ça y est, j'l'ai eu
Rapport de ZHPDiag v1.28.304 par Nicolas Coolman, Update du 31/12/2011
Run by DOMINIQUE at 31/12/2011 12:59:59
Web site :
http://www.premiumorange.com/zeb-he[...]ss/zhpdiag.html
Web site :
http://nicolascoolman.skyrock.com/
Windows 7 Home Premium Edition, 32-bit Service Pack 1 (Build 7601)
State : Version à jour.
Boot mode: Normal (Normal boot)
Logged in as Administrator
---\\ Web Browser
MSIE: Internet Explorer v9.0.8112.16421
MFIE: Mozilla Firefox 7.0.1 v7.0.1 (Defaut)
---\\ Processus lancés
[MD5.BA2E1EA96A03CFB1459B3C1958A89977] - (.TeamViewer GmbH - TeamViewer Remote Control Application.) -- C:\Program Files\TeamViewer\Version6\TeamViewer.exe [8090496] [PID.3692]
[MD5.3F82A3EF8EDDB21CF96E11814193FE7E] - (.TuneUp Software - TuneUp Utilities.) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe [713544] [PID.3744]
[MD5.2718DC27571BD1E37813F5759D2DC118] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [202296] [PID.]
[MD5.B2BCB4A5553E137B026F095D5260EDFC] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [373864] [PID.4516]
[MD5.C450370DCDCFDC4B28FC73DF8047054F] - (.Vitzo - VDownloader.) -- C:\Program Files\VDownloader\VDownloader.exe [858624] [PID.1652]
[MD5.0A6E40741DB7FF0B9A1FF50D16CFEAA7] - (.IncrediMail, Ltd. - IncrediMail Application.) -- C:\Program Files\IncrediMail\bin\ImApp.exe [189896] [PID.4416]
[MD5.ED5D1ABADB3FB05284BAD74BE2A1588A] - (.Grégory HARGOUS - emoticon.gregland.net - Emoticon : La solution pour les Smileys.) -- C:\Program Files\Emoticon\emoticon.exe [1480704] [PID.6088]
[MD5.82DBC5142825B0E2B5466EE5515623E5] - (...) -- C:\Program Files\VDownloader\ffmpeg.exe [14562304] [PID.2760]
[MD5.4E5585800B561FBEF64B27425365A36F] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [924632] [PID.6140]
[MD5.05689AE12F88716C9A319DC7EAA6D393] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [712704] [PID.2668]
[MD5.78405310A9DB8D3CBF27432ED5393F71] - (.Kaspersky Lab ZAO - WebToolBar component.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtblfs.exe [131472] [PID.4476]
[MD5.6436B3D3920AA7B45012D54524F95553] - (.Lavasoft Limited - Ad-Aware Tray Application.) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [1191728] [PID.4144]
[MD5.307FB55BD3D0EC649F28A9ABA075632E] - (.IncrediMail, Ltd. - IncrediMail Tray Application.) -- C:\Program Files\IncrediMail\bin\IncMail.exe [251336] [PID.4696]
~ Scan Processes Running in 00mn 01s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\DOMINIQUE\AppData\Local\Google\Chrome\User Data\Default\Preferences
G0 - GCSP: Preference [User Data\Default][HomePage]
http://www.google.com
G2 - GCE: Preference [User Data\Default] [fheoggkfdfchfphceeifdbepaooicaho] McAfee SiteAdvisor v.3.30.153.1 (Activé)
~ Scan Google Browser in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\DOMINIQUE\AppData\Roaming\Mozilla\Firefox\Profiles\z0sytdrt.default\prefs.js
C:\Users\DOMINIQUE\AppData\Roaming\Mozilla\Firefox\Profiles\z0sytdrt.default\user.js
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Users\DOMINIQUE\AppData\Roaming\Mozilla\Firefox\Profiles\z0sytdrt.default\searchplugins\personas-pour-firefox.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Users\DOMINIQUE\AppData\Roaming\Mozilla\Firefox\Profiles\z0sytdrt.default\searchplugins\search-the-web.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\babylon.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\McSiteAdvisor.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\scenicreflectionstb.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
M3 - MFPP: Plugins - [DOMINIQUE] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
M0 - MFSP: prefs.js [DOMINIQUE - z0sytdrt.default]
http://www.allmyweb.com
M2 - MFEP: prefs.js [DOMINIQUE - z0sytdrt.default\{3112ca9c-de6d-4884-a869-9855de68056c}] [] Google Toolbar for Firefox v7.1.20110512W (.Google Inc..)
M2 - MFEP: prefs.js [DOMINIQUE - z0sytdrt.default\{635abd67-4fe9-1b23-4f01-e679fa7484c1}] [yahoo.ytff] Yahoo! Toolbar v2.4.5.20111209014555 (.Yahoo!.)
M2 - MFEP: prefs.js [DOMINIQUE - z0sytdrt.default\{6e73f6b7-b9ab-44b8-b744-6393e3c2e351}] [] Personas Rotator v3.6 (.Baris Derin.)
M2 - MFEP: prefs.js [DOMINIQUE - z0sytdrt.default\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] [] Zynga Community Toolbar v3.8.1.0 (.Conduit Ltd..)
M2 - MFEP: prefs.js [DOMINIQUE - z0sytdrt.default\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}] [dwhelper] DownloadHelper v4.9.8 (.Michel Gutierrez.)
P2 - FPN:Firefox Plugin Navigator . (.VB2S - VB2S Mannequin Virtuel Web Player.) -- C:\Program Files\Mozilla Firefox\Plugins\MannequinPlayer2.dll
P2 - FPN:Firefox Plugin Navigator . (.Macromedia, Inc. - Macromedia Shockwave for Director Netscape plug-in, version 10.1.) -- C:\Program Files\Mozilla Firefox\Plugins\np32dsw.dll
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Incorporated - <a href='
http://www.adobe.com'>Adobe</a> ESD Version Manager 2.0.) -- C:\Program Files\Mozilla Firefox\Plugins\NPAdbESD.dll
P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - 2.0.0048.0.) -- C:\Program Files\Mozilla Firefox\Plugins\npOGAPlugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.4.5".) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Mozilla Firefox\Plugins\nppl3260.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll
P2 - FPN:Firefox Plugin Navigator . (.Pas de propriétaire - Mannequin Virtuel.) -- C:\Program Files\Mozilla Firefox\Plugins\npredoute.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Mozilla Firefox\Plugins\nprjplug.dll
P2 - FPN:Firefox Plugin Navigator . (.RealNetworks, Inc. - 6.0.12.46.) -- C:\Program Files\Mozilla Firefox\Plugins\nprpjplug.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_29 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60831.0.) -- C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.5.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.5] - (.Microsoft Corp. - Office Live Update v1.5.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@nvidia.com/3DVision] - (.NVIDIA Corporation - NVIDIA 3D Vision plugin for Mozilla browsers.) -- C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
P2 - FPN: [HKLM] [@nvidia.com/3DVisionStreaming] - (.NVIDIA Corporation - NVIDIA 3D Vision Streaming plugin for Mozilla browsers.) -- C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.11.2303] - (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Real Alternative\Browser\Plugins\nppl3260.dll
P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.1465] - (.RealNetworks, Inc. - 6.0.12.1465.) -- C:\Program Files\Real Alternative\Browser\Plugins\nprpjplug.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.4.5".) -- C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
P2 - FPN: [HKLM] [yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1] - (.Yahoo! Inc. - Yahoo! activeX Plug-in Bridge.) -- C:\Program Files\Yahoo!\Common\npyaxmpb.dll
P2 - FPN: [HKCU] [vitzo.com/VDownloader] - (.Vitzo - VDownloader browser plug-in.) -- C:\Program Files\VDownloader\Addons\npVDownloader.dll
~ Scan Firefox Browser in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.incredimail.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)) -- C:\Windows\System32\ieframe.dll
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ Scan IE Browser in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s
---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe
~ Scan Keys in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} . (.Yahoo! Inc. - Yahoo! Toolbar.) -- C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} . (...) -- C:\Program Files\mcafee\msk\mskapbho.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} . (.Kaspersky Lab ZAO - IE Virtual Keyboard.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corporation - Search Helper for Internet Explorer.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: IEExtension.VDownloaderBHO - {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} . (.Kaspersky Lab ZAO - WebToolBar component.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
~ Scan BHO in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} . (.Yahoo! Inc. - Yahoo! Toolbar.) -- C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
~ Scan Toolbar in 00mn 00s
---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
O4 - HKLM\..\Run: [AVP] . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [3PlanesoftAnimatedWallpaper] Clé orpheline
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [IncrediMail] . (.IncrediMail, Ltd. - IncrediMail Tray Application.) -- C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [IncrediMail] . (.IncrediMail, Ltd. - IncrediMail Tray Application.) -- C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-21-3744223251-329315469-658757590-1020-3744223251-329315469-658757590-1017\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-3744223251-329315469-658757590-1020-3744223251-329315469-658757590-1017\..\Run: [3PlanesoftAnimatedWallpaper] Clé orpheline
O4 - HKUS\S-1-5-21-3744223251-329315469-658757590-1020-3744223251-329315469-658757590-1017\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
~ Scan Application in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk . (.VMware, Inc..) -- C:\Program Files\VMware\VMware Player\vmplayer.exe
O4 - Global Startup: C:\Users\MICROMEDIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\MICROMEDIA\Desktop\Internet Explorer.lnk - Clé orpheline
O4 - Global Startup: C:\Users\MICROMEDIA\Desktop\Windows XP Professional.vmx - Raccourci.lnk . (...) -- E:\Windows XP Professional.vmx
O4 - Global Startup: C:\Users\MICROMEDIA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\MICROMEDIA\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk . (.VMware, Inc..) -- C:\Program Files\VMware\VMware Player\vmplayer.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Configurer Send To Toys.lnk . (.Microsoft Corporation.) -- C:\Windows\system32\control.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\View My Screensavers.lnk . (...) -- C:\Users\DOMINIQUE\AppData\Roaming\Astro Gemini Software\Screensaver Manager 2.0\Astro Gemini Screensaver Manager.exe (.not
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\3Planesoft Screensaver Manager.lnk . (...) -- C:\Windows\System32\3Planesoft\Screensaver Manager\Configurator.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\ALIENOR.lnk . (...) -- C:\Desktop
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\Axialis IconWorkshop.lnk . (.Axialis Software.) -- C:\Program Files\Axialis\IconWorkshop\IconWorkshop.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\CYBER POUNCE.lnk . (...) -- C:\Program Files\CyberPounce\Pounce.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\IncrediMail Data Manager.lnk . (.Silent Wings Software.) -- C:\Program Files\IncrediMail Data Manager V1.15\IncrediMail Data Manager.EXE
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\makotocatroses.lnk . (...) -- C:\Program Files\ezthemes.com\makotocatroses
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\PARTAGE.lnk . (.Microsoft Corporation.) -- C:\Windows\explorer.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\Petz 5.lnk . (.Studio Mythos, Inc..) -- C:\JEUX\CATZ5\Petz 5.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\PhotoMailMaker.exe.lnk . (.IncrediMail Ltd..) -- C:\Program Files\PhotoMail Maker\Bin\PhotoMailMaker.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\SOCIALSAFE.lnk . (...) -- C:\Program Files\SocialSafe\SocialSafe.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\Super Finder XT portable.lnk . (.FSL.) -- C:\SuperFinder\SuperFinder.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\SuperCopier2.lnk . (.SFX TEAM.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - Global Startup: C:\Users\DOMINIQUE\Desktop\Tinker.lnk . (.Sherlock Software.) -- C:\JEUX\CATZ5\Tinker\Tinker.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ALIENOR.lnk . (...) -- C:\Desktop
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Babylon.lnk . (.Babylon Ltd..) -- C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bureau.lnk . (...) -- C:\Users\DOMINIQUE\Desktop
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CSMenu.lnk . (.OrdinarySoft.) -- C:\Program Files\CSMenu\CSMenu.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\EXPLORER ACDSee32.lnk . (.ACD Systems, Ltd..) -- C:\IMAGES\ACDSee32\ACDSee32.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FARM TOWN.lnk . (...) -- C:\Desktop\GAMES\FARM TOWN
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FARMLIFE.lnk . (...) -- C:\Desktop\GAMES\FARMLIFE
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FARMVILLE.lnk . (...) -- C:\Desktop\GAMES\FARMVILLE
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\friends_of_1317277959.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\friends_of_1317277959.csv (.not file.)
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ImageFox.lnk . (.ACD Systems, Ltd..) -- C:\IMAGES\ImageFox\ImageFox.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk . (.IncrediMail, Ltd..) -- C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MINI PLANET.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\Desktop\GAMES\MINI PLANET (.not file.)
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PROFESSIONNEL.lnk . (...) -- C:\Desktop\PROFESSIONNEL
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SOCIALSAFE.lnk . (...) -- C:\Program Files\SocialSafe\SocialSafe.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Super Finder.lnk . (.FSL.) -- C:\Program Files\FSL\SuperFinder\SuperFinder.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\taskmgr.exe.lnk . (.Microsoft Corporation.) -- C:\Windows\System32\taskmgr.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VDownloader.lnk . (.Vitzo.) -- C:\Program Files\VDownloader\VDownloader.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk . (.VMware, Inc..) -- C:\Program Files\VMware\VMware Player\vmplayer.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMWARE.lnk . (.VMware, Inc..) -- C:\Program Files\VMware\VMware Player\vmplayer.exe
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WIN XP.lnk . (...) -- E:\Windows XP Professional.vmx
O4 - Global Startup: C:\Users\DOMINIQUE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\YOVILLE.lnk . (...) -- C:\Desktop\GAMES\YOVILLE
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Configurer Send To Toys.lnk . (.Microsoft Corporation.) -- C:\Windows\system32\control.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Creative Element Power Tools.lnk . (.Creative Element.) -- C:\Program Files\Creative Element Power Tools\Control Panel.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicaView Help.lnk . (...) -- C:\Program Files\PicaView32\PicaView32.hlp
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\ALIENOR.lnk . (...) -- C:\Desktop
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\Axialis IconWorkshop.lnk . (.Axialis Software.) -- C:\Program Files\Axialis\IconWorkshop\IconWorkshop.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\Catz5Manual.pdf.lnk . (...) -- C:\JEUX\CATZ5\Manuals\Catz5Manual.pdf
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\Flower Clock 3D Screensaver.lnk . (...) -- C:\Windows\System32\Flower Clock 3D Screensaver.scr
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\IncrediMail Data Manager.lnk . (.Silent Wings Software.) -- C:\Program Files\IncrediMail Data Manager V1.15\IncrediMail Data Manager.EXE
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\IncrediMail.lnk . (.IncrediMail, Ltd..) -- C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\Notes.lnk . (...) -- C:\Users\DOMINIQUE\Documents\Notes
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\PARTAGE.lnk . (.Microsoft Corporation.) -- C:\Windows\explorer.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\PowerpointImageExtractor V1.2.lnk . (.---.) -- C:\Program Files\PowerpointImageExtractor_V1_2\PowerpointImageExtractor.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\SOCIALSAFE.lnk . (...) -- C:\Program Files\SocialSafe\SocialSafe.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\Tinker.lnk . (.Sherlock Software.) -- C:\JEUX\CATZ5\Tinker\Tinker.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\Desktop\ZoomBrowser EX.lnk . (...) -- C:\Windows\Installer\{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}\Zb_icon.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Autumn Forest Écran de veille.lnk . (...) -- C:\Windows\System32\Autumn Forest.scr
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Babylon.lnk . (.Babylon Ltd..) -- C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bureau ALIENOR.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\Desktop (.not file.)
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bureau.lnk . (...) -- C:\Users\DOMINIQUE\Desktop
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CSMenu.lnk . (.OrdinarySoft.) -- C:\Program Files\CSMenu\CSMenu.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\EXPLORER ACDSee32.lnk . (.ACD Systems, Ltd..) -- C:\IMAGES\ACDSee32\ACDSee32.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FARM TOWN.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\Desktop\GAMES\FARM TOWN (.not file.)
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FARMLIFE.lnk . (...) -- C:\$WINDOWS.~Q\DATA\Users\admin\Desktop\FARMLIFE (.not file.)
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FARMVILLE.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\Desktop\GAMES\FARMVILLE (.not file.)
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ImageFox.lnk . (.ACD Systems, Ltd..) -- C:\IMAGES\ImageFox\ImageFox.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk . (.IncrediMail, Ltd..) -- C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MINI PLANET.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\Desktop\GAMES\MINI PLANET (.not file.)
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PARTAGE.lnk . (...) -- C:\partage
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PROFESSIONNEL.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\Desktop\PROFESSIONNEL (.not file.)
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Radio Fr Solo.lnk . (...) -- C:\Program Files\Radio Fr Solo\Radio_Fr_Solo.exe (.not file.)
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SOCIALSAFE.lnk . (...) -- C:\Program Files\SocialSafe\SocialSafe.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\taskmgr.exe.lnk . (.Microsoft Corporation.) -- C:\Windows\System32\taskmgr.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Tinker.lnk . (.Sherlock Software.) -- C:\JEUX\CATZ5\Tinker\Tinker.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk . (.VMware, Inc..) -- C:\Program Files\VMware\VMware Player\vmplayer.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WIN XP.lnk . (...) -- E:\Windows XP Professional.vmx
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger .lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
O4 - Global Startup: C:\Users\COMPTE DE SECOURS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\YOVILLE.lnk . (...) -- C:\Users\DOMINIQUE\Desktop\Desktop\GAMES\YOVILLE (.not file.)
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\Axialis IconWorkshop.lnk . (.Axialis Software.) -- C:\Program Files\Axialis\IconWorkshop\IconWorkshop.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\CDex.lnk . (.Albert L Faber.) -- C:\Program Files\CDex_150\CDex.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\Creative Element Power Tools.lnk . (.Creative Element.) -- C:\Program Files\Creative Element Power Tools\Control Panel.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\Dead Pixel.lnk . (...) -- C:\Program Files\Dead Pixel\Dead Pixel.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\FileZilla Server Interface.lnk . (.FileZilla Project.) -- C:\Program Files\FileZilla Server\FileZilla Server Interface.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\Flower Clock 3D Screensaver.lnk . (...) -- C:\Windows\System32\Flower Clock 3D Screensaver.scr
O4 - Global Startup: C:\Users\Administrateur\Desktop\More 3D Screensavers.lnk . (...) -- C:\Program Files\Flower Clock 3D Screensaver\link2.url
O4 - Global Startup: C:\Users\Administrateur\Desktop\PowerpointImageExtractor V1.2.lnk . (.---.) -- C:\Program Files\PowerpointImageExtractor_V1_2\PowerpointImageExtractor.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\Radio Fr Solo.lnk . (...) -- C:\Program Files\Radio Fr Solo\Radio_Fr_Solo.exe (.not file.)
O4 - Global Startup: C:\Users\Administrateur\Desktop\Tinker.lnk . (.Sherlock Software.) -- C:\JEUX\CATZ5\Tinker\Tinker.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\Ubi Soft Product Registration.lnk . (.Ubi Soft.) -- C:\Program Files\Ubi Soft\Register\register.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\WebView.lnk . (.PROject MT, Ltd..) -- C:\Program Files\PROMT98\WEBVIEW.EXE
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Autumn Forest Écran de veille.lnk . (...) -- C:\Windows\System32\Autumn Forest.scr
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Hard Drive Inspector.lnk . (...) -- C:\Program Files\Hard Drive Inspector\HDInspector.exe (.not file.)
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk . (.IncrediMail, Ltd..) -- C:\Program Files\IncrediMail\bin\IncMail.exe
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Tinker.lnk . (.Sherlock Software.) -- C:\JEUX\CATZ5\Tinker\Tinker.exe
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk . (.VMware, Inc..) -- C:\Program Files\VMware\VMware Player\vmplayer.exe
~ Scan Global Startup in 00mn 01s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ Scan IE Control Panel in 00mn 00s
---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: &Add animation to IncrediMail Style Box . (...) -- C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Ajouter à l'Anti-bannière . (...) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
O8 - Extra context menu item: Translate with &Babylon . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
~ Scan IE Menu Contextuel in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} . (...) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\kbrd.ico
O9 - Extra button: Clavier &virtuel - {CCF151D8-D089-449F-A5A4-D9909053F20F} . (...) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\logo.ico
~ Scan IE Extra Buttons in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\System32\nlaapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\System32\NapiNSP.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\System32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\System32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\System32\mswsock.dll
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\System32\winrnr.dll
~ Scan Winsock in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{786FED12-8D3C-48D3-BE51-802BB8587816}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{786FED12-8D3C-48D3-BE51-802BB8587816}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{786FED12-8D3C-48D3-BE51-802BB8587816}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{A0706021-40DB-4AA2-B6CF-FA4D04EE913D}: DhcpNameServer = 192.168.209.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{DA12949F-6F6E-47A2-B093-777FFECB0214}: DhcpNameServer = 192.168.137.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{A0706021-40DB-4AA2-B6CF-FA4D04EE913D}: DhcpDomain = localdomain
O17 - HKLM\System\CS2\Services\Tcpip\..\{DA12949F-6F6E-47A2-B093-777FFECB0214}: DhcpDomain = localdomain
~ Scan Domain in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files\Windows Live\Messenger\msgrapp.dll
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files\Windows Live\Messenger\msgrapp.dll
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
~ Scan Protocole Additionnel in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: klogon . (.Kaspersky Lab ZAO - Logon Visualizer.) -- C:\Windows\System32\klogon.dll
~ Scan Winlogon in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ Scan SSODL in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) . (.ArcSoft Inc. - ArcSoft Connect Service.) - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Atomic Alarm Clock Time (AtomicAlarmClock) . (...) - C:\Program Files\Atomic Alarm Clock\timeserv.exe (.not file.)
O23 - Service: Kaspersky Anti-Virus Service (AVP) . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) . (.FileZilla Project - FileZilla Server.) - C:\Program Files\FileZilla Server\FileZilla server.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HDD & SSD access service (HDD & SSD access service) . (...) - C:\Program Files\Common Files\BinarySense\disksvc.exe (.not file.)
O23 - Service: Lavasoft Ad-Aware Service (Lavasoft Ad-Aware Service) . (.Lavasoft Limited - Ad-Aware Service Application.) - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 280.2.) - C:\Windows\System32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 6 (TeamViewer6) . (.TeamViewer GmbH - TeamViewer Remote Control Application.) - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) . (.TuneUp Software - TuneUp Utilities Service.) - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\System32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\System32\vmnat.exe
~ Scan Services in 00mn 00s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s
End of the scan (403 lines in 00mn 05s)(0)