et la suite:
---\\ Contents of the Common Files folders (O43)
O43 - CFD: 19/07/2010 - 08:17:07 - [0,000] ----D C:\Program Files (x86)\Activation Assistant for the 2007 Microsoft Office suites
O43 - CFD: 19/12/2012 - 16:14:55 - [755,713] ----D C:\Program Files (x86)\Adobe
O43 - CFD: 19/12/2012 - 15:49:13 - [2,984] ----D C:\Program Files (x86)\Adobe Download Assistant
O43 - CFD: 10/02/2012 - 18:04:34 - [2,316] ----D C:\Program Files (x86)\Apple Software Update
O43 - CFD: 09/01/2013 - 15:02:05 - [0] ----D C:\Program Files (x86)\Bonjour
O43 - CFD: 07/11/2012 - 19:43:20 - [1021,099] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 09/01/2013 - 15:01:39 - [0,266] ----D C:\Program Files (x86)\CyberLink
O43 - CFD: 10/02/2012 - 12:53:28 - [1151,619] ----D C:\Program Files (x86)\Dofus2
O43 - CFD: 01/10/2012 - 19:06:30 - [0,004] ----D C:\Program Files (x86)\DownloadToolz
O43 - CFD: 19/07/2010 - 08:36:05 - [99,507] ----D C:\Program Files (x86)\EasyBits For Kids
O43 - CFD: 19/12/2012 - 16:19:55 - [34,416] ----D C:\Program Files (x86)\GIMP 2
O43 - CFD: 14/11/2012 - 23:21:10 - [4,705] ----D C:\Program Files (x86)\Google
O43 - CFD: 11/12/2012 - 21:35:31 - [7,701] ----D C:\Program Files (x86)\GPLGS
O43 - CFD: 19/07/2010 - 08:35:03 - [1423,215] ----D C:\Program Files (x86)\Hewlett-Packard
O43 - CFD: 19/07/2010 - 08:16:38 - [2,979] ----D C:\Program Files (x86)\Hp
O43 - CFD: 19/07/2010 - 08:40:06 - [278,803] ----D C:\Program Files (x86)\HP Games
O43 - CFD: 09/01/2013 - 15:01:43 - [89,218] --H-D C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 12/12/2012 - 18:22:25 - [6,190] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 07/01/2013 - 20:57:38 - [152,491] ----D C:\Program Files (x86)\iTunes
O43 - CFD: 02/01/2012 - 13:09:57 - [85,466] ----D C:\Program Files (x86)\Java
O43 - CFD: 17/09/2011 - 15:23:12 - [482,903] ----D C:\Program Files (x86)\LibreOffice 3.4
O43 - CFD: 31/12/2012 - 06:33:31 - [12,328] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 11/12/2012 - 21:06:25 - [0,216] ----D C:\Program Files (x86)\Microsoft
O43 - CFD: 17/09/2011 - 10:53:55 - [52,521] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 02/10/2012 - 17:23:35 - [1,182] ----D C:\Program Files (x86)\Microsoft Security Client
O43 - CFD: 14/05/2012 - 20:14:30 - [36,641] ----D C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 11/10/2011 - 17:07:31 - [3,999] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 11/10/2011 - 17:07:31 - [0,331] ----D C:\Program Files (x86)\Microsoft Synchronization Services
O43 - CFD: 10/10/2012 - 20:25:17 - [137,975] ----D C:\Program Files (x86)\Microsoft Works
O43 - CFD: 17/09/2011 - 13:21:15 - [0,015] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 09/01/2013 - 14:58:49 - [0,006] ----D C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 14/07/2009 - 06:32:38 - [0,025] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 19/07/2010 - 08:40:41 - [1,108] ----D C:\Program Files (x86)\MSN Toolbar Installer
O43 - CFD: 17/09/2011 - 11:46:48 - [0] ----D C:\Program Files (x86)\MSXML 4.0
O43 - CFD: 17/09/2011 - 10:52:08 - [19,339] R---D C:\Program Files (x86)\Online Services
O43 - CFD: 02/10/2012 - 17:16:36 - [0,449] ----D C:\Program Files (x86)\Orbitdownloader
O43 - CFD: 11/12/2012 - 21:35:16 - [37,488] ----D C:\Program Files (x86)\PDFCreator
O43 - CFD: 18/11/2012 - 17:41:55 - [72,326] ----D C:\Program Files (x86)\QuickTime
O43 - CFD: 14/10/2012 - 20:21:42 - [0] ----D C:\Program Files (x86)\Real
O43 - CFD: 19/07/2010 - 08:12:27 - [46,193] ----D C:\Program Files (x86)\Realtek
O43 - CFD: 14/07/2009 - 06:32:38 - [37,357] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 18/10/2012 - 19:33:57 - [62,225] ----D C:\Program Files (x86)\Research In Motion
O43 - CFD: 14/05/2012 - 17:19:57 - [102,605] ----D C:\Program Files (x86)\Safari
O43 - CFD: 14/05/2012 - 18:12:26 - [2,176] ----D C:\Program Files (x86)\Samsung
O43 - CFD: 19/07/2010 - 08:12:39 - [0] --H-D C:\Program Files (x86)\Temp
O43 - CFD: 14/07/2009 - 05:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information
O43 - CFD: 24/01/2012 - 19:09:51 - [24,103] ----D C:\Program Files (x86)\Vlcclassic
O43 - CFD: 17/09/2011 - 19:41:12 - [0,500] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 19/07/2010 - 08:42:52 - [392,854] ----D C:\Program Files (x86)\Windows Live
O43 - CFD: 19/07/2010 - 08:41:47 - [0,234] ----D C:\Program Files (x86)\Windows Live SkyDrive
O43 - CFD: 17/09/2011 - 19:41:12 - [5,895] ----D C:\Program Files (x86)\Windows Mail
O43 - CFD: 17/09/2011 - 14:30:39 - [4,791] ----D C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - 06:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 17/09/2011 - 19:41:12 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 17/09/2011 - 14:30:39 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 17/09/2011 - 14:30:39 - [5,717] ----D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 14/01/2013 - 20:35:19 - [11,192] ----D C:\Program Files (x86)\ZHPDiag
O43 - CFD: 19/12/2012 - 16:13:26 - [594,974] ----D C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 01/12/2012 - 08:49:10 - [40,070] ----D C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 15/02/2012 - 23:16:27 - [153,441] ----D C:\Program Files (x86)\Common Files\Apple
O43 - CFD: 19/07/2010 - 08:12:25 - [3,805] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 29/05/2012 - 17:49:13 - [1,201] ----D C:\Program Files (x86)\Common Files\Java
O43 - CFD: 09/01/2013 - 14:59:39 - [0,041] ---AD C:\Program Files (x86)\Common Files\LightScribe
O43 - CFD: 19/07/2010 - 08:30:31 - [0,049] ---AD C:\Program Files (x86)\Common Files\LS Getting Started
O43 - CFD: 17/09/2011 - 10:53:55 - [91,299] ----D C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 14/10/2012 - 20:21:30 - [0,199] ----D C:\Program Files (x86)\Common Files\PX Storage Engine
O43 - CFD: 18/10/2012 - 19:40:17 - [41,131] ----D C:\Program Files (x86)\Common Files\Research In Motion
O43 - CFD: 14/07/2009 - 04:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 14/07/2009 - 04:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 16/12/2012 - 19:46:11 - [0] ----D C:\Program Files (x86)\Common Files\Symantec Shared
O43 - CFD: 13/11/2011 - 20:10:38 - [9,767] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 19/07/2010 - 08:40:52 - [0] ----D C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD: 18/10/2012 - 19:34:24 - [45,921] ----D C:\Program Files (x86)\Common Files\XCPCSync.OEM
O43 - CFD: 07/01/2013 - 20:57:46 - [2,775] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
O43 - CFD: 19/12/2012 - 16:16:10 - [414,735] ----D C:\ProgramData\Adobe
O43 - CFD: 10/02/2012 - 18:04:12 - [257,998] ----D C:\ProgramData\Apple
O43 - CFD: 24/01/2012 - 19:08:36 - [210,100] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Application Data
O43 - CFD: 09/01/2013 - 14:45:13 - [0,107] ----D C:\ProgramData\CyberLink
O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Documents
O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Favorites
O43 - CFD: 11/10/2011 - 17:08:41 - [120,602] ----D C:\ProgramData\Hewlett-Packard
O43 - CFD: 09/02/2012 - 08:24:04 - [16,224] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 11/12/2012 - 21:06:25 - [603,772] -S--D C:\ProgramData\Microsoft
O43 - CFD: 09/01/2013 - 14:58:34 - [0,000] ----D C:\ProgramData\Norton
O43 - CFD: 19/07/2010 - 08:44:15 - [10,224] ----D C:\ProgramData\NortonInstaller
O43 - CFD: 17/09/2011 - 12:03:59 - [0,261] ----D C:\ProgramData\NVIDIA
O43 - CFD: 17/09/2011 - 11:53:33 - [0,501] ----D C:\ProgramData\NVIDIA Corporation
O43 - CFD: 19/07/2010 - 08:15:55 - [3,106] ----D C:\ProgramData\PC-Doctor for Windows
O43 - CFD: 19/07/2010 - 08:15:13 - [3,376] ----D C:\ProgramData\Ralink Driver
O43 - CFD: 14/10/2012 - 20:21:39 - [1,225] ----D C:\ProgramData\Real
O43 - CFD: 17/09/2011 - 20:32:02 - [22,522] ----D C:\ProgramData\Recovery
O43 - CFD: 19/12/2012 - 16:16:09 - [0,002] ----D C:\ProgramData\regid.1986-12.com.adobe
O43 - CFD: 18/10/2012 - 19:34:23 - [0,062] ----D C:\ProgramData\Research In Motion
O43 - CFD: 14/05/2012 - 18:12:21 - [1,234] ----D C:\ProgramData\Samsung
O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Start Menu
O43 - CFD: 17/09/2011 - 15:04:20 - [0,000] ----D C:\ProgramData\Sun
O43 - CFD: 09/01/2013 - 14:58:19 - [1,826] ----D C:\ProgramData\Symantec
O43 - CFD: 19/07/2010 - 08:29:38 - [0,469] ----D C:\ProgramData\Temp
O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Templates
O43 - CFD: 19/07/2010 - 08:40:03 - [1867,832] ----D C:\ProgramData\WildTangent
O43 - CFD: 19/07/2010 - 08:11:14 - [19,334] ----D C:\ProgramData\{657095DF-DBDB-4B17-8245-B38845C97069}
O43 - CFD: 24/01/2012 - 19:08:39 - [0,002] ----D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
O43 - CFD: 19/12/2012 - 16:22:11 - [4,546] ----D C:\Users\Valentin\AppData\Roaming\Adobe
O43 - CFD: 10/12/2012 - 18:23:25 - [0] ----D C:\Users\Valentin\AppData\Roaming\AnkamaCertificates
O43 - CFD: 13/11/2011 - 20:27:39 - [0,005] ----D C:\Users\Valentin\AppData\Roaming\app
O43 - CFD: 16/10/2012 - 17:58:04 - [1007,440] ----D C:\Users\Valentin\AppData\Roaming\Apple Computer
O43 - CFD: 19/12/2012 - 15:49:21 - [0,018] ----D C:\Users\Valentin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
O43 - CFD: 03/04/2012 - 20:51:14 - [0] ----D C:\Users\Valentin\AppData\Roaming\CyberLink
O43 - CFD: 31/12/2012 - 06:25:33 - [52,633] ----D C:\Users\Valentin\AppData\Roaming\Dofus 2
O43 - CFD: 13/11/2011 - 20:27:37 - [0] ----D C:\Users\Valentin\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
O43 - CFD: 16/11/2011 - 11:35:50 - [0] ----D C:\Users\Valentin\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
O43 - CFD: 16/11/2011 - 11:17:31 - [0] ----D C:\Users\Valentin\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
O43 - CFD: 31/12/2012 - 08:05:03 - [93,137] ----D C:\Users\Valentin\AppData\Roaming\Dofus2
O43 - CFD: 12/12/2012 - 18:59:54 - [0] ----D C:\Users\Valentin\AppData\Roaming\DofusTesting
O43 - CFD: 10/12/2012 - 18:22:58 - [0] ----D C:\Users\Valentin\AppData\Roaming\DofusTesting-2
O43 - CFD: 14/12/2012 - 12:37:45 - [0] ----D C:\Users\Valentin\AppData\Roaming\DofusTesting-3
O43 - CFD: 18/12/2012 - 18:31:47 - [0] ----D C:\Users\Valentin\AppData\Roaming\DofusTesting-4
O43 - CFD: 01/10/2012 - 18:53:36 - [0] ----D C:\Users\Valentin\AppData\Roaming\GrabPro
O43 - CFD: 06/10/2011 - 18:09:50 - [0,109] ----D C:\Users\Valentin\AppData\Roaming\Hewlett-Packard
O43 - CFD: 17/01/2013 - 19:16:27 - [0,000] ----D C:\Users\Valentin\AppData\Roaming\HP Support Assistant
O43 - CFD: 17/01/2013 - 19:16:27 - [0,023] ----D C:\Users\Valentin\AppData\Roaming\HpUpdate
O43 - CFD: 17/09/2011 - 10:57:11 - [0] ----D C:\Users\Valentin\AppData\Roaming\Identities
O43 - CFD: 24/01/2012 - 19:53:37 - [1,803] ----D C:\Users\Valentin\AppData\Roaming\LibreOffice
O43 - CFD: 24/01/2012 - 19:53:37 - [0,055] ----D C:\Users\Valentin\AppData\Roaming\Macromedia
O43 - CFD: 09/02/2012 - 08:24:09 - [9,772] ----D C:\Users\Valentin\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 08:44:38 - [0] ----D C:\Users\Valentin\AppData\Roaming\Media Center Programs
O43 - CFD: 20/01/2013 - 12:02:36 - [6,857] -S--D C:\Users\Valentin\AppData\Roaming\Microsoft
O43 - CFD: 24/01/2012 - 19:53:41 - [0,000] ----D C:\Users\Valentin\AppData\Roaming\Mozilla
O43 - CFD: 24/01/2012 - 19:56:12 - [0,001] ----D C:\Users\Valentin\AppData\Roaming\newfolder3
O43 - CFD: 02/10/2012 - 17:16:35 - [0,674] ----D C:\Users\Valentin\AppData\Roaming\Orbit
O43 - CFD: 19/12/2012 - 16:20:26 - [0] ----D C:\Users\Valentin\AppData\Roaming\PDAppFlex
O43 - CFD: 11/12/2012 - 21:36:02 - [0,540] ----D C:\Users\Valentin\AppData\Roaming\PDFCreatorPackages
O43 - CFD: 19/12/2012 - 16:23:19 - [0] ----D C:\Users\Valentin\AppData\Roaming\Pixia
O43 - CFD: 01/10/2012 - 18:53:40 - [0,000] ----D C:\Users\Valentin\AppData\Roaming\ProgSense
O43 - CFD: 14/10/2012 - 20:21:44 - [111,042] ----D C:\Users\Valentin\AppData\Roaming\Real
O43 - CFD: 03/04/2012 - 11:35:40 - [0] ----D C:\Users\Valentin\AppData\Roaming\RealNetworks
O43 - CFD: 19/11/2012 - 21:44:37 - [11,271] ----D C:\Users\Valentin\AppData\Roaming\redsn0w
O43 - CFD: 13/11/2011 - 20:27:39 - [0] ----D C:\Users\Valentin\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
O43 - CFD: 18/10/2012 - 19:37:23 - [3,164] ----D C:\Users\Valentin\AppData\Roaming\Research In Motion
O43 - CFD: 14/10/2012 - 20:25:01 - [0] ----D C:\Users\Valentin\AppData\Roaming\Samsung
O43 - CFD: 14/01/2013 - 20:59:12 - [0,013] ----D C:\Users\Valentin\AppData\Roaming\Template
O43 - CFD: 19/12/2012 - 16:22:01 - [16,848] ----D C:\Users\Valentin\AppData\Local\Adobe
O43 - CFD: 20/01/2012 - 18:36:49 - [0] ----D C:\Users\Valentin\AppData\Local\Apple
O43 - CFD: 15/02/2012 - 23:17:52 - [80,230] ----D C:\Users\Valentin\AppData\Local\Apple Computer
O43 - CFD: 17/09/2011 - 10:51:33 - [0] ----D C:\Users\Valentin\AppData\Local\Application Data
O43 - CFD: 20/11/2012 - 19:25:23 - [2,607] ----D C:\Users\Valentin\AppData\Local\CRE
O43 - CFD: 17/01/2013 - 22:06:40 - [0] ----D C:\Users\Valentin\AppData\Local\Diagnostics
O43 - CFD: 18/10/2012 - 19:38:04 - [53,666] ----D C:\Users\Valentin\AppData\Local\Downloaded Installations
O43 - CFD: 19/01/2013 - 16:32:04 - [0,059] ----D C:\Users\Valentin\AppData\Local\ElevatedDiagnostics
O43 - CFD: 07/11/2012 - 18:33:01 - [0,046] ----D C:\Users\Valentin\AppData\Local\Facebook
O43 - CFD: 19/12/2012 - 16:32:36 - [1,512] ----D C:\Users\Valentin\AppData\Local\fontconfig
O43 - CFD: 19/12/2012 - 16:32:35 - [0,001] ----D C:\Users\Valentin\AppData\Local\gegl-0.2
O43 - CFD: 24/01/2012 - 19:52:47 - [753,383] ----D C:\Users\Valentin\AppData\Local\Google
O43 - CFD: 19/12/2012 - 21:16:43 - [35,484] ----D C:\Users\Valentin\AppData\Local\Hewlett-Packard
O43 - CFD: 17/09/2011 - 10:51:33 - [0] ----D C:\Users\Valentin\AppData\Local\Historique
O43 - CFD: 14/01/2013 - 20:59:09 - [725,440] ----D C:\Users\Valentin\AppData\Local\Microsoft
O43 - CFD: 24/01/2012 - 19:52:49 - [0,160] ----D C:\Users\Valentin\AppData\Local\Microsoft Games
O43 - CFD: 12/10/2011 - 16:09:32 - [0] ----D C:\Users\Valentin\AppData\Local\Mozilla
O43 - CFD: 24/01/2012 - 19:43:22 - [0] ----D C:\Users\Valentin\AppData\Local\PackageAware
O43 - CFD: 31/12/2012 - 06:30:02 - [0] ----D C:\Users\Valentin\AppData\Local\Programs
O43 - CFD: 02/10/2012 - 17:25:08 - [0] ----D C:\Users\Valentin\AppData\Local\Real
O43 - CFD: 18/10/2012 - 19:44:52 - [230,293] ----D C:\Users\Valentin\AppData\Local\Research In Motion
O43 - CFD: 22/01/2013 - 18:36:32 - [622,231] ----D C:\Users\Valentin\AppData\Local\Temp
O43 - CFD: 17/09/2011 - 10:51:33 - [0] ----D C:\Users\Valentin\AppData\Local\Temporary Internet Files
O43 - CFD: 19/12/2012 - 16:23:19 - [0,820] ----D C:\Users\Valentin\AppData\Local\VirtualStore
O43 - CFD: 17/09/2011 - 11:13:39 - [0,006] ----D C:\Users\Valentin\AppData\Local\WindowsUpdate
O43 - CFD: 19/01/2013 - 18:03:38 - [0,013] R---D C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 31/07/2012 - 01:12:52 - [0,000] R---D C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 10/02/2012 - 12:53:28 - [0] ----D C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dofus2
O43 - CFD: 19/01/2013 - 22:56:59 - [0,002] ----D C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 24/01/2012 - 19:56:12 - [0,001] R---D C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 31/07/2012 - 01:12:52 - [0,000] R---D C:\Users\Valentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
~ Scan Program Folder in 00mn 47s
---\\ Last modified or created files under Windows and System32 (O44)
O44 - LFC:[MD5.E69711166AAF03CC15A32FC444E86FBA] - 22/01/2013 - 18:36:39 ---A- . (...) -- C:\Windows\setupact.log [74142]
O44 - LFC:[MD5.62F88BBB07F6924A8C2DC38BF028ECD9] - 22/01/2013 - 18:35:35 ----- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1549936]
O44 - LFC:[MD5.62F88BBB07F6924A8C2DC38BF028ECD9] - 22/01/2013 - 18:35:35 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1549936]
O44 - LFC:[MD5.074BD4189E6FA58A25F5665B715668B8] - 22/01/2013 - 18:35:35 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [106412]
O44 - LFC:[MD5.C94B2B03F2F960CF52E7E7115F6D8DAB] - 22/01/2013 - 18:35:35 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [130770]
O44 - LFC:[MD5.FCF115E5BC16C81496870DF0B031C4A1] - 22/01/2013 - 18:35:35 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [616032]
O44 - LFC:[MD5.6FAC0BCFFACA745AD2917D8F7D9111AC] - 22/01/2013 - 18:35:35 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [704464]
O44 - LFC:[MD5.B6D49D6A830A41DFC42331487AC199DC] - 22/01/2013 - 18:34:00 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1688026]
O44 - LFC:[MD5.AFE8C8CAE6B23CBD5D939FA5D5669850] - 22/01/2013 - 18:29:55 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.7CE0F73027212432CB358537409048E2] - 20/01/2013 - 18:58:40 ---A- . (...) -- C:\Windows\PFRO.log [275506]
O44 - LFC:[MD5.D2BC95F67E9156F42198A3541DA3A9B9] - 13/01/2013 - 19:09:10 . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\FNTCACHE.DAT [46080]
O44 - LFC:[MD5.D2BC95F67E9156F42198A3541DA3A9B9] - 13/01/2013 - 19:09:10 ---A- . (...) -- C:\Windows\SysNative\FNTCACHE.DAT [4980392]
O44 - LFC:[MD5.8ACC1EFC15C4EA1243FF0A48B397BCC1] - 10/01/2013 - 21:10:52 . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\MRT.exe [46080]
O44 - LFC:[MD5.828CAB7AE3F0981C3D362A1436104647] - 07/01/2013 - 20:41:43 ---A- . (...) -- C:\AdwCleaner[S8].txt [33460]
O44 - LFC:[MD5.7813D05FA63A2A34B00F6AE668236EDA] - 31/12/2012 - 13:06:40 ---A- . (...) -- C:\dof.png [858639]
O44 - LFC:[MD5.2ED72B3F76C9368ABC01464DA64DB7AE] - 31/12/2012 - 03:00:46 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\SysNative\atmlib.dll [46080]
O44 - LFC:[MD5.2ED72B3F76C9368ABC01464DA64DB7AE] - 31/12/2012 - 03:00:46 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [46080]
O44 - LFC:[MD5.CB2ABB2DA1E9C977302A78D86D4AE3B0] - 31/12/2012 - 03:00:46 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\SysNative\atmfd.dll [367616]
O44 - LFC:[MD5.CB2ABB2DA1E9C977302A78D86D4AE3B0] - 31/12/2012 - 03:00:46 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [367616]
O44 - LFC:[MD5.523B9B64F2B6C630A2E0A87116C05F12] - 23/11/2012 - 04:26:31 . (...) -- C:\Windows\System32\win32k.sys [1549936]
O44 - LFC:[MD5.639774C9ACD063F028F6084ABF5593AD] - 23/11/2012 - 04:13:57 . (...) -- C:\Windows\System32\taskhost.exe [1549936]
~ Scan Files in 00mn 08s
---\\ Local Security Authority-LSA Deny (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - LiveSSP.) -- C:\Windows\System32\livessp.dll
~ Scan Keys in 00mn 00s
---\\ Safe Boot Control (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ Scan CSB in 00mn 00s
---\\ MountPoints2 Shell Key (MPKS) (O51)
O51 - MPSK:{a9fce8f3-743e-11e1-a5e6-406186eb4726}\AutoRun\command. (...) -- G:\WD SmartWare.exe (.not file.)
~ Scan Keys in 00mn 00s
---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ Scan Keys in 00mn 00s
---\\ ShareTools MSconfig StartupReg (SMSR) (O53) (None)
---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ Scan Keys in 00mn 00s
---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ Scan Keys in 00mn 00s
---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "EnableShellExecuteHooks"=1
~ Scan Keys in 00mn 00s
---\\ System Drivers List (SDL) (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
O58 - SDL:[MD5.306521935042FC0A6988D528643619B3] - 25/10/2007 - 16:26:10 ----- . (...) -- C:\Windows\SysWOW64\drivers\StarOpen.sys [5632]
O58 - SDL:[MD5.9131FE60ADFAB595C8DA53AD6A06AA31] - 02/01/2005 - 22:43:08 ----- . (.INCA Internet Co., Ltd. - nProtect NPSC Kernel Mode Driver for NT.) -- C:\Windows\SysWOW64\npptNT2.sys [4682]
~ Scan Drivers in 00mn 00s
---\\ List all tools cleaner (LATC) (O63)
O63 - Logiciel: ZHPDiag 1.32 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ Scan ADS in 00mn 00s
---\\ List all legacy services(LALS) (O64)
O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
O64 - Services: CurCS - 14/06/2010 - C:\Windows\system32\Drivers\TFsExDisk.sys (TFsExDisk) .(.Teruten Inc - File System Mini Filter Drvier.) - LEGACY_TFSEXDISK
~ Scan Services in 00mn 17s
---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: [HKCU\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Valentin\AppData\Local\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Valentin\AppData\Local\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
~ Scan Keys in 00mn 00s
---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Valentin\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- C:\Program Files (x86)\Safari\Safari.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Users\Valentin\AppData\Local\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files (x86)\Safari\Safari.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Users\Valentin\AppData\Local\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files (x86)\Safari\Safari.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Users\Valentin\AppData\Local\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files (x86)\Safari\Safari.exe (.not file.)
~ Scan Keys in 00mn 00s
---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {269F8860-F8D0-4350-83A2-C53A274A8763} - (Bing) -
http://www.bing.com
~ Scan Keys in 00mn 00s
---\\ Search Svchost Services (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [853504]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [679424]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316928]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [680960]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2428952]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70656]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [209920]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864]
~ Scan Services in 00mn 00s
---\\ Search Particular Root Folder (SPRF) (O84)
[MD5.75F8BC409A632D86022BC3EE172CF76D] [SPRF][02/05/2012] (...) -- C:\Users\Valentin\AppData\Local\Temp\defaultCache.reg [1469404]
[MD5.E8F0610061F5542431960BDC87BE9502] [SPRF][14/10/2012] (.Microsoft Corporation - Microsoft GDI+.) -- C:\Users\Valentin\AppData\Local\Temp\GdiPlus.dll [1712128]
[MD5.E6310E207EA8B2C69D5A1B03A1939752] [SPRF][14/10/2012] (.Samsung Electronics Co., Ltd. - Samsung New PC Studio Installer MessageBox.) -- C:\Users\Valentin\AppData\Local\Temp\InstallerMessageBox.exe [245760]
[MD5.F6959F0CACD35E5430B44F0876EFE55A] [SPRF][15/11/2011] (...) -- C:\Users\Valentin\AppData\Local\Temp\installhelper.dll [1508352]
[MD5.9835AF740C54D07808C5BCC0F4493114] [SPRF][13/04/2012] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Valentin\AppData\Local\Temp\jre-6u32-windows-i586-iftw.exe [910112]
[MD5.EC337BA6ACFCC996E81FC70213BD4C40] [SPRF][03/12/2012] (.Microsoft Corporation - Windows Live Installer.) -- C:\Users\Valentin\AppData\Local\Temp\msg49BC.exe [83249512]
[MD5.EC337BA6ACFCC996E81FC70213BD4C40] [SPRF][03/12/2012] (.Microsoft Corporation - Windows Live Installer.) -- C:\Users\Valentin\AppData\Local\Temp\msg5E84.exe [83249512]
[MD5.18BD318B7082A2A0775A106B9FEA955A] [SPRF][14/10/2012] (.Samsung Electronics Co., Ltd. - Samsung New PC Studio Installer.) -- C:\Users\Valentin\AppData\Local\Temp\NPSInstallerProxy.exe [708608]
[MD5.16F2DA0575483DE3179542D10DB31432] [SPRF][14/10/2012] (...) -- C:\Users\Valentin\AppData\Local\Temp\NPSInstallerProxyMessageBoxHookDll.dll [528384]
[MD5.992437F87CC34D001C0FC97DC434D125] [SPRF][14/05/2012] (.Aedge Performance BCN SL - OfferBox setup.) -- C:\Users\Valentin\AppData\Local\Temp\OB.exe [3174352]
[MD5.F94671573B5030F2508A6D3111FD82BD] [SPRF][14/05/2012] (...) -- C:\Users\Valentin\AppData\Local\Temp\OfferBoxSetup.exe [187344]
[MD5.36C193A91BCD55B3E268F643CBC35ADB] [SPRF][18/10/2012] (...) -- C:\Users\Valentin\AppData\Local\Temp\pool.bin [256]
[MD5.CB5E1A151A543F4A238DC60892FCD2B3] [SPRF][20/11/2012] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\Valentin\AppData\Local\Temp\Shortcut_Shortcut_sweetimsetup.exe [581464]
[MD5.CB5E1A151A543F4A238DC60892FCD2B3] [SPRF][20/11/2012] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\Valentin\AppData\Local\Temp\Shortcut_sweetimsetup.exe [581464]
[MD5.F888959350086A5C75976E4E97ED23CC] [SPRF][20/11/2012] (.SweetIM Technologies Lt - This installer.) -- C:\Users\Valentin\AppData\Local\Temp\SIMEEI2Installer.exe [2962432]
[MD5.7704B843006444B69486FD27D4660845] [SPRF][20/11/2012] (.SweetIM Technologies Lt - This installer.) -- C:\Users\Valentin\AppData\Local\Temp\SIMEEIInstaller.exe [3380216]
[MD5.72412B526BCC716382E62B7939DCFD8F] [SPRF][26/05/2011] (...) -- C:\Users\Valentin\AppData\Local\Temp\SRAssetsHelper.dll [1085952]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][14/01/2013] (...) -- C:\Users\Valentin\AppData\Roaming\wklnhst.dat [0]
[MD5.759D25973D9FDE36BB8BCB0932148B3F] [SPRF][20/11/2012] (.iH8sn0w - sn0wbreeze.) -- C:\Users\Valentin\Desktop\sn0wbreeze-v2.9.7.exe [25271296]
~ Scan Files in 00mn 40s
---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "WMPNSS-In-UDP-NoScope" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-UDP-NoScope" |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-In-UDP" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-UDP" |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "WMPNSS-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "{7C41DD0A-3EE1-4EB9-A750-DE6D4180F3A1}" |In - None - P6 - TRUE | .(...) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe (.not file.)
O87 - FAEL: "{AC4346BD-B898-4FA3-85C1-67EE3D563BF7}" |In - None - P6 - TRUE | .(...) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe (.not file.)
O87 - FAEL: "{B28B4EAA-A323-4AE8-8844-80E043511AE5}" |In - None - P6 - TRUE | .(...) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe (.not file.)
O87 - FAEL: "{B60612D5-0BD2-421B-92E9-1ECBBF6BEB36}" |In - None - P6 - TRUE | .(...) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe (.not file.)
O87 - FAEL: "{2C996D1C-DE13-4C37-9B51-4D632DA1AEEB}" |In - None - P6 - TRUE | .(...) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe (.not file.)
O87 - FAEL: "{D27A83B3-62D7-4A23-9E5C-14A0869F3C4E}" | In - None - P6 - TRUE | .(.CyberLink Corp. - HP DVDSmart Main Program.) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe
O87 - FAEL: "{93555C54-8097-42BC-8995-ED3BA81621B4}" |In - None - P6 - TRUE | .(...) -- c:\Program Files (x86)\CyberLink\PowerDirector\PDR.exe (.not file.)
O87 - FAEL: "{57ADEF37-93AB-4471-950E-0C848A480734}" | In - None - P6 - TRUE | .(.CyberLink Corp. - HP MediaSmart Music Main Program.) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Music\HPTouchSmartMusic.exe
O87 - FAEL: "{40569010-C4CD-41BE-8DC6-1AF0478EDF58}" | In - Public - P6 - TRUE | .(.EasyBits Software AS - EasyBits My First Browser.) -- C:\Program Files (x86)\EasyBits For Kids\Programs\My First Browser\MyFirstBrowser.exe
O87 - FAEL: "{8421B702-B0E2-4603-9985-3272F657ACD5}" | In - Public - P17 - TRUE | .(.EasyBits Software AS - EasyBits My First Browser.) -- C:\Program Files (x86)\EasyBits For Kids\Programs\My First Browser\MyFirstBrowser.exe
O87 - FAEL: "{FBC872C6-33CC-4D50-9C3C-059BDC12FBA4}" |Out - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "{CC0B0767-3D17-4DBF-8046-8010C34E1343}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "{A7BB4FC1-323C-47A8-A1C8-56D734F697DC}" |Out - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "{FA25E4F1-FE59-408F-AD80-CA502D00D039}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)
O87 - FAEL: "TCP Query User{9CFCE5A6-7CB7-4773-B0F7-95F5D956E68C}C:\program files (x86)\real\realplayer\realplay.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\real\realplayer\realplay.exe (.not file.)
O87 - FAEL: "UDP Query User{AD40004D-4369-4F59-821A-A68D66934140}C:\program files (x86)\real\realplayer\realplay.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\real\realplayer\realplay.exe (.not file.)
O87 - FAEL: "{5AE0FBA2-DD6A-4B77-A023-3204B2F3E7A1}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe (.not file.)
O87 - FAEL: "{69FCE97E-93A5-4110-8169-60662B06BB38}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe (.not file.)
O87 - FAEL: "{ADF9B45E-067F-47DD-8F46-F65E2A6B4848}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe (.not file.)
O87 - FAEL: "{236FFCFB-753D-477F-B3E3-5C0BADF30E2B}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsasvr.exe (.not file.)
O87 - FAEL: "{ACAFC985-E0E2-47B9-8D9C-781995609094}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe (.not file.)
O87 - FAEL: "{C85DD827-0B22-4C76-81F2-A121BD5C866A}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Samsung\Samsung New PC Studio\npsvsvr.exe (.not file.)
O87 - FAEL: "{98AB1C7F-2676-42C6-B21D-C0E6E33ED7B6}" | In - None - P17 - TRUE | .(.Apple Inc. - WebKit2WebProcess.exe.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
O87 - FAEL: "{1D320C62-62D6-43DC-84DA-5B36613DBC6F}" | In - Private - P6 - TRUE | .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files (x86)\Research In Motion\BlackBerry desktop\Rim.desktop.exe
O87 - FAEL: "{37DF1B80-2F62-486B-B15F-2A4687B5CA6E}" | In - Private - P17 - TRUE | .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files (x86)\Research In Motion\BlackBerry desktop\Rim.desktop.exe
O87 - FAEL: "{5FA05FBE-FC8F-4907-BA0D-2F0D98F9034E}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.)
O87 - FAEL: "{A3169030-21A1-45BE-8DE9-56505A7DB7BC}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.)
O87 - FAEL: "{24AFBD43-E10F-4F16-8993-B18186A3983F}" | In - Private - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{808AD640-07DF-4C78-9759-267B2BB6DD49}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{F962C2AE-4637-4DE3-8929-32117B59EFC7}" | In - Private - P6 - TRUE | .(...) -- C:\Windows\System32\ARFC\wrtc.exe
O87 - FAEL: "{05F45229-AD82-4D0B-93AD-0DDAB473EDDD}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\System32\ARFC\wrtc.exe
O87 - FAEL: "{928E31B4-9009-4D64-9F88-AE88E7063B0F}" | In - Public - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{EBB33685-45C4-4563-85D4-4CDBB455F3F6}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{C5737DB5-F7E5-4C3E-A2F6-EC203D057F28}" | In - Public - P6 - TRUE | .(...) -- C:\Windows\System32\ARFC\wrtc.exe
O87 - FAEL: "{B9F12A95-2DDE-472F-B38C-6FD4CAE2F4CF}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\System32\ARFC\wrtc.exe
O87 - FAEL: "{E42DF436-ED1A-4D84-AE05-AA5901E46132}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe
~ Scan Firewall in 00mn 01s
---\\ Additionnal Scan (O88)
Database Version : v2.10033 - (09/01/2013)
Clés trouvées (Keys found) : 15
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 6
[HKLM\Software\Wow6432Node\Google\Chrome\Extensions\niogeckbkdcabhnapjbkeiklablhjoca] =Adware.IncrediBar
[HKLM\Software\Classes\Installer\Features\AF2CF8FE20EBB4443855807CA5D6E7A3] =Adware.Boxore
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AF2CF8FE20EBB4443855807CA5D6E7A3] =Adware.Boxore
[HKLM\Software\Wow6432Node\Classes\Installer\Features\AF2CF8FE20EBB4443855807CA5D6E7A3] =Adware.Boxore
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater] =Toolbar.Wajam
[HKLM\Software\WNLT] =Adware.IncrediBar
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{953AA732-9AFB-49C9-84A4-7F96CA0A08DA}] =PUP.SweetIM
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASAPI32] =PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASMANCS] =PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASAPI32] =PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASMANCS] =PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxUpdateService_RASAPI32] =PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxUpdateService_RASMANCS] =PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32] =Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASMANCS] =Toolbar.Agent
C:\Users\Valentin\AppData\LocalLow\Conduit =Toolbar.Conduit
C:\Users\Valentin\AppData\Local\Temp\Shortcut_Shortcut_sweetimsetup.exe
C:\Users\Valentin\AppData\Local\Temp\Shortcut_sweetimsetup.exe
C:\Users\Valentin\AppData\Local\Temp\SweetIESetup.exe.7z
C:\Users\Valentin\AppData\Local\Temp\SweetIMSetup.exe.7z
C:\Users\Valentin\AppData\Local\Temp\SIMEEI2Installer.exe
C:\Users\Valentin\AppData\Local\Temp\SIMEEIInstaller.exe
~ Scan Additionnel in 00mn 26s
---\\ Product Upgrade Codes (O90)
O90 - PUC: "000021090200C0400000000000F01FEC" . (.Module de compatibilité pour Microsoft Office System 2007.) -- c:\Windows\Installer\{90120000-0020-040C-0000-0000000FF1CE}\O12ConvIcon.exe
O90 - PUC: "00002159FA00C0400000000000F01FEC" . (.Microsoft Office PowerPoint Viewer 2007 (French).) -- c:\Windows\Installer\{95120000-00AF-040C-0000-0000000FF1CE}\ppvwicon.exe,0
O90 - PUC: "0694AF70830BBE9498B1F95939A05A44" . (.HP Customer Experience Enhancements.) -- C:\Windows\Installer\{07FA4960-B038-49EB-891B-9F95930AA544}\ARPPRODUCTICON.exe
O90 - PUC: "0C7EC0FA4E3A37D489B82B1978CEE6A9" . (.QuickTime.) -- C:\Windows\Installer\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}\Installer.ico
O90 - PUC: "168061B30527E1545BEEB829FB037A01" . (.Microsoft Works.) -- c:\Windows\Installer\{3B160861-7250-451E-B5EE-8B92BF30A710}\MSWorks.exe
O90 - PUC: "18143A19DAF9BA343AF57E8A49B5E7C1" . (.HP.) -- c:\Windows\Installer\{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}\ARPPRODUCTICON.exe
O90 - PUC: "19907B7920051424B8C07DB4A8ED2B5B" . (.BlackBerry Desktop Software 7.1.) -- C:\Windows\Installer\{97B70991-5002-4241-8B0C-D74B8ADEB2B5}\ARPPRODUCTICON.exe
O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\Windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon
O90 - PUC: "2B7C128712E73FC429B5856B8ACB3611" . (.LibreOffice 3.4.) -- C:\Windows\Installer\{7821C7B2-7E21-4CF3-925B-58B6A8BC6311}\soffice.ico
O90 - PUC: "36F7E47EF07E2f3478F353BF662F362B" . (.MusicStation.) -- C:\Windows\Installer\{E74E7F63-E70F-43f2-873F-35FB66F263B2}\ARPPRODUCTICON.exe
O90 - PUC: "46B5A9879DD95AB419A50FCFA0B1B7EF" . (.Apple Software Update.) -- C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\Installer.ico
O90 - PUC: "4F42BC0DF480ED046B9B0A63626E280F" . (.iCloud.) -- C:\Windows\Installer\{D0CB24F4-084F-40DE-B6B9-A03626E682F0}\ARP.ico
O90 - PUC: "53FA80B5996B44A4BB98E3157E60118E" . (.HP MediaSmart SmartMenu.) -- C:\Windows\Installer\{5B08AF35-B699-4A44-BB89-3E51E70611E8}\SmartMenuIcon
O90 - PUC: "68AB67CA7DA76301B744AA0100000010" . (.Adobe Reader X (10.1.4) - Français.) -- C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AA1000000001}\SC_Reader.ico
O90 - PUC: "782BB4BF9F7372E4C9D4D283280EE8FF" . (.HP.) -- c:\Windows\Installer\{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}\ARPPRODUCTICON.exe
O90 - PUC: "7C43C21609E58D74B9C5F017D78D7262" . (.swMSM.) -- C:\Windows\Installer\{612C34C7-5E90-47D8-9B5C-0F717DD82726}\ARPPRODUCTICON.exe
O90 - PUC: "91785D291CBB3CC40AB8659C8E48CCC2" . (.Microsoft_VC80_CRT_x86.) -- C:\Windows\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe
O90 - PUC: "93FDBE4833B47D940ADBBEE6C2E4181C" . (.Windows Live Sync.) -- C:\Windows\Installer\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}\FolderShare48x48.ico
O90 - PUC: "970DACCDC29FAD442B8526F46C15A7A5" . (.MediaSmart DVD.) -- c:\Windows\Installer\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\ARPPRODUCTICON.exe
O90 - PUC: "9EE58E3C298524145B73CBBED3CAC4D3" . (.Internet Explorer Toolbar 4.6 by SweetPacks.) -- C:\Windows\Installer\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}\ARPPRODUCTICON.exe
O90 - PUC: "ADBE3203B1FB13843B745E1058552FE6" . (.HP.) -- c:\Windows\Installer\{3023EBDA-BF1B-4831-B347-E5018555F26E}\ARPPRODUCTICON.exe
O90 - PUC: "AE48807DEC2E935419BD7466CCE1F5F5" . (.Apple Mobile Device Support.) -- C:\Windows\Installer\{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}\Installer.ico
O90 - PUC: "B0F57C6D1CB39CF48B5CF3E7E80D95AC" . (.Windows Live Photo Gallery.) -- C:\Windows\Installer\{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}\WLXPhotoGalleryIcon.exe
O90 - PUC: "B2FD9C0A5B9838449838816A28001F4B" . (.SweetIM for Messenger 3.7.) -- C:\Windows\Installer\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}\ARPPRODUCTICON.exe
O90 - PUC: "B55DF58AB1984134795AAE690CDB085B" . (.Windows Live Messenger.) -- C:\Windows\Installer\{A85FD55B-891B-4314-97A5-EA96C0BD80B5}\MsblIco.Exe
O90 - PUC: "B846977CE014ABB47BB58551CBFE7ED1" . (.Safari.) -- C:\Windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\Installer.ico
O90 - PUC: "BA0A2B44E214C8F40B851D8EEACCFD5F" . (.PowerRecover.) -- c:\Windows\Installer\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\ARPPRODUCTICON.exe
O90 - PUC: "BD528ECCA74340041A68F5A4F6DD5874" . (.Apple Application Support.) -- C:\Windows\Installer\{CCE825DB-347A-4004-A186-5F4A6FDD8547}\WinInstall.ico
O90 - PUC: "BE31195E5820DFB43AA77BE9CAB6F8B4" . (.Microsoft SQL Server Compact 3.5 SP1 English.) -- C:\Windows\Installer\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}\ProductIcon
O90 - PUC: "C3A8A5940DF864C49997592C16181ABA" . (.HP Support Assistant.) -- C:\Windows\Installer\{495A8A3C-8FD0-4C46-9979-95C26181A1AB}\ARPPRODUCTICON.exe
O90 - PUC: "C7D8BF048FF62FA4CBB8B0D13BA20FB4" . (.HP Advisor.) -- C:\Windows\Installer\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}\ARPPRODUCTICON.exe
O90 - PUC: "CA0B84B9318C4714092474A68857297C" . (.Windows Live ID Sign-in Assistant.) -- C:\Windows\Installer\{9B48B0AC-C813-4174-9042-476A887592C7}\prodicon.ico
O90 - PUC: "CDC8FAD640B9B3140A2FCB1CC38F5AFB" . (.MediaSmart Photo.) -- c:\Windows\Installer\{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}\ARPPRODUCTICON.exe
O90 - PUC: "D366E3D3E7E477545A06E7DCDD5445A8" . (.PVSonyDll.) -- C:\Windows\Installer\{3D3E663D-4E7E-4577-A560-7ECDDD45548A}\ARPPRODUCTICON.exe
O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon
O90 - PUC: "DA67D5E0BF3A5D84480098301B30713D" . (.iTunes.) -- C:\Windows\Installer\{0E5D76AD-A3FB-48D5-8400-8903B10317D3}\Installer.ico
O90 - PUC: "DDB6C50237B7ED245850A990F3532A83" . (.Windows Live Upload Tool.) -- C:\Windows\Installer\{205C6BDD-7B73-42DE-8505-9A093F35A238}\RichUpload.ico
O90 - PUC: "ECEC214627185EB439B5C6CECA2DAC78" . (.Windows Live Mail.) -- C:\Windows\Installer\{6412CECE-8172-4BE5-935B-6CECACD2CA87}\wlmail.exe
O90 - PUC: "ED2388710ED978C4F92839519A0B9358" . (.Windows Live Writer.) -- C:\Windows\Installer\{178832DE-9DE0-4C87-9F82-9315A9B03985}\ApplicationIcon.ico
O90 - PUC: "F7E3E21D31B133949A51617CDD730A59" . (.MediaSmart Video.) -- c:\Windows\Installer\{D12E3E7F-1B13-4933-A915-16C7DD37A095}\ARPPRODUCTICON.exe
O90 - PUC: "FA674C8157468F9478183209EF05EE76" . (.LibreOffice 3.4 Help Pack (French).) -- C:\Windows\Installer\{18C476AF-6475-49F8-8781-2390FE50EE67}\soffice.ico
O90 - PUC: "FD97738F5F1E2A347AEB37F258F6DA7B" . (.Microsoft SQL Server Compact 3.5 SP1 x64 English.) -- C:\Windows\Installer\{F83779DF-E1F5-43A2-A7BE-732F856FADB7}\ProductIcon
~ Scan Files in 00mn 00s
---\\ MyComputer Name Space (O92)
O92 - MNS: Flux de photos - {F0D63F85-37EC-4097-B30D-61B4A8917118}
~ Scan MNS in 00mn 00s
---\\ General States of Services not Microsoft (EGS) (SR:='Running, SS:='Stopped)
SR - | Auto 27/07/2012 63960 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SS - | Demand 09/01/2013 251400 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 11/08/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/12/1899 0 | (ezSharedSvc) . (.EasyBits Software AS.) - C:\Windows\System32\ezSharedSvcHost.exe
SS - | Demand 04/01/2010 238328 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
SS - | Auto 14/11/2012 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 14/11/2012 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SR - | Auto 15/10/2009 120832 | (HP Health Check Service) . (.Hewlett-Packard.) - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
SS - | Demand 30/04/2009 229944 | (hpqwmiex) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
SR - | Demand 12/12/2012 641504 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 30/12/1899 0 | (npggsvc) . (.INCA Internet Co., Ltd..) - C:\Windows\system32\GameMon.des
SR - | Auto 08/08/2010 159336 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SS - | Demand 0 | (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) . (...) - c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms
SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Scan Services in 00mn 27s
End of the scan (1197 lines in 03mn 13s)(0)
voila !
a+[/size]