---\\ Contenu des dossiers ProgramFiles/ProgramData (O43)
O43 - CFD:Common File Directory ----D- S:\Program Files\123 Free Solitaire
O43 - CFD:Common File Directory ----D- S:\Program Files\7-Zip
O43 - CFD:Common File Directory ----D- S:\Program Files\Adobe
O43 - CFD:Common File Directory ----D- S:\Program Files\Adobe.P.S.CS5.Portable
O43 - CFD:Common File Directory ----D- S:\Program Files\AM-DeadLink
O43 - CFD:Common File Directory ----D- S:\Program Files\Apple Software Update
O43 - CFD:Common File Directory ----D- S:\Program Files\Avira
O43 - CFD:Common File Directory ----D- S:\Program Files\CDBurnerXP
O43 - CFD:Common File Directory ----D- S:\Program Files\Cobian Backup 9
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files
O43 - CFD:Common File Directory ----D- S:\Program Files\Defraggler
O43 - CFD:Common File Directory ----D- S:\Program Files\drivers
O43 - CFD:Common File Directory ----D- S:\Program Files\DSpeech
O43 - CFD:Common File Directory ----D- S:\Program Files\DVD Maker
O43 - CFD:Common File Directory ----D- S:\Program Files\EASEUS
O43 - CFD:Common File Directory ----D- S:\Program Files\EclipsePalette
O43 - CFD:Common File Directory ----D- S:\Program Files\EverNote
O43 - CFD:Common File Directory ----D- S:\Program Files\Everything-1.2.1.371
O43 - CFD:Common File Directory ----D- S:\Program Files\FastStone Capture
O43 - CFD:Common File Directory -SH-D- S:\Program Files\Fichiers communs
O43 - CFD:Common File Directory ----D- S:\Program Files\filehippo.com
O43 - CFD:Common File Directory ----D- S:\Program Files\Foxit PDF Editor v2.0.1011(portable)
O43 - CFD:Common File Directory ----D- S:\Program Files\Free Audio Editor
O43 - CFD:Common File Directory ----D- S:\Program Files\FreeTime
O43 - CFD:Common File Directory ----D- S:\Program Files\Google
O43 - CFD:Common File Directory ----D- S:\Program Files\GSpot
O43 - CFD:Common File Directory ----D- S:\Program Files\image deduplicator
O43 - CFD:Common File Directory --H-D- S:\Program Files\InstallShield Installation Information
O43 - CFD:Common File Directory ----D- S:\Program Files\Intel
O43 - CFD:Common File Directory ----D- S:\Program Files\Internet Explorer
O43 - CFD:Common File Directory ----D- S:\Program Files\Java
O43 - CFD:Common File Directory ----D- S:\Program Files\Lavalys
O43 - CFD:Common File Directory ----D- S:\Program Files\LockHunter
O43 - CFD:Common File Directory ----D- S:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD:Common File Directory ----D- S:\Program Files\MediaMonkey
O43 - CFD:Common File Directory ----D- S:\Program Files\Microsoft Games
O43 - CFD:Common File Directory ----D- S:\Program Files\Microsoft Office
O43 - CFD:Common File Directory ----D- S:\Program Files\Microsoft.NET
O43 - CFD:Common File Directory ----D- S:\Program Files\MiPony
O43 - CFD:Common File Directory ---AD- S:\Program Files\Moo0 DiskCleaner 1.10 Portable
O43 - CFD:Common File Directory ----D- S:\Program Files\Mozilla Firefox
O43 - CFD:Common File Directory ----D- S:\Program Files\mp3val(portable)
O43 - CFD:Common File Directory ----D- S:\Program Files\MSBuild
O43 - CFD:Common File Directory ----D- S:\Program Files\MSECache
O43 - CFD:Common File Directory ----D- S:\Program Files\NeoSmart Technologies
O43 - CFD:Common File Directory ----D- S:\Program Files\ObjectDock
O43 - CFD:Common File Directory ----D- S:\Program Files\OpenOffice.org 3
O43 - CFD:Common File Directory ----D- S:\Program Files\PaintStar
O43 - CFD:Common File Directory ----D- S:\Program Files\PhotoFiltre
O43 - CFD:Common File Directory ----D- S:\Program Files\PhotoImpression
O43 - CFD:Common File Directory ----D- S:\Program Files\QuickTime
O43 - CFD:Common File Directory ----D- S:\Program Files\r2 Studios
O43 - CFD:Common File Directory ----D- S:\Program Files\Reallusion
O43 - CFD:Common File Directory ----D- S:\Program Files\Realtek
O43 - CFD:Common File Directory ----D- S:\Program Files\Reference Assemblies
O43 - CFD:Common File Directory ----D- S:\Program Files\Riot
O43 - CFD:Common File Directory ----D- S:\Program Files\ScanSoft
O43 - CFD:Common File Directory ----D- S:\Program Files\SCREEN2EXE
O43 - CFD:Common File Directory R---D- S:\Program Files\Skype
O43 - CFD:Common File Directory ----D- S:\Program Files\Software Informer
O43 - CFD:Common File Directory ----D- S:\Program Files\Sony
O43 - CFD:Common File Directory ----D- S:\Program Files\Sqirlz Lite
O43 - CFD:Common File Directory ----D- S:\Program Files\Sqirlz Water Reflections
O43 - CFD:Common File Directory ----D- S:\Program Files\STOIK morphman
O43 - CFD:Common File Directory ----D- S:\Program Files\System Restore Manager
O43 - CFD:Common File Directory ----D- S:\Program Files\TeamViewer
O43 - CFD:Common File Directory --H-D- S:\Program Files\Temp
O43 - CFD:Common File Directory ----D- S:\Program Files\Trend Micro
O43 - CFD:Common File Directory --H-D- S:\Program Files\Uninstall Information
O43 - CFD:Common File Directory ----D- S:\Program Files\Uninstall Tool
O43 - CFD:Common File Directory ----D- S:\Program Files\VideoLAN
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows Defender
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows Journal
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows Mail
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows Media Player
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows NT
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows Photo Viewer
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows Portable Devices
O43 - CFD:Common File Directory ----D- S:\Program Files\Windows Sidebar
O43 - CFD:Common File Directory ----D- S:\Program Files\Wise Registry Cleaner
O43 - CFD:Common File Directory ----D- S:\Program Files\XnView
O43 - CFD:Common File Directory ----D- S:\Program Files\Yahtzee
O43 - CFD:Common File Directory ----D- S:\Program Files\ZebHelpProcess
O43 - CFD:Common File Directory ----D- S:\Program Files\ZHPDiag
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Adobe
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Apple
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Borland Shared
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\InstallShield
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Java
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\microsoft shared
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Reallusion
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Services
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Skype
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\SpeechEngines
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\System
O43 - CFD:Common File Directory ----D- S:\ProgramData\Adobe
O43 - CFD:Common File Directory ----D- S:\ProgramData\App4rTemp
O43 - CFD:Common File Directory ----D- S:\ProgramData\Apple
O43 - CFD:Common File Directory ----D- S:\ProgramData\Apple Computer
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Application Data
O43 - CFD:Common File Directory ----D- S:\ProgramData\Avira
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Bureau
O43 - CFD:Common File Directory ----D- S:\ProgramData\Canneverbe Limited
O43 - CFD:Common File Directory ----D- S:\ProgramData\CrystalIdea Software
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Desktop
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Documents
O43 - CFD:Common File Directory ----D- S:\ProgramData\Estsoft
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Favoris
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Favorites
O43 - CFD:Common File Directory ----D- S:\ProgramData\Malwarebytes
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Menu Démarrer
O43 - CFD:Common File Directory -S--D- S:\ProgramData\Microsoft
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Modèles
O43 - CFD:Common File Directory ----D- S:\ProgramData\NVIDIA
O43 - CFD:Common File Directory ----D- S:\ProgramData\r2 Studios
O43 - CFD:Common File Directory ----D- S:\ProgramData\Skype
O43 - CFD:Common File Directory ----D- S:\ProgramData\Soluto
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Start Menu
O43 - CFD:Common File Directory ----D- S:\ProgramData\Sun
O43 - CFD:Common File Directory -SH-D- S:\ProgramData\Templates
O43 - CFD:Common File Directory ----D- S:\ProgramData\TreeCardGames
O43 - CFD:Common File Directory ----D- S:\ProgramData\Zylom
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Adobe
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Apple
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Borland Shared
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\InstallShield
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Java
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\microsoft shared
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Reallusion
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Services
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\Skype
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\SpeechEngines
O43 - CFD:Common File Directory ----D- S:\Program Files\Common Files\System
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.52000000000000000000000010EF1200] - 08/11/2010 - 22:55:19 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\WindowsUpdate.log [897646]
O44 - LFC:[MD5.C756130463679FD9DAA95AB5CB7CC481] - 08/11/2010 - 21:27:53 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\setupact.log [560]
O44 - LFC:[MD5.3BF21D037E110AF2AFED9C7EA038D625] - 08/11/2010 - 21:27:48 -S-A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.F3A0DB973C32BB99BCFA63E06BE67650] - 08/11/2010 - 21:26:41 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\TDSSKiller.2.4.7.0_08.11.2010_21.24.56_log.txt [63910]
O44 - LFC:[MD5.244E724B84C3C7556C3DDEEFB8995408] - 08/11/2010 - 16:31:20 --HA- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [13120]
O44 - LFC:[MD5.244E724B84C3C7556C3DDEEFB8995408] - 08/11/2010 - 16:31:20 --HA- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [13120]
O44 - LFC:[MD5.BDE94634945C90F54D7A1530B0BF8F81] - 08/11/2010 - 15:54:47 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\PFRO.log [1608]
O44 - LFC:[MD5.A36EE93698802CD899F98BFD553D8185] - 08/11/2010 - 15:53:27 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- S:\Windows\System32\drivers\ssmdrv.sys [28520]
O44 - LFC:[MD5.F8C56231ED5ECF7D1B46B0330880CCEF] - 08/11/2010 - 15:53:27 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- S:\Windows\System32\drivers\avipbb.sys [126856]
O44 - LFC:[MD5.1EB7D72A82F94F7E9496D363FCE00B68] - 08/11/2010 - 15:53:27 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- S:\Windows\System32\drivers\avgntflt.sys [60936]
O44 - LFC:[MD5.AE72E8619CB31D84DA25E2435E55003C] - 08/11/2010 - 13:27:04 ---A- . (.NirSoft - NirCmd.) -- S:\Windows\NIRCMD.exe [31232]
O44 - LFC:[MD5.F1FBA6185A6A2BC6456970914875078E] - 08/11/2010 - 13:27:04 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\PEV.exe [256512]
O44 - LFC:[MD5.9E05A9C264C8A908A8E79450FCBFF047] - 08/11/2010 - 13:27:04 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\grep.exe [80412]
O44 - LFC:[MD5.2B657A67AEBB84AEA5632C53E61E23BF] - 08/11/2010 - 13:27:04 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\sed.exe [98816]
O44 - LFC:[MD5.5E832F4FAF5F481F2EAF3B3A48F603B8] - 08/11/2010 - 13:27:04 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\zip.exe [68096]
O44 - LFC:[MD5.01D95A1F8CF13D07CC564AABB36BCC0B] - 08/11/2010 - 13:27:04 ---A- . (.SteelWerX - Freeware implementation of REG.EXE.) -- S:\Windows\SWREG.exe [161792]
O44 - LFC:[MD5.B7517DB073B28F5696A1E5528ABEB5D0] - 08/11/2010 - 13:27:04 ---A- . (.SteelWerX - Freeware implementation of SC.EXE.) -- S:\Windows\SWSC.exe [136704]
O44 - LFC:[MD5.B1A9CF0B6F80611D31987C247EC630B4] - 08/11/2010 - 13:26:25 ---A- . (.SteelWerX - Freeware implementation of XCACLS.) -- S:\Windows\SWXCACLS.exe [212480]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 08/11/2010 - 12:31:32 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\setuperr.log [0]
O44 - LFC:[MD5.9DAA7218961710008D7385B01BD3F386] - 08/11/2010 - 01:20:24 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\MBR.exe [89088]
O44 - LFC:[MD5.56FAA866BCC1B16D93344913190BC186] - 06/11/2010 - 18:46:47 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\PerfStringBackup.INI [5764]
O44 - LFC:[MD5.2D82BC712F69EBED9FA0620DB9AB8837] - 06/11/2010 - 18:46:47 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\perfc009.dat [359780]
O44 - LFC:[MD5.3CBB4B0DBD1AF770B17BA4D9FD76C907] - 06/11/2010 - 18:46:47 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\perfc00C.dat [423108]
O44 - LFC:[MD5.CDBE18B152CAE2D3430D388E058B9E09] - 06/11/2010 - 18:46:47 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\perfh009.dat [882160]
O44 - LFC:[MD5.8693DC12EBDF688B07979C63F3B6908C] - 06/11/2010 - 18:46:47 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\perfh00C.dat [1576854]
O44 - LFC:[MD5.68E04F3944E6F82C64B53F8A8F13FB3A] - 02/11/2010 - 10:14:45 ---A- . (.Ricoh - Description string for UvcFilter driver.) -- S:\Windows\System32\drivers\R5U870FLx86.sys [73472]
O44 - LFC:[MD5.7F1356060D1894B46554A0D8E6F13958] - 02/11/2010 - 10:14:45 ---A- . (.Ricoh - Description string for UvcUpperFilter drive.) -- S:\Windows\System32\drivers\R5U870FUx86.sys [43904]
O44 - LFC:[MD5.895F40400A614B0BADEE9E1A76CEB604] - 01/11/2010 - 09:17:46 --HA- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\ezsidmv.dat [56]
O44 - LFC:[MD5.8E5274D2E0D88AAE7084D5305B7D0ABC] - 24/10/2010 - 08:45:29 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\PhotoImpression.ini [1227]
O44 - LFC:[MD5.81D530D7186F71D5F3E9D5AE08814F09] - 15/10/2010 - 00:44:02 ---A- . (.Google Inc. - Google Photos Screensaver.) -- S:\Windows\System32\GPhotos.scr [4280320]
O44 - LFC:[MD5.FB1CC49C551D57D1829FF4F8019371B7] - 14/10/2010 - 06:46:04 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\FNTCACHE.DAT [299424]
O44 - LFC:[MD5.51A850830CB841FBE5B90142BCC6B854] - 13/10/2010 - 16:39:52 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- S:\Windows\System32\java.exe [145184]
O44 - LFC:[MD5.87893167C98FCEF5D14077511F219B75] - 13/10/2010 - 16:39:52 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- S:\Windows\System32\javaw.exe [145184]
O44 - LFC:[MD5.42278A946AB729CB746AA47D48F5FCC0] - 13/10/2010 - 16:39:52 ---A- . (.Sun Microsystems, Inc. - Java(TM) Web Start Launcher.) -- S:\Windows\System32\javaws.exe [153376]
O44 - LFC:[MD5.BD8CA4341B2258D97CB22788E4BF72C7] - 13/10/2010 - 16:39:48 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\System32\jupdate-1.6.0_22-b04.log [3882]
---\\ Déni du service (Local Security Authority) (LSA) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- S:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- S:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- S:\Windows\System32\msv1_0.dll
---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="S:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- S:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- S:\Windows\System32\iccvid.dll
O52 - TDSD: \drivers.desc\"S:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- S:\Windows\System32\l3codeca.acm
---\\ ShareTools MSconfig StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\Adobe ARM [Key] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- S:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- S:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
O53 - SMSR:HKLM\...\startupreg\Google Update [Key] . (.Google Inc. - Programme d'installation de Google.) -- S:\Users\HAPAX\AppData\Local\Google\Update\GoogleUpdate.exe
O53 - SMSR:HKLM\...\startupreg\IAStorIcon [Key] . (.Intel Corporation - IAStorIcon.) -- S:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O53 - SMSR:HKLM\...\startupreg\NvCplDaemon [Key] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- S:\Windows\system32\NvCpl.dll
O53 - SMSR:HKLM\...\startupreg\NvMediaCenter [Key] . (.NVIDIA Corporation - NVIDIA Media Center Library.) -- S:\Windows\system32\NvMcTray.dll
O53 - SMSR:HKLM\...\startupreg\NvSvc [Key] . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 167.6.) -- S:\Windows\system32\nvsvc.dll
O53 - SMSR:HKLM\...\startupreg\RtHDVCpl [Key] . (.Realtek Semiconductor - HD Audio Control Panel.) -- S:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O53 - SMSR:HKLM\...\startupreg\Skytel [Key] . (.Realtek Semiconductor Corp. - Realtek Voice Manager.) -- S:\Program Files\Realtek\Audio\HDA\Skytel.exe
O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- S:\Program Files\Common Files\Java\Java Update\jusched.exe
---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- S:\Windows\system32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- S:\Windows\system32\credssp.dll
---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "DisableRegistryTools"=0
---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDrives"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDrives"=0
---\\ Liste des Drivers Système (SDL) (O58)
O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- S:\Windows\system32\drivers\adp94xx.sys
O58 - SDL:[MD5.0C676BC278D5B59FF5ABD57BBE9123F2] - 14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- S:\Windows\system32\drivers\adpahci.sys
O58 - SDL:[MD5.7C7B5EE4B7B822EC85321FE23A27DB33] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- S:\Windows\system32\drivers\adpu320.sys
O58 - SDL:[MD5.0D40BCF52EA90FC7DF2AEAB6503DEA44] - 14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- S:\Windows\system32\drivers\aliide.sys
O58 - SDL:[MD5.2101A86C25C154F8314B24EF49D7FBC2] - 14/07/2009 - 02:26:15 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- S:\Windows\system32\drivers\amdsata.sys
O58 - SDL:[MD5.EA43AF0C423FF267355F74E7A53BDABA] - 14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- S:\Windows\system32\drivers\amdsbs.sys
O58 - SDL:[MD5.B81C2B5616F6420A9941EA093A92B150] - 14/07/2009 - 02:26:15 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- S:\Windows\system32\drivers\amdxata.sys
O58 - SDL:[MD5.2932004F49677BD84DBC72EDB754FFB3] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- S:\Windows\system32\drivers\arc.sys
O58 - SDL:[MD5.5D6F36C46FD283AE1B57BD2E9FEB0BC7] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- S:\Windows\system32\drivers\arcsas.sys
O58 - SDL:[MD5.D79A49FC67421C7BB7DCBD188A442288] - 05/01/2010 - 02:20:10 ---A- . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) -- S:\Windows\system32\drivers\athur.sys
O58 - SDL:[MD5.1EB7D72A82F94F7E9496D363FCE00B68] - 17/08/2010 - 13:39:11 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- S:\Windows\system32\drivers\avgntflt.sys
O58 - SDL:[MD5.F8C56231ED5ECF7D1B46B0330880CCEF] - 17/08/2010 - 13:39:11 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- S:\Windows\system32\drivers\avipbb.sys
O58 - SDL:[MD5.BD8869EB9CDE6BBE4508D869929869EE] - 13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- S:\Windows\system32\drivers\b57nd60x.sys
O58 - SDL:[MD5.9F9ACC7F7CCDE8A15C282D3F88B43309] - 13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- S:\Windows\system32\drivers\BrFiltLo.sys
O58 - SDL:[MD5.56801AD62213A41F6497F96DEE83755A] - 13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- S:\Windows\system32\drivers\BrFiltUp.sys
O58 - SDL:[MD5.845B8CE732E67F3B4133164868C666EA] - 14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- S:\Windows\system32\drivers\BrSerId.sys
O58 - SDL:[MD5.203F0B1E73ADADBBB7B7B1FABD901F6B] - 13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- S:\Windows\system32\drivers\BrSerWdm.sys
O58 - SDL:[MD5.BD456606156BA17E60A04E18016AE54B] - 13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- S:\Windows\system32\drivers\BrUsbMdm.sys
O58 - SDL:[MD5.AF72ED54503F717A43268B3CC5FAEC2E] - 13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- S:\Windows\system32\drivers\BrUsbSer.sys
O58 - SDL:[MD5.1A231ABEC60FD316EC54C66715543CEC] - 13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- S:\Windows\system32\drivers\bxvbdx.sys
O58 - SDL:[MD5.C537B1DB64D495B9B4717B4D6D9EDBF2] - 14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- S:\Windows\system32\drivers\cmdide.sys
O58 - SDL:[MD5.8B30250D573A8F6B4BD23195160D8707] - 14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- S:\Windows\system32\drivers\djsvs.sys
O58 - SDL:[MD5.0ED67910C8C326796FAA00B2BF6D9D3C] - 14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- S:\Windows\system32\drivers\elxstor.sys
O58 - SDL:[MD5.024E1B5CAC09731E4D868E64DBFB4AB0] - 13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- S:\Windows\system32\drivers\evbdx.sys
O58 - SDL:[MD5.C44E3C2BAB6837DB337DDEE7544736DB] - 13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- S:\Windows\system32\drivers\hcw85cir.sys
O58 - SDL:[MD5.295FDC419039090EB8B49FFDBB374549] - 14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- S:\Windows\system32\drivers\HpSAMD.sys
O58 - SDL:[MD5.26541A068572F650A2FA490726FE81BE] - 03/03/2010 - 18:33:26 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver - x86.) -- S:\Windows\system32\drivers\iaStor.sys
O58 - SDL:[MD5.934AF4D7C5F457B9F0743F4299B77B67] - 14/07/2009 - 02:20:36 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- S:\Windows\system32\drivers\iaStorV.sys
O58 - SDL:[MD5.4173FF5708F3236CF25195FECD742915] - 14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- S:\Windows\system32\drivers\iirsp.sys
O58 - SDL:[MD5.EB119A53CCF2ACC000AC71B065B78FEF] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- S:\Windows\system32\drivers\lsi_fc.sys
O58 - SDL:[MD5.8ADE1C877256A22E49B75D1CC9161F9C] - 14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- S:\Windows\system32\drivers\lsi_sas.sys
O58 - SDL:[MD5.DC9DC3D3DAA0E276FD2EC262E38B11E9] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- S:\Windows\system32\drivers\lsi_sas2.sys
O58 - SDL:[MD5.0A036C7D7CAB643A7F07135AC47E0524] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- S:\Windows\system32\drivers\lsi_scsi.sys
O58 - SDL:[MD5.67B48A903430C6D4FB58CBACA1866601] - 29/04/2010 - 14:39:26 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- S:\Windows\system32\drivers\mbam.sys
O58 - SDL:[MD5.C7DD7D9739785BD3A6B8499EEC1DEE7E] - 29/04/2010 - 14:39:38 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- S:\Windows\system32\drivers\mbamswissarmy.sys
O58 - SDL:[MD5.0FFF5B045293002AB38EB1FD1FC2FB74] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- S:\Windows\system32\drivers\megasas.sys
O58 - SDL:[MD5.DCBAB2920C75F390CAF1D29F675D03D6] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- S:\Windows\system32\drivers\MegaSR.sys
O58 - SDL:[MD5.58218EC6B61B1169CF54AAB0D00F5FE2] - 13/07/2009 - 23:02:51 ---A- . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- S:\Windows\system32\drivers\netw5v32.sys
O58 - SDL:[MD5.1D85C4B390B0EE09C7A46B91EFB2C097] - 14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- S:\Windows\system32\drivers\nfrd960.sys
O58 - SDL:[MD5.61CC6E7237973CAA4E384CE97FD7A7B9] - 26/05/2009 - 10:35:50 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 167.) -- S:\Windows\system32\drivers\nvlddmkm.sys
O58 - SDL:[MD5.3F3D04B1D08D43C16EA7963954EC768D] - 14/07/2009 - 02:20:44 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- S:\Windows\system32\drivers\nvraid.sys
O58 - SDL:[MD5.C99F251A5DE63C6F129CF71933ACED0F] - 14/07/2009 - 02:20:44 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- S:\Windows\system32\drivers\nvstor.sys
O58 - SDL:[MD5.AB95ECF1F6659A60DDC166D8315B0751] - 14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- S:\Windows\system32\drivers\ql2300.sys
O58 - SDL:[MD5.B4DD51DD25182244B86737DC51AF2270] - 14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- S:\Windows\system32\drivers\ql40xx.sys
O58 - SDL:[MD5.68E04F3944E6F82C64B53F8A8F13FB3A] - 29/01/2008 - 15:04:12 ---A- . (.Ricoh - Description string for UvcFilter driver.) -- S:\Windows\system32\drivers\R5U870FLx86.sys
O58 - SDL:[MD5.7F1356060D1894B46554A0D8E6F13958] - 29/01/2008 - 15:04:12 ---A- . (.Ricoh - Description string for UvcUpperFilter driver.) -- S:\Windows\system32\drivers\R5U870FUx86.sys
O58 - SDL:[MD5.2E4F8AD76CB1203D68DB6E8F02E4AF74] - 30/03/2009 - 17:13:42 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- S:\Windows\system32\drivers\RTKVHDA.sys
O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- S:\Windows\system32\drivers\secdrv.sys
O58 - SDL:[MD5.8B7C1768D2CDE2E02E09A66563DDFD16] - 03/08/2007 - 04:36:10 ---A- . (.Sony Corporation - Sony Firmware Extension Parser driver.) -- S:\Windows\system32\drivers\SFEP.sys
O58 - SDL:[MD5.A9F0486851BECB6DDA1D89D381E71055] - 14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- S:\Windows\system32\drivers\sisraid2.sys
O58 - SDL:[MD5.3727097B55738E2F554972C3BE5BC1AA] - 14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- S:\Windows\system32\drivers\sisraid4.sys
O58 - SDL:[MD5.A36EE93698802CD899F98BFD553D8185] - 17/06/2010 - 15:28:02 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- S:\Windows\system32\drivers\ssmdrv.sys
O58 - SDL:[MD5.F92254B0BCFCD10CAAC7BCCC7CB7F467] - 12/11/2009 - 13:48:56 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\drivers\StarOpen.sys
O58 - SDL:[MD5.DB32D325C192B801DF274BFD12A7E72B] - 14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- S:\Windows\system32\drivers\stexstor.sys
O58 - SDL:[MD5.E43574F6A56A0EE11809B48C09E4FD3C] - 14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- S:\Windows\system32\drivers\viaide.sys
O58 - SDL:[MD5.9DFA0CC2F8855A04816729651175B631] - 14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- S:\Windows\system32\drivers\vsmraid.sys
O58 - SDL:[MD5.E00FDFAFF025E94F9821153750C35A6D] - 13/07/2009 - 23:13:45 ---A- . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- S:\Windows\system32\drivers\VSTAZL3.SYS
O58 - SDL:[MD5.BC0C7EA89194C299F051C24119000E17] - 13/07/2009 - 23:13:45 ---A- . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- S:\Windows\system32\drivers\VSTCNXT3.SYS
O58 - SDL:[MD5.CEB4E3B6890E1E42DCA6694D9E59E1A0] - 13/07/2009 - 23:13:46 ---A- . (.Conexant Systems, Inc. - HSF_DP driver.) -- S:\Windows\system32\drivers\VSTDPV3.SYS
O58 - SDL:[MD5.21886AE871840739885A34E7F216AFA7] - 28/04/2010 - 09:37:12 ---A- . (.Marvell - NDIS6.20 Miniport Driver for Marvell Yukon Ethernet Controller.) -- S:\Windows\system32\drivers\yk62x86.sys
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\ANSI.SYS
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 13/07/2009 - 22:40:44 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\country.sys
O58 - SDL:[MD5.539CA34FBC74EC366A0D751028C32A08] - 15/07/2010 - 07:44:20 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\epmntdrv.sys
O58 - SDL:[MD5.1F2F4AB15CE03ECC257FEB2F6DC5A013] - 15/07/2010 - 07:44:20 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\EuGdiDrv.sys
O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 13/07/2009 - 22:40:40 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\HIMEM.SYS
O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 13/07/2009 - 22:40:43 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\KEY01.SYS
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 13/07/2009 - 22:40:43 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\KEYBOARD.SYS
O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 13/07/2009 - 22:40:23 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTDOS.SYS
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 13/07/2009 - 22:40:31 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTDOS404.SYS
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 13/07/2009 - 22:40:35 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTDOS411.SYS
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 13/07/2009 - 22:40:39 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTDOS412.SYS
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 13/07/2009 - 22:40:27 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTDOS804.SYS
O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 13/07/2009 - 22:40:11 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTIO.SYS
O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 13/07/2009 - 22:40:15 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTIO404.SYS
O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 13/07/2009 - 22:40:17 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTIO411.SYS
O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 13/07/2009 - 22:40:19 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTIO412.SYS
O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 13/07/2009 - 22:40:13 ---A- . (.Pas de propriétaire - Pas de description.) -- S:\Windows\system32\NTIO804.SYS
---\\ Liste des outils de nettoyage (LATC) (O63)
O63 - Logiciel: HijackThis 2.0.2 - (.TrendMicro.) [HKLM] -- HijackThis
O63 - Logiciel: ZHPDiag 1.27 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
---\\ Liste des services Legacy (LALS) (O64)
O64 - Services: CurCS - S:\Windows\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\avgntflt.sys - avgntflt (avgntflt) .(.Avira GmbH - Avira Minifilter Driver.) - LEGACY_AVGNTFLT
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Avira GmbH - Avira Driver for Security Enhancement.) - LEGACY_AVIPBB
O64 - Services: CurCS - (.not file.) - Beep (Beep) .(.Pas de propriétaire - Pas de description.) - LEGACY_BEEP
O64 - Services: CurCS - S:\Windows\system32\browser.dll (bowser) .(.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) - LEGACY_BOWSER
O64 - Services: CurCS - S:\Users\HAPAX\AppData\Local\Temp\catchme.sys (.not file.) - catchme (catchme) .(.Pas de propriétaire - Pas de description.) - LEGACY_CATCHME
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\cdfs.sys - CD/DVD File System Reader (cdfs) .(.Microsoft Corporation - CD-ROM File System Driver.) - LEGACY_CDFS
O64 - Services: CurCS - S:\Windows\system32\clfs.sys (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS
O64 - Services: CurCS - S:\Windows\system32\Drivers\cng.sys - CNG (CNG) .(.Microsoft Corporation - Kernel Cryptography, Next Generation.) - LEGACY_CNG
O64 - Services: CurCS - S:\Windows\system32\cscsvc.dll (CSC) .(.Microsoft Corporation - DLL du service CSC.) - LEGACY_CSC
O64 - Services: CurCS - (.not file.) - deqmupctrpjnnts (deqmupctrpjnnts) .(.Pas de propriétaire - Pas de description.) - LEGACY_DEQMUPCTRPJNNTS
O64 - Services: CurCS - S:\Windows\system32\drivers\dfsc.sys (DfsC) .(.Microsoft Corporation - DFS Namespace Client Driver.) - LEGACY_DFSC
O64 - Services: CurCS - S:\Windows\system32\drivers\discache.sys (discache) .(.Microsoft Corporation - System Indexer/Cache Driver.) - LEGACY_DISCACHE
O64 - Services: CurCS - S:\Windows\system32\drivers\dxgkrnl.sys - LDDM Graphics Subsystem (DXGKrnl) .(.Microsoft Corporation - DirectX Graphics Kernel.) - LEGACY_DXGKRNL
O64 - Services: CurCS - S:\Windows\system32\epmntdrv.sys - epmntdrv (epmntdrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_EPMNTDRV
O64 - Services: CurCS - S:\Windows\system32\EuGdiDrv.sys - EuGdiDrv (EuGdiDrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_EUGDIDRV
O64 - Services: CurCS - (.not file.) - FAT12/16/32 File System Driver (fastfat) .(.Pas de propriétaire - Pas de description.) - LEGACY_FASTFAT
O64 - Services: CurCS - S:\Windows\system32\drivers\fileinfo.sys (FileInfo) .(.Microsoft Corporation - FileInfo Filter Driver.) - LEGACY_FILEINFO
O64 - Services: CurCS - S:\Windows\system32\drivers\fltmgr.sys (FltMgr) .(.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) - LEGACY_FLTMGR
O64 - Services: CurCS - S:\Windows\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec) .(.Pas de propriétaire - Pas de description.) - LEGACY_FS_REC
O64 - Services: CurCS - S:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Microsoft Corporation - BitLocker Drive Encryption Driver.) - LEGACY_FVEVOL
O64 - Services: CurCS - S:\Windows\system32\drivers\http.sys (HTTP) .(.Microsoft Corporation - HTTP Pile du protocole.) - LEGACY_HTTP
O64 - Services: CurCS - S:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Microsoft Corporation - Hardware Policy Driver.) - LEGACY_HWPOLICY
O64 - Services: CurCS - (.not file.) - klmd25 (klmd25) .(.Pas de propriétaire - Pas de description.) - LEGACY_KLMD25
O64 - Services: CurCS - S:\Windows\system32\Drivers\ksecdd.sys - KSecDD (KSecDD) .(.Microsoft Corporation - Kernel Security Support Provider Interface.) - LEGACY_KSECDD
O64 - Services: CurCS - S:\Windows\system32\Drivers\ksecpkg.sys - KSecPkg (KSecPkg) .(.Microsoft Corporation - Kernel Security Support Provider Interface.) - LEGACY_KSECPKG
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\lltdio.sys - Link-Layer Topology Discovery Mapper I/O Driver (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO
O64 - Services: CurCS - S:\Windows\system32\drivers\luafv.sys (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV
O64 - Services: CurCS - (.not file.) - mbr (mbr) .(.Pas de propriétaire - Pas de description.) - LEGACY_MBR
O64 - Services: CurCS - S:\Windows\system32\drivers\mountmgr.sys (mountmgr) .(.Microsoft Corporation - Gestionnaire des points de montage.) - LEGACY_MOUNTMGR
O64 - Services: CurCS - S:\Windows\system32\FirewallAPI.dll (mpsdrv) .(.Microsoft Corporation - API du Pare-feu Windows.) - LEGACY_MPSDRV
O64 - Services: CurCS - S:\Windows\system32\wkssvc.dll (mrxsmb) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB
O64 - Services: CurCS - S:\Windows\system32\wkssvc.dll (mrxsmb10) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB10
O64 - Services: CurCS - S:\Windows\system32\wkssvc.dll (mrxsmb20) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB20
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\msahci.sys - msahci (msahci) .(.Microsoft Corporation - MS AHCI 1.0 Standard Driver.) - LEGACY_MSAHCI
O64 - Services: CurCS - S:\Windows\system32\Drivers\MSFS.sys - Msfs (Msfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_MSFS
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\msisadrv.sys - msisadrv (msisadrv) .(.Microsoft Corporation - ISA Driver.) - LEGACY_MSISADRV
O64 - Services: CurCS - S:\Windows\system32\drivers\mup.sys (Mup) .(.Microsoft Corporation - Multiple UNC Provider Driver.) - LEGACY_MUP
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\nwifi.sys - NativeWiFi Filter (NativeWifiP) .(.Microsoft Corporation - Pilote de miniport WiFi natif.) - LEGACY_NATIVEWIFIP
O64 - Services: CurCS - S:\Windows\system32\drivers\ndis.sys (NDIS) .(.Microsoft Corporation - Pilote NDIS 6.20.) - LEGACY_NDIS
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\ndisuio.sys - NDIS Usermode I/O Protocol (Ndisuio) .(.Microsoft Corporation - Pilote d’E/S du mode utilisateur NDIS.) - LEGACY_NDISUIO
O64 - Services: CurCS - S:\Windows\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDPROXY
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\netbios.sys - NetBIOS Interface (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS
O64 - Services: CurCS - S:\Windows\system32\drivers\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT
O64 - Services: CurCS - S:\Windows\system32\Drivers\NPFS.sys - Npfs (Npfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NPFS
O64 - Services: CurCS - S:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) .(.Microsoft Corporation - NSI Proxy.) - LEGACY_NSIPROXY
O64 - Services: CurCS - S:\Windows\system32\Drivers\NTFS.sys - Ntfs (Ntfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NTFS
O64 - Services: CurCS - S:\Windows\system32\Drivers\NULL.sys - Null (Null) .(.Pas de propriétaire - Pas de description.) - LEGACY_NULL
O64 - Services: CurCS - S:\Windows\system32\drivers\pcw.sys - Performance Counters for Windows Driver (pcw) .(.Microsoft Corporation - Performance Counters for Windows Driver.) - LEGACY_PCW
O64 - Services: CurCS - S:\Windows\system32\drivers\peauth.sys - PEAUTH (PEAUTH) .(.Microsoft Corporation - Protected Environment Authentication and Au.) - LEGACY_PEAUTH
O64 - Services: CurCS - (.not file.) - PROCEXP113 (PROCEXP113) .(.Pas de propriétaire - Pas de description.) - LEGACY_PROCEXP113
O64 - Services: CurCS - S:\Windows\system32\drivers\pacer.sys (Psched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED
O64 - Services: CurCS - S:\Windows\system32\wkssvc.dll (rdbss) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_RDBSS
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD
O64 - Services: CurCS - S:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) .(.Microsoft Corporation - RDP Encoder Miniport.) - LEGACY_RDPENCDD
O64 - Services: CurCS - S:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) .(.Microsoft Corporation - RDP Reflector Driver Miniport.) - LEGACY_RDPREFMP
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\rspndr.sys - Link-Layer Topology Discovery Responder (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR
O64 - Services: CurCS - (.not file.) - Security Driver (secdrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SECDRV
O64 - Services: CurCS - (.not file.) - Security Processor Loader Driver (spldr) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPLDR
O64 - Services: CurCS - S:\Windows\system32\srvsvc.dll (srv) .(.Microsoft Corporation - DLL du service Serveur.) - LEGACY_SRV
O64 - Services: CurCS - S:\Windows\system32\srvsvc.dll (srv2) .(.Microsoft Corporation - DLL du service Serveur.) - LEGACY_SRV2
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\srvnet.sys - srvnet (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\ssmdrv.sys - ssmdrv (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV
O64 - Services: CurCS - S:\Windows\system32\vmstorfltres.dll (storflt) .(.Microsoft Corporation - Fichier DLL de ressources du filtre de stoc.) - LEGACY_STORFLT
O64 - Services: CurCS - S:\Windows\system32\tcpipcfg.dll (Tcpip) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TCPIP
O64 - Services: CurCS - S:\Windows\system32\drivers\tcpipreg.sys - TCP/IP Registry Compatibility (tcpipreg) .(.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) - LEGACY_TCPIPREG
O64 - Services: CurCS - S:\Windows\system32\tcpipcfg.dll (tdx) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TDX
O64 - Services: CurCS - S:\Windows\system32\drivers\vga.sys - VgaSave (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE
O64 - Services: CurCS - S:\Windows\system32\drivers\volmgrx.sys (volmgrx) .(.Microsoft Corporation - Pilote d’extension du gestionnaire de volum.) - LEGACY_VOLMGRX
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\volsnap.sys - Volumes de stockage (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\vwififlt.sys - Virtual WiFi Filter Driver (VWiFiFlt) .(.Microsoft Corporation - Virtual WiFi Filter Driver.) - LEGACY_VWIFIFLT
O64 - Services: CurCS - S:\Windows\system32\rascfg.dll (Wanarpv6) .(.Microsoft Corporation - Objets de configuration RAS.) - LEGACY_WANARPV6
O64 - Services: CurCS - S:\Windows\system32\drivers\Wdf01000.sys - Kernel Mode Driver Frameworks service (Wdf01000) .(.Microsoft Corporation - Runtime de l’infrastructure de pilotes en m.) - LEGACY_WDF01000
O64 - Services: CurCS - S:\Windows\system32\DRIVERS\wfplwf.sys - WFP Lightweight Filter (WfpLwf) .(.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - LEGACY_WFPLWF
O64 - Services: CurCS - S:\Windows\system32\drivers\WudfPf.sys - User Mode Driver Frameworks Platform Driver (WudfPf) .(.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) - LEGACY_WUDFPF
---\\ Observateur d'évènement d'application (OEA) (O66)
O66 - EventLog: ID=1000 (Application Error) - (.Microsoft Corporation - Explorateur Windows.) -- S:\Windows\Explorer.EXE
O66 - EventLog: ID=1000 (Application Error) - (.Microsoft Corporation - Processus hôte pour les services Windows.) -- S:\Windows\system32\svchost.exe
O66 - EventLog: ID=1000 (Application Error) - (.Mozilla Corporation - Plugin Container for Firefox.) -- S:\Program Files\Mozilla Firefox\plugin-container.exe
O66 - EventLog: ID=1000 (Application Error) - (.Pas de propriétaire - Pas de description.) -- S:\Program Files\VideoLAN\VLC\vlc.exe
O66 - EventLog: ID=1000 (Application Error) - (.Pas de propriétaire - Pas de description.) -- S:\Program Files\Yahtzee\Yahtzee.exe
O66 - EventLog: ID=1000 (Application Error) - (.Nicolas Coolman - Analyseur de rapports sécurité.) -- S:\Program Files\ZebHelpProcess\ZHP2.exe
---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- S:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <ComFile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- S:\Windows\system32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- S:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- S:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- S:\Windows\regedit.exe
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- S:\Program Files\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- S:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <ComFile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.evt> <evtfile>[HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- S:\Windows\system32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- S:\Program Files\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- S:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- S:\Windows\regedit.exe
---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- S:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- S:\Users\HAPAX\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- S:\Program Files\Internet Explorer\iexplore.exe
---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: S:\Users\HAPAX\Application Data\Mozilla\Firefox\Profiles\\9apkdgyr.default\searchplugins\conduit.xml
O69 - SBI: prefs.js [HAPAX - 9apkdgyr.default] user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2146382&SearchSource=3&q={searchTerms}");
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) -
http://www.bing.comO69 - SBI: SearchScopes [HKCU] {8F8EA17E-71BB-442D-9F35-21BCF6B14791} - (Google) -
http://www.google.comO69 - SBI: SearchScopes [HKCU] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (mipony-plugin Customized Web Search) -
http://search.conduit.com---\\ Internet Feature Controls (IFC) (O81)
O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe
O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe