Problème de vidéo

Voici ce qui y a en bas : color=#A23BEC]< %SYSTEMDRIVE%*.exe >[/color]
[2005/08/16 08:49:12 | 00,040,960 | ---- | M] (Sysinternals - www.sysinternals.com) – C:\junction.exe

< %SYSTEMDRIVE%\eventlog.dll /s /md5 >

< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2009/04/11 07:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\ERDNT\cache\scecli.dll
[2009/04/11 07:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2008/01/19 08:36:19 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s…urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 07:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s…urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2009/04/11 07:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\ERDNT\cache\netlogon.dll
[2009/04/11 07:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2008/01/19 08:35:36 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[2009/04/11 07:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll

< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
[2006/11/02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\ERDNT\cache\cngaudit.dll
[2006/11/02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 10:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< %SYSTEMDRIVE%\sceclt.dll /s /md5 >

< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >

< %SYSTEMDRIVE%\logevent.dll /s /md5 >

< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
[2007/04/25 05:17:36 | 00,277,784 | ---- | M] (Intel Corporation) MD5=5DF93509037399B53D3ECAA8A67B6C58 – C:\Acer\Robson\WINALL\DRIVER\IASTOR.SYS
[2007/04/25 05:18:12 | 00,537,368 | ---- | M] (Intel Corporation) MD5=6E9BEDAEFA5A3F86CECF40F4963F3021 – C:\Acer\Robson\WINALL\DRIVER64\IASTOR.SYS
[2007/03/21 11:58:56 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IASTOR.SYS
[2007/03/21 11:59:30 | 00,381,720 | ---- | M] (Intel Corporation) MD5=9D7ED4275702E2FC409F2CC563245740 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IASTOR.SYS
[2007/03/21 11:58:56 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Windows\System32\drivers\iaStor.sys
[2007/03/21 11:58:56 | 00,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys
[2006/12/22 04:17:02 | 00,273,920 | ---- | M] (Intel Corporation) MD5=16EC9C934AE82B45BEB0CFF9C4277EE8 – C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_6c5f2dca\iaStor.sys
[2007/04/25 05:17:36 | 00,277,784 | ---- | M] (Intel Corporation) MD5=5DF93509037399B53D3ECAA8A67B6C58 – C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_b92fa6ec\iaStor.sys
[2006/12/22 04:17:02 | 00,273,920 | ---- | M] (Intel Corporation) MD5=16EC9C934AE82B45BEB0CFF9C4277EE8 – C:\Windows\System32\DriverStore\FileRepository\iastor.inf_4b499ec9\iaStor.sys

< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
[2006/11/02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2008/01/19 08:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2006/11/02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 08:42:09 | 00,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2009/04/11 07:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2008/07/30 13:00:28 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2009/04/11 07:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2006/11/02 10:49:36 | 00,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/01/19 08:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/07/30 13:00:28 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/07/30 13:00:27 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
[2008/01/19 08:41:30 | 00,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2009/04/11 07:32:26 | 00,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >

< %SYSTEMDRIVE%\viasraid.sys /s /md5 >

< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2006/11/02 10:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\ERDNT\cache\AGP440.sys
[2006/11/02 10:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2008/01/19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2006/11/02 10:49:52 | 00,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2008/01/19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/19 08:42:25 | 00,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys

< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >

< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >

========== Files - Unicode (All) ==========
[2009/07/01 21:14:40 | 00,524,288 | -HS- | M] ()(C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms) – C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms
[2009/07/01 21:14:40 | 00,524,288 | -HS- | M] ()(C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms) – C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms
[2009/07/01 21:14:40 | 00,065,536 | -HS- | M] ()(C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TM.blf) – C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TM.blf
[2009/07/01 21:14:33 | 00,524,288 | -HS- | C] ()(C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms) – C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms
[2009/07/01 21:14:32 | 00,524,288 | -HS- | C] ()(C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms) – C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms
[2009/07/01 21:14:32 | 00,262,144 | ---- | M] ()(C:\Windows\System32??) – C:\Windows\System32??
[2009/07/01 21:14:32 | 00,262,144 | ---- | C] ()(C:\Windows\System32??) – C:\Windows\System32??
[2009/07/01 21:14:32 | 00,065,536 | -HS- | C] ()(C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TM.blf) – C:\Windows\System32??{17a22c68-6651-11de-ae6e-e44fbc7bbe10}.TM.blf
[2009/07/01 21:14:32 | 00,005,120 | -H-- | M] ()(C:\Windows\System32??.LOG1) – C:\Windows\System32??.LOG1
[2009/07/01 21:14:32 | 00,005,120 | -H-- | C] ()(C:\Windows\System32??.LOG1) – C:\Windows\System32??.LOG1
[2009/07/01 21:14:32 | 00,000,000 | -H-- | M] ()(C:\Windows\System32??.LOG2) – C:\Windows\System32??.LOG2
[2009/07/01 21:14:32 | 00,000,000 | -H-- | C] ()(C:\Windows\System32??.LOG2) – C:\Windows\System32??.LOG2
[2009/07/01 21:14:09 | 00,524,288 | -HS- | M] ()(C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms) – C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms
[2009/07/01 21:14:09 | 00,524,288 | -HS- | M] ()(C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms) – C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms
[2009/07/01 21:14:09 | 00,065,536 | -HS- | M] ()(C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TM.blf) – C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TM.blf
[2009/07/01 21:13:46 | 00,524,288 | -HS- | C] ()(C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms) – C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms
[2009/07/01 21:13:46 | 00,524,288 | -HS- | C] ()(C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms) – C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms
[2009/07/01 21:13:46 | 00,262,144 | ---- | M] ()(C:\Windows\System32??) – C:\Windows\System32??
[2009/07/01 21:13:46 | 00,262,144 | ---- | C] ()(C:\Windows\System32??) – C:\Windows\System32??
[2009/07/01 21:13:46 | 00,065,536 | -HS- | C] ()(C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TM.blf) – C:\Windows\System32??{17a22c64-6651-11de-ae6e-e44fbc7bbe10}.TM.blf
[2009/07/01 21:13:46 | 00,005,120 | -H-- | M] ()(C:\Windows\System32??.LOG1) – C:\Windows\System32??.LOG1
[2009/07/01 21:13:46 | 00,005,120 | -H-- | C] ()(C:\Windows\System32??.LOG1) – C:\Windows\System32??.LOG1
[2009/07/01 21:13:46 | 00,000,000 | -H-- | M] ()(C:\Windows\System32??.LOG2) – C:\Windows\System32??.LOG2
[2009/07/01 21:13:46 | 00,000,000 | -H-- | C] ()(C:\Windows\System32??.LOG2) – C:\Windows\System32??.LOG2
[2009/07/01 20:40:23 | 00,524,288 | -HS- | M] ()(C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms) – C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms
[2009/07/01 20:40:23 | 00,524,288 | -HS- | M] ()(C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms) – C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms
[2009/07/01 20:40:23 | 00,524,288 | -HS- | C] ()(C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms) – C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000002.regtrans-ms
[2009/07/01 20:40:23 | 00,524,288 | -HS- | C] ()(C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms) – C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TMContainer00000000000000000001.regtrans-ms
[2009/07/01 20:40:23 | 00,262,144 | ---- | M] ()(C:\Windows\System32?F??) – C:\Windows\System32?F??
[2009/07/01 20:40:23 | 00,065,536 | -HS- | M] ()(C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TM.blf) – C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TM.blf
[2009/07/01 20:40:23 | 00,065,536 | -HS- | C] ()(C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TM.blf) – C:\Windows\System32?F??{17a22bd4-6651-11de-ae6e-e44fbc7bbe10}.TM.blf
[2009/07/01 20:40:23 | 00,005,120 | -H-- | M] ()(C:\Windows\System32?F??.LOG1) – C:\Windows\System32?F??.LOG1
[2009/07/01 20:40:22 | 00,262,144 | ---- | C] ()(C:\Windows\System32?F??) – C:\Windows\System32?F??
[2009/07/01 20:40:22 | 00,005,120 | -H-- | C] ()(C:\Windows\System32?F??.LOG1) – C:\Windows\System32?F??.LOG1
[2009/07/01 20:40:22 | 00,000,000 | -H-- | M] ()(C:\Windows\System32?F??.LOG2) – C:\Windows\System32?F??.LOG2
[2009/07/01 20:40:22 | 00,000,000 | -H-- | C] ()(C:\Windows\System32?F??.LOG2) – C:\Windows\System32?F??.LOG2

========== Alternate Data Streams ==========

@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:A95A95AC
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:B623B5B8
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:B203B914
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:375A40C3
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:AA9519A6
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:798A3728
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:0A73A758
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:7B212553
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:4F8BECB9
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:9E22BBE8
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:30A9E86A
< End of report >

Voici le rapport 1 :

** Rapport MyHosts.txt **

MyHosts V.1.0.0.0 de jeanmimigab

Merci à la team MH et à Batch_man pour leurs aides

Résultat de l’opération:

Le fichier hosts a bien été restauré…

** Fin du rapport **

J’arrive avec le rapport 2

Combofix ne ma pas redémarrer l’ordi je l’ais fais quand même :

ComboFix 09-11-27.07 - Brigitte 28/11/2009 18:10.2.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2037.976 [GMT 1:00]
Lancé depuis: c:\users\Brigitte\Desktop\poisson.exe
SP: SUPERAntiSpyware disabled (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-10-28 au 2009-11-28 ))))))))))))))))))))))))))))))))))))
.

2009-11-28 17:29 . 2009-11-28 17:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-28 08:47 . 2009-11-28 08:48 4096 d-----w- c:\program files\Orbitdownloader
2009-11-27 12:17 . 2009-11-27 12:17 171552 ----a-w- c:\windows\system32\guard32.dll
2009-11-27 12:17 . 2009-11-27 17:59 4096 d-----w- C:\UsbFix
2009-11-26 20:47 . 2009-11-26 20:48 4096 d-----w- c:\programdata\MessengerDiscovery 2
2009-11-26 20:47 . 2009-11-26 20:47 4096 d-----w- c:\program files\MessengerDiscovery 2
2009-11-25 18:42 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 14:22 . 2009-11-25 14:22 -------- d-----w- c:\program files\FileHippo.com
2009-11-25 13:53 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-25 13:53 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-25 13:51 . 2009-11-25 13:52 -------- d-----w- c:\programdata{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-25 11:52 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 11:52 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-23 17:05 . 2009-11-23 17:07 4096 d-----w- c:\program files\7-Zip
2009-11-22 13:03 . 2009-11-22 13:04 4096 d-----w- c:\program files\ImgBurn
2009-11-20 19:22 . 2009-11-20 19:22 -------- d-----w- c:\program files\Recuva
2009-11-20 15:58 . 2009-11-20 17:06 -------- d-----w- c:\users\Brigitte.VirtualBox
2009-11-20 15:54 . 2009-11-10 13:54 116560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-11-20 15:54 . 2009-11-10 13:53 41424 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-11-20 15:53 . 2009-11-20 15:53 -------- d-----w- c:\program files\Sun
2009-11-19 18:15 . 2009-11-19 18:15 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-11-19 18:10 . 2009-11-19 18:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-19 18:05 . 2009-11-19 18:05 -------- d-----w- c:\program files\Microsoft Analysis Services
2009-11-19 18:03 . 2009-11-19 18:03 -------- d-----r- C:\MSOCache
2009-11-18 19:27 . 2009-11-19 12:28 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Download Manager
2009-11-18 19:05 . 2009-11-26 20:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-18 19:03 . 2009-11-26 20:43 4096 d-----w- c:\program files\Windows Live
2009-11-18 15:28 . 2009-11-18 15:28 -------- d-----w- c:\program files\Gibcom
2009-11-17 19:18 . 2009-11-17 19:20 -------- d-----w- c:\program files\Ubisoft
2009-11-17 16:12 . 2009-11-17 16:12 25214 ----a-r- c:\users\Brigitte\AppData\Roaming\Microsoft\Installer{4103778F-5EAF-476E-B3C1-2891EF9A4D8C}\controlPanelIcon.exe
2009-11-17 16:11 . 2009-11-17 16:12 4096 d-----w- c:\program files\Kptic Neonumeric
2009-11-17 11:52 . 2009-11-17 11:52 -------- d-----w- c:\programdata\F-Secure
2009-11-16 20:31 . 2009-11-16 20:41 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Kptic
2009-11-16 17:53 . 2009-11-16 17:54 4096 d-----w- c:\program files\Microsoft Security Essentials
2009-11-16 17:53 . 2009-11-16 18:12 -------- d-----w- c:\programdata\Comodo
2009-11-16 17:53 . 2009-11-25 11:50 128376 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-16 17:53 . 2009-11-17 12:11 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-11-16 17:53 . 2009-11-17 12:11 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-15 14:17 . 2009-11-15 14:17 -------- d-----w- c:\program files\Defraggler
2009-11-15 13:27 . 2009-11-15 13:27 4096 d-----w- c:\programdata\Yahoo! Companion
2009-11-15 13:27 . 2009-11-10 14:50 607544 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-13 19:32 . 2009-11-23 17:17 4096 d-----w- c:\program files\RogueRemover FREE
2009-11-13 15:29 . 2009-11-13 15:29 -------- d-sh–w- c:\programdata{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-11-12 21:13 . 2009-11-26 12:33 4096 d-----w- c:\program files\QuickTime
2009-11-12 12:19 . 2009-11-12 12:19 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Auslogics
2009-11-11 10:43 . 2009-11-11 10:43 653560 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-11 10:17 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 10:17 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-11 10:00 . 2009-11-11 10:00 20480 d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2009-11-11 09:52 . 2009-11-11 09:52 -------- d-----w- c:\users\Brigitte\AppData\Roaming\HouseCall 6.6
2009-11-10 13:54 . 2009-11-10 13:54 95568 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-10 13:54 . 2009-11-10 13:54 133648 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2009-11-10 13:53 . 2009-11-10 13:53 104016 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2009-11-09 18:15 . 2009-11-08 13:46 86016 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
2009-11-08 16:53 . 2009-11-08 16:53 -------- d–h--w- c:\users\Brigitte\784E6B0F00EC495095A2BBA64F44EC48.TMP
2009-11-08 13:32 . 2009-11-08 13:32 -------- d-----w- c:\users\Brigitte\AppData\Local\TechSmith
2009-11-08 13:31 . 2009-11-11 12:11 -------- d-----w- c:\programdata\TechSmith
2009-11-08 13:31 . 2009-11-08 13:31 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-11-08 13:31 . 2009-11-09 18:46 -------- d-----w- c:\program files\TechSmith
2009-11-08 09:37 . 2005-03-11 17:37 1986560 ----a-w- c:\windows\system32\AudFile.dll
2009-11-08 09:37 . 2005-02-24 12:11 1212416 ----a-w- c:\windows\system32\AudioInfos.dll
2009-11-08 09:37 . 2005-02-24 11:51 348160 ----a-w- c:\windows\system32\WMAFile.dll
2009-11-08 09:37 . 2003-01-26 11:41 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2009-11-08 09:37 . 1998-07-12 21:00 15360 ----a-w- c:\windows\system32\inetfr.DLL
2009-11-07 19:47 . 2009-11-07 19:48 4096 d-----w- c:\program files\SRWare Iron
2009-11-07 09:27 . 2009-11-07 09:27 -------- d-----w- c:\program files\Lavalys
2009-11-06 21:32 . 2009-11-07 19:42 1 ----a-w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-06 21:32 . 2009-11-06 21:32 -------- d-----w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org
2009-11-06 21:22 . 2009-11-06 21:22 -------- d-----w- c:\program files\JRE
2009-11-06 21:22 . 2009-11-06 21:22 4096 d-----w- c:\program files\OpenOffice.org 3
2009-11-06 20:48 . 2009-11-06 20:50 4096 d-----w- c:\program files\PhotoFiltre
2009-11-06 17:38 . 2009-11-06 17:38 -------- d-----w- c:\users\Brigitte\AppData\Roaming\ImgBurn
2009-11-06 17:12 . 2009-11-06 17:12 -------- d-----w- c:\programdata\LightScribe
2009-11-06 17:10 . 2009-11-06 17:12 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Nero
2009-11-06 17:05 . 2009-11-06 17:28 -------- d-----w- c:\programdata\Nero
2009-11-06 17:05 . 2009-11-06 17:29 -------- d-----w- c:\program files\Common Files\Nero
2009-11-03 18:27 . 2009-11-03 18:27 -------- d-----w- c:\program files\VS Revo Group
2009-11-02 19:08 . 2009-11-02 19:08 -------- d-----w- c:\program files\uTorrent
2009-11-02 15:19 . 2009-11-28 14:17 4096 d-----w- c:\users\Brigitte\AppData\Roaming\vlc
2009-11-01 15:31 . 2009-07-22 13:07 77824 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
2009-11-01 15:27 . 2009-10-05 11:34 796400 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
2009-11-01 13:32 . 2009-11-01 13:51 4096 d-----w- c:\users\Brigitte\AppData\Roaming\IDM
2009-11-01 12:20 . 2009-11-10 11:40 1730452 ----a-w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2\3558177607\Update.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-28 17:29 . 2009-09-22 16:13 4096 d-----w- c:\users\Brigitte\AppData\Roaming\uTorrent
2009-11-28 17:05 . 2009-09-06 08:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Skype
2009-11-28 16:31 . 2006-11-02 15:48 684650 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-28 16:31 . 2006-11-02 15:48 130846 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-28 16:16 . 2009-09-12 12:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Orbit
2009-11-27 11:50 . 2009-05-03 14:15 15370988 ----a-w- c:\windows\system32\drivers\fidbox.idx
2009-11-27 11:50 . 2009-05-03 14:15 1147482144 ----a-w- c:\windows\system32\drivers\fidbox.dat
2009-11-26 20:47 . 2009-09-16 15:39 4096 d-----w- c:\program files\Messenger Plus! Live
2009-11-26 20:06 . 2008-07-30 13:02 4096 d-----w- c:\programdata\WLInstaller
2009-11-26 12:10 . 2009-10-09 19:10 4096 d-----w- c:\program files\Trend Micro
2009-11-25 17:06 . 2009-05-24 16:30 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Apple Computer
2009-11-23 18:52 . 2009-03-26 19:11 4096 d-----w- c:\program files\Opera
2009-11-23 17:12 . 2009-02-27 15:58 4096 d-----w- c:\programdata\NOS
2009-11-23 17:10 . 2009-09-21 15:40 4096 d-----w- c:\program files\AIMP2
2009-11-22 17:35 . 2007-08-10 07:53 12288 d-----w- c:\programdata\Microsoft Help
2009-11-22 16:33 . 2009-09-21 15:40 4096 d-----w- c:\users\Brigitte\AppData\Roaming\AIMP
2009-11-21 08:43 . 2008-08-12 11:40 6648 ----a-w- c:\users\Brigitte\AppData\Local\d3d9caps.dat
2009-11-20 19:40 . 2009-11-20 19:40 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-19 19:34 . 2008-07-30 09:14 106904 ----a-w- c:\users\Brigitte\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-19 18:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-11-19 17:39 . 2007-08-10 07:56 28672 d-----w- c:\program files\Microsoft Works
2009-11-17 19:40 . 2008-12-25 09:42 -------- d-----w- c:\programdata\Media Center Programs
2009-11-16 18:14 . 2009-07-02 17:42 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-11-15 13:29 . 2008-12-29 10:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Yahoo!
2009-11-15 13:27 . 2009-02-15 10:43 -------- d-----w- c:\programdata\Yahoo!
2009-11-15 13:27 . 2008-07-30 09:12 4096 d-----w- c:\program files\Yahoo!
2009-11-15 10:30 . 2008-08-14 13:00 3420 ----a-w- c:\users\Brigitte\AppData\Roaming\wklnhst.dat
2009-11-13 19:19 . 2009-09-06 08:27 -------- d-----w- c:\users\Brigitte\AppData\Roaming\skypePM
2009-11-13 16:34 . 2009-03-24 16:27 -------- d-----w- c:\programdata\TuneUp Software
2009-11-11 10:29 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-10 19:48 . 2009-09-18 17:27 4096 d-----w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2
2009-11-08 10:45 . 2009-10-24 11:32 -------- d-----w- c:\program files\Java
2009-11-07 13:30 . 2009-06-25 19:00 16384 d-----w- c:\users\Brigitte\AppData\Roaming\dvdcss
2009-11-07 08:09 . 2007-08-10 06:31 16384 d–h--w- c:\program files\InstallShield Installation Information
2009-11-06 17:00 . 2007-08-10 07:18 -------- d-----w- c:\program files\Common Files\NewTech Infosystems
2009-11-02 19:42 . 2009-09-26 09:54 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 13:50 . 2009-09-01 13:57 -------- d-----w- c:\users\Brigitte\AppData\Roaming\DMCache
2009-10-28 15:53 . 2009-10-28 15:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-28 15:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-28 15:52 . 2009-10-28 15:52 0 ------w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-24 14:14 . 2009-10-16 18:18 604488 ------w- c:\windows\system32\TUProgSt.exe
2009-10-24 13:39 . 2008-10-04 09:10 558640 ----a-w- c:\programdata\CyberLink\CLSetup\Download\MCEDS.exe
2009-10-23 20:35 . 2008-08-01 14:16 -------- d-----w- c:\program files\orange
2009-10-23 15:13 . 2009-10-22 15:57 -------- d-----w- c:\programdata\Messenger Plus!
2009-10-22 18:29 . 2009-10-22 18:29 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Talkback
2009-10-22 17:56 . 2009-10-22 17:56 -------- d-----w- c:\programdata\Cobian
2009-10-21 17:00 . 2009-10-21 16:59 4096 d-----w- c:\program files\BackRex Internet Explorer Backup
2009-10-21 16:50 . 2009-10-21 16:50 4096 d-----w- c:\program files\MozBackup
2009-10-21 14:07 . 2009-10-21 14:07 4096 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-16 18:16 . 2009-03-24 16:25 4096 d-sh–w- c:\programdata{55A29068-F2CE-456C-9148-C869879E2357}
2009-10-16 15:23 . 2009-10-16 15:23 -------- d–h--w- c:\program files\Common Files\Updates
2009-10-14 16:30 . 2009-08-20 16:42 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Notepad++
2009-10-13 18:14 . 2009-10-13 18:13 8192 d-----w- c:\program files\Mozilla Thunderbird
2009-10-11 03:17 . 2009-03-12 18:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 20:22 . 2009-10-10 20:22 364544 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\IsLicense40.dll
2009-10-10 20:22 . 2009-10-10 20:22 2273280 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\G-Recorder.exe
2009-10-10 20:18 . 2009-10-10 20:18 868352 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe
2009-10-10 20:18 . 2009-10-10 20:18 53760 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\zlib.dll
2009-10-10 20:18 . 2009-10-10 20:18 640000 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\dbghelp.dll
2009-10-10 20:18 . 2009-10-10 20:18 1712128 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\GdiPlus.dll
2009-10-10 16:35 . 2009-08-20 16:42 4096 d-----w- c:\program files\Notepad++
2009-10-10 10:26 . 2009-09-07 10:43 -------- d-----w- c:\program files\Foxit Software
2009-10-08 21:08 . 2009-10-28 15:44 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-10-28 15:44 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-10-28 15:44 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-08 15:56 . 2009-08-22 09:46 4096 d-----w- c:\program files\KeyScrambler
2009-10-07 17:38 . 2009-10-07 17:38 117760 ----a-w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-07 17:37 . 2009-06-29 10:53 -------- d-----w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com
2009-10-07 16:11 . 2009-06-10 18:19 4096 d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 15:46 . 2009-10-07 15:46 4096 d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-07 15:05 . 2009-10-07 15:05 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Amazon
2009-10-04 21:33 . 2009-08-22 09:46 115312 ------w- c:\windows\system32\drivers\keyscrambler.sys
2009-10-04 15:33 . 2009-09-23 16:00 4096 d-----w- c:\users\Brigitte\AppData\Roaming\HpUpdate
2009-10-04 13:45 . 2009-10-04 13:45 -------- d-----w- c:\program files\VirusTotalUploader
2009-10-04 08:35 . 2009-10-04 08:35 -------- d-----w- c:\programdata\is-9CFN4
2009-10-03 20:23 . 2009-10-03 20:23 -------- d-----w- c:\program files\WOT
2009-10-03 18:35 . 2009-10-03 18:35 -------- d-----w- c:\program files\COMODO
2009-10-03 17:18 . 2009-10-03 16:18 4096 d-----w- c:\program files\Free Window Registry Repair
2009-10-03 14:24 . 2009-07-01 15:01 4096 d-----w- c:\programdata\G DATA
2009-10-03 14:24 . 2009-05-18 17:34 -------- d-----w- c:\program files\Common Files\G DATA
2009-10-02 20:11 . 2009-09-12 12:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\GrabPro
2009-10-02 15:13 . 2009-07-31 15:34 -------- d-----w- c:\programdata\fssg
2009-10-02 10:38 . 2009-10-02 10:38 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-01 01:02 . 2009-10-28 15:47 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-28 15:48 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-28 15:47 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-28 15:47 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-28 15:48 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-28 15:47 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-28 15:47 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-28 15:47 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-28 15:47 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-28 15:47 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-28 15:47 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-28 15:48 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-10-28 15:47 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-10-28 15:47 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-10-28 15:47 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-10-28 15:47 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-26 19:56 . 2009-09-26 19:56 34688 ----a-w- c:\windows\system32\FM20FRA.DLL
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE~\Browser Helper Objects{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-03 20:12 556432 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-04-11 1233920]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-19 125952]
“MailNotifier”=“c:\program files\orange\MailNotifier\MailNotifier.exe” [2009-10-12 692224]
“Messenger (Yahoo!)”=“c:\program files\Yahoo!\Messenger\YahooMessenger.exe” [2009-11-10 5244216]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-11-02 289072]
“msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe” [2009-11-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“PLFSetL”=“c:\windows\PLFSetL.exe” [2007-07-05 94208]
“Malwarebytes’ Anti-Malware”=“c:\program files\Malwarebytes’ Anti-Malware\mbamgui.exe” [2009-09-10 420176]
“MSSE”=“c:\program files\Microsoft Security Essentials\msseces.exe” [2009-09-13 1048392]
“COMODO Internet Security”=“c:\program files\COMODO\COMODO Internet Security\cfp.exe” [2009-11-17 1800464]
“BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe” [2009-09-26 83312]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“KeyScrambler”=“c:\program files\KeyScrambler\getting_started.html” [X]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-11-28 1719568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“FilterAdministratorToken”= 1 (0x1)
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux”=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=“Service”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logiciel Kodak EasyShare.lnk]
backup=c:\windows\pss\Logiciel Kodak EasyShare.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
backup=c:\windows\pss\Orbit.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 - Capture d’écran et lancement.lnk]
backup=c:\windows\pss\OneNote 2007 - Capture d’écran et lancement.lnk.Startup
backupExtension=.Startup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^WkCalRem.LNK]
backup=c:\windows\pss\WkCalRem.LNK.Startup
backupExtension=.Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“WindowsWelcomeCenter”=rundll32.exe oobefldr.dll,ShowWelcomeCenter

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“HP Software Update”=c:\program files\HP\HP Software Update\HPWuSchd2.exe
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):be,e2,88,b6,74,df,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-759318378-497761762-3404630427-1000]
“EnableNotificationsRef”=dword:0000000c

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [16/11/2009 18:53 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [16/11/2009 18:53 29520]
R1 SbFw;SbFw;c:\windows\System32\drivers\SbFw.sys [31/10/2008 06:09 270888]
R1 VBoxDrv;VirtualBox Service;c:\windows\System32\drivers\VBoxDrv.sys [20/11/2009 16:54 116560]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\System32\drivers\VBoxUSBMon.sys [20/11/2009 16:54 41424]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [08/11/2008 11:21 61424]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 15:28 1533808]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [10/08/2007 15:41 179712]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [10/08/2007 15:41 32256]
R3 KeyScrambler;KeyScrambler;c:\windows\System32\drivers\keyscrambler.sys [22/08/2009 10:46 115312]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2009 16:46 19160]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18/06/2009 18:48 42480]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [26/09/2009 04:28 4639136]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\System32\drivers\SbFwIm.sys [06/06/2009 12:07 65576]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\System32\drivers\VBoxNetAdp.sys [10/11/2009 14:54 95568]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\System32\drivers\VBoxNetFlt.sys [10/11/2009 14:53 104016]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes’ Anti-Malware\mbamservice.exe [07/10/2009 16:46 269648]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [31/07/2008 09:57 21504]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [29/10/2009 10:22 30603640]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [30/07/2008 11:28 28224]
S4 0267471241168295mcinstcleanup;0267471241168295mcinstcleanup; [x]
S4 gupdate;Google Update Service (gupdate); [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier ‘Tâches planifiées’

2009-11-28 c:\windows\Tasks\User_Feed_Synchronization-{55AF2E8A-EBC9-4A50-8828-434D9E33BE57}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]

2009-11-28 c:\windows\Tasks\User_Feed_Synchronization-{9E24F08E-1327-49FE-856E-F5C2AE8D8770}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = fr.yahoo.com…
    uSearchMigratedDefaultURL = search.yahoo.com…
    mWindow Title =
    IE: ?4da1a3bfcab942eab3ec3b465ef4d37d
    IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
    IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
    IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
    IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    Trusted Zone: orange.fr\logicielsgratuits
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    DPF: {4DD20514-9520-40A7-9CD6-66883643A20B} - www.boaki.com…
    DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} - logicielsgratuits.orange.fr…
    DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} - webtv.guidetv.orange.fr…
    FF - ProfilePath - c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default
    FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl3.rsa_seed_sha”, true);
.

        • ORPHELINS SUPPRIMES - - - -

AddRemove-Activation Assistant for the 2007 Microsoft Office suites - c:\programdata{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD} - c:\program files\Apoint2K\Uninstap.exe ADDREMOVE
AddRemove-{ORAHSS}.Bas_Debit_CustoUpdate - c:\program files\OrangeHSS\Uninstall\Bas_Debit_CustoUpdate\Shell.exe MainUninstall.shl
AddRemove-{ORAHSS}.Browser - c:\program files\OrangeHSS\Uninstall\Browser\Shell.exe MainUninstall.shl


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-11-28 18:29
Windows 6.0.6002 Service Pack 2 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
“ImagePath”="??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_USERS.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
“88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977”=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,54,ca,1b,61,f8,dc,5a,49,ac,b2,d0,
“2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81”=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,54,ca,1b,61,f8,dc,5a,49,ac,b2,d0,\

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000_Classes\CLSID{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
“scansk”=hex(0):83,b0,78,40,81,e9,75,66,35,39,6e,b9,af,9d,eb,10,2e,43,f5,89,8d,
2f,8a,99,58,6e,ea,03,80,1a,7c,76,b0,47,93,e9,ec,97,3e,8e,00,00,00,00,00,00,\

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000_Classes\CLSID{ef31be34-2309-4cb3-8120-c733202577b9}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
“Model”=dword:00000130
“Therad”=dword:00000020
“MData”=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,05,ce,b4,e4,bb,8b,c6,6f,2e,4d,91,eb,9e,ca,8f,8d,75,38,f2,33,01,e7,\

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
.
Heure de fin: 2009-11-28 18:35
ComboFix-quarantined-files.txt 2009-11-28 17:35

Avant-CF: 19 393 957 888 octets libres
Après-CF: 19 494 051 840 octets libres

    • End Of File - - 95D0D6A9205A45FEB7D08DC068C15CD9

ComboFix 09-11-28.03 - Brigitte 29/11/2009 11:43.3.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2037.1091 [GMT 1:00]
Lancé depuis: c:\users\Brigitte\Desktop\poisson.exe
Commutateurs utilisés :: c:\users\Brigitte\Desktop\CFScript.txt
SP: SUPERAntiSpyware disabled (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
“c:\users\Brigitte\784E6B0F00EC495095A2BBA64F44EC48.TMP”
“c:\users\Brigitte\intro.bmp”
“c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf”
.
ADS - TEMP: deleted 1276 bytes in 11 streams.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\WOT
c:\program files\WOT\WOT.dll
c:\users\Brigitte\intro.bmp
c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-28 au 2009-11-29 ))))))))))))))))))))))))))))))))))))
.

2009-11-29 10:57 . 2009-11-29 11:00 4096 d-----w- c:\users\Brigitte\AppData\Local\temp
2009-11-29 10:57 . 2009-11-29 10:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-29 09:49 . 2009-11-29 09:51 -------- d-----w- c:\program files\Windows Live Safety Center
2009-11-29 09:18 . 2009-11-29 09:18 90112 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy{CF49C79A-50A0-B13D-0DB8-0067D6A7ED5F}-winfile.dll
2009-11-28 18:40 . 2009-11-28 18:40 -------- d-----w- c:\program files\SuperCopier2
2009-11-28 18:36 . 2009-11-28 18:36 -------- d-----w- c:\users\Brigitte\AppData\Roaming\TeraCopy
2009-11-28 17:59 . 2009-11-28 17:59 -------- d-----w- c:\program files\uTorrent
2009-11-28 17:07 . 2009-11-28 17:35 45056 d-----w- C:\poisson
2009-11-28 08:47 . 2009-11-28 08:48 4096 d-----w- c:\program files\Orbitdownloader
2009-11-27 12:17 . 2009-11-27 12:17 171552 ----a-w- c:\windows\system32\guard32.dll
2009-11-27 12:17 . 2009-11-27 17:59 4096 d-----w- C:\UsbFix
2009-11-26 20:47 . 2009-11-26 20:48 -------- d-----w- c:\programdata\MessengerDiscovery 2
2009-11-26 20:47 . 2009-11-26 20:47 4096 d-----w- c:\program files\MessengerDiscovery 2
2009-11-25 18:42 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 14:22 . 2009-11-25 14:22 -------- d-----w- c:\program files\FileHippo.com
2009-11-25 13:53 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-25 13:53 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-25 13:51 . 2009-11-25 13:52 -------- d-----w- c:\programdata{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-25 11:52 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 11:52 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-23 17:05 . 2009-11-23 17:07 4096 d-----w- c:\program files\7-Zip
2009-11-22 13:03 . 2009-11-22 13:04 4096 d-----w- c:\program files\ImgBurn
2009-11-20 19:22 . 2009-11-20 19:22 -------- d-----w- c:\program files\Recuva
2009-11-20 15:58 . 2009-11-20 17:06 -------- d-----w- c:\users\Brigitte.VirtualBox
2009-11-20 15:54 . 2009-11-10 13:54 116560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-11-20 15:54 . 2009-11-10 13:53 41424 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-11-20 15:53 . 2009-11-20 15:53 -------- d-----w- c:\program files\Sun
2009-11-19 18:15 . 2009-11-19 18:15 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-11-19 18:10 . 2009-11-19 18:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-19 18:05 . 2009-11-19 18:05 -------- d-----w- c:\program files\Microsoft Analysis Services
2009-11-19 18:03 . 2009-11-19 18:03 -------- d-----r- C:\MSOCache
2009-11-18 19:27 . 2009-11-19 12:28 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Download Manager
2009-11-18 19:05 . 2009-11-26 20:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-18 19:03 . 2009-11-26 20:43 4096 d-----w- c:\program files\Windows Live
2009-11-18 15:28 . 2009-11-18 15:28 -------- d-----w- c:\program files\Gibcom
2009-11-17 19:18 . 2009-11-17 19:20 -------- d-----w- c:\program files\Ubisoft
2009-11-17 16:12 . 2009-11-17 16:12 25214 ----a-r- c:\users\Brigitte\AppData\Roaming\Microsoft\Installer{4103778F-5EAF-476E-B3C1-2891EF9A4D8C}\controlPanelIcon.exe
2009-11-17 16:11 . 2009-11-17 16:12 4096 d-----w- c:\program files\Kptic Neonumeric
2009-11-17 11:52 . 2009-11-17 11:52 -------- d-----w- c:\programdata\F-Secure
2009-11-16 20:31 . 2009-11-16 20:41 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Kptic
2009-11-16 17:53 . 2009-11-16 17:54 4096 d-----w- c:\program files\Microsoft Security Essentials
2009-11-16 17:53 . 2009-11-16 18:12 -------- d-----w- c:\programdata\Comodo
2009-11-16 17:53 . 2009-11-25 11:50 128376 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-16 17:53 . 2009-11-17 12:11 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-11-16 17:53 . 2009-11-17 12:11 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-15 14:17 . 2009-11-15 14:17 -------- d-----w- c:\program files\Defraggler
2009-11-15 13:27 . 2009-11-29 09:16 -------- d-----w- c:\programdata\Yahoo! Companion
2009-11-15 13:27 . 2009-11-10 14:50 607544 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-13 15:29 . 2009-11-13 15:29 -------- d-sh–w- c:\programdata{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-11-12 21:13 . 2009-11-26 12:33 -------- d-----w- c:\program files\QuickTime
2009-11-12 12:19 . 2009-11-12 12:19 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Auslogics
2009-11-11 10:43 . 2009-11-11 10:43 653560 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-11 10:17 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 10:17 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-11 10:00 . 2009-11-11 10:00 20480 d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2009-11-11 09:52 . 2009-11-11 09:52 -------- d-----w- c:\users\Brigitte\AppData\Roaming\HouseCall 6.6
2009-11-10 13:54 . 2009-11-10 13:54 95568 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-10 13:54 . 2009-11-10 13:54 133648 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2009-11-10 13:53 . 2009-11-10 13:53 104016 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2009-11-09 18:15 . 2009-11-08 13:46 86016 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
2009-11-08 16:53 . 2009-11-08 16:53 -------- d–h--w- c:\users\Brigitte\784E6B0F00EC495095A2BBA64F44EC48.TMP
2009-11-08 13:32 . 2009-11-08 13:32 -------- d-----w- c:\users\Brigitte\AppData\Local\TechSmith
2009-11-08 13:31 . 2009-11-11 12:11 -------- d-----w- c:\programdata\TechSmith
2009-11-08 13:31 . 2009-11-08 13:31 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-11-08 13:31 . 2009-11-09 18:46 -------- d-----w- c:\program files\TechSmith
2009-11-08 09:37 . 2005-03-11 17:37 1986560 ----a-w- c:\windows\system32\AudFile.dll
2009-11-08 09:37 . 2005-02-24 12:11 1212416 ----a-w- c:\windows\system32\AudioInfos.dll
2009-11-08 09:37 . 2005-02-24 11:51 348160 ----a-w- c:\windows\system32\WMAFile.dll
2009-11-08 09:37 . 2003-01-26 11:41 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2009-11-08 09:37 . 1998-07-12 21:00 15360 ----a-w- c:\windows\system32\inetfr.DLL
2009-11-07 19:47 . 2009-11-07 19:48 4096 d-----w- c:\program files\SRWare Iron
2009-11-07 09:27 . 2009-11-07 09:27 -------- d-----w- c:\program files\Lavalys
2009-11-06 21:32 . 2009-11-07 19:42 1 ----a-w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-06 21:32 . 2009-11-06 21:32 -------- d-----w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org
2009-11-06 21:22 . 2009-11-06 21:22 -------- d-----w- c:\program files\JRE
2009-11-06 21:22 . 2009-11-06 21:22 4096 d-----w- c:\program files\OpenOffice.org 3
2009-11-06 20:48 . 2009-11-06 20:50 4096 d-----w- c:\program files\PhotoFiltre
2009-11-06 17:38 . 2009-11-06 17:38 -------- d-----w- c:\users\Brigitte\AppData\Roaming\ImgBurn
2009-11-06 17:12 . 2009-11-06 17:12 -------- d-----w- c:\programdata\LightScribe
2009-11-06 17:10 . 2009-11-06 17:12 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Nero
2009-11-06 17:05 . 2009-11-06 17:28 -------- d-----w- c:\programdata\Nero
2009-11-06 17:05 . 2009-11-06 17:29 -------- d-----w- c:\program files\Common Files\Nero
2009-11-03 18:27 . 2009-11-03 18:27 -------- d-----w- c:\program files\VS Revo Group
2009-11-02 15:19 . 2009-11-29 09:05 -------- d-----w- c:\users\Brigitte\AppData\Roaming\vlc
2009-11-01 15:31 . 2009-07-22 13:07 77824 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
2009-11-01 15:27 . 2009-10-05 11:34 796400 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
2009-11-01 13:32 . 2009-11-01 13:51 -------- d-----w- c:\users\Brigitte\AppData\Roaming\IDM
2009-11-01 12:20 . 2009-11-10 11:40 1730452 ----a-w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2\3558177607\Update.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-29 11:00 . 2009-09-12 12:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Orbit
2009-11-29 10:30 . 2009-09-22 16:13 4096 d-----w- c:\users\Brigitte\AppData\Roaming\uTorrent
2009-11-29 10:26 . 2009-09-06 08:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Skype
2009-11-29 09:05 . 2009-06-25 19:00 16384 d-----w- c:\users\Brigitte\AppData\Roaming\dvdcss
2009-11-28 16:31 . 2006-11-02 15:48 684650 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-28 16:31 . 2006-11-02 15:48 130846 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-27 11:50 . 2009-05-03 14:15 15370988 ----a-w- c:\windows\system32\drivers\fidbox.idx
2009-11-27 11:50 . 2009-05-03 14:15 1147482144 ----a-w- c:\windows\system32\drivers\fidbox.dat
2009-11-26 20:47 . 2009-09-16 15:39 4096 d-----w- c:\program files\Messenger Plus! Live
2009-11-26 20:06 . 2008-07-30 13:02 4096 d-----w- c:\programdata\WLInstaller
2009-11-26 12:10 . 2009-10-09 19:10 4096 d-----w- c:\program files\Trend Micro
2009-11-25 17:06 . 2009-05-24 16:30 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Apple Computer
2009-11-23 18:52 . 2009-03-26 19:11 4096 d-----w- c:\program files\Opera
2009-11-23 17:12 . 2009-02-27 15:58 4096 d-----w- c:\programdata\NOS
2009-11-23 17:10 . 2009-09-21 15:40 4096 d-----w- c:\program files\AIMP2
2009-11-22 17:35 . 2007-08-10 07:53 12288 d-----w- c:\programdata\Microsoft Help
2009-11-22 16:33 . 2009-09-21 15:40 4096 d-----w- c:\users\Brigitte\AppData\Roaming\AIMP
2009-11-21 08:43 . 2008-08-12 11:40 6648 ----a-w- c:\users\Brigitte\AppData\Local\d3d9caps.dat
2009-11-19 19:34 . 2008-07-30 09:14 106904 ----a-w- c:\users\Brigitte\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-19 18:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-11-19 17:39 . 2007-08-10 07:56 28672 d-----w- c:\program files\Microsoft Works
2009-11-17 19:40 . 2008-12-25 09:42 -------- d-----w- c:\programdata\Media Center Programs
2009-11-16 18:14 . 2009-07-02 17:42 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-11-15 13:29 . 2008-12-29 10:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Yahoo!
2009-11-15 13:27 . 2009-02-15 10:43 -------- d-----w- c:\programdata\Yahoo!
2009-11-15 13:27 . 2008-07-30 09:12 4096 d-----w- c:\program files\Yahoo!
2009-11-15 10:30 . 2008-08-14 13:00 3420 ----a-w- c:\users\Brigitte\AppData\Roaming\wklnhst.dat
2009-11-13 19:19 . 2009-09-06 08:27 -------- d-----w- c:\users\Brigitte\AppData\Roaming\skypePM
2009-11-13 16:34 . 2009-03-24 16:27 -------- d-----w- c:\programdata\TuneUp Software
2009-11-11 10:29 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-10 19:48 . 2009-09-18 17:27 4096 d-----w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2
2009-11-08 10:45 . 2009-10-24 11:32 -------- d-----w- c:\program files\Java
2009-11-07 08:09 . 2007-08-10 06:31 16384 d–h--w- c:\program files\InstallShield Installation Information
2009-11-06 17:00 . 2007-08-10 07:18 -------- d-----w- c:\program files\Common Files\NewTech Infosystems
2009-11-02 19:42 . 2009-09-26 09:54 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 13:50 . 2009-09-01 13:57 -------- d-----w- c:\users\Brigitte\AppData\Roaming\DMCache
2009-10-28 15:53 . 2009-10-28 15:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-28 15:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-28 15:52 . 2009-10-28 15:52 0 ------w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-24 14:14 . 2009-10-16 18:18 604488 ------w- c:\windows\system32\TUProgSt.exe
2009-10-24 13:39 . 2008-10-04 09:10 558640 ----a-w- c:\programdata\CyberLink\CLSetup\Download\MCEDS.exe
2009-10-23 20:35 . 2008-08-01 14:16 -------- d-----w- c:\program files\orange
2009-10-23 15:13 . 2009-10-22 15:57 -------- d-----w- c:\programdata\Messenger Plus!
2009-10-22 18:29 . 2009-10-22 18:29 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Talkback
2009-10-22 17:56 . 2009-10-22 17:56 -------- d-----w- c:\programdata\Cobian
2009-10-21 17:00 . 2009-10-21 16:59 4096 d-----w- c:\program files\BackRex Internet Explorer Backup
2009-10-21 16:50 . 2009-10-21 16:50 4096 d-----w- c:\program files\MozBackup
2009-10-21 14:07 . 2009-10-21 14:07 4096 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-16 18:16 . 2009-03-24 16:25 4096 d-sh–w- c:\programdata{55A29068-F2CE-456C-9148-C869879E2357}
2009-10-16 15:23 . 2009-10-16 15:23 -------- d–h--w- c:\program files\Common Files\Updates
2009-10-14 16:30 . 2009-08-20 16:42 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Notepad++
2009-10-13 18:14 . 2009-10-13 18:13 8192 d-----w- c:\program files\Mozilla Thunderbird
2009-10-11 03:17 . 2009-03-12 18:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 20:22 . 2009-10-10 20:22 364544 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\IsLicense40.dll
2009-10-10 20:22 . 2009-10-10 20:22 2273280 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\G-Recorder.exe
2009-10-10 20:18 . 2009-10-10 20:18 868352 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe
2009-10-10 20:18 . 2009-10-10 20:18 53760 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\zlib.dll
2009-10-10 20:18 . 2009-10-10 20:18 640000 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\dbghelp.dll
2009-10-10 20:18 . 2009-10-10 20:18 1712128 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\GdiPlus.dll
2009-10-10 16:35 . 2009-08-20 16:42 4096 d-----w- c:\program files\Notepad++
2009-10-10 10:26 . 2009-09-07 10:43 -------- d-----w- c:\program files\Foxit Software
2009-10-08 21:08 . 2009-10-28 15:44 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-10-28 15:44 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-10-28 15:44 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-08 15:56 . 2009-08-22 09:46 4096 d-----w- c:\program files\KeyScrambler
2009-10-07 17:38 . 2009-10-07 17:38 117760 ----a-w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-07 17:37 . 2009-06-29 10:53 -------- d-----w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com
2009-10-07 16:11 . 2009-06-10 18:19 4096 d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 15:46 . 2009-10-07 15:46 4096 d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-07 15:05 . 2009-10-07 15:05 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Amazon
2009-10-04 21:33 . 2009-08-22 09:46 115312 ------w- c:\windows\system32\drivers\keyscrambler.sys
2009-10-04 15:33 . 2009-09-23 16:00 4096 d-----w- c:\users\Brigitte\AppData\Roaming\HpUpdate
2009-10-04 13:45 . 2009-10-04 13:45 -------- d-----w- c:\program files\VirusTotalUploader
2009-10-04 08:35 . 2009-10-04 08:35 -------- d-----w- c:\programdata\is-9CFN4
2009-10-03 18:35 . 2009-10-03 18:35 -------- d-----w- c:\program files\COMODO
2009-10-03 17:18 . 2009-10-03 16:18 4096 d-----w- c:\program files\Free Window Registry Repair
2009-10-03 14:24 . 2009-07-01 15:01 4096 d-----w- c:\programdata\G DATA
2009-10-03 14:24 . 2009-05-18 17:34 -------- d-----w- c:\program files\Common Files\G DATA
2009-10-02 20:11 . 2009-09-12 12:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\GrabPro
2009-10-02 15:13 . 2009-07-31 15:34 -------- d-----w- c:\programdata\fssg
2009-10-02 10:38 . 2009-10-02 10:38 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-01 01:02 . 2009-10-28 15:47 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-28 15:48 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-28 15:47 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-28 15:47 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-28 15:48 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-28 15:47 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-28 15:47 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-28 15:47 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-28 15:47 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-28 15:47 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-28 15:47 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-28 15:48 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-10-28 15:47 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-10-28 15:47 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-10-28 15:47 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-10-28 15:47 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-26 19:56 . 2009-09-26 19:56 34688 ----a-w- c:\windows\system32\FM20FRA.DLL
2009-09-26 02:32 . 2009-09-26 02:32 1205080 ----a-w- c:\windows\system32\FM20.DLL
2009-09-26 02:32 . 2009-09-26 02:32 31600 ----a-w- c:\windows\system32\FM20ENU.DLL
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\is-9CFN4 ----

2009-10-04 08:35 . 2009-10-04 08:35 152011 —ha-w- c:\programdata\is-9CFN4~PRCustomProps#122.dat
2009-10-04 08:35 . 2009-10-04 08:35 64011 —ha-w- c:\programdata\is-9CFN4~PRObjects#122.dat

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE~\Browser Helper Objects{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-03 20:12 556432 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-04-11 1233920]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-19 125952]
“MailNotifier”=“c:\program files\orange\MailNotifier\MailNotifier.exe” [2009-10-12 692224]
“Messenger (Yahoo!)”=“c:\program files\Yahoo!\Messenger\YahooMessenger.exe” [2009-11-10 5244216]
“msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe” [2009-11-26 3883856]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-11-28 289584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“PLFSetL”=“c:\windows\PLFSetL.exe” [2007-07-05 94208]
“Malwarebytes’ Anti-Malware”=“c:\program files\Malwarebytes’ Anti-Malware\mbamgui.exe” [2009-09-10 420176]
“MSSE”=“c:\program files\Microsoft Security Essentials\msseces.exe” [2009-09-13 1048392]
“COMODO Internet Security”=“c:\program files\COMODO\COMODO Internet Security\cfp.exe” [2009-11-17 1800464]
“BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe” [2009-09-26 83312]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“KeyScrambler”=“c:\program files\KeyScrambler\getting_started.html” [X]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-11-28 1719568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“FilterAdministratorToken”= 1 (0x1)
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux”=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=“Service”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logiciel Kodak EasyShare.lnk]
backup=c:\windows\pss\Logiciel Kodak EasyShare.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
backup=c:\windows\pss\Orbit.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 - Capture d’écran et lancement.lnk]
backup=c:\windows\pss\OneNote 2007 - Capture d’écran et lancement.lnk.Startup
backupExtension=.Startup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^WkCalRem.LNK]
backup=c:\windows\pss\WkCalRem.LNK.Startup
backupExtension=.Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“WindowsWelcomeCenter”=rundll32.exe oobefldr.dll,ShowWelcomeCenter

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“HP Software Update”=c:\program files\HP\HP Software Update\HPWuSchd2.exe
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):be,e2,88,b6,74,df,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-759318378-497761762-3404630427-1000]
“EnableNotificationsRef”=dword:0000000c

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [16/11/2009 18:53 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [16/11/2009 18:53 29520]
R1 SbFw;SbFw;c:\windows\System32\drivers\SbFw.sys [31/10/2008 06:09 270888]
R1 VBoxDrv;VirtualBox Service;c:\windows\System32\drivers\VBoxDrv.sys [20/11/2009 16:54 116560]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\System32\drivers\VBoxUSBMon.sys [20/11/2009 16:54 41424]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [08/11/2008 11:21 61424]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [10/08/2007 15:41 179712]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [10/08/2007 15:41 32256]
R3 KeyScrambler;KeyScrambler;c:\windows\System32\drivers\keyscrambler.sys [22/08/2009 10:46 115312]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2009 16:46 19160]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\System32\drivers\SbFwIm.sys [06/06/2009 12:07 65576]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\System32\drivers\VBoxNetAdp.sys [10/11/2009 14:54 95568]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\System32\drivers\VBoxNetFlt.sys [10/11/2009 14:53 104016]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes’ Anti-Malware\mbamservice.exe [07/10/2009 16:46 269648]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [31/07/2008 09:57 21504]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [29/10/2009 10:22 30603640]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18/06/2009 18:48 42480]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [26/09/2009 04:28 4639136]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [30/07/2008 11:28 28224]
S4 0267471241168295mcinstcleanup;0267471241168295mcinstcleanup; [x]
S4 gupdate;Google Update Service (gupdate); [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier ‘Tâches planifiées’

2009-11-29 c:\windows\Tasks\User_Feed_Synchronization-{55AF2E8A-EBC9-4A50-8828-434D9E33BE57}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]

2009-11-29 c:\windows\Tasks\User_Feed_Synchronization-{9E24F08E-1327-49FE-856E-F5C2AE8D8770}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = fr.yahoo.com…
    uSearchMigratedDefaultURL = search.yahoo.com…
    mWindow Title =
    IE: ?4da1a3bfcab942eab3ec3b465ef4d37d
    IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
    IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
    IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
    IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    Trusted Zone: orange.fr\logicielsgratuits
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    DPF: {4DD20514-9520-40A7-9CD6-66883643A20B} - www.boaki.com…
    DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} - logicielsgratuits.orange.fr…
    DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} - webtv.guidetv.orange.fr…
    FF - ProfilePath - c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default
    FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl3.rsa_seed_sha”, true);
.


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-11-29 12:07
Windows 6.0.6002 Service Pack 2 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
“ImagePath”="??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\acer\Empowering Technology\ePower\ePowerSvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\users\Brigitte\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.


.
Heure de fin: 2009-11-29 12:10 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-11-29 11:10
ComboFix2.txt 2009-11-28 17:35

Avant-CF: 24 811 622 400 octets libres
Après-CF: 24 762 179 584 octets libres

    • End Of File - - 9079DB2FAF1C4F4F7DD1FEC3CE1E0418

Je ne voulais pas que Wot sois supprimer de IE

Ok

Met c’est quoi ce truc : c:\programdata\is-9CFN4

Et non j’en veux pas de ce truc de m***e !!! Je ta passe le rapport de suite !

ComboFix 09-11-29.06 - Brigitte 30/11/2009 13:07.4.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2037.1071 [GMT 1:00]
Lancé depuis: c:\users\Brigitte\Desktop\poisson.exe
Commutateurs utilisés :: c:\users\Brigitte\Desktop\CFScript.txt
SP: SUPERAntiSpyware disabled (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-10-28 au 2009-11-30 ))))))))))))))))))))))))))))))))))))
.

2009-11-30 12:21 . 2009-11-30 12:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-29 11:56 . 2009-11-29 11:56 -------- d-----w- c:\program files\WOT
2009-11-29 10:57 . 2009-11-30 12:23 12288 d-----w- c:\users\Brigitte\AppData\Local\temp
2009-11-29 10:38 . 2009-11-29 11:10 -------- d-----w- C:\poisson17870p
2009-11-29 09:49 . 2009-11-29 09:51 -------- d-----w- c:\program files\Windows Live Safety Center
2009-11-29 09:18 . 2009-11-29 09:18 90112 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy{CF49C79A-50A0-B13D-0DB8-0067D6A7ED5F}-winfile.dll
2009-11-28 18:40 . 2009-11-28 18:40 -------- d-----w- c:\program files\SuperCopier2
2009-11-28 18:36 . 2009-11-28 18:36 -------- d-----w- c:\users\Brigitte\AppData\Roaming\TeraCopy
2009-11-28 17:59 . 2009-11-28 17:59 -------- d-----w- c:\program files\uTorrent
2009-11-28 17:07 . 2009-11-28 17:35 -------- d-----w- C:\poisson
2009-11-28 08:47 . 2009-11-28 08:48 4096 d-----w- c:\program files\Orbitdownloader
2009-11-27 12:17 . 2009-11-27 12:17 171552 ----a-w- c:\windows\system32\guard32.dll
2009-11-27 12:17 . 2009-11-27 17:59 -------- d-----w- C:\UsbFix
2009-11-26 20:47 . 2009-11-26 20:48 -------- d-----w- c:\programdata\MessengerDiscovery 2
2009-11-26 20:47 . 2009-11-26 20:47 4096 d-----w- c:\program files\MessengerDiscovery 2
2009-11-25 18:42 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 14:22 . 2009-11-25 14:22 -------- d-----w- c:\program files\FileHippo.com
2009-11-25 13:53 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-25 13:53 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-25 13:51 . 2009-11-25 13:52 -------- d-----w- c:\programdata{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-25 11:52 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 11:52 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-23 17:05 . 2009-11-23 17:07 4096 d-----w- c:\program files\7-Zip
2009-11-22 13:03 . 2009-11-22 13:04 4096 d-----w- c:\program files\ImgBurn
2009-11-20 19:22 . 2009-11-20 19:22 -------- d-----w- c:\program files\Recuva
2009-11-20 15:58 . 2009-11-20 17:06 -------- d-----w- c:\users\Brigitte.VirtualBox
2009-11-20 15:54 . 2009-11-10 13:54 116560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-11-20 15:54 . 2009-11-10 13:53 41424 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-11-20 15:53 . 2009-11-20 15:53 -------- d-----w- c:\program files\Sun
2009-11-19 18:15 . 2009-11-19 18:15 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-11-19 18:10 . 2009-11-19 18:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-19 18:05 . 2009-11-19 18:05 -------- d-----w- c:\program files\Microsoft Analysis Services
2009-11-19 18:03 . 2009-11-19 18:03 -------- d-----r- C:\MSOCache
2009-11-18 19:27 . 2009-11-19 12:28 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Download Manager
2009-11-18 19:05 . 2009-11-26 20:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-18 19:03 . 2009-11-26 20:43 4096 d-----w- c:\program files\Windows Live
2009-11-18 15:28 . 2009-11-18 15:28 -------- d-----w- c:\program files\Gibcom
2009-11-17 19:18 . 2009-11-17 19:20 -------- d-----w- c:\program files\Ubisoft
2009-11-17 16:12 . 2009-11-17 16:12 25214 ----a-r- c:\users\Brigitte\AppData\Roaming\Microsoft\Installer{4103778F-5EAF-476E-B3C1-2891EF9A4D8C}\controlPanelIcon.exe
2009-11-17 16:11 . 2009-11-17 16:12 4096 d-----w- c:\program files\Kptic Neonumeric
2009-11-17 11:52 . 2009-11-17 11:52 -------- d-----w- c:\programdata\F-Secure
2009-11-16 20:31 . 2009-11-16 20:41 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Kptic
2009-11-16 17:53 . 2009-11-16 17:54 4096 d-----w- c:\program files\Microsoft Security Essentials
2009-11-16 17:53 . 2009-11-16 18:12 -------- d-----w- c:\programdata\Comodo
2009-11-16 17:53 . 2009-11-25 11:50 128376 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-16 17:53 . 2009-11-17 12:11 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-11-16 17:53 . 2009-11-17 12:11 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-15 14:17 . 2009-11-15 14:17 -------- d-----w- c:\program files\Defraggler
2009-11-15 13:27 . 2009-11-10 14:50 607544 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-13 15:29 . 2009-11-13 15:29 -------- d-sh–w- c:\programdata{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-11-12 21:13 . 2009-11-26 12:33 -------- d-----w- c:\program files\QuickTime
2009-11-12 12:19 . 2009-11-12 12:19 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Auslogics
2009-11-11 10:43 . 2009-11-11 10:43 653560 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-11 10:17 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 10:17 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-11 10:00 . 2009-11-11 10:00 20480 d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2009-11-11 09:52 . 2009-11-11 09:52 -------- d-----w- c:\users\Brigitte\AppData\Roaming\HouseCall 6.6
2009-11-10 13:54 . 2009-11-10 13:54 95568 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-10 13:54 . 2009-11-10 13:54 133648 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2009-11-10 13:53 . 2009-11-10 13:53 104016 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2009-11-09 18:15 . 2009-11-08 13:46 86016 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
2009-11-08 16:53 . 2009-11-08 16:53 -------- d–h--w- c:\users\Brigitte\784E6B0F00EC495095A2BBA64F44EC48.TMP
2009-11-08 13:32 . 2009-11-08 13:32 -------- d-----w- c:\users\Brigitte\AppData\Local\TechSmith
2009-11-08 13:31 . 2009-11-11 12:11 -------- d-----w- c:\programdata\TechSmith
2009-11-08 13:31 . 2009-11-08 13:31 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-11-08 13:31 . 2009-11-09 18:46 -------- d-----w- c:\program files\TechSmith
2009-11-08 09:37 . 2005-03-11 17:37 1986560 ----a-w- c:\windows\system32\AudFile.dll
2009-11-08 09:37 . 2005-02-24 12:11 1212416 ----a-w- c:\windows\system32\AudioInfos.dll
2009-11-08 09:37 . 2005-02-24 11:51 348160 ----a-w- c:\windows\system32\WMAFile.dll
2009-11-08 09:37 . 2003-01-26 11:41 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2009-11-08 09:37 . 1998-07-12 21:00 15360 ----a-w- c:\windows\system32\inetfr.DLL
2009-11-07 19:47 . 2009-11-07 19:48 4096 d-----w- c:\program files\SRWare Iron
2009-11-07 09:27 . 2009-11-07 09:27 -------- d-----w- c:\program files\Lavalys
2009-11-06 21:32 . 2009-11-07 19:42 1 ----a-w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-06 21:32 . 2009-11-06 21:32 -------- d-----w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org
2009-11-06 21:22 . 2009-11-06 21:22 -------- d-----w- c:\program files\JRE
2009-11-06 21:22 . 2009-11-06 21:22 4096 d-----w- c:\program files\OpenOffice.org 3
2009-11-06 20:48 . 2009-11-06 20:50 4096 d-----w- c:\program files\PhotoFiltre
2009-11-06 17:38 . 2009-11-06 17:38 -------- d-----w- c:\users\Brigitte\AppData\Roaming\ImgBurn
2009-11-06 17:12 . 2009-11-06 17:12 -------- d-----w- c:\programdata\LightScribe
2009-11-06 17:10 . 2009-11-06 17:12 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Nero
2009-11-06 17:05 . 2009-11-06 17:28 -------- d-----w- c:\programdata\Nero
2009-11-06 17:05 . 2009-11-06 17:29 -------- d-----w- c:\program files\Common Files\Nero
2009-11-03 18:27 . 2009-11-03 18:27 -------- d-----w- c:\program files\VS Revo Group
2009-11-02 15:19 . 2009-11-29 20:42 -------- d-----w- c:\users\Brigitte\AppData\Roaming\vlc
2009-11-01 15:31 . 2009-07-22 13:07 77824 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
2009-11-01 15:27 . 2009-10-05 11:34 796400 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
2009-11-01 13:32 . 2009-11-01 13:51 -------- d-----w- c:\users\Brigitte\AppData\Roaming\IDM
2009-11-01 12:20 . 2009-11-10 11:40 1730452 ----a-w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2\3558177607\Update.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-30 12:23 . 2009-09-12 12:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Orbit
2009-11-30 12:01 . 2009-09-22 16:13 4096 d-----w- c:\users\Brigitte\AppData\Roaming\uTorrent
2009-11-29 21:47 . 2009-09-06 08:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Skype
2009-11-29 21:39 . 2008-07-30 09:12 4096 d-----w- c:\program files\Yahoo!
2009-11-29 09:05 . 2009-06-25 19:00 16384 d-----w- c:\users\Brigitte\AppData\Roaming\dvdcss
2009-11-28 16:31 . 2006-11-02 15:48 684650 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-28 16:31 . 2006-11-02 15:48 130846 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-27 11:50 . 2009-05-03 14:15 15370988 ----a-w- c:\windows\system32\drivers\fidbox.idx
2009-11-27 11:50 . 2009-05-03 14:15 1147482144 ----a-w- c:\windows\system32\drivers\fidbox.dat
2009-11-26 20:47 . 2009-09-16 15:39 4096 d-----w- c:\program files\Messenger Plus! Live
2009-11-26 20:06 . 2008-07-30 13:02 4096 d-----w- c:\programdata\WLInstaller
2009-11-26 12:10 . 2009-10-09 19:10 4096 d-----w- c:\program files\Trend Micro
2009-11-25 17:06 . 2009-05-24 16:30 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Apple Computer
2009-11-23 18:52 . 2009-03-26 19:11 4096 d-----w- c:\program files\Opera
2009-11-23 17:12 . 2009-02-27 15:58 4096 d-----w- c:\programdata\NOS
2009-11-23 17:10 . 2009-09-21 15:40 4096 d-----w- c:\program files\AIMP2
2009-11-22 17:35 . 2007-08-10 07:53 12288 d-----w- c:\programdata\Microsoft Help
2009-11-22 16:33 . 2009-09-21 15:40 4096 d-----w- c:\users\Brigitte\AppData\Roaming\AIMP
2009-11-21 08:43 . 2008-08-12 11:40 6648 ----a-w- c:\users\Brigitte\AppData\Local\d3d9caps.dat
2009-11-19 19:34 . 2008-07-30 09:14 106904 ----a-w- c:\users\Brigitte\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-19 18:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-11-19 17:39 . 2007-08-10 07:56 28672 d-----w- c:\program files\Microsoft Works
2009-11-17 19:40 . 2008-12-25 09:42 -------- d-----w- c:\programdata\Media Center Programs
2009-11-16 18:14 . 2009-07-02 17:42 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-11-15 13:29 . 2008-12-29 10:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Yahoo!
2009-11-15 13:27 . 2009-02-15 10:43 -------- d-----w- c:\programdata\Yahoo!
2009-11-15 10:30 . 2008-08-14 13:00 3420 ----a-w- c:\users\Brigitte\AppData\Roaming\wklnhst.dat
2009-11-13 19:19 . 2009-09-06 08:27 -------- d-----w- c:\users\Brigitte\AppData\Roaming\skypePM
2009-11-13 16:34 . 2009-03-24 16:27 -------- d-----w- c:\programdata\TuneUp Software
2009-11-11 10:29 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-10 19:48 . 2009-09-18 17:27 4096 d-----w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2
2009-11-08 10:45 . 2009-10-24 11:32 -------- d-----w- c:\program files\Java
2009-11-07 08:09 . 2007-08-10 06:31 16384 d–h--w- c:\program files\InstallShield Installation Information
2009-11-06 17:00 . 2007-08-10 07:18 -------- d-----w- c:\program files\Common Files\NewTech Infosystems
2009-11-02 19:42 . 2009-09-26 09:54 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 13:50 . 2009-09-01 13:57 -------- d-----w- c:\users\Brigitte\AppData\Roaming\DMCache
2009-10-28 15:53 . 2009-10-28 15:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-28 15:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-28 15:52 . 2009-10-28 15:52 0 ------w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-24 14:14 . 2009-10-16 18:18 604488 ------w- c:\windows\system32\TUProgSt.exe
2009-10-24 13:39 . 2008-10-04 09:10 558640 ----a-w- c:\programdata\CyberLink\CLSetup\Download\MCEDS.exe
2009-10-23 20:35 . 2008-08-01 14:16 -------- d-----w- c:\program files\orange
2009-10-23 15:13 . 2009-10-22 15:57 -------- d-----w- c:\programdata\Messenger Plus!
2009-10-22 18:29 . 2009-10-22 18:29 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Talkback
2009-10-22 17:56 . 2009-10-22 17:56 -------- d-----w- c:\programdata\Cobian
2009-10-21 17:00 . 2009-10-21 16:59 4096 d-----w- c:\program files\BackRex Internet Explorer Backup
2009-10-21 16:50 . 2009-10-21 16:50 4096 d-----w- c:\program files\MozBackup
2009-10-21 14:07 . 2009-10-21 14:07 4096 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-16 18:16 . 2009-03-24 16:25 4096 d-sh–w- c:\programdata{55A29068-F2CE-456C-9148-C869879E2357}
2009-10-16 15:23 . 2009-10-16 15:23 -------- d–h--w- c:\program files\Common Files\Updates
2009-10-14 16:30 . 2009-08-20 16:42 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Notepad++
2009-10-13 18:14 . 2009-10-13 18:13 8192 d-----w- c:\program files\Mozilla Thunderbird
2009-10-11 03:17 . 2009-03-12 18:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 20:22 . 2009-10-10 20:22 364544 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\IsLicense40.dll
2009-10-10 20:22 . 2009-10-10 20:22 2273280 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\G-Recorder.exe
2009-10-10 20:18 . 2009-10-10 20:18 868352 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe
2009-10-10 20:18 . 2009-10-10 20:18 53760 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\zlib.dll
2009-10-10 20:18 . 2009-10-10 20:18 640000 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\dbghelp.dll
2009-10-10 20:18 . 2009-10-10 20:18 1712128 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\GdiPlus.dll
2009-10-10 16:35 . 2009-08-20 16:42 4096 d-----w- c:\program files\Notepad++
2009-10-10 10:26 . 2009-09-07 10:43 -------- d-----w- c:\program files\Foxit Software
2009-10-08 21:08 . 2009-10-28 15:44 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-10-28 15:44 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-10-28 15:44 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-08 15:56 . 2009-08-22 09:46 4096 d-----w- c:\program files\KeyScrambler
2009-10-07 17:38 . 2009-10-07 17:38 117760 ----a-w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-07 17:37 . 2009-06-29 10:53 -------- d-----w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com
2009-10-07 16:11 . 2009-06-10 18:19 4096 d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 15:46 . 2009-10-07 15:46 4096 d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-07 15:05 . 2009-10-07 15:05 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Amazon
2009-10-04 21:33 . 2009-08-22 09:46 115312 ------w- c:\windows\system32\drivers\keyscrambler.sys
2009-10-04 15:33 . 2009-09-23 16:00 4096 d-----w- c:\users\Brigitte\AppData\Roaming\HpUpdate
2009-10-04 13:45 . 2009-10-04 13:45 -------- d-----w- c:\program files\VirusTotalUploader
2009-10-04 08:35 . 2009-10-04 08:35 -------- d-----w- c:\programdata\is-9CFN4
2009-10-03 18:35 . 2009-10-03 18:35 -------- d-----w- c:\program files\COMODO
2009-10-03 17:18 . 2009-10-03 16:18 4096 d-----w- c:\program files\Free Window Registry Repair
2009-10-03 14:24 . 2009-07-01 15:01 4096 d-----w- c:\programdata\G DATA
2009-10-03 14:24 . 2009-05-18 17:34 -------- d-----w- c:\program files\Common Files\G DATA
2009-10-02 20:11 . 2009-09-12 12:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\GrabPro
2009-10-02 15:13 . 2009-07-31 15:34 -------- d-----w- c:\programdata\fssg
2009-10-02 10:38 . 2009-10-02 10:38 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-01 01:02 . 2009-10-28 15:47 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-28 15:48 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-28 15:47 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-28 15:47 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-28 15:48 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-28 15:47 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-28 15:47 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-28 15:47 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-28 15:47 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-28 15:47 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-28 15:47 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-28 15:48 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-10-28 15:47 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-10-28 15:47 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-10-28 15:47 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-10-28 15:47 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-26 19:56 . 2009-09-26 19:56 34688 ----a-w- c:\windows\system32\FM20FRA.DLL
2009-09-26 02:32 . 2009-09-26 02:32 1205080 ----a-w- c:\windows\system32\FM20.DLL
2009-09-26 02:32 . 2009-09-26 02:32 31600 ----a-w- c:\windows\system32\FM20ENU.DLL
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE~\Browser Helper Objects{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-03 20:12 556432 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-04-11 1233920]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-19 125952]
“MailNotifier”=“c:\program files\orange\MailNotifier\MailNotifier.exe” [2009-10-12 692224]
“Messenger (Yahoo!)”=“c:\program files\Yahoo!\Messenger\YahooMessenger.exe” [2009-11-10 5244216]
“msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe” [2009-11-26 3883856]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-11-28 289584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“PLFSetL”=“c:\windows\PLFSetL.exe” [2007-07-05 94208]
“Malwarebytes’ Anti-Malware”=“c:\program files\Malwarebytes’ Anti-Malware\mbamgui.exe” [2009-09-10 420176]
“MSSE”=“c:\program files\Microsoft Security Essentials\msseces.exe” [2009-09-13 1048392]
“COMODO Internet Security”=“c:\program files\COMODO\COMODO Internet Security\cfp.exe” [2009-11-17 1800464]
“BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe” [2009-09-26 83312]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“KeyScrambler”=“c:\program files\KeyScrambler\getting_started.html” [X]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-11-28 1719568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“FilterAdministratorToken”= 1 (0x1)
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux”=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=“Service”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logiciel Kodak EasyShare.lnk]
backup=c:\windows\pss\Logiciel Kodak EasyShare.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
backup=c:\windows\pss\Orbit.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 - Capture d’écran et lancement.lnk]
backup=c:\windows\pss\OneNote 2007 - Capture d’écran et lancement.lnk.Startup
backupExtension=.Startup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^WkCalRem.LNK]
backup=c:\windows\pss\WkCalRem.LNK.Startup
backupExtension=.Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“WindowsWelcomeCenter”=rundll32.exe oobefldr.dll,ShowWelcomeCenter

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“HP Software Update”=c:\program files\HP\HP Software Update\HPWuSchd2.exe
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):be,e2,88,b6,74,df,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-759318378-497761762-3404630427-1000]
“EnableNotificationsRef”=dword:0000000c

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [16/11/2009 18:53 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [16/11/2009 18:53 29520]
R1 SbFw;SbFw;c:\windows\System32\drivers\SbFw.sys [31/10/2008 06:09 270888]
R1 VBoxDrv;VirtualBox Service;c:\windows\System32\drivers\VBoxDrv.sys [20/11/2009 16:54 116560]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\System32\drivers\VBoxUSBMon.sys [20/11/2009 16:54 41424]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [08/11/2008 11:21 61424]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [10/08/2007 15:41 179712]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [10/08/2007 15:41 32256]
R3 KeyScrambler;KeyScrambler;c:\windows\System32\drivers\keyscrambler.sys [22/08/2009 10:46 115312]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2009 16:46 19160]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\System32\drivers\SbFwIm.sys [06/06/2009 12:07 65576]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\System32\drivers\VBoxNetAdp.sys [10/11/2009 14:54 95568]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\System32\drivers\VBoxNetFlt.sys [10/11/2009 14:53 104016]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes’ Anti-Malware\mbamservice.exe [07/10/2009 16:46 269648]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [31/07/2008 09:57 21504]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [29/10/2009 10:22 30603640]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18/06/2009 18:48 42480]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [26/09/2009 04:28 4639136]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [30/07/2008 11:28 28224]
S4 0267471241168295mcinstcleanup;0267471241168295mcinstcleanup; [x]
S4 gupdate;Google Update Service (gupdate); [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier ‘Tâches planifiées’

2009-11-30 c:\windows\Tasks\User_Feed_Synchronization-{55AF2E8A-EBC9-4A50-8828-434D9E33BE57}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]

2009-11-30 c:\windows\Tasks\User_Feed_Synchronization-{9E24F08E-1327-49FE-856E-F5C2AE8D8770}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = fr.yahoo.com…
    uSearchMigratedDefaultURL = search.yahoo.com…
    mWindow Title =
    IE: ?4da1a3bfcab942eab3ec3b465ef4d37d
    IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
    IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
    IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
    IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    Trusted Zone: orange.fr\logicielsgratuits
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    DPF: {4DD20514-9520-40A7-9CD6-66883643A20B} - www.boaki.com…
    DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} - logicielsgratuits.orange.fr…
    DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} - webtv.guidetv.orange.fr…
    FF - ProfilePath - c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default
    FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl3.rsa_seed_sha”, true);
.


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-11-30 13:24
Windows 6.0.6002 Service Pack 2 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
“ImagePath”="??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\acer\Empowering Technology\ePower\ePowerSvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\users\Brigitte\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\windows\servicing\TrustedInstaller.exe
.


.
Heure de fin: 2009-11-30 13:35 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-11-30 12:34
ComboFix2.txt 2009-11-29 11:10
ComboFix3.txt 2009-11-28 17:35

Avant-CF: 25 375 416 320 octets libres
Après-CF: 25 118 306 304 octets libres

    • End Of File - - CBC7A78E98097AEA4C1D76F6DEE02627

ComboFix 09-11-30.05 - Brigitte 01/12/2009 12:59.5.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2037.1100 [GMT 1:00]
Lancé depuis: c:\users\Brigitte\Desktop\poisson.exe
Commutateurs utilisés :: c:\users\Brigitte\Desktop\CFScript.txt
SP: SUPERAntiSpyware disabled (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
“c:\programdata\is-9CFN4~PRCustomProps#122.dat”
“c:\programdata\is-9CFN4~Projections#122.dat”
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\is-9CFN4
c:\programdata\is-9CFN4~PRCustomProps#122.dat
c:\programdata\is-9CFN4~PRObjects#122.dat

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-01 au 2009-12-01 ))))))))))))))))))))))))))))))))))))
.

2009-12-01 12:13 . 2009-12-01 12:13 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2009-12-01 12:13 . 2009-12-01 12:13 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-01 12:13 . 2009-12-01 12:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-30 12:02 . 2009-11-30 12:35 45056 d-----w- C:\poisson28617p
2009-11-29 11:56 . 2009-11-29 11:56 -------- d-----w- c:\program files\WOT
2009-11-29 10:57 . 2009-12-01 12:15 12288 d-----w- c:\users\Brigitte\AppData\Local\temp
2009-11-29 10:38 . 2009-11-29 11:10 -------- d-----w- C:\poisson17870p
2009-11-29 09:49 . 2009-11-29 09:51 -------- d-----w- c:\program files\Windows Live Safety Center
2009-11-29 09:18 . 2009-11-29 09:18 90112 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy{CF49C79A-50A0-B13D-0DB8-0067D6A7ED5F}-winfile.dll
2009-11-28 18:40 . 2009-11-28 18:40 -------- d-----w- c:\program files\SuperCopier2
2009-11-28 18:36 . 2009-11-28 18:36 -------- d-----w- c:\users\Brigitte\AppData\Roaming\TeraCopy
2009-11-28 17:59 . 2009-11-28 17:59 -------- d-----w- c:\program files\uTorrent
2009-11-28 17:07 . 2009-11-28 17:35 -------- d-----w- C:\poisson
2009-11-28 08:47 . 2009-11-28 08:48 4096 d-----w- c:\program files\Orbitdownloader
2009-11-27 12:17 . 2009-11-27 12:17 171552 ----a-w- c:\windows\system32\guard32.dll
2009-11-27 12:17 . 2009-11-27 17:59 -------- d-----w- C:\UsbFix
2009-11-26 20:47 . 2009-11-26 20:48 -------- d-----w- c:\programdata\MessengerDiscovery 2
2009-11-26 20:47 . 2009-11-26 20:47 4096 d-----w- c:\program files\MessengerDiscovery 2
2009-11-25 18:42 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 14:22 . 2009-11-25 14:22 -------- d-----w- c:\program files\FileHippo.com
2009-11-25 13:53 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-25 13:53 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-25 13:51 . 2009-11-25 13:52 -------- d-----w- c:\programdata{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-25 11:52 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 11:52 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-23 17:05 . 2009-11-23 17:07 4096 d-----w- c:\program files\7-Zip
2009-11-22 13:03 . 2009-11-22 13:04 4096 d-----w- c:\program files\ImgBurn
2009-11-20 19:22 . 2009-11-20 19:22 -------- d-----w- c:\program files\Recuva
2009-11-20 15:58 . 2009-11-30 17:22 -------- d-----w- c:\users\Brigitte.VirtualBox
2009-11-20 15:54 . 2009-11-10 13:54 116560 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-11-20 15:54 . 2009-11-10 13:53 41424 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-11-20 15:53 . 2009-11-20 15:53 -------- d-----w- c:\program files\Sun
2009-11-19 18:15 . 2009-11-19 18:15 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-11-19 18:10 . 2009-11-19 18:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-19 18:05 . 2009-11-19 18:05 -------- d-----w- c:\program files\Microsoft Analysis Services
2009-11-19 18:03 . 2009-11-19 18:03 -------- d-----r- C:\MSOCache
2009-11-18 19:27 . 2009-11-19 12:28 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Download Manager
2009-11-18 19:05 . 2009-11-26 20:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-18 19:03 . 2009-11-26 20:43 4096 d-----w- c:\program files\Windows Live
2009-11-18 15:28 . 2009-11-18 15:28 -------- d-----w- c:\program files\Gibcom
2009-11-17 19:18 . 2009-11-17 19:20 -------- d-----w- c:\program files\Ubisoft
2009-11-17 16:12 . 2009-11-17 16:12 25214 ----a-r- c:\users\Brigitte\AppData\Roaming\Microsoft\Installer{4103778F-5EAF-476E-B3C1-2891EF9A4D8C}\controlPanelIcon.exe
2009-11-17 16:11 . 2009-11-17 16:12 4096 d-----w- c:\program files\Kptic Neonumeric
2009-11-17 11:52 . 2009-11-17 11:52 -------- d-----w- c:\programdata\F-Secure
2009-11-16 20:31 . 2009-11-16 20:41 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Kptic
2009-11-16 17:53 . 2009-11-16 17:54 4096 d-----w- c:\program files\Microsoft Security Essentials
2009-11-16 17:53 . 2009-11-16 18:12 -------- d-----w- c:\programdata\Comodo
2009-11-16 17:53 . 2009-11-25 11:50 128376 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-16 17:53 . 2009-11-17 12:11 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-11-16 17:53 . 2009-11-17 12:11 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-15 14:17 . 2009-11-15 14:17 -------- d-----w- c:\program files\Defraggler
2009-11-15 13:27 . 2009-11-10 14:50 607544 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-13 15:29 . 2009-11-13 15:29 -------- d-sh–w- c:\programdata{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-11-12 21:13 . 2009-11-26 12:33 -------- d-----w- c:\program files\QuickTime
2009-11-12 12:19 . 2009-11-12 12:19 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Auslogics
2009-11-11 10:43 . 2009-11-11 10:43 653560 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-11 10:17 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 10:17 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-11 10:00 . 2009-11-11 10:00 20480 d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2009-11-11 09:52 . 2009-11-11 09:52 -------- d-----w- c:\users\Brigitte\AppData\Roaming\HouseCall 6.6
2009-11-10 13:54 . 2009-11-10 13:54 95568 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-10 13:54 . 2009-11-10 13:54 133648 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2009-11-10 13:53 . 2009-11-10 13:53 104016 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2009-11-09 18:15 . 2009-11-08 13:46 86016 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
2009-11-08 16:53 . 2009-11-08 16:53 -------- d–h--w- c:\users\Brigitte\784E6B0F00EC495095A2BBA64F44EC48.TMP
2009-11-08 13:32 . 2009-11-08 13:32 -------- d-----w- c:\users\Brigitte\AppData\Local\TechSmith
2009-11-08 13:31 . 2009-11-11 12:11 -------- d-----w- c:\programdata\TechSmith
2009-11-08 13:31 . 2009-11-08 13:31 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-11-08 13:31 . 2009-11-09 18:46 -------- d-----w- c:\program files\TechSmith
2009-11-08 09:37 . 2005-03-11 17:37 1986560 ----a-w- c:\windows\system32\AudFile.dll
2009-11-08 09:37 . 2005-02-24 12:11 1212416 ----a-w- c:\windows\system32\AudioInfos.dll
2009-11-08 09:37 . 2005-02-24 11:51 348160 ----a-w- c:\windows\system32\WMAFile.dll
2009-11-08 09:37 . 2003-01-26 11:41 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2009-11-08 09:37 . 1998-07-12 21:00 15360 ----a-w- c:\windows\system32\inetfr.DLL
2009-11-07 19:47 . 2009-11-07 19:48 4096 d-----w- c:\program files\SRWare Iron
2009-11-07 09:27 . 2009-11-07 09:27 -------- d-----w- c:\program files\Lavalys
2009-11-06 21:32 . 2009-11-07 19:42 1 ----a-w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-06 21:32 . 2009-11-06 21:32 -------- d-----w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org
2009-11-06 21:22 . 2009-11-06 21:22 -------- d-----w- c:\program files\JRE
2009-11-06 21:22 . 2009-11-06 21:22 4096 d-----w- c:\program files\OpenOffice.org 3
2009-11-06 20:48 . 2009-11-06 20:50 4096 d-----w- c:\program files\PhotoFiltre
2009-11-06 17:38 . 2009-11-06 17:38 -------- d-----w- c:\users\Brigitte\AppData\Roaming\ImgBurn
2009-11-06 17:12 . 2009-11-06 17:12 -------- d-----w- c:\programdata\LightScribe
2009-11-06 17:10 . 2009-11-06 17:12 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Nero
2009-11-06 17:05 . 2009-11-06 17:28 -------- d-----w- c:\programdata\Nero
2009-11-06 17:05 . 2009-11-06 17:29 -------- d-----w- c:\program files\Common Files\Nero
2009-11-03 18:27 . 2009-11-03 18:27 -------- d-----w- c:\program files\VS Revo Group
2009-11-02 15:19 . 2009-11-30 17:11 -------- d-----w- c:\users\Brigitte\AppData\Roaming\vlc
2009-11-01 15:31 . 2009-07-22 13:07 77824 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
2009-11-01 15:27 . 2009-10-05 11:34 796400 ----a-w- c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
2009-11-01 13:32 . 2009-11-01 13:51 -------- d-----w- c:\users\Brigitte\AppData\Roaming\IDM
2009-11-01 12:20 . 2009-11-10 11:40 1730452 ----a-w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2\3558177607\Update.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-01 12:16 . 2009-09-12 12:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Orbit
2009-12-01 11:54 . 2009-09-06 08:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Skype
2009-12-01 11:50 . 2009-09-22 16:13 4096 d-----w- c:\users\Brigitte\AppData\Roaming\uTorrent
2009-11-30 12:56 . 2006-11-02 15:48 684650 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-30 12:56 . 2006-11-02 15:48 130846 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-29 21:39 . 2008-07-30 09:12 4096 d-----w- c:\program files\Yahoo!
2009-11-29 09:05 . 2009-06-25 19:00 16384 d-----w- c:\users\Brigitte\AppData\Roaming\dvdcss
2009-11-27 11:50 . 2009-05-03 14:15 15370988 ----a-w- c:\windows\system32\drivers\fidbox.idx
2009-11-27 11:50 . 2009-05-03 14:15 1147482144 ----a-w- c:\windows\system32\drivers\fidbox.dat
2009-11-26 20:47 . 2009-09-16 15:39 4096 d-----w- c:\program files\Messenger Plus! Live
2009-11-26 20:06 . 2008-07-30 13:02 4096 d-----w- c:\programdata\WLInstaller
2009-11-26 12:10 . 2009-10-09 19:10 4096 d-----w- c:\program files\Trend Micro
2009-11-25 17:06 . 2009-05-24 16:30 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Apple Computer
2009-11-23 18:52 . 2009-03-26 19:11 4096 d-----w- c:\program files\Opera
2009-11-23 17:12 . 2009-02-27 15:58 4096 d-----w- c:\programdata\NOS
2009-11-23 17:10 . 2009-09-21 15:40 4096 d-----w- c:\program files\AIMP2
2009-11-22 17:35 . 2007-08-10 07:53 12288 d-----w- c:\programdata\Microsoft Help
2009-11-22 16:33 . 2009-09-21 15:40 4096 d-----w- c:\users\Brigitte\AppData\Roaming\AIMP
2009-11-21 08:43 . 2008-08-12 11:40 6648 ----a-w- c:\users\Brigitte\AppData\Local\d3d9caps.dat
2009-11-19 19:34 . 2008-07-30 09:14 106904 ----a-w- c:\users\Brigitte\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-19 18:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-11-19 17:39 . 2007-08-10 07:56 28672 d-----w- c:\program files\Microsoft Works
2009-11-17 19:40 . 2008-12-25 09:42 -------- d-----w- c:\programdata\Media Center Programs
2009-11-16 18:14 . 2009-07-02 17:42 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-11-15 13:29 . 2008-12-29 10:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Yahoo!
2009-11-15 13:27 . 2009-02-15 10:43 -------- d-----w- c:\programdata\Yahoo!
2009-11-15 10:30 . 2008-08-14 13:00 3420 ----a-w- c:\users\Brigitte\AppData\Roaming\wklnhst.dat
2009-11-13 19:19 . 2009-09-06 08:27 -------- d-----w- c:\users\Brigitte\AppData\Roaming\skypePM
2009-11-13 16:34 . 2009-03-24 16:27 -------- d-----w- c:\programdata\TuneUp Software
2009-11-11 10:29 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-10 19:48 . 2009-09-18 17:27 4096 d-----w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2
2009-11-08 10:45 . 2009-10-24 11:32 -------- d-----w- c:\program files\Java
2009-11-07 08:09 . 2007-08-10 06:31 16384 d–h--w- c:\program files\InstallShield Installation Information
2009-11-06 17:00 . 2007-08-10 07:18 -------- d-----w- c:\program files\Common Files\NewTech Infosystems
2009-11-02 19:42 . 2009-09-26 09:54 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 13:50 . 2009-09-01 13:57 -------- d-----w- c:\users\Brigitte\AppData\Roaming\DMCache
2009-10-28 15:53 . 2009-10-28 15:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-28 15:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-28 15:52 . 2009-10-28 15:52 0 ------w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-24 14:14 . 2009-10-16 18:18 604488 ------w- c:\windows\system32\TUProgSt.exe
2009-10-24 13:39 . 2008-10-04 09:10 558640 ----a-w- c:\programdata\CyberLink\CLSetup\Download\MCEDS.exe
2009-10-23 20:35 . 2008-08-01 14:16 -------- d-----w- c:\program files\orange
2009-10-23 15:13 . 2009-10-22 15:57 -------- d-----w- c:\programdata\Messenger Plus!
2009-10-22 18:29 . 2009-10-22 18:29 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Talkback
2009-10-22 17:56 . 2009-10-22 17:56 -------- d-----w- c:\programdata\Cobian
2009-10-21 17:00 . 2009-10-21 16:59 4096 d-----w- c:\program files\BackRex Internet Explorer Backup
2009-10-21 16:50 . 2009-10-21 16:50 4096 d-----w- c:\program files\MozBackup
2009-10-21 14:07 . 2009-10-21 14:07 4096 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-16 18:16 . 2009-03-24 16:25 4096 d-sh–w- c:\programdata{55A29068-F2CE-456C-9148-C869879E2357}
2009-10-16 15:23 . 2009-10-16 15:23 -------- d–h--w- c:\program files\Common Files\Updates
2009-10-14 16:30 . 2009-08-20 16:42 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Notepad++
2009-10-13 18:14 . 2009-10-13 18:13 8192 d-----w- c:\program files\Mozilla Thunderbird
2009-10-11 03:17 . 2009-03-12 18:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 20:22 . 2009-10-10 20:22 364544 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\IsLicense40.dll
2009-10-10 20:22 . 2009-10-10 20:22 2273280 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\G-Recorder.exe
2009-10-10 20:18 . 2009-10-10 20:18 868352 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe
2009-10-10 20:18 . 2009-10-10 20:18 53760 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\zlib.dll
2009-10-10 20:18 . 2009-10-10 20:18 640000 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\dbghelp.dll
2009-10-10 20:18 . 2009-10-10 20:18 1712128 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\GdiPlus.dll
2009-10-10 16:35 . 2009-08-20 16:42 4096 d-----w- c:\program files\Notepad++
2009-10-10 10:26 . 2009-09-07 10:43 -------- d-----w- c:\program files\Foxit Software
2009-10-08 21:08 . 2009-10-28 15:44 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-10-28 15:44 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-10-28 15:44 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-08 15:56 . 2009-08-22 09:46 4096 d-----w- c:\program files\KeyScrambler
2009-10-07 17:38 . 2009-10-07 17:38 117760 ----a-w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-07 17:37 . 2009-06-29 10:53 -------- d-----w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com
2009-10-07 16:11 . 2009-06-10 18:19 4096 d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 15:46 . 2009-10-07 15:46 4096 d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-07 15:05 . 2009-10-07 15:05 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Amazon
2009-10-04 21:33 . 2009-08-22 09:46 115312 ------w- c:\windows\system32\drivers\keyscrambler.sys
2009-10-04 15:33 . 2009-09-23 16:00 4096 d-----w- c:\users\Brigitte\AppData\Roaming\HpUpdate
2009-10-04 13:45 . 2009-10-04 13:45 -------- d-----w- c:\program files\VirusTotalUploader
2009-10-03 18:35 . 2009-10-03 18:35 -------- d-----w- c:\program files\COMODO
2009-10-03 17:18 . 2009-10-03 16:18 4096 d-----w- c:\program files\Free Window Registry Repair
2009-10-03 14:24 . 2009-07-01 15:01 4096 d-----w- c:\programdata\G DATA
2009-10-03 14:24 . 2009-05-18 17:34 -------- d-----w- c:\program files\Common Files\G DATA
2009-10-02 20:11 . 2009-09-12 12:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\GrabPro
2009-10-02 15:13 . 2009-07-31 15:34 -------- d-----w- c:\programdata\fssg
2009-10-01 01:02 . 2009-10-28 15:47 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-28 15:48 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-28 15:47 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-28 15:47 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-28 15:48 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-28 15:47 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-28 15:47 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-28 15:47 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-28 15:47 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-28 15:47 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-28 15:47 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-28 15:48 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-10-28 15:47 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-10-28 15:47 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-10-28 15:47 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-10-28 15:47 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-26 19:56 . 2009-09-26 19:56 34688 ----a-w- c:\windows\system32\FM20FRA.DLL
2009-09-26 02:32 . 2009-09-26 02:32 1205080 ----a-w- c:\windows\system32\FM20.DLL
2009-09-26 02:32 . 2009-09-26 02:32 31600 ----a-w- c:\windows\system32\FM20ENU.DLL
2009-09-25 02:10 . 2009-10-28 15:49 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-10-28 15:49 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE~\Browser Helper Objects{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-03 20:12 556432 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-04-11 1233920]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-19 125952]
“MailNotifier”=“c:\program files\orange\MailNotifier\MailNotifier.exe” [2009-10-12 692224]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-11-28 289584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“PLFSetL”=“c:\windows\PLFSetL.exe” [2007-07-05 94208]
“Malwarebytes’ Anti-Malware”=“c:\program files\Malwarebytes’ Anti-Malware\mbamgui.exe” [2009-09-10 420176]
“MSSE”=“c:\program files\Microsoft Security Essentials\msseces.exe” [2009-09-13 1048392]
“COMODO Internet Security”=“c:\program files\COMODO\COMODO Internet Security\cfp.exe” [2009-11-17 1800464]
“BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe” [2009-09-26 83312]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“KeyScrambler”=“c:\program files\KeyScrambler\getting_started.html” [X]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-11-28 1719568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“FilterAdministratorToken”= 1 (0x1)
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux”=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=“Service”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logiciel Kodak EasyShare.lnk]
backup=c:\windows\pss\Logiciel Kodak EasyShare.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
backup=c:\windows\pss\Orbit.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 - Capture d’écran et lancement.lnk]
backup=c:\windows\pss\OneNote 2007 - Capture d’écran et lancement.lnk.Startup
backupExtension=.Startup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^WkCalRem.LNK]
backup=c:\windows\pss\WkCalRem.LNK.Startup
backupExtension=.Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“WindowsWelcomeCenter”=rundll32.exe oobefldr.dll,ShowWelcomeCenter

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“HP Software Update”=c:\program files\HP\HP Software Update\HPWuSchd2.exe
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):be,e2,88,b6,74,df,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-759318378-497761762-3404630427-1000]
“EnableNotificationsRef”=dword:0000000c

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [16/11/2009 18:53 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [16/11/2009 18:53 29520]
R1 SbFw;SbFw;c:\windows\System32\drivers\SbFw.sys [31/10/2008 06:09 270888]
R1 VBoxDrv;VirtualBox Service;c:\windows\System32\drivers\VBoxDrv.sys [20/11/2009 16:54 116560]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\System32\drivers\VBoxUSBMon.sys [20/11/2009 16:54 41424]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [08/11/2008 11:21 61424]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [10/08/2007 15:41 179712]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [10/08/2007 15:41 32256]
R3 KeyScrambler;KeyScrambler;c:\windows\System32\drivers\keyscrambler.sys [22/08/2009 10:46 115312]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2009 16:46 19160]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\System32\drivers\SbFwIm.sys [06/06/2009 12:07 65576]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\System32\drivers\VBoxNetAdp.sys [10/11/2009 14:54 95568]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\System32\drivers\VBoxNetFlt.sys [10/11/2009 14:53 104016]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes’ Anti-Malware\mbamservice.exe [07/10/2009 16:46 269648]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [31/07/2008 09:57 21504]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [29/10/2009 10:22 30603640]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18/06/2009 18:48 42480]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [26/09/2009 04:28 4639136]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [30/07/2008 11:28 28224]
S4 0267471241168295mcinstcleanup;0267471241168295mcinstcleanup; [x]
S4 gupdate;Google Update Service (gupdate); [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier ‘Tâches planifiées’

2009-12-01 c:\windows\Tasks\User_Feed_Synchronization-{55AF2E8A-EBC9-4A50-8828-434D9E33BE57}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]

2009-12-01 c:\windows\Tasks\User_Feed_Synchronization-{9E24F08E-1327-49FE-856E-F5C2AE8D8770}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = fr.yahoo.com…
    uSearchMigratedDefaultURL = search.yahoo.com…
    mWindow Title =
    IE: ?4da1a3bfcab942eab3ec3b465ef4d37d
    IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
    IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
    IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
    IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    Trusted Zone: orange.fr\logicielsgratuits
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    DPF: {4DD20514-9520-40A7-9CD6-66883643A20B} - www.boaki.com…
    DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} - logicielsgratuits.orange.fr…
    DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} - webtv.guidetv.orange.fr…
    FF - ProfilePath - c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default
    FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\firegpg@firegpg.team\platform\WINNT_x86-msvc\components\ipc.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
    FF - component: c:\users\Brigitte\AppData\Roaming\Mozilla\Firefox\Profiles\5vuwsbyk.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\MICROS~2\Office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl3.rsa_seed_sha”, true);
.


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-12-01 13:16
Windows 6.0.6002 Service Pack 2 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
“ImagePath”="??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\acer\Empowering Technology\ePower\ePowerSvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\users\Brigitte\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.


Comme vas mon PC maintenant Docteur Jean ?

Regarde un virus a été détecter :

[Photo supprimée]

Pour l’instant ca marche . Je suis plus infecter ? C’est sur à 100 % ?

Oh nn oh nn !!

Sa m’énerve.

Sa recommence sa bug partout.

Help Jean.

@++

04/12/2009 ---- 21:33:29,73


§§§§§§ [firefox] §§§§§§

[X] Registre
[ ] Fichier (rapide)
[ ] Fichier (disque systeme)
[X] Fichier (complete)


 [Registre] 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML\DefaultIcon]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML\DefaultIcon]
@=“C:\Program Files\Mozilla Firefox\firefox.exe,1”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\firefox.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared\HTML]
“KnownIDs”=“FirefoxHTML”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9678DCFC4BEC0C94981A31BE297E47D6\471FC3EAC2786C649B6F0C95F3B37C8B]
“File”=“FFirefoxPluginDll”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-759318378-497761762-3404630427-1000\Products\6BBFDF96D153C8B4988D68D79C0D2A4A\InstallProperties]
“DisplayName”=“Windows Media Player Firefox Plugin”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com\www]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Orbit_is1]
“Inno Setup: Deselected Tasks”=“firefox\no,maxthon\no”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}]
“DisplayName”=“Windows Media Player Firefox Plugin”

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.2 (fr)]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.2 (fr)\Main]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.2 (fr)\Uninstall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.2 (fr)\Uninstall]
“Description”=“Mozilla Firefox (3.5.2)”

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.3 (fr)]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.3 (fr)\Main]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.3 (fr)\Uninstall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.5.3 (fr)\Uninstall]
“Description”=“Mozilla Firefox (3.5.3)”

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.6b1 (fr)]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.6b1 (fr)\Main]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.6b1 (fr)\Uninstall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\3.6b1 (fr)\Uninstall]
“Description”=“Mozilla Firefox (3.6b1)”

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.5.2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.5.2\bin]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.5.2\extensions]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.5.3]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.5.3\bin]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.5.3\extensions]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.6b1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.6b1\bin]

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.6b1\extensions]

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins@microsoft.com/OfficeLive,version=1.3]
“ProductName”=“Microsoft Office Live Plug-in for Firefox”

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins@microsoft.com/OfficeLive,version=1.4]
“ProductName”=“Microsoft Office Live Plug-in for Firefox”

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins@microsoft.com/SharePoint,version=14.0]
“Description”=“Microsoft SharePoint Plug-in for Firefox”

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins@microsoft.com/SharePoint,version=14.0]
“ProductName”=“Microsoft SharePoint Plug-in for Firefox”

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins@microsoft.com/SharePoint,version=14.0\MimeTypes\application/x-sharepoint]
“Description”=“Microsoft SharePoint Plug-in for Firefox”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“TCP Query User{865DF9ED-DCAB-4658-85B0-53DAB53E40D0}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“UDP Query User{1B85B1B6-E930-4F4B-87D4-24E7C30D7866}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“TCP Query User{85712156-4BBC-4D2C-BC82-AE50A88ED03E}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“UDP Query User{09CF1E4B-28B0-4320-84EF-C7FF11C4FD31}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“TCP Query User{865DF9ED-DCAB-4658-85B0-53DAB53E40D0}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“UDP Query User{1B85B1B6-E930-4F4B-87D4-24E7C30D7866}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“TCP Query User{85712156-4BBC-4D2C-BC82-AE50A88ED03E}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“UDP Query User{09CF1E4B-28B0-4320-84EF-C7FF11C4FD31}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\Firewall\Policy\36]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\Firewall\Policy\36]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\Firewall\Policy\9]
“Filename”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\Firewall\Policy\9]
“DeviceName”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\166\Rules\0\Allowed\10]
“Filename”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\166\Rules\0\Allowed\10]
“DeviceName”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\166\Rules\0\Allowed\13]
“Filename”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\166\Rules\0\Allowed\13]
“DeviceName”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\166\Rules\0\Allowed\3]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\166\Rules\0\Allowed\3]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\167\Rules\0\Allowed\10]
“Filename”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\167\Rules\0\Allowed\10]
“DeviceName”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\167\Rules\0\Allowed\13]
“Filename”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\167\Rules\0\Allowed\13]
“DeviceName”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\167\Rules\0\Allowed\3]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\167\Rules\0\Allowed\3]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\168\Rules\0\Allowed\10]
“Filename”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\168\Rules\0\Allowed\10]
“DeviceName”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\168\Rules\0\Allowed\13]
“Filename”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\168\Rules\0\Allowed\13]
“DeviceName”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\168\Rules\0\Allowed\3]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\168\Rules\0\Allowed\3]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169\Rules\0\Allowed\10]
“Filename”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169\Rules\0\Allowed\10]
“DeviceName”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169\Rules\0\Allowed\13]
“Filename”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169\Rules\0\Allowed\13]
“DeviceName”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169\Rules\0\Allowed\3]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\169\Rules\0\Allowed\3]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\170\Rules\0\Allowed\1]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\170\Rules\0\Allowed\1]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\182]
“Filename”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\182]
“DeviceName”=“C:\Program Files\Mozilla Firefox\uninstall\helper.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\182\Rules\0\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\uninstall\uninstaller.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\182\Rules\0\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\uninstall\uninstaller.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\188\Rules\13\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\188\Rules\13\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\189\Rules\13\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\189\Rules\13\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\190\Rules\13\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\190\Rules\13\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\191]
“Filename”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\191]
“DeviceName”=“C:\Program Files\Mozilla Firefox\crashreporter.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\191\Rules\13\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\191\Rules\13\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\20\Rules\0\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\20\Rules\0\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\48\Rules\14\Allowed\4]
“Filename”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\48\Rules\14\Allowed\4]
“DeviceName”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\49\Rules\14\Allowed\4]
“Filename”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\49\Rules\14\Allowed\4]
“DeviceName”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\50\Rules\14\Allowed\4]
“Filename”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\50\Rules\14\Allowed\4]
“DeviceName”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\51\Rules\14\Allowed\4]
“Filename”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\51\Rules\14\Allowed\4]
“DeviceName”=“C:\PROGRAM FILES\MOZILLA FIREFOX\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\68\Rules\0\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\68\Rules\0\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\77\Rules\0\Allowed\0]
“Filename”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo\Firewall Pro\Configurations\0\HIPS\Policy\77\Rules\0\Allowed\0]
“DeviceName”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“TCP Query User{865DF9ED-DCAB-4658-85B0-53DAB53E40D0}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“UDP Query User{1B85B1B6-E930-4F4B-87D4-24E7C30D7866}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“TCP Query User{85712156-4BBC-4D2C-BC82-AE50A88ED03E}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“UDP Query User{09CF1E4B-28B0-4320-84EF-C7FF11C4FD31}C:\program files\mozilla firefox\firefox.exe”=“v2.0|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files\mozilla firefox\firefox.exe|Name=Firefox|Desc=Firefox|Edge=FALSE|”

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\firefoxdownload-now.com]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\firefoxdownload-now.com\www]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com\www]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Clients\StartmenuInternet]
@=“FIREFOX.EXE”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\DownloadManager\IDMBI\firefox]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\DownloadManager\IDMBI\firefox]
“name”=“Mozilla Firefox”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\DownloadManager\IDMBI\firefox\0]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\DownloadManager\IDMBI\firefox\0]
“exe”=“C:\Program Files\Mozilla Firefox\firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Foxit Software\Foxit Reader\Updates List\Firefox Plugin]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Foxit Software\Foxit Reader\Updates List\Firefox Plugin]
“SetupPath1”=“C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Foxit Software\Foxit Reader\Updates List\Firefox Plugin]
“Name”=“Firefox Plugin”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Installer\Products\6BBFDF96D153C8B4988D68D79C0D2A4A]
“ProductName”=“Windows Media Player Firefox Plugin”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Installer\Products\6BBFDF96D153C8B4988D68D79C0D2A4A\SourceList\Media]
“DiskPrompt”=“Windows Media Player Firefox Plugin Installation”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\2bc36515_0]
@="{0.0.0.00000000}.{f623c16a-731c-4b57-8994-feda41dd7e76}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox 3.1 Beta 3\firefox.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\54b32774_0]
@="{0.0.0.00000000}.{f623c16a-731c-4b57-8994-feda41dd7e76}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox\firefox.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bb89107a_0]
@="{0.0.0.00000000}.{f623c16a-731c-4b57-8994-feda41dd7e76}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox rc 1\firefox.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\ce257227_0]
@="{0.0.0.00000000}.{f623c16a-731c-4b57-8994-feda41dd7e76}|\Device\HarddiskVolume3\firefox.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\d337311a_0]
@="{0.0.0.00000000}.{f623c16a-731c-4b57-8994-feda41dd7e76}|\Device\HarddiskVolume2\Program Files\Mozilla Firefox 3.5 Beta 4\firefox.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (3.6b1)]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.A\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.aspx\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.avi\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.cab\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.dll\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.doc\OpenWithList]
“c”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.egisenc\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.flv\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.gadget\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.gif\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.gz\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.htm\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.htm\OpenWithProgids]
“FirefoxHTML”=hex(0):

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.htm\UserChoice]
“Progid”=“FirefoxHTML”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.html\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.html\OpenWithProgids]
“FirefoxHTML”=hex(0):

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.html\UserChoice]
“Progid”=“FirefoxHTML”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.jpg\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.lnk\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.md2s\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.MOV\OpenWithList]
“c”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mp3\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mp4\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.msu\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.pdf\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.pdf_\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.plsk\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.png\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.ppt\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.rar\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.shtml\OpenWithProgids]
“FirefoxHTML”=hex(0):

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.shtml\UserChoice]
“Progid”=“FirefoxHTML”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.tar\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.torrent\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.txt\OpenWithList]
“d”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.url\OpenWithList]
“a”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.wmv\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.wps\OpenWithList]
“c”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.xht\UserChoice]
“Progid”=“FirefoxHTML”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.xhtml\UserChoice]
“Progid”=“FirefoxHTML”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.xls\OpenWithList]
“c”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.zip\OpenWithList]
“b”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Firefox]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Firefox\WWW_OpenURL]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\Firefox\WWW_OpenURL]
“ProcessName”=“firefox.exe”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com\www]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice]
“Progid”=“FirefoxURL”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice]
“Progid”=“FirefoxURL”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice]
“Progid”=“FirefoxURL”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Mozilla\Firefox]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Mozilla\Firefox\Crash Reporter]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Orange\DesktopSearch]
“InstallFirefoxToolbar”=dword:00000000

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Classes\CLSID{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Classes\CLSID{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML\DefaultIcon]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
“C:\Program Files\Mozilla Firefox\firefox.exe”=“Firefox”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
“C:\Program Files\Mozilla Firefox\crashreporter.exe”=“crashreporter”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000_Classes\CLSID{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000_Classes\CLSID{42042206-2D85-11D3-8CFF-005004838597}\Old Icon\FirefoxHTML\DefaultIcon]

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
“C:\Program Files\Mozilla Firefox\firefox.exe”=“Firefox”

[HKEY_USERS\S-1-5-21-759318378-497761762-3404630427-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
“C:\Program Files\Mozilla Firefox\crashreporter.exe”=“crashreporter”

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\firefoxdownload-now.com]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\firefoxdownload-now.com\www]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\firefoxdownload-now.com\www]


 [Fichier] 

c:\Users\Brigitte\AppData\Local\Mozilla\Firefox
c:\Users\Brigitte\AppData\Roaming\Mozilla\Firefox
c:\Users\Brigitte\AppData\Local\Mozilla\Firefox
c:\Users\Brigitte\AppData\Roaming\Mozilla\Firefox
c:\Users\Brigitte\AppData\Roaming\Skype\Pictures\firefox.jpg
c:\Users\Brigitte\Pictures\T?l?chargement Internet\firefox.jpg
c:\Windows\Prefetch\FIREFOX.EXE-A606B53C.pf
d:\A coller\FirefoxPortable\App\Firefox
d:\A coller\FirefoxPortable\App\Firefox
d:\A coller\FirefoxPortable\App\Firefox\firefox.exe
d:\A coller\FirefoxPortable\App\Firefox\defaults\pref\firefox.js


 [Même date] 

C:\pagefile.sys
C:\Windows
C:\Windows.
C:\Windows…
C:\Windows\bootstat.dat
C:\Windows\is-6GLCO.exe
C:\Windows\is-6GLCO.lst
C:\Windows\is-6GLCO.msg
C:\Windows\Prefetch
C:\Windows\Temp
C:\Windows\WindowsUpdate.log
C:\Windows\system32\msv1_0.dll
C:\Windows\system32\UIAnimation.dll
C:\Windows\system32\UIRibbon.dll
C:\Windows\system32\UIRibbonRes.dll
C:\Windows\system32\unregmp2.exe
C:\Windows\system32\wmp.dll
C:\Windows\system32\wmploc.DLL
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
C:\Windows\system32\drivers
C:\Windows\system32\drivers.
C:\Windows\system32\drivers…


§§§§§ Fin Rapport §§§§§

Oui je l’ais.

Tien un rapport :

info.txt logfile of random’s system information tool 1.06 2009-12-05 10:17:31

======Uninstall list======

–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{A450831D-25F6-4F42-9662-D000B25E0D82}\setup.exe” -uninstall
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{AA4BF92B-2AAF-11DA-9D78-000129760D75}\setup.exe” -uninstall
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{B145EC69-66F5-11D8-9D75-000129760D75}\setup.exe” -uninstall
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{B804C424-B66D-447A-84BD-C6B88C392C3A}\setup.exe” -uninstall
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{F79A208D-D929-11D9-9D77-000129760D75}\setup.exe” -uninstall
µTorrent–>“C:\Program Files\uTorrent\uTorrent.exe” /UNINSTALL
32 Bit HP CIO Components Installer–>MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
7-Zip 4.65–>“C:\Program Files\7-Zip\Uninstall.exe”
Acer Arcade Deluxe–>C:\Program Files\InstallShield Installation Information{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\Setup.exe -uninstall
Acer Crystal Eye Webcam Video Class Camera -->C:\Program Files\InstallShield Installation Information{399C37FB-08AF-493B-BFED-20FBD85EDF7F}\setup.exe -runfromtemp -l0x040c -removeonly -u
Acer Crystal Eye webcam–>C:\Program Files\InstallShield Installation Information{AA047D7C-5E7C-4878-B75C-77589151B563}\setup.exe -runfromtemp -l0x0009 -removeonly
Acer eAudio Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{57265292-228A-41FA-9AEC-4620CBCC2739}\Setup.exe” -uninstall
Acer eDataSecurity Management–>C:\Acer\Empowering Technology\eDataSecurity\eDSnstHelper.exe -Operation UNINSTALL
Acer eLock Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}\setup.exe” -l0x40c -removeonly
Acer Empowering Technology–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe” -l0x40c -removeonly
Acer eNet Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{C06554A1-2C1E-4D20-B613-EE62C79927CC}\setup.exe” -l0x40c -removeonly
Acer ePower Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{58E5844B-7CE2-413D-83D1-99294BF6C74F}\setup.exe” -l0x40c -removeonly
Acer ePresentation Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{BF839132-BD43-4056-ACBF-4377F4A88E2A}\setup.exe” -l0x40c -removeonly
Acer eSettings Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CE65A9A0-9686-45C6-9098-3C9543A412F0}\setup.exe” -l0x40c -removeonly
Acer Mobility Center Plug-In–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe” -l0x40c -removeonly
Acer ScreenSaver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe” -l0x9 -removeonly
Adobe Flash Player 10 ActiveX–>C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin–>C:\Windows\system32\Macromed\Flash\FlashUtil10e_plugin.exe -uninstall broker+plugin
ArcSoft Print Creations - Album Page–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c -1AlbumPage
ArcSoft Print Creations - Funhouse–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c -1Funhouse
ArcSoft Print Creations - Greeting Card–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c -1GreetingCard
ArcSoft Print Creations - Photo Book–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c -1PhotoBook
ArcSoft Print Creations - Photo Calendar–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c -1Calendar
ArcSoft Print Creations - Scrapbook–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c -1ScrapBook
ArcSoft Print Creations - Slimline Card–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c -1Slimline
ArcSoft Print Creations–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{CAE8A0F1-B498-4C23-95FA-55047E730C8F}\setup.exe” -l0x40c
Assistant de connexion Windows Live–>MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
BackRex Internet Explorer Backup–>C:\PROGRA~1\BACKRE~1\UNWISE.EXE C:\PROGRA~1\BACKRE~1\INSTALL.LOG
Camtasia Studio 6–>MsiExec.exe /I{A589DA26-51BD-475D-8C32-E19E34145842}
CCleaner–>“C:\Program Files\CCleaner\uninst.exe”
CCScore–>MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
Chessmaster Grandmaster Edition–>C:\Program Files\InstallShield Installation Information{27614800-84A9-484E-9CCB-43ED2F1205F5}\setup.exe -runfromtemp -l0x040c
COMODO Internet Security–>C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe -u
Conseiller de mise à niveau vers Windows 7–>MsiExec.exe /I{4983AA07-81D0-4605-BF92-49A343056DC8}
Defraggler–>“C:\Program Files\Defraggler\uninst.exe”
ESSBrwr–>MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCDBK–>MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore–>MsiExec.exe /I{42938595-0D83-404D-9F73-F8177FDD531A}
ESSgui–>MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESSini–>MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD–>MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSPDock–>MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091}
ESSTOOLS–>MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
essvatgt–>MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}
EVEREST Home Edition v2.20–>“C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe”
fflink–>MsiExec.exe /I{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}
FileHippo.com Update Checker–>“C:\Program Files\FileHippo.com\uninstall.exe”
Foxit Reader–>C:\Program Files\Foxit Software\Foxit Reader\Uninstall.exe
Free Window Registry Repair–>C:\PROGRA~1\FREEWI~1\UNWISE.EXE C:\PROGRA~1\FREEWI~1\INSTALL.LOG
Freeraser–>C:\Program Files\Codyssey\Freeraser\Uninstall.exe
Galerie de photos Windows Live–>MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
GNU Privacy Guard–>“C:\Program Files\GNU\GnuPG\uninst-gnupg.exe”
Google Update Helper–>MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HDAUDIO Soft Data Fax Modem with SmartCP–>C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118\UIU32m.exe -U -IAcrZUn32z.inf
HijackThis 2.0.2–>“C:\Program Files\trend micro\HijackThis.exe” /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Customer Participation Program 9.0–>C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 9.0–>C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP OCR Software 9.0–>C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
HP Photosmart All-In-One Software 9.0–>C:\Program Files\HP\Digital Imaging{B22C19AE-6A67-4f28-B541-5AE72FB17A25}\setup\hpzscr01.exe -datfile hposcr15.dat
HP Photosmart Essential 3.5–>C:\Program Files\HP\Digital Imaging\PhotosmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Product Assistant–>MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Solution Center 9.0–>C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update–>MsiExec.exe /X{818ABC3C-635C-4651-8183-D0E9640B7DD1}
HPSSupply–>MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
ImgBurn–>“C:\Program Files\ImgBurn\uninstall.exe”
Installation Windows Live–>C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live–>MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
Intel® Graphics Media Accelerator Driver–>C:\Windows\system32\igxpun.exe -uninstall
Intel® Matrix Storage Manager–>C:\Windows\System32\Imsmudlg.exe
J2SE Runtime Environment 5.0–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
Java™ 6 Update 17–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
Junk Mail filter update–>MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
KeyScrambler–>C:\Program Files\KeyScrambler\uninstall.exe
kgcbaby–>MsiExec.exe /I{E18B549C-5D15-45DA-8D8F-8FD2BD946344}
kgchday–>MsiExec.exe /I{11F3F858-4131-4FFA-A560-3FE282933B6E}
kgchlwn–>MsiExec.exe /I{03EDED24-8375-407D-A721-4643D9768BE1}
kgcinvt–>MsiExec.exe /I{9BD54685-1496-46A5-AB62-357CD140ED8B}
kgckids–>MsiExec.exe /I{693C08A7-9E76-43FF-B11E-9A58175474C4}
kgcmove–>MsiExec.exe /I{A1588373-1D86-4D44-86C9-78ABD190F9CC}
kgcvday–>MsiExec.exe /I{8A8664E1-84C8-4936-891C-BC1F07797549}
Kptic–>MsiExec.exe /X{4103778F-5EAF-476E-B3C1-2891EF9A4D8C}
livebox–>C:\Program Files\InstallShield Installation Information{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
Logiciel Kodak EasyShare–>C:\ProgramData\Kodak\EasyShareSetup$SETUP_140001_25e5dc\Setup.exe /APR-REMOVE
Malwarebytes’ Anti-Malware–>“C:\Program Files\Malwarebytes’ Anti-Malware\unins000.exe”
Messenger Plus! Live–>“C:\Program Files\Messenger Plus! Live\Uninstall.exe”
MessengerDiscovery 2.1.79–>“C:\Program Files\MessengerDiscovery 2\unins000.exe”
Microsoft .NET Framework 1.1 Security Update (KB953297)–>“C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe” “C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp”
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 3.5 Language Pack SP1 - fra–>MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1–>C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1–>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Antimalware Service FR-FR Language Pack–>MsiExec.exe /X{A4526B5A-89C0-4F4B-9E6E-4F883374D5F9}
Microsoft Antimalware–>MsiExec.exe /X{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}
Microsoft Baseline Security Analyzer 2.1–>MsiExec.exe /I{55D1BF8E-EA8F-4969-82B9-B577010CFBCD}
Microsoft Choice Guard–>MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office Access MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-0016-040C-0000-0000000FF1CE}
Microsoft Office Groove MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-00BA-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-0044-040C-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.4–>MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
Microsoft Office OneNote MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-00A1-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2010 (Beta)–>MsiExec.exe /X{20140000-0011-0000-0000-0000000FF1CE}
Microsoft Office Professionnel Plus 2010–>“C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe” /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Proof (Arabic) 2010 (Beta)–>MsiExec.exe /X{20140000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2010 (Beta)–>MsiExec.exe /X{20140000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2010 (Beta)–>MsiExec.exe /X{20140000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2010 (Beta)–>MsiExec.exe /X{20140000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2010 (Beta)–>MsiExec.exe /X{20140000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2010 (Beta)–>MsiExec.exe /X{20140000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2010 (Beta)–>MsiExec.exe /X{20140000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2010 (Beta)–>MsiExec.exe /X{20140000-001B-040C-0000-0000000FF1CE}
Microsoft Search Enhancement Pack–>MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Security Essentials–>C:\Program Files\Microsoft Security Essentials\setup.exe /x
Microsoft Security Essentials–>MsiExec.exe /I{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}
Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]–>MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053–>MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148–>MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17–>MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Works–>MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
Module linguistique Microsoft .NET Framework 3.5 SP1- fra–>C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
MozBackup 1.4.9–>C:\Program Files\MozBackup\Uninstall.exe
Mozilla Thunderbird (2.0.0.23)–>C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT–>MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)–>MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)–>MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
netbrdg–>MsiExec.exe /I{4537EA4B-F603-4181-89FB-2953FC695AB1}
Notepad+±->C:\Program Files\Notepad++\uninstall.exe
Notification Mail–>“C:\Program Files\Orange\MailNotifier\uninstallMailNotifier.exe”
NTI CD & DVD-Maker–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
OfotoXMI–>MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
OGA Notifier 2.0.0048.0–>MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
Orange - Logiciels Internet–>C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
OrangeInstaller version 1.0.0.0–>RunDll32 C:\Windows\system32\advpack.dll,LaunchINFSection C:\Windows\INF\OrangeInstaller_1.0.0.0.inf,DefaultUninstall
Orbit Downloader–>“C:\Program Files\Orbitdownloader\unins000.exe”
Outil de téléchargement Windows Live–>MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PhotoFiltre–>“C:\Program Files\PhotoFiltre\Uninst.exe”
PowerProducer 3.72–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.EXE” -uninstall
Realtek High Definition Audio Driver–>RtlUpd.exe -r -m
Recuva–>“C:\Program Files\Recuva\uninst.exe”
Revo Uninstaller 1.83–>C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
SFR–>MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
SHASTA–>MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
skin0001–>MsiExec.exe /I{5316DFC9-CE99-4458-9AB3-E8726EDE0210}
SKINXSDK–>MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
Skype™ 4.1–>MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
SRWare Iron 3.0.197.0–>“C:\Program Files\SRWare Iron\unins000.exe”
staticcr–>MsiExec.exe /I{8943CE61-53BD-475E-90E1-A580869E98A2}
Sun VirtualBox–>MsiExec.exe /I{ADF29850-DAD7-4F1D-B9DE-0AC58A167C0F}
SuperCopier2–>“C:\Program Files\SuperCopier2\SC2Uninst.exe”
tools-freebsd–>MsiExec.exe /X{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}
tools-linux–>MsiExec.exe /X{D102611A-6466-4101-A51D-51069303AC65}
tools-netware–>MsiExec.exe /X{197597A7-AD33-4898-9D8E-73066818B464}
tools-solaris–>MsiExec.exe /X{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}
tools-windows–>MsiExec.exe /X{FFD9383C-01D5-4897-A954-43AF599AED30}
tools-winPre2k–>MsiExec.exe /X{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
VC 9.0 Runtime–>MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}
VirusTotal Uploader–>“C:\Program Files\VirusTotalUploader\uninstall.exe”
Visual C++ 2008 x86 Runtime - (v9.0.30729)–>MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01–>C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Visual C++ CRT 9.0 SP1–>MsiExec.exe /I{EC25B803-4BDB-47F7-B877-FCE7D7966C0F}
VLC media player 1.0.3–>C:\Program Files\VideoLAN\VLC\uninstall.exe
VMware Workstation–>C:\ProgramData\VMware\VMware Workstation\Uninstaller\uninstall.exe -x
VMware Workstation–>MsiExec.exe /I{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}
VPRINTOL–>MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
Windows Installer Clean Up–>MsiExec.exe /X{121634B0-2F4B-11D3-ADA3-00C04F52DD52}
Windows Live Call–>MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform–>MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live FolderShare–>MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
Windows Live Mail–>MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
Windows Live Messenger–>MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
Windows Live Movie Maker–>MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
Windows Live OneCare safety scanner–>“C:\Program Files\Windows Live Safety Center\UnInstall.exe”
Windows Live OneCare safety scanner–>MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
Windows Live Writer–>MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
Windows Media Player Firefox Plugin–>MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WIRELESS–>MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
WOT pour Internet Explorer–>MsiExec.exe /X{DB6BD5D5-8482-45C0-99CF-745C5B924497}
Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Software Update–>C:\PROGRA~1\Yahoo!\SOFTWA~1\UNINST~1.EXE

======Security center information======

AS: Windows Defender
AS: SUPERAntiSpyware (disabled)

======System event log======

Computer Name: PC-de-Brigitte
Event Code: 5
Message: Le filtre de système de fichiers « is-BKINHdrv » (Version 6.0, 2008-07-08T12:52:58.000Z) n’a pas réussi à s’inscrire auprès du gestionnaire de filtres. L’état final de cette opération était 0xc01c0011.
Record Number: 294756
Source Name: Microsoft-Windows-FilterManager
Time Written: 20090916153548.710097-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Brigitte
Event Code: 4001
Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Record Number: 294746
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20090916153444.546826-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Brigitte
Event Code: 7000
Message: Le service Windows Search n’a pas pu démarrer en raison de l’erreur :
Le service n’a pas répondu assez vite à la demande de lancement ou de contrôle.
Record Number: 294717
Source Name: Service Control Manager
Time Written: 20090916151755.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-Brigitte
Event Code: 7009
Message: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service Windows Search.
Record Number: 294716
Source Name: Service Control Manager
Time Written: 20090916151755.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-Brigitte
Event Code: 10005
Message: DCOM a reçu l’erreur “1053” lors de la mise en route du service WSearch avec les arguments “” pour démarrer le serveur :
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Record Number: 294715
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20090916151755.000000-000
Event Type: Erreur
User:

=====Application event log=====

Computer Name: PC-de-Brigitte
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d’autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

DÉTAIL -
15 user registry handles leaked from \Registry\User\S-1-5-21-759318378-497761762-3404630427-1000:
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Acer\Empowering Technology 2.5\Framework
Process 2032 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\SearchUrl
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 2032 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Google\GoogleToolbarNotifier
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software
Process 2032 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\URLSearchHooks
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 2032 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\AppDataLow\Software\Yahoo\Companion
Process 2032 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\SearchScopes
Process 4808 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Policies

Record Number: 59375
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090622083029.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Brigitte
Event Code: 64
Message: Le certificat de Système local avec l’empreinte numérique 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 est sur le point d’expirer ou a déjà expiré.
Record Number: 59364
Source Name: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Time Written: 20090622081521.000000-000
Event Type: Avertissement
User:

Computer Name: PC-de-Brigitte
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d’autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

DÉTAIL -
3 user registry handles leaked from \Registry\User\S-1-5-21-759318378-497761762-3404630427-1000_Classes:
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000_CLASSES
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000_CLASSES
Process 1868 (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

Record Number: 59335
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090621192109.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Brigitte
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d’autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

DÉTAIL -
13 user registry handles leaked from \Registry\User\S-1-5-21-759318378-497761762-3404630427-1000:
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000
Process 428 (\Device\HarddiskVolume2\Program Files\Micro Application\Anti-Virus Personnel 2008\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Acer\Empowering Technology 2.5\Framework
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 340 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Google\GoogleToolbarNotifier
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 340 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\AppDataLow\Software\Yahoo\Companion
Process 4740 (\Device\HarddiskVolume2\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe) has opened key \REGISTRY\USER\S-1-5-21-759318378-497761762-3404630427-1000\Software\Policies

Record Number: 59334
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090621192107.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Brigitte
Event Code: 64
Message: Le certificat de Système local avec l’empreinte numérique 4e 7c 54 42 2a 43 1a db de 20 36 77 0e b2 fa 58 fb 58 cd 44 est sur le point d’expirer ou a déjà expiré.
Record Number: 59327
Source Name: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Time Written: 20090621154442.000000-000
Event Type: Avertissement
User:

=====Security event log=====

Computer Name: PC-de-Brigitte
Event Code: 4624
Message: L’ouverture de session d’un compte s’est correctement déroulée.

Sujet :
ID de sécurité : S-1-5-18
Nom du compte : PC-DE-BRIGITTE$
Domaine du compte : WORKGROUP
ID d’ouverture de session : 0x3e7

Type d’ouverture de session : 5

Nouvelle ouverture de session :
ID de sécurité : S-1-5-18
Nom du compte : SYSTEM
Domaine du compte : AUTORITE NT
ID d’ouverture de session : 0x3e7
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Informations sur le processus :
ID du processus : 0x2dc
Nom du processus : C:\Windows\System32\services.exe

Informations sur le réseau :
Nom de la station de travail :
Adresse du réseau source : -
Port source : -

Informations détaillées sur l’authentification :
Processus d’ouverture de session : Advapi
Package d’authentification : Negotiate
Services en transit : -
Nom du package (NTLM uniquement) : -
Longueur de la clé : 0

Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
- Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
- Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
- Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
- La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
Record Number: 93366
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090920123106.252472-000
Event Type: Succès de l’audit
User:

Computer Name: PC-de-Brigitte
Event Code: 4648
Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

Sujet :
ID de sécurité : S-1-5-18
Nom du compte : PC-DE-BRIGITTE$
Domaine du compte : WORKGROUP
ID d’ouverture de session : 0x3e7
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Compte dont les informations d’identification ont été utilisées :
Nom du compte : SYSTEM
Domaine du compte : AUTORITE NT
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Serveur cible :
Nom du serveur cible : localhost
Informations supplémentaires : localhost

Informations sur le processus :
ID du processus : 0x2dc
Nom du processus : C:\Windows\System32\services.exe

Informations sur le réseau :
Adresse du réseau : -
Port : -

Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
Record Number: 93365
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090920123106.252472-000
Event Type: Succès de l’audit
User:

Computer Name: PC-de-Brigitte
Event Code: 4672
Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

Sujet :
ID de sécurité : S-1-5-18
Nom du compte : SYSTEM
Domaine du compte : AUTORITE NT
ID d’ouverture de session : 0x3e7

Privilèges : SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 93364
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090920123106.160472-000
Event Type: Succès de l’audit
User:

Computer Name: PC-de-Brigitte
Event Code: 4624
Message: L’ouverture de session d’un compte s’est correctement déroulée.

Sujet :
ID de sécurité : S-1-5-18
Nom du compte : PC-DE-BRIGITTE$
Domaine du compte : WORKGROUP
ID d’ouverture de session : 0x3e7

Type d’ouverture de session : 5

Nouvelle ouverture de session :
ID de sécurité : S-1-5-18
Nom du compte : SYSTEM
Domaine du compte : AUTORITE NT
ID d’ouverture de session : 0x3e7
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Informations sur le processus :
ID du processus : 0x2dc
Nom du processus : C:\Windows\System32\services.exe

Informations sur le réseau :
Nom de la station de travail :
Adresse du réseau source : -
Port source : -

Informations détaillées sur l’authentification :
Processus d’ouverture de session : Advapi
Package d’authentification : Negotiate
Services en transit : -
Nom du package (NTLM uniquement) : -
Longueur de la clé : 0

Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
- Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
- Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
- Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
- La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
Record Number: 93363
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090920123106.160472-000
Event Type: Succès de l’audit
User:

Computer Name: PC-de-Brigitte
Event Code: 4648
Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

Sujet :
ID de sécurité : S-1-5-18
Nom du compte : PC-DE-BRIGITTE$
Domaine du compte : WORKGROUP
ID d’ouverture de session : 0x3e7
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Compte dont les informations d’identification ont été utilisées :
Nom du compte : SYSTEM
Domaine du compte : AUTORITE NT
GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

Serveur cible :
Nom du serveur cible : localhost
Informations supplémentaires : localhost

Informations sur le processus :
ID du processus : 0x2dc
Nom du processus : C:\Windows\System32\services.exe

Informations sur le réseau :
Adresse du réseau : -
Port : -

Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
Record Number: 93362
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090920123106.160472-000
Event Type: Succès de l’audit
User:

======Environment variables======

“ComSpec”=%SystemRoot%\system32\cmd.exe
“FP_NO_HOST_CHECK”=NO
“OS”=Windows_NT
“Path”=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;%CommonProgramFiles%\Microsoft Shared\Windows Live
“PATHEXT”=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
“PROCESSOR_ARCHITECTURE”=x86
“TEMP”=%SystemRoot%\TEMP
“TMP”=%SystemRoot%\TEMP
“USERNAME”=SYSTEM
“windir”=%SystemRoot%
“PROCESSOR_LEVEL”=6
“PROCESSOR_IDENTIFIER”=x86 Family 6 Model 15 Stepping 13, GenuineIntel
“PROCESSOR_REVISION”=0f0d
“NUMBER_OF_PROCESSORS”=2
“VBOX_INSTALL_PATH”=C:\Program Files\Sun\VirtualBox\

-----------------EOF-----------------

ComboFix 09-12-04.02 - Brigitte 05/12/2009 20:55.6.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2037.1070 [GMT 1:00]
Lancé depuis: c:\users\Brigitte\Desktop\poisson9.exe
Commutateurs utilisés :: c:\users\Brigitte\Desktop\CFScript.txt
SP: SUPERAntiSpyware disabled (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\Microsoft\WLSetup
c:\programdata\Microsoft\WLSetup\CabLogs\Logs.CAB
c:\programdata\Microsoft\WLSetup\Logs\2009-09-18_18-18_8b4-35riudt2.log
c:\programdata\Microsoft\WLSetup\Logs\2009-09-18_18-18_f4c-zdc8v9fn.log
c:\programdata\Microsoft\WLSetup\Logs\2009-09-19_16-45_16f8-e7xvxctt.log
c:\programdata\Microsoft\WLSetup\Logs\2009-09-19_16-54_148c-xg41near.log
c:\programdata\Microsoft\WLSetup\Logs\2009-09-20_19-47_1230-w9cmelbi.log
c:\programdata\Microsoft\WLSetup\Logs\2009-10-04_17-16_16e4-immvk6gd.log
c:\programdata\Microsoft\WLSetup\Logs\2009-11-18_19-25_15e8-5hj3vd9p.log
c:\programdata\Microsoft\WLSetup\Logs\2009-11-18_19-44_16cc-lvukfoat.log
c:\programdata\Microsoft\WLSetup\Logs\2009-11-18_19-57_15d0-71vkaope.log
c:\programdata\Microsoft\WLSetup\Logs\2009-11-26_20-34_e4c-cz99jmdu.log
c:\programdata\Microsoft\WLSetup\Logs\2009-11-26_21-35_930-05ygfa5d.log
c:\programdata\Microsoft\WLSetup\wltCFDE.tmp
c:\users\Brigitte\AppData\Local\Mozilla
c:\users\Brigitte\AppData\Local\Mozilla\Firefox\Mozilla Firefox rc 1\active-update.xml
c:\users\Brigitte\AppData\Local\Mozilla\Firefox\Mozilla Firefox rc 1\updates.xml
c:\users\Brigitte\AppData\Local\Mozilla\Firefox\Mozilla Firefox rc 1\updates\last-update.log

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-05 au 2009-12-05 ))))))))))))))))))))))))))))))))))))
.

2009-12-05 20:09 . 2009-12-05 20:11 4096 d-----w- c:\users\Brigitte\AppData\Local\temp
2009-12-05 20:09 . 2009-12-05 20:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-05 15:17 . 2009-12-05 15:21 -------- d-----w- c:\program files\Google
2009-12-05 12:29 . 2009-12-05 12:33 -------- d-----w- c:\program files\TubeMaster++
2009-12-05 09:17 . 2009-12-05 09:17 -------- d-----w- C:\rsit
2009-12-05 08:52 . 2009-12-05 08:58 -------- d-----w- c:\users\Brigitte\SecurityScans
2009-12-04 18:46 . 2009-12-04 18:57 4844296 ----a-w- c:\programdata\Malwarebytes\Malwarebytes’ Anti-Malware\mbam-setup.exe
2009-12-02 18:22 . 2009-12-05 18:41 -------- d-----w- c:\users\Brigitte\AppData\Roaming\VMware
2009-12-02 17:46 . 2009-12-02 17:46 909320 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\uninstall.exe
2009-12-02 17:46 . 2009-12-02 17:33 703024 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\vnetlib.exe
2009-12-02 17:46 . 2009-12-02 17:33 958000 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\vnetlib64.dll
2009-12-02 17:46 . 2009-12-02 17:33 922672 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\vnetlib64.exe
2009-12-02 17:46 . 2009-12-02 17:46 625200 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\instUtils.dll
2009-12-02 17:46 . 2009-12-02 17:33 331776 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\module_ws.dll
2009-12-02 17:46 . 2009-12-02 17:33 760368 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\vnetlib.dll
2009-12-02 17:46 . 2009-12-02 17:33 731696 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\vminstutil.dll
2009-12-02 17:46 . 2009-12-02 17:33 569344 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\module_core.dll
2009-12-02 17:46 . 2009-12-02 17:33 360448 ----a-w- c:\programdata\VMware\VMware Workstation\Uninstaller\module_license.dll
2009-12-02 17:43 . 2009-10-21 23:13 59952 ----a-w- c:\windows\system32\vnetinst.dll
2009-12-02 17:43 . 2009-10-21 23:13 16560 ----a-w- c:\windows\system32\drivers\vmnetadapter.sys
2009-12-02 17:43 . 2009-10-22 03:59 334384 ----a-w- c:\windows\system32\vmnetdhcp.exe
2009-12-02 17:43 . 2009-10-22 04:00 395824 ----a-w- c:\windows\system32\vmnat.exe
2009-12-02 17:43 . 2009-10-22 04:00 26288 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2009-12-02 17:42 . 2009-10-21 23:13 51248 ----a-r- c:\windows\system32\vmnetbridge.dll
2009-12-02 17:42 . 2009-10-21 23:13 36400 ----a-r- c:\windows\system32\drivers\vmnetbridge.sys
2009-12-02 17:42 . 2009-10-21 23:13 18736 ----a-r- c:\windows\system32\drivers\vmnet.sys
2009-12-02 17:42 . 2009-10-22 04:00 760368 ----a-w- c:\windows\system32\vnetlib.dll
2009-12-02 17:41 . 2009-10-22 04:00 23216 ----a-w- c:\windows\system32\drivers\VMkbd.sys
2009-12-02 17:39 . 2009-12-02 17:39 -------- d-----w- c:\program files\Common Files\VMware
2009-12-02 17:37 . 2009-12-05 20:11 4096 d-----w- c:\programdata\VMware
2009-12-02 17:37 . 2009-12-02 17:37 -------- d-----w- c:\program files\VMware
2009-12-02 13:26 . 2009-12-02 13:28 4096 d-----w- c:\program files\Dactylo
2009-12-02 12:51 . 2009-11-30 11:27 123280 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-12-02 12:50 . 2009-11-30 11:27 41616 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2009-12-01 11:56 . 2009-12-01 12:26 -------- d-----w- C:\poisson10305p
2009-11-30 12:02 . 2009-11-30 12:35 -------- d-----w- C:\poisson28617p
2009-11-30 11:27 . 2009-11-30 11:27 100048 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-11-29 11:56 . 2009-11-29 11:56 -------- d-----w- c:\program files\WOT
2009-11-29 10:38 . 2009-11-29 11:10 -------- d-----w- C:\poisson17870p
2009-11-29 09:49 . 2009-11-29 09:51 -------- d-----w- c:\program files\Windows Live Safety Center
2009-11-29 09:18 . 2009-11-29 09:18 90112 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy{CF49C79A-50A0-B13D-0DB8-0067D6A7ED5F}-winfile.dll
2009-11-28 18:36 . 2009-11-28 18:36 -------- d-----w- c:\users\Brigitte\AppData\Roaming\TeraCopy
2009-11-28 17:59 . 2009-11-28 17:59 -------- d-----w- c:\program files\uTorrent
2009-11-28 17:07 . 2009-11-28 17:35 -------- d-----w- C:\poisson
2009-11-28 08:47 . 2009-12-05 12:28 4096 d-----w- c:\program files\Orbitdownloader
2009-11-27 12:17 . 2009-11-27 12:17 171552 ----a-w- c:\windows\system32\guard32.dll
2009-11-27 12:17 . 2009-11-27 17:59 -------- d-----w- C:\UsbFix
2009-11-26 20:47 . 2009-11-26 20:48 4096 d-----w- c:\programdata\MessengerDiscovery 2
2009-11-26 20:47 . 2009-11-26 20:47 4096 d-----w- c:\program files\MessengerDiscovery 2
2009-11-25 18:42 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 14:22 . 2009-11-25 14:22 -------- d-----w- c:\program files\FileHippo.com
2009-11-25 13:53 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-25 13:53 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-25 13:51 . 2009-11-25 13:52 -------- d-----w- c:\programdata{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-25 11:52 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 11:52 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-23 17:05 . 2009-11-23 17:07 4096 d-----w- c:\program files\7-Zip
2009-11-22 13:03 . 2009-11-22 13:04 4096 d-----w- c:\program files\ImgBurn
2009-11-20 19:22 . 2009-11-20 19:22 -------- d-----w- c:\program files\Recuva
2009-11-19 18:15 . 2009-11-19 18:15 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-11-19 18:10 . 2009-11-19 18:10 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-11-19 18:05 . 2009-11-19 18:05 -------- d-----w- c:\program files\Microsoft Analysis Services
2009-11-19 18:03 . 2009-11-19 18:03 -------- d-----r- C:\MSOCache
2009-11-18 19:27 . 2009-11-19 12:28 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Download Manager
2009-11-18 19:05 . 2009-11-26 20:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-18 19:03 . 2009-11-26 20:43 4096 d-----w- c:\program files\Windows Live
2009-11-18 15:28 . 2009-11-18 15:28 -------- d-----w- c:\program files\Gibcom
2009-11-17 19:18 . 2009-11-17 19:20 -------- d-----w- c:\program files\Ubisoft
2009-11-17 16:12 . 2009-11-17 16:12 25214 ----a-r- c:\users\Brigitte\AppData\Roaming\Microsoft\Installer{4103778F-5EAF-476E-B3C1-2891EF9A4D8C}\controlPanelIcon.exe
2009-11-17 16:11 . 2009-11-17 16:12 4096 d-----w- c:\program files\Kptic Neonumeric
2009-11-17 11:52 . 2009-11-17 11:52 -------- d-----w- c:\programdata\F-Secure
2009-11-16 20:31 . 2009-11-16 20:41 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Kptic
2009-11-16 17:53 . 2009-11-16 17:54 4096 d-----w- c:\program files\Microsoft Security Essentials
2009-11-16 17:53 . 2009-11-16 18:12 -------- d-----w- c:\programdata\Comodo
2009-11-16 17:53 . 2009-11-25 11:50 128376 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-16 17:53 . 2009-11-17 12:11 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-11-16 17:53 . 2009-11-17 12:11 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-15 14:17 . 2009-11-15 14:17 -------- d-----w- c:\program files\Defraggler
2009-11-15 13:27 . 2009-11-10 14:50 607544 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-11-13 15:29 . 2009-11-13 15:29 -------- d-sh–w- c:\programdata{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-11-12 21:13 . 2009-11-26 12:33 -------- d-----w- c:\program files\QuickTime
2009-11-12 12:19 . 2009-11-12 12:19 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Auslogics
2009-11-11 10:43 . 2009-11-11 10:43 653560 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-11 10:17 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 10:17 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-11 10:00 . 2009-11-11 10:00 20480 d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2009-11-11 09:52 . 2009-11-11 09:52 -------- d-----w- c:\users\Brigitte\AppData\Roaming\HouseCall 6.6
2009-11-08 16:53 . 2009-11-08 16:53 -------- d–h--w- c:\users\Brigitte\784E6B0F00EC495095A2BBA64F44EC48.TMP
2009-11-08 13:32 . 2009-11-08 13:32 -------- d-----w- c:\users\Brigitte\AppData\Local\TechSmith
2009-11-08 13:31 . 2009-11-11 12:11 -------- d-----w- c:\programdata\TechSmith
2009-11-08 13:31 . 2009-11-08 13:31 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-11-08 13:31 . 2009-11-09 18:46 -------- d-----w- c:\program files\TechSmith
2009-11-08 09:37 . 2005-03-11 17:37 1986560 ----a-w- c:\windows\system32\AudFile.dll
2009-11-08 09:37 . 2005-02-24 12:11 1212416 ----a-w- c:\windows\system32\AudioInfos.dll
2009-11-08 09:37 . 2005-02-24 11:51 348160 ----a-w- c:\windows\system32\WMAFile.dll
2009-11-08 09:37 . 2003-01-26 11:41 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2009-11-08 09:37 . 1998-07-12 21:00 15360 ----a-w- c:\windows\system32\inetfr.DLL
2009-11-07 19:47 . 2009-11-07 19:48 4096 d-----w- c:\program files\SRWare Iron
2009-11-07 09:27 . 2009-11-07 09:27 -------- d-----w- c:\program files\Lavalys
2009-11-06 21:32 . 2009-11-07 19:42 1 ----a-w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-06 21:32 . 2009-11-06 21:32 -------- d-----w- c:\users\Brigitte\AppData\Roaming\OpenOffice.org
2009-11-06 21:22 . 2009-12-02 14:27 -------- d-----w- c:\program files\OpenOffice.org 3
2009-11-06 20:48 . 2009-11-06 20:50 4096 d-----w- c:\program files\PhotoFiltre
2009-11-06 17:38 . 2009-11-06 17:38 -------- d-----w- c:\users\Brigitte\AppData\Roaming\ImgBurn
2009-11-06 17:12 . 2009-11-06 17:12 -------- d-----w- c:\programdata\LightScribe
2009-11-06 17:10 . 2009-11-06 17:12 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Nero
2009-11-06 17:05 . 2009-11-06 17:28 -------- d-----w- c:\programdata\Nero
2009-11-06 17:05 . 2009-11-06 17:29 -------- d-----w- c:\program files\Common Files\Nero

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-05 20:13 . 2009-09-06 08:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Skype
2009-12-05 20:12 . 2009-09-12 12:24 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Orbit
2009-12-05 19:48 . 2009-09-22 16:13 4096 d-----w- c:\users\Brigitte\AppData\Roaming\uTorrent
2009-12-05 19:45 . 2009-08-20 16:42 4096 d-----w- c:\program files\Notepad++
2009-12-05 19:39 . 2009-11-02 15:19 4096 d-----w- c:\users\Brigitte\AppData\Roaming\vlc
2009-12-05 09:36 . 2007-08-10 07:53 12288 d-----w- c:\programdata\Microsoft Help
2009-12-05 09:17 . 2009-10-09 19:10 4096 d-----w- c:\program files\Trend Micro
2009-12-05 07:26 . 2009-10-07 15:46 4096 d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-12-03 15:14 . 2009-10-07 15:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13 . 2009-10-07 15:46 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-02 17:40 . 2006-11-02 15:48 687334 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-02 17:40 . 2006-11-02 15:48 132056 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-02 15:43 . 2009-08-20 16:42 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Notepad++
2009-12-02 14:19 . 2009-03-26 19:11 4096 d-----w- c:\program files\Opera
2009-11-29 21:39 . 2008-07-30 09:12 4096 d-----w- c:\program files\Yahoo!
2009-11-29 09:05 . 2009-06-25 19:00 16384 d-----w- c:\users\Brigitte\AppData\Roaming\dvdcss
2009-11-27 11:50 . 2009-05-03 14:15 15370988 ----a-w- c:\windows\system32\drivers\fidbox.idx
2009-11-27 11:50 . 2009-05-03 14:15 1147482144 ----a-w- c:\windows\system32\drivers\fidbox.dat
2009-11-26 20:47 . 2009-09-16 15:39 4096 d-----w- c:\program files\Messenger Plus! Live
2009-11-26 20:06 . 2008-07-30 13:02 4096 d-----w- c:\programdata\WLInstaller
2009-11-25 17:06 . 2009-05-24 16:30 4096 d-----w- c:\users\Brigitte\AppData\Roaming\Apple Computer
2009-11-23 17:12 . 2009-02-27 15:58 4096 d-----w- c:\programdata\NOS
2009-11-23 17:10 . 2009-09-21 15:40 4096 d-----w- c:\program files\AIMP2
2009-11-22 16:33 . 2009-09-21 15:40 4096 d-----w- c:\users\Brigitte\AppData\Roaming\AIMP
2009-11-21 08:43 . 2008-08-12 11:40 6648 ----a-w- c:\users\Brigitte\AppData\Local\d3d9caps.dat
2009-11-19 19:34 . 2008-07-30 09:14 106904 ----a-w- c:\users\Brigitte\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-19 18:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-11-19 17:39 . 2007-08-10 07:56 28672 d-----w- c:\program files\Microsoft Works
2009-11-17 19:40 . 2008-12-25 09:42 -------- d-----w- c:\programdata\Media Center Programs
2009-11-16 18:14 . 2009-07-02 17:42 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-11-15 13:29 . 2008-12-29 10:24 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Yahoo!
2009-11-15 13:27 . 2009-02-15 10:43 -------- d-----w- c:\programdata\Yahoo!
2009-11-15 10:30 . 2008-08-14 13:00 3420 ----a-w- c:\users\Brigitte\AppData\Roaming\wklnhst.dat
2009-11-13 19:19 . 2009-09-06 08:27 -------- d-----w- c:\users\Brigitte\AppData\Roaming\skypePM
2009-11-13 16:34 . 2009-03-24 16:27 -------- d-----w- c:\programdata\TuneUp Software
2009-11-11 10:29 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-10 19:48 . 2009-09-18 17:27 4096 d-----w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2
2009-11-10 11:40 . 2009-11-01 12:20 1730452 ----a-w- c:\users\Brigitte\AppData\Roaming\MessengerDiscovery 2\3558177607\Update.exe
2009-11-08 10:45 . 2009-10-24 11:32 -------- d-----w- c:\program files\Java
2009-11-07 08:09 . 2007-08-10 06:31 16384 d–h--w- c:\program files\InstallShield Installation Information
2009-11-06 17:00 . 2007-08-10 07:18 -------- d-----w- c:\program files\Common Files\NewTech Infosystems
2009-11-03 18:27 . 2009-11-03 18:27 -------- d-----w- c:\program files\VS Revo Group
2009-11-02 19:42 . 2009-09-26 09:54 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 13:51 . 2009-11-01 13:32 4096 d-----w- c:\users\Brigitte\AppData\Roaming\IDM
2009-11-01 13:50 . 2009-09-01 13:57 -------- d-----w- c:\users\Brigitte\AppData\Roaming\DMCache
2009-10-28 15:53 . 2009-10-28 15:53 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-28 15:53 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-28 15:52 . 2009-10-28 15:52 0 ------w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-24 14:14 . 2009-10-16 18:18 604488 ------w- c:\windows\system32\TUProgSt.exe
2009-10-24 13:39 . 2008-10-04 09:10 558640 ----a-w- c:\programdata\CyberLink\CLSetup\Download\MCEDS.exe
2009-10-23 20:35 . 2008-08-01 14:16 -------- d-----w- c:\program files\orange
2009-10-23 15:13 . 2009-10-22 15:57 -------- d-----w- c:\programdata\Messenger Plus!
2009-10-22 18:29 . 2009-10-22 18:29 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Talkback
2009-10-22 17:56 . 2009-10-22 17:56 -------- d-----w- c:\programdata\Cobian
2009-10-22 04:00 . 2009-10-22 04:00 853936 ----a-w- c:\windows\system32\drivers\vmx86.sys
2009-10-22 04:00 . 2009-10-22 04:00 70704 ----a-w- c:\windows\system32\drivers\vmci.sys
2009-10-22 02:47 . 2009-10-22 02:47 32304 ----a-w- c:\windows\system32\drivers\hcmon.sys
2009-10-22 02:22 . 2009-10-22 02:22 252464 ----a-w- c:\windows\system32\vmnc.dll
2009-10-21 17:00 . 2009-10-21 16:59 4096 d-----w- c:\program files\BackRex Internet Explorer Backup
2009-10-21 16:50 . 2009-10-21 16:50 4096 d-----w- c:\program files\MozBackup
2009-10-21 14:07 . 2009-10-21 14:07 4096 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-16 18:16 . 2009-03-24 16:25 4096 d-sh–w- c:\programdata{55A29068-F2CE-456C-9148-C869879E2357}
2009-10-16 15:23 . 2009-10-16 15:23 -------- d–h--w- c:\program files\Common Files\Updates
2009-10-13 18:14 . 2009-10-13 18:13 8192 d-----w- c:\program files\Mozilla Thunderbird
2009-10-12 13:33 . 2009-10-12 13:33 64960 ----a-w- c:\windows\system32\drivers\stcp2v30.sys
2009-10-11 03:17 . 2009-03-12 18:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 20:22 . 2009-10-10 20:22 364544 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\IsLicense40.dll
2009-10-10 20:22 . 2009-10-10 20:22 2273280 ----a-w- c:\programdata\Skype\Plugins\Plugins\603EE37F99AD4A1D96456E9CE0982199\G-Recorder.exe
2009-10-10 20:18 . 2009-10-10 20:18 868352 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe
2009-10-10 20:18 . 2009-10-10 20:18 53760 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\zlib.dll
2009-10-10 20:18 . 2009-10-10 20:18 640000 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\dbghelp.dll
2009-10-10 20:18 . 2009-10-10 20:18 1712128 ----a-w- c:\programdata\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\GdiPlus.dll
2009-10-10 10:26 . 2009-09-07 10:43 -------- d-----w- c:\program files\Foxit Software
2009-10-08 21:08 . 2009-10-28 15:44 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-10-28 15:44 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-10-28 15:44 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-08 15:56 . 2009-08-22 09:46 4096 d-----w- c:\program files\KeyScrambler
2009-10-07 17:38 . 2009-10-07 17:38 117760 ----a-w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-07 17:37 . 2009-06-29 10:53 -------- d-----w- c:\users\Brigitte\AppData\Roaming\SUPERAntiSpyware.com
2009-10-07 16:11 . 2009-06-10 18:19 4096 d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 15:05 . 2009-10-07 15:05 -------- d-----w- c:\users\Brigitte\AppData\Roaming\Amazon
2009-10-04 21:33 . 2009-08-22 09:46 115312 ------w- c:\windows\system32\drivers\keyscrambler.sys
2009-10-01 01:02 . 2009-10-28 15:47 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-28 15:48 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-28 15:47 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-28 15:47 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-28 15:48 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-28 15:47 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-28 15:47 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-28 15:47 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-28 15:47 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-28 15:47 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-28 15:47 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-28 15:48 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-10-28 15:47 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-10-28 15:47 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-10-28 15:47 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-10-28 15:47 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-26 19:56 . 2009-09-26 19:56 34688 ----a-w- c:\windows\system32\FM20FRA.DLL
2009-09-26 02:32 . 2009-09-26 02:32 1205080 ----a-w- c:\windows\system32\FM20.DLL
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE~\Browser Helper Objects{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-03 20:12 556432 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-04-11 1233920]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-19 125952]
“MailNotifier”=“c:\program files\orange\MailNotifier\MailNotifier.exe” [2009-10-12 692224]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-11-28 289584]
“Freeraser”=“c:\program files\Codyssey\Freeraser\Freeraser.exe” [2009-04-15 1903104]
“Messenger (Yahoo!)”=“c:\program files\Yahoo!\Messenger\YahooMessenger.exe” [2009-11-10 5244216]
“msnmsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe” [2009-11-26 3883856]
“Skype”=“c:\program files\Skype\Phone\Skype.exe” [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“PLFSetL”=“c:\windows\PLFSetL.exe” [2007-07-05 94208]
“MSSE”=“c:\program files\Microsoft Security Essentials\msseces.exe” [2009-09-13 1048392]
“COMODO Internet Security”=“c:\program files\COMODO\COMODO Internet Security\cfp.exe” [2009-11-17 1800464]
“BCSSync”=“c:\program files\Microsoft Office\Office14\BCSSync.exe” [2009-09-26 83312]
“vmware-tray”=“c:\program files\VMware\VMware Workstation\vmware-tray.exe” [2009-10-22 129584]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“KeyScrambler”=“c:\program files\KeyScrambler\getting_started.html” [X]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-11-28 1719568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“FilterAdministratorToken”= 1 (0x1)
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=c:\windows\System32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux”=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=“Service”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logiciel Kodak EasyShare.lnk]
backup=c:\windows\pss\Logiciel Kodak EasyShare.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Orbit.lnk]
backup=c:\windows\pss\Orbit.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 - Capture d’écran et lancement.lnk]
backup=c:\windows\pss\OneNote 2007 - Capture d’écran et lancement.lnk.Startup
backupExtension=.Startup

[HKLM~\startupfolder\C:^Users^Brigitte^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^WkCalRem.LNK]
backup=c:\windows\pss\WkCalRem.LNK.Startup
backupExtension=.Startup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“WindowsWelcomeCenter”=rundll32.exe oobefldr.dll,ShowWelcomeCenter

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“HP Software Update”=c:\program files\HP\HP Software Update\HPWuSchd2.exe
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):be,e2,88,b6,74,df,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-759318378-497761762-3404630427-1000]
“EnableNotificationsRef”=dword:0000000c

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [16/11/2009 18:53 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [16/11/2009 18:53 29520]
R1 SbFw;SbFw;c:\windows\System32\drivers\SbFw.sys [31/10/2008 06:09 270888]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [08/11/2008 11:21 61424]
R2 vmci;VMware vmci;c:\windows\System32\drivers\vmci.sys [22/10/2009 05:00 70704]
R2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [22/10/2009 03:47 563760]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [10/08/2007 15:41 179712]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [10/08/2007 15:41 32256]
R3 KeyScrambler;KeyScrambler;c:\windows\System32\drivers\keyscrambler.sys [22/08/2009 10:46 115312]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\System32\drivers\SbFwIm.sys [06/06/2009 12:07 65576]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [05/12/2009 16:17 135664]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [31/07/2008 09:57 21504]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [29/10/2009 10:22 30603640]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18/06/2009 18:48 42480]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [26/09/2009 04:28 4639136]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [30/07/2008 11:28 28224]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\System32\drivers\VBoxNetAdp.sys [30/11/2009 12:27 100048]
S4 0267471241168295mcinstcleanup;0267471241168295mcinstcleanup; [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier ‘Tâches planifiées’

2009-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

  • c:\program files\Google\Update\GoogleUpdate.exe [2009-12-05 15:17]

2009-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

  • c:\program files\Google\Update\GoogleUpdate.exe [2009-12-05 15:17]

2009-12-05 c:\windows\Tasks\User_Feed_Synchronization-{55AF2E8A-EBC9-4A50-8828-434D9E33BE57}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]

2009-12-05 c:\windows\Tasks\User_Feed_Synchronization-{B9F5AA25-7397-45DF-9E85-5786632F2D22}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = fr.yahoo.com…
    uSearchMigratedDefaultURL = search.yahoo.com…
    mWindow Title =
    IE: ?4da1a3bfcab942eab3ec3b465ef4d37d
    IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
    IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
    IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
    IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
    Trusted Zone: orange.fr\logicielsgratuits
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    DPF: {4DD20514-9520-40A7-9CD6-66883643A20B} - www.boaki.com…
    DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} - logicielsgratuits.orange.fr…
    DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} - webtv.guidetv.orange.fr…
    .

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-12-05 21:13
Windows 6.0.6002 Service Pack 2 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
“ImagePath”="??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\vmnat.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\acer\Empowering Technology\ePower\ePowerSvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\VMware\VMware Workstation\vmware-authd.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\vmnetdhcp.exe
c:\windows\ehome\ehmsas.exe
c:\users\Brigitte\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.


.
Heure de fin: 2009-12-05 21:23 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-12-05 20:22
ComboFix2.txt 2009-12-01 12:26
ComboFix3.txt 2009-11-30 12:35
ComboFix4.txt 2009-11-29 11:10
ComboFix5.txt 2009-12-05 19:50

Avant-CF: 25 008 529 408 octets libres
Après-CF: 24 753 963 008 octets libres

    • End Of File - - 4FA2F30A12DEA32538449F630ADD5C97

J’ai réinstaller Firefox et il ne s’ouvre plus et il est dans la mémoire et il bosse pas !

Help !


A si y s'ouvre
voici le rapport :

Le volume dans le lecteur C s’appelle Windows Vista
Le numéro de série du volume est 3CFE-25A5

Répertoire de c:\windows

05/12/2009 21:12 .
05/12/2009 21:12 …
30/07/2008 10:12 ACER
15/01/2007 13:28 336 ACERTOURREMINDERRUN.REG
30/07/2008 19:53 3 AFirst.cmd
15/09/2009 19:51 183 aimpr.ini
30/07/2008 10:26 115 Alaunch.ini
05/12/2009 21:03 AppPatch
02/12/2009 15:27 assembly
20/09/2009 10:59 121 bdagent.INI
25/05/2006 00:22 53 248 bdoscandel.exe
14/03/2005 13:38 469 bdoscandellang.ini
19/01/2008 08:33 58 880 bfsvc.exe
31/07/2008 10:31 Boot
05/12/2009 21:11 67 584 bootstat.dat
02/11/2006 13:37 Branding
01/10/2009 17:08 154 cavscan.INI
30/07/2008 10:12 1 550 CLEANUP.CMD
01/10/2004 21:32 92 CLEANUP.INI
18/05/2007 03:56 9 csup.txt
02/11/2006 13:37 Cursors
05/12/2009 09:57 Debug
14/11/2002 15:32 55 808 devcon.exe
10/08/2007 07:31 319 456 DIFxAPI.dll
31/07/2008 10:33 DigitalLocker
19/05/2009 16:27 Downloaded Installations
28/11/2009 10:19 Downloaded Program Files
21/12/1998 15:57 90 112 easyh32.dll
08/05/1998 10:42 217 088 Easyhelp.dll
15/10/2009 20:27 ehome
29/11/2009 11:57 ERDNT
09/05/2007 12:34 16 437 832 eRy.exe
11/04/2009 07:27 2 926 592 explorer.exe
19/11/2009 19:17 Fonts
02/11/2006 16:46 fr-FR
17/10/2009 09:37 ftpcache
19/01/2008 08:33 13 312 fveupdate.exe
02/11/2006 11:22 Globalization
31/08/2000 08:00 80 412 grep.exe
30/07/2008 10:26 92 GridV.UNI
02/06/2009 16:34 Help
19/01/2008 08:33 498 176 HelpPane.exe
21/09/2009 18:48 Hewlett-Packard
02/11/2006 10:45 14 848 hh.exe
10/08/2007 07:31 315 392 HideWin.exe
19/09/2006 12:41 8 328 HomePremium.xml
19/09/2006 08:49 14 HomePremium_X86_FR.ID
13/07/2009 12:27 159 022 hpoins15.dat
06/06/2007 00:04 1 039 hpomdl15.dat
13/07/2009 09:08 119 515 hpqins00.dat
21/03/2009 19:48 19 561 hpqins13.dat
28/05/2009 10:03 IME
05/12/2009 13:12 inf
05/12/2009 16:22 Installer
03/04/2009 12:03 Internet Logs
27/03/2009 16:58 657 408 is-28GNU.exe
27/03/2009 16:58 124 is-28GNU.lst
27/03/2009 16:58 10 586 is-28GNU.msg
31/07/2008 10:33 L2Schemas
02/11/2006 11:23 LiveKernelReports
30/07/2008 10:15 83 LManager.UNI
21/10/2009 18:06 Logs
25/10/2009 06:11 77 312 MBR.exe
07/04/2009 13:08 McAfee.com
02/11/2006 13:37 Media
05/12/2009 20:04 239 937 393 MEMORY.DMP
19/10/2009 16:50 7 900 MessengerPlus.ini
02/11/2006 08:46 43 131 mib.bin
28/11/2009 17:54 Microsoft.NET
05/12/2009 20:04 Minidump
19/10/2008 18:38 ModemLogs
31/07/2008 10:33 MSAgent
18/09/2006 22:30 1 405 msdfmap.ini
02/11/2006 12:18 nap
20/04/2009 12:56 31 232 NIRCMD.exe
19/01/2008 08:33 151 040 notepad.exe
11/08/2009 16:02 0 nsreg.dat
10/08/2007 07:24 16 384 ocsetup_cbs_install_OEMHelpCustomization.dpx
10/08/2007 07:24 49 152 ocsetup_cbs_install_OEMHelpCustomization.perf
10/08/2007 07:24 4 489 216 ocsetup_install_OEMHelpCustomization.etl
02/11/2006 12:18 Offline Web Pages
19/12/2006 12:47 228 648 OptChecker.exe
19/12/2006 12:34 163 120 OptRemove.exe
30/07/2008 10:04 Panther
10/08/2007 08:55 PCHEALTH
02/11/2006 13:37 Performance
14/11/2009 01:47 260 608 PEV.exe
05/12/2009 21:10 906 PFRO.log
28/06/2007 08:18 131 PidList.ini
02/11/2006 12:18 PLA
25/04/2007 06:47 45 056 PLFSet.dll
05/07/2007 11:35 94 208 PLFSetL.exe
22/03/2009 17:17 PolicyDefinitions
04/12/2009 21:24 Prefetch
02/11/2006 12:18 Provisioning
03/10/2009 16:50 pss
19/01/2008 08:33 134 656 regedit.exe
03/07/2009 19:10 registration
26/11/2009 12:50 rescache
02/11/2006 12:18 Resources
06/07/2007 04:06 4 669 440 RtHDVCpl.exe
12/01/2007 09:54 520 192 RtlExUpd.dll
16/01/2007 03:39 1 191 936 RtlUpd.exe
02/11/2006 11:24 SchCache
02/11/2006 13:37 schemas
02/11/2006 12:18 security
31/08/2000 08:00 98 816 sed.exe
02/11/2006 13:47 ServiceProfiles
28/05/2009 10:03 servicing
14/06/2004 01:24 30 SETPANEL.INI
02/11/2006 13:47 Setup
31/07/2009 13:37 290 816 Setup1.exe
05/12/2009 12:59 0 setupact.log
05/12/2009 12:59 0 setuperr.log
19/11/2009 19:15 ShellNew
15/06/2007 09:45 1 826 816 SkyTel.exe
02/04/2009 15:37 SoftwareDistribution
02/11/2006 13:42 Speech
31/07/2009 13:37 74 752 ST6UNST.EXE
24/06/2009 11:55 Sun
30/07/2008 10:02 SUYIN NB Cam
31/08/2000 08:00 161 792 SWREG.exe
31/08/2000 08:00 136 704 SWSC.exe
31/08/2000 08:00 212 480 SWXCACLS.exe
03/04/2009 20:55 system
05/12/2009 21:12 215 system.ini
05/12/2009 21:03 System32
02/11/2006 12:18 tapi
05/12/2009 19:58 Tasks
05/12/2009 22:03 Temp
02/11/2006 11:23 tracing
02/11/2006 13:34 94 784 twain.dll
19/05/2009 16:27 twain_32
02/11/2006 13:34 50 688 twain_32.dll
12/03/2007 02:35 12 288 Twunk_16.dll
02/11/2006 13:34 49 680 twunk_16.exe
12/03/2007 02:35 12 288 Twunk_32.dll
02/11/2006 13:34 31 232 twunk_32.exe
28/06/2007 13:45 183 056 UNINST32.EXE
02/11/2006 13:37 Web
19/11/2009 19:08 254 win.ini
02/11/2006 16:46 WindowsMobile
11/05/2009 18:44 749 WindowsShell.Manifest
05/12/2009 21:27 675 786 WindowsUpdate.log
18/09/2006 22:43 256 192 winhelp.exe
02/11/2006 10:45 9 216 winhlp32.exe
25/11/2009 19:45 winsxs
10/07/2009 13:01 307 560 WLXPGSS.SCR
11/12/2002 19:11 37 916 WMPrfFRA.prx
02/11/2006 13:35 316 640 WMSysPr9.prx
31/08/2000 08:00 68 096 zip.exe
18/09/2006 22:43 707 _default.pif
85 fichier(s) 279 150 163 octets
67 Rép(s) 24 651 546 624 octets libres

Firefox ne s’ouvre plus !!!:o(

Ca ne marche pas !

Il se démarre.


Je les fermer et redémarrer ( le mode Firefox )en mode sans échec et rien.