 - [144,893] ----D- C:\Program Files (x86)\OrangeHSS
O43 - CFD: 17/08/2011 - 13:27:14 - [94,691] ----D- C:\Program Files (x86)\Picasa2
O43 - CFD: 05/06/2009 - 14:00:46 - [0,993] ----D- C:\Program Files (x86)\PlayReady
O43 - CFD: 19/09/2010 - 19:35:46 - [72,799] ----D- C:\Program Files (x86)\QuickTime
O43 - CFD: 05/09/2009 - 15:50:32 - [6,048] ----D- C:\Program Files (x86)\Realtek
O43 - CFD: 02/11/2006 - 16:07:28 - [36,050] ----D- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 24/12/2010 - 20:26:26 - [0,081] ----D- C:\Program Files (x86)\ResultBar
O43 - CFD: 18/09/2010 - 18:20:42 - [62,665] ----D- C:\Program Files (x86)\Securitoo
O43 - CFD: 05/10/2009 - 08:05:06 - [0,132] ----D- C:\Program Files (x86)\Snapshot Viewer
O43 - CFD: 05/06/2009 - 14:21:56 - [0] --H-D- C:\Program Files (x86)\Temp
O43 - CFD: 05/09/2009 - 16:11:26 - [188,792] ----D- C:\Program Files (x86)\Toshiba
O43 - CFD: 05/06/2009 - 14:56:54 - [526,901] ----D- C:\Program Files (x86)\TOSHIBA Games
O43 - CFD: 02/11/2006 - 16:36:08 - [0] --H-D- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 18/09/2010 - 18:36:20 - [17,076] ----D- C:\Program Files (x86)\Wanadoo
O43 - CFD: 21/01/2008 - 04:09:50 - [0,970] ----D- C:\Program Files (x86)\Windows Calendar
O43 - CFD: 21/01/2008 - 04:09:48 - [0,051] ----D- C:\Program Files (x86)\Windows Collaboration
O43 - CFD: 21/01/2008 - 04:09:42 - [0,481] ----D- C:\Program Files (x86)\Windows Defender
O43 - CFD: 09/11/2009 - 20:55:12 - [43,810] ----D- C:\Program Files (x86)\Windows Live
O43 - CFD: 09/11/2009 - 20:55:02 - [0,234] ----D- C:\Program Files (x86)\Windows Live SkyDrive
O43 - CFD: 16/12/2010 - 13:18:14 - [8,526] ----D- C:\Program Files (x86)\Windows Mail
O43 - CFD: 16/10/2010 - 14:42:42 - [2,870] ----D- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 02/11/2006 - 16:07:28 - [7,577] ----D- C:\Program Files (x86)\Windows NT
O43 - CFD: 21/01/2008 - 04:09:48 - [12,841] ----D- C:\Program Files (x86)\Windows Photo Gallery
O43 - CFD: 21/01/2008 - 04:09:50 - [7,272] ----D- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 15/12/2011 - 15:08:20 - [9,122] ----D- C:\Program Files (x86)\ZHPDiag
O43 - CFD: 05/06/2009 - 14:49:42 - [4,382] ----D- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 19/09/2010 - 19:36:30 - [72,023] ----D- C:\Program Files (x86)\Common Files\Apple
O43 - CFD: 05/06/2009 - 15:01:16 - [0,089] ----D- C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 19/09/2010 - 10:59:08 - [7,537] ----D- C:\Program Files (x86)\Common Files\France Telecom
O43 - CFD: 18/09/2010 - 18:41:10 - [3,626] ----D- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 11/11/2009 - 09:30:16 - [428,290] ----D- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 02/11/2006 - 14:33:54 - [0,003] ----D- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 02/11/2006 - 14:33:54 - [39,198] ----D- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 05/10/2009 - 08:05:06 - [41,485] ----D- C:\Program Files (x86)\Common Files\System
O43 - CFD: 05/09/2009 - 16:05:02 - [0,982] ----D- C:\Program Files (x86)\Common Files\TOSHIBA Shared
O43 - CFD: 09/11/2009 - 20:52:08 - [0] ----D- C:\Program Files (x86)\Common Files\Windows Live
~ Scan Program Folder in 02mn 13s

---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.214CCEC6FD3D4E351A19CF3188790497] - 15/12/2011 - 14:55:16 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1403547]
O44 - LFC:[MD5.C3314656A77F6F7EFFF7DB95F4F92584] - 15/12/2011 - 14:51:37 ---A- . (...) -- C:\Windows\dd_vcredistMSI2BC1.txt [591936]
O44 - LFC:[MD5.5A84E2E907362774FC9E2C96C23E3EBD] - 15/12/2011 - 14:51:37 ---A- . (...) -- C:\Windows\dd_vcredistUI2BC1.txt [12336]
O44 - LFC:[MD5.6FFEE47D371324EF5AF302FB1DB7C095] - 15/12/2011 - 14:42:52 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.295B2514E5ED5DBF1EF7987FD2B42340] - 12/12/2011 - 08:53:25 ---A- . (...) -- C:\Windows\dd_vcredistUI2F61.txt [12400]
O44 - LFC:[MD5.55C35360F25BF10C194F7D1C1CABBFEF] - 12/12/2011 - 08:53:23 ---A- . (...) -- C:\Windows\dd_vcredistMSI2F61.txt [593570]
O44 - LFC:[MD5.F2793312C434D3DA4A9AAFAEA3177C5C] - 11/12/2011 - 09:37:51 ---A- . (...) -- C:\Windows\dd_vcredistUI034E.txt [12416]
O44 - LFC:[MD5.AB48D7BE9488A850FEC963407D88F627] - 11/12/2011 - 09:37:49 ---A- . (...) -- C:\Windows\dd_vcredistMSI034E.txt [593978]
O44 - LFC:[MD5.CA89F508579C41810FCCE901DEC0DCC7] - 10/12/2011 - 11:17:32 ---A- . (...) -- C:\Windows\dd_vcredistUI0174.txt [12384]
O44 - LFC:[MD5.0AEE2A8A96949D453935C2E23D23B629] - 10/12/2011 - 11:17:31 ---A- . (...) -- C:\Windows\dd_vcredistMSI0174.txt [593178]
O44 - LFC:[MD5.7B09D98F66D2FFBDBDA5F12529C34A9E] - 10/12/2011 - 10:31:59 ---A- . (...) -- C:\Windows\dd_vcredistUI5E97.txt [12416]
O44 - LFC:[MD5.C7E4A6B43A11120F3434AC70FBC97529] - 10/12/2011 - 10:31:58 ---A- . (...) -- C:\Windows\dd_vcredistMSI5E97.txt [593978]
O44 - LFC:[MD5.7DFE114516BCB83CC18A2873A735C27E] - 09/12/2011 - 10:19:25 ---A- . (...) -- C:\Windows\dd_vcredistUI06CA.txt [12416]
O44 - LFC:[MD5.AE9E1D3236D6348D15DEC06860F12824] - 09/12/2011 - 10:19:24 ---A- . (...) -- C:\Windows\dd_vcredistMSI06CA.txt [593978]
O44 - LFC:[MD5.841FAC1D3D3F31077862B2C07DE4C9BE] - 08/12/2011 - 16:45:19 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1470810]
O44 - LFC:[MD5.E7FD93FD694E20B74A7D729BB94BA0EF] - 08/12/2011 - 16:45:19 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [101250]
O44 - LFC:[MD5.D29BCA7C95D6256AA54FDEBECD0A4DC5] - 08/12/2011 - 16:45:19 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [123556]
O44 - LFC:[MD5.B735BFE186AB69C79515E3AA8E230A60] - 08/12/2011 - 16:45:19 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [587178]
O44 - LFC:[MD5.9DE9E5CD76589B259FEB6258223B42DA] - 08/12/2011 - 16:45:19 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [669566]
O44 - LFC:[MD5.841FAC1D3D3F31077862B2C07DE4C9BE] - 08/12/2011 - 16:45:19 RSHAD . (...) -- C:\Windows\system32\PerfStringBackup.INI [1470810]
O44 - LFC:[MD5.E7FD93FD694E20B74A7D729BB94BA0EF] - 08/12/2011 - 16:45:19 RSHAD . (...) -- C:\Windows\system32\perfc009.dat [101250]
O44 - LFC:[MD5.D29BCA7C95D6256AA54FDEBECD0A4DC5] - 08/12/2011 - 16:45:19 RSHAD . (...) -- C:\Windows\system32\perfc00C.dat [123556]
O44 - LFC:[MD5.B735BFE186AB69C79515E3AA8E230A60] - 08/12/2011 - 16:45:19 RSHAD . (...) -- C:\Windows\system32\perfh009.dat [587178]
O44 - LFC:[MD5.9DE9E5CD76589B259FEB6258223B42DA] - 08/12/2011 - 16:45:19 RSHAD . (...) -- C:\Windows\system32\perfh00C.dat [669566]
O44 - LFC:[MD5.076C8D27FA7D46E2828F9BFDD36B6132] - 08/12/2011 - 10:15:18 ---A- . (...) -- C:\Windows\dd_vcredistMSI3564.txt [594794]
O44 - LFC:[MD5.C45F63975F082F9E869C2047A0A7A235] - 08/12/2011 - 10:15:18 ---A- . (...) -- C:\Windows\dd_vcredistUI3564.txt [12448]
O44 - LFC:[MD5.4DEED57DA3BC7C55BA53380CF6CC5FA3] - 06/12/2011 - 08:53:50 ---A- . (...) -- C:\Windows\dd_vcredistUI5AEA.txt [12352]
O44 - LFC:[MD5.6602992C19376C9F0591A0BE672414A5] - 06/12/2011 - 08:53:49 ---A- . (...) -- C:\Windows\dd_vcredistMSI5AEA.txt [592346]
O44 - LFC:[MD5.E4DFB9ACEE80CE1E75E971ECBE602577] - 05/12/2011 - 09:17:08 ---A- . (...) -- C:\Windows\dd_vcredistUI1E89.txt [12448]
O44 - LFC:[MD5.994F8BC00C1E0FA97ECCB1AE3B8107C7] - 05/12/2011 - 09:17:07 ---A- . (...) -- C:\Windows\dd_vcredistMSI1E89.txt [594794]
O44 - LFC:[MD5.3D9CF3EBFA7CE333F83FD6CF8E696FA1] - 04/12/2011 - 09:35:19 ---A- . (...) -- C:\Windows\dd_vcredistUI5E7C.txt [12400]
O44 - LFC:[MD5.3063041050693D1B9835D28AABC43E8D] - 04/12/2011 - 09:35:17 ---A- . (...) -- C:\Windows\dd_vcredistMSI5E7C.txt [593570]
O44 - LFC:[MD5.86DE5AC2754A10260A6137D055045916] - 03/12/2011 - 09:38:58 ---A- . (...) -- C:\Windows\dd_vcredistUI131F.txt [12432]
O44 - LFC:[MD5.D8B7A1696B9ECFEF277A0D9ED67D6EEE] - 03/12/2011 - 09:38:56 ---A- . (...) -- C:\Windows\dd_vcredistMSI131F.txt [594386]
O44 - LFC:[MD5.6E0540B80E21CBABD7030FE0D7DFBAB0] - 02/12/2011 - 09:43:07 ---A- . (...) -- C:\Windows\dd_vcredistUI482D.txt [12400]
O44 - LFC:[MD5.3211C5C870A1DC3C50E51ABD4BA4D2EF] - 02/12/2011 - 09:43:06 ---A- . (...) -- C:\Windows\dd_vcredistMSI482D.txt [593570]
O44 - LFC:[MD5.0F31C007E547CC6F64CC8CA588ADA2E8] - 01/12/2011 - 11:31:23 ---A- . (...) -- C:\Windows\dd_vcredistUI4CEC.txt [12336]
O44 - LFC:[MD5.95EC7241CDC15796363878D479AB7A45] - 01/12/2011 - 11:31:22 ---A- . (...) -- C:\Windows\dd_vcredistMSI4CEC.txt [591938]
O44 - LFC:[MD5.6222E2DD7567271EA7798AAF1BD2A3D7] - 30/11/2011 - 12:40:17 ---A- . (...) -- C:\Windows\dd_vcredistMSI3375.txt [593162]
O44 - LFC:[MD5.79A4B619A8706C2089C86163C8977332] - 30/11/2011 - 12:40:17 ---A- . (...) -- C:\Windows\dd_vcredistUI3375.txt [12384]
O44 - LFC:[MD5.C586947CD262E8CDF32B875B9F3ED4C0] - 29/11/2011 - 14:26:06 ---A- . (...) -- C:\Windows\dd_vcredistUI3630.txt [12368]
O44 - LFC:[MD5.CE82B6B3320D16FE30FEB94DF9F584B5] - 29/11/2011 - 14:26:05 ---A- . (...) -- C:\Windows\dd_vcredistMSI3630.txt [592754]
O44 - LFC:[MD5.2A9BB53B6E72764DDA68FCA4614B7E92] - 28/11/2011 - 12:50:18 ---A- . (...) -- C:\Windows\dd_vcredistUI1ED9.txt [12384]
O44 - LFC:[MD5.C3F7CA93C47420DD0A918E7CA4A0A533] - 28/11/2011 - 12:50:16 ---A- . (...) -- C:\Windows\dd_vcredistMSI1ED9.txt [593162]
O44 - LFC:[MD5.F4B58F0E169381F28B26FF133C35D24A] - 27/11/2011 - 10:44:33 ---A- . (...) -- C:\Windows\dd_vcredistUI7061.txt [12336]
O44 - LFC:[MD5.F304F4930F6E6C9A6BE459577BA407D5] - 27/11/2011 - 10:44:31 ---A- . (...) -- C:\Windows\dd_vcredistMSI7061.txt [591938]
O44 - LFC:[MD5.18805D36AAA04FD69A3D75F49337A5B1] - 26/11/2011 - 08:36:37 ---A- . (...) -- C:\Windows\dd_vcredistMSI406B.txt [593570]
O44 - LFC:[MD5.131B98513FAD3A762D500A8C0134C2AF] - 26/11/2011 - 08:36:37 ---A- . (...) -- C:\Windows\dd_vcredistUI406B.txt [12400]
O44 - LFC:[MD5.627CB15A6CA53CE463C5893E0B5909FF] - 25/11/2011 - 17:06:46 ---A- . (...) -- C:\Windows\dd_vcredistUI78B0.txt [12432]
O44 - LFC:[MD5.2E0730B172505BC30F0D07E1B4F39BBF] - 25/11/2011 - 17:06:44 ---A- . (...) -- C:\Windows\dd_vcredistMSI78B0.txt [594386]
O44 - LFC:[MD5.603622F5F0591F552A9CC88FE53B2CB2] - 24/11/2011 - 12:13:44 ---A- . (...) -- C:\Windows\dd_vcredistUI4A4D.txt [12352]
O44 - LFC:[MD5.5EC470F044AF309DDCFF73B8C3EB0368] - 24/11/2011 - 12:13:42 ---A- . (...) -- C:\Windows\dd_vcredistMSI4A4D.txt [592346]
O44 - LFC:[MD5.1228E78D3E470E4AE59B1ADF7C946BB6] - 23/11/2011 - 16:23:00 ---A- . (...) -- C:\Windows\dd_vcredistMSI3AF6.txt [592754]
O44 - LFC:[MD5.152F5B569AAC63F09B3A9378591A2531] - 23/11/2011 - 16:23:00 ---A- . (...) -- C:\Windows\dd_vcredistUI3AF6.txt [12368]
O44 - LFC:[MD5.BFF6B6C5F003F544C557658024B7C312] - 22/11/2011 - 15:25:04 ---A- . (...) -- C:\Windows\dd_vcredistUI409E.txt [12352]
O44 - LFC:[MD5.F6C00D088D0C690284CD47B28019A872] - 22/11/2011 - 15:25:01 ---A- . (...) -- C:\Windows\dd_vcredistMSI409E.txt [592346]
O44 - LFC:[MD5.DFF2644A406529289A4272D0C22608B3] - 21/11/2011 - 12:27:45 ---A- . (...) -- C:\Windows\dd_vcredistUI6AD6.txt [12416]
O44 - LFC:[MD5.34871427F98C0FF67F777F6DD2116E89] - 21/11/2011 - 12:27:43 ---A- . (...) -- C:\Windows\dd_vcredistMSI6AD6.txt [593978]
O44 - LFC:[MD5.1AAA5703E0CB34572CC449FADFFA24CD] - 20/11/2011 - 09:25:45 ---A- . (...) -- C:\Windows\dd_vcredistUI1144.txt [12384]
O44 - LFC:[MD5.96EEF968CDC81B108252161A1AFE9F13] - 20/11/2011 - 09:25:43 ---A- . (...) -- C:\Windows\dd_vcredistMSI1144.txt [593162]
O44 - LFC:[MD5.84F38D6CBDB35B2F2160530D15DF91E8] - 19/11/2011 - 08:31:27 ---A- . (...) -- C:\Windows\dd_vcredistUI1982.txt [12432]
O44 - LFC:[MD5.68ADA14A2ECC483B0AC8E4DC8F82B55B] - 19/11/2011 - 08:31:25 ---A- . (...) -- C:\Windows\dd_vcredistMSI1982.txt [594386]
O44 - LFC:[MD5.82031DA746CDE66253B2A414FCFE6680] - 19/11/2011 - 08:24:57 ---A- . (...) -- C:\Windows\PFRO.log [487046]
O44 - LFC:[MD5.0FF770FED66B527DAD9D34023031F00C] - 18/11/2011 - 16:49:34 ---A- . (...) -- C:\Windows\dd_vcredistUI48BF.txt [12352]
O44 - LFC:[MD5.4C2D6C0606CF9D7B4063F2EBA54C7B4F] - 18/11/2011 - 16:49:32 ---A- . (...) -- C:\Windows\dd_vcredistMSI48BF.txt [592346]
O44 - LFC:[MD5.617C0594F4CA2B3DBAE6C36B3CE568BC] - 17/11/2011 - 13:15:35 ---A- . (...) -- C:\Windows\dd_vcredistUI56E3.txt [12336]
O44 - LFC:[MD5.D77CCEABFB8CFEBAB00AA94924161DEA] - 17/11/2011 - 13:15:34 ---A- . (...) -- C:\Windows\dd_vcredistMSI56E3.txt [591938]
~ Scan Files in 00mn 23s

---\\ Export de clé d'application autorisée (O47)
O47 - AAKE:Key Export SP - "C:\Program Files (x86)\OrangeHSS\Connectivity\ConnectivityManager.exe" [Enabled] .(.France Telecom SA - Pas de description.) -- C:\Program Files (x86)\OrangeHSS\Connectivity\ConnectivityManager.exe
~ Scan Keys in 00mn 00s

---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\system32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\system32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\system32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\system32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\system32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\system32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\system32\tspkg.dll
~ Scan Keys in 00mn 00s

---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\system32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\system32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\system32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\system32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\system32\Drivers\volmgrx.sys
~ Scan CSB in 00mn 00s

---\\ MountPoints2 Shell Key (O51)
O51 - MPSK:{81a51b36-9a28-11de-870d-806e6f6e6963}\AutoRun\command. (...) -- F:\setup.exe (.not file.)
~ Scan Keys in 00mn 00s

---\\ Trojan Driver Search Data (HKLM) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ Scan Keys in 00mn 00s

---\\ ShareTools MSconfig StartupReg (O53) (None)

---\\ Microsoft Control Security Providers (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll
~ Scan Keys in 00mn 00s

---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=2
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
~ Scan Keys in 00mn 00s

---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0
~ Scan Keys in 00mn 00s

---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.F14215E37CF124104575073F782111D2] - 21/01/2008 - 03:46:53 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys [486456]
O58 - SDL:[MD5.7D05A75E3066861A6610F7EE04FF085C] - 21/01/2008 - 03:46:54 RSHAD . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys [342584]
O58 - SDL:[MD5.820A201FE08A0C345B3BEDBC30E1A77C] - 21/01/2008 - 03:46:54 RSHAD . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (X64).) -- C:\Windows\system32\drivers\adpu160m.sys [126520]
O58 - SDL:[MD5.9B4AB6854559DC168FBB4C24FC52E794] - 21/01/2008 - 03:47:27 RSHAD . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\system32\drivers\adpu320.sys [185912]
O58 - SDL:[MD5.E59BC94C0FC336F2F6A07A7E16441C48] - 02/11/2006 - 22:38:10 RSHAD . (.Agere Systems - SoftModem Device Driver.) -- C:\Windows\system32\drivers\agrsm64.sys [1074688]
O58 - SDL:[MD5.157D0898D4B73F075CE9FA26B482DF98] - 21/01/2008 - 03:46:50 RSHAD . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys [15976]
O58 - SDL:[MD5.BA8417D4765F3988FF921F30F630E303] - 21/01/2008 - 03:46:52 RSHAD . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys [90680]
O58 - SDL:[MD5.9D41C435619733B34CC16A511E644B11] - 21/01/2008 - 03:47:00 RSHAD . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys [91192]
O58 - SDL:[MD5.E6DEE1FF3EC08C146AE607257B2AC25E] - 11/11/2009 - 12:43:03 RSHAD . (.ALWIL Software - avast! File System Access Blocking Driver.) -- C:\Windows\system32\drivers\aswFsBlk.sys [22096]
O58 - SDL:[MD5.976E731BC951D76237E960FAD7402741] - 11/11/2009 - 12:43:27 RSHAD . (.ALWIL Software - avast! File System Minifilter for Windows 2003/Vista.) -- C:\Windows\system32\drivers\aswMonFlt.sys [63056]
O58 - SDL:[MD5.10FDE4D126DD0D09D59A84F703449244] - 11/11/2009 - 12:43:43 RSHAD . (.ALWIL Software - avast! TDI RDR Driver.) -- C:\Windows\system32\drivers\aswRdr.sys [28752]
O58 - SDL:[MD5.0211624896D0B05F24533540E22FC740] - 11/11/2009 - 14:14:04 RSHAD . (.ALWIL Software - avast! self protection module.) -- C:\Windows\system32\drivers\aswSP.sys [120912]
O58 - SDL:[MD5.F0CDAE379C90D6E1D873C10B5CA1AF0C] - 11/11/2009 - 12:46:56 RSHAD . (.ALWIL Software - avast! TDI Filter Driver.) -- C:\Windows\system32\drivers\aswTdi.sys [51280]
O58 - SDL:[MD5.C28928BECD9D35248C2A6CB18032CACC] - 05/09/2009 - 22:30:46 RSHAD . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\system32\drivers\atikmdag.sys [5356032]
O58 - SDL:[MD5.40014A6251A68D1EC48001B1653CCEE0] - 21/01/2008 - 03:47:30 RSHAD . (...) -- C:\Windows\system32\drivers\bdasup.sys [15616]
O58 - SDL:[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - 02/11/2006 - 22:30:15 RSHAD . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys [18432]
O58 - SDL:[MD5.B114D3098E9BDB8BEA8B053685831BE6] - 02/11/2006 - 22:30:15 RSHAD . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys [8704]
O58 - SDL:[MD5.F0F0BA4D815BE446AA6A4583CA3BCA9B] - 02/11/2006 - 09:43:25 RSHAD . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys [86528]
O58 - SDL:[MD5.A6ECA2151B08A09CACECA35C07F05B42] - 02/11/2006 - 22:30:18 RSHAD . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys [47104]
O58 - SDL:[MD5.B79968002C277E869CF38BD22CD61524] - 02/11/2006 - 22:30:18 RSHAD . (...) -- C:\Windows\system32\drivers\BrUsbMdm.sys [14976]
O58 - SDL:[MD5.A87528880231C54E75EA7A44943B38BF] - 02/11/2006 - 12:42:33 RSHAD . (...) -- C:\Windows\system32\drivers\BrUsbSer.sys [14720]
O58 - SDL:[MD5.B52D9A14CE4101577900A364BA86F3DF] - 21/01/2008 - 03:46:51 RSHAD . (...) -- C:\Windows\system32\drivers\CmBatt.sys [17792]
O58 - SDL:[MD5.E5D5499A1C50A54B5161296B6AFE6192] - 21/01/2008 - 03:46:50 RSHAD . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys [18024]
O58 - SDL:[MD5.222CB641B4B8A1D1126F8033F9FD6A00] - 02/11/2006 - 12:50:06 RSHAD . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\system32\drivers\djsvs.sys [88168]
O58 - SDL:[MD5.264CEE7B031A9D6C827F3D0CB031F2FE] - 21/01/2008 - 03:46:56 RSHAD . (...) -- C:\Windows\system32\drivers\E1G6032E.sys [146176]
O58 - SDL:[MD5.C4636D6E10469404AB5308D9FD45ED07] - 21/01/2008 - 03:46:59 RSHAD . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys [397368]
O58 - SDL:[MD5.CD0C80E5E9A9BF8DD145F43713D77993] - 05/09/2009 - 11:18:40 RSHAD . (.ENE TECHNOLOGY INC. - ENE CIR Driver for eHome(64).) -- C:\Windows\system32\drivers\enecir.sys [68608]
O58 - SDL:[MD5.B0B0C493609E40BD9E1B8F2AA9CCBEDC] - 05/09/2009 - 00:56:00 RSHAD . (.ENE TECHNOLOGY INC. - ENE CIR HID Driver(64).) -- C:\Windows\system32\drivers\enecirhid.sys [14336]
O58 - SDL:[MD5.8492D808C79BD6FE439F77BE84956CDF] - 05/09/2009 - 08:16:00 RSHAD . (.ENE TECHNOLOGY INC. - ENE CIR HID Mapper Driver(64).) -- C:\Windows\system32\drivers\enecirhidma.sys [6656]
O58 - SDL:[MD5.E403AACF8C7BB11375122D2464560311] - 19/09/2010 - 13:17:08 RSHAD . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [34152]
O58 - SDL:[MD5.B13C6930BE914AA433C320E01B0182F3] - 21/01/2008 - 03:46:55 RSHAD . (...) -- C:\Windows\system32\drivers\hidparse.sys [31616]
O58 - SDL:[MD5.D7109A1E6BD2DFDBCBA72A6BC626A13B] - 21/01/2008 - 03:46:59 RSHAD . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\system32\drivers\HpCISSs.sys [47672]
O58 - SDL:[MD5.1ADAA4F16073FD0C7270F451FD024E97] - 05/06/2009 - 16:26:18 RSHAD . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\system32\drivers\iaStor.sys [407576]
O58 - SDL:[MD5.3E3BF3627D886736D0B4E90054F929F6] - 21/01/2008 - 03:46:59 RSHAD . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\system32\drivers\iaStorV.sys [290872]
O58 - SDL:[MD5.8C3951AD2FE886EF76C7B5027C3125D3] - 02/11/2006 - 13:02:39 RSHAD . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys [44648]
O58 - SDL:[MD5.63C766CDC609FF8206CB447A65ABBA4A] - 02/11/2006 - 13:02:09 RSHAD . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\system32\drivers\iteatapi.sys [37480]
O58 - SDL:[MD5.1281FE73B17664631D12F643CBEA3F59] - 02/11/2006 - 13:02:09 RSHAD . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\system32\drivers\iteraid.sys [37480]
O58 - SDL:[MD5.C241B97AA60AC47FA8C628B3AD489B34] - 05/06/2009 - 15:36:40 RSHAD . (.JMicron Technology Corporation - JMicron JMB38X Flash Media Controller Driver.) -- C:\Windows\system32\drivers\jmcr.sys [138592]
O58 - SDL:[MD5.1D419CF43DB29396ECD7113D129D94EB] - 21/01/2008 - 03:49:00 RSHAD . (...) -- C:\Windows\system32\drivers\ksthunk.sys [20864]
O58 - SDL:[MD5.9C551A9121639A9779862CB8A6CABF03] - 05/06/2009 - 10:30:14 ---A- . (.COMPAL ELECTRONIC INC. - LPCFilter.) -- C:\Windows\system32\drivers\LPCFilter.sys [32040]
O58 - SDL:[MD5.ACBE1AF32D3123E330A07BFBC5EC4A9B] - 21/01/2008 - 03:46:51 RSHAD . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys [113720]
O58 - SDL:[MD5.799FFB2FC4729FA46D2157C0065B3525] - 21/01/2008 - 03:46:56 RSHAD . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys [105016]
O58 - SDL:[MD5.F445FF1DAAD8A226366BFAF42551226B] - 21/01/2008 - 03:47:01 RSHAD . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys [113720]
O58 - SDL:[MD5.5C5CD6AACED32FB26C3FB34B3DCF972F] - 21/01/2008 - 03:46:59 RSHAD . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows Vista/Longhorn for x.) -- C:\Windows\system32\drivers\megasas.sys [35896]
O58 - SDL:[MD5.859BC2436B076C77C159ED694ACFE8F8] - 21/01/2008 - 03:46:56 RSHAD . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys [438328]
O58 - SDL:[MD5.3C200630A89EF2C0864D515B7A75802E] - 02/11/2006 - 13:02:24 RSHAD . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows Vista/Longhorn for.) -- C:\Windows\system32\drivers\Mraid35x.sys [39016]
O58 - SDL:[MD5.0EA73E498F53B96D83DBFCA074AD4CF8] - 21/01/2008 - 03:49:52 RSHAD . (...) -- C:\Windows\system32\drivers\mskssrv.sys [11008]
O58 - SDL:[MD5.52E59B7E992A58E740AA63F57EDBAE8B] - 02/11/2006 - 10:37:30 RSHAD . (...) -- C:\Windows\system32\drivers\mspclock.sys [7040]
O58 - SDL:[MD5.49084A75BAE043AE02D5B44D02991BB2] - 02/11/2006 - 10:37:30 RSHAD . (...) -- C:\Windows\system32\drivers\mspqm.sys [6656]
O58 - SDL:[MD5.86D632D75D05D5B7C7C043FA3564AE86] - 21/01/2008 - 03:49:52 RSHAD . (...) -- C:\Windows\system32\drivers\mstee.sys [7936]
O58 - SDL:[MD5.2BDCB7B7917380794C9D87AC2153CE33] - 05/09/2009 - 06:50:30 RSHAD . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\system32\drivers\NETw5v64.sys [4751360]
O58 - SDL:[MD5.4AC08BD6AF2DF42E0C3196D826C8AEA7] - 02/11/2006 - 13:03:03 RSHAD . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys [51816]
O58 - SDL:[MD5.2C040B7ADA5B06F6FACADAC8514AA034] - 21/01/2008 - 03:46:54 RSHAD . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys [128056]
O58 - SDL:[MD5.F7EA0FE82842D05EDA3EFDD376DBFDBA] - 21/01/2008 - 03:46:54 RSHAD . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys [54328]
O58 - SDL:[MD5.7B58953E2F263421FDBB09A192712A85] - 02/11/2006 - 10:43:56 RSHAD . (...) -- C:\Windows\system32\drivers\ohci1394.sys [72192]
O58 - SDL:[MD5.2C3BA65F8CA712730050C29104E093F9] - 05/06/2009 - 10:46:44 RSHAD . (...) -- C:\Windows\system32\drivers\PGEffect.sys [32832]
O58 - SDL:[MD5.0B83F4E681062F3839BE2EC1D98FD94A] - 21/01/2008 - 03:46:52 RSHAD . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys [1221176]
O58 - SDL:[MD5.E1C80F8D4D1E39EF9595809C1369BF2A] - 02/11/2006 - 12:50:27 RSHAD . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys [124008]
O58 - SDL:[MD5.EE328F24FFC3AC211F48266864C65FA6] - 05/06/2009 - 17:30:12 RSHAD . (...) -- C:\Windows\system32\drivers\RtHDMIVX.sys [189088]
O58 - SDL:[MD5.627C6B352718E59DF08F02C536E2E0ED] - 05/06/2009 - 16:15:50 RSHAD . (...) -- C:\Windows\system32\drivers\RTKVHD64.sys [1746208]
O58 - SDL:[MD5.3E800D0DD24C5CFE61A1D71A3F6FEAB9] - 05/09/2009 - 13:29:40 RSHAD . (.Realtek - Realtek 8136/8168/8169 NDIS6 64-bit Driver.) -- C:\Windows\system32\drivers\Rtlh64.sys [206336]
O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 02/11/2006 - 00:51:44 RSHAD . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys [23040]
O58 - SDL:[MD5.3A2F769FAB9582BC720E11EA1DFB184D] - 21/01/2008 - 03:47:26 RSHAD . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys [78392]
O58 - SDL:[MD5.75576CFC649C1A3FAA196DD1FBF23434] - 21/01/2008 - 03:51:03 RSHAD . (...) -- C:\Windows\system32\drivers\stream.sys [68224]
O58 - SDL:[MD5.2F26A2C6FC96B29BEFF5D8ED74E6625B] - 02/11/2006 - 13:02:52 RSHAD . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\system32\drivers\symc8xx.sys [49256]
O58 - SDL:[MD5.A909667976D3BCCD1DF813FED517D837] - 02/11/2006 - 13:02:37 RSHAD . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_hi.sys [44648]
O58 - SDL:[MD5.36887B56EC2D98B9C362F6AE4DE5B7B0] - 02/11/2006 - 13:02:47 RSHAD . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_u3.sys [48232]
O58 - SDL:[MD5.EA7043973D9305235E7B68AC0C6EC889] - 05/06/2009 - 15:37:40 RSHAD . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\system32\drivers\SynTP.sys [266288]
O58 - SDL:[MD5.D45586A9FACB2C9708B10E491EF748A6] - 05/06/2009 - 13:03:36 RSHAD . (.TOSHIBA Corporation. - TOSHIBA ODD Writing Driver for x64..) -- C:\Windows\system32\drivers\tdcmdpst.sys [27272]
O58 - SDL:[MD5.E29A0C5C97615BFFAB138ABE308733B4] - 05/09/2009 - 16:23:26 RSHAD . (.TOSHIBA Corporation - TOSHIBA HDD Protection Driver.) -- C:\Windows\system32\drivers\thpdrv.sys [35392]
O58 - SDL:[MD5.D6704940A79831B4FA271D7A73D291D8] - 05/09/2009 - 09:29:04 RSHAD . (...) -- C:\Windows\system32\drivers\Thpevm.sys [14872]
O58 - SDL:[MD5.9FB4AA68D4E833C795994513BC9E3ACA] - 05/06/2009 - 15:33:08 RSHAD . (.TOSHIBA Corporation - TOSHIBA Bluetooth EC Driver.) -- C:\Windows\system32\drivers\tosrfec.sys [18944]
O58 - SDL:[MD5.DD50A5DF5F7B29FDB6B5FEA728C43DC3] - 05/09/2009 - 18:12:14 RSHAD . (.TOSHIBA Corporation - tos_sps2.) -- C:\Windows\system32\drivers\tos_sps64.sys [504912]
O58 - SDL:[MD5.BE32A8658A0B56474AD4D0BB8AFA8E55] - 05/09/2009 - 15:48:20 RSHAD . (.TOSHIBA Corporation - TOSHIBA TVALZ Filter Driver for x64.) -- C:\Windows\system32\drivers\TVALZFL.sys [14472]
O58 - SDL:[MD5.9A744CC3D804EC38A6C2C65BC3C6FCD8] - 05/09/2009 - 13:00:30 RSHAD . (...) -- C:\Windows\system32\drivers\TVALZ_O.SYS [26968]
O58 - SDL:[MD5.697F0446134CDC8F99E69306184FBBB4] - 21/01/2008 - 03:46:56 RSHAD . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\system32\drivers\uliahci.sys [284728]
O58 - SDL:[MD5.31707F09846056651EA2C37858F5DDB0] - 02/11/2006 - 12:50:54 RSHAD . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win2003.) -- C:\Windows\system32\drivers\ulsata.sys [148072]
O58 - SDL:[MD5.85E5E43ED5B48C8376281BAB519271B7] - 21/01/2008 - 03:46:52 RSHAD . (.Promise Technology, Inc. - Promise SATAII150 Series x64 Windows Driver.) -- C:\Windows\system32\drivers\ulsata2.sys [174696]
O58 - SDL:[MD5.CD03479F2DA26500B203ED075C146A7A] - 19/09/2010 - 20:47:42 RSHAD . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\system32\drivers\usbaapl64.sys [50688]
O58 - SDL:[MD5.BBA210DA84215350A9D377C474CFDE63] - 21/01/2008 - 03:48:42 RSHAD . (...) -- C:\Windows\system32\drivers\USBCAMD2.sys [32512]
O58 - SDL:[MD5.991DD226913B98BE0716E34579E22311] - 05/06/2009 - 02:50:46 RSHAD . (...) -- C:\Windows\system32\drivers\usbd.sys [7680]
O58 - SDL:[MD5.8294B6C3FDB6C33F24E150DE647ECDAA] - 21/01/2008 - 03:46:50 RSHAD . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys [18024]
O58 - SDL:[MD5.A68F455ED2673835209318DD61BFBB0E] - 21/01/2008 - 03:47:25 RSHAD . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys [149048]
O58 - SDL:[MD5.FEF8FE5923FEAD2CEE4DFABFCE3393A7] - 02/11/2006 - 10:40:24 RSHAD . (...) -- C:\Windows\system32\drivers\wacompen.sys [26624]
O58 - SDL:[MD5.9C551A9121639A9779862CB8A6CABF03] - 05/06/2009 - 10:30:14 ---A- . (.COMPAL ELECTRONIC INC. - LPCFilter.) -- C:\Windows\SysWOW64\drivers\LPCFilter.sys [32040]
O58 - SDL:[MD5.49452BFCEC22F36A7A9B9C2181BC3042] - 05/06/2009 - 03:38:33 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\SysWOW64\drivers\pxhelp20.sys [43872]
~ Scan Drivers in 00mn 04s

---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 1.28 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ Scan ADS in 00mn 00s

---\\ Liste des services Legacy (O64)
O64 - Services: CurCS - ??\??\???? - C:\Windows\system32\Drivers\aswFsBlk.sys (aswFsBlk) .(.ALWIL Software - avast! File System Access Blocking Driver.) - LEGACY_ASWFSBLK
O64 - Services: CurCS - 19/01/2010 - C:\Windows\system32\drivers\aswMonFlt.sys (aswMonFlt) .(.ALWIL Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT
O64 - Services: CurCS - ??\??\???? - C:\Windows\system32\Drivers\aswRdr.sys (aswRdr) .(.ALWIL Software - avast! TDI RDR Driver.) - LEGACY_ASWRDR
O64 - Services: CurCS - ??\??\???? - C:\Windows\system32\Drivers\aswSP.sys (aswSP) .(.ALWIL Software - avast! self protection module.) - LEGACY_ASWSP
O64 - Services: CurCS - ??\??\???? - C:\Windows\system32\Drivers\aswTdi.sys (aswTdi) .(.ALWIL Software - avast! TDI Filter Driver.) - LEGACY_ASWTDI
O64 - Services: CurCS - ??\??\???? - C:\Windows\system32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
~ Scan Services in 00mn 01s

---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (. - .) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.html> <htmlfile>[HKCU\..\open\Command] (.Not Key.)
O67 - Shell Spawning: <.com> <>[HKU\..\open\Command] (.Not Key.)
O67 - Shell Spawning: <.exe> <>[HKU\..\open\Command] (.Not Key.)
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
~ Scan Keys in 00mn 00s

---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe
~ Scan Keys in 00mn 00s

---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) -
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Bing) -
~ Scan Keys in 00mn 00s

---\\ Recherche des services démarrés par Svchost (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [26624]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [85504]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\system32\shsvcs.dll [301568]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [49152]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [49152]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [179712]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [718336]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [454656]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [444928]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [98304]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [308224]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [88064]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [61952]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [342016]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [318464]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes Terminal Server.) -- C:\Windows\System32\termsrv.dll [546816]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [2424024]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [1082368]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [301568]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [224256]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [28672]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [45056]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [154112]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\system32\mmcss.dll [37888]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [86528]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [74752]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [854528]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [221696]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service de configuration des services Terminal Server.) -- C:\Windows\system32\sessenv.dll [74752]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [103424]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [178688]
~ Scan Services in 00mn 00s

---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.07BF1173C6C5998B7A8F86A3A9C9DA90] [SPRF][13/09/2011] (...) -- C:\Users\LAURA\AppData\Local\d3d9caps.dat [680]
[MD5.E8115176FE86A4A8B1198679E59B77A4] [SPRF][10/11/2011] (...) -- C:\Users\LAURA\AppData\Local\d3d9caps64.dat [732]
[MD5.E537D5292BA395B72545AC61B2B65FB8] [SPRF][17/05/2011] (...) -- C:\Users\LAURA\AppData\Local\Temp\0.6974451306865791.exe [22898]
[MD5.653D3CB84C500D25823EBEAD417ABF06] [SPRF][29/09/2011] (.McAfee, Inc. - McAfee Scanner Content Installer.) -- C:\Users\LAURA\AppData\Local\Temp\contentDATs.exe [755104]
[MD5.D3E007FBC92173642415D33A0CD83D18] [SPRF][18/09/2010] (.Google Inc. - GoogleToolbarNotifier.) -- C:\Users\LAURA\AppData\Local\Temp\SearchWithGoogleUpdate.exe [426552]
[MD5.B2C46C7064C867F4722A0F51CF18FB62] [SPRF][16/09/2011] (.McAfee, Inc. - McAfee Security Scan Plus Installer.) -- C:\Users\LAURA\AppData\Local\Temp\SecurityScan_Release.exe [3598224]
[MD5.B049DB731AB6107E9B1A4E1384EF5F17] [SPRF][15/12/2011] (...) -- C:\Users\LAURA\AppData\Roaming\6dxrmdxv36oj16o2.dat [8]
[MD5.7EC6AD4D93C64FBAD38B9DEA675BEF5B] [SPRF][08/12/2011] (...) -- C:\Users\LAURA\AppData\Roaming\wklnhst.dat [18634]
[MD5.77D31FB654A53DBFB151C7A8E11E3A02] [SPRF][17/07/2009] (.Adobe Systems Incorporated - Adobe® Flash® Player ActiveX Installer.) -- C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe [1962160]
~ Scan Files in 00mn 01s

---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{E9A21A2A-C1C2-48A0-99F7-E1B48A7E6388}C:\program files (x86)\orange\telephone sur pc\telephonesurpc.exe" | In - Public - P6 - TRUE | .(.France Telecom.) -- C:\Program Files (x86)\Orange\Telephone sur PC\TelephoneSurPC.exe
O87 - FAEL: "UDP Query User{E048BEED-85CA-44A4-BC2F-0EB4E1D6C4E4}C:\program files (x86)\orange\telephone sur pc\telephonesurpc.exe" | In - Public - P17 - TRUE | .(.France Telecom.) -- C:\Program Files (x86)\Orange\Telephone sur PC\TelephoneSurPC.exe
O87 - FAEL: "{212150A3-5E5B-4E73-A62C-24C28A649C9B}" | In - Public - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{4F1C7487-BB6C-41C0-9F51-AB64E0D2A8A3}" | In - Public - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{194B38C9-A8FF-460E-BB94-9DFA6BB0C3CB}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe
O87 - FAEL: "TCP Query User{11450BCE-2B3B-4E42-B912-B0E1F01BBE53}C:\program files (x86)\google\google earth\client\googleearth.exe" | In - Public - P6 - TRUE | .(.Google.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
O87 - FAEL: "UDP Query User{53C32625-868E-4347-967D-C66CFEB94610}C:\program files (x86)\google\google earth\client\googleearth.exe" | In - Public - P17 - TRUE | .(.Google.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
O87 - FAEL: "TCP Query User{B8D6EFA1-D6DD-4428-9EE2-2BA5C61DEAA3}C:\program files (x86)\google\google earth\plugin\geplugin.exe" | In - Public - P6 - TRUE | .(.Google - Google Earth.) -- C:\Program Files (x86)\Google\Google Earth\plugin\geplugin.exe
O87 - FAEL: "UDP Query User{DC18D3E7-B697-4171-BFDE-8FCC972BF321}C:\program files (x86)\google\google earth\plugin\geplugin.exe" | In - Public - P17 - TRUE | .(.Google.) -- C:\Program F
---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "TCP Query User{E9A21A2A-C1C2-48A0-99F7-E1B48A7E6388}C:\program files (x86)\orange\telephone sur pc\telephonesurpc.exe" | In - Public - P6 - TRUE | .(.France Telecom.) -- C:\Program Files (x86)\Orange\Telephone sur PC\TelephoneSurPC.exe
O87 - FAEL: "UDP Query User{E048BEED-85CA-44A4-BC2F-0EB4E1D6C4E4}C:\program files (x86)\orange\telephone sur pc\telephonesurpc.exe" | In - Public - P17 - TRUE | .(.France Telecom.) -- C:\Program Files (x86)\Orange\Telephone sur PC\TelephoneSurPC.exe
O87 - FAEL: "{212150A3-5E5B-4E73-A62C-24C28A649C9B}" | In - Public - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{4F1C7487-BB6C-41C0-9F51-AB64E0D2A8A3}" | In - Public - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{194B38C9-A8FF-460E-BB94-9DFA6BB0C3CB}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe
O87 - FAEL: "TCP Query User{11450BCE-2B3B-4E42-B912-B0E1F01BBE53}C:\program files (x86)\google\google earth\client\googleearth.exe" | In - Public - P6 - TRUE | .(.Google.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
O87 - FAEL: "UDP Query User{53C32625-868E-4347-967D-C66CFEB94610}C:\program files (x86)\google\google earth\client\googleearth.exe" | In - Public - P17 - TRUE | .(.Google.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
O87 - FAEL: "TCP Query User{B8D6EFA1-D6DD-4428-9EE2-2BA5C61DEAA3}C:\program files (x86)\google\google earth\plugin\geplugin.exe" | In - Public - P6 - TRUE | .(.Google - Google Earth.) -- C:\Program Files (x86)\Google\Google Earth\plugin\geplugin.exe
O87 - FAEL: "UDP Query User{DC18D3E7-B697-4171-BFDE-8FCC972BF321}C:\program files (x86)\google\google earth\plugin\geplugin.exe" | In - Public - P17 - TRUE | .(.Google.) -- C:\Program Files (x86)\Google\Google Earth\plugin\geplugin.exe
~ Scan Firewall in 00mn 02s

---\\ Scan Additionnel (O88)
Database Version : 8886 - (12/12/2011)
Clés trouvées (Keys found) : 7
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 2
Fichiers trouvés (Files found) : 0

[HKLM\Software\WOW6432Node\Classes\shopperreports.reporter] =>Adware.ShopperReports
[HKLM\Software\WOW6432Node\Classes\shopperreports.reporter.1] =>Adware.ShopperReports
[HKLM\Software\WOW6432Node\Classes\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227}] =>Adware.ClickPotato
[HKLM\Software\WOW6432Node\Classes\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE}] =>Adware.ClickPotato
[HKLM\Software\WOW6432Node\Classes\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D}] =>Adware.ClickPotato
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}] =>Spyware.BHO
[HKLM\Software\WOW6432Node\Classes\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306}] =>Adware.ClickPotato
C:\ProgramData\ResultBar =>Adware.ResultBar
C:\Program Files (x86)\ResultBar =>Adware.ResultBar
~ Scan Additionnel in 00mn 09s

---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 05/09/2009 203264 | (AMD External Events Utility) . (.AMD.) - C:\Windows\system32\atiesrxx.exe
SR - | Auto 19/09/2010 144672 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 19/01/2010 40384 | (avast! Antivirus) . (.ALWIL Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
SR - | Demand 19/01/2010 40384 | (avast! Mail Scanner) . (.ALWIL Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
SR - | Demand 19/01/2010 40384 | (avast! Web Scanner) . (.ALWIL Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
SR - | Auto 19/09/2010 345376 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
SR - | Auto 05/06/2009 20544 | (camsvc) . (.TOSHIBA.) - C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe
SR - | Auto 05/09/2009 36864 | (ConfigFree Gadget Service) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe
SR - | Auto 05/09/2009 46448 | (ConfigFree Service) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe
SR - | Auto 19/09/2010 65536 | (FTRTSVC) . (.France Telecom SA.) - C:\Program Files (x86)\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
SS - | Demand 05/06/2009 242424 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
SS - | Auto 01/02/2010 135664 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 01/02/2010 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 06/11/2009 182768 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SR - | Demand 19/09/2010 932640 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 16/09/2011 227232 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
SR - | Auto 05/09/2009 564536 | (Thpsrv) . (.TOSHIBA Corporation.) - C:\Windows\system32\ThpSrv.exe
SR - | Auto 05/09/2009 62776 | (TMachInfo) . (.TOSHIBA Corporation.) - C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe
SR - | Auto 05/09/2009 83312 | (TNaviSrv) . (.TOSHIBA Corporation.) - C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
SR - | Auto 05/06/2009 135168 | (TODDSrv) . (.TOSHIBA Corporation.) - C:\Windows\system32\TODDSrv.exe
SR - | Auto 05/09/2009 488288 | (TosCoSrv) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
SS - | Auto 0 | (TOSHIBA Bluetooth Service) . (...) - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
SR - | Auto 05/09/2009 242176 | (TOSHIBA eco Utility Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TECO\TecoService.exe
SR - | Auto 05/06/2009 84480 | (TOSHIBA HDD SSD Alert Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
SR - | Auto 05/09/2009 803696 | (TPCHSrv) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
SS - | Demand 0 | C:\Windows\servicing\TrustedInstaller.exe (TrustedInstaller) . (...) - C:\Windows\servicing\TrustedInstaller.exe
SR - | Auto 21/01/2008 27648 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Scan Services in 00mn 11s

---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
~ Scan MBR in 00mn 02s

---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by LAURA at 15/12/2011 15:11:31

********* Dump file Name *********
~ Scan MBR in 00mn 04s

End of the scan (1302 lines in 03mn 49s)(0)
Utilisateur anonyme
15 déc. 2011 à 16:11
Je t'ai posée une question
Et bien tu ouvres ce lien

Dans la fenêtre chemin à parcourir
Tu cliques sur le bouton "parcourir"

Tu te rends sur ton bureau;tu sélectionnes ce rapport ZHPDiag.txt
Tu cliques ensuite sur "envoyer le fichier"

Un lien dans ce style:
te sera proposé

tu le copies et le mets dans ta prochaine réponse .

aucunement besoin d'aller dans parcourir...
Utilisateur anonyme
15 déc. 2011 à 17:06
aucunement besoin d'aller dans parcourir...

Oui et donc:

"Aucun fichier de déposé"
Utilisateur anonyme
15 déc. 2011 à 17:28

Impeccable ;-))

1)* Télécharger sur le bureau RogueKiller(par Tigzy)
* Quitter tous les programmes en cours
* Sous Vista/Seven , clic droit -> lancer en tant qu'administrateur
* Sinon lancer simplement RogueKiller.exe
* Lorsque demandé, taper 2 et valider
* Un rapport à dû s'ouvrir (RKreport.txt se trouve également à côté de l'exécutable), donner son contenu à la personne qui vous aide
* Si le programme a été bloqué, ne pas hésiter a essayé plusieurs fois. Si vraiment cela ne passe pas (ça peut arriver), le renommer en winlogon.exe

2)Télécharge Malwaresbytes anti malware ici

Bouton »Download free version »

* Installe le (choisis bien "français" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici :

* Potasse le tuto pour te familiariser avec le prg :

(cela dis, il est très simple d'utilisation).

relance Malwaresbytes en suivant scrupuleusement ces consignes :

! Déconnecte toi et ferme toutes applications en cours !

* Lance Malwarebyte's. Sous Vista et Seven (clic droit de la souris « exécuter en tant que administrateur »)

*Procèdes à une mise à jour

*Fais un examen dit "Complet"

--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "Afficher les résultats" " .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " supprimer la sélection " .

Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwaresbytes, le dernier en date)

étant donné que je n'ai plus de problèmes, je vais pas m'embeter non ?
Utilisateur anonyme
15 déc. 2011 à 17:32
Il te reste des problèmes...

Mais c'est comme tu veux.

Tu devrais d'ici peu de nouveau être infecté par cette même vérole.

RogueKiller V6.2.0 [12/12/2011] par Tigzy
mail: tigzyRK<at>gmail<dot>com

Systeme d'exploitation: Windows Vista (6.0.6001 Service Pack 1) 64 bits version
Demarrage : Mode normal
Utilisateur: LAURA [Droits d'admin]
Mode: Suppression -- Date : 15/12/2011 17:35:52

¤¤¤ Processus malicieux: 0 ¤¤¤

¤¤¤ Entrees de registre: 2 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤ localhost
::1 localhost

¤¤¤ MBR Verif: ¤¤¤
--- User ---
[MBR] 98b9ea1cab446591b82f5f6a04cd0594
[BSP] 07382e929ead50918c73afaf8e113dba : MBR Code unknown
Partition table:
0 - [XXXXXX] NTFS [HIDDEN!] Offset (sectors): 2048 | Size: 1572 Mo
1 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 3074048 | Size: 250053 Mo
2 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 491460608 | Size: 248480 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Termine : << RKreport[1].txt >>
en 2 j'ai télécharger mais je ne le trouve pas
Utilisateur anonyme
15 déc. 2011 à 17:45
Tu utilises Firefox?

Regarde dans le dossier >>téléchargements

je ne sais plus, possible que c'était avec firefox
il n'y a rien dans téléchargements