re-bonjour voila le premier rapport (main.txt)
Deckard's System Scanner v20071014.68
Run by aurelien on 2008-05-19 19:51:08
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
41: 2008-05-19 17:51:14 UTC - RP41 - Deckard's System Scanner Restore Point
40: 2008-05-19 13:50:35 UTC - RP40 - Software Distribution Service 3.0
39: 2008-05-18 23:46:51 UTC - RP39 - Software Distribution Service 3.0
38: 2008-05-18 22:59:38 UTC - RP38 - Supprimé EPSON Web-To-Page
37: 2008-05-18 22:59:12 UTC - RP37 - Removed Google Toolbar
for Internet Explorer
-- First Restore Point --
1: 2008-05-13 18:05:44 UTC - RP1 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as aurelien.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:51:47, on 19/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\winsys2.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET NOD32
Antivirus\egui.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ESET\ESET NOD32
Antivirus\ekrn.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Fichiers communs\Softwin\
BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\aurelien.ALPINE-\Mes documents\reparer windows\dss.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\aurelien.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.google.com/search?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32
Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall
BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} -
http://www.orange.fr (file missing) (HKCU)
O15 - ESC Trusted Zone:
http://*.update.microsoft.com
O16 - DPF: CabBuilder -
http://kiw.imgag.com/imgag/kiw/toolbar/ ... ontrol.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/activescan ... stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windows ... 8357086812
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2005 ... scan53.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service:
BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\
BitDefender Scan Server\bdss.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32
Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32
Antivirus\ekrn.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service:
BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\
BitDefender Update Service\livesrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: DiRT Drivers Auto Removal (pr2ah4nc) (pr2ah4nc) - CODEMASTERS - C:\WINDOWS\system32\pr2ah4nc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service:
BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
O23 - Service:
BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Fichiers communs\Softwin\
BitDefender Communicator\xcommsvr.exe
--
End of file - 8751 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080518-005342-732 O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
backup-20080518-005342-952 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-005813-165 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-010025-325 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-010528-109 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-010707-702 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
backup-20080518-010707-834 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-011034-178 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-013541-775 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-014544-300 O4 - HKLM\..\Run: [BM77adae23] Rundll32.exe "C:\WINDOWS\system32\evmyweqi.dll",s
backup-20080518-165331-264 O2 - BHO: (no name) - {F26692C2-426C-4EAF-B5B2-779B334965C3} - (no file)
backup-20080518-165331-330 O2 - BHO: (no name) - {4ABAB99C-79B9-4CA8-92E7-634715C30127} - (no file)
backup-20080518-165331-362 O2 - BHO: (no name) - {B82F29E4-8368-4B14-9C00-5138C0D94034} - (no file)
backup-20080518-165331-540 O2 - BHO: (no name) - {8DF95D70-5699-4F34-9AC7-98DEA4A53392} - (no file)
backup-20080518-165331-550 O2 - BHO: (no name) - {45C693F5-7236-4EAA-988E-5CE5608C7B9C} - (no file)
backup-20080518-165331-629 O2 - BHO: (no name) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - (no file)
backup-20080518-165331-696 O2 - BHO: (no name) - {1269125A-3ACA-40FA-8D28-4A396FAF2438} - (no file)
backup-20080518-165331-725 O2 - BHO: (no name) - {77BE8E39-68C1-444D-83DF-C1077E27B8CE} - (no file)
backup-20080518-165331-927 O20 - Winlogon Notify: nnnoLBRj - nnnoLBRj.dll (file missing)
backup-20080518-165331-933 O2 - BHO: (no name) - {FB5EAFD2-C373-410C-9925-DA3372693EF4} - (no file)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - c:\windows\system32\pcandis5.sys <Not>
S3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 FTRTSVC (France Telecom Routing Table Service) - c:\windows\system32\ftrtsvc.exe <Not>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 PLFlash DeviceIoControl Service - c:\windows\system32\ioctlsvc.exe <Not>
S4 Boonty Games - "c:\program files\fichiers communs\boonty shared\service\boonty.exe" <Not>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8169/8110 Family Gigabit Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8167&SUBSYS_235C1462&REV_10\4&11B6166B&0&30F0
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8169/8110 Family Gigabit Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8167&SUBSYS_235C1462&REV_10\4&11B6166B&0&30F0
Service: RTL8023xp
Class GUID: {4D36E97B-E325-11CE-BFC1-08002BE10318}
Description: NERO IMAGEDRIVE SCSI Controller
Device ID: IMAGEDRV\NEROIMAGEDRV\0000
Manufacturer: Fabricant inconnu
Name: NERO IMAGEDRIVE SCSI Controller
PNP Device ID: IMAGEDRV\NEROIMAGEDRV\0000
Service: imagedrv
-- Scheduled Tasks -------------------------------------------------------------
2008-05-19 16:30:00 404 --a------ C:\WINDOWS\Tasks\Advanced WindowsCare V2 Pro.job
2008-05-19 15:11:34 318 --a------ C:\WINDOWS\Tasks\GlaryInitialize.job
2008-05-18 20:00:00 416 --a------ C:\WINDOWS\Tasks\AwcProUpdate.job
-- Files created between 2008-04-19 and 2008-05-19 -----------------------------
2008-05-19 19:16:48 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\WinRAR
2008-05-19 18:20:03 0 d-------- C:\VundoFix Backups
2008-05-19 15:50:36 0 d-------- C:\WINDOWS\LastGood
2008-05-19 00:43:10 0 d--hs---- C:\Documents and Settings\aurelien.ALPINE-\Recent
2008-05-19 00:14:05 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-05-18 19:38:48 0 d-------- C:\Program Files\Winsos
2008-05-18 19:33:46 89600 --a------ C:\WINDOWS\system32\CMCTLFR.DLL <Not>
2008-05-18 19:33:46 20992 --a------ C:\WINDOWS\system32\CMCT2FR.DLL <Not>
2008-05-18 19:33:44 0 d-------- C:\Program Files\PerfectToolsXP2
2008-05-18 19:18:15 51611 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-05-18 19:15:34 4847 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-05-18 19:14:55 0 d-------- C:\WINDOWS\BricoPacks
2008-05-18 17:27:53 0 d-------- C:\Program Files\Bus Simulator
2008-05-18 17:26:22 0 d-------- C:\Program Files\DAEMON Tools
2008-05-18 17:09:46 306688 --a------ C:\WINDOWS\IsUninst.exe <Not>
2008-05-18 04:37:34 2930 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-18 04:37:01 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-18 04:37:01 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not>
2008-05-18 04:37:01 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not>
2008-05-18 04:37:01 82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not>
2008-05-18 04:37:00 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not>
2008-05-18 04:35:09 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-18 04:35:08 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not>
2008-05-18 02:24:23 0 d-------- C:\Program Files\Panda Security
2008-05-18 01:48:58 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Grisoft
2008-05-18 01:48:50 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-05-18 00:49:06 0 d-------- C:\Program Files\Trend Micro
2008-05-17 20:57:50 0 d-------- C:\Program Files\Spyware Doctor
2008-05-17 20:03:32 36864 --a------ C:\WINDOWS\system32\IfHelper.dll <Not>
2008-05-17 00:25:49 6029312 --a------ C:\Documents and Settings\aurelien.ALPINE-\ntuser.dat
2008-05-17 00:25:48 1572864 --a------ C:\Documents and Settings\LocalService.AUTORITE NT.000\ntuser.dat
2008-05-15 06:31:30 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ESET
2008-05-15 05:25:53 114688 --a------ C:\WINDOWS\system32\ffyrovdl.dll
2008-05-15 05:16:54 933 --a------ C:\WINDOWS\system32\cwlsvjwg.exe
2008-05-14 22:05:43 0 d-------- C:\Program Files\Registry Easy
2008-05-14 20:07:24 507904 --a------ C:\WINDOWS\TMUPDATE.DLL <Not>
2008-05-14 20:07:19 69689 --a------ C:\WINDOWS\UNZIP.DLL <Not>
2008-05-14 20:07:14 286720 --a------ C:\WINDOWS\PATCH.EXE <Not>
2008-05-14 19:49:28 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-14 19:49:28 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\SUPERAntiSpyware.com
2008-05-14 10:07:42 933 --a------ C:\WINDOWS\system32\msbmeyjj.exe
2008-05-14 10:05:08 526225 ---hs---- C:\WINDOWS\system32\eeigkbdc.ini2
2008-05-14 10:04:27 114176 --a------ C:\WINDOWS\system32\cdbkgiee.dll
2008-05-14 10:01:28 123392 --a------ C:\WINDOWS\system32\sofnpuus.dll
2008-05-14 04:43:05 0 d-------- C:\Program Files\SAGEM
2008-05-14 02:28:19 0 d-------- C:\Program Files\Advanced Spyware Remover
2008-05-14 00:44:33 0 d-------- C:\WINDOWS\NV21962692.TMP
2008-05-14 00:44:12 69632 -ra------ C:\WINDOWS\system32\sw24.exe
2008-05-13 20:01:22 0 d-------- C:\WINDOWS\Prefetch
2008-05-13 19:45:08 0 d-------- C:\WINDOWS\NV8081048.TMP
2008-05-13 15:57:56 131584 --a------ C:\WINDOWS\system32\pvflgdek.dll
2008-05-13 15:55:06 114688 --a------ C:\WINDOWS\system32\fsvxfwwx.dll
2008-05-13 03:45:44 132096 --a------ C:\WINDOWS\system32\jagilgbv.dll
2008-05-13 03:39:43 125952 --a------ C:\WINDOWS\system32\wgvtgljf.dll
2008-05-13 03:35:13 0 d-------- C:\Program Files\Glary Utilities
2008-05-13 03:33:59 0 d-------- C:\Program Files\AxBx
2008-05-13 03:09:01 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Comodo
2008-05-13 03:09:00 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\comodo
2008-05-13 03:08:58 0 d-------- C:\Program Files\COMODO
2008-05-13 03:05:38 505574 --ahs---- C:\WINDOWS\system32\MWEgNnnn.ini2
2008-05-13 03:05:36 370688 --a------ C:\WINDOWS\system32\nnnNgEWM.dll
2008-05-13 02:47:08 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-05-13 02:01:08 505797 --ahs---- C:\WINDOWS\system32\mTAdcccf.ini2
2008-05-12 21:56:16 505530 --ahs---- C:\WINDOWS\system32\XENWxyxx.ini2
2008-05-12 15:00:49 0 d-------- C:\Program Files\LightDriver(2)
2008-05-12 14:56:26 0 d-------- C:\Program Files\BlocPub
2008-05-12 03:12:58 0 d-------- C:\Program Files\langart
2008-05-12 03:08:37 0 d-------- C:\Program Files\Kaspersky Lab
2008-05-12 03:05:30 0 d-------- C:\Program Files\PC Wizard 2007
2008-05-12 03:03:46 0 d-------- C:\Program Files\RegCleaner
2008-05-12 02:44:01 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Webroot
2008-05-12 02:44:00 0 d-------- C:\Program Files\Webroot
2008-05-12 02:44:00 0 d-------- C:\Program Files\Fichiers communs\Webroot Shared
2008-05-12 01:08:25 2855 --a------ C:\WINDOWS\system32\kb16.PIF
2008-05-11 22:14:48 933 --a------ C:\WINDOWS\system32\puttradv.exe
2008-05-11 22:13:50 704989 --ahs---- C:\WINDOWS\system32\NVGiPqru.ini2
2008-05-11 20:23:13 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not>
2008-05-11 20:09:13 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-05-11 17:01:01 0 d-------- C:\Program Files\uTorrent
2008-05-11 01:11:54 198982 --ahs---- C:\WINDOWS\system32\edehknnn.ini2
2008-05-09 22:20:50 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Codemasters
2008-05-09 22:19:49 0 dr-h----- C:\Documents and Settings\aurelien.ALPINE-\Application Data\SecuROM
2008-05-09 22:19:15 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallShield
2008-05-09 22:19:01 0 d-------- C:\WINDOWS\85EBB28365AF4C539EBE7C0A232762F7.TMP
2008-05-09 22:18:48 0 d-------- C:\ProgramData
2008-05-09 19:35:01 0 d-------- C:\Program Files\Codemasters
2008-05-09 16:15:41 133120 --a------ C:\WINDOWS\system32\vjaefxcx.dll
2008-05-09 16:12:33 196312 --ahs---- C:\WINDOWS\system32\gikjknpo.ini2
2008-05-09 16:07:19 0 d-------- C:\Extracted
2008-05-09 16:06:34 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\BOONTY
2008-05-09 16:06:28 0 d-------- C:\Program Files\Fichiers communs\BOONTY Shared
2008-05-09 16:06:12 0 d-------- C:\Program Files\BoontyGames
2008-05-06 02:32:58 0 d-------- C:\Program Files\GameHouse
2008-05-05 01:04:34 0 d-------- C:\My Downloads
2008-05-05 00:53:15 0 d-------- C:\Program Files\BitRoll
2008-05-03 22:36:27 0 d-------- C:\Program Files\GameShadow
2008-05-03 22:26:39 0 d-------- C:\Program Files\Eidos
2008-05-03 22:25:38 0 d-------- C:\Program Files\OpenAL
2008-05-03 19:37:01 0 d-------- C:\Program Files\EPSON Print CD
2008-05-03 19:35:31 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\UDL
2008-05-03 19:32:42 495616 --a------ C:\WINDOWS\system32\PICSDK2.dll <Not>
2008-05-03 19:32:42 73728 --a------ C:\WINDOWS\system32\PICSDK.dll <Not>
2008-05-03 19:32:41 77824 --a------ C:\WINDOWS\system32\PICEntry.dll <Not>
2008-05-03 19:32:41 114688 --a------ C:\WINDOWS\system32\EpPicPrt.dll <Not>
2008-05-03 19:32:41 111932 --a------ C:\WINDOWS\system32\EPPICPrinterDB.dat
2008-05-03 19:32:41 1139 --a------ C:\WINDOWS\system32\EPPICPresetData_PT.dat
2008-05-03 19:32:41 1120 --a------ C:\WINDOWS\system32\EPPICPresetData_IT.dat
2008-05-03 19:32:41 1107 --a------ C:\WINDOWS\system32\EPPICPresetData_GE.dat
2008-05-03 19:32:41 1129 --a------ C:\WINDOWS\system32\EPPICPresetData_FR.dat
2008-05-03 19:32:41 1136 --a------ C:\WINDOWS\system32\EPPICPresetData_ES.dat
2008-05-03 19:32:41 1104 --a------ C:\WINDOWS\system32\EPPICPresetData_EN.dat
2008-05-03 19:32:41 1146 --a------ C:\WINDOWS\system32\EPPICPresetData_DU.dat
2008-05-03 19:32:41 1129 --a------ C:\WINDOWS\system32\EPPICPresetData_CF.dat
2008-05-03 19:32:41 1139 --a------ C:\WINDOWS\system32\EPPICPresetData_BP.dat
2008-05-03 19:32:41 4943 --a------ C:\WINDOWS\system32\EPPICPattern6.dat
2008-05-03 19:32:41 21390 --a------ C:\WINDOWS\system32\EPPICPattern5.dat
2008-05-03 19:32:41 11811 --a------ C:\WINDOWS\system32\EPPICPattern4.dat
2008-05-03 19:32:41 24903 --a------ C:\WINDOWS\system32\EPPICPattern3.dat
2008-05-03 19:32:41 20148 --a------ C:\WINDOWS\system32\EPPICPattern2.dat
2008-05-03 19:32:41 31053 --a------ C:\WINDOWS\system32\EPPICPattern131.dat
2008-05-03 19:32:41 27417 --a------ C:\WINDOWS\system32\EPPICPattern121.dat
2008-05-03 19:32:41 26154 --a------ C:\WINDOWS\system32\EPPICPattern1.dat
2008-05-03 19:32:41 65536 --a------ C:\WINDOWS\system32\EPPicMgr.dll <Not>
2008-05-03 17:52:53 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
2008-05-03 17:52:28 0 d-------- C:\Program Files\epson
2008-05-01 23:40:26 0 d-------- C:\Program Files\City Interactive
2008-05-01 02:36:04 0 d-------- C:\Program Files\D-Tools
2008-05-01 00:03:08 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ScreenSeven
2008-05-01 00:03:07 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Intenium
2008-05-01 00:02:53 0 d-------- C:\Program Files\Beetle Ju 3
2008-04-30 22:49:06 0 d-------- C:\Program Files\Tomb Raider - Anniversary
2008-04-27 23:55:38 20 --a------ C:\WINDOWS\popcinfot.dat
2008-04-27 23:55:36 16 --a------ C:\WINDOWS\popcinfo.dat
2008-04-27 23:36:35 0 d-------- C:\Bejeweled 2 Deluxe en Español
2008-04-27 16:50:43 0 d-------- C:\WINDOWS\Snow Queen Mahjong
2008-04-27 16:50:43 0 d-------- C:\Program Files\Snow Queen Mahjong
2008-04-26 15:38:45 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Gaijin Ent
2008-04-26 14:36:50 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\AlwaysNeat
2008-04-26 14:36:29 0 d-------- C:\Program Files\GamesBar
2008-04-26 14:36:03 0 d-------- C:\Program Files\orange
2008-04-26 14:36:03 0 d-------- C:\Program Files\Fichiers communs\Oberon Media
2008-04-26 02:56:56 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Media Player Classic
2008-04-25 16:54:13 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\PCToolsFirewallPlus
2008-04-25 16:50:15 0 d-------- C:\temp
2008-04-25 16:41:12 0 d-------- C:\Program Files\PC Tools Firewall Plus
2008-04-25 16:32:11 0 d-------- C:\Roadkil's Error List
2008-04-25 16:28:13 0 d-------- C:\Program Files\Lavalys
2008-04-25 16:25:05 0 d-------- C:\Program Files\Satsuki Decoder Pack
2008-04-25 16:18:41 0 d-------- C:\Program Files\PopUp Destroy
2008-04-24 13:41:55 164352 --a------ C:\WINDOWS\system32\unrar.dll
2008-04-24 13:41:52 217088 --a------ C:\WINDOWS\system32\yv12vfw.dll <Not>
2008-04-24 13:41:52 159839 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-04-24 13:41:52 755027 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-04-24 13:41:51 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-04-24 13:41:51 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not>
2008-04-24 13:41:51 682496 --a------ C:\WINDOWS\system32\divx.dll <Not>
2008-04-24 13:41:48 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-04-24 13:30:31 0 d-------- C:\Program Files\Riva
2008-04-21 22:34:01 215144 --a------ C:\WINDOWS\patchw32.dll
2008-04-21 22:31:07 0 d-------- C:\Program Files\AGEIA Technologies
2008-04-21 22:11:40 0 d-------- C:\Program Files\THQ
2008-04-21 15:48:27 0 d-------- C:\Program Files\Alcohol Soft
2008-04-21 15:45:03 639224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-04-21 03:02:37 0 d-------- C:\Program Files\eMule
2008-04-20 19:49:17 216602 --ahs---- C:\WINDOWS\system32\DccKnXbc.ini2
2008-04-19 20:53:06 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
-- Find3M Report ---------------------------------------------------------------
2008-05-19 19:11:51 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\uTorrent
2008-05-19 19:11:28 0 d-a------ C:\Program Files\Wanadoo
2008-05-19 15:13:00 53 --a------ C:\biosinfo
2008-05-19 15:11:24 0 d-------- C:\Program Files\Google
2008-05-19 01:26:41 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Macromedia
2008-05-19 01:11:59 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Adobe
2008-05-19 01:02:36 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-19 00:58:17 501740 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-05-19 00:58:17 80670 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-05-19 00:26:24 0 d-------- C:\Program Files\Fichiers communs
2008-05-18 19:51:44 0 d-------- C:\Program Files\Movie Maker
2008-05-18 19:18:14 219648 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-05-18 19:02:58 0 d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-05-15 21:45:11 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-05-14 02:39:05 0 d-------- C:\Program Files\IObit
2008-05-13 19:53:43 23704 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-04-21 00:05:40 0 d-------- C:\Program Files\MSN Messenger
2008-04-15 20:23:56 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-14 23:57:04 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Simply Super Software
2008-04-14 21:29:49 195593 --ahs---- C:\WINDOWS\system32\oVFhRXbc.ini2
2008-04-13 20:58:57 196916 --ahs---- C:\WINDOWS\system32\HiiSuBeg.ini2
2008-04-13 20:26:28 198671 --ahs---- C:\WINDOWS\system32\bKStEMoq.ini2
2008-04-11 20:09:57 0 d-------- C:\Program Files\NeroInstall.bak
2008-04-11 19:46:00 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Nero
2008-04-11 19:41:15 0 d-------- C:\Program Files\Nero
2008-04-11 18:21:37 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\GlarySoft
2008-04-11 18:04:18 0 d-------- C:\Program Files\Microsoft Silverlight
2008-04-11 03:01:16 0 d-------- C:\Program Files\MSXML 6.0
2008-04-10 23:00:02 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\vlc
2008-04-09 19:44:40 0 d-------- C:\Program Files\MSBuild
2008-04-09 19:39:53 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-09 17:45:39 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Ubisoft
2008-04-08 22:49:45 0 d-------- C:\Program Files\Messenger
2008-04-08 19:12:30 0 d-------- C:\Program Files\Java
2008-04-08 19:11:03 0 d-------- C:\Program Files\VideoLAN
2008-04-08 19:10:31 0 d-------- C:\Documents and Settings\aurelien.ALPINE-\Application Data\Sun
2008-04-08 18:37:40 0 d-------- C:\Program Files\Securitoo
2008-04-08 18:28:25 0 d-------- C:\Program Files\Intel
2008-04-08 18:20:48 0 d-------- C:\Program Files\Realtek
2008-04-08 17:54:40 0 d-------- C:\Program Files\Setup Files
2008-04-08 17:15:56 0 d-------- C:\Program Files\CCleaner
2008-04-08 00:01:27 62 --ahs---- C:\Documents and Settings\aurelien.ALPINE-\Application Data\desktop.ini
2008-04-05 18:55:50 0 d-------- C:\Program Files\Fichiers communs\Nero
2008-03-29 21:49:56 0 d-------- C:\Program Files\Fichiers communs\Adobe
2008-03-27 23:52:22 0 d-------- C:\Program Files\Microsoft Games
2008-03-22 03:35:00 0 d-------- C:\Program Files\Fichiers communs\BitCtrl
2008-03-09 07:25:10 236 --ah----- C:\Program Files\Fichiers communs\dx.reg
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [12/04/2007 17:44 C:\WINDOWS\system32\nwiz.exe]
"SW20"="C:\WINDOWS\system32\sw20.exe" [15/12/2006 04:58]
"SW24"="C:\WINDOWS\system32\sw24.exe" [15/12/2006 04:58]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [28/02/2008 09:59]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [18/02/2008 16:29]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/04/2007 17:44]
"WinSys2"="C:\WINDOWS\system32\winsys2.exe" [15/12/2006 04:59]
"RTHDCPL"="RTHDCPL.EXE" [04/05/2006 09:59 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 12:43 C:\WINDOWS\Alcmtr.exe]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [23/08/2004 14:49]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [12/04/2007 17:44]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [14/10/2004 16:55]
"egui"="C:\Program Files\ESET\ESET NOD32
Antivirus\egui.exe" [13/03/2008 16:48]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [10/04/2008 15:14]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 11:25]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [12/11/2006 12:48]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [28/02/2008 17:07]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [02/03/2006 14:00]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [11/05/2008 17:01]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [23/08/2004 14:50]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sockspy.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\urqPiGVN
"Notification Packages"= :\WINDOWS\system32\srrstr.dll cli scecli scecli scecli scecli scecli scecli scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{47a5bd36-23dc-11dc-bccf-806d6172696f}]
-- Hosts -----------------------------------------------------------------------
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
www.032439.com
127.0.0.1 032439.com
8382 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-05-19 19:52:29 ------------