Rapport de ZHPDiag v2013.7.16.29 par Nicolas Coolman, Update du 17/07/2013 Run by Administrateur at 19/07/2013 18:53:10 WebSite: http://nicolascoolman.webs.com State : Version à jour. WhiteList : Disable High Elevated Privileges : OK UAC : Not Found ---\\ Web Browser MSIE: Internet Explorer v8.0.6001.18702 MFIE: Mozilla Firefox 22.0 (Defaut) ---\\ Windows Product Information ~ Langage: Français Windows XP Professional Service Pack 3 (Build 2600) Windows Automatic Updates : OK Windows Genuine Advantage : OK ---\\ System Protection Avira Free Antivirus v13.0.0.3880 Malwarebytes Anti-Malware version 1.75.0.1300 ESET Online Scanner v3 ---\\ System Optimizer CCleaner v4.03 =>Piriform Ltd ---\\ Peer To Peer (P2P) ---\\ Software Update Adobe Flash Player 11 Plugin Adobe Reader XI Java 7 Update 25 ---\\ System Information ~ Processor: x86 Family 15 Model 4 Stepping 9, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 2047 MB (69% free) System Restore: Activé (Enable) System drive C: has 16 GB (32%) free of 49 GB ---\\ Logged in mode ~ Computer Name: PCFIXE ~ User Name: Administrateur ~ All Users Names: SUPPORT_388945a0, RB, HelpAssistant, ASPNET, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Documents and Settings\Administrateur\Application Data\ ~ %Desktop% : C:\Documents and Settings\Administrateur\Bureau\ ~ %Favorites% : C:\Documents and Settings\Administrateur\Favoris\ ~ %LocalAppData% : C:\Documents and Settings\Administrateur\Local Settings\Application Data\ ~ %StartMenu% : C:\Documents and Settings\Administrateur\Menu Démarrer\ ~ %Windir% : C:\WINDOWS\ ~ %System% : C:\WINDOWS\system32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 16 Go of 49 Go) D:\ Hard drive, Flash drive, Thumb drive (Free 7 Go of 91 Go) E:\ Hard drive, Flash drive, Thumb drive (Free 3 Go of 10 Go) H:\ CD-ROM drive (Not Inserted) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 30 Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 - 03:34:03.) -- C:\WINDOWS\Explorer.exe [1037824] [MD5.08125B740C62E6DEA9483A15043AD0D5] - (.Microsoft Corporation - Internet Extensions for Win32.) (.07/06/2013 - 22:48:38.) -- C:\WINDOWS\system32\wininet.dll [920064] [MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 - 03:34:28.) -- C:\WINDOWS\system32\Winlogon.exe [512000] [MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/08/2011 - 14:49:54.) -- C:\WINDOWS\system32\Drivers\AFD.sys [138496] [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/04/2008 - 19:40:30.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512] [MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.13/04/2008 - 20:14:21.) -- C:\WINDOWS\system32\Drivers\Cdfs.sys [63744] [MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.13/04/2008 - 19:40:46.) -- C:\WINDOWS\system32\Drivers\Cdrom.sys [62976] [MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) (.14/04/2008 - 02:57:38.) -- C:\WINDOWS\system32\Drivers\Fips.sys [44672] [MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.13/04/2008 - 17:36:05.) -- C:\WINDOWS\system32\Drivers\HDAudBus.sys [144384] [MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - (.Microsoft Corporation - Pilote de port i8042.) (.14/04/2008 - 03:00:52.) -- C:\WINDOWS\system32\Drivers\i8042prt.sys [54144] [MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.13/04/2008 - 19:40:58.) -- C:\WINDOWS\system32\Drivers\Imapi.sys [42112] [MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.13/04/2008 - 19:57:15.) -- C:\WINDOWS\system32\Drivers\IpNat.sys [152832] [MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.13/04/2008 - 20:19:42.) -- C:\WINDOWS\system32\Drivers\IPSec.sys [75264] [MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/07/2011 - 14:29:31.) -- C:\WINDOWS\system32\Drivers\MRxSmb.sys [456320] [MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.13/04/2008 - 20:21:00.) -- C:\WINDOWS\system32\Drivers\netBT.sys [162816] [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/04/2008 - 20:15:53.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976] [MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/04/2008 - 03:09:40.) -- C:\WINDOWS\system32\Drivers\Parport.sys [80384] [MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.13/04/2008 - 20:19:43.) -- C:\WINDOWS\system32\Drivers\Rasl2tp.sys [51328] [MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/04/2008 - 19:32:51.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224] [MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) (.14/04/2008 - 02:57:34.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58752] [MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.14/04/2008 - 02:56:04.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53376] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/978 ~ Mes musiques (My Musics) : 2/7914 ~ Mes Favoris (My Favorites) : 1/5 ~ Mes Documents (My Documents) : 2/17601 ~ Mon Bureau (My Desktop) : 0/30 ~ Menu demarrer (Programs) : 1/57 ~ Hidden Files: Scanned in 00mn 14s ---\\ Processus lancés [MD5.A03F8B3BF819A1C8C9661A71FE53F09F] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\WINDOWS\system32\Ati2evxx.exe [573440] [PID.940] [MD5.C245E08EC469A52A622EFDC9787A0DCC] - (.Adobe Systems Incorporated - Adobe Photoshop Elements 10.0 (component).) -- C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624] [PID.1348] [MD5.D5C9856D2C2F8909C0A553E4AC8E3873] - (.Outertech - Cacheman - controls RAM and File Cache.) -- C:\Program Files\Cacheman\CachemanServ.exe [238152] [PID.1432] [MD5.58BF7714A312698108A96D0DE2BB6825] - (.CobianSoft, Luis Cobian - Cobian Backup Gravity VSC Requester.) -- C:\Program Files\Cobian Backup 11\cbVSCService11.exe [67584] [PID.1200] [MD5.793EF38A5FD086C3C8E48A8A861562ED] - (.Microsoft Corporation - Content Index service.) -- C:\WINDOWS\system32\cisvc.exe [5632] [PID.1560] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [PID.1920] [MD5.8726802EA4FBFFA3FD54FD2449BF51D4] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe [217992] [PID.1956] [MD5.4F4D4AA1E0849FECC0CF5AACD59030B5] - (.Oracle Corporation - Java Quick Starter Service.) -- C:\Program Files\Java\jre7\bin\jqs.exe [182184] [PID.172] [MD5.E0E4A1F81A7D69C595A8A9DDAD084C19] - (.Nero AG - NeroUpdate.) -- C:\Program Files\Nero\Update\NASvc.exe [769432] [PID.208] [MD5.E50A782AA8D261116C7426EEBB21C1F2] - (.Nitro PDF Software - Nitro PDF Spool Service.) -- C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624] [PID.256] [MD5.0C5AD6A1BB7A828EEEF9DE893C019616] - (.SafeNet, Inc. - Sentinel RMS Development Kit License Manage.) -- C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe [847872] [PID.336] [MD5.A6CDD9E3288C9C11D204B8E2F98D0B61] - (...) -- C:\Program Files\VIA\RAID\vialogsv.exe [55920] [PID.536] [MD5.C1DB9BDF885C2F1ADC15264FBEA2788F] - (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961] [PID.3648] [MD5.F881B72FA102295208B33DC22E84A3FC] - (.Soft4Ever - Look 'n' Stop Firewall.) -- C:\Program Files\looknstop\looknstop.exe [593128] [PID.3656] [MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [253816] [PID.3668] [MD5.8491FDA93507F2F27FFBA11372764086] - (.Avira Operations GmbH & Co. KG - Avira On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088] [PID.1628] [MD5.68C105908A54D734D2B154DB546F562E] - (.Avira Operations GmbH & Co. KG - Avira Shadow Copy Service.) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe [76856] [PID.2820] [MD5.99387251353598C939592FAF40DF8AA9] - (.Avira Operations GmbH & Co. KG - Avira Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024] [PID.3668] [MD5.4631FF0EE2964CCDC646AF807CB778F5] - (.Avira Operations GmbH & Co. KG - Avira System Tray Tool.) -- c:\program files\avira\antivir desktop\avgnt.exe [345144] [PID.3300] [MD5.72999AA48322DA948CE50C08B414A0EC] - (.Microsoft Corporation - Indexing Service filter daemon.) -- C:\WINDOWS\system32\cidaemon.exe [8192] [PID.3972] [MD5.C8D28F8B498CADBB9445AC4545BD41B7] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [920472] [PID.2876] [MD5.9F419AD2EBFF9044CA845484CFBEAC48] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [7719936] [PID.3696] ~ Processes Running: Scanned in 00mn 01s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\prefs.js M3 - MFPP: Plugins - [Administrateur] -- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\searchplugins\pc-astuces.xml M0 - MFSP: prefs.js [Administrateur - s5ykwdfj.default] http://ixquick.com M2 - MFEP: prefs.js [Administrateur - s5ykwdfj.default\firefox@ghostery.com] [] Ghostery v2.9.6 (..) M2 - MFEP: prefs.js [Administrateur - s5ykwdfj.default\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)] [WOT] WOT v20120910 (..) M2 - MFEP: prefs.js [Administrateur - s5ykwdfj.default\{ab91efd4-6975-4081-8552-1b3922ed79e2}] [] HP Detect v1.0.24.1 (..) P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- C:\Program Files\Picasa3\npPicasa3.dll P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.25.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\WINDOWS\system32\npDeployJava1.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.25.2] - (.Oracle Corporation - Next Generation Java Plug-in 10.25.2 for Mozilla browsers.) -- C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.20513.0.) -- c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll P2 - FPN: [HKLM] [@microsoft.com/OfficeAuthz,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\Program Files\Microsoft Office\Office14\NPAUTHZ.dll P2 - FPN: [HKLM] [@microsoft.com/SharePoint,version=14.0] - (.Microsoft Corporation - The plug-in allows you to open and edit files using Microsoft Office a.) -- C:\Program Files\Microsoft Office\Office14\NPSPWRAP.dll P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll P2 - FPN: [HKLM] [@nitropdf.com/NitroPDF] - (.Nitro PDF - Nitro PDF plugin for Firefox and Chrome.) -- C:\Program Files\Nitro\Reader 3\npnitromozilla.dll P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.450] - (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.448] - (.RealNetworks, Inc. - 6.0.12.448.) -- C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.02.) -- C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll P2 - FPN: [HKLM] [adobe.com/AdobeAAMDetect] - (.Adobe Systems - A plugin to detect whether the Adobe Application Manager is installed.) -- C:\Program Files\Fichiers communs\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll ~ Firefox Browser: 21 Scanned in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ixquick.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems - A plugin to detect whether the Adobe Application Manager is installed.) (No version) -- (.not file.) R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0 ~ IE Browser: 12 Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\WINDOWS\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ~ Keys: Scanned in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 03s ~ Nombre de lignes (Lines number): 11442 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office\Office14\URLREDIR.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\jp2ssv.dll ~ BHO: 5 Scanned in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [HOSTS Anti-Adware_PUPs] . (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe O4 - HKLM\..\Run: [Look 'n' Stop] . (.Soft4Ever - Look 'n' Stop Firewall.) -- C:\Program Files\looknstop\looknstop.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe O4 - HKLM\..\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe O4 - HKUS\S-1-5-21-583907252-1284227242-725345543-500\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe ~ Application: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Programs: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe ~ Global Startup: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -- Clé orpheline O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll ~ Winsock: 3 Scanned in 00mn 00s ---\\ Objets ActiveX (Downloaded Program Files)(O16) O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} ((no name)) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1321351512390 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} ((no name)) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1356518037015 ~ Objets ActiveX: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{8F5CB321-CC4F-44D8-8E5F-87A9D934CBFB}: DhcpNameServer = 62.2.24.158 62.2.17.60 62.2.24.162 62.2.17.61 O17 - HKLM\System\CS1\Services\Tcpip\..\{8F5CB321-CC4F-44D8-8E5F-87A9D934CBFB}: DhcpNameServer = 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158 O17 - HKLM\System\CS2\Services\Tcpip\..\{8F5CB321-CC4F-44D8-8E5F-87A9D934CBFB}: DhcpNameServer = 62.2.24.158 62.2.17.60 62.2.24.162 62.2.17.61 O17 - HKLM\System\CS3\Services\Tcpip\..\{8F5CB321-CC4F-44D8-8E5F-87A9D934CBFB}: DhcpNameServer = 62.2.24.158 62.2.17.60 62.2.24.162 62.2.17.61 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.2.24.158 62.2.17.60 62.2.24.162 62.2.17.61 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll O18 - Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE14\MSOXMLMF.dll ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: AtiExtEvent . (.ATI Technologies Inc. - ATI External Event Utility DLL Module.) -- C:\WINDOWS\system32\Ati2evxx.dll O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll O20 - Winlogon Notify: LBTWlgn . (.Logitech, Inc. - Logitech Bluetooth Service.) -- c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\WINDOWS\system32\WgaLogon.dll O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll ~ SSODL: 5 Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Adobe Active File Monitor V10 (AdobeActiveFileMonitor10.0) . (.Adobe Systems Incorporated - Adobe Photoshop Elements 10.0 (component).) - C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe O23 - Service: Avira Planificateur (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Avira Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Protection temps réel (AntiVirService) . (.Avira Operations GmbH & Co. KG - Avira On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: (Ati HotKey Poller) . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart (ATI Smart) . (.Pas de propriétaire - ATI Smart.) - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Cacheman Service (CachemanService) . (.Outertech - Cacheman - controls RAM and File Cache.) - C:\Program Files\Cacheman\CachemanServ.exe O23 - Service: Cobian Backup 11 Service « Volume Shadow (cbVSCService11) . (.CobianSoft, Luis Cobian - Cobian Backup Gravity VSC Requester.) - C:\Program Files\Cobian Backup 11\cbVSCService11.exe O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: HOSTS Anti-PUPs (HOSTS Anti-PUPs) . (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Oracle Corporation - Java Quick Starter Service.) - C:\Program Files\Java\jre7\bin\jqs.exe O23 - Service: Nero Update (NAUpdate) . (.Nero AG - NeroUpdate.) - C:\Program Files\Nero\Update\NASvc.exe O23 - Service: NitroPDFReaderDriverCreatorReadSpool3 (NitroReaderDriverReadSpool3) . (.Nitro PDF Software - Nitro PDF Spool Service.) - C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe O23 - Service: Sentinel RMS License Manager (Sentinel RMS License Manager) . (.SafeNet, Inc. - Sentinel RMS Development Kit License Manage.) - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: VRAID Log Service (VRAID Log Service) . (...) - C:\Program Files\VIA\RAID\vialogsv.exe ~ Services: 15 Scanned in 00mn 06s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ BootExecute (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-PCFIXE-Administrateur.job [368] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-PCFIXE-RB.job [344] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1068] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1072] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\MyDefrag v4.3.1 Daily.job [350] [MD5.476BB014F3F68C0C15EDDD5B444DA8FF] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [257416] [MD5.320681DF28D82CDCA7E3EED0846625DB] [APT] [AdobeAAMUpdater-1.0-PCFIXE-Administrateur] (.Adobe Systems Incorporated.) -- C:\Program Files\Fichiers communs\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [444904] [MD5.320681DF28D82CDCA7E3EED0846625DB] [APT] [AdobeAAMUpdater-1.0-PCFIXE-RB] (.Adobe Systems Incorporated.) -- C:\Program Files\Fichiers communs\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [444904] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.54A591A772B9A2F298790C231B29AF63] [APT] [MyDefrag v4.3.1 Daily] (...) -- C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [5663] ~ Scheduled Task: 13 Scanned in 00mn 00s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Mise à jour de la version d’Internet Explorer - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} . (.Microsoft Corporation - IE Per User Active Setup Uninstall Utility.) -- C:\WINDOWS\system32\ieudinit.exe O40 - ASIC: Lecteur Windows Media - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitaire d'installation du Lecteur Windows Media de Microsoft.) -- C:\WINDOWS\inf\unregmp2.exe O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\WINDOWS\system32\ie4uinit.exe.mui O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - IEAK branding.) -- C:\WINDOWS\system32\iedkcs32.dll O40 - ASIC: Outlook Express - >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} . (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe O40 - ASIC: Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll O40 - ASIC: Microsoft Windows Media Player 6.4 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\WINDOWS\system32\themeui.dll O40 - ASIC: Microsoft Outlook Express 6 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Bibliothèque d'installation Outlook Express.) -- C:\Program Files\Outlook Express\setup50.exe O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (...) -- C:\WINDOWS\INF\msnetmtg.inf O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (...) -- C:\WINDOWS\INF\msmsgs.inf O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\WINDOWS\system32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (...) -- C:\WINDOWS\INF\wmp11.inf O40 - ASIC: Carnet d'adresses 6 - {7790769C-0471-11d2-AF11-00C04FA35D02} . (.Microsoft Corporation - Bibliothèque d'installation Outlook Express.) -- C:\Program Files\Outlook Express\setup50.exe O40 - ASIC: Mise à jour du Bureau Windows - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\WINDOWS\system32\ie4uinit.exe.mui O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- c:\WINDOWS\system32\mscories.dll O40 - ASIC: Shockwave Flash - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.2 r152.) -- C:\WINDOWS\system32\Macromed\Flash\Flash10n.ocx O40 - ASIC: Installed Component - S-1-5-21-583907252-1284227242-725345543-500 - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} -- Not Hexadécimal CLSID O40 - ASIC: Installed Component - S-1-5-21-583907252-1284227242-725345543-500 - >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS -- Not Hexadécimal CLSID ~ Active Setup: 20 Scanned in 00mn 00s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys O41 - Driver: (avipbb) . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) - C:\WINDOWS\system32\DRIVERS\avipbb.sys O41 - Driver: (avkmgr) . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) - C:\WINDOWS\system32\DRIVERS\avkmgr.sys O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\WINDOWS\system32\DRIVERS\intelppm.sys O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys O41 - Driver: (lnsfw1) . (.Pas de propriétaire - LNSFW1 LnS Driver.) - C:\WINDOWS\system32\drivers\lnsfw1.sys O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\WINDOWS\system32\DRIVERS\redbook.sys O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\WINDOWS\system32\DRIVERS\serial.sys O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\WINDOWS\system32\DRIVERS\ssmdrv.sys O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys O41 - Driver: Carte vidéo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys ~ Drivers: 88 Scanned in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: 7-Zip 9.22beta - (...) [HKLM] -- 7-Zip O42 - Logiciel: ATI - Utilitaire de désinstallation du logiciel - (...) [HKLM] -- All ATI Software O42 - Logiciel: ATI Catalyst Control Center - (...) [HKLM] -- {055EE59D-217B-43A7-ABFF-507B966405D8} O42 - Logiciel: ATI Display Driver - (...) [HKLM] -- ATI Display Driver O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {A0087DDE-69D0-11E2-AD57-43CA6188709B} O42 - Logiciel: Adobe Community Help - (.Adobe Systems Incorporated..) [HKLM] -- {A127C3C0-055E-38CF-B38F-1E85F8BBBFFE} O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Premiere Elements 10 - (.Adobe Systems Incorporated.) [HKLM] -- {AAF4DEA2-5A69-4819-9BB2-BF3D540F9024} O42 - Logiciel: Adobe Premiere Elements 10 Content - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Premiere Elements 10 Content O42 - Logiciel: Adobe Premiere Elements 10 Content - (.Adobe Systems Incorporated.) [HKLM] -- {9C8D1290-0A4C-446C-AD86-0590812660CC} O42 - Logiciel: Adobe Premiere Elements 10 Content 1 - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Premiere Elements 10 Content 1 O42 - Logiciel: Adobe Premiere Elements 10 Content 1 - (.Adobe Systems Incorporated.) [HKLM] -- {340C0246-975B-420F-8ADD-DEA69B16FDEE} O42 - Logiciel: Adobe Premiere Elements 10 Content 2 - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Premiere Elements 10 Content 2 O42 - Logiciel: Adobe Premiere Elements 10 Content 2 - (.Adobe Systems Incorporated.) [HKLM] -- {D66A42BA-3747-4628-9CE4-9E7C18C3ED95} O42 - Logiciel: Adobe Premiere Elements 10 Content 3 - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Premiere Elements 10 Content 3 O42 - Logiciel: Adobe Premiere Elements 10 Content 3 - (.Adobe Systems Incorporated.) [HKLM] -- {99C7D73D-E201-4D03-B8A4-5EDBA529B505} O42 - Logiciel: Adobe Premiere Elements 10 HD Content 1 - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Premiere Elements 10 HD Content 1 O42 - Logiciel: Adobe Premiere Elements 10 HD Content 1 - (.Adobe Systems Incorporated.) [HKLM] -- {5D037ECA-B00A-466F-848C-D21B4DB69DEA} O42 - Logiciel: Adobe Premiere Elements 10 HD Content 2 - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Premiere Elements 10 HD Content 2 O42 - Logiciel: Adobe Premiere Elements 10 HD Content 2 - (.Adobe Systems Incorporated.) [HKLM] -- {D1CE6204-061A-43B5-830F-6A8A35C4E0C6} O42 - Logiciel: Adobe Premiere Elements 10 HD Content 3 - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Premiere Elements 10 HD Content 3 O42 - Logiciel: Adobe Premiere Elements 10 HD Content 3 - (.Adobe Systems Incorporated.) [HKLM] -- {4F29521F-7338-4D15-8691-8FEEB987780C} O42 - Logiciel: Adobe Reader XI (11.0.02) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} O42 - Logiciel: Audacity 2.0.2 - (.Audacity Team.) [HKLM] -- Audacity_is1 O42 - Logiciel: Avira Free Antivirus v13.0.0.3880 - (.Avira.) [HKLM] -- Avira AntiVir Desktop O42 - Logiciel: C-Media WDM Audio Driver - (...) [HKLM] -- C-Media Audio Driver O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>Piriform Ltd O42 - Logiciel: CLX.PayMaker - (.CREALOGIX.) [HKLM] -- {2A408599-FCA1-4113-A528-FC0281B052F0} O42 - Logiciel: Cacheman - (.Outertech.) [HKLM] -- Cacheman O42 - Logiciel: CalDate, version béta 1.03b - (.F. Michaud.) [HKLM] -- CalDate_is1 O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {8D7133DE-27D2-47E5-B248-4180278D32AA} O42 - Logiciel: Clic & Tax 2012 12.3.29 - (.Ringler Informatik AG.) [HKLM] -- NP_NE_2012 O42 - Logiciel: Cobian Backup 11 Gravity - (...) [HKLM] -- CobBackup11 O42 - Logiciel: Corel Applications - (...) [HKLM] -- Corel Applications O42 - Logiciel: DriverMax 6 - (.Innovative Solutions.) [HKLM] -- DMX5_is1 O42 - Logiciel: ERUNT 1.1j - (.Lars Hederer.) [HKLM] -- ERUNT_is1 O42 - Logiciel: ESET Online Scanner v3 - (...) [HKLM] -- ESET Online Scanner O42 - Logiciel: EVEREST Home Edition v2.20 - (.Lavalys Inc.) [HKLM] -- EVEREST Home Edition_is1 O42 - Logiciel: EasyCleaner - (.ToniArts.) [HKLM] -- {F5346614-B7C4-4E94-826A-E2363155233D} O42 - Logiciel: FormatFactory 3.0.1 - (.Free Time.) [HKLM] -- FormatFactory O42 - Logiciel: Genesys USB Mass Storage Device - (.Genesys Logic.) [HKLM] -- {959B7F35-2819-40C5-A0CD-3C53B5FCC935} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {0A844D8F-A965-11E2-9E77-B8AC6F98CCE3} O42 - Logiciel: Généatique 2011 - (.CDIP.) [HKLM] -- {927E30E0-90E8-4772-8803-D42820C5951A}_is1 O42 - Logiciel: HP FWUpdateEDO2 - (.Hewlett-Packard.) [HKLM] -- {415FA9AD-DA10-4ABE-97B6-5051D4795C90} O42 - Logiciel: HP Officejet Pro 8600 Aide - (.Hewlett Packard.) [HKLM] -- {B6F5C6D8-C443-4B55-932F-AE11B5743FC4} O42 - Logiciel: HP Product Detection - (.HP.) [HKLM] -- {879F7C80-BCA3-4A11-BDB1-658252ECD7E0} O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3} O42 - Logiciel: Hamster Free Video Converter - (.Hamster Soft.) [HKLM] -- {7E350663-86D3-466A-AB79-28156A9ABF6E}_is1 O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5 O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5 O42 - Logiciel: I.R.I.S. OCR - (.HP.) [HKLM] -- {CA6BCA2F-EDEB-408F-850B-31404BE16A61} O42 - Logiciel: Internet Explorer (Enable DEP) - (...) [HKLM] -- {a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb O42 - Logiciel: Jaquette Express 1.9.1.0 - (...) [HKLM] -- Jaquette Express O42 - Logiciel: Java 7 Update 25 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217021FF} O42 - Logiciel: LAME v3.98.2 for Audacity - (...) [HKLM] -- LAME for Audacity_is1 O42 - Logiciel: Lecteur Windows Media 11 - (...) [HKLM] -- Windows Media Player O42 - Logiciel: Logiciel de base du périphérique HP Officejet Pro 8600 - (.Hewlett-Packard Co..) [HKLM] -- {07CB889D-658E-445A-B589-9325AC6873DF} O42 - Logiciel: Logitech SetPoint 6.32 - (.Logitech.) [HKLM] -- SP6 O42 - Logiciel: Look 'n' Stop 2.07 - (.Soft4Ever.) [HKLM] -- Look 'n' Stop 2.07 O42 - Logiciel: MPC-HC 1.6.8 - (.MPC-HC Team.) [HKLM] -- {2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1 O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} O42 - Logiciel: MSXML 6.0 Parser - (.Microsoft Corporation.) [HKLM] -- {AEB9948B-4FF2-47C9-990E-47014492A0FE} O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1 O42 - Logiciel: Malwarebytes' RogueRemover - (.Malwarebytes.) [HKLM] -- Malwarebytes' RogueRemover FREE_is1 O42 - Logiciel: MediaCoder 0.8.22.5500 - (.Broad Intelligence.) [HKLM] -- MediaCoder O42 - Logiciel: MediaMonkey 4.0 - (.Ventis Media Inc..) [HKLM] -- MediaMonkey_is1 O42 - Logiciel: Microsoft Baseline Security Analyzer 2.2 - (.Microsoft Corporation.) [HKLM] -- {13CD417D-F1F1-4AC4-945D-FDDEB884756F} O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1 O42 - Logiciel: Microsoft Image Composite Editor - (.Microsoft Corporation.) [HKLM] -- {3D599ADA-65D9-4B51-898F-CE718DEC5DBB} O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 - (.Microsoft Corporation.) [HKLM] -- Wdf01009 O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Microsoft Tool Web Package : EXCTRLST.EXE - (.Microsoft Corporation.) [HKLM] -- {B0650E3D-FDCA-4908-B74B-0CC1731BDB93} O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000 O42 - Logiciel: Microsoft WSE 3.0 Runtime - (.Microsoft Corp..) [HKLM] -- {E3E71D07-CD27-46CB-8448-16D4FB29AA13} O42 - Logiciel: MoneyPen 2.0 - (.Paymaker.) [HKLM] -- {47C09BBC-470E-4507-8E62-463F9A243D53} O42 - Logiciel: Mozilla Firefox 22.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 22.0 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: MyDefrag v4.3.1 - (.J.C. Kessels.) [HKLM] -- MyDefrag v4.3.1_is1 O42 - Logiciel: MyTomTom 3.2.0.1116 - (.TomTom.) [HKLM] -- MyTomTom O42 - Logiciel: NTREGOPT 1.1j - (.Lars Hederer.) [HKLM] -- NTREGOPT_is1 O42 - Logiciel: Nero 6 - (...) [HKLM] -- Nero - Burning Rom!UninstallKey O42 - Logiciel: Nero BurnRights - (.Nero AG.) [HKLM] -- {1001266B-D4BB-46D9-B023-2612A8CE3A31} O42 - Logiciel: Nero BurnRights 12 - (.Nero AG.) [HKLM] -- {0F9EAB70-E891-49E0-9974-37C6BE3BA6D0} O42 - Logiciel: Nero BurnRights Help (CHM) - (.Nero AG.) [HKLM] -- {8E7EABFA-BF37-4824-B792-4220C9E04233} O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM] -- {ABC88553-8770-4B97-B43E-5A90647A5B63} O42 - Logiciel: Nero ControlCenter Help (CHM) - (.Nero AG.) [HKLM] -- {C994C746-C6D0-4EBA-B09E-DF7B18381B69} O42 - Logiciel: Nero Core Components - (.Nero AG.) [HKLM] -- {BEBEE34D-84A2-4EDD-8BEA-96CC54371263} O42 - Logiciel: Nero Update - (.Nero AG.) [HKLM] -- {65BB0407-4CC8-4DC7-952E-3EEFDF05602A} O42 - Logiciel: Nitro Reader 3 - (.Nitro.) [HKLM] -- {2F9A6DF6-429D-4958-B65B-65B8233F6E2C} O42 - Logiciel: PDF-XChange 4 - (.Tracker Software Products Ltd.) [HKLM] -- {EA08048C-3823-4DC8-B169-1D5D11FFC19F}_is1 O42 - Logiciel: PDFTK Builder 3.5.3 - (...) [HKLM] -- PDFTK Builder_is1 O42 - Logiciel: PRE10STIInstaller - (.Adobe Systems Incorporated.) [HKLM] -- {CE1F2DF3-5836-4A27-A3FE-6717492DDE5E} O42 - Logiciel: PSE10 STI Installer - (.Adobe Systems Incorporated.) [HKLM] -- {11D08055-939C-432b-98C3-E072478A0CD7} O42 - Logiciel: Paragon Drive Backup™ 9.0 Free Edition - (.Paragon Software.) [HKLM] -- {985F828E-0E98-429F-9C05-EF3BDE7568F7} O42 - Logiciel: Password Safe - (...) [HKLM] -- Password Safe O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3 O42 - Logiciel: Radio Fr Solo 2.1 - (...) [HKLM] -- Radio_Fr O42 - Logiciel: Real Alternative 2.0.2 - (...) [HKLM] -- RealAlt_is1 O42 - Logiciel: RegSeeker - (.HoverDesk.) [HKLM] -- RegSeeker O42 - Logiciel: Revo Uninstaller 1.95 - (.VS Revo Group.) [HKLM] -- Revo Uninstaller O42 - Logiciel: Sentinel RMS License Manager 8.4.0 - (.SafeNet, Inc..) [HKLM] -- {B371BA93-A660-43BB-9CB4-79B74A72B406} O42 - Logiciel: Skype™ 6.5 - (.Skype Technologies S.A..) [HKLM] -- {4E76FF7E-AEBA-4C87-B788-CD47E5425B9D} O42 - Logiciel: SmartSound Common Data - (.SmartSound Software Inc..) [HKLM] -- InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8} O42 - Logiciel: SmartSound Common Data - (.SmartSound Software Inc..) [HKLM] -- {B8A2869E-30CA-40C5-9CF8-BD7354E57EF8} O42 - Logiciel: SmartSound Premiere Elements 10 Plugin - (.SmartSound Software Inc..) [HKLM] -- {0E16C1BC-72A7-4DB7-BBB8-560EDCCA74B5} O42 - Logiciel: SmartSound Sonicfire Pro 5 - (.SmartSound Software Inc..) [HKLM] -- InstallShield_{1D273D91-D7D5-4036-8B84-EB4615FF5F81} O42 - Logiciel: SmartSound Sonicfire Pro 5 - (.SmartSound Software Inc..) [HKLM] -- {1D273D91-D7D5-4036-8B84-EB4615FF5F81} O42 - Logiciel: SpywareBlaster 5.0 - (.BrightFort LLC.) [HKLM] -- SpywareBlaster_is1 O42 - Logiciel: Transfert Windows - (.Microsoft Corporation.) [HKLM] -- WET7Cable O42 - Logiciel: UPC Fiber Power Optimizer - (.Cablecom GmbH.) [HKLM] -- UPC Fiber Power Optimizer O42 - Logiciel: UPC Fiber Power Optimizer - (.Cablecom GmbH.) [HKLM] -- {631141AD-79AA-447F-B403-21C704D39B8C} O42 - Logiciel: Unlocker 1.9.1 - (.Cedrick Collomb.) [HKLM] -- Unlocker O42 - Logiciel: VIA Gestionnaire de périphériques de plate-forme - (.VIA Technologies, Inc..) [HKLM] -- InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169} O42 - Logiciel: VIA Rhine-Family Fast-Ethernet Adapter - (...) [HKLM] -- VN_VUIns_Rhine_VIA O42 - Logiciel: VLC media player 2.0.7 - (.VideoLAN.) [HKLM] -- VLC media player O42 - Logiciel: Visual Studio C++ 10.0 Runtime - (...) [HKLM] -- {4412F224-3849-4461-A3E9-DEEF8D252790} O42 - Logiciel: WinPcap 4.1.2 - (.CACE Technologies.) [HKLM] -- WinPcapInst O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify O42 - Logiciel: Windows Installer Clean Up - (.Microsoft Corporation.) [HKLM] -- {121634B0-2F4B-11D3-ADA3-00C04F52DD52} O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8 O42 - Logiciel: Windows Media Format 11 runtime - (...) [HKLM] -- Windows Media Format Runtime O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11 O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11 O42 - Logiciel: Windows Search 4.0 - (.Microsoft Corporation.) [HKLM] -- KB940157 O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service O42 - Logiciel: XML Paper Specification Shared Components Language Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- XPSEPSCLP O42 - Logiciel: XMind - (.XMind Ltd..) [HKLM] -- XMind O42 - Logiciel: XMind 2012 (v3.3.1) - (.XMind Ltd..) [HKLM] -- XMind_is1 O42 - Logiciel: XnView 1.98.4 - (.Gougelet Pierre-e.) [HKLM] -- XnView_is1 O42 - Logiciel: eReg - (.Logitech, Inc..) [HKLM] -- {3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C} O42 - Logiciel: upc cablecom Installer - (.upc cablecom GmbH.) [HKLM] -- upc cablecom Installer O42 - Logiciel: upc cablecom Installer - (.upc cablecom GmbH.) [HKLM] -- {F61310F9-DE52-4EF9-B514-F41DE0BC0418} ~ Logic: 246 Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\ATI] [HKCU\Software\Adobe] [HKCU\Software\Ahead] [HKCU\Software\Avira] [HKCU\Software\Bitdefender] [HKCU\Software\BugSplat] [HKCU\Software\CREALOGIX] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\ESET] [HKCU\Software\FileOpen] [HKCU\Software\FreeTime] [HKCU\Software\Freemake] [HKCU\Software\Fridgesoft] [HKCU\Software\GNU] [HKCU\Software\Gabest] [HKCU\Software\Google] [HKCU\Software\HP] [HKCU\Software\Haali] [HKCU\Software\Hewlett-Packard] [HKCU\Software\I.R.I.S.] [HKCU\Software\IM Providers] [HKCU\Software\Innovative Solutions] [HKCU\Software\Intel] [HKCU\Software\JavaSoft] [HKCU\Software\Lavalys] [HKCU\Software\Licenses] [HKCU\Software\Macromedia] [HKCU\Software\MainConcept] [HKCU\Software\Malwarebytes' Anti-Malware] [HKCU\Software\MediaMonkey] [HKCU\Software\Mozilla] [HKCU\Software\MyDefrag] [HKCU\Software\NITRO] [HKCU\Software\Nero] [HKCU\Software\Netscape] [HKCU\Software\NewBlue] [HKCU\Software\ODBC] [HKCU\Software\Outertech] [HKCU\Software\ParetoLogic] =>PUP.Paretologic [HKCU\Software\Paymaker] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\Radio Fr Solo] [HKCU\Software\RealNetworks] [HKCU\Software\Safer Networking Limited] [HKCU\Software\Skype] [HKCU\Software\Soft4Ever] [HKCU\Software\TAdvCheckList] [HKCU\Software\TCP Optimizer] [HKCU\Software\The Silicon Realms Toolworks] [HKCU\Software\TomTom] [HKCU\Software\Tracker Software] [HKCU\Software\Trolltech] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\VSRevoGroup] [HKCU\Software\Winamp] [HKCU\Software\combit] [HKCU\Software\eSupport.com] =>Rogue.RegistryWizard [HKCU\Software\ej-technologies] [HKCU\Software\geissplugin] [HKCU\Software\mquadr.at] [HKLM\Software\ATI Technologies] [HKLM\Software\ATI] [HKLM\Software\AVAST Software] [HKLM\Software\Adobe] [HKLM\Software\AdwCleaner] [HKLM\Software\Ahead] [HKLM\Software\Alienware] [HKLM\Software\AviSynth] [HKLM\Software\Avid] [HKLM\Software\Avira] [HKLM\Software\BrowserChoice] [HKLM\Software\C07ft5Y] [HKLM\Software\CAVEditLib] [HKLM\Software\Cameleon] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\CobianSoft] [HKLM\Software\Corel] [HKLM\Software\DivXNetworks] [HKLM\Software\Eset] [HKLM\Software\Freemake] [HKLM\Software\GNU] [HKLM\Software\Gabest] [HKLM\Software\Gemplus] [HKLM\Software\Google] [HKLM\Software\HP] [HKLM\Software\HaaliMkx] [HKLM\Software\HeadStrong] [HKLM\Software\Hewlett-Packard] [HKLM\Software\IM Providers] [HKLM\Software\Innovative Solutions] [HKLM\Software\InstallShield] [HKLM\Software\InterVideo] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Lame for Audacity] [HKLM\Software\Licenses] [HKLM\Software\Logitech] [HKLM\Software\Macromedia] [HKLM\Software\Malwarebytes' Anti-Malware] [HKLM\Software\MimarSinan] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\Nero] [HKLM\Software\Nitro] [HKLM\Software\Ntpad] [HKLM\Software\ODBC] [HKLM\Software\Outertech] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Program Groups] [HKLM\Software\Rainbow Technologies] [HKLM\Software\RealAlternative] [HKLM\Software\RealNetworks] [HKLM\Software\RegisteredApplications] [HKLM\Software\Sage] [HKLM\Software\Schlumberger] [HKLM\Software\ShunSoft] [HKLM\Software\Skype] [HKLM\Software\SmartSound Software] [HKLM\Software\Sonic] [HKLM\Software\SpywareBlaster] [HKLM\Software\TomTom] [HKLM\Software\Tracker Software] [HKLM\Software\Trolltech] [HKLM\Software\UPC Swiss] [HKLM\Software\VIA Raid Lib] [HKLM\Software\VIA Technologies, Inc] [HKLM\Software\VN_VUIns] [HKLM\Software\VideoLAN] [HKLM\Software\WinPcap] [HKLM\Software\Windows 3.1 Migration Status] [HKLM\Software\Windows] [HKLM\Software\X-AVCSD] [HKLM\Software\XMind Ltd] [HKLM\Software\XnView] [HKLM\Software\ej-technologies] [HKLM\Software\mozilla.org] [HKLM\Software\mquadr.at] ~ Key Software: 255 Scanned in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 14/11/2011 - 21:48:15 - [3,440] ----D C:\Program Files\7-Zip O43 - CFD: 01/01/2013 - 19:30:07 - [-1848,886] ----D C:\Program Files\Adobe O43 - CFD: 11/03/2013 - 20:46:00 - [1,297] ----D C:\Program Files\Ahead O43 - CFD: 30/01/2013 - 12:54:37 - [78,935] ----D C:\Program Files\ATI Technologies O43 - CFD: 06/01/2013 - 22:17:41 - [43,773] ----D C:\Program Files\Audacity O43 - CFD: 25/05/2013 - 11:31:01 - [219,294] ----D C:\Program Files\Avira O43 - CFD: 16/06/2013 - 16:40:26 - [3,509] ----D C:\Program Files\Cacheman O43 - CFD: 04/01/2013 - 15:18:21 - [5,215] ----D C:\Program Files\CalDate O43 - CFD: 27/06/2013 - 22:13:38 - [5,594] ----D C:\Program Files\CCleaner =>Piriform Ltd O43 - CFD: 10/03/2013 - 22:34:19 - [0,323] ----D C:\Program Files\CDex O43 - CFD: 20/04/2013 - 15:47:03 - [150,051] ----D C:\Program Files\Clic & Tax 2012 O43 - CFD: 18/07/2013 - 22:16:43 - [211,395] ----D C:\Program Files\CLX.PayMaker O43 - CFD: 06/12/2012 - 22:50:48 - [36,800] ----D C:\Program Files\Cobian Backup 11 O43 - CFD: 14/11/2011 - 09:56:13 - [0] ----D C:\Program Files\ComPlus Applications O43 - CFD: 14/11/2011 - 19:12:39 - [84,549] ----D C:\Program Files\Corel O43 - CFD: 04/11/2012 - 19:54:04 - [21,394] ----D C:\Program Files\CoverDesigner O43 - CFD: 25/11/2011 - 23:16:11 - [84,552] ----D C:\Program Files\Drive Backup 9.0 Free Edition O43 - CFD: 07/02/2013 - 15:50:25 - [16,036] ----D C:\Program Files\DriverMax O43 - CFD: 10/05/2013 - 08:53:57 - [3,397] ----D C:\Program Files\EasyCleaner O43 - CFD: 19/11/2011 - 17:31:50 - [0,639] ----D C:\Program Files\ERUNT O43 - CFD: 19/11/2011 - 10:56:20 - [186,310] ----D C:\Program Files\ESET O43 - CFD: 10/11/2012 - 13:51:15 - [6,497] ----D C:\Program Files\EVEREST Home Edition O43 - CFD: 05/07/2013 - 22:52:02 - [847,804] ----D C:\Program Files\Fichiers communs O43 - CFD: 29/04/2013 - 07:34:11 - [135,765] ----D C:\Program Files\FormatFactory O43 - CFD: 10/02/2013 - 22:42:28 - [0] ----D C:\Program Files\Freemake O43 - CFD: 16/11/2011 - 22:17:01 - [322,363] ----D C:\Program Files\Geneatique2011 O43 - CFD: 16/06/2013 - 16:32:22 - [241,417] ----D C:\Program Files\Google O43 - CFD: 30/01/2013 - 18:20:46 - [17,802] ----D C:\Program Files\Hamster Soft O43 - CFD: 24/11/2012 - 20:01:30 - [3,508] ----D C:\Program Files\Hewlett-Packard O43 - CFD: 26/12/2012 - 13:17:05 - [0,561] ----D C:\Program Files\Hosts_Anti_Adwares_PUPs O43 - CFD: 16/07/2013 - 10:25:42 - [163,318] ----D C:\Program Files\HP O43 - CFD: 18/11/2011 - 19:39:42 - [4,139] ----D C:\Program Files\Image Composite Editor O43 - CFD: 04/11/2012 - 19:54:32 - [0,857] ----D C:\Program Files\ImageDrive O43 - CFD: 19/07/2013 - 15:50:39 - [21,480] ----D C:\Program Files\InstallShield Installation Information O43 - CFD: 11/07/2013 - 23:30:28 - [5,743] ----D C:\Program Files\Internet Explorer O43 - CFD: 16/11/2011 - 19:13:20 - [3,315] ----D C:\Program Files\Jaquette Express O43 - CFD: 20/06/2013 - 19:27:18 - [124,311] ----D C:\Program Files\Java O43 - CFD: 10/03/2013 - 22:34:39 - [1,171] ----D C:\Program Files\Lame for Audacity O43 - CFD: 15/11/2011 - 12:25:18 - [22,261] ----D C:\Program Files\Logitech O43 - CFD: 31/03/2013 - 12:01:46 - [1,149] ----D C:\Program Files\looknstop O43 - CFD: 10/04/2013 - 11:32:01 - [13,352] ----D C:\Program Files\Malwarebytes' Anti-Malware O43 - CFD: 25/05/2013 - 18:21:47 - [188,276] ----D C:\Program Files\MediaCoder O43 - CFD: 11/03/2013 - 22:58:56 - [50,039] ----D C:\Program Files\MediaMonkey O43 - CFD: 14/11/2011 - 12:51:07 - [2,053] ----D C:\Program Files\Messenger O43 - CFD: 25/11/2012 - 19:18:36 - [0] ----D C:\Program Files\Microsoft O43 - CFD: 14/11/2011 - 17:58:54 - [38,002] ----D C:\Program Files\Microsoft Analysis Services O43 - CFD: 18/11/2012 - 12:31:53 - [2,460] ----D C:\Program Files\Microsoft Baseline Security Analyzer 2 O43 - CFD: 14/11/2011 - 10:00:17 - [0] ----D C:\Program Files\microsoft frontpage O43 - CFD: 14/11/2011 - 18:21:37 - [693,063] ----D C:\Program Files\Microsoft Office O43 - CFD: 12/07/2013 - 08:19:42 - [40,851] ----D C:\Program Files\Microsoft Silverlight O43 - CFD: 25/11/2011 - 13:30:28 - [0,757] ----D C:\Program Files\Microsoft Sync Framework O43 - CFD: 27/08/2012 - 18:08:39 - [0,934] ----D C:\Program Files\Microsoft WSE O43 - CFD: 18/11/2011 - 19:29:46 - [7,789] ----D C:\Program Files\Microsoft.NET O43 - CFD: 15/11/2011 - 23:37:26 - [2,068] ----D C:\Program Files\MoneyPen O43 - CFD: 14/11/2011 - 13:51:46 - [9,894] ----D C:\Program Files\Movie Maker O43 - CFD: 02/07/2013 - 21:27:42 - [47,229] ----D C:\Program Files\Mozilla Firefox O43 - CFD: 03/07/2013 - 07:50:54 - [0,214] ----D C:\Program Files\Mozilla Maintenance Service O43 - CFD: 16/06/2013 - 18:22:21 - [22,283] ----D C:\Program Files\MPC-HC O43 - CFD: 14/11/2011 - 18:44:56 - [0,025] ----D C:\Program Files\MSBuild O43 - CFD: 01/01/2013 - 19:28:33 - [29,243] ----D C:\Program Files\MSECache O43 - CFD: 14/11/2011 - 09:55:22 - [18,385] ----D C:\Program Files\MSN O43 - CFD: 14/11/2011 - 09:55:52 - [0] ----D C:\Program Files\MSN Gaming Zone O43 - CFD: 15/11/2011 - 19:08:12 - [0] ----D C:\Program Files\MSXML 4.0 O43 - CFD: 19/07/2013 - 10:26:47 - [3,193] ----D C:\Program Files\MyDefrag v4.3.1 O43 - CFD: 29/06/2013 - 18:28:16 - [17,457] ----D C:\Program Files\MyTomTom 3 O43 - CFD: 11/03/2013 - 16:24:56 - [70,049] ----D C:\Program Files\Nero O43 - CFD: 04/11/2012 - 19:54:07 - [12,264] ----D C:\Program Files\Nero BackItUp O43 - CFD: 04/11/2012 - 19:54:40 - [4,961] ----D C:\Program Files\Nero SoundTrax O43 - CFD: 04/11/2012 - 19:54:07 - [2,094] ----D C:\Program Files\Nero StartSmart O43 - CFD: 04/11/2012 - 19:54:39 - [2,179] ----D C:\Program Files\Nero Toolkit O43 - CFD: 04/11/2012 - 19:54:39 - [8,173] ----D C:\Program Files\Nero Wave Editor O43 - CFD: 14/11/2011 - 12:44:56 - [3,133] ----D C:\Program Files\NetMeeting O43 - CFD: 22/12/2012 - 23:10:14 - [80,335] ----D C:\Program Files\Nitro O43 - CFD: 29/03/2013 - 13:19:11 - [0,232] ----D C:\Program Files\NT Registry Optimizer O43 - CFD: 14/11/2011 - 13:54:06 - [4,176] ----D C:\Program Files\Outlook Express O43 - CFD: 14/11/2011 - 22:28:18 - [19,789] ----D C:\Program Files\Password Safe O43 - CFD: 19/02/2013 - 21:02:46 - [3,463] ----D C:\Program Files\PDFTK Builder O43 - CFD: 31/03/2013 - 17:15:34 - [77,100] ----D C:\Program Files\Picasa3 O43 - CFD: 02/09/2012 - 10:32:47 - [2,967] ----D C:\Program Files\PoiMixer O43 - CFD: 02/12/2012 - 11:53:12 - [11,035] ----D C:\Program Files\Radio Fr Solo O43 - CFD: 02/12/2012 - 13:10:51 - [21,963] ----D C:\Program Files\Real Alternative O43 - CFD: 26/11/2012 - 23:35:03 - [0,134] ----D C:\Program Files\Realtek AC97 O43 - CFD: 14/11/2011 - 18:44:44 - [36,207] ----D C:\Program Files\Reference Assemblies O43 - CFD: 16/07/2013 - 15:38:04 - [2,941] ----D C:\Program Files\RegSeeker O43 - CFD: 16/06/2013 - 16:34:13 - [0,060] ----D C:\Program Files\Resource Kit O43 - CFD: 04/07/2013 - 11:58:50 - [6,523] ----D C:\Program Files\Revo Uninstaller O43 - CFD: 16/11/2011 - 14:19:44 - [1,690] ----D C:\Program Files\RogueRemover FREE O43 - CFD: 19/07/2013 - 15:53:36 - [1,733] ----D C:\Program Files\Samsung O43 - CFD: 14/11/2011 - 09:58:09 - [0,001] ----D C:\Program Files\Services en ligne O43 - CFD: 20/06/2013 - 23:08:14 - [18,953] R---D C:\Program Files\Skype O43 - CFD: 27/08/2012 - 17:07:22 - [29,775] ----D C:\Program Files\SmartSound Software O43 - CFD: 18/07/2013 - 22:19:42 - [7,738] ----D C:\Program Files\SpywareBlaster O43 - CFD: 24/11/2012 - 23:01:54 - [0] ----D C:\Program Files\Temp O43 - CFD: 27/08/2012 - 18:28:36 - [0,021] ----D C:\Program Files\TomTom International B.V O43 - CFD: 14/11/2011 - 19:25:08 - [9,669] ----D C:\Program Files\Tracker Software O43 - CFD: 14/11/2011 - 11:12:41 - [0] ----D C:\Program Files\Uninstall Information O43 - CFD: 16/01/2013 - 23:45:51 - [0,222] ----D C:\Program Files\Unlocker O43 - CFD: 15/11/2011 - 08:58:27 - [127,890] ----D C:\Program Files\upc cablecom O43 - CFD: 14/11/2011 - 23:04:00 - [0,905] ----D C:\Program Files\UPC Fiber Power Optimizer O43 - CFD: 15/11/2011 - 11:58:22 - [8,194] ----D C:\Program Files\VIA O43 - CFD: 15/12/2012 - 17:09:45 - [101,905] ----D C:\Program Files\VideoLAN O43 - CFD: 27/11/2012 - 22:36:57 - [94,079] ----D C:\Program Files\VLC O43 - CFD: 17/11/2011 - 18:53:08 - [5,167] ----D C:\Program Files\Windows Desktop Search O43 - CFD: 25/11/2011 - 22:15:44 - [30,386] ----D C:\Program Files\Windows Easy Transfer 7 O43 - CFD: 01/01/2013 - 19:28:48 - [0,136] ----D C:\Program Files\Windows Installer Clean Up O43 - CFD: 02/12/2012 - 11:41:13 - [3,415] ----D C:\Program Files\Windows Media Connect 2 O43 - CFD: 02/12/2012 - 11:41:13 - [8,148] ----D C:\Program Files\Windows Media Player O43 - CFD: 14/11/2011 - 12:44:53 - [1,310] ----D C:\Program Files\Windows NT O43 - CFD: 14/11/2011 - 09:58:13 - [0] --H-D C:\Program Files\WindowsUpdate O43 - CFD: 07/02/2013 - 16:13:58 - [0,180] ----D C:\Program Files\WinPcap O43 - CFD: 04/11/2012 - 19:54:08 - [1,688] ----D C:\Program Files\WMPBurn O43 - CFD: 14/11/2011 - 10:00:17 - [0] ----D C:\Program Files\xerox O43 - CFD: 20/04/2013 - 16:17:35 - [50,713] ----D C:\Program Files\XMind O43 - CFD: 20/04/2013 - 15:25:39 - [47,962] ----D C:\Program Files\XMind(2) O43 - CFD: 16/11/2011 - 13:47:29 - [16,149] ----D C:\Program Files\XnView O43 - CFD: 15/11/2011 - 19:08:55 - [0,000] ----D C:\Program Files\Zero G Registry O43 - CFD: 19/07/2013 - 18:53:29 - [17,043] ----D C:\Program Files\ZHPDiag O43 - CFD: 01/01/2013 - 19:25:09 - [458,335] ----D C:\Program Files\Fichiers communs\Adobe O43 - CFD: 20/05/2013 - 21:32:50 - [45,604] ----D C:\Program Files\Fichiers communs\Adobe AIR O43 - CFD: 04/11/2012 - 19:53:57 - [13,141] ----D C:\Program Files\Fichiers communs\Ahead O43 - CFD: 16/12/2012 - 20:24:34 - [0,095] ----D C:\Program Files\Fichiers communs\DESIGNER O43 - CFD: 14/11/2011 - 12:01:03 - [8,201] ----D C:\Program Files\Fichiers communs\InstallShield O43 - CFD: 20/04/2013 - 16:08:10 - [1,189] ----D C:\Program Files\Fichiers communs\Java O43 - CFD: 15/11/2011 - 12:26:05 - [22,474] ----D C:\Program Files\Fichiers communs\LogiShrd O43 - CFD: 16/12/2012 - 20:25:56 - [249,683] ----D C:\Program Files\Fichiers communs\Microsoft Shared O43 - CFD: 14/11/2011 - 09:57:26 - [0,271] ----D C:\Program Files\Fichiers communs\MSSoap O43 - CFD: 11/03/2013 - 14:31:45 - [17,704] ----D C:\Program Files\Fichiers communs\Nero O43 - CFD: 22/12/2012 - 23:10:13 - [15,773] ----D C:\Program Files\Fichiers communs\Nitro O43 - CFD: 14/11/2011 - 10:39:57 - [0] ----D C:\Program Files\Fichiers communs\ODBC O43 - CFD: 27/08/2012 - 18:07:40 - [2,324] ----D C:\Program Files\Fichiers communs\SafeNet Sentinel O43 - CFD: 14/11/2011 - 09:57:29 - [0,008] ----D C:\Program Files\Fichiers communs\Services O43 - CFD: 20/06/2013 - 23:08:14 - [1,904] ----D C:\Program Files\Fichiers communs\Skype O43 - CFD: 14/11/2011 - 10:39:54 - [3,612] ----D C:\Program Files\Fichiers communs\SpeechEngines O43 - CFD: 16/12/2012 - 20:18:31 - [7,487] ----D C:\Program Files\Fichiers communs\System O43 - CFD: 18/11/2011 - 19:17:11 - [0] ----D C:\Program Files\Fichiers communs\Windows Live O43 - CFD: 19/07/2013 - 15:49:51 - [-1596,507] R---D C:\Documents and Settings\All Users\Application Data O43 - CFD: 19/07/2013 - 17:45:09 - [0,004] ----D C:\Documents and Settings\All Users\Bureau O43 - CFD: 19/07/2013 - 15:56:38 - [33,091] R---D C:\Documents and Settings\All Users\Documents O43 - CFD: 02/12/2012 - 11:42:30 - [3,004] -SH-D C:\Documents and Settings\All Users\DRM O43 - CFD: 14/11/2011 - 10:39:31 - [0] ----D C:\Documents and Settings\All Users\Favoris O43 - CFD: 24/11/2012 - 21:07:53 - [1,391] R---D C:\Documents and Settings\All Users\Menu Démarrer O43 - CFD: 14/11/2011 - 18:02:01 - [2,834] ----D C:\Documents and Settings\All Users\Microsoft O43 - CFD: 14/11/2011 - 10:39:31 - [0] ----D C:\Documents and Settings\All Users\Modèles O43 - CFD: 20/05/2013 - 21:33:03 - [88,503] ----D C:\Documents and Settings\Administrateur\Application Data\Adobe O43 - CFD: 22/10/2012 - 22:34:00 - [1,860] ----D C:\Documents and Settings\Administrateur\Application Data\Ahead O43 - CFD: 06/11/2012 - 16:29:31 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\Apple Computer O43 - CFD: 31/10/2012 - 18:57:17 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\ATI O43 - CFD: 25/05/2013 - 11:36:58 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\Avira O43 - CFD: 25/05/2013 - 18:21:05 - [0,017] ----D C:\Documents and Settings\Administrateur\Application Data\Broad Intelligence O43 - CFD: 31/08/2012 - 19:09:31 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\Canneverbe Limited O43 - CFD: 20/09/2012 - 14:27:48 - [0,000] ----D C:\Documents and Settings\Administrateur\Application Data\CrystalIdea Software O43 - CFD: 03/04/2013 - 22:19:08 - [146,164] ----D C:\Documents and Settings\Administrateur\Application Data\Downloaded Installations O43 - CFD: 02/04/2013 - 15:02:49 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\ElevatedDiagnostics O43 - CFD: 03/04/2013 - 22:18:18 - [0,000] ----D C:\Documents and Settings\Administrateur\Application Data\FileOpen O43 - CFD: 22/12/2012 - 21:34:55 - [0,001] ----D C:\Documents and Settings\Administrateur\Application Data\gdp O43 - CFD: 03/06/2013 - 19:05:08 - [0,000] ----D C:\Documents and Settings\Administrateur\Application Data\Gestionnaire de Téléchargements Qobuz O43 - CFD: 27/01/2013 - 13:00:36 - [0,049] ----D C:\Documents and Settings\Administrateur\Application Data\Google O43 - CFD: 22/12/2012 - 21:16:21 - [0,001] ----D C:\Documents and Settings\Administrateur\Application Data\HpUpdate O43 - CFD: 27/08/2012 - 21:35:00 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\Identities O43 - CFD: 27/11/2012 - 16:44:00 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\linguae O43 - CFD: 27/08/2012 - 16:52:38 - [0,000] ----D C:\Documents and Settings\Administrateur\Application Data\Macromedia O43 - CFD: 31/08/2012 - 07:45:12 - [0,004] ----D C:\Documents and Settings\Administrateur\Application Data\Malwarebytes O43 - CFD: 22/03/2013 - 13:28:02 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\Media Player Classic O43 - CFD: 12/04/2013 - 10:22:31 - [0,456] ----D C:\Documents and Settings\Administrateur\Application Data\MediaMonkey O43 - CFD: 01/01/2013 - 19:28:48 - [11,141] -S--D C:\Documents and Settings\Administrateur\Application Data\Microsoft O43 - CFD: 29/08/2012 - 19:20:42 - [73,778] ----D C:\Documents and Settings\Administrateur\Application Data\Mozilla O43 - CFD: 02/11/2012 - 22:31:01 - [0,003] ----D C:\Documents and Settings\Administrateur\Application Data\mquadr.at O43 - CFD: 03/04/2013 - 22:18:18 - [1,891] ----D C:\Documents and Settings\Administrateur\Application Data\Nitro O43 - CFD: 01/04/2013 - 22:24:43 - [0,137] ----D C:\Documents and Settings\Administrateur\Application Data\QuickScan O43 - CFD: 02/12/2012 - 13:12:42 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\Real O43 - CFD: 19/07/2013 - 15:56:25 - [0,289] ----D C:\Documents and Settings\Administrateur\Application Data\Samsung O43 - CFD: 20/06/2013 - 23:21:30 - [4,157] ----D C:\Documents and Settings\Administrateur\Application Data\Skype O43 - CFD: 28/08/2012 - 22:34:39 - [29,289] ----D C:\Documents and Settings\Administrateur\Application Data\Sun O43 - CFD: 27/11/2012 - 22:38:26 - [0,077] ----D C:\Documents and Settings\Administrateur\Application Data\vlc O43 - CFD: 11/03/2013 - 16:43:34 - [0] ----D C:\Documents and Settings\Administrateur\Application Data\Windows Search O43 - CFD: 20/04/2013 - 15:25:39 - [6,289] ----D C:\Documents and Settings\Administrateur\Application Data\XMind O43 - CFD: 05/06/2013 - 22:36:52 - [0,038] ----D C:\Documents and Settings\Administrateur\Application Data\XnView O43 - CFD: 06/07/2013 - 02:00:04 - [27,059] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Adobe O43 - CFD: 06/11/2012 - 16:37:44 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Apple O43 - CFD: 02/09/2012 - 22:04:12 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Apple Computer O43 - CFD: 31/10/2012 - 18:57:17 - [0,061] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\ATI O43 - CFD: 26/11/2012 - 22:55:17 - [0,596] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\eSupport.com =>Rogue.RegistryWizard O43 - CFD: 25/11/2012 - 10:46:54 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\FreeOCR O43 - CFD: 16/06/2013 - 16:32:14 - [20,658] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Google O43 - CFD: 24/11/2012 - 21:31:29 - [0,153] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\HP O43 - CFD: 11/09/2012 - 16:03:56 - [24,927] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Innovative Solutions O43 - CFD: 31/03/2013 - 12:15:05 - [0,088] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\looknstop O43 - CFD: 17/01/2013 - 13:25:00 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\MediaMonkey O43 - CFD: 24/11/2012 - 19:59:32 - [75,415] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft O43 - CFD: 16/12/2012 - 20:16:25 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft Help O43 - CFD: 27/11/2012 - 16:42:11 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\mondicoreader O43 - CFD: 29/08/2012 - 19:20:08 - [32,273] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla O43 - CFD: 02/11/2012 - 22:38:20 - [0,003] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\mquadr.at O43 - CFD: 11/03/2013 - 22:23:59 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\PasswordSafe O43 - CFD: 12/12/2012 - 18:22:44 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\PoiEdit O43 - CFD: 28/08/2012 - 22:34:42 - [0,282] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Sun O43 - CFD: 11/11/2012 - 18:15:59 - [0] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\Temp O43 - CFD: 29/06/2013 - 18:28:32 - [0,166] ----D C:\Documents and Settings\Administrateur\Local Settings\Application Data\TomTom O43 - CFD: 02/04/2013 - 15:37:11 - [0,014] R---D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Accessoires O43 - CFD: 10/03/2013 - 22:34:18 - [0,016] ----D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Audio-Vidéo O43 - CFD: 24/11/2012 - 23:21:06 - [0,000] R---D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage O43 - CFD: 15/07/2013 - 09:01:20 - [0,002] ----D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\GPS O43 - CFD: 02/04/2013 - 21:28:09 - [0,001] ----D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Navigateurs O43 - CFD: 04/07/2013 - 11:59:39 - [0,008] ----D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Nettoyage, maintenance, sauvegardes O43 - CFD: 23/06/2013 - 19:44:30 - [0,000] R---D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Outils d'administration O43 - CFD: 31/03/2013 - 17:11:44 - [0,002] ----D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Sécurité O43 - CFD: 20/04/2013 - 16:18:03 - [0,001] ----D C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\XMind ~ Program Folder: 207 Scanned in 00mn 36s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.CA320E7927F60CF19A5E764F842BA2B6] - 19/07/2013 - 16:23:19 ---A- . (...) -- C:\WINDOWS\system32\wpa.dbl [2206] O44 - LFC:[MD5.704E68F8CDDD39EAC9E4942F9641B7D4] - 19/07/2013 - 16:22:47 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1262764] O44 - LFC:[MD5.E25DD35DBECDE9DCC6413C1087A9742A] - 19/07/2013 - 16:22:24 ---A- . (...) -- C:\WINDOWS\system32\lservsta [296043] O44 - LFC:[MD5.385937FC8D3B47B97000DB1664FBEBC4] - 19/07/2013 - 16:22:03 ---A- . (...) -- C:\WINDOWS\setupapi.log [166056] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 19/07/2013 - 16:22:01 ---A- . (...) -- C:\WINDOWS\0.log [0] O44 - LFC:[MD5.7BA80B34C6421BD94D7388E17023A52A] - 19/07/2013 - 16:22:00 ---A- . (...) -- C:\WINDOWS\wiadebug.log [237] O44 - LFC:[MD5.31D7408942CD4E438D0D47C7C6C8EC3F] - 19/07/2013 - 16:21:58 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50] O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 19/07/2013 - 16:21:10 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048] O44 - LFC:[MD5.47753FC8A002AF8D6A41DE96C5CCF70B] - 19/07/2013 - 16:21:09 ---A- . (...) -- C:\WINDOWS\system32\ativvaxx.cap [3568] O44 - LFC:[MD5.3235DC83ADA49200732024E78D355A4D] - 19/07/2013 - 16:20:03 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32342] O44 - LFC:[MD5.79BECDF8B965DD046D78BB2A5152E7F7] - 19/07/2013 - 15:55:30 ---A- . (...) -- C:\WINDOWS\system32\perfc009.dat [92134] O44 - LFC:[MD5.763615D936B02A30C1C61476CFA5133E] - 19/07/2013 - 15:55:30 ---A- . (...) -- C:\WINDOWS\system32\perfc00C.dat [118340] O44 - LFC:[MD5.CA29E7D862A7CC0D92E87BA8D48AB6D1] - 19/07/2013 - 15:55:30 ---A- . (...) -- C:\WINDOWS\system32\perfh009.dat [528630] O44 - LFC:[MD5.15894198F57E3C707CC538BC2DBABEBC] - 19/07/2013 - 15:55:30 ---A- . (...) -- C:\WINDOWS\system32\perfh00C.dat [624714] O44 - LFC:[MD5.80F6A392A409A2AEE90D3E9C79B50F62] - 19/07/2013 - 15:54:32 ---A- . (...) -- C:\WINDOWS\nsw.log [887] O44 - LFC:[MD5.DA21D3251FDB3799331581C7027EC616] - 19/07/2013 - 15:17:47 ---A- . (...) -- C:\WINDOWS\setupact.log [5109] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 19/07/2013 - 14:58:47 --HA- . (...) -- C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf [0] O44 - LFC:[MD5.109014DB646968C3A1A0DCFC06D9903B] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\MedCtrOC.log [1275] O44 - LFC:[MD5.B9563F0C16D0BAD9A3C9DBA8A33883A6] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\comsetup.log [6183] O44 - LFC:[MD5.352FBB934BD9F6B9CE0E17A0E632E998] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\iis6.log [20037] O44 - LFC:[MD5.E9D8CD7DA3CA063BF107A689E79DD591] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\imsins.log [1374] O44 - LFC:[MD5.760D8400007B9C61E132CE1CB170B57D] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\msgsocm.log [927] O44 - LFC:[MD5.BB90623DC64B84B508D11784EA036511] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\netfxocm.log [3249] O44 - LFC:[MD5.9A8CC68B6A80EF654D87258CAF8CE629] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\ntdtcsetup.log [3741] O44 - LFC:[MD5.DA5689E1D670937EAB9F81DD2B6825B5] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\ocgen.log [8868] O44 - LFC:[MD5.48C377FAF31138008C52B234D6CA7B80] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\ocmsn.log [1026] O44 - LFC:[MD5.A72968432882126ED8DA9CE49C07F983] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\tabletoc.log [933] O44 - LFC:[MD5.09FCF49BC0EA0C30B579FF8E634EE867] - 19/07/2013 - 14:58:46 ---A- . (...) -- C:\WINDOWS\tsoc.log [8463] O44 - LFC:[MD5.D88B30126A0F7EFCFAD6920F622471D1] - 19/07/2013 - 14:58:45 ---A- . (...) -- C:\WINDOWS\FaxSetup.log [18550] O44 - LFC:[MD5.BA5B23014C34C000903C77132A6A8F07] - 19/07/2013 - 14:58:38 ---A- . (...) -- C:\WINDOWS\msmqinst.log [5712] O44 - LFC:[MD5.09349DBF356E139A3D2D7CC66ED91619] - 19/07/2013 - 09:05:49 ---A- . (...) -- C:\AdwCleaner[R29].txt [1508] O44 - LFC:[MD5.0905370F973FE5BD7D324DDD1BF18AA2] - 19/07/2013 - 07:57:03 ---A- . (...) -- C:\WINDOWS\system32\PerfStringBackup.INI [1339368] O44 - LFC:[MD5.D46E4B4A3C48350959EDEE19F3189933] - 19/07/2013 - 07:45:32 ---A- . (...) -- C:\WINDOWS\KB2808679.log [12662] O44 - LFC:[MD5.E4AEFE8B6FE5D9A206D61D8BBAE6F1FC] - 19/07/2013 - 07:45:32 ---A- . (...) -- C:\WINDOWS\imsins.BAK [1374] O44 - LFC:[MD5.6E453E702B431937B97EFDC25D83D218] - 19/07/2013 - 07:45:29 ---A- . (...) -- C:\WINDOWS\updspapi.log [1011] O44 - LFC:[MD5.D0633F46DF4AAB15FB384C5F9905C2DD] - 19/07/2013 - 07:38:51 ---A- . (...) -- C:\WINDOWS\KB2632503-IE8.log [9297] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 19/07/2013 - 07:38:43 ---A- . (...) -- C:\WINDOWS\setuperr.log [0] O44 - LFC:[MD5.04DC861BB0336E6F97B668E810A93E61] - 19/07/2013 - 07:07:10 ---A- . (...) -- C:\AdwCleaner[R28].txt [1447] O44 - LFC:[MD5.A31246180E61140AD7FF9DD7EDF1F6A1] - 19/07/2013 - 06:36:59 ---A- . (.Trend Micro Inc. - TrendMicro Common Module NoTrap Build.) -- C:\WINDOWS\system32\Drivers\tmcomm.sys [200976] O44 - LFC:[MD5.B695A532891B927459579C25C7E69901] - 18/07/2013 - 21:38:20 ---A- . (...) -- C:\AdwCleaner[S7].txt [1742] O44 - LFC:[MD5.322658F64FD7AAFE16B999B02B713535] - 18/07/2013 - 21:37:19 ---A- . (...) -- C:\AdwCleaner[R27].txt [1676] O44 - LFC:[MD5.81360ACBCA851F9FEE87E6BDC53E1289] - 18/07/2013 - 08:51:01 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\WINDOWS\system32\FlashPlayerApp.exe [692104] O44 - LFC:[MD5.8C1348AB014241E4C92E12AC5B0C34FC] - 18/07/2013 - 08:51:00 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl [71048] O44 - LFC:[MD5.2A845AA98E7F0BFD4B4D943DFB97599A] - 16/07/2013 - 09:26:57 ----- . (.Hewlett-Packard Co. - HP Discovery Port Monitor.) -- C:\WINDOWS\system32\HPDiscoPM5912.dll [544616] O44 - LFC:[MD5.89EAFA4BC408233376A671415670812D] - 16/07/2013 - 09:26:52 ---A- . (.Hewlett-Packard - Hewlett-Packard WIA 1.0 scanner driver.) -- C:\WINDOWS\system32\HPWia1_OJ8600.dll [488808] O44 - LFC:[MD5.233CB3C555D7B4C3E6CED6BA80FFAC9B] - 16/07/2013 - 09:26:52 ---A- . (.Hewlett-Packard Co. - HPScanTRDrv Module.) -- C:\WINDOWS\system32\HPScanTRDrv_OJ8600.dll [1946472] O44 - LFC:[MD5.DCFA512AB345485F4487DE22551A96D0] - 16/07/2013 - 09:26:49 ---A- . (.Hewlett-Packard Co. - DeviceCoInstaller.) -- C:\WINDOWS\system32\hpinkcoi5912.dll [216424] O44 - LFC:[MD5.1665A33CEF8427CE81574E389B7CBEEC] - 16/07/2013 - 09:26:49 ---A- . (.Hewlett-Packard Co. - Print Status Interface.) -- C:\WINDOWS\system32\hpinksts5912.dll [429928] O44 - LFC:[MD5.B67B1C5A722A6EBF074903F9D96CF7A7] - 16/07/2013 - 09:26:48 ---A- . (.Hewlett-Packard Co. - Print Status Language Monitor.) -- C:\WINDOWS\system32\hpinksts5912LM.dll [270696] O44 - LFC:[MD5.B155A71562C82CECA7DC22D9CFA55737] - 15/07/2013 - 10:25:13 ---A- . (...) -- C:\AdwCleaner[R26].txt [1265] O44 - LFC:[MD5.551166803B195060C8F4CA5555F74DB9] - 12/07/2013 - 07:19:44 ---A- . (...) -- C:\WINDOWS\system32\FNTCACHE.DAT [245512] O44 - LFC:[MD5.97F8765AA163AD92FE5CA39D4C0D3908] - 06/07/2013 - 11:40:53 ---A- . (...) -- C:\WINDOWS\quark.ini [36] O44 - LFC:[MD5.D066C6E0918AABA89844DD696D26E841] - 06/07/2013 - 11:28:48 ---A- . (.Rainbow Technologies, Inc. - Sentinel System Driver Virtual Device Drive.) -- C:\WINDOWS\system32\rnbovdd.dll [18432] O44 - LFC:[MD5.75A464AB094498AADB12F4BEDB152D8C] - 06/07/2013 - 09:34:09 ---A- . (...) -- C:\AdwCleaner[S6].txt [1469] O44 - LFC:[MD5.13D7267FD7174832D1FBF9FF5E17C71C] - 06/07/2013 - 09:33:01 ---A- . (...) -- C:\AdwCleaner[R25].txt [1405] ~ Files: 55 Scanned in 00mn 03s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.DFCFC80FDD8E619CC4387EA78459F6D9] - 18/07/2013 - 21:19:44 ---A- - C:\WINDOWS\Prefetch\HPNETWORKCOMMUNICATOR.EXE-06F04F0C.pf O45 - LFCP:[MD5.EB32EE3DF1F362C98AD893543EBC4FAD] - 19/07/2013 - 06:50:09 ---A- - C:\WINDOWS\Prefetch\EXCEL.EXE-0164E1F4.pf O45 - LFCP:[MD5.8C26ABB2B46D64A3F2500B520D8DB431] - 19/07/2013 - 07:28:05 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf O45 - LFCP:[MD5.8BA6F1126135AE962CF9D41D41304BF7] - 19/07/2013 - 07:45:17 ---A- - C:\WINDOWS\Prefetch\UPDROOTS.EXE-15EEE67B.pf O45 - LFCP:[MD5.89D50DCC966B5937A2180A31C060042F] - 19/07/2013 - 07:47:42 ---A- - C:\WINDOWS\Prefetch\UNLODCTR.EXE-37313252.pf O45 - LFCP:[MD5.9EEAF5010A8375C6220667B7CB06FBC6] - 19/07/2013 - 07:48:52 ---A- - C:\WINDOWS\Prefetch\REGTLIBV12.EXE-35B5D8AD.pf O45 - LFCP:[MD5.C42BED18400DD1C90A05B4DCB2D720A2] - 19/07/2013 - 07:51:55 ---A- - C:\WINDOWS\Prefetch\MSIPATCHREGFIX-X86.EXE-2ADB4CCC.pf O45 - LFCP:[MD5.99386922EE2B5068D1F3559F3A8A2191] - 19/07/2013 - 07:57:00 ---A- - C:\WINDOWS\Prefetch\MOFCOMP.EXE-01718E95.pf O45 - LFCP:[MD5.38AEC90D33CEAE5A6D8ABCD7C7C68DA1] - 19/07/2013 - 07:57:18 ---A- - C:\WINDOWS\Prefetch\LODCTR.EXE-1009C3B4.pf O45 - LFCP:[MD5.0EF111F694A2591405B5BE570BFAB20B] - 19/07/2013 - 08:57:42 ---A- - C:\WINDOWS\Prefetch\GOOGLECRASHHANDLER.EXE-16C80308.pf O45 - LFCP:[MD5.6536C383D76CBD8B6BE385B819FE0994] - 19/07/2013 - 09:02:12 ---A- - C:\WINDOWS\Prefetch\ADWCLEANER.EXE-14F98D0A.pf O45 - LFCP:[MD5.53EE490A63CA629D325545C2A7139E4B] - 19/07/2013 - 09:03:26 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-17B341D7.pf O45 - LFCP:[MD5.16E9E0D12153C6F9DA23B1C3160E4CC7] - 19/07/2013 - 09:03:35 ---A- - C:\WINDOWS\Prefetch\MSHTA.EXE-331DF029.pf O45 - LFCP:[MD5.694EF4CAA6F9E7F1413CEE5358FA51D7] - 19/07/2013 - 09:06:55 ---A- - C:\WINDOWS\Prefetch\MSICUU.EXE-36C66799.pf O45 - LFCP:[MD5.78E49AA0D55529B7DCD027475CE4AE89] - 19/07/2013 - 09:08:42 ---A- - C:\WINDOWS\Prefetch\CONTROL.EXE-013DBFB5.pf O45 - LFCP:[MD5.1B574A4009438C78EF57AFD3521C9FE2] - 19/07/2013 - 09:08:43 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-13E68835.pf O45 - LFCP:[MD5.1A0F52BC51CDAAA3AED6A4C2898D4609] - 19/07/2013 - 09:10:08 ---A- - C:\WINDOWS\Prefetch\ERUNT.EXE-10F447C7.pf O45 - LFCP:[MD5.4D4EE949CCBD7B72EC3376EC6B053CAC] - 19/07/2013 - 09:10:32 ---A- - C:\WINDOWS\Prefetch\NTREGOPT.EXE-14783365.pf O45 - LFCP:[MD5.F5D9F13F50CD9270E420360DCC0B0A73] - 19/07/2013 - 09:17:53 ---A- - C:\WINDOWS\Prefetch\MYDEFRAG.EXE-27931A93.pf O45 - LFCP:[MD5.1FFFC68E59E3DFB9CA82669BA417793E] - 19/07/2013 - 11:09:26 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-26E91A0F.pf O45 - LFCP:[MD5.84835277F6A415502339802C281ACBBA] - 19/07/2013 - 11:10:34 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-1F95A0AC.pf O45 - LFCP:[MD5.86BB6C5A94766F431B9A5B3139CF2EA7] - 19/07/2013 - 11:27:24 ---A- - C:\WINDOWS\Prefetch\NITROP~4.EXE-1BF35B51.pf O45 - LFCP:[MD5.E1A2E467CB106D4757E3EED4935C9DD7] - 19/07/2013 - 11:27:49 ---A- - C:\WINDOWS\Prefetch\PLUGIN-CONTAINER.EXE-15EDC9DD.pf O45 - LFCP:[MD5.6263FEA6411BB4C602C3DFF92F92F69C] - 19/07/2013 - 11:36:47 ---A- - C:\WINDOWS\Prefetch\PWSAFE.EXE-0FFF15EE.pf O45 - LFCP:[MD5.70D3E87F03ECAF23DCAFDD9A39305932] - 19/07/2013 - 12:25:05 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-37A55E23.pf O45 - LFCP:[MD5.6180F37AB3C42FE6225C2D1F33DDC0B8] - 19/07/2013 - 12:35:29 ---A- - C:\WINDOWS\Prefetch\UPDATE.EXE-2577D203.pf O45 - LFCP:[MD5.36F84249D7F9D6BC801437752D951528] - 19/07/2013 - 12:35:38 ---A- - C:\WINDOWS\Prefetch\UPDRGUI.EXE-027FAE5A.pf O45 - LFCP:[MD5.1734B24D00F3B50BC27C7E3F4592C177] - 19/07/2013 - 13:48:17 ---A- - C:\WINDOWS\Prefetch\SAMSUNG-KIES_2-6-0-13064-2_FR-0AE07C5F.pf O45 - LFCP:[MD5.83E902B5F8A1B8B5D9F35B38B6F45657] - 19/07/2013 - 13:48:43 ---A- - C:\WINDOWS\Prefetch\WRITEDESCEXECUTEFILENAME.EXE-083ECAFF.pf O45 - LFCP:[MD5.F5E806CA36C65C8643C303A5E95E9960] - 19/07/2013 - 13:59:53 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-118888AE.pf O45 - LFCP:[MD5.90C3E64FCF713614BE867CBB8B596284] - 19/07/2013 - 14:01:49 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-23AFA353.pf O45 - LFCP:[MD5.A0D2B430769BB1C2DDF3084A7D45D983] - 19/07/2013 - 14:02:59 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-43A64E89.pf O45 - LFCP:[MD5.815D8F3C861561D1B9CBFE32A91DECF0] - 19/07/2013 - 14:06:13 ---A- - C:\WINDOWS\Prefetch\ACRORD32.EXE-3B19D33B.pf O45 - LFCP:[MD5.340B9A2565C8264686D3BEBED3B719C0] - 19/07/2013 - 14:48:31 ---A- - C:\WINDOWS\Prefetch\SAMSUNG-KIES_2-6-0-13064-2_FR-0DD19392.pf O45 - LFCP:[MD5.EBAF11F4CD9C6A03CCBBE7E8622445D6] - 19/07/2013 - 14:48:57 ---A- - C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf O45 - LFCP:[MD5.AECF623BDFA713989B29B969B16B2E17] - 19/07/2013 - 14:50:51 ---A- - C:\WINDOWS\Prefetch\WRITEDESCEXECUTEFILENAME.EXE-287133B4.pf O45 - LFCP:[MD5.B3C0DD7B92A853EDE3CA894C74673CF2] - 19/07/2013 - 14:52:21 ---A- - C:\WINDOWS\Prefetch\EXPAND.EXE-2490DB85.pf O45 - LFCP:[MD5.F1A3B2F49161B5248F8A1E8CE3683CD5] - 19/07/2013 - 14:55:07 ---A- - C:\WINDOWS\Prefetch\NGEN.EXE-1F9EA69F.pf O45 - LFCP:[MD5.DD01F174AEE7A2F5FA84FC5E2EA6A97D] - 19/07/2013 - 14:56:12 ---A- - C:\WINDOWS\Prefetch\KIESAGENT.EXE-08CE9DBD.pf O45 - LFCP:[MD5.3D813164BB4B9A26C8926FE0404522EB] - 19/07/2013 - 14:56:27 ---A- - C:\WINDOWS\Prefetch\WPFFONTCACHE_V0400.EXE-212A3846.pf O45 - LFCP:[MD5.32B946F04A9BC9370DF2FF3C6A0C170C] - 19/07/2013 - 14:56:32 ---A- - C:\WINDOWS\Prefetch\CONNECTIONMANAGER.EXE-3A872C5F.pf O45 - LFCP:[MD5.97A30C92B9EDE0CC2D8A28390CC0AA5F] - 19/07/2013 - 14:56:32 ---A- - C:\WINDOWS\Prefetch\DEVICEMANAGER.EXE-30082278.pf O45 - LFCP:[MD5.86C70C39E86F501F149E02BB70B05043] - 19/07/2013 - 14:56:42 ---A- - C:\WINDOWS\Prefetch\CVTRES.EXE-39A29289.pf O45 - LFCP:[MD5.D15B33BD09CABC92E197D6B560C5B7DF] - 19/07/2013 - 14:56:43 ---A- - C:\WINDOWS\Prefetch\CSC.EXE-250B622E.pf O45 - LFCP:[MD5.5F9FB09C0F3F3AC76AC9313B62A719E9] - 19/07/2013 - 14:57:12 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-3965301C.pf O45 - LFCP:[MD5.EEB42BE819ADD08525A51C09CBAE2BBD] - 19/07/2013 - 14:57:32 ---A- - C:\WINDOWS\Prefetch\UPDATE.EXE-09704197.pf O45 - LFCP:[MD5.AD5D8A3CD77F8A1C8A10692A8AE78D6F] - 19/07/2013 - 14:57:36 ---A- - C:\WINDOWS\Prefetch\MICROSOFT WINUSB INSTALL-V1.0-1A3C6F6B.pf O45 - LFCP:[MD5.C469AE4B99079797F12FFE6DE73F5E71] - 19/07/2013 - 15:02:17 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-2DB435EA.pf O45 - LFCP:[MD5.A06B225522AB17278EA715C04C7DA0EE] - 19/07/2013 - 15:02:42 ---A- - C:\WINDOWS\Prefetch\UPDATE.EXE-3374175E.pf O45 - LFCP:[MD5.77AA35EC7ECFF7ED4CF5BFA84CB8E5C7] - 19/07/2013 - 15:02:49 ---A- - C:\WINDOWS\Prefetch\MICROSOFT WINUSB INSTALL-V1.0-29DFFBE4.pf O45 - LFCP:[MD5.857161AC6E26517629A5E07EEBFA286A] - 19/07/2013 - 15:04:23 ---A- - C:\WINDOWS\Prefetch\SAMSUNG_USB_DRIVER_FOR_MOBILE-06A217F5.pf O45 - LFCP:[MD5.0DD498190EDDA7A89D37FE24601F8A1D] - 19/07/2013 - 15:04:59 ---A- - C:\WINDOWS\Prefetch\SETUP.EXE-2BC13049.pf O45 - LFCP:[MD5.8C2A581169508BF17032DFEAB41D29CA] - 19/07/2013 - 15:13:08 ---A- - C:\WINDOWS\Prefetch\MSCORSVW.EXE-1366B4F5.pf O45 - LFCP:[MD5.EEB23D35764381F2F3F99CAB04244E0E] - 19/07/2013 - 15:15:13 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-1F7BD309.pf O45 - LFCP:[MD5.D59B51F32BF58EFC06D024F7E2757E22] - 19/07/2013 - 15:15:32 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-3E17E352.pf O45 - LFCP:[MD5.03AAA728B0740D1404955C6BA1F04B6C] - 19/07/2013 - 15:16:34 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-46C80BD5.pf O45 - LFCP:[MD5.056BC40F7D333D91B4543F58DA0B9881] - 19/07/2013 - 15:16:47 ---A- - C:\WINDOWS\Prefetch\UPDATE.EXE-2B81B247.pf O45 - LFCP:[MD5.5337BFC9625DFDB96F5DD33ED0A96248] - 19/07/2013 - 15:16:52 ---A- - C:\WINDOWS\Prefetch\MICROSOFT WINUSB INSTALL-V1.0-00A1D37A.pf O45 - LFCP:[MD5.0C677C5AD110B5D7FFA27B64AEB20E7E] - 19/07/2013 - 15:17:58 ---A- - C:\WINDOWS\Prefetch\DEVICEDATASERVICE.EXE-2C6EB740.pf O45 - LFCP:[MD5.480851D7EFFF9D4C49793AD86661004F] - 19/07/2013 - 15:42:25 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf O45 - LFCP:[MD5.AAA559432A7EDD7BE4C6604147905642] - 19/07/2013 - 15:50:06 ---A- - C:\WINDOWS\Prefetch\OUTLOOK.EXE-33904C46.pf O45 - LFCP:[MD5.8E57BFBAFFFB538B2F97CD4C5F76A3AC] - 19/07/2013 - 15:50:29 ---A- - C:\WINDOWS\Prefetch\OSPPSVC.EXE-307F45D2.pf O45 - LFCP:[MD5.6DFA7B9832801C69B554CBD33A6468A8] - 19/07/2013 - 15:53:02 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-4B06AD8F.pf O45 - LFCP:[MD5.3164242D6E20867B990C2E11E542A175] - 19/07/2013 - 15:53:12 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-14FC201E.pf O45 - LFCP:[MD5.E9E4D5F4E4FFB7EF08F93F1462A9133F] - 19/07/2013 - 15:54:13 ---A- - C:\WINDOWS\Prefetch\RUNONCE.EXE-2803F297.pf O45 - LFCP:[MD5.67A1CBD1471E38771D5D7B24C038A0CA] - 19/07/2013 - 15:54:32 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-268BFF96.pf O45 - LFCP:[MD5.3B308D41F6A2DA60DE59FF4618D59FC7] - 19/07/2013 - 15:55:30 ---A- - C:\WINDOWS\Prefetch\WMIADAP.EXE-2DF425B2.pf O45 - LFCP:[MD5.2E1482800F5E7F33F9DD3079D2CE62AD] - 19/07/2013 - 15:59:46 ---A- - C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf O45 - LFCP:[MD5.C01B73DE37086ADBB001F1E16C4E06EC] - 19/07/2013 - 16:01:17 ---A- - C:\WINDOWS\Prefetch\KIESTRAYAGENT.EXE-2338B09E.pf O45 - LFCP:[MD5.9996C99313D1512FC2516BF773DE8C7F] - 19/07/2013 - 16:01:33 ---A- - C:\WINDOWS\Prefetch\KIESPDLR.EXE-3B202350.pf O45 - LFCP:[MD5.F45E189A80B77345BB21E8E804A9B85A] - 19/07/2013 - 16:01:39 ---A- - C:\WINDOWS\Prefetch\KIES.EXE-32E73EEC.pf O45 - LFCP:[MD5.17E9B3851DE427C6C88B2F3056A7CE6C] - 19/07/2013 - 16:01:59 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-147710F4.pf O45 - LFCP:[MD5.E86A65E42F554751D4A713DAC96C6BDC] - 19/07/2013 - 16:02:05 ---A- - C:\WINDOWS\Prefetch\MMC.EXE-39071BCC.pf O45 - LFCP:[MD5.4F85ADED3BEECBA71F35B03C904966D2] - 19/07/2013 - 16:08:19 ---A- - C:\WINDOWS\Prefetch\RSTRUI.EXE-03C49A96.pf O45 - LFCP:[MD5.0A907087839C390E8979800D33B106F3] - 19/07/2013 - 16:08:56 ---A- - C:\WINDOWS\Prefetch\ADWCLEANER.EXE-2EE8E3FD.pf O45 - LFCP:[MD5.C3C02CD8144478A4DC10BDE5A65B1A92] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\JQS.EXE-21B69FF4.pf O45 - LFCP:[MD5.F3DC3BCF5F14F3C0B74871F09116138C] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\LSERVNT.EXE-39269B8E.pf O45 - LFCP:[MD5.1FC6D8692BE2B3C5E82987613BBBE911] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\NASVC.EXE-1DF30799.pf O45 - LFCP:[MD5.A032C2CB4345543251863FDFF90C1F73] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\NITROPDFREADERDRIVERSERVICE3.-15E1E152.pf O45 - LFCP:[MD5.ACE84E5A2083AD714655932E09E0E5B3] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf O45 - LFCP:[MD5.8FC0AA1CBCD8B7A3EEDE257289FA2B74] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\UPDATER.EXE-23F4D955.pf O45 - LFCP:[MD5.564C2E9D758C1DB20ACBC7B3C4685C62] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\VIALOGSV.EXE-0FD7C219.pf O45 - LFCP:[MD5.275AD317D35FB312D3710380606A5391] - 19/07/2013 - 16:12:31 ---A- - C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf O45 - LFCP:[MD5.4140FE969B9E2B56BCF1C07ABF4A3767] - 19/07/2013 - 16:16:17 ---A- - C:\WINDOWS\Prefetch\AVCENTER.EXE-1A970FA0.pf O45 - LFCP:[MD5.5C4F6A41E7B0738BA15838F4C4715FEA] - 19/07/2013 - 16:18:59 ---A- - C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf O45 - LFCP:[MD5.2B89D321ECD5F4B7751C6C7BC40DEF9A] - 19/07/2013 - 16:23:11 ---A- - C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf O45 - LFCP:[MD5.6B234E4397F05A21F88E5A3E02833919] - 19/07/2013 - 16:23:14 ---A- - C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf O45 - LFCP:[MD5.2824A9E0EF762C4A24DF4DD1117C1192] - 19/07/2013 - 16:23:17 ---A- - C:\WINDOWS\Prefetch\MPNOTIFY.EXE-3631A846.pf O45 - LFCP:[MD5.D4AB9697CE5AD007D32631986577BDCA] - 19/07/2013 - 16:23:23 ---A- - C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf O45 - LFCP:[MD5.D5321C2D0AFEF708F7867649E28544E7] - 19/07/2013 - 16:23:24 ---A- - C:\WINDOWS\Prefetch\WGATRAY.EXE-0ED38BED.pf O45 - LFCP:[MD5.E1E88732BDD384F557BC711E585A4EF5] - 19/07/2013 - 16:23:28 ---A- - C:\WINDOWS\Prefetch\ATI2EVXX.EXE-19D16EB9.pf O45 - LFCP:[MD5.143251852A3E2514DFAA091F65376E6D] - 19/07/2013 - 16:23:28 ---A- - C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf O45 - LFCP:[MD5.B36BDF14B9CC128B6C35CCAD9CC07CF9] - 19/07/2013 - 16:23:32 ---A- - C:\WINDOWS\Prefetch\HOSTS_ANTI-ADWARE_MAIN.EXE-0C80525D.pf O45 - LFCP:[MD5.7F3D15852022FB12CDF8C38E723CDA02] - 19/07/2013 - 16:23:32 ---A- - C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf O45 - LFCP:[MD5.A0A92EACA54D477BF26D15C006F8B671] - 19/07/2013 - 16:23:33 ---A- - C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf O45 - LFCP:[MD5.96C4CDAC36B3516013A4343C6812F6AB] - 19/07/2013 - 16:23:33 ---A- - C:\WINDOWS\Prefetch\JUSCHED.EXE-0173BDFB.pf O45 - LFCP:[MD5.60D3319450E685DAE6762DB5060CE927] - 19/07/2013 - 16:23:34 ---A- - C:\WINDOWS\Prefetch\LOOKNSTOP.EXE-2375335D.pf O45 - LFCP:[MD5.08068EC2AE9BB67EC83B51D07602C8E9] - 19/07/2013 - 16:23:36 ---A- - C:\WINDOWS\Prefetch\AVIRA_FREE_ANTIVIRUS.EXE-269F74F9.pf O45 - LFCP:[MD5.726DA8438912AB8CAC196ECCC883212C] - 19/07/2013 - 16:23:43 ---A- - C:\WINDOWS\Prefetch\AVWEBLOADER.EXE-04BFF2FE.pf O45 - LFCP:[MD5.2427E8505DC079B3638D5CED030DD796] - 19/07/2013 - 16:24:39 ---A- - C:\WINDOWS\Prefetch\PRESETUP.EXE-23750675.pf O45 - LFCP:[MD5.A6C9FD62F9E1F275D46E0EF369009C6B] - 19/07/2013 - 16:24:59 ---A- - C:\WINDOWS\Prefetch\INSTHLP.EXE-1A05A5BA.pf O45 - LFCP:[MD5.B77144FF03791FCBBF0A1151BF6F54C3] - 19/07/2013 - 16:25:01 ---A- - C:\WINDOWS\Prefetch\SETUP.EXE-1E3E54FC.pf O45 - LFCP:[MD5.23510E362185C628A612CB579C1C1D7B] - 19/07/2013 - 16:26:29 ---A- - C:\WINDOWS\Prefetch\AVGUARD.EXE-27095CE7.pf O45 - LFCP:[MD5.4DFFE096DF7E48C4D2CC8FAC8908881D] - 19/07/2013 - 16:26:58 ---A- - C:\WINDOWS\Prefetch\AVGNT.EXE-200FEF40.pf O45 - LFCP:[MD5.83D514BFC19119F6AD5C29042EA8F4F9] - 19/07/2013 - 16:27:05 ---A- - C:\WINDOWS\Prefetch\AVSHADOW.EXE-0F67375E.pf O45 - LFCP:[MD5.AF91B0EEFF2AE5CB978E9C269C01E108] - 19/07/2013 - 16:27:05 ---A- - C:\WINDOWS\Prefetch\SCHED.EXE-030F29E1.pf O45 - LFCP:[MD5.DEBA9C4FD19AE6F6E7E291EA8E3159E3] - 19/07/2013 - 16:28:24 ---A- - C:\WINDOWS\Prefetch\IPMGUI.EXE-1C3915CE.pf O45 - LFCP:[MD5.09B5CF033DF1234D21422E393E5DFBB0] - 19/07/2013 - 16:28:41 ---A- - C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf O45 - LFCP:[MD5.1BD5EBDBBEC7E83CE107E19DBB99AE56] - 19/07/2013 - 16:28:56 ---A- - C:\WINDOWS\Prefetch\CIDAEMON.EXE-27AE97A4.pf O45 - LFCP:[MD5.5F22D0B32093F4CEB0E946059B112CE3] - 19/07/2013 - 16:29:18 ---A- - C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf O45 - LFCP:[MD5.1EFD196C2FCF66611F9E705BD55CD2B8] - 19/07/2013 - 16:29:21 ---A- - C:\WINDOWS\Prefetch\MBAM.EXE-0BEE0439.pf O45 - LFCP:[MD5.E8F6B0F437F400FC35B84D3AB6E10D18] - 19/07/2013 - 16:30:02 ---A- - C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf O45 - LFCP:[MD5.37A24DA42543FBE8DDAE8E11ED540E53] - 19/07/2013 - 16:32:12 ---A- - C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf O45 - LFCP:[MD5.7261A8D196E256B9A894A06D0C9D5C42] - 19/07/2013 - 16:42:24 ---A- - C:\WINDOWS\Prefetch\FIREFOX.EXE-28641590.pf O45 - LFCP:[MD5.FA81FC937F4E269A7125521C9FF8E387] - 19/07/2013 - 16:45:05 ---A- - C:\WINDOWS\Prefetch\ZHPDIAG2.TMP-06B30FAA.pf O45 - LFCP:[MD5.C52B69936AF09313808FD30DAAB8CB59] - 19/07/2013 - 16:45:06 ---A- - C:\WINDOWS\Prefetch\ZHPDIAG2.EXE-0B9AE0C7.pf O45 - LFCP:[MD5.1F4FD87B18867D6FC370767050BBA32C] - 19/07/2013 - 16:59:55 ---A- - C:\WINDOWS\Prefetch\Layout.ini O45 - LFCP:[MD5.A870E9208C51B7AEEDB65DA6A1340272] - 19/07/2013 - 17:05:14 ---A- - C:\WINDOWS\Prefetch\WSCNTFY.EXE-1B24F5EB.pf O45 - LFCP:[MD5.6AB501AECD311F0C04ADFA6048706BAB] - 19/07/2013 - 17:29:51 ---A- - C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-1E123D86.pf O45 - LFCP:[MD5.1AD9338E82F747F685B7A4672FCF747B] - 19/07/2013 - 17:42:58 ---A- - C:\WINDOWS\Prefetch\NOTEPAD.EXE-189578DA.pf O45 - LFCP:[MD5.B251F637A269766A790B3207CC1FD485] - 19/07/2013 - 17:45:15 ---A- - C:\WINDOWS\Prefetch\AVWSC.EXE-0283F9DD.pf O45 - LFCP:[MD5.1E3223A3B1802A860AD6AC754AB17DCA] - 19/07/2013 - 17:48:01 ---A- - C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf O45 - LFCP:[MD5.9522EFEDB2CAEDBEC5F8B62427655E65] - 19/07/2013 - 17:52:20 ---A- - C:\WINDOWS\Prefetch\ZHPHEP.EXE-07C98D09.pf O45 - LFCP:[MD5.B4298B8446900302A996CC7140F8A6D9] - 19/07/2013 - 17:52:29 ---A- - C:\WINDOWS\Prefetch\ZHPDIAG.EXE-021B7932.pf O45 - LFCP:[MD5.387570756BFE16B92DFFFC5DE37C8374] - 19/07/2013 - 17:53:00 ---A- - C:\WINDOWS\Prefetch\FLASHPLAYERUPDATESERVICE.EXE-34BC5027.pf O45 - LFCP:[MD5.765AF880C6CE23BD5D4F2A56006DE555] - 19/07/2013 - 17:53:27 ---A- - C:\WINDOWS\Prefetch\PV.EXE-215F4419.pf O45 - LFCP:[MD5.44C0C9D0420DB1F913928FE1DE5891A0] - 19/07/2013 - 17:53:35 ---A- - C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf O45 - LFCP:[MD5.937322EDA0EBCCD7ACD48E026F278B01] - 19/07/2013 - 17:53:35 ---A- - C:\WINDOWS\Prefetch\SUBINACL.EXE-17974576.pf O45 - LFCP:[MD5.64AFEC47363B049A0893BF54DC80825F] - 19/07/2013 - 17:53:41 ---A- - C:\WINDOWS\Prefetch\SCHTASKS.EXE-0CBF6A11.pf ~ Prefetcher: 129 Scanned in 00mn 01s ---\\ Opérations et fonctions au démarrage de Windows Explorer (O46) O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL O46 - SEH:ShellExecuteHooks - Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll ~ ShellExecuteHooks: Scanned in 00mn 00s ---\\ Export de clé d'application autorisée (O47) O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\system32\sessmgr.exe O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O47 - AAKE:Key Export SP - "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" [Enabled] .(.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\Office14\OUTLOOK.exe O47 - AAKE:Key Export SP - "C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" [Enabled] .(.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\Office14\GROOVE.exe O47 - AAKE:Key Export SP - "C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe" [Enabled] .(.SafeNet, Inc..) -- C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe O47 - AAKE:Key Export SP - "C:\Program Files\upc cablecom\installer\upc_cablecom_installer.exe" [Enabled] .(.mquadr.at software engineering & consulting.) -- C:\Program Files\upc cablecom\installer\upc_cablecom_installer.exe O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\system32\sessmgr.exe O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe ~ Keys Export: 8 Scanned in 00mn 00s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\WINDOWS\system32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Kerberos Security Package.) -- C:\WINDOWS\system32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\WINDOWS\system32\wdigest.dll ~ LSA: 6 Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- C:\WINDOWS\system32\Drivers\dmboot.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\system32\Drivers\dmio.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- C:\WINDOWS\system32\Drivers\sr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\Wdf01000.sys . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\WINDOWS\system32\Drivers\Wdf01000.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- C:\WINDOWS\system32\Drivers\dmboot.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\system32\Drivers\dmio.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ip6fw.sys . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- C:\WINDOWS\system32\Drivers\ip6fw.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\system32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpcdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\WINDOWS\system32\Drivers\rdpcdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- C:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpwd.sys . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- C:\WINDOWS\system32\Drivers\rdpwd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- C:\WINDOWS\system32\Drivers\sr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdpipe.sys . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdpipe.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdtcp.sys . (.Microsoft Corporation - TCP Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdtcp.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\Wdf01000.sys . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\WINDOWS\system32\Drivers\Wdf01000.sys ~ CSB: 23 Scanned in 00mn 00s ---\\ Image File Execution Options (IFEO) (O50) O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d ~ IFEO: Scanned in 00mn 00s ---\\ Trojan Driver Search Data (HKLM) (O52) O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\system32\tssoft32.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\system32\iccvid.dll O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\system32\ir41_32.ax O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\system32\ir50_32.dll O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm ~ TDSD: 12 Scanned in 00mn 00s ---\\ ShareTools MSconfig StartupReg (O53) O53 - SMSR:HKLM\...\startupreg\HP Officejet Pro 8600 (NET) [Key] . (.Hewlett-Packard Co. - ScanToPCActivationApp.) -- C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe O53 - SMSR:HKLM\...\startupreg\MyTomTomSA.exe [Key] . (.TomTom - MyTomTom.) -- C:\Program Files\MyTomTom 3\MyTomTomSA.exe ~ SMSR Keys: 2 Scanned in 00mn 00s ---\\ Microsoft Control Security Providers (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll ~ MSCP: 6 Scanned in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "RunStartupScriptSync"=0 ~ MWPS: 6 Scanned in 00mn 00s ---\\ Microsoft Windows Policies Explorer (O56) O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=255 O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveAutoRun"=67108863 O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDesktopCleanupWizard"=1 O56 - MWPE:[HKCU\...\policies\Explorer] - "NoActiveDesktop"= O56 - MWPE:[HKCU\...\policies\Explorer] - "NoSaveSettings"= O56 - MWPE:[HKCU\...\policies\Explorer] - "ClearRecentDocsOnExit"= O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveTypeAutoRun"=255 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveAutoRun"=67108863 O56 - MWPE:[HKLM\...\policies\Explorer] - "HonorAutoRunSetting"=0 ~ MWPE Keys: 9 Scanned in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.7E682D97868CEFAE5D2BBD23EBBF7207] - 01/08/2008 - 07:38:20 ---A- . (.ATI Technologies Inc. - ATI Radeon WindowsNT Miniport Driver.) -- C:\WINDOWS\system32\Drivers\ati2mtag.sys [3266560] O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 28/09/2001 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9037] ~ Drivers: Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 16/07/2013 - 09:31:34 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\96D7A99548C36B10D2E8035A3E0DCA1A [1200180] O61 - LFC: 16/07/2013 - 09:31:34 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\96D7A99548C36B10D2E8035A3E0DCA1A [134] O61 - LFC: 16/07/2013 - 09:31:35 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\HP\AtInstall\HPDeviceSetupTimeSizeLog.txt [2824] O61 - LFC: 16/07/2013 - 09:31:36 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\HP\AtInstall\HPSoftwareTimeSizeLog.txt [1126] O61 - LFC: 16/07/2013 - 09:33:40 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\search-metadata.json [494] O61 - LFC: 16/07/2013 - 09:33:40 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\searchplugins\pc-astuces.xml [2584] O61 - LFC: 16/07/2013 - 09:33:41 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\search.json [13283] O61 - LFC: 16/07/2013 - 09:38:07 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\bookmarkbackups\bookmarks-2013-07-16.json [381722] O61 - LFC: 16/07/2013 - 14:38:04 ---A- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Nettoyage, maintenance, sauvegardes\RegSeeker\RegSeeker.lnk [706] O61 - LFC: 16/07/2013 - 14:38:06 ---A- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Nettoyage, maintenance, sauvegardes\RegSeeker\License.lnk [710] O61 - LFC: 16/07/2013 - 14:38:06 ---A- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Nettoyage, maintenance, sauvegardes\RegSeeker\Order.lnk [698] O61 - LFC: 16/07/2013 - 14:38:06 ---A- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Nettoyage, maintenance, sauvegardes\RegSeeker\Uninstall.lnk [705] O61 - LFC: 16/07/2013 - 14:38:06 ---A- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Nettoyage, maintenance, sauvegardes\RegSeeker\Website.lnk [722] O61 - LFC: 17/07/2013 - 11:16:34 ---A- C:\Documents and Settings\Administrateur\Bureau\Outils\speedyfox.exe [607704] O61 - LFC: 18/07/2013 - 02:47:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\pattern\icrc$oth.161 [36339219] O61 - LFC: 18/07/2013 - 08:51:21 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\12236C41CDDF9E40BA5606CDF086B821 [142375] O61 - LFC: 18/07/2013 - 08:51:21 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\12236C41CDDF9E40BA5606CDF086B821 [114] O61 - LFC: 18/07/2013 - 08:52:02 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [535736] O61 - LFC: 18/07/2013 - 08:52:19 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\bookmarkbackups\bookmarks-2013-07-18.json [381722] O61 - LFC: 18/07/2013 - 21:15:15 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 [105631] O61 - LFC: 18/07/2013 - 21:15:15 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 [124] O61 - LFC: 18/07/2013 - 21:16:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\OnlineUpdateBackup_2.1.47.0_20130718_221632.zip [8210528] O61 - LFC: 18/07/2013 - 21:16:49 ---A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CLR Security Config\v2.0.50727.42\security.config.cch [7818] O61 - LFC: 18/07/2013 - 21:17:58 -S-A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat [32768] O61 - LFC: 18/07/2013 - 21:18:49 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\chromeappsstore.sqlite [98304] O61 - LFC: 18/07/2013 - 21:18:51 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\search.sqlite [2048] O61 - LFC: 18/07/2013 - 21:19:13 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\urlclassifier3.sqlite [46071808] O61 - LFC: 18/07/2013 - 21:19:15 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\webappsstore.sqlite [3072] O61 - LFC: 18/07/2013 - 21:19:30 ---A- C:\Documents and Settings\Administrateur\Application Data\CrystalIdea Software\SpeedyFox\preferences.xml [378] O61 - LFC: 18/07/2013 - 21:31:47 ---A- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2013-07-18 (22-21-02).txt [2126] O61 - LFC: 18/07/2013 - 21:52:17 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\hcversion.xml [305] O61 - LFC: 18/07/2013 - 21:52:17 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\hcversion.xml [305] O61 - LFC: 18/07/2013 - 21:52:18 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\hcpackage.exe [2423744] O61 - LFC: 18/07/2013 - 21:52:29 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 [18] O61 - LFC: 18/07/2013 - 21:52:29 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 [52521] O61 - LFC: 18/07/2013 - 21:52:29 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 [216] O61 - LFC: 18/07/2013 - 21:52:29 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 [216] O61 - LFC: 18/07/2013 - 22:19:08 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\04AFA8793E5CDC4A81C6CD4554A30707 [1311] O61 - LFC: 18/07/2013 - 22:19:08 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\D4F348B882DF3F205ECCB6243795CB3A [554] O61 - LFC: 18/07/2013 - 22:19:08 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\04AFA8793E5CDC4A81C6CD4554A30707 [118] O61 - LFC: 18/07/2013 - 22:19:08 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\D4F348B882DF3F205ECCB6243795CB3A [112] O61 - LFC: 19/07/2013 - 06:35:37 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-4ba4f7f0.idx [463] O61 - LFC: 19/07/2013 - 06:36:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\AUCache\AU_Cache\housecall-ctp-p.activeupdate.trendmicro.com\ini_xml.zip [2487] O61 - LFC: 19/07/2013 - 06:36:33 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\AUCache\AU_Cache\housecall-ctp-p.activeupdate.trendmicro.com\ini_xml.zip.etag [164] O61 - LFC: 19/07/2013 - 06:36:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\patchretry.dat [12] O61 - LFC: 19/07/2013 - 06:36:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\temp_bf_0_1340000400_1374212210.retry [1] O61 - LFC: 19/07/2013 - 06:36:51 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\temp_bf_0_1340000400_1374212210.len [8] O61 - LFC: 19/07/2013 - 06:36:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HCBackup\temp_bf_0_1340000400_1374212210 [1591158] O61 - LFC: 19/07/2013 - 06:36:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\pattern\cache.dat [4] O61 - LFC: 19/07/2013 - 06:37:02 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\tmfbe\.inuse [0] O61 - LFC: 19/07/2013 - 06:37:02 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\tmfbep\.inuse [0] O61 - LFC: 19/07/2013 - 06:37:45 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\log\C6959E9E-59E7-4ADF-A174-A3C9969B8C71\configuration.xml [1150] O61 - LFC: 19/07/2013 - 06:40:18 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\B1AA84065EC5876DF7F06B36A34A8167 [14506] O61 - LFC: 19/07/2013 - 06:40:18 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\B1AA84065EC5876DF7F06B36A34A8167 [84] O61 - LFC: 19/07/2013 - 06:40:27 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\74BFD122C0875EC75DBE5C6DB4C59019 [19662] O61 - LFC: 19/07/2013 - 06:40:27 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\74BFD122C0875EC75DBE5C6DB4C59019 [124] O61 - LFC: 19/07/2013 - 06:41:08 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\B69D763EB21649DA26F20618312DEE70 [75397] O61 - LFC: 19/07/2013 - 06:41:08 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\B69D763EB21649DA26F20618312DEE70 [128] O61 - LFC: 19/07/2013 - 06:41:09 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\1F356F4D07FE8C483E769E4586569404 [47262] O61 - LFC: 19/07/2013 - 06:41:09 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\1F356F4D07FE8C483E769E4586569404 [126] O61 - LFC: 19/07/2013 - 06:41:33 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\DC2135CED98D8A4D7C0CEE202BB0B810 [469] O61 - LFC: 19/07/2013 - 06:41:33 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\F5A17C00E427F919C4A49EEF5AD0EE53 [460] O61 - LFC: 19/07/2013 - 06:41:33 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\DC2135CED98D8A4D7C0CEE202BB0B810 [98] O61 - LFC: 19/07/2013 - 06:41:33 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\F5A17C00E427F919C4A49EEF5AD0EE53 [110] O61 - LFC: 19/07/2013 - 06:41:59 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\3B6E683A7A45CC59BF035C9BA8C7AB9D [494] O61 - LFC: 19/07/2013 - 06:41:59 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\3B6E683A7A45CC59BF035C9BA8C7AB9D [132] O61 - LFC: 19/07/2013 - 06:50:04 ---A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Office\Recent\Ordonnances Besson.xlsx.LNK [583] O61 - LFC: 19/07/2013 - 06:50:04 ---A- C:\Documents and Settings\Administrateur\Recent\Anne.lnk [461] O61 - LFC: 19/07/2013 - 06:50:04 ---A- C:\Documents and Settings\Administrateur\Recent\Ordonnances Besson.xlsx.lnk [627] O61 - LFC: 19/07/2013 - 06:50:04 --H-- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Office\Recent\index.dat [1982] O61 - LFC: 19/07/2013 - 06:52:51 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\content-prefs.sqlite [229376] O61 - LFC: 19/07/2013 - 06:53:08 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\76\2CDD4d01 [27381] O61 - LFC: 19/07/2013 - 06:53:08 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\B\06\F26F9d01 [110585] O61 - LFC: 19/07/2013 - 06:53:55 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\healthreport\state.json [89] O61 - LFC: 19/07/2013 - 06:54:54 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\6D\78865d01 [36751] O61 - LFC: 19/07/2013 - 06:55:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\efd3b954dbc47a1fa4e8c1b649312ec9.png [38579] O61 - LFC: 19/07/2013 - 06:55:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\pattern\BF.ptn [11534380] O61 - LFC: 19/07/2013 - 06:55:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\pattern\crcdiff.dat [483541] O61 - LFC: 19/07/2013 - 06:56:12 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\58\46AE2d01 [41461] O61 - LFC: 19/07/2013 - 06:56:15 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\EC\BF413d01 [23050] O61 - LFC: 19/07/2013 - 06:56:15 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\B\37\894F3d01 [67843] O61 - LFC: 19/07/2013 - 06:56:15 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\6D\28440d01 [26753] O61 - LFC: 19/07/2013 - 06:56:37 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\92\91C8Fd01 [37340] O61 - LFC: 19/07/2013 - 06:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\DF\081C1d01 [27923] O61 - LFC: 19/07/2013 - 06:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\DC\7FBF8d01 [33430] O61 - LFC: 19/07/2013 - 06:56:40 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\37\A0ED9d01 [27337] O61 - LFC: 19/07/2013 - 06:56:41 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\3A\D7D9Fd01 [64578] O61 - LFC: 19/07/2013 - 06:56:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\DD\F81D5d01 [24496] O61 - LFC: 19/07/2013 - 06:56:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\2E\31BF6d01 [44706] O61 - LFC: 19/07/2013 - 06:56:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\A4\F9375d01 [35120] O61 - LFC: 19/07/2013 - 06:56:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\9\BA\5265Bd01 [103804] O61 - LFC: 19/07/2013 - 06:56:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\9\D2\7D9A8d01 [97502] O61 - LFC: 19/07/2013 - 06:56:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\DE\7F04Ad01 [65498] O61 - LFC: 19/07/2013 - 06:56:58 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\2E\DCEC4d01 [38293] O61 - LFC: 19/07/2013 - 06:56:58 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\1C\A7830d01 [23252] O61 - LFC: 19/07/2013 - 06:56:59 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\5F\580F5d01 [21399] O61 - LFC: 19/07/2013 - 07:00:49 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\1B\57BC8d01 [48751] O61 - LFC: 19/07/2013 - 07:02:06 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\005490403b4414c9bb7c8929e9188062.png [57084] O61 - LFC: 19/07/2013 - 07:02:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\6c74d453de356650734160af046aae24.png [70049] O61 - LFC: 19/07/2013 - 07:02:49 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\blocklist.xml [73641] O61 - LFC: 19/07/2013 - 07:02:49 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\15\A1C0Fd01 [73641] O61 - LFC: 19/07/2013 - 07:02:54 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\43175adfac0798d3761f0ca9afe55e0b.png [32821] O61 - LFC: 19/07/2013 - 07:03:11 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\bookmarkbackups\bookmarks-2013-07-19.json [381722] O61 - LFC: 19/07/2013 - 07:07:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\RdLang_rdlang32.fra [12092928] O61 - LFC: 19/07/2013 - 07:08:48 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\C\3F\11B4Dd01 [16559] O61 - LFC: 19/07/2013 - 07:09:04 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\pluginreg.dat [7678] O61 - LFC: 19/07/2013 - 07:09:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\A1\1C161d01 [63079] O61 - LFC: 19/07/2013 - 07:09:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\6\59\911DAd01 [36132] O61 - LFC: 19/07/2013 - 07:09:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\B\70\EF40Dd01 [41582] O61 - LFC: 19/07/2013 - 07:09:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\DC\34D55d01 [21327] O61 - LFC: 19/07/2013 - 07:09:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\31\E2B0Cd01 [62844] O61 - LFC: 19/07/2013 - 07:09:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\77\21873d01 [63712] O61 - LFC: 19/07/2013 - 07:09:21 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\A7\A10E5d01 [63564] O61 - LFC: 19/07/2013 - 07:09:22 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\82\AF25Ed01 [17135] O61 - LFC: 19/07/2013 - 07:09:22 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\C6\5F2F8d01 [29017] O61 - LFC: 19/07/2013 - 07:09:24 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\44904f78fbad8120a80a039b2b3c7c0f.png [122986] O61 - LFC: 19/07/2013 - 07:09:52 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\addons.sqlite [524288] O61 - LFC: 19/07/2013 - 07:09:52 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\6\35\92032d01 [775729] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\META-INF\manifest.mf [28421] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\META-INF\zigbert.sf [28529] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\block.html [2933] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\display.png [1609] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-about.js [861] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-about.png [12299] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-badge.xml [785] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-bugs.json [254579] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-clean.js [4343] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-click2play.json [2858] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-common.js [39631] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-compatibility.json [878] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-cookiemonster.js [2134] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-db.js [23430] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-html-options.js [38648] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-html-walkthrough.js [26089] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-lso.js [3798] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-lsos.json [79951] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-off-16x16.png [637] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-pbl.js [1829] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-rules.js [351] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-scanner.js [2215] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-silverlight.js [3932] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-sqlite.js [2208] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-surrogatedb.js [4210] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-translator.js [95334] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-ui.js [46118] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery.css [6678] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery.js [46215] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery.png [1689] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery.xul [8403] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery_eula.txt [3135] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\help-16x16.png [1067] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\arrow-hover.png [4614] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\arrows.gif [617] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\clippy_button_over.png [296] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\clippy_button_up.png [400] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\down.gif [487] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\ghostery-about.png [12299] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\gradBD.gif [319] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\panels.png [152498] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Footer\bh_ghostery_footer_button_disabled.png [3494] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Footer\bh_ghostery_footer_button_hover.png [3440] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Footer\bh_ghostery_footer_button_off.png [1724] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Footer\bh_ghostery_footer_help_down.png [1782] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Footer\bh_ghostery_footer_help_hover.png [3674] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Footer\bh_ghostery_footer_help_off.png [1989] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Header\bh_ghostery_header_cog_down.png [1947] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Header\bh_ghostery_header_cog_hover.png [3840] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Settings\bh_ghostery_settings_button_off.png [1632] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_alert.png [3299] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_arrow_down_hover.png [1475] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_arrow_down_off.png [1437] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_arrow_up_hover.png [1530] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_arrow_up_off.png [1459] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_check_grey_off.png [1905] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_green_hover.png [1956] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_green_off.png [1959] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_red_hover.png [1964] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_red_off.png [1937] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_track_hover_left.png [3858] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_track_off.png [3569] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_arrow_right_off.png [286] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_close_hover.png [1087] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_close_off.png [1136] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_control_off.png [2992] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_control_on.png [2992] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_indicator_check_green.png [3484] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_indicator_check_grey.png [3327] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_indicator_cross_blue.png [3408] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_indicator_cross_green.png [3449] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_indicator_cross_red.png [3439] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\turorial_panel.png [11527] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\base-short.png [196] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\base.png [230] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\bg-bottom.png [77] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\bg-top.png [82] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\email.png [398] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\ghosty_TM.png [6667] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\panelarrow-down.png [280] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\panelarrow-up.png [290] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\play.png [283] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\questions.png [264] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\reload-long.png [1157] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\reload.png [395] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\settings.png [531] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\right.gif [496] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\sample.png [14654] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\sample2.png [3523] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\sample3.png [3797] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\sample_c2p.png [5727] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\sample_c2p_button.png [6352] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\star.png [1814] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\includes\jquery-1.7.1.min.js [93868] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\includes\jquery.scrollintogreatness-1.0.0.js [873] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\includes\jquery.simplemodal.1.4.1.min.js [9469] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\includes\tiptip\jquery.tipTip.minified.js [5251] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\options.html [16819] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\options.xul [1193] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\popup.css [16921] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\popup.html [11638] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\share-16x16.png [890] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\tiptip_license.txt [829] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\transparent-16x16.png [212] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\wizard.html [12230] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\de-DE\ghostery.dtd [6115] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\en-US\ghostery.dtd [6173] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\en-US\ghostery.properties [986] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\es-ES\ghostery.dtd [6519] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\fr-FR\ghostery.dtd [6693] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\fr-FR\ghostery.properties [1168] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\ja-JP\ghostery.dtd [6705] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\ja-JP\ghostery.properties [1149] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\ru-RU\ghostery.dtd [7256] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\ru-RU\ghostery.properties [1326] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\components\ghostery-content-policy.js [16726] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\defaults\preferences\defaults.js [2048] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\ghostery_eula.txt [3135] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\install.rdf [3813] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\allow_unblock.png [1962] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\blocked_redirect.html [2242] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\font\OpenSans-Bold.eot [34226] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\font\OpenSans-Bold.svg [67899] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\font\OpenSans-Bold.ttf [34048] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\font\OpenSans-Bold.woff [21844] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery-32.png [1689] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery.png [718] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery_facebook.png [1650] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery_linkedin.png [1596] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery_pinterest.png [1782] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery_vkontakte.png [1666] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghosty_blocked.png [2048] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\icon128.png [3204] O61 - LFC: 19/07/2013 - 07:09:53 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\rbc_50px.png [2810] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\META-INF\zigbert.rsa [3045] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome.manifest [1023] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\about.xul [2931] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\cbox-check-dis.gif [60] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\cbox-check.gif [54] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\customize-16x16.gif [366] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-16x16.png [718] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-html-block.js [1300] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-surrogates.json [9038] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\ghostery-uninstaller.js [2580] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\arrow.png [4684] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Footer\bh_ghostery_footer_button_down.png [1488] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Header\bh_ghostery_header_cog_off.png [2152] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Settings\bh_ghostery_settings_button_down.png [1437] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Settings\bh_ghostery_settings_button_hover.png [3431] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_check_green_hover.png [1962] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_check_green_off.png [1955] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_check_grey_hover.png [1884] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_blue_hover.png [1959] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_blue_off.png [1943] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_yellow_hover.png [1962] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_indicator_cross_yellow_off.png [1948] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tracker\bh_ghostery_tracker_track_hover_right.png [3680] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_arrow_left_hover.png [3185] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_arrow_left_off.png [311] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_arrow_right_hover.png [166] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_indicator_cross_grey.png [3323] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_indicator_cross_yellow.png [3426] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\Tutorial\bh_ghostery_tutorial_track_lrg.png [10422] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\chat.png [325] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\ghosty-top.png [2532] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\pause-long.png [315] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\pause-reload.png [1231] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\popup\pause.png [360] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\images\s1.gif [2545] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\includes\tiptip\tipTip.css [2432] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\content\jquery_license.txt [366] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\de-DE\ghostery.properties [1050] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\chrome\locale\es-ES\ghostery.properties [1077] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\allow_once.png [1962] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\click2play.html [2364] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\click2play.png [976] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery_plus.png [1756] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery_stumble.png [1708] O61 - LFC: 19/07/2013 - 07:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions\firefox@ghostery.com\resource\ghostery_twitter.png [1732] O61 - LFC: 19/07/2013 - 07:09:58 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\healthreport.sqlite [1146880] O61 - LFC: 19/07/2013 - 07:10:05 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\extensions.sqlite [524288] O61 - LFC: 19/07/2013 - 07:10:06 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\user.bugs.db [0] O61 - LFC: 19/07/2013 - 07:10:06 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\user.site.preferences.db [0] O61 - LFC: 19/07/2013 - 07:10:11 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\bugs.db [247343] O61 - LFC: 19/07/2013 - 07:10:11 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\click2play.db [2784] O61 - LFC: 19/07/2013 - 07:10:11 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\compatibility.db [919] O61 - LFC: 19/07/2013 - 07:10:11 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\lsos.db [75441] O61 - LFC: 19/07/2013 - 07:10:11 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\surrogates.db [8941] O61 - LFC: 19/07/2013 - 07:10:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\B2\18914d01 [91713] O61 - LFC: 19/07/2013 - 07:10:21 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\6A\29AEAd01 [46261] O61 - LFC: 19/07/2013 - 07:15:15 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\V73C2Ja03316 [2031243] O61 - LFC: 19/07/2013 - 07:18:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\HouseCall\V73C2Jb03316 [0] O61 - LFC: 19/07/2013 - 07:18:33 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\90\44C06d01 [17021] O61 - LFC: 19/07/2013 - 07:18:35 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\A4\2FF48d01 [27267] O61 - LFC: 19/07/2013 - 07:18:35 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\15\C3FE6d01 [77094] O61 - LFC: 19/07/2013 - 07:18:35 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\67\0B528d01 [143665] O61 - LFC: 19/07/2013 - 07:18:35 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\74\CB68Ad01 [16540] O61 - LFC: 19/07/2013 - 07:18:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\0C\C4048d01 [18442] O61 - LFC: 19/07/2013 - 07:18:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\54\91CCBd01 [36772] O61 - LFC: 19/07/2013 - 07:18:57 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\ec8eff4a4887ce4f262608436d40a57f.png [61774] O61 - LFC: 19/07/2013 - 07:18:59 ---A- C:\Documents and Settings\Administrateur\Bureau\Outils\Peu utilisés\RogueKiller.exe [915968] O61 - LFC: 19/07/2013 - 07:19:48 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\207B9FD92391B9B2A60A89B4C965D5DF [618] O61 - LFC: 19/07/2013 - 07:19:48 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\D41693DAFE5DEF0C36959FF1FCEF5C96 [603] O61 - LFC: 19/07/2013 - 07:19:48 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\207B9FD92391B9B2A60A89B4C965D5DF [174] O61 - LFC: 19/07/2013 - 07:19:48 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\D41693DAFE5DEF0C36959FF1FCEF5C96 [166] O61 - LFC: 19/07/2013 - 07:19:49 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\B8CC409ACDBF2A2FE04C56F2875B1FD6 [561] O61 - LFC: 19/07/2013 - 07:19:49 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\B8CC409ACDBF2A2FE04C56F2875B1FD6 [134] O61 - LFC: 19/07/2013 - 07:23:15 ---A- C:\Documents and Settings\Administrateur\SecurityScans\Config\mru.cfg [514] O61 - LFC: 19/07/2013 - 07:23:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\MBSA\Cache\wsusscn2.cab [75594840] O61 - LFC: 19/07/2013 - 07:24:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\MBSA\Cache\wsusscn2.cab.dat [192] O61 - LFC: 19/07/2013 - 07:25:51 ---A- C:\Documents and Settings\Administrateur\SecurityScans\Config\CurrScanSet.cfg [372] O61 - LFC: 19/07/2013 - 07:25:51 ---A- C:\Documents and Settings\Administrateur\SecurityScans\DOMICILE - PCFIXE (19-07-2013 08-25).mbsa [258516] O61 - LFC: 19/07/2013 - 07:25:57 ---A- C:\Documents and Settings\Administrateur\Recent\RKreport[0]_S_07192013_082153.txt.lnk [610] O61 - LFC: 19/07/2013 - 07:26:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat [294804] O61 - LFC: 19/07/2013 - 07:27:10 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{2F445E94-F03C-11E2-AE7F-000000000000}.dat [3584] O61 - LFC: 19/07/2013 - 07:27:56 -S-A- C:\Documents and Settings\Administrateur\IECompatCache\index.dat [65536] O61 - LFC: 19/07/2013 - 07:27:56 -S-A- C:\Documents and Settings\Administrateur\PrivacIE\index.dat [131072] O61 - LFC: 19/07/2013 - 07:27:56 -SHA- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Internet Explorer\UserData\index.dat [32768] O61 - LFC: 19/07/2013 - 07:27:56 -SHA- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat [16384] O61 - LFC: 19/07/2013 - 07:27:57 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\0C09EE3178373E7148C22DF27EB85C4A [132843] O61 - LFC: 19/07/2013 - 07:27:57 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\0C09EE3178373E7148C22DF27EB85C4A [98] O61 - LFC: 19/07/2013 - 07:27:59 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\1DAF2884EC4DFA96BA4A58D4DBC9C406 [1393] O61 - LFC: 19/07/2013 - 07:27:59 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\AC9005F5466BD463DF06D711B370595F [10378] O61 - LFC: 19/07/2013 - 07:27:59 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\1DAF2884EC4DFA96BA4A58D4DBC9C406 [128] O61 - LFC: 19/07/2013 - 07:27:59 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\AC9005F5466BD463DF06D711B370595F [188] O61 - LFC: 19/07/2013 - 07:36:56 ---A- C:\Documents and Settings\Administrateur\Cookies\ZRWR1H50.txt [352] O61 - LFC: 19/07/2013 - 07:39:30 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\F90F18257CBB4D84216AC1E1F3BB2C76 [550] O61 - LFC: 19/07/2013 - 07:39:30 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\F90F18257CBB4D84216AC1E1F3BB2C76 [164] O61 - LFC: 19/07/2013 - 07:39:33 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\7396C420A8E1BC1DA97F1AF0D10BAD21 [554] O61 - LFC: 19/07/2013 - 07:39:33 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\7396C420A8E1BC1DA97F1AF0D10BAD21 [168] O61 - LFC: 19/07/2013 - 07:43:45 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\KB2600217_20130719_083901703-Microsoft .NET Framework 4 Client Profile-MSP0.txt [17279548] O61 - LFC: 19/07/2013 - 07:43:45 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\KB2600217_20130719_083901703.html [58840] O61 - LFC: 19/07/2013 - 07:51:07 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\KB2836939_20130719_084539750-Microsoft .NET Framework 4 Client Profile-MSP0.txt [18081444] O61 - LFC: 19/07/2013 - 07:51:07 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\KB2836939_20130719_084539750.html [65298] O61 - LFC: 19/07/2013 - 07:51:52 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\Microsoft .NET Framework 3.5-KB2836940_20130719_065123687-Msi0.txt [1395832] O61 - LFC: 19/07/2013 - 07:51:52 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\Microsoft .NET Framework 3.5-KB2836940_20130719_065123687.html [86678] O61 - LFC: 19/07/2013 - 07:51:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\dd_clwireg.txt [12426] O61 - LFC: 19/07/2013 - 07:57:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\Microsoft .NET Framework 2.0-KB2836941_20130719_065204156-Msi0.txt [18413856] O61 - LFC: 19/07/2013 - 07:57:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\Microsoft .NET Framework 2.0-KB2836941_20130719_065204156.html [501644] O61 - LFC: 19/07/2013 - 08:54:59 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{584F79E9-F03C-11E2-AE7F-000000000000}.dat [4096] O61 - LFC: 19/07/2013 - 08:54:59 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{584F79EA-F03C-11E2-AE7F-000000000000}.dat [41472] O61 - LFC: 19/07/2013 - 08:54:59 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{3D11BB94-F03C-11E2-AE7F-000000000000}.dat [3584] O61 - LFC: 19/07/2013 - 08:54:59 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\{8232612C-F048-11E2-AE7F-000000000000}.dat [32768] O61 - LFC: 19/07/2013 - 08:55:10 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows\UsrClass.bak [319488] O61 - LFC: 19/07/2013 - 09:03:39 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Protect\S-1-5-21-583907252-1284227242-725345543-500\d39eb06c-0c2e-4392-a84e-f5edfa8b127a [388] O61 - LFC: 19/07/2013 - 09:03:39 -SHA- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Protect\S-1-5-21-583907252-1284227242-725345543-500\2fac168a-f5e2-440b-b553-e9b7addaff55 [388] O61 - LFC: 19/07/2013 - 09:03:39 -SHA- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Protect\S-1-5-21-583907252-1284227242-725345543-500\d7acf8b2-1740-4161-af31-e265add34a5f [388] O61 - LFC: 19/07/2013 - 09:03:39 -SHA- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Protect\S-1-5-21-583907252-1284227242-725345543-500\e3749a42-4865-4562-9cf9-3a546b6e2eb1 [388] O61 - LFC: 19/07/2013 - 09:06:44 ---A- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Nettoyage, maintenance, sauvegardes\Windows Install Clean Up.lnk [2351] O61 - LFC: 19/07/2013 - 09:12:18 --HA- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows\UsrClass.tmp.LOG [0] O61 - LFC: 19/07/2013 - 09:13:04 ---A- C:\Documents and Settings\Administrateur\ntuser.bak [4980736] O61 - LFC: 19/07/2013 - 11:11:31 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\NitroSysFonts01.dat [194239] O61 - LFC: 19/07/2013 - 11:22:52 ---A- C:\Documents and Settings\Administrateur\Application Data\Nitro\Reader\3.0\DocLog.txt [0] O61 - LFC: 19/07/2013 - 11:22:52 ---A- C:\Documents and Settings\Administrateur\Application Data\Nitro\Reader\3.0\NitroPDFRecovery.dat [106] O61 - LFC: 19/07/2013 - 14:04:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\18\CAA26d01 [33136] O61 - LFC: 19/07/2013 - 14:04:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\9D\3C7F0d01 [118040] O61 - LFC: 19/07/2013 - 14:04:58 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\F1\29F8Cd01 [16543] O61 - LFC: 19/07/2013 - 14:04:58 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\9\DB\26136d01 [26946] O61 - LFC: 19/07/2013 - 14:04:58 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\02\53CD2d01 [102520] O61 - LFC: 19/07/2013 - 14:04:59 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\25\32FFAd01 [252285] O61 - LFC: 19/07/2013 - 14:04:59 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\6\76\A3E7Bd01 [25904] O61 - LFC: 19/07/2013 - 14:05:07 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\9\46\B1913d01 [30351] O61 - LFC: 19/07/2013 - 14:05:10 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\FD\5BD38d01 [41134] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\66\119A1d01 [20962] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\7D\1A1AAd01 [32498] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\F7\7C5D6d01 [39108] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\2\1C\622D1d01 [41495] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\7C\6EAA5d01 [24225] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\85\671B2d01 [30555] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\DE\C1909d01 [40848] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\BC\C83AEd01 [42115] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\B\87\035F6d01 [24699] O61 - LFC: 19/07/2013 - 14:05:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\F9\2382Ed01 [48271] O61 - LFC: 19/07/2013 - 14:05:12 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\3C\188D7d01 [53246] O61 - LFC: 19/07/2013 - 14:05:12 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\8B\DCDE3d01 [47040] O61 - LFC: 19/07/2013 - 14:05:12 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\98\0F6FDd01 [37625] O61 - LFC: 19/07/2013 - 14:05:12 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\9\2E\FA9BEd01 [17482] O61 - LFC: 19/07/2013 - 14:05:13 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\2\B0\C40AEd01 [41953] O61 - LFC: 19/07/2013 - 14:05:13 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\77\D13BCd01 [24982] O61 - LFC: 19/07/2013 - 14:05:13 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\1B\0A1A5d01 [17560] O61 - LFC: 19/07/2013 - 14:05:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\E5\C2465d01 [59969] O61 - LFC: 19/07/2013 - 14:05:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\B2\D64FBd01 [86635] O61 - LFC: 19/07/2013 - 14:05:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\FE\5413Ed01 [77131] O61 - LFC: 19/07/2013 - 14:05:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\9A\AB6C0d01 [41117] O61 - LFC: 19/07/2013 - 14:05:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\87\88CFBd01 [83816] O61 - LFC: 19/07/2013 - 14:05:16 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\8327d1b5e11e2155a901ae82924f3bfc.png [164291] O61 - LFC: 19/07/2013 - 14:05:49 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\0e1c5c010d27de1e61e43d92f391df3d.png [198699] O61 - LFC: 19/07/2013 - 14:06:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\0D\41293d01 [21213] O61 - LFC: 19/07/2013 - 14:06:15 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\C0\B3831d01 [42999] O61 - LFC: 19/07/2013 - 14:06:16 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\4D\7A4A2d01 [71916] O61 - LFC: 19/07/2013 - 14:06:29 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\2\91\0A536d01 [19650] O61 - LFC: 19/07/2013 - 14:06:29 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\41\98E40d01 [225662] O61 - LFC: 19/07/2013 - 14:06:29 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\35\DCAACd01 [30226] O61 - LFC: 19/07/2013 - 14:06:29 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\2A\5F58Dd01 [39727] O61 - LFC: 19/07/2013 - 14:06:32 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\fb1ae2c39b068161bda9264d8fc5fcdc.png [24149] O61 - LFC: 19/07/2013 - 14:06:49 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\3E\80C47d01 [29938] O61 - LFC: 19/07/2013 - 14:06:49 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\6B\7B6BDd01 [58660] O61 - LFC: 19/07/2013 - 14:06:49 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\B\5B\3ADA1d01 [51340] O61 - LFC: 19/07/2013 - 14:06:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\0D\90510d01 [38436] O61 - LFC: 19/07/2013 - 14:06:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\C\9A\74C9Ed01 [22567] O61 - LFC: 19/07/2013 - 14:06:52 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\B\89\E749Fd01 [77236] O61 - LFC: 19/07/2013 - 14:06:52 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\B4\6F3D4d01 [80124] O61 - LFC: 19/07/2013 - 14:06:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\92\0F5D3d01 [75856] O61 - LFC: 19/07/2013 - 14:06:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\9\D7\01AC0d01 [36730] O61 - LFC: 19/07/2013 - 14:06:55 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\C\8E\D7777d01 [171629] O61 - LFC: 19/07/2013 - 14:06:56 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\33\E0B92d01 [189373] O61 - LFC: 19/07/2013 - 14:06:57 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\32\87AB2d01 [77236] O61 - LFC: 19/07/2013 - 14:06:57 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\05\1F01Dd01 [80124] O61 - LFC: 19/07/2013 - 14:06:58 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\BC\C9A67d01 [33186] O61 - LFC: 19/07/2013 - 14:07:00 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\FB\4124Bd01 [23228] O61 - LFC: 19/07/2013 - 14:07:01 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\0C\C72A1d01 [77236] O61 - LFC: 19/07/2013 - 14:07:03 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\C\C4\8C56Ed01 [17645] O61 - LFC: 19/07/2013 - 14:07:06 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\B\28\8F256d01 [19704] O61 - LFC: 19/07/2013 - 14:07:13 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\2bbd06190655ca9a51365169276ccbaa.png [26801] O61 - LFC: 19/07/2013 - 14:07:23 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\6\3E\B14A0d02 [24397] O61 - LFC: 19/07/2013 - 14:07:30 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\bcefa1a8529d0850a3d291b2f4644f49.png [26941] O61 - LFC: 19/07/2013 - 14:07:43 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\2\D9\5119Ed01 [22747] O61 - LFC: 19/07/2013 - 14:07:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\047765b5e5a83bfcb6e49efeb51b5a77.png [24236] O61 - LFC: 19/07/2013 - 14:08:02 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\3c7ef8828d96aae6acb7cf263d7d8261.png [31031] O61 - LFC: 19/07/2013 - 14:08:35 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\08\8D478d01 [80124] O61 - LFC: 19/07/2013 - 14:08:35 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\F7\774F6d01 [77236] O61 - LFC: 19/07/2013 - 14:08:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\8E\957C4d01 [152964] O61 - LFC: 19/07/2013 - 14:08:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\E7\EA0A2d01 [249985] O61 - LFC: 19/07/2013 - 14:08:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\93\271BCd01 [75856] O61 - LFC: 19/07/2013 - 14:08:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\FD\C2310d01 [36730] O61 - LFC: 19/07/2013 - 14:08:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\FD\88C9Ed01 [155088] O61 - LFC: 19/07/2013 - 14:09:20 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\adblockplus-rules.json [365283] O61 - LFC: 19/07/2013 - 14:09:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\2B\23734d01 [84918] O61 - LFC: 19/07/2013 - 14:09:54 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\formhistory.sqlite [196608] O61 - LFC: 19/07/2013 - 14:37:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\goog-malware-shavar.cache [12] O61 - LFC: 19/07/2013 - 14:37:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\goog-malware-shavar.pset [792072] O61 - LFC: 19/07/2013 - 14:37:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\goog-malware-shavar.sbstore [1669810] O61 - LFC: 19/07/2013 - 14:37:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\goog-phish-shavar.cache [12] O61 - LFC: 19/07/2013 - 14:37:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\goog-phish-shavar.pset [1127876] O61 - LFC: 19/07/2013 - 14:37:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\goog-phish-shavar.sbstore [948190] O61 - LFC: 19/07/2013 - 14:51:38 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\selectedBugs [6863] O61 - LFC: 19/07/2013 - 14:51:38 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\ghostery\selectedLsos [3083] O61 - LFC: 19/07/2013 - 14:51:46 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\e07e74c75fe2a16ca7bd77476052761c.png [36505] O61 - LFC: 19/07/2013 - 14:53:54 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\Content\E48DDEA3BF68DF580551FA0F27950B54 [573] O61 - LFC: 19/07/2013 - 14:53:54 -S-A- C:\Documents and Settings\Administrateur\Application Data\Microsoft\CryptnetUrlCache\MetaData\E48DDEA3BF68DF580551FA0F27950B54 [232] O61 - LFC: 19/07/2013 - 14:56:11 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\KiesInstall.Log [24555] O61 - LFC: 19/07/2013 - 14:56:33 ---A- C:\Documents and Settings\Administrateur\Application Data\Samsung\Kies\FirmwareUpdate\dkdlqmdlrkqt [16] O61 - LFC: 19/07/2013 - 14:56:33 ---A- C:\Documents and Settings\Administrateur\Application Data\Samsung\Kies\FirmwareUpdate\zlrkqt [32] O61 - LFC: 19/07/2013 - 14:56:33 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\dkdlqmdlrkqt [16] O61 - LFC: 19/07/2013 - 14:56:33 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\zlrkqt [32] O61 - LFC: 19/07/2013 - 14:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\CloseButton.png [3332] O61 - LFC: 19/07/2013 - 14:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\engineer.png [7955] O61 - LFC: 19/07/2013 - 14:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\firmware_phone_fac_icon.png [4911] O61 - LFC: 19/07/2013 - 14:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\firmware_phone_icon.png [3970] O61 - LFC: 19/07/2013 - 14:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\firmware_popup_backup.png [3758] O61 - LFC: 19/07/2013 - 14:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\firmware_popup_warning.png [2855] O61 - LFC: 19/07/2013 - 14:56:38 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\firmware_ready.png [30263] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_FrameBottom.png [2799] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_FrameLeft.png [2820] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_FrameLeftBottomCorner.png [2800] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_FrameRight.png [2820] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_FrameRightBottomCorner.png [2800] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_Line.png [123] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_Messenger_Body.png [516] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_Messenger_Close.png [3219] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_NotiBox_Body.png [684] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\PNG_icon_kies.png [1529] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\Popup_border_top_right.png [2870] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\firmware_upgrade_icon.png [4119] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\phone_01_icon.png [4400] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\phone_01_icon_dim.png [2417] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\popup_border_top_center.png [2821] O61 - LFC: 19/07/2013 - 14:56:39 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\res\popup_border_top_left.png [2867] O61 - LFC: 19/07/2013 - 15:01:46 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\EC\52898d01 [22579] O61 - LFC: 19/07/2013 - 15:01:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\7aa81f02fa46f75b00a004e8346bbb6f.png [44265] O61 - LFC: 19/07/2013 - 15:01:52 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\c113c5b7d6c9066e310d26df1e911861.png [7984] O61 - LFC: 19/07/2013 - 15:01:58 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\0\79\10EA0d01 [20162] O61 - LFC: 19/07/2013 - 15:02:12 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\saved-telemetry-pings\a136e501-8a38-4584-8677-cb05f83d2ded [67977] O61 - LFC: 19/07/2013 - 15:02:13 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\52b9de8507223b1dc93320d94e2d9973.png [59043] O61 - LFC: 19/07/2013 - 15:02:14 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\permissions.sqlite [15360] O61 - LFC: 19/07/2013 - 15:17:33 ---A- C:\Documents and Settings\Administrateur\Application Data\Samsung\Kies\00000001.dat [131072] O61 - LFC: 19/07/2013 - 15:17:51 ---A- C:\Documents and Settings\Administrateur\Application Data\Samsung\Kies\00000002.dat [65536] O61 - LFC: 19/07/2013 - 15:17:57 ---A- C:\Documents and Settings\Administrateur\Application Data\Samsung\Kies\00000003.dat [65536] O61 - LFC: 19/07/2013 - 15:42:28 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\KiesLiveupdateTemp\PluginHost.xml [278] O61 - LFC: 19/07/2013 - 15:45:58 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\saved-telemetry-pings\c8427b17-1892-406c-8404-79517a056677 [28104] O61 - LFC: 19/07/2013 - 15:46:01 ---A- C:\Documents and Settings\Administrateur\Application Data\Samsung\Kies\MSDB.db [40960] O61 - LFC: 19/07/2013 - 15:52:41 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\test-malware-simple.cache [44] O61 - LFC: 19/07/2013 - 15:52:41 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\test-malware-simple.pset [16] O61 - LFC: 19/07/2013 - 15:52:41 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\test-malware-simple.sbstore [232] O61 - LFC: 19/07/2013 - 15:52:41 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\test-phish-simple.cache [44] O61 - LFC: 19/07/2013 - 15:52:41 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\test-phish-simple.pset [16] O61 - LFC: 19/07/2013 - 15:52:41 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing(3)\test-phish-simple.sbstore [232] O61 - LFC: 19/07/2013 - 15:52:44 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\saved-telemetry-pings\a14992ea-72d2-4139-a4c4-77e5e2e29628 [23354] O61 - LFC: 19/07/2013 - 15:54:58 ---A- C:\Documents and Settings\Administrateur\Voisinage réseau\Bureau sur PCfixe (Pcfixe)\target.lnk [591] O61 - LFC: 19/07/2013 - 15:54:59 ---A- C:\Documents and Settings\Administrateur\Voisinage réseau\Mes images sur PCfixe (Pcfixe)\target.lnk [607] O61 - LFC: 19/07/2013 - 15:54:59 ---A- C:\Documents and Settings\Administrateur\Voisinage réseau\SharedDocs sur PCfixe (Pcfixe)\target.lnk [607] O61 - LFC: 19/07/2013 - 15:54:59 ---A- C:\Documents and Settings\Administrateur\Voisinage réseau\Wallpaper sur PCfixe (Pcfixe)\target.lnk [603] O61 - LFC: 19/07/2013 - 15:54:59 ---A- C:\Documents and Settings\Administrateur\Voisinage réseau\Web sur PCfixe (Pcfixe)\target.lnk [579] O61 - LFC: 19/07/2013 - 16:01:37 ---A- C:\Documents and Settings\Administrateur\Bureau\AdwCleaner[S8].txt [2112] O61 - LFC: 19/07/2013 - 16:17:05 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\9de41f15a27248f85ce9485782347ddd.png [16032] O61 - LFC: 19/07/2013 - 16:17:12 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\2\01\3E34Dd01 [33136] O61 - LFC: 19/07/2013 - 16:17:13 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\D5\792CEd01 [101421] O61 - LFC: 19/07/2013 - 16:17:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\F4\B9F61d01 [130720] O61 - LFC: 19/07/2013 - 16:17:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\F0\59960d01 [49325] O61 - LFC: 19/07/2013 - 16:17:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\B3\FA1C9d01 [28356] O61 - LFC: 19/07/2013 - 16:17:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\E0\EECBFd01 [30006] O61 - LFC: 19/07/2013 - 16:17:20 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\62\AFA7Bd01 [29317] O61 - LFC: 19/07/2013 - 16:17:26 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\60\92ADFd01 [83412] O61 - LFC: 19/07/2013 - 16:17:26 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\A\99\38F11d01 [20122] O61 - LFC: 19/07/2013 - 16:17:26 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\E3\5D675d01 [488306] O61 - LFC: 19/07/2013 - 16:17:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\4\A7\E9E5Cd01 [24003] O61 - LFC: 19/07/2013 - 16:17:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\7\03\63AABd01 [28164] O61 - LFC: 19/07/2013 - 16:17:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\8D\CD7F0d01 [56608] O61 - LFC: 19/07/2013 - 16:17:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\9\BB\8766Bd01 [56020] O61 - LFC: 19/07/2013 - 16:17:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\47\847FBd01 [24378] O61 - LFC: 19/07/2013 - 16:17:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\59\32577d01 [206791] O61 - LFC: 19/07/2013 - 16:17:27 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\E\C9\58F72d01 [57084] O61 - LFC: 19/07/2013 - 16:17:28 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\D\75\443DFd01 [56896] O61 - LFC: 19/07/2013 - 16:17:32 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\8\68\2913Bd01 [41243] O61 - LFC: 19/07/2013 - 16:17:33 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\C\53\911BCd01 [96632] O61 - LFC: 19/07/2013 - 16:17:33 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\F\1B\9358Bd01 [51785] O61 - LFC: 19/07/2013 - 16:18:39 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\cookies.sqlite [524288] O61 - LFC: 19/07/2013 - 16:18:47 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\saved-telemetry-pings\6725aea1-7f14-463b-be88-af3cf79548d9 [53744] O61 - LFC: 19/07/2013 - 16:18:47 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\sessionstore.js [2385] O61 - LFC: 19/07/2013 - 16:18:48 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\cert8.db [212992] O61 - LFC: 19/07/2013 - 16:18:48 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\key3.db [16384] O61 - LFC: 19/07/2013 - 16:18:48 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\_CACHE_001_ [4194304] O61 - LFC: 19/07/2013 - 16:18:48 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\_CACHE_002_ [4194304] O61 - LFC: 19/07/2013 - 16:18:48 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\_CACHE_003_ [4194304] O61 - LFC: 19/07/2013 - 16:18:49 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Telemetry.ShutdownTime.txt [6] O61 - LFC: 19/07/2013 - 16:19:50 --HA- C:\Documents and Settings\Administrateur\Local Settings\Application Data\IconCache.db [6429072] O61 - LFC: 19/07/2013 - 16:23:19 -SHA- C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\MSHist012013071920130720\index.dat [32768] O61 - LFC: 19/07/2013 - 16:24:51 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\AppRemover_Log.txt [3108] O61 - LFC: 19/07/2013 - 16:29:56 ---A- C:\Documents and Settings\Administrateur\Recent\AdwCleaner[S8].txt.lnk [535] O61 - LFC: 19/07/2013 - 16:42:31 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\places.sqlite-shm [32768] O61 - LFC: 19/07/2013 - 16:42:36 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\webapps\webapps.json [2] O61 - LFC: 19/07/2013 - 16:42:39 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\cookies.sqlite-shm [32768] O61 - LFC: 19/07/2013 - 16:42:40 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\C\39\3094Cd01 [20153] O61 - LFC: 19/07/2013 - 16:42:40 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\_CACHE_MAP_ [33044] O61 - LFC: 19/07/2013 - 16:42:41 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\urlclassifierkey3.txt [154] O61 - LFC: 19/07/2013 - 16:42:43 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\test-malware-simple.cache [44] O61 - LFC: 19/07/2013 - 16:42:43 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\test-malware-simple.pset [16] O61 - LFC: 19/07/2013 - 16:42:43 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\test-malware-simple.sbstore [232] O61 - LFC: 19/07/2013 - 16:42:43 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\test-phish-simple.cache [44] O61 - LFC: 19/07/2013 - 16:42:43 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\test-phish-simple.sbstore [232] O61 - LFC: 19/07/2013 - 16:42:44 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\test-phish-simple.pset [16] O61 - LFC: 19/07/2013 - 16:42:47 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\0313d77de32ede819beb35805bc9f747.png [56750] O61 - LFC: 19/07/2013 - 16:42:50 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\healthreport.sqlite-shm [32768] O61 - LFC: 19/07/2013 - 16:42:50 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\healthreport.sqlite-wal [0] O61 - LFC: 19/07/2013 - 16:42:50 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\68385c31c02d03b68a8c3301a6e40c24.png [40171] O61 - LFC: 19/07/2013 - 16:43:03 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\1\DD\E80E9d01 [66817] O61 - LFC: 19/07/2013 - 16:43:03 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\2\FF\60AE9d01 [16831] O61 - LFC: 19/07/2013 - 16:43:03 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\6\55\F2B1Cd01 [97726] O61 - LFC: 19/07/2013 - 16:43:03 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\C\B7\3C44Ad01 [93491] O61 - LFC: 19/07/2013 - 16:43:04 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\6\66\BB4A5d01 [70597] O61 - LFC: 19/07/2013 - 16:43:05 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\2\ED\31940d01 [85746] O61 - LFC: 19/07/2013 - 16:43:05 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\3\27\C1BD1d01 [28387] O61 - LFC: 19/07/2013 - 16:43:05 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\6\7C\FD3EEd01 [89070] O61 - LFC: 19/07/2013 - 16:44:14 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\Cache\5\5F\84503d01 [37958] O61 - LFC: 19/07/2013 - 16:44:16 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\downloads.sqlite [98304] O61 - LFC: 19/07/2013 - 16:44:16 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\places.sqlite [10485760] O61 - LFC: 19/07/2013 - 16:44:16 ---A- C:\Documents and Settings\Administrateur\Bureau\ZHPDiag2.exe [5003832] O61 - LFC: 19/07/2013 - 16:44:19 ---A- C:\Documents and Settings\Administrateur\Local Settings\Temp\4Oe6KIqZ.exe.part [5003832] O61 - LFC: 19/07/2013 - 16:44:21 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\00fe636fbf1bc5db2b35579671a7e54e.png [59191] O61 - LFC: 19/07/2013 - 16:44:29 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\thumbnails\4947bd754449219639e8606ce6535092.png [35275] O61 - LFC: 19/07/2013 - 16:44:30 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\localstore.rdf [32970] O61 - LFC: 19/07/2013 - 16:44:31 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\_CACHE_CLEAN_ [1] O61 - LFC: 19/07/2013 - 16:45:17 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\startupCache\startupCache.4.little [60121] O61 - LFC: 19/07/2013 - 16:51:41 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\places.sqlite-wal [295160] O61 - LFC: 19/07/2013 - 17:30:41 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\prefs.js [74509] O61 - LFC: 19/07/2013 - 17:42:19 ---A- C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\cookies.sqlite-wal [11560] O61 - LFC: 19/07/2013 - 17:42:23 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\goog-malware-shavar.sbstore [962482] O61 - LFC: 19/07/2013 - 17:42:24 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\goog-malware-shavar.cache [12] O61 - LFC: 19/07/2013 - 17:42:24 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\goog-malware-shavar.pset [439336] O61 - LFC: 19/07/2013 - 17:42:25 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\goog-phish-shavar.cache [12] O61 - LFC: 19/07/2013 - 17:42:25 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\goog-phish-shavar.pset [424516] O61 - LFC: 19/07/2013 - 17:42:25 ---A- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5ykwdfj.default\safebrowsing\goog-phish-shavar.sbstore [283856] O61 - LFC: 19/07/2013 - 17:42:48 ---A- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2013-07-19 (17-30-30).txt [2174] O61 - LFC: 19/07/2013 - 17:51:51 ---A- C:\Documents and Settings\Administrateur\Bureau\mbam-log-2013-07-19 (17-30-30).txt [2174] O61 - LFC: 19/07/2013 - 17:51:51 ---A- C:\Documents and Settings\Administrateur\Recent\mbam-log-2013-07-19 (17-30-30).txt.lnk [541] O61 - LFC: 19/07/2013 - 17:52:21 -S-A- C:\Documents and Settings\Administrateur\IETldCache\index.dat [262144] O61 - LFC: 19/07/2013 - 17:52:22 ---A- C:\Documents and Settings\Administrateur\Cookies\index.dat [32768] O61 - LFC: 19/07/2013 - 17:52:22 ---A- C:\Documents and Settings\Administrateur\Local Settings\Historique\History.IE5\index.dat [81920] ~ 59 Fichiers temporaires (Temporary files) ~ 2 Fichiers cookies (Cookies files) ~ Files: 596 Scanned in 00mn 05s ---\\ Alternate Data Stream File (O62) O62 - ADS:Alternate Data Stream File - C:\WINDOWS\system32\difxapi.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\WINDOWS\system32\rnbovdd.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\WINDOWS\system32\vuins32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\WINDOWS\system32\Drivers\fetnd5bv.sys:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\WINDOWS\system32\Drivers\viamraid.sys:Zone.Identifier ~ ADS: Scanned in 00mn 02s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ ADS: Scanned in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - 01/09/2011 - C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (AdobeActiveFileMonitor10.0) .(.Adobe Systems Incorporated - Adobe Photoshop Elements 10.0 (component).) - LEGACY_ADOBEACTIVEFILEMONITOR10.0 O64 - Services: CurCS - 18/07/2013 - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (AdobeFlashPlayerUpdateSvc) .(.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 11.8 r8.) - LEGACY_ADOBEFLASHPLAYERUPDATESVC O64 - Services: CurCS - 17/08/2011 - C:\WINDOWS\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Alerter) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_ALERTER O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\alg.exe (ALG) .(.Microsoft Corporation - Application Layer Gateway Service.) - LEGACY_ALG O64 - Services: CurCS - 02/07/2013 - C:\Program Files\Avira\AntiVir Desktop\sched.exe (AntiVirSchedulerService) .(.Avira Operations GmbH & Co. KG - Avira Scheduler.) - LEGACY_ANTIVIRSCHEDULERSERVICE O64 - Services: CurCS - 02/07/2013 - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (AntiVirService) .(.Avira Operations GmbH & Co. KG - Avira On-Access Service.) - LEGACY_ANTIVIRSERVICE O64 - Services: CurCS - 01/08/2008 - C:\WINDOWS\system32\Ati2evxx.exe (Ati HotKey Poller) .(.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - LEGACY_ATI_HOTKEY_POLLER O64 - Services: CurCS - 10/02/2010 - C:\WINDOWS\system32\ati2sgag.exe (ATI Smart) .(.Pas de propriétaire - ATI Smart.) - LEGACY_ATI_SMART O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (AudioSrv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_AUDIOSRV O64 - Services: CurCS - 25/05/2013 - C:\WINDOWS\system32\DRIVERS\avgntflt.sys (avgntflt) .(.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) - LEGACY_AVGNTFLT O64 - Services: CurCS - 25/05/2013 - C:\WINDOWS\system32\DRIVERS\avipbb.sys (avipbb) .(.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) - LEGACY_AVIPBB O64 - Services: CurCS - 25/05/2013 - C:\WINDOWS\system32\DRIVERS\avkmgr.sys (avkmgr) .(.Avira Operations GmbH & Co. KG - Avira Manager Driver.) - LEGACY_AVKMGR O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (BITS) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_BITS O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Browser) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_BROWSER O64 - Services: CurCS - 14/05/2013 - C:\Program Files\Cacheman\CachemanServ.exe (CachemanService) .(.Outertech - Cacheman - controls RAM and File Cache.) - LEGACY_CACHEMANSERVICE O64 - Services: CurCS - 05/12/2012 - C:\Program Files\Cobian Backup 11\cbVSCService11.exe (cbVSCService11) .(.CobianSoft, Luis Cobian - Cobian Backup Gravity VSC Requester.) - LEGACY_CBVSCSERVICE11 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\cisvc.exe (CiSvc) .(.Microsoft Corporation - Content Index service.) - LEGACY_CISVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\clipsrv.exe (ClipSrv) .(.Microsoft Corporation - Windows NT DDE Server.) - LEGACY_CLIPSRV O64 - Services: CurCS - 25/07/2008 - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (clr_optimization_v2.0.50727_32) .(.Microsoft Corporation - .NET Runtime Optimization Service.) - LEGACY_CLR_OPTIMIZATION_V2.0.50727_32 O64 - Services: CurCS - 18/03/2010 - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (clr_optimization_v4.0.30319_32) .(.Microsoft Corporation - .NET Runtime Optimization Service.) - LEGACY_CLR_OPTIMIZATION_V4.0.30319_32 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\dllhost.exe (COMSysApp) .(.Microsoft Corporation - COM Surrogate.) - LEGACY_COMSYSAPP O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (CryptSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_CRYPTSVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Dhcp) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DHCP O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\dmadmin.exe (dmadmin) .(.Microsoft Corp., Veritas Software - Processus du service Gestionnaire de disque.) - LEGACY_DMADMIN O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\drivers\dmboot.sys (dmboot) .(.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disq.) - LEGACY_DMBOOT O64 - Services: CurCS - 28/09/2001 - C:\WINDOWS\system32\drivers\dmload.sys (dmload) .(.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) - LEGACY_DMLOAD O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (dmserver) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DMSERVER O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Dnscache) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DNSCACHE O64 - Services: CurCS - 17/11/2011 - C:\WINDOWS\system32\Drivers\DrvAgent32.sys (DrvAgent32) .(.Phoenix Technologies - DriverAgent Direct I/O for 32-bit Windows.) - LEGACY_DRVAGENT32 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (ERSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_ERSVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (EventSystem) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_EVENTSYSTEM O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (FastUserSwitchingCompatibility) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_FASTUSERSWITCHINGCOMPATIBILITY O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\drivers\fltmgr.sys (FltMgr) .(.Microsoft Corporation - Microsoft Filesystem Filter Manager.) - LEGACY_FLTMGR O64 - Services: CurCS - 29/07/2008 - C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (FontCache3.0.0.0) .(.Microsoft Corporation - PresentationFontCache.exe.) - LEGACY_FONTCACHE3.0.0.0 O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\msgpc.sys (Gpc) .(.Microsoft Corporation - MS General Packet Classifier.) - LEGACY_GPC O64 - Services: CurCS - 11/06/2013 - C:\Program Files\Google\Update\GoogleUpdate.exe (gupdate) .(.Google Inc. - Programme d'installation de Google.) - LEGACY_GUPDATE O64 - Services: CurCS - 20/11/2008 - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (gusvc) .(.Google - gusvc.) - LEGACY_GUSVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (helpsvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HELPSVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (HidServ) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HIDSERV O64 - Services: CurCS - 26/12/2012 - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe (HOSTS Anti-PUPs) .(.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) - LEGACY_HOSTS_ANTI-PUPS O64 - Services: CurCS - 13/12/2008 - C:\WINDOWS\system32\DRIVERS\hotcore3.sys (hotcore3) .(.Paragon Software Group - A part of Paragon System Utilities.) - LEGACY_HOTCORE3 O64 - Services: CurCS - 20/10/2009 - C:\WINDOWS\system32\Drivers\HTTP.sys (HTTP) .(.Microsoft Corporation - HTTP Protocol Stack.) - LEGACY_HTTP O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (HTTPFilter) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HTTPFILTER O64 - Services: CurCS - 29/07/2008 - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (idsvc) .(.Microsoft Corporation - Windows CardSpace.) - LEGACY_IDSVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\imapi.exe (ImapiService) .(.Microsoft Corporation - API Image Mastering.) - LEGACY_IMAPISERVICE O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\ipnat.sys (IpNat) .(.Microsoft Corporation - IP Network Address Translator.) - LEGACY_IPNAT O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\ipsec.sys (IPSec) .(.Microsoft Corporation - IPSec Driver.) - LEGACY_IPSEC O64 - Services: CurCS - 12/06/2013 - C:\Program Files\Java\jre7\bin\jqs.exe (JavaQuickStarterService) .(.Oracle Corporation - Java Quick Starter Service.) - LEGACY_JAVAQUICKSTARTERSERVICE O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (lanmanserver) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LANMANSERVER O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (LanmanWorkstation) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LANMANWORKSTATION O64 - Services: CurCS - 27/09/2011 - C:\Program Files\Fichiers communs\LogiShrd\Bluetooth\lbtserv.exe (LBTServ) .(.Logitech, Inc. - Logitech Bluetooth Service.) - LEGACY_LBTSERV O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (LmHosts) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LMHOSTS O64 - Services: CurCS - 31/03/2013 - C:\WINDOWS\system32\drivers\lnsfw1.sys (lnsfw1) .(.Pas de propriétaire - LNSFW1 LnS Driver.) - LEGACY_LNSFW1 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\mnmsrvc.exe (mnmsrvc) .(.Microsoft Corporation - Partage de Bureau à distance NetMeeting.) - LEGACY_MNMSRVC O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\Drivers\mountmgr.sys (mountmgr) .(.Microsoft Corporation - Mount Manager.) - LEGACY_MOUNTMGR O64 - Services: CurCS - 18/06/2013 - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (MozillaMaintenance) .(.Mozilla Foundation - Pas de description.) - LEGACY_MOZILLAMAINTENANCE O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\mrxdav.sys (MRxDAV) .(.Microsoft Corporation - Windows NT WebDav Minirdr.) - LEGACY_MRXDAV O64 - Services: CurCS - 15/07/2011 - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys (MRxSmb) .(.Microsoft Corporation - Windows NT SMB Minirdr.) - LEGACY_MRXSMB O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\msdtc.exe (MSDTC) .(.Microsoft Corporation - MS DTC console program.) - LEGACY_MSDTC O64 - Services: CurCS - 19/05/2008 - C:\WINDOWS\system32\msiexec.exe (MSIServer) .(.Microsoft Corporation - Windows® installer.) - LEGACY_MSISERVER O64 - Services: CurCS - 21/04/2011 - C:\WINDOWS\system32\Drivers\Mup.sys (Mup) .(.Microsoft Corporation - Multiple UNC Provider driver.) - LEGACY_MUP O64 - Services: CurCS - 13/07/2012 - C:\Program Files\Nero\Update\NASvc.exe (NAUpdate) .(.Nero AG - NeroUpdate.) - LEGACY_NAUPDATE O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\Drivers\NDIS.sys (NDIS) .(.Microsoft Corporation - NDIS 5.1 wrapper driver.) - LEGACY_NDIS O64 - Services: CurCS - 08/07/2011 - C:\WINDOWS\system32\DRIVERS\ndistapi.sys (NdisTapi) .(.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) - LEGACY_NDISTAPI O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\ndisuio.sys (Ndisuio) .(.Microsoft Corporation - NDIS User mode I/O Driver.) - LEGACY_NDISUIO O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\netbios.sys (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\netdde.exe (NetDDE) .(.Microsoft Corporation - DDE Réseau - Communication DDE.) - LEGACY_NETDDE O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (Netlogon) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_NETLOGON O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Netman) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NETMAN O64 - Services: CurCS - 26/03/2013 - C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe (NitroReaderDriverReadSpool3) .(.Nitro PDF Software - Nitro PDF Spool Service.) - LEGACY_NITROREADERDRIVERREADSPOOL3 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Nla) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NLA O64 - Services: CurCS - 11/02/2011 - C:\WINDOWS\system32\drivers\npf.sys (npf) .(.CACE Technologies, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) - LEGACY_NPF O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (NtLmSsp) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_NTLMSSP O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (NtmsSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NTMSSVC O64 - Services: CurCS - 09/01/2010 - C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.exe (ose) .(.Microsoft Corporation - Office Source Engine.) - LEGACY_OSE O64 - Services: CurCS - 09/01/2010 - C:\Program Files\Fichiers communs\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.exe (osppsvc) .(.Microsoft Corporation - Microsoft Office Software Protection Platfo.) - LEGACY_OSPPSVC O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\Drivers\PartMgr.sys (PartMgr) .(.Microsoft Corporation - Partition Manager.) - LEGACY_PARTMGR O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (PolicyAgent) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_POLICYAGENT O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (ProtectedStorage) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_PROTECTEDSTORAGE O64 - Services: CurCS - 28/09/2001 - C:\WINDOWS\system32\DRIVERS\rasacd.sys (RasAcd) .(.Microsoft Corporation - RAS Automatic Connection Driver.) - LEGACY_RASACD O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (RasMan) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_RASMAN O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\rdbss.sys (Rdbss) .(.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - LEGACY_RDBSS O64 - Services: CurCS - 28/09/2001 - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\sessmgr.exe (RDSessMgr) .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bu.) - LEGACY_RDSESSMGR O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (RemoteAccess) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_REMOTEACCESS O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (RemoteRegistry) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_REMOTEREGISTRY O64 - Services: CurCS - 28/09/2001 - C:\WINDOWS\system32\rsvp.exe (RSVP) .(.Microsoft Corporation - Microsoft RSVP.) - LEGACY_RSVP O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (SamSs) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_SAMSS O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\SCardSvr.exe (SCardSvr) .(.Microsoft Corporation - Serveur de gestion de ressources des cartes.) - LEGACY_SCARDSVR O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Schedule) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SCHEDULE O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (seclogon) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SECLOGON O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (SENS) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SENS O64 - Services: CurCS - 26/05/2010 - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe (Sentinel RMS License Manager) .(.SafeNet, Inc. - Sentinel RMS Development Kit License Manage.) - LEGACY_SENTINEL_RMS_LICENSE_MANAGER O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (SharedAccess) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SHAREDACCESS O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (ShellHWDetection) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SHELLHWDETECTION O64 - Services: CurCS - 03/06/2013 - C:\Program Files\Skype\Updater\Updater.exe (SkypeUpdate) .(.Skype Technologies - Skype Updater Service.) - LEGACY_SKYPEUPDATE O64 - Services: CurCS - 17/08/2010 - C:\WINDOWS\system32\spoolsv.exe (Spooler) .(.Microsoft Corporation - Spooler SubSystem App.) - LEGACY_SPOOLER O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\sr.sys (sr) .(.Microsoft Corporation - Pilote de filtre de système de fichiers pou.) - LEGACY_SR O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (srservice) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SRSERVICE O64 - Services: CurCS - 17/02/2011 - C:\WINDOWS\system32\DRIVERS\srv.sys (Srv) .(.Microsoft Corporation - Server driver.) - LEGACY_SRV O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (SSDPSRV) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SSDPSRV O64 - Services: CurCS - 25/05/2013 - C:\WINDOWS\system32\DRIVERS\ssmdrv.sys (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (stisvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_STISVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\dllhost.exe (SwPrv) .(.Microsoft Corporation - COM Surrogate.) - LEGACY_SWPRV O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\smlogsvc.exe (SysmonLog) .(.Microsoft Corporation - Service des alertes et des journaux de perf.) - LEGACY_SYSMONLOG O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (TapiSrv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_TAPISRV O64 - Services: CurCS - 20/06/2008 - C:\WINDOWS\system32\DRIVERS\tcpip.sys (Tcpip) .(.Microsoft Corporation - TCP/IP Protocol Driver.) - LEGACY_TCPIP O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Themes) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_THEMES O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\tlntsvr.exe (TlntSvr) .(.Microsoft Corporation - Telnet.) - LEGACY_TLNTSVR O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (TrkWks) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_TRKWKS O64 - Services: CurCS - 04/07/2010 - Pas de propriétaire (UnlockerDriver5) .(...) - LEGACY_UNLOCKERDRIVER5 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (upnphost) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_UPNPHOST O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\ups.exe (UPS) .(.Microsoft Corporation - UPS Service.) - LEGACY_UPS O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\viaide.sys (ViaIde) .(.Microsoft Corporation - Generic PCI IDE Bus Driver.) - LEGACY_VIAIDE O64 - Services: CurCS - 15/11/2011 - Pas de propriétaire (VRAID Log Service) .(...) - LEGACY_VRAID_LOG_SERVICE O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\vssvc.exe (VSS) .(.Microsoft Corporation - Service de cliché instantané de volumes Mic.) - LEGACY_VSS O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (W32Time) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_W32TIME O64 - Services: CurCS - 13/04/2008 - C:\WINDOWS\system32\DRIVERS\wanarp.sys (Wanarp) .(.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - LEGACY_WANARP O64 - Services: CurCS - 14/07/2009 - C:\WINDOWS\system32\Drivers\wdf01000.sys (Wdf01000) .(.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) - LEGACY_WDF01000 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (WebClient) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WEBCLIENT O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (winmgmt) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WINMGMT O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (WmdmPmSN) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WMDMPMSN O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\wbem\wmiapsrv.exe (WmiApSrv) .(.Microsoft Corporation - Service de la carte de performance WMI.) - LEGACY_WMIAPSRV O64 - Services: CurCS - 18/04/2013 - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (WPFFontCache_v0400) .(.Microsoft Corporation - wpffontcache_v0400.exe.) - LEGACY_WPFFONTCACHE_V0400 O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (wscsvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WSCSVC O64 - Services: CurCS - 26/05/2008 - C:\WINDOWS\system32\SearchIndexer.exe (WSearch) .(.Microsoft Corporation - Microsoft Windows Search Indexer.) - LEGACY_WSEARCH O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (wuauserv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WUAUSERV O64 - Services: CurCS - 28/09/2006 - C:\WINDOWS\system32\DRIVERS\WudfPf.sys (WudfPf) .(.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) - LEGACY_WUDFPF O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (WudfSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WUDFSVC O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (WZCSVC) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WZCSVC ~ Legacy: 166 Scanned in 00mn 01s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe ~ FASS Keys: 17 Scanned in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: prefs.js [Administrateur - s5ykwdfj.default] user_pref("weboftrust.search.ask.display", "Ask.com Web Search"); O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com ~ Keys: Scanned in 00mn 00s ---\\ Recherche des services démarrés par Svchost (O83) O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\WINDOWS\system32\appmgmts.dll [176640] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496] O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [78336] O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464] O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - DLL Service gestionnaire de disque logique.) -- C:\WINDOWS\system32\dmserver.dll [24576] O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Service client DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [127488] O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040] O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - Pas de description.) -- C:\WINDOWS\system32\es.dll [253952] O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] O83 - Search Svchost Services: HidServ (HidServ) . (.Microsoft Corporation - HID Audio Service.) -- C:\WINDOWS\system32\hidserv.dll [21504] O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [99840] O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096] O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792] O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gestionnaire de connexions réseau.) -- C:\WINDOWS\system32\netman.dll [198144] O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll [247808] O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gestionnaire de stockage amovible.) -- C:\WINDOWS\system32\ntmssvc.dll [438272] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248] O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Moteur du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [194560] O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\WINDOWS\system32\seclogon.dll [18944] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\WINDOWS\system32\ipnathlp.dll [332800] O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Service de restauration du système.) -- C:\WINDOWS\system32\srsvc.dll [171520] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\WINDOWS\system32\tapisrv.dll [249856] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112] O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Service de temps Windows.) -- C:\WINDOWS\system32\w32time.dll [178176] O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Service configuration automatique sans fil.) -- C:\WINDOWS\system32\wzcsvc.dll [483840] O83 - Search Svchost Services: Wmi (Wmi) . (.Microsoft Corporation - API avancées Windows 32.) -- C:\WINDOWS\system32\advapi32.dll [685568] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [145408] O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896] O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\WINDOWS\system32\qmgr.dll [409088] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680] O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400] O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINDOWS\system32\MsPMSNSv.dll [27136] O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Exécution du service Agent de quarantaine.) -- C:\WINDOWS\system32\qagentrt.dll [293376] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\system32\kmsvc.dll [61440] ~ Services: 40 Scanned in 00mn 00s ---\\ Scan Additionnel (O88) Database Version : v2.12771 - (17/07/2013) Clés trouvées (Keys found) : 3 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 1 Fichiers trouvés (Files found) : 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9E8EB35-FF77-455D-B677-91E5E4FC06C2}] =>Toolbar.Freemake [HKCU\Software\ParetoLogic] =>PUP.Paretologic [HKCU\Software\eSupport.com] =>Rogue.RegistryWizard C:\Documents and Settings\Administrateur\Local Settings\Application Data\eSupport.com =>Rogue.RegistryWizard ~ Additionnel Scan: 258605 Items scanned in 00mn 49s ---\\ Product Upgrade Codes (O90) O90 - PUC: "000021090200C0400000000000F01FEC" . (.Module de compatibilité pour Microsoft Office System 2007.) -- C:\WINDOWS\Installer\{90120000-0020-040C-0000-0000000FF1CE}\O12ConvIcon.exe O90 - PUC: "07BAE9F0198E0E949947736CEBB36A0D" . (.Nero BurnRights 12.) -- C:\WINDOWS\Installer\{0F9EAB70-E891-49E0-9974-37C6BE3BA6D0}\ARPPRODUCTICON.exe O90 - PUC: "0921D8C9C4A0C644DA685009186206CC" . (.Adobe Premiere Elements 10 Content.) -- C:\WINDOWS\Installer\{9C8D1290-0A4C-446C-AD86-0590812660CC}\ARPPRODUCTICON.exe O90 - PUC: "19D372D15D7D6304B848BE6451FFF518" . (.SmartSound Sonicfire Pro 5.) -- C:\WINDOWS\Installer\{1D273D91-D7D5-4036-8B84-EB4615FF5F81}\ARPPRODUCTICON.exe O90 - PUC: "243493A986A4ABE4586A555B954F7E00" . (.Microsoft .NET Framework 1.1 French Language Pack.) -- C:\WINDOWS\Installer\{9A394342-4A68-4EBA-85A6-55B559F4E700}\ndpsetup.ico O90 - PUC: "2AED4FAA96A59184B92BFBD345F00942" . (.Adobe Premiere Elements 10.) -- C:\WINDOWS\Installer\{AAF4DEA2-5A69-4819-9BB2-BF3D540F9024}\ARPPRODUCTICON.exe O90 - PUC: "35588CBA077879B44BE3A50946A7B536" . (.Nero ControlCenter.) -- C:\WINDOWS\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ARPPRODUCTICON.exe O90 - PUC: "3A80BAA3921F5DB44B90EA76F43957D9" . (.Prerequisite installer.) -- C:\WINDOWS\Installer\{3AAB08A3-F129-4BD5-B409-AE674F93759D}\ARPPRODUCTICON.exe O90 - PUC: "4026EC1DA1605B3438F0A6A8534C0E6C" . (.Adobe Premiere Elements 10 HD Content 2.) -- C:\WINDOWS\Installer\{D1CE6204-061A-43B5-830F-6A8A35C4E0C6}\ARPPRODUCTICON.exe O90 - PUC: "416A3D22C284A44439C2D91A8BCEFD2D" . (.Elements 10 Organizer.) -- C:\WINDOWS\Installer\{22D3A614-482C-444A-932C-9DA1B8ECDFD2}\ARPPRODUCTICON.exe O90 - PUC: "470F333EF7CFD695D316440FCE828E0C" . (.ccc-utility.) -- C:\WINDOWS\Installer\{E333F074-FC7F-596D-3D61-44F0EC28E8C0}\ARPPRODUCTICON.exe O90 - PUC: "51F9064CC3BFE79DAB1AF4011805932C" . (.Catalyst Control Center Graphics Full Existing.) -- C:\WINDOWS\Installer\{C4609F15-FB3C-D97E-BAA1-4F10815039C2}\ARPPRODUCTICON.exe O90 - PUC: "59B268CB304FA5A47926CBFD92D36609" . (..) -- C:\WINDOWS\Installer\{BC862B95-F403-4A5A-9762-BCDF293D6690}\ARPPRODUCTICON.exe O90 - PUC: "5E215153DB10878EF675AAE315D7E9EC" . (.Skins.) -- C:\WINDOWS\Installer\{351512E5-01BD-E878-6F57-AA3E517D9ECE}\ARPPRODUCTICON.exe O90 - PUC: "6040D8F0557773CA569237DA46D9EB23" . (.Catalyst Control Center Graphics Previews Common.) -- C:\WINDOWS\Installer\{0F8D0406-7755-AC37-6529-73AD649DBE32}\ARPPRODUCTICON.exe O90 - PUC: "6420C043B579F024A8DDED6AB961DFEE" . (.Adobe Premiere Elements 10 Content 1.) -- C:\WINDOWS\Installer\{340C0246-975B-420F-8ADD-DEA69B16FDEE}\ARPPRODUCTICON.exe O90 - PUC: "64396ABB1A1643DB7EA5D41832D21BEF" . (.Catalyst Control Center Localization All.) -- C:\WINDOWS\Installer\{BBA69346-61A1-BD34-E75A-4D81232DB1FE}\ARPPRODUCTICON.exe O90 - PUC: "647C499C0D6CABE40BE9FDB78183B196" . (.Nero ControlCenter Help (CHM).) -- C:\WINDOWS\Installer\{C994C746-C6D0-4EBA-B09E-DF7B18381B69}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D O90 - PUC: "68AB67CA7DA76301B744BA0000000010" . (.Adobe Reader XI (11.0.02) - Français.) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico O90 - PUC: "6B33DADD00C8D82480B77A8038559BEB" . (.Catalyst Control Center Graphics Light.) -- C:\WINDOWS\Installer\{DDAD33B6-8C00-428D-087B-A7088355B9BE}\ARPPRODUCTICON.exe O90 - PUC: "6FD6A9F2D92485946BB5568B32F3E6C2" . (.Nitro Reader 3.) -- C:\WINDOWS\Installer\{2F9A6DF6-429D-4958-B65B-65B8233F6E2C}\Reader.ico O90 - PUC: "7040BB568CC47CD459E2E3FEFD5006A2" . (.Nero Update.) -- C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}\ARPPRODUCTICON.exe O90 - PUC: "716BB088E4198E718D779AB6CA75492D" . (.Catalyst Control Center Graphics Full New.) -- C:\WINDOWS\Installer\{880BB617-914E-17E8-D877-A96BAC5794D2}\ARPPRODUCTICON.exe O90 - PUC: "8C22737D56F3B57C6A13D56398D4BA29" . (.ccc-core-static.) -- C:\WINDOWS\Installer\{D73722C8-3F65-C75B-A631-5D36894DAB92}\ARPPRODUCTICON.exe O90 - PUC: "995804A21ACF31145A82CF20180B250F" . (.CLX.PayMaker.) -- C:\WINDOWS\Installer\{2A408599-FCA1-4113-A528-FC0281B052F0}\appicon.exe O90 - PUC: "9B57D603FFF756FFC067752FEFF41E6D" . (.Catalyst Control Center Core Implementation.) -- C:\WINDOWS\Installer\{306D75B9-7FFF-FF65-0C76-57F2FE4FE1D6}\ARPPRODUCTICON.exe O90 - PUC: "AB24A66D74738264C94EE9C7813CDE59" . (.Adobe Premiere Elements 10 Content 2.) -- C:\WINDOWS\Installer\{D66A42BA-3747-4628-9CE4-9E7C18C3ED95}\ARPPRODUCTICON.exe O90 - PUC: "ACE730D5A00BF66448C82DB1D46BD9AE" . (.Adobe Premiere Elements 10 HD Content 1.) -- C:\WINDOWS\Installer\{5D037ECA-B00A-466F-848C-D21B4DB69DEA}\ARPPRODUCTICON.exe O90 - PUC: "AD500236192C572582C4E59EB6507C41" . (.Catalyst Control Center HydraVision Full.) -- C:\WINDOWS\Installer\{632005DA-C291-5275-284C-5EE96B05C714}\ARPPRODUCTICON.exe O90 - PUC: "ADA995D39D5615B498F8EC17D8CED5BB" . (.Microsoft Image Composite Editor.) -- C:\WINDOWS\Installer\{3D599ADA-65D9-4B51-898F-CE718DEC5DBB}\_112D608FD02CD87FDC7735.exe O90 - PUC: "AFBAE7E873FB42847B2924029C0E2433" . (.Nero BurnRights Help (CHM).) -- C:\WINDOWS\Installer\{8E7EABFA-BF37-4824-B792-4220C9E04233}\NeroHelpIcon.A2EDDB31_726D_4D40_8014_5D5F2D3EF945 O90 - PUC: "B6621001BB4D9D640B3262218AECA313" . (.Nero BurnRights.) -- C:\WINDOWS\Installer\{1001266B-D4BB-46D9-B023-2612A8CE3A31}\ARPPRODUCTICON.exe O90 - PUC: "C0EB27C652E3DCAC0007F29D0CA2AB41" . (.ccc-core-preinstall.) -- C:\WINDOWS\Installer\{6C72BE0C-3E25-CACD-0070-2FD9C02ABA14}\ARPPRODUCTICON.exe O90 - PUC: "C4E4AFE2F5B77F841A0CA18A287B9A3C" . (.HP Update.) -- C:\WINDOWS\Installer\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}\ARPPRODUCTICON.exe O90 - PUC: "CB1C61E07A277BD4BB8B65E0CDAC475B" . (.SmartSound Premiere Elements 10 Plugin.) -- C:\WINDOWS\Installer\{0E16C1BC-72A7-4DB7-BBB8-560EDCCA74B5}\ARPPRODUCTICON.exe O90 - PUC: "CBB90C74E0747054E82664F3A942D335" . (.MoneyPen 2.0.) -- C:\WINDOWS\Installer\{47C09BBC-470E-4507-8E62-463F9A243D53}\InstDlg.exe O90 - PUC: "D37D7C99102E30D48B4AE5BD5A925B50" . (.Adobe Premiere Elements 10 Content 3.) -- C:\WINDOWS\Installer\{99C7D73D-E201-4D03-B8A4-5EDBA529B505}\ARPPRODUCTICON.exe O90 - PUC: "D714DC311F1F4CA449D5DFED8B4857F6" . (.Microsoft Baseline Security Analyzer 2.2.) -- C:\WINDOWS\Installer\{13CD417D-F1F1-4AC4-945D-FDDEB884756F}\mbsa.exe O90 - PUC: "D988BC70E856A5445B983952CA8637FD" . (.Logiciel de base du périphérique HP Officejet Pro 8600.) -- C:\WINDOWS\Installer\{07CB889D-658E-445A-B589-9325AC6873DF}\ARP_Icon O90 - PUC: "E7FF67E4ABEA78C47B88DC745E24B5D9" . (.Skype™ 6.5.) -- C:\WINDOWS\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe O90 - PUC: "E828F58989E0F924C950FEB3ED57867F" . (.Paragon Drive Backup™ 9.0 Free Edition.) -- C:\WINDOWS\Installer\{985F828E-0E98-429F-9C05-EF3BDE7568F7}\ARPPRODUCTICON.exe O90 - PUC: "E9682A8BAC035C04C98FDB37455EE78F" . (.SmartSound Common Data.) -- C:\WINDOWS\Installer\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}\ARPPRODUCTICON.exe O90 - PUC: "ED3317D82D725E742B84140872D823AA" . (.Catalyst Control Center - Branding.) -- C:\WINDOWS\Installer\{8D7133DE-27D2-47E5-B248-4180278D32AA}\ARPPRODUCTICON.exe O90 - PUC: "F12592F4833751D46819F8EE9B7887C0" . (.Adobe Premiere Elements 10 HD Content 3.) -- C:\WINDOWS\Installer\{4F29521F-7338-4D15-8691-8FEEB987780C}\ARPPRODUCTICON.exe O90 - PUC: "F8D448A0569A2E11E9778BCAF689CC3E" . (.Google Earth.) -- C:\WINDOWS\Installer\{0A844D8F-A965-11E2-9E77-B8AC6F98CCE3}\ARPPRODUCTICON.exe ~ Update Products: 122 Scanned in 00mn 00s ---\\ MyComputer Name Space (O92) O92 - MNS: Web Folders - {BDEADF00-C265-11D0-BCED-00A0C90AB50F} ~ MNS: 1 Scanned in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SR - | Auto 01/09/2011 169624 | (AdobeActiveFileMonitor10.0) . (.Adobe Systems Incorporated.) - C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe SS - | Demand 18/07/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe SR - | Auto 02/07/2013 84024 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe SR - | Auto 02/07/2013 108088 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe SS - | Disabled 02/07/2013 589368 | (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.exe SR - | Auto 01/08/2008 573440 | (Ati HotKey Poller) . (.ATI Technologies Inc..) - C:\WINDOWS\system32\Ati2evxx.exe SS - | Auto 593920 | (ATI Smart) . (...) - C:\WINDOWS\system32\ati2sgag.exe SR - | Auto 14/05/2013 238152 | (CachemanService) . (.Outertech.) - C:\Program Files\Cacheman\CachemanServ.exe SR - | Auto 05/12/2012 67584 | (cbVSCService11) . (.CobianSoft, Luis Cobian.) - C:\Program Files\Cobian Backup 11\cbVSCService11.exe SS - | Demand 14/04/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe SS - | Auto 11/06/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 11/06/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 20/11/2008 136120 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Auto 285795 | (HOSTS Anti-PUPs) . (...) - C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware.exe SR - | Auto 12/06/2013 182184 | (JavaQuickStarterService) . (.Oracle Corporation.) - C:\Program Files\Java\jre7\bin\jqs.exe SS - | Disabled 27/09/2011 295192 | (LBTServ) . (.Logitech, Inc..) - C:\Program Files\Fichiers communs\LogiShrd\Bluetooth\lbtserv.exe SS - | Demand 18/06/2013 117144 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SR - | Auto 13/07/2012 769432 | (NAUpdate) . (.Nero AG.) - C:\Program Files\Nero\Update\NASvc.exe SR - | Auto 26/03/2013 196624 | (NitroReaderDriverReadSpool3) . (.Nitro PDF Software.) - C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe SR - | Auto 26/05/2010 847872 | (Sentinel RMS License Manager) . (.SafeNet, Inc..) - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe SS - | Auto 03/06/2013 162408 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe SR - | Auto 55920 | (VRAID Log Service) . (...) - C:\Program Files\VIA\RAID\vialogsv.exe ~ Services: Scanned in 00mn 00s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Run by Administrateur at 19/07/2013 18:57:38 device: opened successfully user: MBR read successfully Disk trace: called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys videX32.sys PCIIDEX.SYS C:\WINDOWS\system32\drivers\videX32.sys VIA Technologies, Inc. VIA PCI IDE MINI Driver 1 nt!IofCallDriver[0x804E3735] >> \Device\Harddisk0\DR0[0x8A57EAB8] 3 CLASSPNP[0xF7637FD7] >> nt!IofCallDriver[0x804E3735] >> \Device\00000069[0x8A5CCF18] 5 ACPI[0xF75AD620] >> nt!IofCallDriver[0x804E3735] >> \Device\Ide\IdeDeviceP0T0L0-3[0x8A5C9D98] kernel: MBR read successfully user & kernel MBR OK ~ MBR: 14 Scanned in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by Administrateur at 19/07/2013 18:57:40 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 04s ---\\ Malicius Software Information ~ http://nicolascoolman.webs.com/apps/blog/show/30068076-pup-paretologic =>PUP.Paretologic ~ MSI: 1 link(s) detected in 00mn 09s End of the scan (2208 lines in 04mn 35s)(0)