Virus java agent ZB ZD

Bonjour,
J'ai depuis pas mal de temps maintenant de nombreux pbs avec mon pc. J'ai avast (version gratuite) comme anti virus et fais régulièrement des scans au démarrage. Aujourd'hui, il m'a détecté java agent ZB et java agent ZD. Il les a mis en quarantaine mais ne sais pas si cela va régler tous les problèmes que je peux avoir. J'ai visiblement aussi un problème de carte graphique qui me plante mon pc régulièrement. après avoir visité pas mal de forum, je ne sais plus du tout quoi faire, les réponses à ce genre de problèmes étant très différentes. J'ai pensé à formater mais là, j'avoue avoir un peu peur de cette manip. Mes graveurs ne reconnaissent plus depuis longtemps cd et dvd vierges, je ne peux donc plus graver. Je suis désespérée. Je suis novice en la matière et aimerais trouver qq'un qui puisse réellement m'aider. Je vous en remercie d'avance

52 réponses

Résumé de la discussion

Des symptômes constants sur un PC, avec Avast gratuit détectant des Java agent ZB et ZD et des plantages graphiques sous Windows Vista, amènent à rechercher une solution fiable et sécurisée. Plusieurs interventions suggèrent un nettoyage en profondeur des malwares détectés via des outils comme ADWCleaner et Ad-Remover, complété par des scans avec OTL et des guides de suppression manuelle. La meilleure réponse recommande précisément ADWCleaner pour la suppression, puis de partager le rapport final, tout en dégageant des risques liés aux téléchargements douteux et aux outils adware. Pour l'accompagnement, plusieurs conseils portent aussi sur la prudence lors des manipulations système et la nécessité de sauvegarder les données, car les opérations peuvent modifier des éléments critiques.

Bobot (l’IA à votre service)
  1. salut si tu n'as pas la version update 29 de Java , desinstalle

    ==============================

    Télécharge ici :OTL

    enregistre le sur ton Bureau.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    => Clique ici pour voir la Configuration

    ▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"

    netsvcs
    safebootminimal
    safebootnetwork
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\*.ini
    %systemroot%\Tasks\*.*
    %systemroot%\system32\Tasks\*.*
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\config\*.exe /s
    %systemroot%\system32\*.sys
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /s
    CREATERESTOREPOINT


    ▶ Clic sur Analyse.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
    0
    1. J'ai fait tout ce que tu m'as dit, j'ai bien les 2 rapports "Extras. Txt" et "OTL. Txt" mais qd j'ouvre le lien http://cijoint.fr/ j'ai juste une page blanche. Est-ce normal?
      0
    2. http://cjoint.com/?AKDuMaIlcsu
      http://cjoint.com/?AKDuNYBJHXv

      J'espère que tu pourras m'aider... merci
      0
      1. Télécharge et enregistre ADWcleaner sur ton bureau :

        ADWCleaner (Merci à Xplode)

        Lance le,

        clique sur suppression et poste son rapport.

        ================================

        ▶ Télécharge ici : Ad-remover sur ton bureau :

        ▶ Déconnecte toi et ferme toutes applications en cours !

        si tu as XP => double clique
        si tu as Vista ou windows 7 => clic droit "executer en tant que...."


        ▶ sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

        ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

        ▶ Au menu principal choisis "option Nettoyer" et tape sur [entrée] .

        ▶ Laisse travailler l'outil et ne touche à rien ...

        ▶ Poste le rapport qui apparait à la fin , sur le forum ...

        ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

        0
        1. # AdwCleaner v1.319 - Rapport créé le 30/11/2011 à 11:35:48
          # Mis à jour le 20/11/11 à 11h par Xplode
          # Système d'exploitation : Windows Vista (TM) Ultimate Service Pack 2 (32 bits)
          # Nom d'utilisateur : lo - PC-DE-LO (Administrateur)
          # Exécuté depuis : C:\Users\lo\Downloads\adwcleaner.exe
          # Option [Suppression]

          ***** [Services] *****

          ***** [Fichiers / Dossiers] *****

          ***** [Registre] *****

          ***** [Navigateurs] *****

          -\\ Internet Explorer v9.0.8112.16421

          [OK] Le registre ne contient aucune entrée illégitime.

          -\\ Mozilla Firefox v8.0 (fr)

          Profil : ktcew1gd.default
          Fichier : C:\Users\lo\AppData\Roaming\Mozilla\Firefox\Profiles\ktcew1gd.default\prefs.js

          [OK] Le fichier ne contient aucune entrée illégitime.

          -\\ Google Chrome v0.0.0.0

          Fichier : C:\Users\lo\AppData\Local\Google\Chrome\User Data\Default\Preferences

          [OK] Le fichier ne contient aucune entrée illégitime.

          *************************

          AdwCleaner[R1].txt - [34303 octets] - [30/11/2011 11:28:53]
          AdwCleaner[S1].txt - [34620 octets] - [30/11/2011 11:29:34]
          AdwCleaner[R2].txt - [1204 octets] - [30/11/2011 11:35:26]
          AdwCleaner[S2].txt - [1137 octets] - [30/11/2011 11:35:48]

          *************************

          Dossier Temporaire : 10 dossier(s)et 44 fichier(s) supprimés

          ########## EOF - C:\AdwCleaner[S2].txt - [1358 octets] ##########
          0
          1. je n'arrive pas à poster le rapport adRemover
            0
            1. il apparait qd je valide que le titre du message n'est pas renseigné. que faire?
              0
            2. http://cjoint.com/?AKEny542wAc

              Finalement, je l'envoie par le lien que tu m'as donné antérieurement.
              0
          2. il reste plein de clés pourries

            ======================

            desactive ton antivirus
            desactive Windows defender si présent
            desactive ton pare-feu

            Ferme toutes tes appilications en cours

            telecharge et enregistre ceci sur ton bureau :

            Pre_Scan

            si le lien ne fonctionne pas :

            http://www.archive-host.com

            Avertissement: Il y aura une extinction du bureau pendant le scan --> pas de panique.

            une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan.txt" sur le bureau.

            si 'outil est bloqué par l'infection utilise cette version : Version .pif

            si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

            si l'outil semble ne pas avoir fonctionné renomme-le winlogon , ou change son extension en .com ou .scr

            Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

            Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan

            ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

            clique sur ce lien : http://www.cijoint.fr/

            ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

            ▶ Clique sur Ouvrir.

            ▶ Clique sur "Cliquez ici pour déposer le fichier".

            Un lien de cette forme :

            http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

            est ajouté dans la page.

            ▶ Copie ce lien dans ta réponse.

            si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
            0
            1. http://cjoint.com/?AKEwfkF0BxQ

              Voici mon rapport Pre Scan
              0
              1. cet ordinateur est une horreur !

                ==============================

                va falloir choisir un seul antivirus

                avast ou f-secure
                0
                1. Je ne te le fais pas dire! une vraie cata!
                  Mais je pensais avoir un seul antivirus, je n'ai pas souvenir d'avoir mis f-secure.
                  Mais alors que dois je faire pour le reste? tu penses que je devrais le formater? ou y a t il une solution plus soft? je te fais confiance.
                  0
              2. hello on va s en occuper y a une solution plus soft ^^

                sers-toi de cette page pour virer les restes de f-secure pour commencer

                Désinstallation Antivirus , Parefeu , Antispyware
                0
                1. salut!
                  J'ai téléchargé f-secure uninstallation tool. voici le rapport

                  http://cjoint.com/?ALbnxjTKQP9
                  0
                2. En anglais... je ne sais même pas si c'est un rapport d'ailleurs... mais je compte sur toi! encore merci
                  0
              3. je ne comprends pas j'ai plus accès à ton lien pres_scan
                0
                1. ok

                  je vois que tu telecharges beaucoup chez softonic : grosse erreur ce sont des distributeurs d'adwares

                  ==========================

                  oublie spybot il sert à rien

                  ==========================

                  dans ton dossier de telechargements , tu as des installeurs de programmes qui datent de mathusalem , tu devrais faire un grand menage

                  ==========================

                  desinstalle si presents dans la liste :

                  QuickStores-Toolbar
                  ecouter-la-radio Toolbar
                  BitLord
                  spybot

                  ==========================

                  fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

                  Lance Pre_script , une page vierge va s'ouvrir.

                  selectionne tout le texte en gras ci-dessous, puis (clic droit/copier ou ctrl+c) :
                  ___________________________________________________
                  Registry::
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar]
                  "{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}"=-
                  "{6e454792-2f36-46d3-bb20-4be949b6fb8a}"=-
                  "10"=-
                  [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6e454792-2f36-46d3-bb20-4be949b6fb8a}]
                  [-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}]
                  [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AskInstallChecker.exe]
                  [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\askToolbarInstaller.exe]
                  [-HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}]
                  [-HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ec453f3c-c53a-4fc3-a7fb-9f2c30571810}]
                  [-HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}]
                  [-HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0CAE09DD-0F0D-40E9-ADCA-4714872B5493}]
                  [-HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFD74367-2D8D-4E46-ADA2-B83AFE01D518}]
                  [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\092dffec-88e4-4be3-ad9a-f5d138bb9585]
                  [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\27c485d3-92f2-4677-947a-4c704b769642]
                  [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\46c71dbe-f245-4304-9648-5c2d1159439e]
                  [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\ca26a468-7bd9-441a-a8ac-e21c26aff362]
                  [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{096B0472-7D04-4982-9542-2ADF9132FF76}]
                  [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AED78522-9D61-4451-8978-7F3AACFDFC3B}]
                  [-HKCU\Software\BitLord]
                  [-HKLM\Software\BrowserChoice]
                  [-HKLM\Software\ecouter-la-radio]

                  file::
                  C:\Users\lo\Downloads\7L6g8cH8.part
                  C:\Users\lo\Downloads\acrobat-reader_AdbeRdr920_fr_FR.exe
                  C:\Users\lo\Downloads\installer_windows_password_cracker_3_05_Français_French.exe
                  C:\Users\lo\Downloads\AdbeRdr910_fr_FR.exe
                  C:\Users\lo\AppData\Local\ocqwo.dat
                  C:\Windows\Tasks\Ad-Aware Update (Weekly).job

                  folder::
                  C:\Users\lo\AppData\Roaming\Mozilla\Firefox\Profiles\ktcew1gd.default\extensions\quickstores@quickstores.de
                  C:\Users\lo\AppData\Roaming\Mozilla\Firefox\Profiles\ktcew1gd.default\extensions\{1c491116-c175-45e1-a570-6fb14fea8b7b}(36)
                  C:\Users\lo\AppData\Roaming\Mozilla\Firefox\Profiles\ktcew1gd.default\extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352}(37)
                  C:\ProgramData\Spybot - Search & Destroy
                  C:\Users\lo\AppData\Local\BitLord
                  C:\Program Files\ecouter-la-radio

                  Host::

                  ADS::
                  C:\ProgramData\TEMP

                  attrib::

                  clean::

                  ___________________________________________________

                  colle-le ensuite (clic droit/coller ou ctrl+V) dans la page vierge.

                  puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

                  des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

                  poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

                  si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
                  ¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  0
                  1. voilà mon rapport Pre_script :

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 1.0.2.118 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                    ¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

                    Mise à jour : 25/11/2011 | 03.50 Par g3n-h@ckm@n
                    Utilisateur : lo (Administrateurs)
                    Ordinateur : PC-DE-LO
                    Système d'exploitation : Windows Vista (TM) Ultimate (32 bits)
                    Internet Explorer : 9.0.8112.16421
                    Mozilla Firefox : 8.0 (fr)

                    Switchs possibles :

                    processes:: | file:: | folder:: | Registry::
                    Driver:: | replace:: | DNS:: | Command::
                    attrib:: | txt:: | Host:: | NsLook::
                    list:: | IP:: | ADS:: | Kill:: | clean::
                    Reboot:: | MBR:: | Fixmbr::

                    Script : 13:41:53

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                    Modification du registre effectuée

                    ¤

                    Supprimé : C:\Users\lo\Downloads\7L6g8cH8.part
                    Supprimé : C:\Users\lo\Downloads\acrobat-reader_AdbeRdr920_fr_FR.exe
                    Supprimé : C:\Users\lo\Downloads\installer_windows_password_cracker_3_05_Français_French.exe
                    Supprimé : C:\Users\lo\Downloads\AdbeRdr910_fr_FR.exe
                    Supprimé : C:\Users\lo\AppData\Local\ocqwo.dat
                    Supprimé : C:\Windows\Tasks\Ad-Aware Update (Weekly).job

                    ¤

                    Supprimé : C:\Users\lo\AppData\Roaming\Mozilla\Firefox\Profiles\ktcew1gd.default\extensions\quickstores@quickstores.de
                    Supprimé : C:\Users\lo\AppData\Roaming\Mozilla\Firefox\Profiles\ktcew1gd.default\extensions\{1c491116-c175-45e1-a570-6fb14fea8b7b}(36)
                    Supprimé : C:\Users\lo\AppData\Roaming\Mozilla\Firefox\Profiles\ktcew1gd.default\extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352}(37)
                    Supprimé : C:\ProgramData\Spybot - Search & Destroy
                    Supprimé : C:\Users\lo\AppData\Local\BitLord
                    Supprimé : C:\Program Files\ecouter-la-radio

                    ¤

                    ¤ Hosts

                    ::1 localhost
                    # Start of entries inserted by Spybot - Search & Destroy
                    127.0.0.1 www.007guard.com
                    127.0.0.1 007guard.com
                    127.0.0.1 008i.com
                    127.0.0.1 www.008k.com
                    127.0.0.1 008k.com
                    127.0.0.1 www.00hq.com
                    127.0.0.1 00hq.com
                    127.0.0.1 010402.com
                    127.0.0.1 www.032439.com
                    127.0.0.1 032439.com
                    127.0.0.1 www.1001-search.info
                    127.0.0.1 1001-search.info
                    127.0.0.1 www.100888290cs.com
                    127.0.0.1 100888290cs.com
                    127.0.0.1 www.100sexlinks.com
                    127.0.0.1 100sexlinks.com
                    127.0.0.1 www.10sek.com
                    127.0.0.1 10sek.com
                    127.0.0.1 www.123topsearch.com
                    127.0.0.1 123topsearch.com
                    127.0.0.1 www.132.com
                    127.0.0.1 132.com
                    127.0.0.1 www.136136.net
                    127.0.0.1 136136.net

                    [.......]

                    ¤ Hosts Fix

                    127.0.0.1 localhost

                    ¤

                    Alternate Data Streams :

                    C:\ProgramData\TEMP : Deleted :3D0E56AC:$DATA
                    C:\ProgramData\TEMP : Deleted :8CEFE51A:$DATA

                    ¤

                    Disques externes : 84 Objets réattribués
                    Disque Local : 11 Objets réattribués
                    Utilisateurs : 1 Objets réattribués
                    ProgramFiles : 14 Objets réattribués
                    Music : 1499 Objets réattribués
                    Pictures : 3 Objets réattribués
                    Videos : 0 Objets réattribués
                    Downloads : 10 Objets réattribués
                    Desktop : 8 Objets réattribués
                    Links : 0 Objets réattribués
                    Searches : 3 Objets réattribués
                    Contacts : 10 Objets réattribués
                    Saved Games : 0 Objets réattribués
                    Favorites : 0 Objets réattribués
                    Documents : 8 Objets réattribués
                    Windows : 94 Objets réattribués
                    StartMenu : 2 Objets réattribués
                    Librairies : 0 Objets réattribués
                    Quick Launch : 0 Objets réattribués
                    %AppData% : 59 Objets réattribués

                    ¤

                    ¤¤¤¤¤¤¤¤¤¤ | Nettoyage disque

                    Nettoyage du disque effectué

                    ¤

                    Fin : 13:46:36

                    ¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
                    0
                    1. bien refais un scan OTL comme au debut
                      0
                      1. hello tu pourrais laisser les rapports au format txt stp ?
                        0
                        1. J'aimerais bien mais je n'y arrive pas. j'ai eu le même pb la première fois avec les rapports OTL

                          Je te les mets donc ci-dessous:

                          OTL logfile created on: 03/12/2011 12:01:34 - Run 1
                          OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\lo\Downloads
                          Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
                          Internet Explorer (Version = 9.0.8112.16421)
                          Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

                          3,25 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 58,36% Memory free
                          6,71 Gb Paging File | 5,35 Gb Available in Paging File | 79,63% Paging File free
                          Paging file location(s): ?:\pagefile.sys [binary data]

                          %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
                          Drive C: | 288,04 Gb Total Space | 137,75 Gb Free Space | 47,82% Space Free | Partition Type: NTFS
                          Drive D: | 298,09 Gb Total Space | 281,03 Gb Free Space | 94,28% Space Free | Partition Type: NTFS
                          Drive E: | 10,00 Gb Total Space | 6,23 Gb Free Space | 62,28% Space Free | Partition Type: NTFS

                          Computer Name: PC-DE-LO | User Name: lo | Logged in as Administrator.
                          Boot Mode: Normal | Scan Mode: All users
                          Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

                          [color=#E56717]========== Processes (All) ==========/color

                          PRC - [2011/11/29 13:13:53 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\lo\Downloads\OTL.exe
                          PRC - [2011/11/28 19:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                          PRC - [2011/11/22 15:45:32 | 000,161,336 | ---- | M] (Google) -- C:\Users\lo\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
                          PRC - [2011/11/12 22:15:36 | 000,282,008 | ---- | M] () -- C:\ProgramData\media center Bouygues Telecom\media center\external\MediaServerTray.exe
                          PRC - [2011/11/09 23:42:38 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
                          PRC - [2011/11/09 23:42:37 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
                          PRC - [2011/10/15 09:53:00 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
                          PRC - [2010/11/26 16:22:55 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          PRC - [2010/11/04 17:34:06 | 000,171,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe
                          PRC - [2010/10/16 00:24:14 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Users\lo\AppData\Local\Google\Update\GoogleUpdate.exe
                          PRC - [2010/05/14 10:44:46 | 000,248,552 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
                          PRC - [2009/04/11 07:28:08 | 000,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
                          PRC - [2009/04/11 07:27:59 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchProtocolHost.exe
                          PRC - [2009/04/11 07:27:58 | 000,087,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe
                          PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
                          PRC - [2009/04/11 07:27:33 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwm.exe
                          PRC - [2008/01/19 08:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
                          PRC - [2008/01/19 08:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
                          PRC - [2008/01/19 08:33:09 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehtray.exe
                          PRC - [2008/01/19 08:33:09 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehmsas.exe
                          PRC - [2007/07/23 07:27:00 | 004,452,352 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
                          PRC - [2005/08/11 15:30:30 | 000,081,920 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

                          [color=#E56717]========== Modules (All) ==========/color

                          MOD - [2011/11/30 22:28:51 | 001,003,576 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
                          MOD - [2011/11/30 22:28:51 | 000,150,072 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\gtn.dll
                          MOD - [2011/11/29 16:40:55 | 000,027,776 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\defs\11120300\uiext.dll
                          MOD - [2011/11/29 13:13:53 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\lo\Downloads\OTL.exe
                          MOD - [2011/11/28 19:01:30 | 000,210,616 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\1036\uiLangRes.dll
                          MOD - [2011/11/28 19:01:29 | 000,097,280 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\1036\Base.dll
                          MOD - [2011/11/28 19:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                          MOD - [2011/11/28 19:01:22 | 001,821,000 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\CommonRes.dll
                          MOD - [2011/11/28 19:01:22 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
                          MOD - [2011/11/28 19:01:20 | 000,398,576 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswSqLt.dll
                          MOD - [2011/11/28 19:01:20 | 000,220,880 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswProperty.dll
                          MOD - [2011/11/28 19:01:20 | 000,205,448 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswLog.dll
                          MOD - [2011/11/28 19:01:20 | 000,108,616 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswJsFlt.dll
                          MOD - [2011/11/28 19:01:20 | 000,025,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswUtil.dll
                          MOD - [2011/11/28 19:01:19 | 000,048,888 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswEngLdr.dll
                          MOD - [2011/11/28 19:01:18 | 000,682,344 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswAux.dll
                          MOD - [2011/11/28 19:01:18 | 000,317,200 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll
                          MOD - [2011/11/28 19:01:18 | 000,167,832 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswData.dll
                          MOD - [2011/11/28 19:01:18 | 000,163,736 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswCmnIS.dll
                          MOD - [2011/11/28 19:01:18 | 000,097,840 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\aswCmnOS.dll
                          MOD - [2011/11/28 19:01:17 | 000,204,448 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\ashBase.dll
                          MOD - [2011/11/28 19:01:17 | 000,150,352 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\ashTask.dll
                          MOD - [2011/11/28 19:01:17 | 000,122,512 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\ashShell.dll
                          MOD - [2011/11/28 19:01:17 | 000,061,760 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\ashTaskEx.dll
                          MOD - [2011/11/28 19:01:14 | 000,319,784 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\Aavm4h.dll
                          MOD - [2011/11/28 19:01:13 | 000,072,584 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AavmRpch.dll
                          MOD - [2011/11/22 16:24:36 | 000,296,504 | ---- | M] (Google) -- C:\Users\lo\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
                          MOD - [2011/11/22 16:24:32 | 007,222,840 | ---- | M] (Google) -- C:\Users\lo\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll
                          MOD - [2011/11/22 15:45:32 | 000,161,336 | ---- | M] (Google) -- C:\Users\lo\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
                          MOD - [2011/11/17 11:30:03 | 008,527,008 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
                          MOD - [2011/11/12 22:15:36 | 001,935,872 | ---- | M] (Apache Software Foundation) -- C:\ProgramData\media center Bouygues Telecom\media center\external\xerces-c_3_1.dll
                          MOD - [2011/11/12 22:15:36 | 000,768,848 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\media center Bouygues Telecom\media center\external\msvcr100.dll
                          MOD - [2011/11/12 22:15:36 | 000,421,200 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\media center Bouygues Telecom\media center\external\msvcp100.dll
                          MOD - [2011/11/12 22:15:36 | 000,282,008 | ---- | M] () -- C:\ProgramData\media center Bouygues Telecom\media center\external\MediaServerTray.exe
                          MOD - [2011/11/09 23:42:38 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
                          MOD - [2011/11/09 23:42:38 | 000,269,272 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\freebl3.dll
                          MOD - [2011/11/09 23:42:38 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
                          MOD - [2011/11/09 23:42:38 | 000,015,832 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\mozalloc.dll
                          MOD - [2011/11/09 23:42:37 | 015,789,016 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\xul.dll
                          MOD - [2011/11/09 23:42:37 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
                          MOD - [2011/11/09 23:42:37 | 000,801,752 | ---- | M] (sqlite.org) -- C:\Program Files\Mozilla Firefox\mozsqlite3.dll
                          MOD - [2011/11/09 23:42:37 | 000,719,832 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\mozcrt19.dll
                          MOD - [2011/11/09 23:42:37 | 000,719,832 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\mozcpp19.dll
                          MOD - [2011/11/09 23:42:37 | 000,646,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\nss3.dll
                          MOD - [2011/11/09 23:42:37 | 000,371,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\nssckbi.dll
                          MOD - [2011/11/09 23:42:37 | 000,183,256 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\nspr4.dll
                          MOD - [2011/11/09 23:42:37 | 000,166,872 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\softokn3.dll
                          MOD - [2011/11/09 23:42:37 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\ssl3.dll
                          MOD - [2011/11/09 23:42:37 | 000,109,528 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\smime3.dll
                          MOD - [2011/11/09 23:42:37 | 000,105,432 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\nssdbm3.dll
                          MOD - [2011/11/09 23:42:37 | 000,089,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\nssutil3.dll
                          MOD - [2011/11/09 23:42:37 | 000,021,464 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\plc4.dll
                          MOD - [2011/11/09 23:42:37 | 000,020,440 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\plds4.dll
                          MOD - [2011/11/09 23:42:37 | 000,019,416 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\xpcom.dll
                          MOD - [2011/11/09 23:42:37 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
                          MOD - [2011/10/29 13:46:35 | 000,815,256 | ---- | M] (Google Inc.) -- C:\Users\lo\AppData\Local\Google\Update\1.3.21.79\goopdate.dll
                          MOD - [2011/10/15 09:53:00 | 013,205,312 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll
                          MOD - [2011/10/15 09:53:00 | 007,041,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll
                          MOD - [2011/10/15 09:53:00 | 004,678,976 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvui.dll
                          MOD - [2011/10/15 09:53:00 | 003,134,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NvUpdate\NvUpdt.dll
                          MOD - [2011/10/15 09:53:00 | 002,458,432 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll
                          MOD - [2011/10/15 09:53:00 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
                          MOD - [2011/10/15 09:53:00 | 001,169,408 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NvUpdate\NvUpdtr.dll
                          MOD - [2011/10/15 09:53:00 | 000,602,432 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll
                          MOD - [2011/10/15 00:54:42 | 000,154,432 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvStereoApiI.dll
                          MOD - [2011/10/15 00:54:36 | 000,576,832 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPI.dll
                          MOD - [2011/10/15 00:54:26 | 000,265,536 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
                          MOD - [2011/09/01 03:33:10 | 009,704,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
                          MOD - [2011/09/01 03:28:33 | 001,102,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
                          MOD - [2011/09/01 03:28:15 | 001,126,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
                          MOD - [2011/09/01 03:23:27 | 001,791,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
                          MOD - [2011/08/25 17:14:01 | 000,563,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
                          MOD - [2011/08/25 17:14:01 | 000,238,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oleacc.dll
                          MOD - [2011/07/09 08:30:10 | 006,724,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
                          MOD - [2011/06/17 10:29:34 | 000,062,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\MFC90FRA.DLL
                          MOD - [2011/06/17 10:29:23 | 003,781,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll
                          MOD - [2011/06/17 10:29:11 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
                          MOD - [2011/06/17 10:29:11 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
                          MOD - [2011/06/15 17:12:11 | 000,182,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\xmllite.dll
                          MOD - [2011/05/30 08:17:57 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
                          MOD - [2011/05/17 08:27:52 | 000,413,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
                          MOD - [2011/04/29 16:59:36 | 000,276,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\schannel.dll
                          MOD - [2011/04/12 17:07:38 | 000,892,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\kernel32.dll
                          MOD - [2011/03/03 16:40:05 | 000,542,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\AppPatch\AcLayers.dll
                          MOD - [2011/03/03 16:40:05 | 000,458,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\AppPatch\AcSpecfc.dll
                          MOD - [2011/03/02 16:44:26 | 000,168,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dnsapi.dll
                          MOD - [2011/02/22 14:33:12 | 001,068,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
                          MOD - [2011/01/21 17:35:22 | 011,586,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shell32.dll
                          MOD - [2011/01/21 17:35:22 | 000,353,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shlwapi.dll
                          MOD - [2011/01/20 17:08:16 | 000,478,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxgi.dll
                          MOD - [2011/01/20 17:08:06 | 001,029,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
                          MOD - [2011/01/20 17:08:06 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
                          MOD - [2011/01/20 17:08:06 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
                          MOD - [2011/01/20 17:08:06 | 000,160,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
                          MOD - [2011/01/20 17:07:42 | 000,258,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winspool.drv
                          MOD - [2011/01/20 17:07:16 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\stobject.dll
                          MOD - [2011/01/20 17:07:03 | 001,075,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shdocvw.dll
                          MOD - [2011/01/20 17:04:54 | 000,209,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfplat.dll
                          MOD - [2011/01/20 14:47:51 | 000,683,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
                          MOD - [2010/11/26 16:22:55 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          MOD - [2010/11/04 19:55:38 | 000,352,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
                          MOD - [2010/11/04 19:51:35 | 001,748,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\GdiPlus.dll
                          MOD - [2010/11/04 17:34:06 | 000,171,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskeng.exe
                          MOD - [2010/10/16 00:24:14 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Users\lo\AppData\Local\Google\Update\GoogleUpdate.exe
                          MOD - [2010/10/15 14:48:59 | 001,205,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntdll.dll
                          MOD - [2010/10/07 12:23:00 | 000,152,864 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mdnsNSP.dll
                          MOD - [2010/08/31 16:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
                          MOD - [2010/08/31 16:43:52 | 000,531,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_88f3a38569c2c436\comctl32.dll
                          MOD - [2010/08/20 16:57:32 | 000,581,120 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_fr.dll
                          MOD - [2010/08/20 16:57:32 | 000,273,920 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopCommon.dll
                          MOD - [2010/08/20 16:57:32 | 000,123,392 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll
                          MOD - [2010/06/28 18:00:21 | 001,316,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ole32.dll
                          MOD - [2010/06/18 18:31:29 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rtutils.dll
                          MOD - [2010/05/14 10:44:46 | 000,248,552 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
                          MOD - [2010/05/04 20:13:07 | 000,231,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
                          MOD - [2010/04/16 17:46:48 | 000,502,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\usp10.dll
                          MOD - [2010/03/18 12:16:28 | 000,771,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcr100_clr0400.dll
                          MOD - [2010/01/21 16:05:44 | 000,062,464 | ---- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codeca.acm
                          MOD - [2009/12/23 12:33:29 | 000,172,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wintrust.dll
                          MOD - [2009/11/08 09:55:32 | 001,130,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dfshim.dll
                          MOD - [2009/11/08 09:55:32 | 000,297,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mscoree.dll
                          MOD - [2009/10/23 18:10:19 | 000,714,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
                          MOD - [2009/10/01 02:02:04 | 000,334,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceApi.dll
                          MOD - [2009/10/01 02:02:02 | 000,087,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WPDShServiceObj.dll
                          MOD - [2009/10/01 02:01:59 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PortableDeviceTypes.dll
                          MOD - [2009/09/25 03:10:10 | 000,974,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
                          MOD - [2009/09/25 03:07:08 | 000,189,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecsExt.dll
                          MOD - [2009/09/25 03:04:32 | 000,321,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PhotoMetadataHandler.dll
                          MOD - [2009/09/04 12:41:59 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msasn1.dll
                          MOD - [2009/08/24 12:36:45 | 000,377,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winhttp.dll
                          MOD - [2009/08/11 17:44:26 | 001,401,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msxml6.dll
                          MOD - [2009/07/17 14:54:43 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\atl.dll
                          MOD - [2009/07/11 20:01:41 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wlanapi.dll
                          MOD - [2009/06/15 15:53:43 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\secur32.dll
                          MOD - [2009/06/15 15:52:42 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lpk.dll
                          MOD - [2009/06/15 15:51:38 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dciman32.dll
                          MOD - [2009/06/10 12:41:46 | 002,386,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMVCORE.DLL
                          MOD - [2009/04/30 15:01:00 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\Windows\Temp\logishrd\LVPrcInj07.dll
                          MOD - [2009/04/23 13:15:07 | 000,784,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rpcrt4.dll
                          MOD - [2009/04/11 07:28:26 | 000,223,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wscntfy.dll
                          MOD - [2009/04/11 07:28:26 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wscapi.dll
                          MOD - [2009/04/11 07:28:25 | 001,077,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vssapi.dll
                          MOD - [2009/04/11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\user32.dll
                          MOD - [2009/04/11 07:28:25 | 000,287,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wldap32.dll
                          MOD - [2009/04/11 07:28:25 | 000,250,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtapi.dll
                          MOD - [2009/04/11 07:28:25 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winmm.dll
                          MOD - [2009/04/11 07:28:25 | 000,108,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\userenv.dll
                          MOD - [2009/04/11 07:28:25 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wbemsvc.dll
                          MOD - [2009/04/11 07:28:25 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wbemprox.dll
                          MOD - [2009/04/11 07:28:25 | 000,020,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\version.dll
                          MOD - [2009/04/11 07:28:25 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winrnr.dll
                          MOD - [2009/04/11 07:28:24 | 002,205,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SyncCenter.dll
                          MOD - [2009/04/11 07:28:24 | 001,591,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\setupapi.dll
                          MOD - [2009/04/11 07:28:24 | 001,576,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
                          MOD - [2009/04/11 07:28:24 | 000,380,416 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
                          MOD - [2009/04/11 07:28:24 | 000,301,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srchadmin.dll
                          MOD - [2009/04/11 07:28:24 | 000,203,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\uDWM.dll
                          MOD - [2009/04/11 07:28:24 | 000,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spp.dll
                          MOD - [2009/04/11 07:28:24 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samlib.dll
                          MOD - [2009/04/11 07:28:23 | 003,174,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netshell.dll
                          MOD - [2009/04/11 07:28:23 | 002,226,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\networkexplorer.dll
                          MOD - [2009/04/11 07:28:23 | 001,823,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pnidui.dll
                          MOD - [2009/04/11 07:28:23 | 001,541,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\onex.dll
                          MOD - [2009/04/11 07:28:23 | 001,381,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Query.dll
                          MOD - [2009/04/11 07:28:23 | 000,754,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\propsys.dll
                          MOD - [2009/04/11 07:28:23 | 000,467,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netapi32.dll
                          MOD - [2009/04/11 07:28:23 | 000,286,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rasapi32.dll
                          MOD - [2009/04/11 07:28:23 | 000,242,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pdh.dll
                          MOD - [2009/04/11 07:28:23 | 000,228,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SLC.dll
                          MOD - [2009/04/11 07:28:23 | 000,121,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntmarta.dll
                          MOD - [2009/04/11 07:28:23 | 000,098,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\powrprof.dll
                          MOD - [2009/04/11 07:28:23 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\olepro32.dll
                          MOD - [2009/04/11 07:28:22 | 000,805,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NaturalLanguage6.dll
                          MOD - [2009/04/11 07:28:22 | 000,679,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcrt.dll
                          MOD - [2009/04/11 07:28:22 | 000,670,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
                          MOD - [2009/04/11 07:28:22 | 000,351,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
                          MOD - [2009/04/11 07:28:22 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mswsock.dll
                          MOD - [2009/04/11 07:28:22 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
                          MOD - [2009/04/11 07:28:22 | 000,163,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msutb.dll
                          MOD - [2009/04/11 07:28:22 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll
                          MOD - [2009/04/11 07:28:22 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msshooks.dll
                          MOD - [2009/04/11 07:28:21 | 002,241,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msi.dll
                          MOD - [2009/04/11 07:28:20 | 002,012,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\milcore.dll
                          MOD - [2009/04/11 07:28:20 | 000,807,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msctf.dll
                          MOD - [2009/04/11 07:28:20 | 000,564,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll
                          MOD - [2009/04/11 07:28:20 | 000,391,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mscms.dll
                          MOD - [2009/04/11 07:28:20 | 000,378,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imapi2.dll
                          MOD - [2009/04/11 07:28:20 | 000,356,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MediaMetadataHandler.dll
                          MOD - [2009/04/11 07:28:20 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MMDevAPI.dll
                          MOD - [2009/04/11 07:28:20 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imm32.dll
                          MOD - [2009/04/11 07:28:20 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IPHLPAPI.DLL
                          MOD - [2009/04/11 07:28:20 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mpr.dll
                          MOD - [2009/04/11 07:28:20 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsCtfMonitor.dll
                          MOD - [2009/04/11 07:28:20 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\midimap.dll
                          MOD - [2009/04/11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\fastprox.dll
                          MOD - [2009/04/11 07:28:19 | 000,595,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FWPUCLNT.DLL
                          MOD - [2009/04/11 07:28:19 | 000,444,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dsound.dll
                          MOD - [2009/04/11 07:28:19 | 000,297,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gdi32.dll
                          MOD - [2009/04/11 07:28:19 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\es.dll
                          MOD - [2009/04/11 07:28:19 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\eappcfg.dll
                          MOD - [2009/04/11 07:28:19 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehSSO.dll
                          MOD - [2009/04/11 07:28:19 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\EhStorShell.dll
                          MOD - [2009/04/11 07:28:19 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gpapi.dll
                          MOD - [2009/04/11 07:28:19 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\feclient.dll
                          MOD - [2009/04/11 07:28:19 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
                          MOD - [2009/04/11 07:28:18 | 001,985,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
                          MOD - [2009/04/11 07:28:18 | 001,788,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d9.dll
                          MOD - [2009/04/11 07:28:18 | 001,324,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\browseui.dll
                          MOD - [2009/04/11 07:28:18 | 000,978,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\crypt32.dll
                          MOD - [2009/04/11 07:28:18 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscui.dll
                          MOD - [2009/04/11 07:28:18 | 000,450,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\comdlg32.dll
                          MOD - [2009/04/11 07:28:18 | 000,274,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\bcrypt.dll
                          MOD - [2009/04/11 07:28:18 | 000,204,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc.dll
                          MOD - [2009/04/11 07:28:18 | 000,131,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscobj.dll
                          MOD - [2009/04/11 07:28:18 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll
                          MOD - [2009/04/11 07:28:18 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\AudioSes.dll
                          MOD - [2009/04/11 07:28:18 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\authz.dll
                          MOD - [2009/04/11 07:28:18 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscapi.dll
                          MOD - [2009/04/11 07:28:18 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscdll.dll
                          MOD - [2009/04/11 07:28:17 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\advapi32.dll
                          MOD - [2009/04/11 07:28:17 | 000,171,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\apphelp.dll
                          MOD - [2009/04/11 07:28:08 | 000,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
                          MOD - [2009/04/11 07:27:59 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchProtocolHost.exe
                          MOD - [2009/04/11 07:27:58 | 000,087,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFilterHost.exe
                          MOD - [2009/04/11 07:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rsaenh.dll
                          MOD - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
                          MOD - [2009/04/11 07:27:33 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwm.exe
                          MOD - [2009/04/11 07:27:12 | 000,640,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\bthprops.cpl
                          MOD - [2009/04/11 07:27:12 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wdmaud.drv
                          MOD - [2009/04/11 07:27:12 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msacm32.drv
                          MOD - [2009/03/07 11:30:07 | 000,181,856 | ---- | M] (F-Secure Corporation) -- C:\Program Files\SFR\Pack Sécurité\FSPS\program\fslsp.dll
                          MOD - [2008/09/23 14:35:44 | 000,082,528 | ---- | M] (F-Secure Corp.) -- c:\Program Files\SFR\Pack Sécurité\Scanner-Interface\fsgkiapi.dll
                          MOD - [2008/08/31 20:39:34 | 001,425,912 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\OFFICE11\MSXML5.DLL
                          MOD - [2008/01/19 08:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
                          MOD - [2008/01/19 08:38:38 | 000,671,288 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpRtMon.dll
                          MOD - [2008/01/19 08:38:25 | 000,312,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpClient.dll
                          MOD - [2008/01/19 08:37:11 | 000,026,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wtsapi32.dll
                          MOD - [2008/01/19 08:37:11 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wsock32.dll
                          MOD - [2008/01/19 08:37:11 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WSHTCPIP.DLL
                          MOD - [2008/01/19 08:37:11 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wship6.dll
                          MOD - [2008/01/19 08:37:09 | 000,179,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ws2_32.dll
                          MOD - [2008/01/19 08:37:08 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpclsp.dll
                          MOD - [2008/01/19 08:37:04 | 000,195,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnssci.dll
                          MOD - [2008/01/19 08:36:58 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMASF.DLL
                          MOD - [2008/01/19 08:36:56 | 000,140,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winsta.dll
                          MOD - [2008/01/19 08:36:55 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winnsi.dll
                          MOD - [2008/01/19 08:36:48 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbemcomn.dll
                          MOD - [2008/01/19 08:36:48 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vsstrace.dll
                          MOD - [2008/01/19 08:36:47 | 000,240,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\uxtheme.dll
                          MOD - [2008/01/19 08:36:41 | 001,298,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\TMM.dll
                          MOD - [2008/01/19 08:36:40 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\thumbcache.dll
                          MOD - [2008/01/19 08:36:37 | 000,376,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sxs.dll
                          MOD - [2008/01/19 08:36:35 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srclient.dll
                          MOD - [2008/01/19 08:36:24 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shacct.dll
                          MOD - [2008/01/19 08:36:15 | 000,071,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rasman.dll
                          MOD - [2008/01/19 08:36:14 | 000,079,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\QUTIL.DLL
                          MOD - [2008/01/19 08:36:12 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\QAGENT.DLL
                          MOD - [2008/01/19 08:36:07 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pnrpnsp.dll
                          MOD - [2008/01/19 08:36:06 | 000,017,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\PlaySndSrv.dll
                          MOD - [2008/01/19 08:36:01 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oledlg.dll
                          MOD - [2008/01/19 08:35:59 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntshrui.dll
                          MOD - [2008/01/19 08:35:58 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntdsapi.dll
                          MOD - [2008/01/19 08:35:57 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\nsi.dll
                          MOD - [2008/01/19 08:35:45 | 002,643,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsData000c.dll
                          MOD - [2008/01/19 08:35:38 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\nlaapi.dll
                          MOD - [2008/01/19 08:35:35 | 000,050,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NapiNSP.dll
                          MOD - [2008/01/19 08:35:13 | 000,206,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mstask.dll
                          MOD - [2008/01/19 08:35:10 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msidle.dll
                          MOD - [2008/01/19 08:34:55 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msdmo.dll
                          MOD - [2008/01/19 08:34:54 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msacm32.dll
                          MOD - [2008/01/19 08:34:49 | 000,187,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mlang.dll
                          MOD - [2008/01/19 08:34:32 | 000,153,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imagehlp.dll
                          MOD - [2008/01/19 08:34:28 | 000,215,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\icm32.dll
                          MOD - [2008/01/19 08:34:26 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\HotStartUserAgent.dll
                          MOD - [2008/01/19 08:34:22 | 000,890,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FXSST.dll
                          MOD - [2008/01/19 08:34:22 | 000,227,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FXSAPI.dll
                          MOD - [2008/01/19 08:34:21 | 000,403,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FirewallAPI.dll
                          MOD - [2008/01/19 08:34:08 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\eappprxy.dll
                          MOD - [2008/01/19 08:34:07 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\duser.dll
                          MOD - [2008/01/19 08:34:07 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmredir.dll
                          MOD - [2008/01/19 08:34:07 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
                          MOD - [2008/01/19 08:34:03 | 000,522,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ddraw.dll
                          MOD - [2008/01/19 08:34:03 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devenum.dll
                          MOD - [2008/01/19 08:34:02 | 000,798,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dbghelp.dll
                          MOD - [2008/01/19 08:33:59 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\credssp.dll
                          MOD - [2008/01/19 08:33:52 | 000,523,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\clbcatq.dll
                          MOD - [2008/01/19 08:33:49 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cabinet.dll
                          MOD - [2008/01/19 08:33:47 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\avrt.dll
                          MOD - [2008/01/19 08:33:45 | 000,397,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\AudioEng.dll
                          MOD - [2008/01/19 08:33:42 | 000,326,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\actxprxy.dll
                          MOD - [2008/01/19 08:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
                          MOD - [2008/01/19 08:33:09 | 000,125,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehtray.exe
                          MOD - [2008/01/19 08:33:09 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehmsas.exe
                          MOD - [2008/01/19 08:33:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
                          MOD - [2008/01/19 07:14:23 | 000,925,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\FXSRESM.dll
                          MOD - [2007/07/23 07:27:00 | 004,452,352 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
                          MOD - [2006/11/02 13:34:21 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehProxy.dll
                          MOD - [2006/11/02 13:32:42 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\AltTab.dll
                          MOD - [2006/11/02 13:32:41 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\linkinfo.dll
                          MOD - [2006/11/02 13:32:26 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IconCodecService.dll
                          MOD - [2006/11/02 13:32:25 | 000,653,928 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpRes.dll
                          MOD - [2006/11/02 10:46:14 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wlanutil.dll
                          MOD - [2006/11/02 10:46:13 | 000,869,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winbrand.dll
                          MOD - [2006/11/02 10:46:13 | 000,191,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\tapi32.dll
                          MOD - [2006/11/02 10:46:13 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SndVolSSO.dll
                          MOD - [2006/11/02 10:46:13 | 000,111,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shimeng.dll
                          MOD - [2006/11/02 10:46:13 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\TSChannel.dll
                          MOD - [2006/11/02 10:46:12 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\psapi.dll
                          MOD - [2006/11/02 10:46:12 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rasadhlp.dll
                          MOD - [2006/11/02 10:46:07 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msiltcfg.dll
                          MOD - [2006/11/02 10:46:07 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msimg32.dll
                          MOD - [2006/11/02 10:46:05 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mapi32.dll
                          MOD - [2006/11/02 10:46:05 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\hid.dll
                          MOD - [2006/11/02 10:46:05 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ksuser.dll
                          MOD - [2006/11/02 10:46:03 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d8thk.dll
                          MOD - [2006/11/02 10:46:02 | 000,737,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\batmeter.dll
                          MOD - [2006/11/02 09:33:06 | 000,002,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\normaliz.dll
                          MOD - [2006/11/02 09:22:06 | 006,237,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\NlsLexicons000c.dll
                          MOD - [2005/08/11 15:30:30 | 000,081,920 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

                          [color=#E56717]========== Win32 Services (All) ==========/color

                          SRV - File not found [Auto | Stopped] -- -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
                          SRV - [2011/11/28 19:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
                          SRV - [2011/10/15 09:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
                          SRV - [2011/10/15 09:53:00 | 001,136,448 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Windows\System32\nvvsvc.exe -- (nvsvc)
                          SRV - [2011/10/15 00:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
                          SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
                          SRV - [2011/05/26 02:03:24 | 001,177,600 | ---- | M] () [On_Demand | Stopped] -- C:\ProgramData\media center Bouygues Telecom\MediaServer.exe -- (BytelMediaServer)
                          SRV - [2011/05/13 14:27:02 | 001,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
                          SRV - [2011/03/28 19:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
                          SRV - [2011/03/07 14:33:34 | 000,820,520 | ---- | M] (Apple Inc.) [On_Demand | Stopped] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
                          SRV - [2011/03/02 16:44:27 | 000,086,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
                          SRV - [2011/02/22 14:33:09 | 000,797,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\FntCache.dll -- (FontCache)
                          SRV - [2011/02/18 15:37:16 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
                          SRV - [2010/11/26 16:22:55 | 000,182,768 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
                          SRV - [2010/11/04 19:55:12 | 000,601,600 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
                          SRV - [2010/10/07 12:23:00 | 000,345,376 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
                          SRV - [2010/09/22 16:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
                          SRV - [2010/09/06 17:20:29 | 000,125,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
                          SRV - [2010/08/20 16:57:32 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)
                          SRV - [2010/08/17 15:11:37 | 000,128,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
                          SRV - [2010/03/18 12:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
                          SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
                          SRV - [2010/03/04 11:09:24 | 000,135,664 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdatem) Service Google Update (gupdatem)
                          SRV - [2010/03/04 11:09:24 | 000,135,664 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate) Service Google Update (gupdate)
                          SRV - [2010/02/18 14:30:03 | 000,200,704 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\iphlpsvc.dll -- (iphlpsvc)
                          SRV - [2009/10/09 22:56:18 | 001,181,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WsmSvc.dll -- (WinRM) Gestion à distance de Windows (Gestion WSM)
                          SRV - [2009/10/09 22:55:52 | 000,146,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wecsvc.dll -- (Wecsvc)
                          SRV - [2009/10/01 02:01:54 | 000,081,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wpdbusenum.dll -- (WPDBusEnum)
                          SRV - [2009/08/24 12:36:45 | 000,377,344 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\winhttp.dll -- (WinHttpAutoProxySvc)
                          SRV - [2009/08/07 03:23:45 | 001,929,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
                          SRV - [2009/07/11 20:01:42 | 000,513,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
                          SRV - [2009/07/10 12:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (Themes)
                          SRV - [2009/07/10 12:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
                          SRV - [2009/06/15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
                          SRV - [2009/06/15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
                          SRV - [2009/06/15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (Netlogon)
                          SRV - [2009/06/15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
                          SRV - [2009/06/10 12:42:23 | 000,160,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)
                          SRV - [2009/04/30 15:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
                          SRV - [2009/04/11 07:28:26 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
                          SRV - [2009/04/11 07:28:25 | 001,017,856 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (Eventlog)
                          SRV - [2009/04/11 07:28:25 | 000,453,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (stisvc) Acquisition d'image Windows (WIA)
                          SRV - [2009/04/11 07:28:25 | 000,413,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wcncsvc.dll -- (wcncsvc)
                          SRV - [2009/04/11 07:28:25 | 000,282,624 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\w32time.dll -- (W32Time)
                          SRV - [2009/04/11 07:28:25 | 000,222,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
                          SRV - [2009/04/11 07:28:25 | 000,212,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\umrdp.dll -- (UmRdpService)
                          SRV - [2009/04/11 07:28:25 | 000,199,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\WebClnt.dll -- (WebClient)
                          SRV - [2009/04/11 07:28:25 | 000,162,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
                          SRV - [2009/04/11 07:28:25 | 000,140,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wpcsvc.dll -- (WPCSvc)
                          SRV - [2009/04/11 07:28:25 | 000,126,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wersvc.dll -- (WerSvc)
                          SRV - [2009/04/11 07:28:25 | 000,029,184 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\uxsms.dll -- (UxSms)
                          SRV - [2009/04/11 07:28:24 | 000,558,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\sysmain.dll -- (SysMain)
                          SRV - [2009/04/11 07:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs) Appel de procédure distante (RPC)
                          SRV - [2009/04/11 07:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
                          SRV - [2009/04/11 07:28:24 | 000,449,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\termsrv.dll -- (TermService)
                          SRV - [2009/04/11 07:28:24 | 000,311,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
                          SRV - [2009/04/11 07:28:24 | 000,262,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
                          SRV - [2009/04/11 07:28:24 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
                          SRV - [2009/04/11 07:28:24 | 000,107,008 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\regsvc.dll -- (RemoteRegistry)
                          SRV - [2009/04/11 07:28:24 | 000,095,232 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\SCardSvr.dll -- (SCardSvr)
                          SRV - [2009/04/11 07:28:24 | 000,060,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\SLUINotify.dll -- (SLUINotify)
                          SRV - [2009/04/11 07:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
                          SRV - [2009/04/11 07:28:23 | 000,644,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\p2psvc.dll -- (PNRPsvc)
                          SRV - [2009/04/11 07:28:23 | 000,644,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\p2psvc.dll -- (PNRPAutoReg)
                          SRV - [2009/04/11 07:28:23 | 000,644,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\p2psvc.dll -- (p2psvc)
                          SRV - [2009/04/11 07:28:23 | 000,644,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\p2psvc.dll -- (p2pimsvc)
                          SRV - [2009/04/11 07:28:23 | 000,302,592 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\QAGENTRT.DLL -- (napagent)
                          SRV - [2009/04/11 07:28:23 | 000,153,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
                          SRV - [2009/04/11 07:28:20 | 000,438,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\IKEEXT.DLL -- (IKEEXT)
                          SRV - [2009/04/11 07:28:20 | 000,407,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
                          SRV - [2009/04/11 07:28:20 | 000,364,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
                          SRV - [2009/04/11 07:28:19 | 000,576,512 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\gpsvc.dll -- (gpsvc)
                          SRV - [2009/04/11 07:28:19 | 000,564,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\emdmgmt.dll -- (EMDMgmt)
                          SRV - [2009/04/11 07:28:19 | 000,268,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
                          SRV - [2009/04/11 07:28:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\hidserv.dll -- (hidserv)
                          SRV - [2009/04/11 07:28:18 | 000,491,008 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cscsvc.dll -- (CscService)
                          SRV - [2009/04/11 07:28:18 | 000,334,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
                          SRV - [2009/04/11 07:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
                          SRV - [2009/04/11 07:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
                          SRV - [2009/04/11 07:28:18 | 000,204,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcsvc.dll -- (Dhcp)
                          SRV - [2009/04/11 07:28:18 | 000,175,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
                          SRV - [2009/04/11 07:28:18 | 000,129,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
                          SRV - [2009/04/11 07:28:18 | 000,040,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\bthserv.dll -- (BthServ)
                          SRV - [2009/04/11 07:28:18 | 000,040,448 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\certprop.dll -- (SCPolicySvc)
                          SRV - [2009/04/11 07:28:18 | 000,040,448 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\certprop.dll -- (CertPropSvc)
                          SRV - [2009/04/11 07:28:17 | 000,148,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appmgmts.dll -- (AppMgmt)
                          SRV - [2009/04/11 07:28:15 | 000,137,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wbem\WmiApSrv.exe -- (wmiApSrv)
                          SRV - [2009/04/11 07:28:10 | 001,055,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
                          SRV - [2009/04/11 07:28:10 | 000,918,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbengine.exe -- (wbengine)
                          SRV - [2009/04/11 07:28:09 | 000,385,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\vds.exe -- (vds)
                          SRV - [2009/04/11 07:28:07 | 000,039,424 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\servicing\TrustedInstaller.exe -- (TrustedInstaller)
                          SRV - [2009/04/11 07:27:59 | 000,441,344 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SearchIndexer.exe -- (WSearch)
                          SRV - [2009/04/11 07:27:49 | 003,408,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SLsvc.exe -- (slsvc)
                          SRV - [2009/04/11 07:27:45 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\msiexec.exe -- (msiserver)
                          SRV - [2009/04/11 07:27:31 | 002,092,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dfsr.exe -- (DFSR)
                          SRV - [2009/03/30 05:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
                          SRV - [2009/03/07 11:30:27 | 000,215,648 | ---- | M] (F-Secure Corporation) [Auto | Stopped] -- C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe -- (F-Secure Gatekeeper Handler Starter)
                          SRV - [2009/02/18 19:39:20 | 000,043,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
                          SRV - [2009/02/18 19:38:43 | 000,129,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
                          SRV - [2009/02/18 19:38:42 | 000,879,448 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
                          SRV - [2008/09/23 14:37:18 | 000,117,400 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE -- (FSMA)
                          SRV - [2008/09/23 14:35:40 | 000,510,560 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe -- (FSDFWD)
                          SRV - [2008/09/23 14:34:32 | 000,490,080 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe -- (FSAUA)
                          SRV - [2008/09/19 03:03:58 | 000,065,536 | ---- | M] (PostgreSQL Global Development Group) [Auto | Stopped] -- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe -- (pgsql-8.3)
                          SRV - [2008/07/18 12:13:20 | 000,053,760 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Windows\System32\HPZipm12.dll -- (Pml Driver HPZ12)
                          SRV - [2008/07/18 12:13:20 | 000,044,032 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Windows\System32\HPZinw12.dll -- (Net Driver HPZ12)
                          SRV - [2008/04/29 14:36:20 | 000,020,480 | ---- | M] (TechCity Solutions France) [Auto | Running] -- C:\Program Files\BboxUpdate\eSRunService.exe -- (eStantLaunchService)
                          SRV - [2008/04/07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
                          SRV - [2008/01/19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
                          SRV - [2008/01/19 08:37:12 | 000,055,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\WUDFSvc.dll -- (wudfsvc)
                          SRV - [2008/01/19 08:36:52 | 000,062,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wercplsupport.dll -- (wercplsupport)
                          SRV - [2008/01/19 08:36:50 | 000,073,728 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\wdi.dll -- (WdiSystemHost)
                          SRV - [2008/01/19 08:36:50 | 000,073,728 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\wdi.dll -- (WdiServiceHost)
                          SRV - [2008/01/19 08:36:46 | 000,259,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\upnphost.dll -- (upnphost)
                          SRV - [2008/01/19 08:36:42 | 000,075,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\trkwks.dll -- (TrkWks)
                          SRV - [2008/01/19 08:36:39 | 000,056,320 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\tbssvc.dll -- (TBS)
                          SRV - [2008/01/19 08:36:36 | 000,155,648 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ssdpsrv.dll -- (SSDPSRV)
                          SRV - [2008/01/19 08:36:36 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\sstpsvc.dll -- (SstpSvc) Service SSTP (Secure Socket Tunneling Protocol)
                          SRV - [2008/01/19 08:36:21 | 000,084,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\SessEnv.dll -- (SessionEnv)
                          SRV - [2008/01/19 08:36:21 | 000,047,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\Sens.dll -- (SENS)
                          SRV - [2008/01/19 08:36:20 | 000,104,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
                          SRV - [2008/01/19 08:36:20 | 000,019,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\seclogon.dll -- (seclogon)
                          SRV - [2008/01/19 08:36:15 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
                          SRV - [2008/01/19 08:36:14 | 000,243,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\qwave.dll -- (QWAVE)
                          SRV - [2008/01/19 08:36:06 | 001,502,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pla.dll -- (pla)
                          SRV - [2008/01/19 08:36:03 | 000,037,888 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\pcasvc.dll -- (PcaSvc)
                          SRV - [2008/01/19 08:35:57 | 000,018,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
                          SRV - [2008/01/19 08:35:38 | 000,168,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
                          SRV - [2008/01/19 08:35:36 | 000,274,432 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
                          SRV - [2008/01/19 08:35:36 | 000,237,056 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\netprofm.dll -- (netprofm)
                          SRV - [2008/01/19 08:34:56
                          0
                          1. et le second

                            OTL Extras logfile created on: 03/12/2011 12:01:34 - Run 1
                            OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\lo\Downloads
                            Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
                            Internet Explorer (Version = 9.0.8112.16421)
                            Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

                            3,25 Gb Total Physical Memory | 1,90 Gb Available Physical Memory | 58,36% Memory free
                            6,71 Gb Paging File | 5,35 Gb Available in Paging File | 79,63% Paging File free
                            Paging file location(s): ?:\pagefile.sys [binary data]

                            %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
                            Drive C: | 288,04 Gb Total Space | 137,75 Gb Free Space | 47,82% Space Free | Partition Type: NTFS
                            Drive D: | 298,09 Gb Total Space | 281,03 Gb Free Space | 94,28% Space Free | Partition Type: NTFS
                            Drive E: | 10,00 Gb Total Space | 6,23 Gb Free Space | 62,28% Space Free | Partition Type: NTFS

                            Computer Name: PC-DE-LO | User Name: lo | Logged in as Administrator.
                            Boot Mode: Normal | Scan Mode: All users
                            Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

                            [color=#E56717]========== Extra Registry (All) ==========[/color]

                            [color=#E56717]========== File Associations ==========[/color]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
                            .bat [@ = batfile] -- "%1" %*
                            .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
                            .cmd [@ = cmdfile] -- "%1" %*
                            .com [@ = comfile] -- "%1" %*
                            .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
                            .exe [@ = exefile] -- "%1" %*
                            .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
                            .hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation)
                            .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
                            .inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
                            .ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
                            .url [@ = InternetShortcut] -- C:\Windows\System32\rundll32.exe (Microsoft Corporation)
                            .js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
                            .jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
                            .pif [@ = piffile] -- "%1" %*
                            .reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
                            .scr [@ = scrfile] -- "%1" /S
                            .txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
                            .vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
                            .vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
                            .wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
                            .wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)

                            [HKEY_USERS\S-1-5-21-3755630821-3851052671-1714120705-1000\SOFTWARE\Classes\<extension>]
                            .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

                            [color=#E56717]========== Shell Spawning ==========[/color]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
                            batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
                            batfile [open] -- "%1" %*
                            batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
                            chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
                            cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
                            cmdfile [open] -- "%1" %*
                            cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
                            comfile [open] -- "%1" %*
                            cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
                            exefile [open] -- "%1" %*
                            helpfile [open] -- Reg Error: Key error.
                            hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
                            htafile [open] -- C:\Windows\system32\mshta.exe "%1" %* (Microsoft Corporation)
                            htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
                            htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
                            htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
                            htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
                            http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
                            https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
                            inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
                            inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
                            inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
                            inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
                            inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
                            InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
                            InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
                            jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
                            jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
                            jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
                            jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
                            jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
                            jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
                            piffile [open] -- "%1" %*
                            regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
                            regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
                            regfile [merge] -- Reg Error: Key error.
                            regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
                            scrfile [config] -- "%1"
                            scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
                            scrfile [open] -- "%1" /S
                            txtfile [edit] -- Reg Error: Key error.
                            txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
                            txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
                            txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
                            vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
                            vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
                            vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
                            vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
                            vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
                            vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
                            wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
                            wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
                            wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
                            wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
                            Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
                            Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
                            Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
                            Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                            Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
                            Folder [open] -- C:\Windows\explorer.exe (Microsoft Corporation)
                            Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
                            Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
                            Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
                            CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

                            [color=#E56717]========== Security Center Settings ==========[/color]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                            "cval" = 1

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
                            "DisableMonitoring" = 1

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
                            "AntiVirusOverride" = 0
                            "AntiSpywareOverride" = 0
                            "FirewallOverride" = 0
                            "VistaSp1" = Reg Error: Unknown registry data type -- File not found
                            "VistaSp2" = Reg Error: Unknown registry data type -- File not found

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

                            [color=#E56717]========== Firewall Settings ==========[/color]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
                            "DisableNotifications" = 0
                            "EnableFirewall" = 1

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
                            "DisableNotifications" = 0
                            "EnableFirewall" = 1

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
                            "DisableNotifications" = 0
                            "EnableFirewall" = 1

                            [color=#E56717]========== Authorized Applications List ==========[/color]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                            "C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

                            [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
                            "{098DF49B-46C9-48E1-8A4F-28A1C5209DB0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
                            "{0FA3FAD9-78C4-4A73-993F-EF4B9FCF40E2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
                            "{17004F64-FB0F-45F8-95D8-5150DE2C3BAE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
                            "{1CD98122-F2FC-422C-916C-06275F2D4829}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
                            "{1D67F5BC-3765-48E9-9FF3-9869C5E3CD0F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
                            "{26282CE1-21E9-482A-866D-3CBFB55AD3A3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
                            "{2B0FB7CE-3F74-4F71-86E5-8FFC34EFE961}" = lport=4672 | protocol=17 | dir=in | name=emule |
                            "{2D76B2B5-12FB-4138-94EE-71DA9CF72272}" = rport=2869 | protocol=6 | dir=out | app=system |
                            "{2DB9409B-D6AB-40C9-95AF-664AE31997B3}" = lport=8562 | protocol=17 | dir=in | name=emule |
                            "{2E819567-4350-42E1-83E7-D36D435AEC7A}" = lport=2869 | protocol=6 | dir=in | app=system |
                            "{341DDE9F-D4F8-4DAC-B29C-BF98DDC96423}" = lport=3390 | protocol=6 | dir=in | app=system |
                            "{4B951480-9368-48C8-AF46-E5D6020AAAD0}" = lport=10244 | protocol=6 | dir=in | app=system |
                            "{51D23A12-F194-4AB4-8392-DB64702C9C1A}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe |
                            "{61A4217B-DAAD-4DE5-8C03-756756039983}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
                            "{6755DCE0-E8D8-4FC1-9279-942150CD9DEC}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
                            "{6B19C297-0322-4FD3-86F3-4BF5594C0E69}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
                            "{72E4C015-802A-431F-A807-2823EC6A3426}" = rport=138 | protocol=17 | dir=out | app=system |
                            "{7317080D-D4A5-4CE2-8617-8B59A4959942}" = lport=445 | protocol=6 | dir=in | app=system |
                            "{74B676A8-6AFE-4F40-B527-5B7D90369A5B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
                            "{79747EA9-B885-4232-99F8-D36093596AE5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
                            "{85C7B87E-45F6-4A1C-95F6-9F88F9362115}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
                            "{8DC65FDF-E36E-441D-9322-8AF4FC38C7AD}" = lport=8561 | protocol=6 | dir=in | name=emule |
                            "{93B61BD6-1C83-4296-B8F0-0FCE6A655E6F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
                            "{964AB0C0-BE37-46E7-AFF2-B911013EC998}" = rport=445 | protocol=6 | dir=out | app=system |
                            "{997C6F6A-8172-40BB-9499-51307AF8CE7D}" = rport=139 | protocol=6 | dir=out | app=system |
                            "{9D79FD52-D1C3-4515-9D89-F42B6232B843}" = rport=10244 | protocol=6 | dir=out | app=system |
                            "{A33A47B4-6BA3-4814-98BE-960347E054D8}" = rport=137 | protocol=17 | dir=out | app=system |
                            "{A6F871C9-5F2B-4CB3-A247-54683108A862}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
                            "{A9882A64-C47B-420A-9841-12DF823351F6}" = lport=2869 | protocol=6 | dir=in | app=system |
                            "{A9C18A25-6F19-4600-A92D-7812EB71D6BC}" = lport=139 | protocol=6 | dir=in | app=system |
                            "{AAE239AF-0DB3-448C-B4D2-427A56D33545}" = lport=4662 | protocol=6 | dir=in | name=emule |
                            "{BAFF2FFF-737E-416E-ABFF-952E70CEE4D9}" = lport=137 | protocol=17 | dir=in | app=system |
                            "{BC3388D6-5991-489A-B786-A4C726FC8E5F}" = lport=138 | protocol=17 | dir=in | app=system |
                            "{BC84A34B-27ED-4564-B956-CD4D6233F4E6}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
                            "{C5A2A67D-A930-43E9-B73A-A032D756922F}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe |
                            "{D28FCE8D-CA45-4204-90C9-8BA52823B6BD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
                            "{D9C26243-D922-44C2-99DE-C47CDD322B08}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
                            "{ED0DEBEF-121F-44D6-962A-C99B3178F9F2}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
                            "{EDE2CB4E-1263-40FE-AE12-5F86688E765F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
                            "{F8019E8A-86AF-45BB-A4F3-5CBA0CF474B1}" = lport=2869 | protocol=6 | dir=in | app=system |

                            [color=#E56717]========== Vista Active Application Exception List ==========[/color]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
                            "{00638CCE-0296-4F3C-A918-AD37D2D36DD4}" = protocol=17 | dir=in | app=c:\program files\bboxupdate\btliveupdate.exe |
                            "{00CC2144-9730-464E-8D20-635CF61ED3A8}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
                            "{00DD96F4-4169-48C6-A9EF-8AF05813CF25}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
                            "{00E5D804-4E42-4B57-9F8A-F82280853665}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{0102A131-85A1-42D2-B6CC-781D494FF2DE}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{0CBA1FEC-4065-48B6-856E-0A247067D360}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{0CC4DAEC-B3C9-443F-808D-3201611A7057}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{0DD1CD8A-8D25-40D9-A36D-FF12A7474A43}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
                            "{12D4E7DC-4855-4423-B460-BD70551FFD41}" = protocol=17 | dir=in | app=c:\program files\bbox\eskernel.exe |
                            "{131ECCFC-B3F0-4A9E-BD55-23D2D73616AF}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{179CFFDC-6FE8-4230-BEC4-E7291D03F7F3}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{18BA2D45-8A09-4D97-8A2E-779509BD8399}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{1AA1BC13-5BA0-4CFD-924E-C289A164757D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
                            "{1CC6C8A8-0A83-433B-9E0A-43C3FFBDDAD1}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{1E0F2E7F-7E25-431C-AB51-D121B9CDC6E8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
                            "{1F9E8375-6AA4-4D52-8493-EF10909558EB}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{1FCC1458-AD2F-4AB3-96E6-3D995273C07A}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{20BFBBED-2506-4195-8C47-BB269FA64692}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{214844E1-083C-4425-BA14-1B21BFA0E817}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{224463B9-061D-4762-898B-86565E22D22C}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
                            "{231449D7-4F39-4D92-9BA2-1E807AA9E8E6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
                            "{23D96A2D-5EAB-40DB-9A88-EE1A9F26D484}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
                            "{2607B466-B4EA-42FE-8D92-19B44C1AAAC2}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{26FBA003-870B-4870-A03D-350FC19FC7C7}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{2B1D6D05-64FD-4A5D-8BB1-FAE0786A2226}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{2C7D7812-EEE6-4D6B-988B-4951DA98F3C3}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
                            "{2C7E2FF9-FD54-458C-85DB-DCDE885504F4}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
                            "{2D6F48A0-4B63-4EE3-9FDB-83071AFD0B1F}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
                            "{2DFC6D7F-A399-498E-87F9-9E189635D319}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{2EE2CDA3-E96D-41BA-A662-451CE58600E6}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{3075F514-D2CD-4A25-8F85-3C0D4ACF8181}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{327A96DF-99CF-4E3D-A279-65618FCFDAD8}" = protocol=6 | dir=in | app=c:\users\lo\appdata\local\google\google talk plugin\googletalkplugin.exe |
                            "{34699895-7F73-4A63-AF64-66829060F3BD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
                            "{358F33C0-796A-49DB-81E5-705A939E0C30}" = protocol=6 | dir=in | app=c:\program files\shareaza\shareaza.exe |
                            "{3BF73364-B4E4-4F01-8367-BC64A99C1668}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
                            "{3F89A599-FD2C-4B1C-AEAD-4F4E9DA38EE6}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{41B35D27-2F38-4C16-8365-35F686DB6A38}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{43B85E3A-9004-4D31-9CC0-3B7D8F047E19}" = protocol=6 | dir=in | app=c:\users\lo\appdata\local\google\google talk plugin\googletalkplugin.exe |
                            "{4A2B1727-5C3B-4259-93F4-8F919D30A704}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{4B684934-680F-4587-960E-02DE86183818}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
                            "{4BE1A227-F0BE-4535-BE63-59F33AD4CC97}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
                            "{4DF99E93-617D-4A2C-9218-C23BFEC4C91E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
                            "{4F4D76BE-CDCF-4E25-9FB7-D1A31A338C69}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
                            "{529AC4DB-F64B-4C7C-A0BD-72DC4A00771E}" = protocol=6 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsasvr.exe |
                            "{535B80E5-639B-4AEE-AD25-9071F67D3B22}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{57798A17-3FA1-4E0F-A58C-1F0527FD161E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{5846966C-296D-45A2-8711-F16A58B51AA0}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{5BBF0ADE-5E2E-406D-911D-6C07A118D961}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{5E37451F-62AE-431F-8246-637ED6CE79D8}" = protocol=6 | dir=in | app=c:\program files\bboxupdate\btliveupdate.exe |
                            "{5EA18CD8-4133-4523-AC17-9571EE352DFD}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{6381176A-BADF-43BA-A1E8-A20385C34802}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{65FD42E2-040F-4833-B670-10625DFFACE8}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
                            "{67DDA653-C60E-42E3-96AB-6950929CE7C3}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
                            "{686A3B86-F06F-4B7B-A577-5B1FC039200D}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{68A2C468-24FE-4066-8A46-09EB7B208E30}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{699C4F0D-6D29-47AB-8D7D-F07AE6364BCC}" = protocol=6 | dir=in | app=f:\data\eskernel.exe |
                            "{6BC5AB70-A0AE-41E5-B392-C126CB10ABD9}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{6D5569F9-54A5-4C78-BFF1-41C452AF7874}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe |
                            "{6D978F5C-C899-4129-B3E4-E3E881BCB7D5}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{6E06C0F7-3370-4FF6-AD5B-A6B2196C6EE6}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
                            "{6E09C67D-49A7-4C08-83CF-2F288A3A91EB}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{6EE88CE7-3783-40B3-8015-969602447A3D}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
                            "{717A925C-CED0-493F-B3A6-FA2D71858DE4}" = protocol=17 | dir=in | app=c:\users\lo\appdata\local\google\google talk plugin\googletalkplugin.exe |
                            "{782D0065-A8F1-4B72-BA0D-F00B269B9522}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
                            "{7922AA2D-3358-4475-B862-9AA76913F156}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{79A4CE58-230A-4674-AAC9-1F281F999C33}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{7B1D68E7-1388-42A8-9067-526CC33CFCF4}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{7DF29F6C-8497-47C6-9DBC-13BBBDC6DD2A}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{812DC052-0459-4591-B3A9-76A3D6FC2FD4}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{81643AA4-B417-48FB-B3F8-3DD7C28A5987}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{8515C958-ACC7-4B75-95B9-ACD1829D3502}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{85FD7056-C23A-425C-B009-1526FC173DB3}" = protocol=17 | dir=in | app=f:\data\eskernel.exe |
                            "{89315A05-3983-44AE-BA4E-EFBA9CAF3850}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{8B3A9E31-68A8-43B6-8E31-2FEC37339DDD}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
                            "{8C7A6258-A35A-488B-A246-9215C55B576E}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
                            "{8E7A5DB8-3A30-42E2-9C94-BC7821F04BE0}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{8FBC0026-79AA-45A3-BCA1-2BEF7BC67201}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{90978E74-C8DE-491F-9701-65F22FF652FD}" = protocol=17 | dir=in | app=c:\program files\samsung\samsung new pc studio\npsvsvr.exe |
                            "{90FA9328-0C8C-4E26-9AC5-849E77263E20}" = protocol=17 | dir=in | app=c:\programdata\media center bouygues telecom\mediaserver.exe |
                            "{95C24351-E073-4DFF-848B-825E5DB8961C}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{96422981-BD1A-418B-A196-B23CCCAA2C64}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{9743A2B0-0D6E-4A5A-9734-6C9FB395507A}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{97B46CAD-89BB-442A-A673-4F928FC34314}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{97FE543C-7EAE-4CA5-862D-40F47D9602C2}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{97FEA181-DD34-425E-859A-F390C88F94E0}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{99C11BF4-F616-45EA-A1EE-F56F60B59F56}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{9A526F2E-F60F-4ABD-B890-4BD31B76FD25}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{9D7C0EE6-EC42-48EA-89F2-FD1B3F273ED6}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{9EC4CADA-8D1A-4830-97A7-4D0FD0658D82}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{A02C3AC7-273B-450C-B379-E0B6229810B6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
                            "{A0774821-F7EB-441B-B095-124580E9E2C2}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{A25B8B15-5AE7-4AE6-8CE2-468013FB61BD}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{A27E9CDF-01AE-4A91-B0D4-A68EA7C1D30C}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{A73B1BB7-0BE3-481A-A1C6-994D5BEC27A3}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{A7EFF06D-694B-4021-9AED-CED15155BA5D}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{AB8F66EC-92A0-478C-8874-2D6672C13C11}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{ADFADDFE-6F0D-44FC-AFCD-BD2DE8F0B4B7}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{B41032B6-D987-4B84-A81F-55A6F89B5801}" = protocol=17 | dir=in | app=c:\program files\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe |
                            "{B74859F0-C319-41E5-A502-B9D73538F7F7}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{B75448C3-2F32-493A-A2E3-368DCFE76274}" = protocol=17 | dir=in | app=c:\program files\sfr\media center\httpd\httpd.exe |
                            "{B94275E6-5403-4169-8DC0-5E3E79B87B5D}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{B9E69E3F-3D9A-4E50-A754-85E0619A5CCF}" = protocol=6 | dir=in | app=c:\program files\bbox\eskernel.exe |
                            "{BBDC4FFA-8D37-4FB5-8D90-35A06B5BE43A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
                            "{BCA63E2E-320A-44BA-AFFD-5BD58F914FA5}" = protocol=17 | dir=in | app=f:\data\eskernel.exe |
                            "{BCAA702C-300B-4DD6-B7FF-BA07ADBEF117}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{BD0A00D5-C135-4085-8EB9-6727E16C413B}" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
                            "{BD2AAB58-25AC-4325-8715-7B7501007701}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{BE7AB8A8-B646-43C9-B4A7-82A0AF4B120F}" = protocol=17 | dir=in | app=c:\program files\shareaza\shareaza.exe |
                            "{BE9BAA2A-5F24-4CF6-A39B-532E0254AAF4}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{BEBB922E-4414-4A9D-B954-E77408873B82}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{C45914F9-BC93-4353-A6F0-510A7EF1CA16}" = dir=in | app=c:\program files\skype\phone\skype.exe |
                            "{C754BB71-1F97-4EAA-A2AD-4C18F7C4E346}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{C8D75F36-D7C2-47B4-993D-0DF2D62F7D10}" = protocol=6 | dir=in | app=f:\data\eskernel.exe |
                            "{CB217A1A-D2CF-4FE3-B96E-3CD0F708BE42}" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
                            "{CB9C57CB-24EF-43AA-8233-3D428DAA2295}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
                            "{CEC9E69B-6F30-4F7F-A145-C3BFEDA578B7}" = protocol=6 | dir=in | app=c:\program files\sfr\media center\mediacenter.exe |
                            "{CF48FEAA-66D2-4D0F-8DD3-3D6BDFB836E7}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{D21C41F7-4DA5-45C1-9EFA-3F6F01CE60B0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
                            "{D22271E6-C86E-4444-9F92-6FB862408B8B}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{D40FEC94-CE91-452B-819A-95A9040F029A}" = protocol=6 | dir=in | app=c:\program files\sfr\media center\httpd\httpd.exe |
                            "{D52C7BEE-ABDE-4227-BEEC-0466BC766C48}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{DB9FD900-99DC-4197-AFB6-4368CA495EE2}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{DE8E47F5-DD78-474F-95F3-A6358AC56A94}" = protocol=6 | dir=in | app=c:\programdata\media center bouygues telecom\mediaserver.exe |
                            "{E0ED75C8-F015-4D81-B172-40E7E777AC43}" = protocol=17 | dir=in | app=c:\users\lo\appdata\local\google\google talk plugin\googletalkplugin.exe |
                            "{E659EBB1-D9EF-4945-ABE5-7B857E9C639D}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe |
                            "{E977A796-0335-4723-BC34-2A68345F953E}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{EA3A922A-01EC-4B58-812D-7129B94DDA57}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
                            "{EB84B3CE-8582-485E-B882-134465012D87}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe |
                            "{EB9C68BC-F4E0-4B53-B0DC-54E77EDD913B}" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
                            "{EE7974E3-A3A3-4B28-9AB4-9E1764934562}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{F0A15683-7387-4BAC-B5B4-E0B37E08E080}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe |
                            "{F0E4D6EF-56BD-42AF-B507-27067AA2CEE9}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
                            "{F435B6C5-4D1F-4907-B0F7-75BEE0F161DE}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{F4B19EF5-9923-4C31-995B-4C61CFC2D586}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{F595522D-F50F-4A3C-AC43-56E5E21C6CE5}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{F89C9CC8-2A26-48FE-B6D9-53BA0039E499}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
                            "{F8DDD917-2DB0-48A6-8B62-5C0417A11463}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
                            "{F9EF7D79-581D-4F8B-B3D0-4256750C22A0}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{FAE0C17C-0079-474C-9FBF-B5CD85982355}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{FB2D1309-A7F3-493F-98C4-87A14634B93A}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{FE4350AC-E734-4630-B83E-CDB379F31F14}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
                            "{FE9C87B7-0A9D-47DC-A4DF-F04F61DD0134}" = protocol=17 | dir=in | app=c:\program files\sfr\media center\mediacenter.exe |
                            "TCP Query User{00F2BE31-9B8F-4A06-983B-02F6251A7FD5}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
                            "TCP Query User{1D832B17-5581-45CE-95F7-88923D9B5F44}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
                            "TCP Query User{21E75B7C-A60C-474A-AE85-1E89960034F5}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
                            "TCP Query User{2832F6EB-9A59-4DEB-A9AE-AA2C4F0B0C26}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
                            "TCP Query User{29D6A050-4413-48A5-970B-8A5129F70628}C:\program files\bitlord2\bitlord.exe" = protocol=6 | dir=in | app=c:\program files\bitlord2\bitlord.exe |
                            "TCP Query User{72C82D1F-6085-4928-8B34-E150B4B42ECA}C:\program files\logitech\logitech vid\vid.exe" = protocol=6 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
                            "TCP Query User{87BDFCBA-395E-4D00-A081-C317D236276A}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
                            "TCP Query User{8F5CD6B4-8C0F-43B4-B793-4B28DDA30D1A}C:\program files\msn messenger\msnmsgr.exe" = protocol=6 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
                            "TCP Query User{93BCD0FF-0D84-4B79-B996-43EABF332002}C:\users\lo\live-player\live-player.exe" = protocol=6 | dir=in | app=c:\users\lo\live-player\live-player.exe |
                            "TCP Query User{A18DA008-D924-40BD-8FBC-26E963C411A3}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
                            "TCP Query User{B8E0CEC7-5D05-474E-A2E1-4F24331E1B99}C:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe" = protocol=6 | dir=in | app=c:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe |
                            "TCP Query User{B99B1377-8D6C-4CD6-B82C-310E72BB8118}C:\program files\bitlord\bitlord.exe" = protocol=6 | dir=in | app=c:\program files\bitlord\bitlord.exe |
                            "TCP Query User{BC0435BC-9934-4888-B244-C523B22EC438}C:\program files\azureus\azureus.exe" = protocol=6 | dir=in | app=c:\program files\azureus\azureus.exe |
                            "TCP Query User{C8B8365A-348E-4955-A90A-76580506A235}C:\program files\counterpath\eyebeam 1.5\eyebeam.exe" = protocol=6 | dir=in | app=c:\program files\counterpath\eyebeam 1.5\eyebeam.exe |
                            "TCP Query User{EBF86201-F9CE-43B9-8233-29C92364DF7E}C:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe" = protocol=6 | dir=in | app=c:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe |
                            "TCP Query User{EDD0550D-CC92-4023-A63E-779A7C0C79ED}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
                            "TCP Query User{F21FD0F8-B3AA-4AA5-8AB0-95E831F4881E}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
                            "TCP Query User{F550390E-373B-4786-B5A6-165914D619F6}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
                            "UDP Query User{0E715EDA-6260-4FBF-A856-001FF6C2C0C1}C:\program files\bitlord2\bitlord.exe" = protocol=17 | dir=in | app=c:\program files\bitlord2\bitlord.exe |
                            "UDP Query User{2B306EF5-4E33-40D7-82DC-8D2B01A3CFD2}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
                            "UDP Query User{2E7A4F96-A310-4CE2-8833-743AF42361D9}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
                            "UDP Query User{3FD615D1-8457-454A-A6A2-21C4A55CDEAC}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
                            "UDP Query User{4E536F19-43D7-476F-BD15-89F3CFA8CE6A}C:\program files\bitlord\bitlord.exe" = protocol=17 | dir=in | app=c:\program files\bitlord\bitlord.exe |
                            "UDP Query User{4FB9B84C-3DD2-4252-B475-5343543E2779}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
                            "UDP Query User{53BF7F30-CBD3-4D6C-9A56-390B5A5E7AFB}C:\program files\counterpath\eyebeam 1.5\eyebeam.exe" = protocol=17 | dir=in | app=c:\program files\counterpath\eyebeam 1.5\eyebeam.exe |
                            "UDP Query User{5F277AE2-87B3-4141-9F56-E65DC2F0F1A9}C:\program files\azureus\azureus.exe" = protocol=17 | dir=in | app=c:\program files\azureus\azureus.exe |
                            "UDP Query User{6B8A9B0E-269E-4F80-B4BB-26228B2AA94C}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
                            "UDP Query User{855F816B-9FD4-48CC-92C2-AEB66C64DAA1}C:\program files\logitech\logitech vid\vid.exe" = protocol=17 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
                            "UDP Query User{8B19F4B1-54DD-454A-81C5-792B5BC2248E}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
                            "UDP Query User{A7B69373-B600-4B19-A320-525E2DCE9DD0}C:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe" = protocol=17 | dir=in | app=c:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe |
                            "UDP Query User{A82AA4D4-37C4-4978-AFAE-13F6A8237B09}C:\program files\msn messenger\msnmsgr.exe" = protocol=17 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
                            "UDP Query User{DDA301BC-D5D5-4BCE-87F3-93B9894E36A8}C:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe" = protocol=17 | dir=in | app=c:\programdata\media center bouygues telecom\media center\external\mediaservertray.exe |
                            "UDP Query User{E907176A-AF9F-4D0A-A949-346F25066182}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
                            "UDP Query User{E9598118-30DB-4892-8CA4-66F1C1575F84}C:\users\lo\live-player\live-player.exe" = protocol=17 | dir=in | app=c:\users\lo\live-player\live-player.exe |
                            "UDP Query User{F47937EE-2F95-4449-95D9-B81B9637642A}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
                            "UDP Query User{FEFBFD6E-039E-4451-B5DC-BF4542E9C453}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

                            [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
                            "{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
                            "{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
                            "{0542AC3C-963B-4176-8FFD-41029EFC95AA}" = Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)
                            "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
                            "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
                            "{0B786D83-C6AA-4022-BBFD-6A02D8F0121B}" = Fritz11
                            "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
                            "{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
                            "{0F5B4A82-9DAF-3D13-8CB8-AEB25E4A614E}" = Microsoft .NET Framework 4 Client Profile FRA Language Pack
                            "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
                            "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
                            "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
                            "{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
                            "{1AE3E621-E0C0-4aa1-B10B-B3E353A8D110}" = c3100_Help
                            "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
                            "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
                            "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
                            "{2075CB0A-D26F-4DAA-B424-5079296B43BA}" = Windows Live FolderShare
                            "{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
                            "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
                            "{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
                            "{282E5AB2-8E47-4571-B6FA-6B512555B557}" = HP Photosmart.All-In-One Driver Software 8.0 .A
                            "{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
                            "{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
                            "{2B49F593-1DCD-C1C7-CAE0-935BBC867CF0}" = media center Bouygues Telecom
                            "{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
                            "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
                            "{31383A1D-FAE6-435A-9DBD-FDB61C7C8EC9}" = Ulead Photo Express 5 SE
                            "{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6
                            "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
                            "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
                            "{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
                            "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
                            "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
                            "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
                            "{3E31821C-7917-367E-938E-E65FC413EA31}" = Microsoft .NET Framework 3.5 Language Pack SP1 - fra
                            "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
                            "{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
                            "{44F5A980-8A6B-4aca-8D85-EFCE5D67D379}" = AIO_CDA_ProductContext
                            "{469434A4-E972-4828-8288-1C1E721478D9}" = Extension de Windows Live Toolbar (Windows Live Toolbar)
                            "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
                            "{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
                            "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
                            "{4A3C7929-C8E8-4679-8B45-E53BE636EAC9}" = Menus intelligents (Windows Live Toolbar)
                            "{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
                            "{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
                            "{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
                            "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
                            "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
                            "{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = Guide de l'utilisateur
                            "{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
                            "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
                            "{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
                            "{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
                            "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
                            "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
                            "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
                            "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
                            "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
                            "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
                            "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
                            "{6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C}" = Microsoft Works
                            "{6B5F2A58-956E-43F2-B962-D28827C65682}" = PolePositionQuizz
                            "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
                            "{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}" = Complément Messenger
                            "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
                            "{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel(R) PRO Network Connections 12.1.11.0
                            "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
                            "{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
                            "{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
                            "{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
                            "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
                            "{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
                            "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
                            "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
                            "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
                            "{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
                            "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
                            "{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}" = MP3 Player Utilities 4.18
                            "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
                            "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
                            "{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
                            "{90120000-0020-040C-0000-0000000FF1CE}" = Module de compatibilité pour Microsoft Office System 2007
                            "{904CCF62-818D-4675-BC76-D37EB399F917}" = Gestionnaire pour appareils Windows Mobile
                            "{9085040C-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
                            "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
                            "{93695498-4D9E-4D30-9EC4-8B4A8DEFB4F7}" = ChessBase Light 2007
                            "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
                            "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
                            "{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
                            "{97DB07C0-7E43-4C4A-8766-26396935F177}" = Playchess
                            "{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
                            "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
                            "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
                            "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
                            "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
                            "{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
                            "{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
                            "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
                            "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
                            "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
                            "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
                            "{AABDD1F7-DA6B-4BA2-8F81-C7175A846E9C}" = ChessBase Light 2007
                            "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
                            "{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger
                            "{AB61E316-F10B-43eb-B47F-42095835F9CC}" = C3100
                            "{AB93C51F-71F9-4A28-8134-FE1B5B9373E9}" = Windows Live Remote Service Resources
                            "{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
                            "{AC76BA86-7AD7-1036-7B44-AA1000000001}" = Adobe Reader X (10.1.1) - Français
                            "{AC96671C-2001-432C-9826-5266D84EF1DC}" = Logitech Webcam Software
                            "{AF1C9345-B53D-4110-BFBF-A0DD83AEAB83}" = AIO_CDA_Software
                            "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
                            "{B087B0C3-F595-485A-B86B-73326BA8693A}" = OpenOffice.org 2.3
                            "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Pilote 3D Vision 285.62
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panneau de configuration NVIDIA 285.62
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Pilote graphique 285.62
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Pilote du contrôleur 3D Vision 285.62
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Logiciel système PhysX 9.11.0621
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Mises à jour NVIDIA 1.5.20
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
                            "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
                            "{B823632F-3B72-4514-8861-B961CE263224}" = PostgreSQL 8.3
                            "{BCF16F16-AC0E-4ABE-A9EF-412CF484BA51}" = Windows Live Family Safety
                            "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
                            "{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
                            "{C252EB7B-7AE0-46DE-9BEE-DF681B885F13}" = Outil de diagnostic de modem
                            "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
                            "{C716522C-3731-4667-8579-40B098294500}" = Toolbox
                            "{C861504E-2F57-4F95-AB0A-C7C7D8E46A4E}" = Windows Live Family Safety
                            "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
                            "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
                            "{C8E4455F-0F70-4DA2-A9F9-2D56C80E10AD}" = Sibelius Scorch (ActiveX Only)
                            "{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
                            "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
                            "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
                            "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype(TM) 4.2
                            "{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
                            "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
                            "{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
                            "{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}" = HP Update
                            "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
                            "{DFDBE1F9-04CE-4645-BB6C-4590EABC7A9C}" = Windows Live Remote Client Resources
                            "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
                            "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
                            "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
                            "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
                            "{E7044E25-3038-4A76-9064-344AC038043E}" = Mise à jour du pilote du Gestionnaire pour appareils Windows Mobile
                            "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
                            "{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
                            "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
                            "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
                            "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
                            "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
                            "{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
                            "{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
                            "{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
                            "3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0)
                            "Adobe AIR" = Adobe AIR
                            "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
                            "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
                            "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
                            "avast" = avast! Free Antivirus
                            "BboxUpdate" =
                            "Bouygues Telecom - désinstallation Bbox" =
                            "CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 PCI V.92 Modem
                            "com.bytel.mediacenter" = media center Bouygues Telecom
                            "Dell Support Center" = Dell Support Center
                            "Digital Camera Driver" = Digital Camera Driver
                            "E24870CB6AA1C3511635FF9020A3E9471287FBE7" = Package de pilotes Windows - MobileTop (sshpmdm) Modem (01/26/2008 2.6.0.0)
                            "eMule" = eMule
                            "FormatFactory" = FormatFactory 2.30
                            "F-Secure Product 444" =
                            "Google Desktop" = Google Desktop
                            "HP Imaging Device Functions" = HP Imaging Device Functions 8.0
                            "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
                            "HPExtendedCapabilities" = HP Customer Participation Program 8.0
                            "HPOCR" = HP OCR Software 8.0
                            "lvdrivers_12.0" = Coffret de pilotes Logitech Webcam Software
                            "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
                            "media center Bouygues Telecom" = media center Bouygues Telecom
                            "MessenPass" = NirSoft MessenPass
                            "Microsoft .NET Framework 3.5 Language Pack SP1 - fra" = Module linguistique Microsoft .NET Framework 3.5 SP1- fra
                            "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
                            "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
                            "Microsoft .NET Framework 4 Client Profile FRA Language Pack" = Module linguistique Microsoft .NET Framework 4 Client Profile FRA
                            "Mozilla Firefox 8.0 (x86 fr)" = Mozilla Firefox 8.0 (x86 fr)
                            "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
                            "Picasa 3" = Picasa 3
                            "PROSetDX" = Intel(R) PRO Network Connections 12.1.11.0
                            "RealPlayer 12.0" = RealPlayer
                            "SystemRequirementsLab" = System Requirements Lab
                            "Uninstall_is1" = Uninstall 1.0.0.1
                            "VLC media player" = VLC media player 1.0.1
                            "WinLiveSuite" = Windows Live
                            "WinRAR archiver" = Archiveur WinRAR

                            [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

                            [HKEY_USERS\S-1-5-21-3755630821-3851052671-1714120705-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
                            "309a46b1dc89b774" = Dell Driver Download Manager
                            "Ad-Remover" = Ad-Remover
                            "f031ef6ac137efc5" = Dell Driver Download Manager
                            "Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
                            "Notification de cadeaux MSN" = Notification de cadeaux MSN
                            "uTorrent" = µTorrent

                            [color=#E56717]========== Last 10 Event Log Errors ==========[/color]

                            [ Antivirus Events ]
                            Error - 28/02/2009 20:15:05 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 23/06/2009 20:00:49 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 30/06/2009 17:48:20 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 19/07/2009 19:15:57 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 18/09/2009 21:04:11 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 18/09/2009 21:04:11 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 13/10/2009 09:30:12 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 05/11/2009 23:00:30 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 12/12/2009 00:35:01 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            Error - 10/01/2010 00:30:00 | Computer Name = PC-de-lo | Source = avast! | ID = 33554522
                            Description =

                            [ Application Events ]
                            Error - 02/12/2011 16:18:55 | Computer Name = PC-de-lo | Source = VSS | ID = 8194
                            Description = Erreur du service de cliché instantané des volumes : erreur lors de
                            l'interrogation de l'interface IVssWriterCallback. hr = 0x80070005. Cette erreur
                            est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur
                            ou du demandeur. Opération : Données du rédacteur en cours de collecte Contexte :

                            ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220} Nom du rédacteur:
                            System Writer ID d'instance du rédacteur: {e3079b92-279c-4c88-aa22-d57f55d6da47}

                            Error - 02/12/2011 16:29:07 | Computer Name = PC-de-lo | Source = RapiMgr | ID = 2
                            Description = Failed to start the Windows Mobile-based device connectivity service
                            due to EnableRAPIMgr(0x80070005) failure (see data for failure code).

                            Error - 02/12/2011 16:29:07 | Computer Name = PC-de-lo | Source = RapiMgr | ID = 2
                            Description = Failed to start the Windows Mobile-based device connectivity service
                            due to EnableRAPIMgr(0x80070005) failure (see data for failure code).

                            Error - 03/12/2011 06:47:36 | Computer Name = PC-de-lo | Source = PostgreSQL | ID = 0
                            Description = 2011-12-03 10:47:36 GMT FATAL: bogus data in lock file "postmaster.pid":
                            ""

                            Error - 03/12/2011 06:51:42 | Computer Name = PC-de-lo | Source = RapiMgr | ID = 2
                            Description = Failed to start the Windows Mobile-based device connectivity service
                            due to EnableRAPIMgr(0x80070005) failure (see data for failure code).

                            Error - 03/12/2011 06:51:42 | Computer Name = PC-de-lo | Source = SecurityCenter | ID = 3
                            Description = Le service Centre de sécurité de Windows n'a pas pu établir de requêtes
                            d'événements avec WMI pour contrôler le programme antivirus, le logiciel anti-espion
                            et le pare-feu tiers.

                            Error - 03/12/2011 06:51:44 | Computer Name = PC-de-lo | Source = RapiMgr | ID = 2
                            Description = Failed to start the Windows Mobile-based device connectivity service
                            due to EnableRAPIMgr(0x80070005) failure (see data for failure code).

                            Error - 03/12/2011 06:54:04 | Computer Name = PC-de-lo | Source = MsiInstaller | ID = 11706
                            Description = Produit : Roxio Update Manager -- Erreur 1706. Package d'installation
                            pour le produit Roxio Update Manager introuvable. Réessayez d'exécuter Windows
                            Installer avec un package d'installation valide UM.MSI.

                            Error - 03/12/2011 07:04:22 | Computer Name = PC-de-lo | Source = RapiMgr | ID = 2
                            Description = Failed to start the Windows Mobile-based device connectivity service
                            due to EnableRAPIMgr(0x80070005) failure (see data for failure code).

                            Error - 03/12/2011 07:04:23 | Comp
                            0
                          2. voilà, c'est vrai c'est long.... j'espère pouvoir régler tous ces problèmes.
                            0
                        • 1
                        • 2
                        • 3