Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rapport de ZHPDiag v1.31.095 par Nicolas Coolman, Update du 24/05/2012
- Run by TheFireNight at 29/05/2012 12:35:55
- Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
- Web site : http://nicolascoolman.skyrock.com/
- State : Version à jour.
- ---\\ Web Browser
- MSIE: Internet Explorer v
- ---\\ Windows Product Information
- ~ Langage: Français
- Windows 7 Ultimate Edition, 64-bit Service Pack 1 (Build 7601)
- Windows Server License Manager Script : OK
- ~ Windows(R) 7, OEM_SLP channel
- System Locked Preinstallation (OEM_SLP) : OK
- Windows ID Activation : OK
- ~ Windows Partial Key : 2C9T3
- Windows License : OK
- ~ Windows Remaining Initializations Number : 3
- Software Protection Service (Protection logicielle) : KO
- Windows Automatic Updates : OK
- Windows Activation Technologies : OK
- ---\\ System Information
- ~ Processor: Intel64 Family 6 Model 30 Stepping 5, GenuineIntel
- ~ Operating System: 64 Bits
- Boot mode: Normal (Normal boot)
- Total RAM: 16382 MB (80% free)
- System Restore: Inconnu (Unknown)
- System drive C: has 372 GB (44%) free of 839 GB
- ---\\ Logged in mode
- ~ Computer Name: THEFIRENIGHT-PC
- ~ User Name: TheFireNight
- ~ All Users Names: UpdatusUser, TheFireNight, HomeGroupUser$, Administrateur,
- ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
- Logged in as Administrator
- ---\\ Environnement Variables
- ~ System Unit : C:\
- ~ %AppData% : C:\Users\TheFireNight\AppData\Roaming\
- ~ %Desktop% : C:\Users\TheFireNight\Desktop\
- ~ %Favorites% : C:\Users\TheFireNight\Favorites\
- ~ %LocalAppData% : C:\Users\TheFireNight\AppData\Local\
- ~ %StartMenu% : C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\
- ~ %Windir% : C:\Windows\
- ~ %System% : C:\Windows\System32\
- ---\\ DOS/Devices
- C:\ Hard drive, Flash drive, Thumb drive (Free 372 Go of 839 Go)
- D:\ Hard drive, Flash drive, Thumb drive (Free 673 Go of 1024 Go)
- E:\ Hard drive, Flash drive, Thumb drive (Free 76 Go of 181 Go)
- F:\ Hard drive, Flash drive, Thumb drive (Free 714 Go of 932 Go)
- G:\ Hard drive, Flash drive, Thumb drive (Free 4 Go of 115 Go)
- H:\ CD-ROM drive (Not Inserted)
- I:\ CD-ROM drive (Free 0 Go of 0 Go)
- J:\ CD-ROM drive (Not Inserted)
- K:\ Floppy drive, Flash card reader, USB Key (Free 1 Go of 2 Go)
- ---\\ Security Center & Tools Informations
- ~ Scan Security Center in 00mn 00s
- ---\\ Recherche particulière de fichiers génériques
- [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
- [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
- [MD5.F6C45D1D448B38A3298505917710F047] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.16/12/2011 - 09:47:38.) -- C:\Windows\System32\wininet.dll [1188864]
- [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
- [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
- [MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688]
- [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
- [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
- [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
- [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
- [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
- [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
- [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
- [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
- [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
- [MD5.A2F74975097F52A00745F9637451FDD8] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.11/03/2011 - 07:41:34.) -- C:\Windows\system32\Drivers\ntfs.sys [1659776]
- [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
- [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
- [MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.20/11/2010 - 12:06:41.) -- C:\Windows\system32\Drivers\rdpdr.sys [165888]
- [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
- [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
- [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
- ~ Scan Generic Processes in 00mn 00s
- ---\\ Etat des fichiers cachés (Caché/Total)
- ~ Mes images (My Pictures) : 1/10
- ~ Mes Favoris (My Favorites) : 1/26
- ~ Mes Documents (My Documents) : 1/1791
- ~ Mon Bureau (My Desktop) : 1/9545
- ~ Menu demarrer (Programs) : 0/77
- ~ Scan Hidden Files in 00mn 04s
- ---\\ Processus lancés
- [MD5.BC7C727B013657D6C3658AF7038CC5CB] - (.Acronis - Acronis Scheduler Helper.) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395224] [PID.2324]
- [MD5.842A65DB009E15C9F55C37C88470F991] - (.TeamViewer GmbH - TeamViewer Remote Control Application.) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe [6766976] [PID.4564]
- [MD5.B6080F3A1CA495190D1583C2202CAA61] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [17148552] [PID.5100]
- [MD5.A974F7EB760451D7CF7342F9E088DBB0] - (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872] [PID.4420]
- [MD5.782FEF655DBF8653C9F2722BEBF7A8A6] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [4241512] [PID.3628]
- [MD5.995BEB69AE5C50D354894354F5A6CD5A] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296] [PID.4784]
- [MD5.4F69AABB5D82AA4EF6DFF7871212ADF6] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [924600] [PID.3960]
- [MD5.A7B6857B7503D9CA4F40D17A7EBB67FB] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [16824] [PID.5420]
- [MD5.CC926B0811C3FA2363C98711410FEF24] - (...) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [4540928] [PID.15840]
- ~ Scan Processes Running in 00mn 00s
- ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
- C:\Users\TheFireNight\AppData\Roaming\Mozilla\Firefox\Profiles\tnpljgjm.default\prefs.js
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\amazon-france.xml
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\avg-secure-search.xml
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\bing.xml
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\eBay-france.xml
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\google.xml
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\wikipedia-fr.xml
- M3 - MFPP: Plugins - [TheFireNight] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\yahoo-france.xml
- M2 - MFEP: prefs.js [TheFireNight - tnpljgjm.default\{1018e4d6-728f-4b20-ad56-37578a4de76b}] [] Flagfox v4.1.15 (.Dave Garrett.)
- M2 - MFEP: prefs.js [TheFireNight - tnpljgjm.default\{91aa5abe-9de4-4347-b7b5-322c38dd9271}] [] Clippings v3.1.7 (.AE Creations.)
- M2 - MFEP: prefs.js [TheFireNight - tnpljgjm.default\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}] [WOT] WOT v20120515 (.WOT Services Oy.)
- M2 - MFEP: prefs.js [TheFireNight - tnpljgjm.default\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}] [dwhelper] DownloadHelper v4.9.9 (.Michel Gutierrez.)
- P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npdeployJava1.dll
- P2 - FPN:Firefox Plugin Navigator . (.Solidworks Corporation - EModel Plugin.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npEModelPlugin.dll
- P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\NPOFF12.DLL
- P2 - FPN:Firefox Plugin Navigator . (.Tracker Software Products Ltd. - PDF-XChange Viewer Netscape Gecko Plugin.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npPDFXCviewNPPlugin.dll
- P2 - FPN: [HKCU] [@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf] - (.Tracker Software Products Ltd. - PDF-XChange Viewer Netscape Gecko Plugin.) -- C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
- ~ Scan Firefox Browser in 00mn 00s
- ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
- R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
- R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
- R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com
- R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com
- R3 - URLSearchHook: (no name) [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Tracker Software Products Ltd. - PDF-XChange Viewer Netscape Gecko Plugin.) (No version) -- (.not file.)
- ~ Scan IE Browser in 00mn 00s
- ---\\ Internet Explorer, Proxy Management (R5)
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
- ~ Scan Proxy management in 00mn 00s
- ---\\ Redirection du fichier Hosts (O1)
- ~ Le fichier hosts est sain (The hosts file is clean).
- ~ Scan Hosts File in 00mn 00s
- ~ Nombre de lignes (Lines number): 0
- ---\\ Applications démarrées par registre & par dossier (O4)
- O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
- O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
- ~ Scan Application in 00mn 00s
- ---\\ Autres liens utilisateurs (O4)
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Acronis True Image Home 2011.lnk . (.Acronis.) -- C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageLauncher.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Algobox.lnk . (...) -- C:\Program Files (x86)\Algobox\algobox.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Blender.lnk . (...) -- C:\Program Files (x86)\Blender Foundation\Blender\blender.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Blu-ray Disc Suite.lnk . (.CyberLink.) -- C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\PowerStarter.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Crysis2.exe - Raccourci.lnk . (.Crytek GmbH.) -- C:\Program Files (x86)\Electronic Arts\Crytek\Crysis 2\bin32\Crysis2.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\DVDFab 8 Qt.lnk . (.Fengtao Software Inc..) -- C:\Program Files (x86)\DVDFab 8 Qt\DVDFab.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Endless City Configuration.lnk . (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Demos\Endless City\bin\EndlessCityLauncher.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Endless City.lnk . (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Demos\Endless City\bin\EndlessCityLauncher.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Glary Utilities.lnk . (.Glarysoft Ltd.) -- C:\Program Files (x86)\Glary Utilities\Integrator.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Letters from Nowhere.lnk . (...) -- C:\Program Files (x86)\Playrix Entertainment\Letters from Nowhere\Letters from Nowhere.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\LettersFromNowhere2.exe - Raccourci.lnk . (...) -- C:\Program Files (x86)\Playrix Entertainment\Letters from Nowhere 2\LettersFromNowhere2.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\metro 2033.lnk . (.4A Games.) -- C:\Program Files (x86)\METRO 2033\metro2033.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\OCCT.lnk . (.OCCT.) -- C:\Program Files (x86)\OCCTPT\OCCT.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Options ImagePrinter.lnk . (.Copyright (C) 2008 Ibadov Tariel <tari.) -- C:\Program Files (x86)\ImagePrinter\Options.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Orbit.lnk . (.Orbitdownloader.com.) -- C:\Program Files (x86)\Orbitdownloader\orbitdm.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Paradise.lnk . (...) -- C:\Program Files (x86)\Micro Application\Paradise\Startup.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\skse_loader.exe - Raccourci.lnk . (...) -- C:\Program Files (x86)\Skyrim\skse_loader.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\SyncBack.lnk . (.2BrightSparks.) -- C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\TESV.exe - Raccourci.lnk . (...) -- C:\Program Files (x86)\Skyrim\skse_loader.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\The Witcher Enhanced Edition.lnk . (...) -- C:\Program Files (x86)\The Witcher Enhanced Edition\System\witcher.exe (.not file.)
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\WinSettings.LNK . (.FileStream, Inc..) -- C:\Program Files (x86)\WinSettings\WinSettings.Exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Wondershare Video Converter Platinum.lnk . (.Wondershare.) -- C:\Program Files (x86)\Wondershare\Video Converter Platinum\VideoConverter.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Word Reader 6.24.lnk . (.Abdio Software Inc.) -- C:\Program Files (x86)\Abdio\Word Reader\WordReader.exe
- O4 - Global Startup: C:\Users\TheFireNight\Desktop\Zentimo.lnk . (.Crystal Rich Ltd.) -- C:\Program Files (x86)\Zentimo\Zentimo.exe
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DVDFab 8 Qt.lnk . (.Fengtao Software Inc..) -- C:\Program Files (x86)\DVDFab 8 Qt\DVDFab.exe
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eDrawings 2008.lnk . (.Solidworks.) -- C:\Program Files (x86)\Common Files\eDrawings2008\EModelViewer.exe
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Glary Utilities.lnk . (.Glarysoft Ltd.) -- C:\Program Files (x86)\Glary Utilities\Integrator.exe
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mp3tag.lnk . (.Florian Heidenreich.) -- C:\Program Files (x86)\Mp3tag\Mp3tag.exe
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Oracle VM VirtualBox.lnk . (...) -- C:\Program Files (x86)\Oracle\VirtualBox\VirtualBox.exe (.not file.)
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SolidWorks 2008 SP2.1.lnk . (.Macrovision Corporation.) -- C:\Windows\Installer\{16A8E913-434D-4842-9A9F-A475F41FE0FF}\i386_SldWorks.exe
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SolidWorks Explorer.lnk . (.Macrovision Corporation.) -- C:\Windows\Installer\{700A17C4-F268-48E3-AF4A-CC01A85AF0E5}\NewShortcut1.exe
- O4 - Global Startup: C:\Users\TheFireNight\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Zentimo.lnk . (.Crystal Rich Ltd.) -- C:\Program Files (x86)\Zentimo\Zentimo.exe
- ~ Scan Global Startup in 00mn 04s
- ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
- O8 - Extra context menu item: &Download by Orbit . (.Orbitdownloader.com - Orbitmxt.) -- C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll
- O8 - Extra context menu item: &Grab video by Orbit . (.Orbitdownloader.com - Orbitmxt.) -- C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll
- O8 - Extra context menu item: Do&wnload selected by Orbit . (.Orbitdownloader.com - Orbitmxt.) -- C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll
- O8 - Extra context menu item: Down&load all by Orbit . (.Orbitdownloader.com - Orbitmxt.) -- C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll
- O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\Program Files (x86)\MICROS~3\Office12\EXCEL.exe
- ~ Scan IE Menu Contextuel in 00mn 00s
- ---\\ Enumération Active Desktop & MHTML Editor (O24)
- O24 - Default MHTML Editor: Last - .(...) - (.not file.)
- ~ Scan Desktop Component in 00mn 00s
- ---\\ Tâches planifiées en automatique (O39)
- O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job
- O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GlaryInitialize.job
- O39 - APT:Automatic Planified Task - C:\Windows\Tasks\SyncBack all.job
- [MD5.5447AF432CDA61159ADDE218C468FFD9] [APT] [AdobeAAMUpdater-1.0-TheFireNight-PC-TheFireNight] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
- [MD5.C3746969AD71734124DFDC7A1642DFA9] [APT] [AnVir Task Manager] (.AnVir Software.) -- C:\Program Files (x86)\AnVir Task Manager\anvir.exe
- [MD5.00000000000000000000000000000000] [APT] [FRAPS] (...) -- C:\Fraps\fraps.exe (.not file.)
- [MD5.D24DD70A143B4F4C09FFAE27DEA2C07D] [APT] [Launch HTC Sync Loader] (...) -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
- [MD5.D41D8CD98F00B204E9800998ECF8427E] [APT] [MyDefrag v4.3.1 Daily] (...) -- C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD"
- [MD5.D41D8CD98F00B204E9800998ECF8427E] [APT] [MyDefrag v4.3.1 Monthly] (...) -- C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD"
- [MD5.00000000000000000000000000000000] [APT] [{9418CB74-88A7-49C3-89FE-04B988E4936C}] (...) -- C:\Users\TheFireNight\Desktop\Windows7-DreamScene.exe (.not file.)
- [MD5.F4AD88FF508A573E3EC7C8E0E4760328] [APT] [ASUS Update Checker] (.ASUSTeK Computer Inc..) -- C:\Program Files (x86)\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
- ~ Scan Scheduled Task in 00mn 00s
- ---\\ Composants installés (ActiveSetup Installed Components) (O40) (None)
- ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
- O43 - CFD: 30/09/2011 - 13:29:41 - [611,746] ----D C:\Program Files (x86)\1C Company
- O43 - CFD: 17/04/2012 - 18:01:34 - [60,844] ----D C:\Program Files (x86)\2BrightSparks
- O43 - CFD: 04/09/2011 - 23:11:57 - [3,348] ----D C:\Program Files (x86)\7-Zip
- O43 - CFD: 03/02/2012 - 00:19:54 - [2,143] ----D C:\Program Files (x86)\Abdio
- O43 - CFD: 10/01/2012 - 21:32:46 - [202,235] ----D C:\Program Files (x86)\Acronis
- O43 - CFD: 09/02/2012 - 22:40:15 - [809,343] ----D C:\Program Files (x86)\Adobe
- O43 - CFD: 29/10/2011 - 22:45:39 - [2,665] ----D C:\Program Files (x86)\Adobe Media Player
- O43 - CFD: 25/04/2012 - 17:07:23 - [5,173] ----D C:\Program Files (x86)\AGEIA Technologies
- O43 - CFD: 18/11/2011 - 00:43:51 - [35,885] ----D C:\Program Files (x86)\Algobox
- O43 - CFD: 29/09/2011 - 13:01:53 - [17,019] ----D C:\Program Files (x86)\Almeza
- O43 - CFD: 17/05/2012 - 01:35:57 - [-1760,057] ----D C:\Program Files (x86)\Amnesia - The Dark Descent
- O43 - CFD: 09/02/2012 - 19:48:09 - [844,475] ----D C:\Program Files (x86)\Android
- O43 - CFD: 15/03/2012 - 14:24:14 - [12,041] ----D C:\Program Files (x86)\AnVir Task Manager
- O43 - CFD: 14/05/2012 - 19:43:11 - [100,120] ----D C:\Program Files (x86)\Apowersoft
- O43 - CFD: 01/05/2012 - 15:55:15 - [33,654] ----D C:\Program Files (x86)\Ashampoo
- O43 - CFD: 10/01/2012 - 23:28:43 - [21,021] ----D C:\Program Files (x86)\ASUS
- O43 - CFD: 17/10/2011 - 22:48:04 - [0,140] ----D C:\Program Files (x86)\AviSynth 2.5
- O43 - CFD: 30/01/2012 - 21:12:50 - [-1651,806] ----D C:\Program Files (x86)\Bethesda Softworks
- O43 - CFD: 29/08/2011 - 13:48:56 - [1548,691] ----D C:\Program Files (x86)\bitComposer Games
- O43 - CFD: 24/11/2011 - 14:44:43 - [82,077] ----D C:\Program Files (x86)\Blender Foundation
- O43 - CFD: 29/08/2011 - 13:22:35 - [4,846] ----D C:\Program Files (x86)\Business Logic Corporation
- O43 - CFD: 28/05/2012 - 13:52:23 - [-1492,132] ----D C:\Program Files (x86)\Common Files
- O43 - CFD: 25/12/2011 - 22:06:29 - [1142,437] ----D C:\Program Files (x86)\CyberLink
- O43 - CFD: 21/05/2012 - 00:35:25 - [353,940] ----D C:\Program Files (x86)\Daedalic Entertainment
- O43 - CFD: 28/04/2012 - 01:31:44 - [25,441] ----D C:\Program Files (x86)\DAEMON Tools Lite
- O43 - CFD: 30/12/2011 - 23:10:18 - [4,368] ----D C:\Program Files (x86)\DIY DataRecovery MBRtool 2
- O43 - CFD: 29/02/2012 - 01:58:43 - [52,844] ----D C:\Program Files (x86)\DVDFab 8 Qt
- O43 - CFD: 25/04/2012 - 17:10:34 - [159,564] ----D C:\Program Files (x86)\DWGeditor
- O43 - CFD: 21/01/2012 - 13:21:02 - [124,855] ----D C:\Program Files (x86)\EA Games
- O43 - CFD: 26/05/2012 - 21:09:38 - [103,075] ----D C:\Program Files (x86)\Electronic Arts
- O43 - CFD: 17/10/2011 - 22:46:26 - [39,898] ----D C:\Program Files (x86)\eRightSoft
- O43 - CFD: 26/05/2012 - 20:18:12 - [3,975] ----D C:\Program Files (x86)\Futuremark
- O43 - CFD: 22/09/2011 - 12:50:51 - [6,046] ----D C:\Program Files (x86)\GeoGebra
- O43 - CFD: 07/12/2011 - 18:23:46 - [2,432] ----D C:\Program Files (x86)\GiMeSpace Desktop Extender 3D
- O43 - CFD: 19/02/2012 - 19:46:26 - [18,755] ----D C:\Program Files (x86)\Glary Utilities
- O43 - CFD: 09/02/2012 - 22:41:27 - [45,279] ----D C:\Program Files (x86)\HTC
- O43 - CFD: 04/05/2012 - 20:43:33 - [3,005] ----D C:\Program Files (x86)\ImagePrinter
- O43 - CFD: 26/05/2012 - 20:18:12 - [1179,927] --H-D C:\Program Files (x86)\InstallShield Installation Information
- O43 - CFD: 22/11/2011 - 00:03:38 - [0,092] ----D C:\Program Files (x86)\Intel
- O43 - CFD: 02/03/2012 - 02:46:54 - [3,732] ----D C:\Program Files (x86)\Internet Explorer
- O43 - CFD: 21/04/2012 - 02:55:06 - [13,224] ----D C:\Program Files (x86)\IZArc
- O43 - CFD: 30/12/2011 - 22:00:20 - [3,276] ----D C:\Program Files (x86)\JAM Software
- O43 - CFD: 28/05/2012 - 13:49:39 - [177,441] ----D C:\Program Files (x86)\Java
- O43 - CFD: 06/01/2012 - 15:33:53 - [79,716] ----D C:\Program Files (x86)\Kroll Ontrack
- O43 - CFD: 11/03/2012 - 19:24:43 - [47,293] ----D C:\Program Files (x86)\Leawo
- O43 - CFD: 08/11/2011 - 08:30:02 - [10,535] ----D C:\Program Files (x86)\lg_fwupdate
- O43 - CFD: 28/05/2012 - 16:00:34 - [11,554] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
- O43 - CFD: 27/04/2012 - 03:19:59 - [135,654] ----D C:\Program Files (x86)\Matrix Multimedia
- O43 - CFD: 20/09/2011 - 12:17:21 - [-876,840] ----D C:\Program Files (x86)\METRO 2033
- O43 - CFD: 11/12/2011 - 13:14:12 - [-1923,097] ----D C:\Program Files (x86)\Micro Application
- O43 - CFD: 30/08/2011 - 00:01:53 - [0,216] ----D C:\Program Files (x86)\Microsoft
- O43 - CFD: 23/09/2011 - 14:27:04 - [0,764] ----D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
- O43 - CFD: 25/04/2012 - 17:07:22 - [584,230] ----D C:\Program Files (x86)\Microsoft Office
- O43 - CFD: 18/03/2012 - 05:22:23 - [36,634] ----D C:\Program Files (x86)\Microsoft Silverlight
- O43 - CFD: 22/09/2011 - 21:27:04 - [0,014] ----D C:\Program Files (x86)\Microsoft Visual Studio
- O43 - CFD: 22/09/2011 - 21:25:05 - [56,656] ----D C:\Program Files (x86)\Microsoft Visual Studio 8
- O43 - CFD: 23/09/2011 - 14:23:57 - [3,554] ----D C:\Program Files (x86)\Microsoft Works
- O43 - CFD: 28/12/2011 - 14:42:12 - [0,934] ----D C:\Program Files (x86)\Microsoft WSE
- O43 - CFD: 22/09/2011 - 21:26:53 - [7,797] ----D C:\Program Files (x86)\Microsoft.NET
- O43 - CFD: 04/05/2012 - 20:31:56 - [0] ----D C:\Program Files (x86)\Miraplacid
- O43 - CFD: 26/05/2012 - 18:47:52 - [89,143] ----D C:\Program Files (x86)\Mozilla Firefox
- O43 - CFD: 04/05/2012 - 07:37:31 - [0,210] ----D C:\Program Files (x86)\Mozilla Maintenance Service
- O43 - CFD: 07/09/2011 - 00:07:52 - [7,032] ----D C:\Program Files (x86)\Mp3tag
- O43 - CFD: 22/09/2011 - 21:27:09 - [0,025] ----D C:\Program Files (x86)\MSBuild
- O43 - CFD: 14/12/2011 - 22:39:16 - [19,263] ----D C:\Program Files (x86)\MSECache
- O43 - CFD: 09/02/2012 - 22:39:48 - [0,147] ----D C:\Program Files (x86)\MSXML 4.0
- O43 - CFD: 19/09/2011 - 17:44:38 - [10,174] ----D C:\Program Files (x86)\MultiStage Recovery
- O43 - CFD: 30/12/2011 - 23:07:35 - [3,551] ----D C:\Program Files (x86)\MunSoft
- O43 - CFD: 29/10/2011 - 22:45:24 - [0] ----D C:\Program Files (x86)\My Company Name
- O43 - CFD: 24/11/2011 - 18:19:05 - [27,136] ----D C:\Program Files (x86)\NifTools
- O43 - CFD: 28/08/2011 - 22:34:09 - [11,160] ----D C:\Program Files (x86)\Notepad++
- O43 - CFD: 13/03/2012 - 23:07:11 - [372,101] ----D C:\Program Files (x86)\NVIDIA Corporation
- O43 - CFD: 01/12/2011 - 16:57:40 - [18,017] ----D C:\Program Files (x86)\OCCTPT
- O43 - CFD: 28/05/2012 - 13:49:57 - [33,186] ----D C:\Program Files (x86)\Oracle
- O43 - CFD: 14/05/2012 - 20:16:29 - [13,376] ----D C:\Program Files (x86)\Orbitdownloader
- O43 - CFD: 23/12/2011 - 20:44:25 - [46,023] ----D C:\Program Files (x86)\PC Fresh
- O43 - CFD: 04/01/2012 - 14:17:01 - [5,923] ----D C:\Program Files (x86)\PC Inspector File Recovery
- O43 - CFD: 05/09/2011 - 13:04:15 - [406,549] ----D C:\Program Files (x86)\Playrix Entertainment
- O43 - CFD: 31/12/2011 - 20:08:47 - [41,820] ----D C:\Program Files (x86)\PowerQuest
- O43 - CFD: 24/11/2011 - 18:14:51 - [71,007] ----D C:\Program Files (x86)\PyFFI
- O43 - CFD: 09/01/2012 - 21:48:39 - [4,627] ----D C:\Program Files (x86)\RAMDisk
- O43 - CFD: 14/07/2009 - 07:32:38 - [37,349] ----D C:\Program Files (x86)\Reference Assemblies
- O43 - CFD: 21/04/2012 - 14:54:42 - [2,166] ----D C:\Program Files (x86)\Resource Hacker
- O43 - CFD: 16/03/2012 - 19:21:23 - [16,513] R---D C:\Program Files (x86)\Skype
- O43 - CFD: 21/12/2011 - 18:49:24 - [-445,136] ----D C:\Program Files (x86)\Skyrim
- O43 - CFD: 25/04/2012 - 17:11:32 - [-1340,803] ----D C:\Program Files (x86)\SolidWorks
- O43 - CFD: 05/05/2012 - 18:18:15 - [5,564] ----D C:\Program Files (x86)\SpeedFan
- O43 - CFD: 09/02/2012 - 22:40:32 - [0,473] ----D C:\Program Files (x86)\Spirent Communications
- O43 - CFD: 18/09/2011 - 13:29:47 - [23,625] ----D C:\Program Files (x86)\Stardock
- O43 - CFD: 12/11/2011 - 00:27:59 - [0,467] ----D C:\Program Files (x86)\SystemRequirementsLab
- O43 - CFD: 04/03/2012 - 06:13:23 - [24,960] ----D C:\Program Files (x86)\TeamViewer
- O43 - CFD: 31/12/2011 - 11:34:58 - [119,765] ----D C:\Program Files (x86)\The Elder Scrolls V Skyrim
- O43 - CFD: 02/10/2011 - 03:51:35 - [-246,549] ----D C:\Program Files (x86)\The Witcher 2
- O43 - CFD: 23/09/2011 - 12:56:28 - [96,197] ----D C:\Program Files (x86)\THQ
- O43 - CFD: 14/07/2009 - 06:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information
- O43 - CFD: 16/09/2011 - 22:40:59 - [73,807] ----D C:\Program Files (x86)\VIA
- O43 - CFD: 29/08/2011 - 23:38:15 - [88,835] ----D C:\Program Files (x86)\VideoLAN
- O43 - CFD: 14/07/2009 - 13:04:03 - [0,500] ----D C:\Program Files (x86)\Windows Defender
- O43 - CFD: 30/08/2011 - 00:01:49 - [43,684] ----D C:\Program Files (x86)\Windows Live
- O43 - CFD: 30/08/2011 - 00:01:38 - [0,234] ----D C:\Program Files (x86)\Windows Live SkyDrive
- O43 - CFD: 28/08/2011 - 23:28:08 - [5,895] ----D C:\Program Files (x86)\Windows Mail
- O43 - CFD: 28/08/2011 - 23:28:08 - [4,791] ----D C:\Program Files (x86)\Windows Media Player
- O43 - CFD: 14/07/2009 - 07:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT
- O43 - CFD: 28/08/2011 - 23:28:08 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer
- O43 - CFD: 28/08/2011 - 23:28:08 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices
- O43 - CFD: 28/08/2011 - 23:28:08 - [5,717] ----D C:\Program Files (x86)\Windows Sidebar
- O43 - CFD: 12/05/2012 - 04:17:30 - [4,777] ----D C:\Program Files (x86)\Windows Virtual PC
- O43 - CFD: 20/04/2012 - 15:59:57 - [0,227] ----D C:\Program Files (x86)\WinPcap
- O43 - CFD: 21/01/2012 - 23:17:38 - [2,669] ----D C:\Program Files (x86)\WinSettings
- O43 - CFD: 22/11/2011 - 18:38:16 - [98,922] ----D C:\Program Files (x86)\Wondershare
- O43 - CFD: 12/12/2011 - 16:56:25 - [7,196] ----D C:\Program Files (x86)\Zentimo
- O43 - CFD: 29/05/2012 - 12:35:44 - [13,545] ----D C:\Program Files (x86)\ZHPDiag
- O43 - CFD: 10/01/2012 - 21:33:31 - [94,675] ----D C:\Program Files (x86)\Common Files\Acronis
- O43 - CFD: 29/10/2011 - 22:52:41 - [962,204] ----D C:\Program Files (x86)\Common Files\Adobe
- O43 - CFD: 09/02/2012 - 22:40:14 - [37,554] ----D C:\Program Files (x86)\Common Files\Adobe AIR
- O43 - CFD: 25/11/2011 - 14:16:07 - [902,469] ----D C:\Program Files (x86)\Common Files\Autodesk Shared
- O43 - CFD: 03/11/2011 - 23:00:43 - [0,132] ----D C:\Program Files (x86)\Common Files\CyberLink
- O43 - CFD: 25/04/2012 - 17:07:23 - [0,195] ----D C:\Program Files (x86)\Common Files\DESIGNER
- O43 - CFD: 25/04/2012 - 17:10:21 - [69,835] ----D C:\Program Files (x86)\Common Files\eDrawings2008
- O43 - CFD: 14/12/2011 - 22:37:46 - [29,184] ----D C:\Program Files (x86)\Common Files\Gestionnaire d'installation SolidWorks
- O43 - CFD: 22/11/2011 - 00:04:57 - [13,115] ----D C:\Program Files (x86)\Common Files\InstallShield
- O43 - CFD: 28/05/2012 - 13:52:23 - [1,181] ----D C:\Program Files (x86)\Common Files\Java
- O43 - CFD: 03/11/2011 - 22:55:25 - [35,512] ----D C:\Program Files (x86)\Common Files\LightScribe
- O43 - CFD: 14/12/2011 - 22:39:18 - [271,359] ----D C:\Program Files (x86)\Common Files\microsoft shared
- O43 - CFD: 29/10/2011 - 22:45:24 - [0,195] ----D C:\Program Files (x86)\Common Files\PX Storage Engine
- O43 - CFD: 14/07/2009 - 05:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
- O43 - CFD: 16/03/2012 - 19:21:23 - [2,056] ----D C:\Program Files (x86)\Common Files\Skype
- O43 - CFD: 25/04/2012 - 17:11:00 - [35,504] ----D C:\Program Files (x86)\Common Files\SolidWorks Shared
- O43 - CFD: 29/10/2011 - 22:45:24 - [0,355] ----D C:\Program Files (x86)\Common Files\Sonic Shared
- O43 - CFD: 14/07/2009 - 05:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines
- O43 - CFD: 10/11/2011 - 08:27:11 - [42,257] ----D C:\Program Files (x86)\Common Files\System
- O43 - CFD: 29/08/2011 - 13:31:15 - [0] ----D C:\Program Files (x86)\Common Files\Windows Live
- O43 - CFD: 25/04/2012 - 17:09:33 - [64,424] ----D C:\Program Files (x86)\Common Files\Wise Installation Wizard
- O43 - CFD: 22/11/2011 - 18:38:23 - [2,460] ----D C:\Program Files (x86)\Common Files\Wondershare
- O43 - CFD: 10/01/2012 - 22:52:39 - [0,049] ----D C:\ProgramData\Acronis
- O43 - CFD: 23/11/2011 - 13:46:35 - [0,000] ----D C:\ProgramData\Ad Muncher
- O43 - CFD: 23/02/2012 - 20:40:06 - [432,252] ----D C:\ProgramData\Adobe
- O43 - CFD: 29/10/2011 - 22:54:45 - [0] ----D C:\ProgramData\ALM
- O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Application Data
- O43 - CFD: 26/11/2011 - 00:40:35 - [0,156] ----D C:\ProgramData\Autodesk
- O43 - CFD: 28/08/2011 - 22:36:47 - [351,807] ----D C:\ProgramData\AVAST Software
- O43 - CFD: 30/09/2011 - 13:18:06 - [0] ----D C:\ProgramData\Blizzard Entertainment
- O43 - CFD: 28/08/2011 - 20:52:36 - [0] --H-D C:\ProgramData\Bureau
- O43 - CFD: 14/05/2012 - 20:14:57 - [0,000] --H-D C:\ProgramData\Common Files
- O43 - CFD: 25/12/2011 - 15:52:46 - [1,518] ----D C:\ProgramData\CyberLink
- O43 - CFD: 17/05/2012 - 01:16:23 - [0,002] ----D C:\ProgramData\DAEMON Tools Lite
- O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Desktop
- O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Documents
- O43 - CFD: 29/02/2012 - 00:19:17 - [0] ----D C:\ProgramData\dvdfab
- O43 - CFD: 21/01/2012 - 13:40:44 - [0] ----D C:\ProgramData\EA Core
- O43 - CFD: 21/01/2012 - 13:40:43 - [0,328] ----D C:\ProgramData\Electronic Arts
- O43 - CFD: 28/08/2011 - 20:52:36 - [0] --H-D C:\ProgramData\Favoris
- O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Favorites
- O43 - CFD: 26/11/2011 - 00:35:40 - [0,045] ----D C:\ProgramData\FLEXnet
- O43 - CFD: 17/05/2012 - 01:38:26 - [0,000] ----D C:\ProgramData\fltk.org
- O43 - CFD: 25/12/2011 - 22:05:32 - [0,205] ----D C:\ProgramData\install_clap
- O43 - CFD: 04/11/2011 - 19:30:12 - [0,001] ----D C:\ProgramData\LightScribe
- O43 - CFD: 20/11/2011 - 23:56:31 - [1,200] ----D C:\ProgramData\ma-config.com
- O43 - CFD: 28/05/2012 - 16:00:33 - [6,842] ----D C:\ProgramData\Malwarebytes
- O43 - CFD: 28/08/2011 - 20:52:36 - [0] --H-D C:\ProgramData\Menu Démarrer
- O43 - CFD: 30/12/2011 - 23:17:40 - [30,973] -S--D C:\ProgramData\Microsoft
- O43 - CFD: 20/01/2012 - 08:41:42 - [0,261] ----D C:\ProgramData\Microsoft Help
- O43 - CFD: 28/08/2011 - 20:52:36 - [0] --H-D C:\ProgramData\Modèles
- O43 - CFD: 04/05/2012 - 07:37:29 - [0,000] ----D C:\ProgramData\Mozilla
- O43 - CFD: 29/05/2012 - 10:35:42 - [2,935] ----D C:\ProgramData\NVIDIA
- O43 - CFD: 16/09/2011 - 19:50:20 - [0,936] ----D C:\ProgramData\NVIDIA Corporation
- O43 - CFD: 25/12/2011 - 15:52:38 - [0,000] ----D C:\ProgramData\PDVD
- O43 - CFD: 04/09/2011 - 19:35:43 - [0,247] ----D C:\ProgramData\Playrix Entertainment
- O43 - CFD: 23/02/2012 - 20:40:00 - [0,002] ----D C:\ProgramData\regid.1986-12.com.adobe
- O43 - CFD: 31/10/2011 - 13:42:50 - [0,341] ----D C:\ProgramData\Saitek
- O43 - CFD: 18/02/2012 - 13:20:00 - [0,123] ----D C:\ProgramData\SeriousBit
- O43 - CFD: 16/03/2012 - 19:21:20 - [18,537] ----D C:\ProgramData\Skype
- O43 - CFD: 25/04/2012 - 17:07:22 - [119,176] ----D C:\ProgramData\SolidWorks
- O43 - CFD: 18/09/2011 - 13:29:54 - [95,517] ----D C:\ProgramData\Stardock
- O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Start Menu
- O43 - CFD: 22/09/2011 - 12:47:30 - [0,000] ----D C:\ProgramData\Sun
- O43 - CFD: 01/05/2012 - 23:37:04 - [0,926] ---AD C:\ProgramData\Temp
- O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Templates
- O43 - CFD: 12/05/2012 - 03:22:49 - [0,002] ----D C:\ProgramData\Windows Genuine Advantage
- O43 - CFD: 21/05/2012 - 00:25:02 - [0] ----D C:\ProgramData\xml_param
- O43 - CFD: 12/12/2011 - 16:56:25 - [0,253] ----D C:\ProgramData\ZentimoService
- O43 - CFD: 18/09/2011 - 20:16:49 - [5,372] --H-D C:\ProgramData\{37477C0D-A625-4A04-AC90-BC17FC1DAEB2}
- O43 - CFD: 10/01/2012 - 23:39:28 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Acronis
- O43 - CFD: 10/05/2012 - 18:24:56 - [20,890] ----D C:\Users\TheFireNight\AppData\Roaming\Adobe
- O43 - CFD: 14/05/2012 - 19:43:18 - [1,389] ----D C:\Users\TheFireNight\AppData\Roaming\Apowersoft
- O43 - CFD: 26/11/2011 - 00:40:35 - [0,004] ----D C:\Users\TheFireNight\AppData\Roaming\Autodesk
- O43 - CFD: 05/09/2011 - 14:58:25 - [0,475] ----D C:\Users\TheFireNight\AppData\Roaming\Awem
- O43 - CFD: 07/12/2011 - 18:24:05 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\BeSpotted
- O43 - CFD: 24/11/2011 - 14:49:55 - [0,022] ----D C:\Users\TheFireNight\AppData\Roaming\Blender Foundation
- O43 - CFD: 29/08/2011 - 13:22:59 - [-1510,161] ----D C:\Users\TheFireNight\AppData\Roaming\Business Logic
- O43 - CFD: 25/12/2011 - 07:07:10 - [0,008] ----D C:\Users\TheFireNight\AppData\Roaming\CyberLink
- O43 - CFD: 28/04/2012 - 01:32:03 - [0,901] ----D C:\Users\TheFireNight\AppData\Roaming\DAEMON Tools Lite
- O43 - CFD: 29/02/2012 - 01:38:58 - [0,014] ----D C:\Users\TheFireNight\AppData\Roaming\DVDFab
- O43 - CFD: 25/04/2012 - 17:10:38 - [0,001] ----D C:\Users\TheFireNight\AppData\Roaming\DWGeditor
- O43 - CFD: 17/05/2012 - 01:38:26 - [0,000] ----D C:\Users\TheFireNight\AppData\Roaming\fltk.org
- O43 - CFD: 19/05/2012 - 18:34:26 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\GetRightToGo
- O43 - CFD: 19/02/2012 - 19:47:51 - [0,091] ----D C:\Users\TheFireNight\AppData\Roaming\GlarySoft
- O43 - CFD: 09/02/2012 - 22:41:49 - [0,455] ----D C:\Users\TheFireNight\AppData\Roaming\HTC
- O43 - CFD: 09/02/2012 - 23:15:13 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
- O43 - CFD: 28/08/2011 - 20:53:15 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Identities
- O43 - CFD: 18/12/2011 - 13:24:57 - [3,758] ----D C:\Users\TheFireNight\AppData\Roaming\IM
- O43 - CFD: 30/12/2011 - 22:00:21 - [0,002] ----D C:\Users\TheFireNight\AppData\Roaming\JAM Software
- O43 - CFD: 11/03/2012 - 19:28:55 - [0,002] ----D C:\Users\TheFireNight\AppData\Roaming\Leawo
- O43 - CFD: 28/08/2011 - 21:02:34 - [0,128] ----D C:\Users\TheFireNight\AppData\Roaming\Macromedia
- O43 - CFD: 28/05/2012 - 16:00:37 - [1,864] ----D C:\Users\TheFireNight\AppData\Roaming\Malwarebytes
- O43 - CFD: 14/07/2009 - 13:26:24 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Media Center Programs
- O43 - CFD: 01/05/2012 - 23:32:53 - [9,003] -S--D C:\Users\TheFireNight\AppData\Roaming\Microsoft
- O43 - CFD: 28/08/2011 - 21:22:01 - [122,410] ----D C:\Users\TheFireNight\AppData\Roaming\Mozilla
- O43 - CFD: 21/05/2012 - 00:27:34 - [0,059] ----D C:\Users\TheFireNight\AppData\Roaming\Mp3tag
- O43 - CFD: 28/08/2011 - 22:35:08 - [0,344] ----D C:\Users\TheFireNight\AppData\Roaming\Notepad++
- O43 - CFD: 30/10/2011 - 18:10:14 - [2,927] ----D C:\Users\TheFireNight\AppData\Roaming\NVIDIA
- O43 - CFD: 29/05/2012 - 00:37:31 - [8,387] ----D C:\Users\TheFireNight\AppData\Roaming\Orbit
- O43 - CFD: 14/05/2012 - 20:16:33 - [0,000] ----D C:\Users\TheFireNight\AppData\Roaming\ProgSense
- O43 - CFD: 16/11/2011 - 00:36:22 - [0,001] ----D C:\Users\TheFireNight\AppData\Roaming\ScripterRon
- O43 - CFD: 29/05/2012 - 12:13:47 - [3,925] ----D C:\Users\TheFireNight\AppData\Roaming\Skype
- O43 - CFD: 12/11/2011 - 00:27:55 - [0,324] ----D C:\Users\TheFireNight\AppData\Roaming\SystemRequirementsLab
- O43 - CFD: 18/05/2012 - 19:01:22 - [1,106] ----D C:\Users\TheFireNight\AppData\Roaming\TeamViewer
- O43 - CFD: 11/03/2012 - 19:29:53 - [1,469] ----D C:\Users\TheFireNight\AppData\Roaming\tiger-k
- O43 - CFD: 14/02/2012 - 19:09:18 - [0,002] ----D C:\Users\TheFireNight\AppData\Roaming\VBA-M
- O43 - CFD: 28/05/2012 - 23:21:14 - [0,336] ----D C:\Users\TheFireNight\AppData\Roaming\vlc
- O43 - CFD: 07/05/2012 - 21:18:25 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\WinBatch
- O43 - CFD: 20/09/2011 - 07:22:40 - [0,000] ----D C:\Users\TheFireNight\AppData\Roaming\WinRAR
- O43 - CFD: 22/11/2011 - 18:38:17 - [0,986] ----D C:\Users\TheFireNight\AppData\Roaming\Wondershare
- O43 - CFD: 18/11/2011 - 01:17:32 - [0,001] ----D C:\Users\TheFireNight\AppData\Roaming\xm1
- O43 - CFD: 29/08/2011 - 18:11:40 - [34,421] ----D C:\Users\TheFireNight\AppData\Roaming\XRay Engine
- O43 - CFD: 12/12/2011 - 16:56:34 - [0,099] ----D C:\Users\TheFireNight\AppData\Roaming\Zentimo
- O43 - CFD: 20/09/2011 - 12:34:54 - [0,003] ----D C:\Users\TheFireNight\AppData\Local\4A Games
- O43 - CFD: 23/12/2011 - 18:04:49 - [260,691] ----D C:\Users\TheFireNight\AppData\Local\Abelssoft
- O43 - CFD: 09/02/2012 - 22:40:07 - [51,452] ----D C:\Users\TheFireNight\AppData\Local\Adobe
- O43 - CFD: 15/03/2012 - 14:27:48 - [0,097] ----D C:\Users\TheFireNight\AppData\Local\AnVir
- O43 - CFD: 28/08/2011 - 20:52:45 - [0] ----D C:\Users\TheFireNight\AppData\Local\Application Data
- O43 - CFD: 26/11/2011 - 00:40:49 - [68,976] ----D C:\Users\TheFireNight\AppData\Local\Autodesk
- O43 - CFD: 28/11/2011 - 21:12:09 - [0,009] ----D C:\Users\TheFireNight\AppData\Local\backburner
- O43 - CFD: 25/12/2011 - 21:00:28 - [0,006] ----D C:\Users\TheFireNight\AppData\Local\Cyberlink
- O43 - CFD: 15/01/2012 - 02:00:38 - [0] ----D C:\Users\TheFireNight\AppData\Local\Diagnostics
- O43 - CFD: 13/12/2011 - 15:02:32 - [7,890] ----D C:\Users\TheFireNight\AppData\Local\DiskBoss Pro
- O43 - CFD: 09/02/2012 - 22:40:52 - [28,299] ----D C:\Users\TheFireNight\AppData\Local\Downloaded Installations
- O43 - CFD: 21/05/2012 - 08:12:25 - [0] ----D C:\Users\TheFireNight\AppData\Local\ElevatedDiagnostics
- O43 - CFD: 28/08/2011 - 20:52:45 - [0] ----D C:\Users\TheFireNight\AppData\Local\Historique
- O43 - CFD: 19/02/2012 - 15:53:28 - [0,047] ----D C:\Users\TheFireNight\AppData\Local\Htc
- O43 - CFD: 25/12/2011 - 07:06:34 - [0] ----D C:\Users\TheFireNight\AppData\Local\MediaServer
- O43 - CFD: 04/05/2012 - 20:31:45 - [176,451] ----D C:\Users\TheFireNight\AppData\Local\Microsoft
- O43 - CFD: 09/05/2012 - 20:43:23 - [0,174] ----D C:\Users\TheFireNight\AppData\Local\Microsoft Games
- O43 - CFD: 22/09/2011 - 21:24:38 - [0] ----D C:\Users\TheFireNight\AppData\Local\Microsoft Help
- O43 - CFD: 28/08/2011 - 21:21:57 - [208,152] ----D C:\Users\TheFireNight\AppData\Local\Mozilla
- O43 - CFD: 30/09/2011 - 13:12:18 - [0] ----D C:\Users\TheFireNight\AppData\Local\Oblivion
- O43 - CFD: 01/12/2011 - 18:29:47 - [0,015] ----D C:\Users\TheFireNight\AppData\Local\OCCT
- O43 - CFD: 04/11/2011 - 08:19:35 - [0,039] ----D C:\Users\TheFireNight\AppData\Local\Power2Go
- O43 - CFD: 17/02/2012 - 23:10:07 - [0,004] ----D C:\Users\TheFireNight\AppData\Local\SKIDROW
- O43 - CFD: 11/11/2011 - 16:33:07 - [0,000] ----D C:\Users\TheFireNight\AppData\Local\Skyrim
- O43 - CFD: 22/09/2011 - 07:40:47 - [15,820] ----D C:\Users\TheFireNight\AppData\Local\stardock
- O43 - CFD: 29/05/2012 - 12:35:46 - [-1635,461] ----D C:\Users\TheFireNight\AppData\Local\Temp
- O43 - CFD: 28/08/2011 - 20:52:45 - [0] ----D C:\Users\TheFireNight\AppData\Local\Temporary Internet Files
- O43 - CFD: 16/10/2011 - 16:39:47 - [75,469] ----D C:\Users\TheFireNight\AppData\Local\The Witcher
- O43 - CFD: 01/10/2011 - 13:17:15 - [0] ----D C:\Users\TheFireNight\AppData\Local\The Witcher 2
- O43 - CFD: 30/09/2011 - 13:34:58 - [2,688] ----D C:\Users\TheFireNight\AppData\Local\VirtualStore
- O43 - CFD: 22/11/2011 - 18:38:24 - [0] ----D C:\Users\TheFireNight\AppData\Local\Wondershare
- O43 - CFD: 14/07/2009 - 06:54:32 - [0,011] R---D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
- O43 - CFD: 10/01/2012 - 23:27:08 - [0,025] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acronis
- O43 - CFD: 27/02/2012 - 23:19:35 - [0,000] R---D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- O43 - CFD: 18/11/2011 - 00:43:51 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Algobox
- O43 - CFD: 15/03/2012 - 14:24:14 - [0,000] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager
- O43 - CFD: 11/11/2011 - 02:49:13 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Battle Engine Aquila
- O43 - CFD: 24/11/2011 - 18:06:05 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blender Foundation
- O43 - CFD: 03/11/2011 - 23:50:37 - [0,031] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
- O43 - CFD: 30/12/2011 - 23:10:18 - [0,000] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DIY DataRecovery MBRtool 2
- O43 - CFD: 19/05/2012 - 16:09:34 - [0,002] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
- O43 - CFD: 04/05/2012 - 20:43:24 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ImagePrinter
- O43 - CFD: 14/07/2009 - 06:49:38 - [0,001] R---D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
- O43 - CFD: 27/04/2012 - 02:43:19 - [0,001] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microchip
- O43 - CFD: 28/08/2011 - 22:34:07 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
- O43 - CFD: 01/12/2011 - 16:57:40 - [0] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OCCT
- O43 - CFD: 28/05/2012 - 00:07:09 - [0] R---D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- O43 - CFD: 20/09/2011 - 07:22:17 - [0,003] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
- O43 - CFD: 21/01/2012 - 23:17:39 - [0,003] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinSettings
- O43 - CFD: 12/12/2011 - 16:56:25 - [0,005] ----D C:\Users\TheFireNight\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zentimo
- O43 - CFD: 30/09/2011 - 13:29:41 - [611,746] ----D C:\Program Files (x86)\1C Company
- O43 - CFD: 17/04/2012 - 18:01:34 - [60,844] ----D C:\Program Files (x86)\2BrightSparks
- O43 - CFD: 04/09/2011 - 23:11:57 - [3,348] ----D C:\Program Files (x86)\7-Zip
- O43 - CFD: 03/02/2012 - 00:19:54 - [2,143] ----D C:\Program Files (x86)\Abdio
- O43 - CFD: 10/01/2012 - 21:32:46 - [202,235] ----D C:\Program Files (x86)\Acronis
- O43 - CFD: 09/02/2012 - 22:40:15 - [809,343] ----D C:\Program Files (x86)\Adobe
- O43 - CFD: 29/10/2011 - 22:45:39 - [2,665] ----D C:\Program Files (x86)\Adobe Media Player
- O43 - CFD: 25/04/2012 - 17:07:23 - [5,173] ----D C:\Program Files (x86)\AGEIA Technologies
- O43 - CFD: 18/11/2011 - 00:43:51 - [35,885] ----D C:\Program Files (x86)\Algobox
- O43 - CFD: 29/09/2011 - 13:01:53 - [17,019] ----D C:\Program Files (x86)\Almeza
- O43 - CFD: 17/05/2012 - 01:35:57 - [-1760,057] ----D C:\Program Files (x86)\Amnesia - The Dark Descent
- O43 - CFD: 09/02/2012 - 19:48:09 - [844,475] ----D C:\Program Files (x86)\Android
- O43 - CFD: 15/03/2012 - 14:24:14 - [12,041] ----D C:\Program Files (x86)\AnVir Task Manager
- O43 - CFD: 14/05/2012 - 19:43:11 - [100,120] ----D C:\Program Files (x86)\Apowersoft
- O43 - CFD: 01/05/2012 - 15:55:15 - [33,654] ----D C:\Program Files (x86)\Ashampoo
- O43 - CFD: 10/01/2012 - 23:28:43 - [21,021] ----D C:\Program Files (x86)\ASUS
- O43 - CFD: 17/10/2011 - 22:48:04 - [0,140] ----D C:\Program Files (x86)\AviSynth 2.5
- O43 - CFD: 30/01/2012 - 21:12:50 - [-1651,806] ----D C:\Program Files (x86)\Bethesda Softworks
- O43 - CFD: 29/08/2011 - 13:48:56 - [1548,691] ----D C:\Program Files (x86)\bitComposer Games
- O43 - CFD: 24/11/2011 - 14:44:43 - [82,077] ----D C:\Program Files (x86)\Blender Foundation
- O43 - CFD: 29/08/2011 - 13:22:35 - [4,846] ----D C:\Program Files (x86)\Business Logic Corporation
- O43 - CFD: 28/05/2012 - 13:52:23 - [-1492,132] ----D C:\Program Files (x86)\Common Files
- O43 - CFD: 25/12/2011 - 22:06:29 - [1142,437] ----D C:\Program Files (x86)\CyberLink
- O43 - CFD: 21/05/2012 - 00:35:25 - [353,940] ----D C:\Program Files (x86)\Daedalic Entertainment
- O43 - CFD: 28/04/2012 - 01:31:44 - [25,441] ----D C:\Program Files (x86)\DAEMON Tools Lite
- O43 - CFD: 30/12/2011 - 23:10:18 - [4,368] ----D C:\Program Files (x86)\DIY DataRecovery MBRtool 2
- O43 - CFD: 29/02/2012 - 01:58:43 - [52,844] ----D C:\Program Files (x86)\DVDFab 8 Qt
- O43 - CFD: 25/04/2012 - 17:10:34 - [159,564] ----D C:\Program Files (x86)\DWGeditor
- O43 - CFD: 21/01/2012 - 13:21:02 - [124,855] ----D C:\Program Files (x86)\EA Games
- O43 - CFD: 26/05/2012 - 21:09:38 - [103,075] ----D C:\Program Files (x86)\Electronic Arts
- O43 - CFD: 17/10/2011 - 22:46:26 - [39,898] ----D C:\Program Files (x86)\eRightSoft
- O43 - CFD: 26/05/2012 - 20:18:12 - [3,975] ----D C:\Program Files (x86)\Futuremark
- O43 - CFD: 22/09/2011 - 12:50:51 - [6,046] ----D C:\Program Files (x86)\GeoGebra
- O43 - CFD: 07/12/2011 - 18:23:46 - [2,432] ----D C:\Program Files (x86)\GiMeSpace Desktop Extender 3D
- O43 - CFD: 19/02/2012 - 19:46:26 - [18,755] ----D C:\Program Files (x86)\Glary Utilities
- O43 - CFD: 09/02/2012 - 22:41:27 - [45,279] ----D C:\Program Files (x86)\HTC
- O43 - CFD: 04/05/2012 - 20:43:33 - [3,005] ----D C:\Program Files (x86)\ImagePrinter
- O43 - CFD: 26/05/2012 - 20:18:12 - [1179,927] --H-D C:\Program Files (x86)\InstallShield Installation Information
- O43 - CFD: 22/11/2011 - 00:03:38 - [0,092] ----D C:\Program Files (x86)\Intel
- O43 - CFD: 02/03/2012 - 02:46:54 - [3,732] ----D C:\Program Files (x86)\Internet Explorer
- O43 - CFD: 21/04/2012 - 02:55:06 - [13,224] ----D C:\Program Files (x86)\IZArc
- O43 - CFD: 30/12/2011 - 22:00:20 - [3,276] ----D C:\Program Files (x86)\JAM Software
- O43 - CFD: 28/05/2012 - 13:49:39 - [177,441] ----D C:\Program Files (x86)\Java
- O43 - CFD: 06/01/2012 - 15:33:53 - [79,716] ----D C:\Program Files (x86)\Kroll Ontrack
- O43 - CFD: 11/03/2012 - 19:24:43 - [47,293] ----D C:\Program Files (x86)\Leawo
- O43 - CFD: 08/11/2011 - 08:30:02 - [10,535] ----D C:\Program Files (x86)\lg_fwupdate
- O43 - CFD: 28/05/2012 - 16:00:34 - [11,554] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
- O43 - CFD: 27/04/2012 - 03:19:59 - [135,654] ----D C:\Program Files (x86)\Matrix Multimedia
- O43 - CFD: 20/09/2011 - 12:17:21 - [-876,840] ----D C:\Program Files (x86)\METRO 2033
- O43 - CFD: 11/12/2011 - 13:14:12 - [-1923,097] ----D C:\Program Files (x86)\Micro Application
- O43 - CFD: 30/08/2011 - 00:01:53 - [0,216] ----D C:\Program Files (x86)\Microsoft
- O43 - CFD: 23/09/2011 - 14:27:04 - [0,764] ----D C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
- O43 - CFD: 25/04/2012 - 17:07:22 - [584,230] ----D C:\Program Files (x86)\Microsoft Office
- O43 - CFD: 18/03/2012 - 05:22:23 - [36,634] ----D C:\Program Files (x86)\Microsoft Silverlight
- O43 - CFD: 22/09/2011 - 21:27:04 - [0,014] ----D C:\Program Files (x86)\Microsoft Visual Studio
- O43 - CFD: 22/09/2011 - 21:25:05 - [56,656] ----D C:\Program Files (x86)\Microsoft Visual Studio 8
- O43 - CFD: 23/09/2011 - 14:23:57 - [3,554] ----D C:\Program Files (x86)\Microsoft Works
- O43 - CFD: 28/12/2011 - 14:42:12 - [0,934] ----D C:\Program Files (x86)\Microsoft WSE
- O43 - CFD: 22/09/2011 - 21:26:53 - [7,797] ----D C:\Program Files (x86)\Microsoft.NET
- O43 - CFD: 04/05/2012 - 20:31:56 - [0] ----D C:\Program Files (x86)\Miraplacid
- O43 - CFD: 26/05/2012 - 18:47:52 - [89,143] ----D C:\Program Files (x86)\Mozilla Firefox
- O43 - CFD: 04/05/2012 - 07:37:31 - [0,210] ----D C:\Program Files (x86)\Mozilla Maintenance Service
- O43 - CFD: 07/09/2011 - 00:07:52 - [7,032] ----D C:\Program Files (x86)\Mp3tag
- O43 - CFD: 22/09/2011 - 21:27:09 - [0,025] ----D C:\Program Files (x86)\MSBuild
- O43 - CFD: 14/12/2011 - 22:39:16 - [19,263] ----D C:\Program Files (x86)\MSECache
- O43 - CFD: 09/02/2012 - 22:39:48 - [0,147] ----D C:\Program Files (x86)\MSXML 4.0
- O43 - CFD: 19/09/2011 - 17:44:38 - [10,174] ----D C:\Program Files (x86)\MultiStage Recovery
- O43 - CFD: 30/12/2011 - 23:07:35 - [3,551] ----D C:\Program Files (x86)\MunSoft
- O43 - CFD: 29/10/2011 - 22:45:24 - [0] ----D C:\Program Files (x86)\My Company Name
- O43 - CFD: 24/11/2011 - 18:19:05 - [27,136] ----D C:\Program Files (x86)\NifTools
- O43 - CFD: 28/08/2011 - 22:34:09 - [11,160] ----D C:\Program Files (x86)\Notepad++
- O43 - CFD: 13/03/2012 - 23:07:11 - [372,101] ----D C:\Program Files (x86)\NVIDIA Corporation
- O43 - CFD: 01/12/2011 - 16:57:40 - [18,017] ----D C:\Program Files (x86)\OCCTPT
- O43 - CFD: 28/05/2012 - 13:49:57 - [33,186] ----D C:\Program Files (x86)\Oracle
- O43 - CFD: 14/05/2012 - 20:16:29 - [13,376] ----D C:\Program Files (x86)\Orbitdownloader
- O43 - CFD: 23/12/2011 - 20:44:25 - [46,023] ----D C:\Program Files (x86)\PC Fresh
- O43 - CFD: 04/01/2012 - 14:17:01 - [5,923] ----D C:\Program Files (x86)\PC Inspector File Recovery
- O43 - CFD: 05/09/2011 - 13:04:15 - [406,549] ----D C:\Program Files (x86)\Playrix Entertainment
- O43 - CFD: 31/12/2011 - 20:08:47 - [41,820] ----D C:\Program Files (x86)\PowerQuest
- O43 - CFD: 24/11/2011 - 18:14:51 - [71,007] ----D C:\Program Files (x86)\PyFFI
- O43 - CFD: 09/01/2012 - 21:48:39 - [4,627] ----D C:\Program Files (x86)\RAMDisk
- O43 - CFD: 14/07/2009 - 07:32:38 - [37,349] ----D C:\Program Files (x86)\Reference Assemblies
- O43 - CFD: 21/04/2012 - 14:54:42 - [2,166] ----D C:\Program Files (x86)\Resource Hacker
- O43 - CFD: 16/03/2012 - 19:21:23 - [16,513] R---D C:\Program Files (x86)\Skype
- O43 - CFD: 21/12/2011 - 18:49:24 - [-445,136] ----D C:\Program Files (x86)\Skyrim
- O43 - CFD: 25/04/2012 - 17:11:32 - [-1340,803] ----D C:\Program Files (x86)\SolidWorks
- O43 - CFD: 05/05/2012 - 18:18:15 - [5,564] ----D C:\Program Files (x86)\SpeedFan
- O43 - CFD: 09/02/2012 - 22:40:32 - [0,473] ----D C:\Program Files (x86)\Spirent Communications
- O43 - CFD: 18/09/2011 - 13:29:47 - [23,625] ----D C:\Program Files (x86)\Stardock
- O43 - CFD: 12/11/2011 - 00:27:59 - [0,467] ----D C:\Program Files (x86)\SystemRequirementsLab
- O43 - CFD: 04/03/2012 - 06:13:23 - [24,960] ----D C:\Program Files (x86)\TeamViewer
- O43 - CFD: 31/12/2011 - 11:34:58 - [119,765] ----D C:\Program Files (x86)\The Elder Scrolls V Skyrim
- O43 - CFD: 02/10/2011 - 03:51:35 - [-246,549] ----D C:\Program Files (x86)\The Witcher 2
- O43 - CFD: 23/09/2011 - 12:56:28 - [96,197] ----D C:\Program Files (x86)\THQ
- O43 - CFD: 14/07/2009 - 06:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information
- O43 - CFD: 16/09/2011 - 22:40:59 - [73,807] ----D C:\Program Files (x86)\VIA
- O43 - CFD: 29/08/2011 - 23:38:15 - [88,835] ----D C:\Program Files (x86)\VideoLAN
- O43 - CFD: 14/07/2009 - 13:04:03 - [0,500] ----D C:\Program Files (x86)\Windows Defender
- O43 - CFD: 30/08/2011 - 00:01:49 - [43,684] ----D C:\Program Files (x86)\Windows Live
- O43 - CFD: 30/08/2011 - 00:01:38 - [0,234] ----D C:\Program Files (x86)\Windows Live SkyDrive
- O43 - CFD: 28/08/2011 - 23:28:08 - [5,895] ----D C:\Program Files (x86)\Windows Mail
- O43 - CFD: 28/08/2011 - 23:28:08 - [4,791] ----D C:\Program Files (x86)\Windows Media Player
- O43 - CFD: 14/07/2009 - 07:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT
- O43 - CFD: 28/08/2011 - 23:28:08 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer
- O43 - CFD: 28/08/2011 - 23:28:08 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices
- O43 - CFD: 28/08/2011 - 23:28:08 - [5,717] ----D C:\Program Files (x86)\Windows Sidebar
- O43 - CFD: 12/05/2012 - 04:17:30 - [4,777] ----D C:\Program Files (x86)\Windows Virtual PC
- O43 - CFD: 20/04/2012 - 15:59:57 - [0,227] ----D C:\Program Files (x86)\WinPcap
- O43 - CFD: 21/01/2012 - 23:17:38 - [2,669] ----D C:\Program Files (x86)\WinSettings
- O43 - CFD: 22/11/2011 - 18:38:16 - [98,922] ----D C:\Program Files (x86)\Wondershare
- O43 - CFD: 12/12/2011 - 16:56:25 - [7,196] ----D C:\Program Files (x86)\Zentimo
- O43 - CFD: 29/05/2012 - 12:35:44 - [13,545] ----D C:\Program Files (x86)\ZHPDiag
- O43 - CFD: 10/01/2012 - 21:33:31 - [94,675] ----D C:\Program Files (x86)\Common Files\Acronis
- O43 - CFD: 29/10/2011 - 22:52:41 - [962,204] ----D C:\Program Files (x86)\Common Files\Adobe
- O43 - CFD: 09/02/2012 - 22:40:14 - [37,554] ----D C:\Program Files (x86)\Common Files\Adobe AIR
- O43 - CFD: 25/11/2011 - 14:16:07 - [902,469] ----D C:\Program Files (x86)\Common Files\Autodesk Shared
- O43 - CFD: 03/11/2011 - 23:00:43 - [0,132] ----D C:\Program Files (x86)\Common Files\CyberLink
- O43 - CFD: 25/04/2012 - 17:07:23 - [0,195] ----D C:\Program Files (x86)\Common Files\DESIGNER
- O43 - CFD: 25/04/2012 - 17:10:21 - [69,835] ----D C:\Program Files (x86)\Common Files\eDrawings2008
- O43 - CFD: 14/12/2011 - 22:37:46 - [29,184] ----D C:\Program Files (x86)\Common Files\Gestionnaire d'installation SolidWorks
- O43 - CFD: 22/11/2011 - 00:04:57 - [13,115] ----D C:\Program Files (x86)\Common Files\InstallShield
- O43 - CFD: 28/05/2012 - 13:52:23 - [1,181] ----D C:\Program Files (x86)\Common Files\Java
- O43 - CFD: 03/11/2011 - 22:55:25 - [35,512] ----D C:\Program Files (x86)\Common Files\LightScribe
- O43 - CFD: 14/12/2011 - 22:39:18 - [271,359] ----D C:\Program Files (x86)\Common Files\microsoft shared
- O43 - CFD: 29/10/2011 - 22:45:24 - [0,195] ----D C:\Program Files (x86)\Common Files\PX Storage Engine
- O43 - CFD: 14/07/2009 - 05:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
- O43 - CFD: 16/03/2012 - 19:21:23 - [2,056] ----D C:\Program Files (x86)\Common Files\Skype
- O43 - CFD: 25/04/2012 - 17:11:00 - [35,504] ----D C:\Program Files (x86)\Common Files\SolidWorks Shared
- O43 - CFD: 29/10/2011 - 22:45:24 - [0,355] ----D C:\Program Files (x86)\Common Files\Sonic Shared
- O43 - CFD: 14/07/2009 - 05:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines
- O43 - CFD: 10/11/2011 - 08:27:11 - [42,257] ----D C:\Program Files (x86)\Common Files\System
- O43 - CFD: 29/08/2011 - 13:31:15 - [0] ----D C:\Program Files (x86)\Common Files\Windows Live
- O43 - CFD: 25/04/2012 - 17:09:33 - [64,424] ----D C:\Program Files (x86)\Common Files\Wise Installation Wizard
- O43 - CFD: 22/11/2011 - 18:38:23 - [2,460] ----D C:\Program Files (x86)\Common Files\Wondershare
- ~ Scan Program Folder in 00mn 17s
- ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
- O44 - LFC:[MD5.4420883A6C0888F58E5CAAAC10BBEDB1] - 29/05/2012 - 11:35:58 ---A- . (...) -- C:\Windows\ntbtlog.txt [4607156]
- O44 - LFC:[MD5.2ACE366DC6958A97595E7B3D46E881BB] - 29/05/2012 - 09:42:38 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1414959]
- O44 - LFC:[MD5.FF83F0B73DF51F3D44B126D35EA788D9] - 29/05/2012 - 09:41:36 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1670440]
- O44 - LFC:[MD5.FB1B6F6290403B50BDF1C5128CF9C143] - 29/05/2012 - 09:41:36 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [122522]
- O44 - LFC:[MD5.24CFC675FEA303959DEC0C8DE2668C7C] - 29/05/2012 - 09:41:36 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [150356]
- O44 - LFC:[MD5.7814801AB3853213D0B2968F62A5E93D] - 29/05/2012 - 09:41:36 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [655650]
- O44 - LFC:[MD5.7B87C37558654284E971A2C6E43CC5BE] - 29/05/2012 - 09:41:36 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [749928]
- O44 - LFC:[MD5.FF83F0B73DF51F3D44B126D35EA788D9] - 29/05/2012 - 09:41:36 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1670440]
- O44 - LFC:[MD5.F26E6F80718AE900D3CCBAE83EEE0464] - 29/05/2012 - 09:35:42 ---A- . (...) -- C:\Windows\setupact.log [64152]
- O44 - LFC:[MD5.1ED30B20C09EDF099138E7113B7CC4A9] - 29/05/2012 - 09:35:41 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
- O44 - LFC:[MD5.D969837CEE63802B986F3E66FC36EA06] - 29/05/2012 - 07:19:47 ---A- . (...) -- C:\UsbFix.txt [17263]
- O44 - LFC:[MD5.E7C293FBC4FDF5CB471581DD1462DC2A] - 29/05/2012 - 06:20:01 ---A- . (...) -- C:\Windows\PFRO.log [22072]
- O44 - LFC:[MD5.9542A9AA7AB1002E0DC2CC33FF8582A4] - 27/05/2012 - 21:43:34 ----- . (...) -- C:\RansomFix_27052012_2243.txt [411]
- O44 - LFC:[MD5.C7A5932C6B5AFC180C49B965C1862B5C] - 26/05/2012 - 17:54:28 ----- . (...) -- C:\virus.rar [140278]
- O44 - LFC:[MD5.44E6089600364AD83DC34088CF3053EE] - 26/05/2012 - 17:47:52 ----- . (...) -- C:\pic.jpg [2502918]
- O44 - LFC:[MD5.022678D6636FEBF29FCDF241C5464466] - 12/05/2012 - 12:50:32 ---A- . (...) -- C:\Windows\SysNative\FNTCACHE.DAT [5129480]
- O44 - LFC:[MD5.73675FAAF12AE4FDDA1706EA890A79BE] - 04/05/2012 - 19:43:27 ---A- . (.Copyright (C) 2007-2010 Ibadov Tariel - Developed using the MinGw Ibadov Tariel.) -- C:\Windows\SysNative\imgport.dll [1375084]
- O44 - LFC:[MD5.BDC369986F9F71FA097B5FE2C065D701] - 04/05/2012 - 19:35:38 ----- . (...) -- C:\mail.jpg [200958]
- O44 - LFC:[MD5.65A92429071B169EFFC030A94F0C3437] - 04/05/2012 - 19:31:56 ----- . (...) -- C:\mpsetup.log [50455]
- O44 - LFC:[MD5.569445948F7A9ECFA8C843F9D58C8AAC] - 01/05/2012 - 22:23:45 ----- . (...) -- C:\Document1_1.jpg [1072576]
- ~ Scan Files in 00mn 14s
- ---\\ Contrôle du Safe Boot (CSB) (O49) (None)
- ---\\ MountPoints2 Shell Key (O51)
- O51 - MPSK:{29cef920-906b-11e1-9ec9-806e6f6e6963}\AutoRun\command. (.Daedalic Entertainment - Machinarium Setup.) -- I:\machinarium_install.exe
- ~ Scan Keys in 00mn 00s
- ---\\ ShareTools MSconfig StartupReg (O53) (None)
- ---\\ Liste des Drivers Système (O58)
- O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
- O58 - SDL:[MD5.A82C01606DC27D05D9D3BFB6BB807E32] - 04/08/2009 - 10:28:28 ---A- . (...) -- C:\Windows\SysWOW64\drivers\AsIO.sys [13440]
- O58 - SDL:[MD5.12583AF6CBE0050651EAF2723B3AD7B3] - 18/03/2011 - 17:08:56 ---A- . (.Almico Software - SpeedFan x64 Driver.) -- C:\Windows\SysWOW64\speedfan.sys [29592]
- ~ Scan Drivers in 00mn 00s
- ---\\ File Associations Shell Spawning (O67)
- O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- ~ Scan Keys in 00mn 00s
- ---\\ Start Menu Internet (O68) (None)
- ---\\ Search Browser Infection (O69)
- O69 - SBI: SearchScopes [HKCU] ${searchCLSID} - (@ieframe.dll,-12512) - http://search.live.com
- O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
- O69 - SBI: SearchScopes [HKCU] {95B7759C-8C7F-4BF1-B163-73684A933233} - (AVG Secure Search) - http://isearch.avg.com
- ~ Scan Keys in 00mn 00s
- ---\\ Recherche des services démarrés par Svchost (O83) (None)
- ---\\ Recherche particuliere à la racine de certains dossiers (O84)
- [MD5.7E7EB7AFF595774E5E500B34058CC1A7] [SPRF][05/05/2012] (...) -- C:\Users\TheFireNight\AppData\Local\Temp\sfamcc00001.dll [192512]
- [MD5.51151D3AD8DA0DFA0E7A681AA2FF8870] [SPRF][05/05/2012] (...) -- C:\Users\TheFireNight\AppData\Local\Temp\sfareca00001.dll [158720]
- [MD5.A4A8CE1C7696B143356208609BA1A4C9] [SPRF][18/12/2010] (...) -- C:\Users\TheFireNight\AppData\Local\Temp\sfextra.dll [55296]
- [MD5.8D03B10F0DCED524A88A3FF4B370F50D] [SPRF][18/01/2012] (...) -- C:\Users\TheFireNight\AppData\Local\Temp\sqlite3.exe [465408]
- [MD5.6602AC57EFA112AB40C0EA2BFA3A8886] [SPRF][22/01/2008] (.Pas de propriétaire - SWINSTRES MFC Application.) -- C:\Users\TheFireNight\AppData\Local\Temp\swinstres.dll [83224]
- [MD5.563DDD0F98830A643B4FF851AE4EDDBA] [SPRF][22/01/2008] (.SolidWorks Corporation - MSETUP MFC Application.) -- C:\Users\TheFireNight\AppData\Local\Temp\swmires.dll [1824024]
- [MD5.37DE6C2EC99D36B3BDEAA5C38A23F8EB] [SPRF][19/03/2012] (.Microsoft Corporation - Windows Live Installer.) -- C:\Users\TheFireNight\AppData\Local\Temp\wlsetup-cvr.exe [152509800]
- [MD5.4BF437CDDF8C692738CFA413231C9B3C] [SPRF][16/05/2012] (.Yontoo LLC - Yontoo Runtime.) -- C:\Users\TheFireNight\AppData\Local\Temp\YontooIEClient.dll [194928]
- [MD5.E8F0C3AF81A302E9E1580F851AD84C5F] [SPRF][22/05/2012] (.Yontoo LLC - Installer.) -- C:\Users\TheFireNight\AppData\Local\Temp\YontooSetup-S.exe [1051840]
- [MD5.4F2FCC010E7FC16AC664E53141E4258B] [SPRF][19/02/2012] (...) -- C:\Users\TheFireNight\AppData\Local\Temp\~gu-ver.dat [131]
- [MD5.C385759EE20390E42F000475687002AD] [SPRF][30/12/2011] (...) -- C:\Users\TheFireNight\Desktop\BootSector_DriveG.dat [512]
- [MD5.11F8513A73636B122996588432AAAA8F] [SPRF][31/12/2011] (...) -- C:\Users\TheFireNight\Desktop\BootSector_DriveH(s).dat [512]
- [MD5.55B871EBDEDF31B813D0B1DD9E8C6710] [SPRF][31/12/2011] (...) -- C:\Users\TheFireNight\Desktop\BootSector_DriveH.dat [512]
- [MD5.FD4DB196596A1AEB0208607661EC4E8B] [SPRF][07/12/2003] (.e-merge GmbH - WinAce Self-Extractor.) -- C:\Users\TheFireNight\Desktop\Borland Builder 6.0 DLL Files.exe [936507]
- [MD5.94A90E3FB00CBF795204B6A74CB606C8] [SPRF][18/09/2011] (.Stardock Corporation, Inc. - DeskScapes Installation.) -- C:\Users\TheFireNight\Desktop\deskscapes_public.exe [55492520]
- [MD5.86D1B2E9C7C11B99305EB6597D80CB0A] [SPRF][18/03/2008] (.Microsoft Corporation - Microsoft Windows 7 Ultimate Extra: Windows DreamScene.) -- C:\Users\TheFireNight\Desktop\DreamScene.dll [233888]
- [MD5.5CE8E62BAD59805A8D203C4289A8CE75] [SPRF][05/11/2008] (...) -- C:\Users\TheFireNight\Desktop\DreamScene.reg [16180]
- [MD5.AD02810B9BF9D855740BA2B3A46AF396] [SPRF][09/03/2009] (.InstallShield Software Corporation - Setup.exe.) -- C:\Users\TheFireNight\Desktop\Installer Scientific workplace (SWP) Pro 5.50.2953.exe [92396799]
- [MD5.07886398F5223B638CFDA8B3EBD2FFD6] [SPRF][31/12/2011] (...) -- C:\Users\TheFireNight\Desktop\MBR.dat [512]
- [MD5.45ED62C317AAD54B1989F76EBD5A06D1] [SPRF][31/12/2011] (...) -- C:\Users\TheFireNight\Desktop\MBR_HardDisk1.dat [512]
- [MD5.284F0A4ABB0F54C7BF42316D02D9F430] [SPRF][31/12/2011] (...) -- C:\Users\TheFireNight\Desktop\MBR_HardDisk2.dat [512]
- [MD5.AEE49FE16DD04188BBDDED80D613E3BE] [SPRF][01/05/2012] (.Miraplacid - Miraplacid Publisher Setup.) -- C:\Users\TheFireNight\Desktop\mpublisher.exe [5091328]
- [MD5.AEE49FE16DD04188BBDDED80D613E3BE] [SPRF][04/05/2012] (.Miraplacid - Miraplacid Publisher Setup.) -- C:\Users\TheFireNight\Desktop\mpublisher[1].exe [5091328]
- [MD5.AEE49FE16DD04188BBDDED80D613E3BE] [SPRF][04/05/2012] (.Miraplacid - Miraplacid Publisher Setup.) -- C:\Users\TheFireNight\Desktop\mpublisher[2].exe [5091328]
- [MD5.158E44A0504C8AFD5CED5EE8B1445106] [SPRF][02/03/2011] (.Orbmu2k - NVIDIA Inspector.) -- C:\Users\TheFireNight\Desktop\nvidiaInspector.exe [530432]
- [MD5.CD404196D281780AEDCA5E3BFD81E73A] [SPRF][17/01/2006] (.MacKichan Software - Scientific Workplace.) -- C:\Users\TheFireNight\Desktop\swp-pro.exe [5214265]
- [MD5.38E6B942506EB0DA8C6E8A17A9BC74C6] [SPRF][28/05/2012] (.El Desaparecido - UsbFix NSIS Installer.) -- C:\Users\TheFireNight\Desktop\UsbFix.exe [1499012]
- [MD5.11B9F1E66EE67F0C765C5895A99755DD] [SPRF][29/08/2011] (...) -- C:\Users\TheFireNight\Desktop\vlc-1.1.11-win32.exe [21073936]
- [MD5.F4A8BF342CBB05600A0999EAE4B6253E] [SPRF][18/09/2011] (...) -- C:\Users\TheFireNight\Desktop\windows-7-dreamscene-installer.exe [347783]
- [MD5.FB30D948346F9367A83DFE5BAB2668F8] [SPRF][22/08/2011] (.Adobe Systems, Inc. - Adobe® Flash® Player Installer/Uninstaller 10.3 r183.) -- C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe [3126944]
- ~ Scan Files in 00mn 03s
- End of the scan (758 lines in 01mn 01s)(0)
Advertisement
Add Comment
Please, Sign In to add comment