ComboFix 08-11-06.01 - Flo 2008-11-13 16:39:29.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1594 [GMT 1:00]
Lancé depuis: C:\Users\Flo\Desktop\Flolcho.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-13 au 2008-11-13 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-12 18:28 --------- d-----w C:\Program Files\Navilog1
2008-11-12 11:18 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-11-12 11:17 --------- d-----w C:\Users\Flo\AppData\Roaming\Malwarebytes
2008-11-12 11:17 --------- d-----w C:\ProgramData\Malwarebytes
2008-11-11 22:01 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-11-11 22:01 22,328 ----a-w C:\Users\Flo\AppData\Roaming\PnkBstrK.sys
2008-11-11 22:01 103,736 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-11-11 22:00 669,184 ----a-w C:\Windows\System32\pbsvc.exe
2008-11-11 21:59 --------- d-----w C:\ProgramData\Media Center Programs
2008-11-11 21:44 --------- d-----w C:\Program Files\Electronic Arts
2008-11-10 11:36 --------- d-----w C:\Program Files\GameSpy
2008-11-07 17:51 --------- d-----w C:\Program Files\MSN Messenger
2008-11-06 20:33 --------- d-----w C:\Users\Flo\AppData\Roaming\U3
2008-11-02 19:42 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-10-31 18:10 --------- d-----w C:\Users\Flo\AppData\Roaming\foobar2000
2008-10-29 15:22 --------- d-----w C:\Program Files\InstallShield Installation Information
2008-10-29 15:21 --------- d-----w C:\Program Files\Veoh Networks
2008-10-29 13:42 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-10-29 13:42 --------- d-----w C:\Program Files\Launch Manager
2008-10-29 13:42 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-10-29 13:42 --------- d-----w C:\Program Files\Java
2008-10-29 13:41 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-10-29 13:41 --------- d-----w C:\Program Files\Windows Journal
2008-10-29 13:41 --------- d-----w C:\Program Files\Intel
2008-10-26 15:42 2,606 ----a-w C:\Users\Flo\AppData\Roaming\wklnhst.dat
2008-10-22 15:10 38,496 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-10-16 18:50 --------- d-----w C:\Program Files\Windows Mail
2008-10-16 10:15 --------- d-----w C:\ProgramData\Microsoft Help
2008-10-15 21:26 --------- d-----w C:\Users\Flo\AppData\Roaming\Media Center Programs
2008-10-10 17:16 --------- d-----w C:\Program Files\Common Files\Steam
2008-10-05 19:48 --------- d-----w C:\ProgramData\Apple Computer
2008-10-05 19:48 --------- d-----w C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-02 03:49 827,392 ----a-w C:\Windows\System32\wininet.dll
2008-09-30 09:30 --------- d-----w C:\ProgramData\Lavasoft
2008-09-30 09:26 --------- d-----w C:\Program Files\Lavasoft
2008-09-30 09:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-30 09:14 --------- d-----w C:\ProgramData\VadeRetro
2008-09-30 09:11 --------- d-----w C:\Users\Flo\AppData\Roaming\VadeRetro
2008-09-18 05:09 3,601,464 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-09-18 04:56 147,456 ----a-w C:\Windows\System32\Faultrep.dll
2008-09-18 04:56 125,952 ----a-w C:\Windows\System32\wersvc.dll
2008-09-18 02:16 2,032,640 ----a-w C:\Windows\System32\win32k.sys
2008-09-17 15:52 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-17 15:44 --------- d-----w C:\Program Files\Bonjour
2008-08-29 08:18 87,336 ----a-w C:\Windows\System32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w C:\Windows\System32\dnssd.dll
2008-06-06 09:57 174 --sha-w C:\Program Files\desktop.ini
2007-12-08 09:52 225,280 ----a-w C:\Users\Flo\AppData\Roaming\Rewire.dll
2002-08-26 17:54 327,680 ----a-r C:\Users\Flo\AppData\Roaming\MafiaSetup.exe
.
((((((((((((((((((((((((((((( snapshot@2008-11-08_ 0.47.46.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-11 21:59:54 9,662 ----a-r C:\Windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\ARPPRODUCTICON.exe
- 2007-12-25 01:42:56 10,134 ----a-r C:\Windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\checkForUpdatesSC_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2008-11-11 21:59:55 10,134 ----a-r C:\Windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\checkForUpdatesSC_000E79B7E7254F01870AC12942B7F8E4.exe
- 2007-12-25 01:42:56 10,134 ----a-r C:\Windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2008-11-11 21:59:55 10,134 ----a-r C:\Windows\Installer\{000E79B7-E725-4F01-870A-C12942B7F8E4}\visitWebsite_000E79B7E7254F01870AC12942B7F8E4.exe
+ 2008-11-10 11:36:54 57,344 ----a-r C:\Windows\Installer\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}\ARPPRODUCTICON.exe
+ 2008-11-10 11:36:54 57,344 ----a-r C:\Windows\Installer\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}\Comrade.exe_CD7D16AA9DCA4A66A4ABF9C1BE60B1B5.exe
+ 2008-11-10 11:36:54 57,344 ----a-r C:\Windows\Installer\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}\NewShortcut7_CD7D16AA9DCA4A66A4ABF9C1BE60B1B5.exe
+ 2008-11-10 11:36:54 57,344 ----a-r C:\Windows\Installer\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}\NewShortcut8_CD7D16AA9DCA4A66A4ABF9C1BE60B1B5.exe
+ 2008-11-10 11:36:54 8,854 ----a-r C:\Windows\Installer\{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}\UNINST_Uninstall_Com_CD7D16AA9DCA4A66A4ABF9C1BE60B1B5.exe
- 2008-11-07 23:29:12 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-11-13 15:30:45 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-11-13 15:30:45 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-11-07 23:29:53 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-11-13 15:30:45 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-11-13 15:30:45 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-11-07 23:30:22 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-11-13 14:34:08 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-11-07 23:30:22 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-13 14:34:08 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-07 23:30:22 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-13 14:34:08 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-02 17:40:53 75,072 ----a-w C:\Windows\System32\drivers\avipbb.sys
+ 2008-11-13 14:35:16 75,072 ----a-w C:\Windows\System32\drivers\avipbb.sys
- 2008-10-16 18:52:53 314,616 ----a-w C:\Windows\System32\FNTCACHE.DAT
+ 2008-11-12 21:40:43 316,656 ----a-w C:\Windows\System32\FNTCACHE.DAT
- 2008-11-07 23:34:47 105,276 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-11-13 15:12:09 105,276 ----a-w C:\Windows\System32\perfc009.dat
- 2008-11-07 23:34:47 128,418 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-11-13 15:12:09 128,418 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-11-07 23:34:47 595,946 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-11-13 15:12:09 595,946 ----a-w C:\Windows\System32\perfh009.dat
- 2008-11-07 23:34:47 679,418 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-11-13 15:12:09 679,418 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-11-03 01:09:41 6,553,600 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
+ 2008-11-13 14:45:57 6,553,600 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
- 2008-11-07 23:30:08 12,080 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-722847408-4120334268-1447528841-1000_UserData.bin
+ 2008-11-13 15:07:43 12,270 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-722847408-4120334268-1447528841-1000_UserData.bin
- 2008-11-07 23:30:08 82,960 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-11-13 15:07:43 83,180 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-11-07 23:30:07 61,874 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-11-13 15:07:41 62,170 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-11-07 17:44:58 287,522 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-11-13 13:52:08 290,022 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2008-11-07 15:17:12 262,870 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2008-11-11 17:37:28 265,286 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
- 2008-11-02 19:35:14 91,656,472 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-11-13 11:21:59 93,486,364 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2006-11-02 09:41:09 2,048 ----a-w C:\Windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18136_none_8853d47896e90b40\msxml3r.dll
+ 2006-11-02 09:41:09 2,048 ----a-w C:\Windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.18138_none_885590b496e78ad1\msxml6r.dll
+ 2008-09-15 22:27:41 2,413,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16764_none_f064ff046e80cc5f\OESpamFilter.dat
+ 2008-09-15 22:27:41 2,413,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20937_none_f1120e5787836182\OESpamFilter.dat
+ 2008-09-15 22:27:41 2,413,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18157_none_f2590e746b9c8d64\OESpamFilter.dat
+ 2008-09-15 22:27:41 2,413,072 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22288_none_f2c33bc584d19a58\OESpamFilter.dat
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 08:33 1233920]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 11:55 5674352]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 08:33 125952]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-09-26 19:14 3660848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-05-09 10:36 1286144]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-12 17:42 457728]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-04-04 08:02 678672]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-09-02 18:40 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 03:27 144784]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-11-07 13:57 159744]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-10 10:10 4468736 C:\Windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2001-01-10 19:37:37 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"EnableUIADesktopToggle"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=eNetHook.dll
[HKLM\~\startupfolder\C:^Users^Flo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Téléchargez gratuitement 2 titres audios.lnk]
path=C:\Users\Flo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Téléchargez gratuitement 2 titres audios.lnk
backup=C:\Windows\pss\Téléchargez gratuitement 2 titres audios.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
--a------ 2007-02-15 18:39 151552 C:\Acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 19:12 111936 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-12-31 15:29 962560 C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
--a------ 2007-06-29 15:03 36864 C:\Program Files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
--a------ 2006-06-12 13:32 700416 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2007-02-06 00:52 849280 C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 D:\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
--------- 2007-05-03 10:16 206952 C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
--a------ 2007-03-09 17:51 45056 C:\Windows\PLFSet.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 11:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-10-10 18:14 1410296 D:\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-06-16 20:36 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2008-09-26 19:14 3660848 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
--a------ 2006-11-05 20:48 57344 C:\Acer\WR_PopUp\WarReg_PopUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
--a------ 2007-05-07 11:51 1826816 C:\Windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F4F6F825-4E89-486A-8B95-3192340F817A}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{28276C90-044D-4DD6-8E4D-FC3B032F02B6}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{3B2A64A9-C232-4765-AE81-D5C8F5CE7259}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{0F36CD92-4215-41E1-8427-8FDC82BC297D}"= C:\Program Files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{E3AD86A2-0361-4E7B-9E46-FCC6BCEB485D}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{C2DA6328-0705-499B-B8E6-95D7426FAB66}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6EF6711E-5547-43D9-84B2-2BAD84EAF4ED}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DAB198F0-26F2-4555-B0C1-37E127744911}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{9767B165-41D9-456E-AB57-2E66087E7BD5}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{4E5258EA-245A-458B-9B16-85083C48C43D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{122424D4-7311-463A-A17D-40363CA4347F}C:\\program files\\sierra\\fear\\fpupdate.exe"= UDP:C:\program files\sierra\fear\fpupdate.exe:fpupdate
"UDP Query User{6C102FC5-0343-4E8E-89B0-CFA130555EA2}C:\\program files\\sierra\\fear\\fpupdate.exe"= TCP:C:\program files\sierra\fear\fpupdate.exe:fpupdate
"{3F29F6A6-2EA9-40C8-8261-F7425A46B247}"= UDP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"{F3D958A2-6F5C-40B4-8A12-714DD517B125}"= TCP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"{89027A54-1984-4FA3-BA6D-2AD9A89CD7F7}"= UDP:C:\Program Files\Sierra\FEAR\FEARMP.exe:FEAR
"{2F71E015-E287-4E0E-8DB9-D97C73186968}"= TCP:C:\Program Files\Sierra\FEAR\FEARMP.exe:FEAR
"TCP Query User{9B64581C-48F5-43FA-BDBC-06CB811F3274}C:\\users\\flo\\desktop\\warcraft iii\\war3.exe"= UDP:C:\users\flo\desktop\warcraft iii\war3.exe:war3.exe
"UDP Query User{A7E3EC21-CD48-4020-BF54-6FE1EE355EE3}C:\\users\\flo\\desktop\\warcraft iii\\war3.exe"= TCP:C:\users\flo\desktop\warcraft iii\war3.exe:war3.exe
"TCP Query User{FC06F41F-FF66-47A1-A21D-9A939DDF0DDA}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{195C577B-2E76-4923-95E9-93B1753D7F1F}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"TCP Query User{F795ECD2-920F-45D2-A0BB-08477C410A71}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{7BE6A109-275B-42F6-A2D4-026FDD2C83E9}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{339CA8F2-5B1D-4D36-9D77-D1001F2F4E1F}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{014317EC-0E19-4DB4-A5FA-F45D33193401}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{9EB34EFD-2CA2-4567-BC5D-5D17A3B0249D}"= UDP:C:\Program Files\FrostWire\FrostWire.exe:LimeWire
"{68C4A4F3-C626-4FFF-9004-09790793C410}"= TCP:C:\Program Files\FrostWire\FrostWire.exe:LimeWire
"TCP Query User{FC38239E-75F7-4862-8F1F-31F3E5024740}C:\\program files\\ares\\ares.exe"= UDP:C:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{6CC855A6-F0B4-483C-94B6-021DCE5BF439}C:\\program files\\ares\\ares.exe"= TCP:C:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{D0FD599F-F5E2-4AF6-A1F4-FECA401DD328}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{E36DAD49-562D-457B-BAAD-B95B97A15D71}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"{69901ECF-7CF6-42B8-9C1B-7515CB4FBE93}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{7FD5DBEB-CD62-49ED-9F14-ADA4129AA981}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{98C4AC8E-66EF-420B-83DD-3B95D9F200F9}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{C2D1729F-76B6-4332-B977-DF8DA5FB9E36}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{00CDF089-CFF7-475D-9F29-32DEB5FADB06}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F0544D17-C479-4809-B66A-534A9FAFA06A}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"TCP Query User{631BBB20-AB60-4163-9DF1-C191B5D7BAA2}D:\\sierra\\arcanum\\arcanum.exe"= UDP:D:\sierra\arcanum\arcanum.exe:Arcanum
"UDP Query User{A457EF4F-B9D5-413F-9268-D950D1043395}D:\\sierra\\arcanum\\arcanum.exe"= TCP:D:\sierra\arcanum\arcanum.exe:Arcanum
"TCP Query User{31CC1357-B7F6-4D0D-A78A-24587F6FBA55}D:\\silverfall\\silverfall.exe"= UDP:D:\silverfall\silverfall.exe:Silverfall
"UDP Query User{FCFE2935-77BE-4379-9B71-A1AF4D98CB25}D:\\silverfall\\silverfall.exe"= TCP:D:\silverfall\silverfall.exe:Silverfall
"TCP Query User{6FF68CFA-6A8A-4B0A-9424-0FBDFE27D4E9}D:\\program files\\mohaa.exe"= UDP:D:\program files\mohaa.exe:Medal of Honor Allied Assault(tm)
"UDP Query User{0E0AB83A-BE4C-4A8E-81A9-416809FAAC2F}D:\\program files\\mohaa.exe"= TCP:D:\program files\mohaa.exe:Medal of Honor Allied Assault(tm)
"TCP Query User{07B1DAEC-C190-496B-A2B7-07AE5081FE2A}C:\\program files\\share 1.0 ex2\\share.exe"= UDP:C:\program files\share 1.0 ex2\share.exe:Share
"UDP Query User{B6DA4B94-7AED-4E71-A76A-8475D274539F}C:\\program files\\share 1.0 ex2\\share.exe"= TCP:C:\program files\share 1.0 ex2\share.exe:Share
"TCP Query User{EEF72A69-6FAD-4996-B9AE-DBA18B3BBEDA}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{BD400E3E-A192-4C93-BF2F-8B3E3878AAA2}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"{8FE9B927-47CF-4551-9C02-00E65CED0738}"= UDP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{F49326FE-D15F-48C9-B0CA-ED1BEA0C4967}"= TCP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{D716ABE6-E83F-413A-B9CA-A6DE64132AED}"= UDP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{21EFADC3-5AEC-4660-A875-73215A131F68}"= TCP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"TCP Query User{31CE8ADD-765D-4427-8337-AC5F4BA26F6E}D:\\sierra\\fpupdate.exe"= UDP:D:\sierra\fpupdate.exe:fpupdate
"UDP Query User{FEA701E8-DFF5-41B0-A6E7-C3B11FDD0F90}D:\\sierra\\fpupdate.exe"= TCP:D:\sierra\fpupdate.exe:fpupdate
"{A27F36B2-63D9-43A3-90DC-DC504233C7BB}"= UDP:D:\Sierra\FEAR.exe:FEAR
"{BB81289D-8B7B-466E-B7B3-0175F7EA6545}"= TCP:D:\Sierra\FEAR.exe:FEAR
"{0F57C1B9-4A12-4B0B-9A21-F102F0AC339E}"= UDP:D:\Sierra\FEARMP.exe:FEAR
"{60A939F9-BAB0-4B0D-98DF-F4BBC8B024E3}"= TCP:D:\Sierra\FEARMP.exe:FEAR
"{03593397-AB84-4B7C-A6F5-FE8DF42299BE}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{341C5ECD-6D5B-4DE2-A0AA-48508DD99296}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{2B024841-3B16-4683-9472-D32AA5DC5140}"= UDP:D:\iTunes.exe:iTunes
"{459D8120-2DB2-45F2-A1CB-006BB1E530A7}"= TCP:D:\iTunes.exe:iTunes
"{A9E7A095-F1BE-4294-9F06-4BBED3751B24}"= UDP:D:\Steam.exe:Steam Client
"{15433B62-C71F-4F3B-9962-1F4D1E4C858A}"= TCP:D:\Steam.exe:Steam Client
"{2D5EC84C-860A-4BBB-801B-B87AA9C9B85C}"= UDP:D:\SteamApps\common\Lost Planet Extreme Condition\LostPlanetDx10.exe:LostPlanetDX10
"{454E749D-B41B-4DA8-AFF3-6D74874034AA}"= TCP:D:\SteamApps\common\Lost Planet Extreme Condition\LostPlanetDx10.exe:LostPlanetDX10
"{8A643186-2B0D-447F-B28A-4987CD18EEB1}"= UDP:D:\SteamApps\common\Lost Planet Extreme Condition\LostPlanetDx9.exe:LostPlanetDX9
"{E21FC015-7358-4C73-BEBE-1E6142E36D07}"= TCP:D:\SteamApps\common\Lost Planet Extreme Condition\LostPlanetDx9.exe:LostPlanetDX9
"TCP Query User{75CE2E7B-F9B4-4082-9F7C-7F97E03DAA4D}C:\\users\\flo\\desktop\\crack\\lostplanetdx9.exe"= UDP:C:\users\flo\desktop\crack\lostplanetdx9.exe:lostplanetdx9.exe
"UDP Query User{DF78125E-7BB5-4068-B436-E081ABEDE197}C:\\users\\flo\\desktop\\crack\\lostplanetdx9.exe"= TCP:C:\users\flo\desktop\crack\lostplanetdx9.exe:lostplanetdx9.exe
"TCP Query User{06FF240D-1B2B-4FDF-BE90-0849A82F268F}D:\\emule\\emule.exe"= UDP:D:\emule\emule.exe:eMule
"UDP Query User{A2C311DC-4BC8-494A-BEF9-173E42B2D6CE}D:\\emule\\emule.exe"= TCP:D:\emule\emule.exe:eMule
"TCP Query User{713A7383-3372-4590-9FF8-0ADABD77705E}C:\\users\\flo\\desktop\\lost.planet.extreme.condition-unleashed-crack\\crack\\lostplanetdx9.exe"= UDP:C:\users\flo\desktop\lost.planet.extreme.condition-unleashed-crack\crack\lostplanetdx9.exe:lostplanetdx9.exe
"UDP Query User{859192F2-D95A-425E-A83E-FC2B9BB3DEF0}C:\\users\\flo\\desktop\\lost.planet.extreme.condition-unleashed-crack\\crack\\lostplanetdx9.exe"= TCP:C:\users\flo\desktop\lost.planet.extreme.condition-unleashed-crack\crack\lostplanetdx9.exe:lostplanetdx9.exe
"{3A67F3BA-0B62-4EF8-AB04-44699B9F5649}"= UDP:D:\LimeWire\LimeWire.exe:LimeWire
"{AA4B6CD9-E02C-4A14-83C3-C7C35547BBE1}"= TCP:D:\LimeWire\LimeWire.exe:LimeWire
"{E9D5E634-0544-4DDF-A67B-9C67DC70EC3B}"= UDP:D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{DAC83187-4696-49C2-9C59-1EC38885DB69}"= TCP:D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{364E0036-DAAD-4894-902A-AD71D526E1AD}"= UDP:D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{4CCE181F-D61E-4EB6-8697-ACE12E7C08F5}"= TCP:D:\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{A1864EB5-79E5-4ECA-A429-6FB1F36A085F}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{77347962-34A9-4B04-95B2-BA262699205B}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{BAACB067-D100-4174-BD46-07459D62ED10}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{8E8CC5FC-FA5B-4CF4-9B12-D44AA9CFA443}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{A6C8C247-211C-4C7F-86C0-A5F74CA3AE43}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys [2007-03-07 09:26 32256]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-02 15:51 13560]
S2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-01-26 14:24 50688]
S3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-05-04 15:19 2591232]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-02-08 08:03 179712]
S3 PMUSB2G;PassMark® Software USB 2.0 Loopback plug;C:\Windows\system32\Drivers\PMUSB.sys [2004-11-25 16:11 18944]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-10-10 18:14 87288]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4fb4f2c1-1d06-11dc-a2e6-806e6f6e6963}]
\shell\AutoRun\command - F:\AutoRunCD.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ef4b407-30df-11dd-9859-0019d2c4c165}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d40ab10-746a-11dd-942d-0019d2c4c165}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
*Newly Created Service* - ECACHE
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-RunOnce-<NO NAME> - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Users\Flo\AppData\Roaming\Mozilla\Firefox\Profiles\t2p94jkv.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.