Ci dessous le second scan par ZHPDiag de Nicolas Coolman partie 1 :
Rapport de ZHPDiag v1.27.182 par Nicolas Coolman, Update du 21/03/2011
Run by Rida at 23/03/2011 15:17:47
Web site :
http://www.premiumorange.com/zeb-help-p ... pdiag.htmlContact :
nicolascoolman@yahoo.fr---\\ Web Browser
MSIE: Internet Explorer v8.0.6001.18702
---\\ System Information
Windows XP Professional Service Pack 3 (Build 2600)
Processor: x86 Family 6 Model 13 Stepping 8, GenuineIntel
Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1022 MB (50% free)
System Restore: Activé (Enable)
System drive C: has 17 GB (35%) free of 49 GB
---\\ Logged in mode
Computer Name: RIDAN
User Name: Rida
All Users Names: SUPPORT_388945a0, Rida, postgres, HelpAssistant, Administrateur,
Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator
---\\ Environnement Variables
%AppData%=C:\Documents and Settings\Rida\Application Data
%LocalAppData%=C:\Documents and Settings\Rida\Local Settings\Application Data
%StartMenu%=C:\Documents and Settings\Rida\Menu Démarrer
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 17 Go of 49 Go)
D:\ CD-ROM drive (Not Inserted)
E:\ Hard drive, Flash drive, Thumb drive (Free 30 Go of 44 Go)
F:\ CD-ROM drive (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Free 1 Go of 1 Go)
---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
---\\ Recherche particulière de fichiers génériques
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 03:34:03.) -- C:\Windows\Explorer.exe [1037824]
[MD5.AF4EAA3B35A2D206E1902D7CA61B958A] - (.Microsoft Corporation - Internet Extensions for Win32.) (.21/12/2010 00:53:04.) -- C:\Windows\System32\wininet.dll [916480]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 03:34:28.) -- C:\Windows\System32\Winlogon.exe [512000]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/04/2008 19:40:30.) -- C:\Windows\System32\drivers\atapi.sys [96512]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/04/2008 20:15:53.) -- C:\Windows\System32\drivers\ntfs.sys [574976]
---\\ Processus lancés
[MD5.12B0134BB2F5E482128F901E34E7138E] - (.Intel Corporation - EvtEng Module.) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [86016]
[MD5.02B4B912D7AD5ED9F2F37EAC6A68D4AF] - (.Intel Corporation - Event Monitor - Supports driver extensions.) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [372809]
[MD5.2695E3E9497BF72ABB44B5010EC5DA16] - (.AVAST Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [42184]
[MD5.2E9A1A6555C20424FC6DCC3AF21F4D68] - (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [3451496]
[MD5.57D8C4ED26DFD7EF0E2CB196FB8BFB54] - (.DivX, LLC - DivX Download Manager Service.) -- C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe [63360]
[MD5.CB7CA3DC268CA9D3FC1349A60EA48211] - (.Pas de propriétaire - DivX Update.) -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704]
[MD5.644795F6985C740F5E36E9336B837D0B] - (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31072]
[MD5.93EEFBC237ADFC406F52EE56D97F784B] - (.Sony Corporation - Pas de description.) -- C:\Program Files\Sony\ISB Utility\ISBMgr.exe [32768]
[MD5.4B9C4018690BF6BE6346199FE3FEC2AC] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.EXE [14720000]
[MD5.5C6450EAAFD24E5B416E29700452F385] - (.Sony Corporation - SPM Module.) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [184320]
[MD5.2E5212A0BFB98FE0167C92C76C87AFE3] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [249064]
[MD5.4B5F60169F872E6033F09A52BCA791EA] - (.Sony Corporation - Pas de description.) -- C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe [151552]
[MD5.47CA2F039FDB67697EE60C260CB8083C] - (.Google - Google Talk.) -- C:\Program Files\Google\Google Talk\googletalk.exe [3297280]
[MD5.89F7C30A91E5581BDF14C62AB46A2B2D] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe [255536]
[MD5.5E06A9D23727DAF96FAA796F1135FDCD] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
[MD5.A2FB43EDBAA0F2EB24A316A4DC2843D5] - (.Nitro PDF Software - Solid Spool Service.) -- C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [196912]
[MD5.A3469A25100D510EEF5B8A65A890286F] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 77.43.) -- C:\WINDOWS\system32\nvsvc32.exe [127044]
[MD5.A1DD33D16F277CE34124EE52AB2C0F14] - (...) -- C:\WINDOWS\system32\PnkBstrA.exe [75064]
[MD5.38CDA1E493C6589910A3FBE81ECCD354] - (...) -- C:\WINDOWS\system32\PnkBstrB.exe [189480]
[MD5.B9732EAAEF554978E61DC97D15A1C877] - (.Intel Corporation - RegSrvc Module.) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [139264]
[MD5.2B0EAC2B6E5F1C5E007DABAE101028B0] - (.Sony Corporation - VAIO Event Service (Service Module).) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [153600]
[MD5.49489CD0ED2C1F16E3DBB7102A8558D8] - (.Google Inc. - Google Chrome.) -- C:\Documents and Settings\Rida\Local Settings\Application Data\Google\Chrome\Application\chrome.exe [1010232]
[MD5.2DCC5C800F51D487178814CA9EADA181] - (.Microsoft Corporation - Bloc-notes.) -- C:\WINDOWS\system32\NOTEPAD.EXE [70656]
[MD5.1191D84C20F70BB4D84AE689E3E57F07] - (...) -- C:\Program Files\WinRAR\WinRAR.exe [968704]
[MD5.D601A903A38C0754A052B6CE0A727B22] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [642048]
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\acpro.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\MediaDICO-fr.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\MyHeritage.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo.xml
M3 - MFPP: Plugins - [Rida] -- C:\Program Files\Mozilla FireFox\searchplugins\YouGoo.xml
P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - 1.9.0009.1.) -- C:\Program Files\Mozilla Firefox\Plugins\npLegitCheckPlugin.dll
P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - 1.6.0028.1.) -- C:\Program Files\Mozilla Firefox\Plugins\npOGAPlugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@divx.com/DivX Browser Plugin,version=1.0.0] - (.DivX, LLC - DivX Web Player version 2.1.0.900.) -- C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
P2 - FPN: [HKLM] [@divx.com/DivX OVS Helper,version=1.0.0] - (.DivX, LLC. - DivX OVS Helper Plug-in.) -- C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_24 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=8] - (.Google Inc. - Google Update.) -- C:\Documents and Settings\Rida\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
M0 - MFSP: prefs.js [Rida - 1tq65o8b.default]
http://search.myheritage.com/M2 - MFEP: prefs.js [Rida - 1tq65o8b.default\searchrecs@veoh.com] [] Veoh Video Compass v1.5.2 (.Veoh Networks, Inc..)
M2 - MFEP: prefs.js [Rida - 1tq65o8b.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.2.1 (.Microsoft.)
M2 - MFEP: prefs.js [Rida - 1tq65o8b.default\{635abd67-4fe9-1b23-4f01-e679fa7484c1}] [yahoo.ytff] Yahoo! Toolbar v2.1.1.20091029021655 (.Yahoo!.)
M2 - MFEP: prefs.js [Rida - 1tq65o8b.default\{8e7da7e7-9f7e-426e-b964-be9f1cbc9d79}] [] Download-FR Toolbar v2.7.2.0 (.Conduit Ltd..)
M2 - MFEP: prefs.js [Rida - 1tq65o8b.default\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] [] uTorrentBar Community Toolbar v3.2.3.3 (.Conduit Ltd..)
M2 - MFEP: prefs.js [Rida - 1tq65o8b.default\{c95a4e8e-816d-4655-8c79-d736da1adb6d}] [] Hotspot Shield Toolbar v2.7.2.0 (.Conduit Ltd..)
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
G1 - GCS: Preference [User Data\Default] None
G0 - GCSP: Preference [User Data\Default][HomePage]
http://search.autocompletepro.comG2 - GCE: Preference [User Data\Default] [fnjbmmemklcjgepojigaapkoodmkgbae] DivX HiQ v.2.1.0.900 (Activé)
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.19019 (longhorn_ie8_gdr.101217-1700)) -- C:\WINDOWS\system32\ieframe.dll
R3 - URLSearchHook: Radio Bar 2 Toolbar - {9bb815eb-3f9f-4e11-9150-cb70e29b40fc} . (.Conduit Ltd. - Conduit Toolbar.) (6.1.0.7) -- C:\Program Files\Radio_Bar_2\tbRadi.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} . (.Conduit Ltd. - Conduit Toolbar.) (6.2.7.3) -- C:\Program Files\uTorrentBar\tbuTo1.dll
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
---\\ ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} . (.DivX, LLC - DivX Web Player version 2.1.0.900.) -- C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} . (.DivX, LLC - DivX Web Player version 2.1.0.900.) -- C:\Program Files\DivX\DivX Plus We
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.Pas de propriétaire - avast! WebRep Plugin.) -- C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Radio Bar 2 Toolbar - {9bb815eb-3f9f-4e11-9150-cb70e29b40fc} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Radio_Bar_2\tbRadi.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} . (.Megaupload Limited - Mega Manager IE Click Catcher.) -- C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\uTorrentBar\tbuTo1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Radio Bar 2 Toolbar - {9bb815eb-3f9f-4e11-9150-cb70e29b40fc} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Radio_Bar_2\tbRadi.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\uTorrentBar\tbuTo1.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.Pas de propriétaire - avast! WebRep Plugin.) -- C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
---\\ ---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\WINDOWS\system32\NvCpl.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- C:\Windows\ALCMTR.exe
O4 - HKLM\..\Run: [AzMixerSel] . (.Realtek Semiconductor Corp. - Azalia Mixer Select.) -- C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [DivX Download Manager] . (.DivX, LLC - DivX Download Manager Service.) -- C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe
O4 - HKLM\..\Run: [DivXUpdate] . (.Pas de propriétaire - DivX Update.) -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
O4 - HKLM\..\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
O4 - HKLM\..\Run: [ISBMgr.exe] . (.Sony Corporation - Pas de description.) -- C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [KernelFaultCheck] Clé orpheline
O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\Windows\RTHDCPL.exe
O4 - HKLM\..\Run: [SonyPowerCfg] . (.Sony Corporation - SPM Module.) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
O4 - HKLM\..\Run: [VAIO Update 2] . (.Sony Corporation - Pas de description.) -- C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
O4 - HKLM\..\Run: [TrojanScanner] . (.Simply Super Software - Trojan Scanner.) -- C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\daemon.exe
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Documents and Settings\Rida\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
O4 - HKCU\..\Run: [googletalk] . (.Google - Google Talk.) -- C:\Program Files\Google\Google Talk\googletalk.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-21-583907252-287218729-725345543-1004-583907252-287218729-725345543-1003\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\McAfee Security Scan Plus.lnk . (.McAfee, Inc..) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Search.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Démarrage\OneNote 2007 Screen Clipper and Launcher.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
---\\ ---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Reader 9.lnk . (...) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-A91000000001}\SC_Reader.ico
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\MSN.lnk . (.Microsoft Corporation.) -- C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Nitro PDF Reader.lnk . (...) -- C:\WINDOWS\Installer\{4213B968-D534-42C5-8EDD-936ED9C912F4}\Reader.ico
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Post-it® Software Notes Lite.lnk . (.3M.) -- C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\VAIO Control Center.lnk . (.Sony Corporation.) -- C:\Program Files\Sony\VAIO Control Center\VAIO Control Center.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Messenger.lnk . (.Microsoft Corporation.) -- C:\Program Files\Messenger\msmsgs.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Movie Maker.lnk . (.Microsoft Corporation.) -- C:\Program Files\Movie Maker\moviemk.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Search.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Assistance à distance.lnk . (.Microsoft Corporation.) -- C:\WINDOWS\system32\rcimlby.exe
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Ecouter la radio.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Meteo.lnk - Clé orpheline
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Navigateur OfferBox.lnk . (...) -- C:\Program Files\OfferBox\OfferBoxLauncher.exe (.not file.)
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Network Stumbler.lnk . (...) -- C:\Program Files\Network Stumbler\NetStumbler.exe
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Outlook Express.lnk . (.Microsoft Corporation.) -- C:\Program Files\Outlook Express\msimn.exe
O4 - Global Startup: C:\Documents And Settings\Rida\Menu Démarrer\Programmes\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: E&xport to Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\Office12\EXCEL.exe
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {878AC5FC-BE78-4bae-896C-7F75B790A71E} . (.not file.) - C:\Program Files\PokerStars.BE\main.ico
O9 - Extra 'Tools' menuitem: S&end to OneNote - {90EAE591-7E7E-434a-8E28-ECFD00071806} . (.not file.) - C:\Program Files\PokerStars.FR\main.ico
O9 - Extra button: S&end to OneNote - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{97357926-17AE-461F-A356-90233D9F008F}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{97357926-17AE-461F-A356-90233D9F008F}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{97357926-17AE-461F-A356-90233D9F008F}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{97357926-17AE-461F-A356-90233D9F008F}: DhcpDomain = Belkin
O17 - HKLM\System\CS1\Services\Tcpip\..\{97357926-17AE-461F-A356-90233D9F008F}: DhcpDomain = Belkin
O17 - HKLM\System\CS3\Services\Tcpip\..\{97357926-17AE-461F-A356-90233D9F008F}: DhcpDomain = Belkin
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\Windows\System32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\Windows\System32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\Windows\System32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
O20 - Winlogon Notify: VESWinlogon . (.Sony Corporation - VAIO Event Service (Winlogon Notification M.) -- C:\Windows\System32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\Windows\System32\WgaLogon.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll
---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: (dmadmin) . (.Microsoft Corp., Veritas Software - Processus du service Gestionnaire de disque.) - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: (EvtEng) . (.Intel Corporation - EvtEng Module.) - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: (gupdate1c999f2e4cfa59e) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: (gusvc) . (.Google - gusvc.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: (IDriverT) . (.Macrovision Corporation - IDriverT Module.) - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: (Macromedia Licensing Service) . (.Pas de propriétaire - System Level Service Utilty.) - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: (McComponentHostService) . (.McAfee, Inc. - Component Host Service.) - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: (MSCSPTISRV) . (.Sony Corporation - MSCSPTISRV Module.) - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: (NitroReaderDriverReadSpool) . (.Nitro PDF Software - Solid Spool Service.) - C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe
O23 - Service: (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 77.43.) - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: (PACSPTISVR) . (.Pas de propriétaire - PACSPTISVR Module.) - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) . (.PostgreSQL Global Development Group - pg_ctl - starts/stops/restarts the PostgreS.) - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: (PnkBstrA) . (...) - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: (PnkBstrB) . (...) - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: (RegSrvc) . (.Intel Corporation - RegSrvc Module.) - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) . (.CACE Technologies, Inc. - Remote Packet Capture Daemon.) - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: (S24EventMonitor) . (.Intel Corporation - Event Monitor - Supports driver extensions.) - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: (SonicStage Back-End Service) . (.Sony Corporation - SonicStage Back-End Service Module.) - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: (SPTISRV) . (.Sony Corporation - SPTISRV Module.) - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: (SSScsiSV) . (.Sony Corporation - SonicStage Scsi I/F Server.) - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: (VAIO Event Service) . (.Sony Corporation - VAIO Event Service (Service Module).) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\Office12\WINWORD.exe
---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Google Software Updater.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-287218729-725345543-1003Core.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-287218729-725345543-1003UA.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Norton Security Scan for Rida.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\OGALogon.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{DC72525F-B6B3-47F4-8B9C-47D458AB05B4}.job
[MD5.5467F1FF0AF264566740F67E8B810735] [APT] [Google Software Updater] (.Google.) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[MD5.626A24ED1228580B9518C01930936DF9] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.626A24ED1228580B9518C01930936DF9] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[MD5.626A24ED1228580B9518C01930936DF9] [APT] [GoogleUpdateTaskUserS-1-5-21-583907252-287218729-725345543-1003Core] (.Google Inc..) -- C:\Documents and Settings\Rida\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[MD5.626A24ED1228580B9518C01930936DF9] [APT] [GoogleUpdateTaskUserS-1-5-21-583907252-287218729-725345543-1003UA] (.Google Inc..) -- C:\Documents and Settings\Rida\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[MD5.AA6DB1D357B0DB08B969D14889D9C9CA] [APT] [Norton Security Scan for Rida] (.Symantec Corporation.) -- C:\Program Files\Norton Security Scan\Engine\2.7.3.34\Nss.exe
[MD5.EC9B420801D3D7F82388267D13D0F89B] [APT] [OGALogon] (.Pas de propriétaire.) -- C:\WINDOWS\system32\OGAexeC.exe
---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: (DMICall) . (.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) - C:\Windows\System32\DRIVERS\DMICall.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\Windows\System32\DRIVERS\imapi.sys
O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\Windows\System32\DRIVERS\intelppm.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\Windows\System32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\Windows\System32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\Windows\System32\DRIVERS\redbook.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\Windows\System32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
O41 - Driver: Carte vidéo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 22/03/2011 - 17:43:48 - [0] ----D- C:\Program Files\1-More Scanner
O43 - CFD: 12/05/2009 - 22:33:46 - [3669537] ----D- C:\Program Files\3M
O43 - CFD: 03/01/2011 - 23:57:44 - [259573] ----D- C:\Program Files\Acunetix
O43 - CFD: 23/03/2011 - 14:53:38 - [112021139] ----D- C:\Program Files\Ad-Remover
O43 - CFD: 19/03/2009 - 00:20:36 - [158573932] ----D- C:\Program Files\Adobe
O43 - CFD: 28/10/2010 - 17:34:20 - [7573699] ----D- C:\Program Files\adslTV
O43 - CFD: 18/04/2010 - 11:30:26 - [149105881] ----D- C:\Program Files\Alwil Software
O43 - CFD: 22/03/2011 - 19:07:32 - [9226504] ----D- C:\Program Files\Auslogics
O43 - CFD: 17/02/2009 - 21:54:04 - [17765] ----D- C:\Program Files\Canal
O43 - CFD: 28/10/2010 - 18:04:32 - [3020912] ----D- C:\Program Files\CCleaner
O43 - CFD: 16/03/2009 - 22:49:04 - [0] ----D- C:\Program Files\ComPlus Applications
O43 - CFD: 17/02/2009 - 21:21:50 - [9180430] ----D- C:\Program Files\DAEMON Tools Lite
O43 - CFD: 07/02/2011 - 21:16:26 - [99984766] ----D- C:\Program Files\DivX
O43 - CFD: 23/12/2010 - 10:24:24 - [4507970] ----D- C:\Program Files\DOSBox-0.74
O43 - CFD: 19/02/2009 - 17:57:56 - [685279524] ----D- C:\Program Files\EA GAMES
O43 - CFD: 26/10/2010 - 18:02:34 - [27333873] ----D- C:\Program Files\El Juky
O43 - CFD: 28/10/2010 - 17:35:24 - [0] ----D- C:\Program Files\ElcomSoft
O43 - CFD: 22/03/2011 - 18:03:58 - [7990136548] ----D- C:\Program Files\eMule
O43 - CFD: 23/03/2011 - 14:31:42 - [21602832] ----D- C:\Program Files\Everest Poker.fr
O43 - CFD: 22/03/2011 - 18:46:16 - [826452292] ----D- C:\Program Files\Fichiers communs
O43 - CFD: 28/10/2010 - 17:47:04 - [8974336] ----D- C:\Program Files\Free Video Converter
O43 - CFD: 22/03/2011 - 18:04:24 - [69111] ----D- C:\Program Files\GanttProject
O43 - CFD: 25/09/2010 - 20:25:34 - [97506206] ----D- C:\Program Files\Google
O43 - CFD: 20/12/2009 - 15:27:20 - [0] ----D- C:\Program Files\Hotspot_Shield
O43 - CFD: 22/03/2011 - 18:42:06 - [12862873] ----D- C:\Program Files\Image-Line
O43 - CFD: 23/06/2010 - 20:29:16 - [0] ----D- C:\Program Files\ING
O43 - CFD: 28/10/2010 - 17:47:40 - [151472427] ----D- C:\Program Files\Inkscape
O43 - CFD: 28/10/2010 - 18:13:16 - [46608818] --H-D- C:\Program Files\InstallShield Installation Information
O43 - CFD: 16/03/2009 - 23:50:02 - [15824005] ----D- C:\Program Files\Intel
O43 - CFD: 03/01/2011 - 23:33:34 - [294298] ----D- C:\Program Files\IntelliTamper
O43 - CFD: 24/08/2009 - 19:03:48 - [332] ----D- C:\Program Files\Internet Download Manager
O43 - CFD: 11/02/2011 - 00:09:20 - [5189606] ----D- C:\Program Files\Internet Explorer
O43 - CFD: 16/03/2011 - 14:10:56 - [81053210] ----D- C:\Program Files\Java
O43 - CFD: 15/05/2010 - 21:59:08 - [178608660] ----D- C:\Program Files\Macromedia
O43 - CFD: 18/05/2009 - 20:45:28 - [3103763] ----D- C:\Program Files\MagicISO
O43 - CFD: 01/11/2010 - 18:55:16 - [9454922] ----D- C:\Program Files\McAfee Security Scan
O43 - CFD: 02/01/2011 - 20:11:22 - [15113363] ----D- C:\Program Files\MediaFeed
O43 - CFD: 18/03/2010 - 20:45:34 - [7366368] ----D- C:\Program Files\Megaupload
O43 - CFD: 17/03/2009 - 14:55:50 - [2152579] ----D- C:\Program Files\Messenger
O43 - CFD: 19/11/2009 - 23:32:20 - [226432] ----D- C:\Program Files\Microsoft
O43 - CFD: 16/03/2009 - 22:53:32 - [0] ----D- C:\Program Files\microsoft frontpage
O43 - CFD: 17/02/2009 - 21:31:56 - [647745457] ----D- C:\Program Files\Microsoft Office
O43 - CFD: 17/02/2009 - 21:31:36 - [14904] ----D- C:\Program Files\Microsoft Visual Studio
O43 - CFD: 14/12/2009 - 23:59:22 - [3726168] ----D- C:\Program Files\Microsoft Works
O43 - CFD: 13/08/2010 - 17:09:18 - [10374874] ----D- C:\Program Files\Movie Maker
O43 - CFD: 26/01/2011 - 22:47:18 - [32801562] ----D- C:\Program Files\Mozilla Firefox
O43 - CFD: 18/02/2009 - 02:02:16 - [26521] ----D- C:\Program Files\MSBuild
O43 - CFD: 20/06/2009 - 16:43:48 - [21446345] ----D- C:\Program Files\MSN
O43 - CFD: 16/03/2009 - 22:48:32 - [8745735] ----D- C:\Program Files\MSN Gaming Zone
O43 - CFD: 17/03/2009 - 01:54:40 - [0] ----D- C:\Program Files\MSXML 4.0
O43 - CFD: 28/10/2010 - 17:54:10 - [254992] ----D- C:\Program Files\MyHeritage
O43 - CFD: 17/03/2009 - 14:50:22 - [3285523] ----D- C:\Program Files\NetMeeting
O43 - CFD: 08/02/2011 - 21:31:34 - [890520] ----D- C:\Program Files\Network Stumbler
O43 - CFD: 18/02/2011 - 19:38:32 - [63464403] ----D- C:\Program Files\Nitro PDF
O43 - CFD: 28/08/2010 - 01:48:50 - [12269272] ----D- C:\Program Files\Norton Security Scan
O43 - CFD: 28/08/2010 - 01:48:46 - [8446131] ----D- C:\Program Files\NortonInstaller
O43 - CFD: 13/07/2010 - 20:48:00 - [1900870] ----D- C:\Program Files\Nsasoft
O43 - CFD: 16/03/2009 - 22:48:44 - [1804] ----D- C:\Program Files\Online Services
O43 - CFD: 15/12/2010 - 22:24:32 - [4379321] ----D- C:\Program Files\Outlook Express
O43 - CFD: 18/02/2011 - 19:35:46 - [3620877] ----D- C:\Program Files\Outsim
O43 - CFD: 16/06/2009 - 18:16:34 - [49916541] ----D- C:\Program Files\Passware
O43 - CFD: 17/03/2009 - 01:26:18 - [20406230] ----D- C:\Program Files\PDFCreator
O43 - CFD: 23/09/2009 - 22:43:44 - [5790685] ----D- C:\Program Files\pdfsam
O43 - CFD: 28/10/2010 - 17:54:58 - [2537] ----D- C:\Program Files\PokerStars
O43 - CFD: 19/03/2011 - 13:04:14 - [60841089] ----D- C:\Program Files\PokerStars.BE
O43 - CFD: 19/03/2011 - 13:03:56 - [62476358] ----D- C:\Program Files\PokerStars.FR
O43 - CFD: 06/03/2011 - 01:25:32 - [71877479] ----D- C:\Program Files\PokerTracker 3
O43 - CFD: 06/03/2011 - 00:40:02 - [424569564] ----D- C:\Program Files\PostgreSQL
O43 - CFD: 29/09/2010 - 20:03:02 - [4081227] ----D- C:\Program Files\Radio_Bar_2
O43 - CFD: 17/03/2009 - 00:35:12 - [34704461] ----D- C:\Program Files\Realtek
O43 - CFD: 18/02/2009 - 01:58:38 - [36400897] ----D- C:\Program Files\Reference Assemblies
O43 - CFD: 21/03/2011 - 23:26:16 - [7625724] ----D- C:\Program Files\Samsung
O43 - CFD: 16/03/2009 - 22:51:28 - [1025] ----D- C:\Program Files\Services en ligne
O43 - CFD: 17/03/2009 - 01:20:02 - [4605362] ----D- C:\Program Files\SLD Codec Pack
O43 - CFD: 01/02/2011 - 21:52:12 - [27595035] ----D- C:\Program Files\Solegis
O43 - CFD: 16/03/2009 - 23:57:14 - [51525344] ----D- C:\Program Files\Sony
O43 - CFD: 30/01/2010 - 17:47:42 - [162] ----D- C:\Program Files\TechSmith
O43 - CFD: 28/10/2010 - 17:56:36 - [27328703] ----D- C:\Program Files\trademanager
O43 - CFD: 23/03/2011 - 12:20:08 - [403925] ----D- C:\Program Files\Trend Micro
O43 - CFD: 22/03/2011 - 18:22:10 - [11035350] ----D- C:\Program Files\Trojan Remover
O43 - CFD: 20/03/2011 - 21:49:36 - [1556] ----D- C:\Program Files\TubeMaster++
O43 - CFD: 16/03/2009 - 23:16:30 - [0] --H-D- C:\Program Files\Uninstall Information
O43 - CFD: 23/11/2010 - 19:33:06 - [395128] ----D- C:\Program Files\uTorrent
O43 - CFD: 02/01/2011 - 22:37:24 - [8036982] ----D- C:\Program Files\uTorrentBar
O43 - CFD: 09/04/2010 - 21:30:32 - [31445051] ----D- C:\Program Files\Veoh Networks
O43 - CFD: 01/04/2010 - 19:31:56 - [3680755] ----D- C:\Program Files\VirtualDub
O43 - CFD: 18/02/2011 - 19:37:26 - [5351424] ----D- C:\Program Files\VstPlugins
O43 - CFD: 10/06/2009 - 23:33:52 - [5418300] ----D- C:\Program Files\Windows Desktop Search
O43 - CFD: 19/11/2009 - 23:32:14 - [45806173] ----D- C:\Program Files\Windows Live
O43 - CFD: 19/11/2009 - 23:32:00 - [245112] ----D- C:\Program Files\Windows Live SkyDrive
O43 - CFD: 17/02/2009 - 15:28:40 - [3581070] ----D- C:\Program Files\Windows Media Connect 2
O43 - CFD: 30/09/2009 - 19:15:12 - [10066263] ----D- C:\Program Files\Windows Media Player
O43 - CFD: 17/03/2009 - 14:50:18 - [3942655] ----D- C:\Program Files\Windows NT
O43 - CFD: 16/03/2009 - 22:51:34 - [0] --H-D- C:\Program Files\WindowsUpdate
O43 - CFD: 03/01/2011 - 22:48:14 - [237571] ----D- C:\Program Files\WinPcap
O43 - CFD: 14/05/2009 - 20:18:52 - [3525705] ----D- C:\Program Files\WinRAR
O43 - CFD: 08/11/2009 - 22:51:16 - [1808231] ----D- C:\Program Files\X'nBeep 1.1
O43 - CFD: 16/03/2009 - 22:53:32 - [0] ----D- C:\Program Files\xerox
O43 - CFD: 19/02/2009 - 11:02:48 - [175] --H-D- C:\Program Files\Zero G Registry
O43 - CFD: 23/03/2011 - 15:18:14 - [5466421] ----D- C:\Program Files\ZHPDiag
O43 - CFD: 27/04/2009 - 23:37:16 - [4672638] ----D- C:\Program Files\Fichiers Communs\Adobe
O43 - CFD: 17/02/2009 - 21:53:36 - [31787256] ----D- C:\Program Files\Fichiers Communs\Adobe AIR
O43 - CFD: 17/02/2009 - 21:31:36 - [92976] ----D- C:\Program Files\Fichiers Communs\DESIGNER
O43 - CFD: 27/08/2010 - 22:48:24 - [24006656] ----D- C:\Program Files\Fichiers Communs\DivX Shared
O43 - CFD: 28/10/2010 - 17:47:12 - [8073467] ----D- C:\Program Files\Fichiers Communs\DVDVideoSoft
O43 - CFD: 16/03/2009 - 23:30:56 - [11513720] ----D- C:\Program Files\Fichiers Communs\InstallShield
O43 - CFD: 16/03/2011 - 14:13:22 - [1247175] ----D- C:\Program Files\Fichiers Communs\Java
O43 - CFD: 15/05/2010 - 22:00:50 - [221184] ----D- C:\Program Files\Fichiers Communs\Macromedia
O43 - CFD: 15/05/2010 - 22:01:42 - [68096] ----D- C:\Program Files\Fichiers Communs\Macromedia Shared
O43 - CFD: 18/04/2010 - 01:03:36 - [175972261] ----D- C:\Program Files\Fichiers Communs\Microsoft Shared
O43 - CFD: 16/03/2009 - 22:50:34 - [284160] ----D- C:\Program Files\Fichiers Communs\MSSoap
O43 - CFD: 18/02/2011 - 19:38:32 - [16539614] ----D- C:\Program Files\Fichiers Communs\Nitro PDF
O43 - CFD: 19/01/2001 - 14:57:10 - [0] ----D- C:\Program Files\Fichiers Communs\ODBC
O43 - CFD: 02/02/2011 - 19:54:28 - [0] ----D- C:\Program Files\Fichiers Communs\PC SOFT
O43 - CFD: 16/03/2009 - 22:50:38 - [8106] ----D- C:\Program Files\Fichiers Communs\Services
O43 - CFD: 16/03/2009 - 23:55:14 - [56905532] ----D- C:\Program Files\Fichiers Communs\Sony Shared
O43 - CFD: 19/01/2001 - 14:57:08 - [3787229] ----D- C:\Program Files\Fichiers Communs\SpeechEngines
O43 - CFD: 29/01/2011 - 15:55:20 - [390147167] ----D- C:\Program Files\Fichiers Communs\Symantec Shared
O43 - CFD: 14/12/2009 - 23:56:28 - [40967761] ----D- C:\Program Files\Fichiers Communs\System
O43 - CFD: 19/11/2009 - 23:17:12 - [60157294] ----D- C:\Program Files\Fichiers Communs\Windows Live
O43 - CFD: 12/05/2009 - 22:34:06 - [2457600] ----D- C:\Documents and Settings\Rida\Application Data\3M
O43 - CFD: 03/05/2010 - 21:17:22 - [6082271] ----D- C:\Documents and Settings\Rida\Application Data\Adobe
O43 - CFD: 19/07/2009 - 22:59:18 - [259279909] ----D- C:\Documents and Settings\Rida\Application Data\Apple Computer
O43 - CFD: 22/03/2011 - 19:07:50 - [1087489] ----D- C:\Documents and Settings\Rida\Application Data\Auslogics
O43 - CFD: 26/10/2010 - 18:09:18 - [1993953] ----D- C:\Documents and Settings\Rida\Application Data\Bump Technologies, Inc
O43 - CFD: 29/05/2010 - 18:13:36 - [2007] ----D- C:\Documents and Settings\Rida\Application Data\Convertisseur PDF Pro
O43 - CFD: 25/09/2010 - 17:46:24 - [9296] ----D- C:\Documents and Settings\Rida\Application Data\CrazyLoader
O43 - CFD: 17/02/2009 - 21:22:42 - [0] ----D- C:\Documents and Settings\Rida\Application Data\DAEMON Tools
O43 - CFD: 17/02/2009 - 21:24:26 - [3048] ----D- C:\Documents and Settings\Rida\Application Data\DAEMON Tools Lite
O43 - CFD: 17/02/2009 - 21:22:42 - [0] ----D- C:\Documents and Settings\Rida\Application Data\DAEMON Tools Pro
O43 - CFD: 13/09/2010 - 21:22:08 - [150528] ----D- C:\Documents and Settings\Rida\Application Data\DivX
O43 - CFD: 24/08/2009 - 17:53:32 - [208896] ----D- C:\Documents and Settings\Rida\Application Data\DMCache
O43 - CFD: 18/03/2010 - 07:49:16 - [359] ----D- C:\Documents and Settings\Rida\Application Data\dvdcss
O43 - CFD: 19/02/2011 - 13:35:20 - [14412] ----D- C:\Documents and Settings\Rida\Application Data\FileZilla
O43 - CFD: 25/08/2009 - 21:36:44 - [637] ----D- C:\Documents and Settings\Rida\Application Data\FreeCall
O43 - CFD: 01/04/2010 - 20:36:22 - [666] ----D- C:\Documents and Settings\Rida\Application Data\FreeVideoConverter
O43 - CFD: 28/02/2009 - 23:26:16 - [33609] ----D- C:\Documents and Settings\Rida\Application Data\Google
O43 - CFD: 17/09/2010 - 16:55:26 - [168] ----D- C:\Documents and Settings\Rida\Application Data\gtk-2.0
O43 - CFD: 19/02/2009 - 17:56:24 - [0] ----D- C:\Documents and Settings\Rida\Application Data\Help
O43 - CFD: 12/05/2009 - 11:21:04 - [3638] ----D- C:\Documents and Settings\Rida\Application Data\Icone
O43 - CFD: 16/03/2009 - 23:16:32 - [0] ----D- C:\Documents and Settings\Rida\Application Data\Identities
O43 - CFD: 24/08/2009 - 19:02:38 - [48859515] ----D- C:\Documents and Settings\Rida\Application Data\IDM
O43 - CFD: 23/09/2009 - 21:53:44 - [20623] ----D- C:\Documents and Settings\Rida\Application Data\Inkscape
O43 - CFD: 16/03/2009 - 23:31:58 - [0] ----D- C:\Documents and Settings\Rida\Application Data\InstallShield
O43 - CFD: 07/02/2011 - 21:16:24 - [13722793] ----D- C:\Documents and Settings\Rida\Application Data\Local
O43 - CFD: 15/05/2010 - 22:21:08 - [1950903] ----D- C:\Documents and Settings\Rida\Application Data\Macromedia
O43 - CFD: 18/03/2010 - 20:46:44 - [418722] ----D- C:\Documents and Settings\Rida\Application Data\Megaupload
O43 - CFD: 13/09/2010 - 18:46:52 - [17401986] -S--D- C:\Documents and Settings\Rida\Application Data\Microsoft
O43 - CFD: 17/03/2009 - 01:20:12 - [12571245] ----D- C:\Documents and Settings\Rida\Application Data\Mozilla
O43 - CFD: 01/09/2010 - 19:23:14 - [0] ----D- C:\Documents and Settings\Rida\Application Data\MyHeritage
O43 - CFD: 03/03/2011 - 11:13:48 - [3964] ----D- C:\Documents and Settings\Rida\Application Data\Nitro PDF
O43 - CFD: 25/06/2010 - 19:57:28 - [308] ----D- C:\Documents and Settings\Rida\Application Data\Office Genuine Advantage
O43 - CFD: 16/06/2009 - 18:17:00 - [4611] ----D- C:\Documents and Settings\Rida\Application Data\Passware
O43 - CFD: 28/10/2010 - 18:13:16 - [0] ----D- C:\Documents and Settings\Rida\Application Data\Samsung
O43 - CFD: 22/03/2011 - 18:21:48 - [3761072] ----D- C:\Documents and Settings\Rida\Application Data\Simply Super Software
O43 - CFD: 03/03/2011 - 11:12:10 - [209745] ----D- C:\Documents and Settings\Rida\Application Data\SolidDocuments
O43 - CFD: 22/02/2009 - 22:27:14 - [0] ----D- C:\Documents and Settings\Rida\Application Data\Sony Corporation
O43 - CFD: 12/08/2009 - 18:09:26 - [27420779] ----D- C:\Documents and Settings\Rida\Application Data\Sports Interactive
O43 - CFD: 17/03/2009 - 20:43:02 - [8986340] ----D- C:\Documents and Settings\Rida\Application Data\Sun
O43 - CFD: 30/09/2009 - 19:15:16 - [2252229] ----D- C:\Documents and Settings\Rida\Application Data\Todae
O43 - CFD: 20/02/2011 - 01:44:46 - [2325485] ----D- C:\Documents and Settings\Rida\Application Data\uTorrent
O43 - CFD: 28/10/2010 - 17:34:08 - [395041] ----D- C:\Documents and Settings\Rida\Application Data\vlc
O43 - CFD: 14/05/2009 - 23:48:40 - [196] ----D- C:\Documents and Settings\Rida\Application Data\Windows Desktop Search
O43 - CFD: 24/04/2009 - 14:46:42 - [0] ----D- C:\Documents and Settings\Rida\Application Data\Windows Search
O43 - CFD: 14/05/2009 - 20:19:06 - [0] ----D- C:\Documents and Settings\Rida\Application Data\WinRAR
O43 - CFD: 29/05/2010 - 18:14:02 - [51313972] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Adobe
O43 - CFD: 12/05/2009 - 22:24:22 - [0] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Apple
O43 - CFD: 14/05/2009 - 20:32:12 - [361033] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Apple Computer
O43 - CFD: 26/10/2010 - 18:10:02 - [0] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Bump Technologies, Inc
O43 - CFD: 28/10/2010 - 17:34:44 - [16856] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\crazyloader Air
O43 - CFD: 25/02/2009 - 17:37:12 - [96431] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Criterion Games
O43 - CFD: 11/12/2010 - 23:06:48 - [10973] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\DOSBox
O43 - CFD: 25/02/2009 - 17:35:38 - [16808211] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Downloaded Installations
O43 - CFD: 13/09/2010 - 18:05:40 - [736330144] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Google
O43 - CFD: 19/02/2009 - 17:56:24 - [0] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Help
O43 - CFD: 14/05/2009 - 23:48:44 - [223752] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Identities
O43 - CFD: 15/05/2010 - 22:00:50 - [71852669] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Macromedia
O43 - CFD: 31/03/2010 - 23:18:38 - [1109569814] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Microsoft
O43 - CFD: 17/02/2009 - 21:25:54 - [0] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Microsoft Help
O43 - CFD: 17/03/2009 - 01:20:12 - [30704993] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Mozilla
O43 - CFD: 03/03/2011 - 21:52:22 - [244853] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\P5
O43 - CFD: 15/09/2009 - 22:33:24 - [189480] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\PunkBuster
O43 - CFD: 29/09/2010 - 20:03:50 - [467420] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Radio_Bar_2
O43 - CFD: 22/03/2011 - 04:31:18 - [0] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\Temp
O43 - CFD: 02/01/2011 - 22:37:00 - [1167592] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\uTorrentBar
O43 - CFD: 02/02/2011 - 19:54:32 - [174] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\WDSetup
O43 - CFD: 31/03/2010 - 23:22:08 - [0] ----D- C:\Documents and Settings\Rida\Local Settings\Application Data\WMTools Downloaded Files