Bonjour,
Comme tout (ou presque) était revenu à la normale, je n'ai pas suivi...
Il n'y a plus de problème majeur, mais quelques messages curieux par ci par là, connexion internet aléatoire... et comme nous ne sommes jamais aller au bout de cette procédure, je souhaiterai vraiment terminé.
FindyKill -> Option 1, puis Option 2
Il a trouver des choses, surtout des trucs corrompu. Si besoin des rapports, je les posterais.
J'ai désinstallé, réinstaller
Antivir.
Voici le rapport OTList: faut-il executer le fix?
OTListIt logfile created on: 2009-04-18 13:44:12 - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Propriétaire\Bureau
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: yyyy-MM-dd
2.00 Gb Total Physical Memory | 1.52 Gb Available Physical Memory | 75.96% Memory free
3.85 Gb Paging File | 3.47 Gb Available in Paging File | 90.22% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.65 Gb Total Space | 55.34 Gb Free Space | 56.67% Space Free | Partition Type: NTFS
Drive D: | 368.10 Gb Total Space | 296.74 Gb Free Space | 80.61% Space Free | Partition Type: NTFS
Drive E: | 317.79 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
Drive G: | 186.31 Gb Total Space | 185.34 Gb Free Space | 99.48% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 3.84 Gb Total Space | 1.31 Gb Free Space | 34.20% Space Free | Partition Type: FAT32
Computer Name: VINY-71E5D7ACCC
Current User Name: Propriétaire
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2006-10-23 14:50:35 | 00,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe
PRC - [2008-12-12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2009-03-29 20:55:49 | 04,414,520 | ---- | M] (
Prevx) -- C:\Program Files\
Prevx\
prevx.exe
PRC - [2009-02-06 19:08:58 | 00,533,360 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe
PRC - [2009-02-11 16:05:14 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2009-03-09 06:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2007-05-08 17:00:48 | 02,179,072 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Multimedia Keyboard Driver\V5\KMWDSrv.exe
PRC - [2007-08-08 09:25:08 | 00,836,904 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
PRC - [2007-04-12 23:44:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2007-05-28 18:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2007-01-04 23:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2003-08-27 11:29:46 | 00,065,536 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\wanmpsvc.exe
PRC - [2004-08-19 16:09:54 | 01,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009-03-29 20:55:49 | 04,414,520 | ---- | M] (
Prevx) -- C:\Program Files\
Prevx\
prevx.exe
PRC - [2008-05-27 10:50:30 | 00,413,696 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QTTask.exe
PRC - [2002-06-03 12:38:12 | 00,049,152 | ---- | M] (ScanSoft, Inc) -- C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
PRC - [2006-09-26 02:52:48 | 00,050,736 | ---- | M] (America Online, Inc.) -- C:\Program Files\Fichiers communs\AOL\1203422821\ee\AOLSoftware.exe
PRC - [2006-11-14 11:21:28 | 16,270,848 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2008-02-19 00:05:36 | 00,026,112 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\RealPlay.exe
PRC - [2007-03-06 14:51:14 | 00,212,992 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Multimedia Keyboard Driver\V5\StartAutorun.exe
PRC - [2007-09-17 22:51:14 | 01,470,464 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Multimedia Keyboard Driver\V5\KMConfig.exe
PRC - [2009-02-06 19:08:58 | 00,454,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsui.exe
PRC - [2009-02-27 13:39:24 | 00,753,664 | ---- | M] (Apple Inc.) -- C:\Program Files\AirPort\APAgent.exe
PRC - [2009-03-09 06:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2007-09-25 23:18:54 | 00,561,152 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Multimedia Keyboard Driver\V5\KMProcess.exe
PRC - [2004-05-10 23:49:40 | 00,156,784 | -H-- | M] (America Online, Inc.) -- C:\Program Files\AOL 9.0b\aoltray.exe
PRC - [2007-12-14 16:58:30 | 00,241,664 | ---- | M] () -- C:\Program Files\Philips\Philips SPC230NC Webcam\TrayMin230.exe
PRC - [2007-05-29 10:37:02 | 00,654,336 | ---- | M] (Hercules) -- C:\Program Files\Hercules\WiFi Station\WifiStation.exe
PRC - [2008-12-31 19:58:48 | 00,143,360 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
PRC - [2006-06-01 22:33:22 | 00,001,536 | ---- | M] () -- c:\program files\fichiers communs\aol\1203422821\ee\services\antiSpywareApp\ver2_0_28_1\AOLSP Scheduler.exe
PRC - [2008-12-31 19:58:48 | 00,125,440 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
PRC - [2008-10-15 13:31:25 | 00,068,865 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\sched.exe
PRC - [2008-06-12 13:28:40 | 00,266,497 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\avgnt.exe
PRC - [2008-10-15 13:29:28 | 00,151,297 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\avguard.exe
PRC - [2009-04-18 13:03:03 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Propriétaire\Bureau\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2006-10-23 14:50:35 | 00,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe -- (AOL ACS [Auto | Running])
SRV - [2008-07-25 12:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008-12-12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008-07-25 12:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009-03-29 20:55:49 | 04,414,520 | ---- | M] (
Prevx) -- C:\Program Files\
Prevx\
prevx.exe -- (CSIScanner [Auto | Running])
SRV - [2008-07-29 22:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009-02-06 19:08:58 | 00,533,360 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc [Auto | Running])
SRV - [2009-02-11 16:05:14 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c98c51c3ba61c2 [Auto | Stopped])
SRV - [2004-08-19 16:09:38 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008-07-29 20:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - File not found -- -- (iisrstap32 [Auto | Stopped])
SRV - [2009-03-09 06:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2007-05-08 17:00:48 | 02,179,072 | ---- | M] (UASSOFT.COM) -- C:\Program Files\Multimedia Keyboard Driver\V5\KMWDSrv.exe -- (KMWDSERVICE [Auto | Running])
SRV - [2007-11-15 10:09:42 | 00,121,360 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ [On_Demand | Stopped])
SRV - [2007-08-08 09:25:08 | 00,836,904 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3 [Auto | Running])
SRV - [2008-07-29 20:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007-08-03 12:51:18 | 00,382,248 | ---- | M] (Nero AG) -- C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2007-04-12 23:44:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008-08-12 15:58:11 | 00,066,872 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrA.txt -- (PnkBstrA [Auto | Stopped])
SRV - [2009-01-14 18:53:02 | 00,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort [Disabled | Stopped])
SRV - [2007-05-28 18:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE [Auto | Running])
SRV - [2007-01-04 23:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service [Auto | Running])
SRV - [2003-08-27 11:29:46 | 00,065,536 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\wanmpsvc.exe -- (WANMiniportService [Auto | Running])
SRV - [2006-11-03 10:59:14 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2008-10-15 13:31:25 | 00,068,865 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
SRV - [2008-10-15 13:29:28 | 00,151,297 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
========== Driver Services (SafeList) ==========
DRV - [2008-01-23 10:19:44 | 00,501,560 | ---- | M] (Protect Software GmbH) -- C:\WINDOWS\system32\drivers\acedrv11.sys -- (acedrv11 [Auto | Running])
DRV - [2009-04-17 22:23:33 | 00,021,419 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\DRIVERS\AegisP.sys -- (AegisP [Auto | Running])
DRV - [2005-02-22 23:58:56 | 00,011,776 | ---- | M] (Arcsoft, Inc.) -- C:\WINDOWS\system32\drivers\Afc.sys -- (Afc [On_Demand | Running])
DRV - [2008-05-22 17:01:39 | 00,278,984 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\atksgt.sys -- (atksgt [Auto | Running])
DRV - [2008-05-09 12:15:47 | 00,045,376 | ---- | M] (
Avira GmbH) -- C:\WINDOWS\SYSTEM32\DRIVERS\avgntdd.sys -- (avgntdd [System | Stopped])
DRV - [2008-12-08 18:01:56 | 00,055,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys -- (fssfltr [Auto | Running])
DRV - [2005-01-07 18:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2006-11-15 08:34:40 | 04,225,920 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2006-02-07 13:52:58 | 00,006,912 | R--- | M] (JMicron ) -- C:\WINDOWS\system32\DRIVERS\JGOGO.sys -- (JGOGO [Boot | Running])
DRV - [2006-10-30 05:31:58 | 00,043,648 | R--- | M] (JMicron Technology Corp.) -- C:\WINDOWS\system32\DRIVERS\jraid.sys -- (JRAID [Boot | Running])
DRV - [2007-09-21 03:10:20 | 00,020,240 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys -- (L8042Kbd [On_Demand | Stopped])
DRV - [2007-09-21 03:10:26 | 00,063,120 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\L8042mou.Sys -- (L8042mou [On_Demand | Stopped])
DRV - [2009-01-19 16:35:20 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd [Boot | Running])
DRV - [2004-08-03 22:59:34 | 00,034,688 | ---- | M] (Toshiba Corp.) -- C:\WINDOWS\System32\drivers\lbrtfdc.sys -- (lbrtfdc [System | Stopped])
DRV - [2007-09-21 03:10:40 | 00,035,088 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys -- (LHidFilt [On_Demand | Running])
DRV - [2008-05-22 17:01:39 | 00,025,416 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\lirsgt.sys -- (lirsgt [Auto | Running])
DRV - [2007-09-21 03:10:46 | 00,036,240 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys -- (LMouFilt [On_Demand | Running])
DRV - [2007-09-21 03:10:54 | 00,078,992 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\LMouKE.Sys -- (LMouKE [On_Demand | Stopped])
DRV - [2004-08-13 04:56:20 | 00,005,810 | R--- | M] () -- C:\WINDOWS\system32\DRIVERS\ASACPI.sys -- (MTsensor [On_Demand | Running])
DRV - [2007-04-12 23:44:00 | 06,738,656 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2006-04-24 19:52:28 | 00,100,736 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata [Boot | Running])
DRV - [2006-02-17 13:28:30 | 00,034,176 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2006-02-17 13:28:32 | 00,013,056 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2007-09-26 14:28:46 | 00,008,576 | ---- | M] (PixArt Imaging Incorporation) -- C:\WINDOWS\system32\DRIVERS\PAEAFLT.sys -- (PAEAFLT.sys [On_Demand | Running])
DRV - [2004-08-05 05:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2009-03-29 20:55:49 | 00,022,024 | ---- | M] (
Prevx) -- C:\WINDOWS\System32\drivers\pxscan.sys -- (pxscan [Boot | Running])
DRV - [2006-12-01 11:00:32 | 00,395,648 | ---- | M] (Ralink Technology Inc.) -- C:\WINDOWS\system32\DRIVERS\RT61.sys -- (RT61 [On_Demand | Running])
DRV - [2008-03-27 18:43:20 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\SECDRV.SYS -- (SecDrv [Auto | Running])
DRV - [2001-08-17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
DRV - [2007-12-31 16:19:50 | 00,461,056 | ---- | M] (PixArt Imaging Inc.) -- C:\WINDOWS\system32\DRIVERS\SPC230NC.SYS -- (SPC230NC [On_Demand | Running])
DRV - [2009-01-13 17:05:54 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2007-11-08 18:03:26 | 00,021,248 | ---- | M] (
AVIRA GmbH) -- C:\WINDOWS\system32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2003-01-10 17:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\system32\DRIVERS\wanatw4.sys -- (wanatw [On_Demand | Running])
DRV - [2008-05-20 15:29:43 | 00,052,032 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
DRV - [2007-02-27 14:24:55 | 00,011,840 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
DRV - [2008-10-30 10:21:03 | 00,075,072 | ---- | M] (
Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1078081533-789336058-725345543-1002\S-1-5-21-1078081533-789336058-725345543-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1078081533-789336058-725345543-1002\S-1-5-21-1078081533-789336058-725345543-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.planete-aventure.net/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5
FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009-02-05 22:24:42 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008-11-15 20:14:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2008-12-18 16:11:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2008-12-18 16:11:03 | 00,000,000 | ---D | M]
[2008-11-08 22:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Propriétaire\Application Data\mozilla\Extensions
[2008-11-08 22:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Propriétaire\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-02-05 22:38:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Propriétaire\Application Data\mozilla\Firefox\Profiles\rykeb851.default\extensions
[2008-11-15 20:27:38 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Application Data\Mozilla\FireFox\Profiles\rykeb851.default\searchplugins\aim-search.xml
[2008-12-31 19:58:47 | 00,001,775 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Application Data\Mozilla\FireFox\Profiles\rykeb851.default\searchplugins\live-search.xml
[2009-04-09 21:27:13 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2008-12-18 16:11:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008-02-18 22:46:01 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008-03-21 16:06:05 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008-07-21 13:58:13 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008-11-15 20:14:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008-12-03 15:04:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009-03-27 18:48:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2008-12-18 16:10:56 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2008-12-18 16:10:56 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2006-09-10 13:35:08 | 00,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2008-11-19 17:15:22 | 00,000,757 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2008-04-16 06:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2006-09-10 13:35:08 | 00,000,748 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MediaDICO-fr.xml
[2008-03-29 15:59:44 | 00,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2006-09-12 20:49:04 | 00,000,652 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe" (Apple Inc.)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe (AOL LLC)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\
Avira\
AntiVir PersonalEdition Classic\avgnt.exe" /min (
Avira GmbH)
O4 - HKLM..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun (Microsoft Corporation)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1203422821\ee\AOLSoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot (JMicron Technology Corp.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [KMConfig] "C:\Program Files\Multimedia Keyboard Driver\V5\StartAutorun.exe" KMConfig.exe File not found
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER (RealNetworks, Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SPC_Monitor] C:\WINDOWS\Philips\SPC230NC\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [SPC230NC_Monitor] C:\WINDOWS\Philips\SPC230NC\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1078081533-789336058-725345543-1002..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount (Alcohol Soft Development Team)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0b\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\TrayMin230.lnk = C:\Program Files\Philips\Philips SPC230NC Webcam\TrayMin230.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WiFi Station.lnk = C:\Program Files\Hercules\WiFi Station\WifiStation.exe (Hercules)
O4 - Startup: C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage\Outil de notification Live Search.lnk = C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 1
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 1
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogoff = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKU\S-1-5-21-1078081533-789336058-725345543-1002_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions -
res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html ()
O8 - Extra context menu item: Easy-WebPrint Impression rapide -
res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html ()
O8 - Extra context menu item: Easy-WebPrint Imprimer -
res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html ()
O8 - Extra context menu item: Easy-WebPrint Prévisualiser -
res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html ()
O9 - Extra Button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\..Trusted Domains: aol.com ([objects] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1078081533-789336058-725345543-1002\..Trusted Domains: 56 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8}
http://download.playfirst.com/play/game ... 0.0.21.cab (CPlayFirstFashionDasControl Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (Reg Error: Key error.)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC}
http://www.pogo.com/cdl/launcher/PogoWe ... taller.CAB (PogoWebLauncher Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3}
http://copainsdavant.linternaute.com/fr ... oader5.cab (Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windows ... 4310147937 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microso ... 4310862125 (MUWebControl Class)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737}
http://menki.spaces.live.com/PhotoUpload/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2}
https://signin2.valueactive.com/Registe ... lashax.cab (FlashXControl Object)
O16 - DPF: {E41BA393-9078-424E-9554-9DB5126F5F4C}
http://download.playfirst.com/play/game ... 0.0.13.cab (CPlayFirstDreamChronControl Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll - c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-02-18 22:41:09 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004-11-05 16:38:44 | 00,002,238 | R--- | M] () - E:\Autorun.ico -- [ CDFS ]
O32 - AutoRun File - [2004-11-19 10:47:43 | 00,000,045 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{0140c6e8-f67b-11dc-98af-001d60b2cec8}\Shell - "" = AutoRun
O33 - MountPoints2\{0140c6e8-f67b-11dc-98af-001d60b2cec8}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O33 - MountPoints2\{eb825756-0437-11de-9acd-001d60b2cec8}\Shell - "" = AutoRun
O33 - MountPoints2\{eb825756-0437-11de-9acd-001d60b2cec8}\Shell\AutoRun\command - "" = H:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[6 C:\WINDOWS\*.tmp files]
[2013-07-18 18:03:24 | 01,825,892 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Mes documents\margaux1.JPG
[2013-07-18 18:03:06 | 01,800,380 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Mes documents\margaux.JPG
[2009-04-18 13:37:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Bureau\french
[2009-04-18 13:36:56 | 00,000,776 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Configure FileMenu Tools.lnk
[2009-04-18 13:36:56 | 00,000,000 | ---D | C] -- C:\Program Files\LopeSoft
[2009-04-18 13:31:58 | 00,001,851 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\
AntiVir PE Classic.lnk
[2009-04-18 13:31:55 | 00,075,072 | ---- | C] (
Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009-04-18 13:31:55 | 00,045,376 | ---- | C] (
Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009-04-18 13:31:55 | 00,022,336 | ---- | C] (
Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009-04-18 13:31:55 | 00,000,000 | ---D | C] -- C:\Program Files\
Avira
[2009-04-18 13:04:20 | 00,001,376 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Bureau\FindyKill.lnk
[2009-04-18 13:04:18 | 00,000,000 | ---D | C] -- C:\FindyKill
[2009-04-18 13:02:08 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Propriétaire\Bureau\OTListIt2.exe
[2009-04-17 22:23:24 | 00,395,648 | ---- | C] (Ralink Technology Inc.) -- C:\WINDOWS\System32\drivers\rt61.sys
[2009-04-17 22:23:24 | 00,395,008 | ---- | C] (Ralink Technology Inc.) -- C:\WINDOWS\System32\drivers\RT619x.sys
[2009-04-17 22:23:24 | 00,238,080 | ---- | C] (Ralink Technology Inc.) -- C:\WINDOWS\System32\drivers\rt25009x.sys
[2009-04-17 22:23:24 | 00,236,800 | ---- | C] (Ralink Technology Inc.) -- C:\WINDOWS\System32\drivers\rt2500.sys
[2009-04-17 22:23:24 | 00,008,192 | ---- | C] () -- C:\WINDOWS\System32\drivers\rt2661.bin
[2009-04-17 22:23:24 | 00,008,192 | ---- | C] () -- C:\WINDOWS\System32\drivers\rt2561s.bin
[2009-04-17 22:23:24 | 00,008,192 | ---- | C] () -- C:\WINDOWS\System32\drivers\rt2561.bin
[2009-04-17 22:23:24 | 00,001,732 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\WiFi Station.lnk
[2009-04-17 22:23:24 | 00,001,563 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WiFi Station.lnk
[2009-04-17 22:23:24 | 00,000,000 | ---D | C] -- C:\Program Files\Hercules
[2009-04-17 22:23:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\InstallShield
[2009-04-16 12:34:00 | 01,076,371 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Bureau\constat2_avril09.PDF
[2009-04-16 12:32:17 | 01,490,670 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Bureau\constat1_avril09.PDF
[2009-04-15 18:14:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Bureau\torrents
[2009-04-14 21:06:12 | 00,001,621 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Bureau\Travel Agency.lnk
[2009-04-14 21:06:10 | 00,000,000 | ---D | C] -- C:\Program Files\Travel Agency
[2009-04-11 19:32:54 | 00,000,000 | ---D | C] -- C:\Program Files\Hospital Hustle
[2009-04-11 18:11:12 | 00,000,000 | ---D | C] -- C:\Program Files\Games
[2009-04-10 22:01:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\uTorrent
[2009-04-10 16:41:20 | 00,000,630 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Bureau\µTorrent.lnk
[2009-04-10 16:22:00 | 00,000,853 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Mes documents\Raccourci vers utorrent.lnk
[2009-04-10 13:54:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Mes documents\Jack Keane
[2009-04-10 13:52:08 | 00,001,955 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Bureau\Jouer à Jack Keane.lnk
[2009-04-10 13:49:09 | 00,000,000 | ---D | C] -- C:\Program Files\10TACLE STUDIOS
[2009-04-09 09:56:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\Ice Cream Craze
[2009-04-09 09:56:00 | 00,000,000 | ---D | C] -- C:\Program Files\Ice Cream Craze
[2009-04-08 19:34:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Ranch Rush
[2009-04-08 13:02:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\Sortasoft
[2009-04-08 13:02:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sortasoft
[2009-04-08 12:51:59 | 00,000,000 | ---D | C] -- C:\WINDOWS\Funky Farm 2
[2009-04-08 12:30:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Mes documents\Megaplex Madness
[2009-04-08 12:29:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Megaplex Madness Now Playing
[2009-04-07 16:34:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\eGames
[2009-04-07 16:34:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\eGames
[2009-04-07 16:34:23 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\Propriétaire\Application Data\.#
[2009-04-07 16:34:23 | 00,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\SWF Studio
[2009-04-06 20:23:52 | 00,024,364 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Mes documents\Poste.jpg
[2009-04-06 15:08:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\ShinyTales
[2009-04-06 14:52:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\sowhat
[2009-04-06 14:52:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\Wonderburg
[2009-04-04 19:04:50 | 04,628,357 | ---- | C] () -- C:\Documents and Settings\Propriétaire\Bureau\Christophe Willem - Berlin.mp3
[2009-04-03 20:16:22 | 00,000,000 | ---D | C] -- C:\Program Files\Fashion Craze
[2009-04-03 14:40:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\Wendys Wellness
[2009-04-02 19:55:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\Shape games
[2009-04-02 19:55:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Success Story
[2009-04-01 19:00:22 | 00,000,000 | ---D | C] -- C:\Program Files\Women's Murder Club
[2009-03-31 20:17:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\Total Eclipse
[2009-03-31 18:47:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\Anabel
[2009-03-30 18:54:09 | 00,000,000 | ---D | C] -- C:\Program Files\AxBx
[2009-03-28 21:26:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Bureau\musikfilm usa
[2009-03-24 20:31:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\ZEMNOTT
[2009-03-23 23:09:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\Coyotes Tale
[2009-03-22 21:20:25 | 00,022,024 | ---- | C] (
Prevx) -- C:\WINDOWS\System32\drivers\pxscan.sys
[2009-03-22 21:20:25 | 00,000,000 | ---D | C] -- C:\Program Files\
Prevx
[2009-03-22 21:20:22 | 00,000,048 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009-03-22 21:20:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2009-03-22 20:58:56 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009-03-22 20:58:56 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009-03-22 20:58:56 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009-03-22 20:58:56 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009-03-22 20:58:56 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009-03-22 20:58:56 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009-03-22 20:58:56 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009-03-22 20:58:56 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009-03-22 20:58:56 | 00,028,672 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009-03-22 20:58:52 | 00,400,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF32472.exe
[2009-03-22 20:58:52 | 00,000,000 | ---D | C] -- C:\ComboFix
[2009-03-22 19:33:35 | 00,152,904 | ---- | C] () -- C:\WINDOWS\System32\vghd.scr
[2009-03-22 19:33:35 | 00,000,000 | ---D | C] -- C:\Program Files\vghd
[2009-03-22 19:33:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\vghd
[2009-03-22 19:33:32 | 00,000,001 | ---- | C] () -- C:\WINDOWS\System32\uniq.tll
[2009-03-22 19:31:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\Tropical Mania
[2009-03-22 16:12:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\Flood Light Games
[2009-02-26 15:47:51 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2009-02-26 15:47:51 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2009-02-26 15:47:51 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2009-02-26 15:34:22 | 00,000,254 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009-01-13 21:07:34 | 00,000,145 | ---- | C] () -- C:\WINDOWS\GAME.INI
[2009-01-13 17:05:54 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-11-28 16:54:06 | 00,000,433 | ---- | C] () -- C:\WINDOWS\Buildalot3.ini
[2008-10-29 18:17:30 | 00,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2008-10-03 14:34:39 | 00,000,842 | ---- | C] () -- C:\WINDOWS\System32\SPC230NC.INI
[2008-07-24 20:01:34 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-07-09 20:58:44 | 00,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008-07-04 10:12:56 | 00,000,071 | ---- | C] () -- C:\WINDOWS\Pex.INI
[2008-06-11 12:24:06 | 00,025,713 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2008-05-22 17:01:39 | 00,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008-05-22 17:01:39 | 00,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008-02-24 21:00:43 | 00,000,109 | ---- | C] () -- C:\WINDOWS\NAVIGMA.INI
[2008-02-19 00:24:21 | 00,000,525 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008-02-19 00:16:45 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS79.DLL
[2008-02-18 23:45:54 | 00,000,907 | R--- | C] () -- C:\WINDOWS\System32\AsusSetup.ini
[2008-02-18 23:45:54 | 00,000,263 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2008-02-18 23:43:49 | 00,013,412 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2008-02-18 23:43:37 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008-02-18 23:43:36 | 00,013,174 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008-02-18 23:43:26 | 00,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007-07-23 09:03:32 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007-07-23 09:03:32 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007-07-23 09:03:32 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007-04-12 23:44:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007-04-12 23:44:00 | 01,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007-04-12 23:44:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007-04-12 23:44:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007-04-12 23:44:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004-10-24 21:41:59 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\60a8c6af.dll
[2004-10-24 21:41:58 | 00,010,752 | ---- | C] () -- C:\WINDOWS\System32\59ccf640.dll
[2004-10-24 21:41:55 | 00,000,034 | ---- | C] () -- C:\WINDOWS\System32\00be9f99.dll
[2004-08-05 05:00:00 | 00,000,738 | ---- | C] () -- C:\WINDOWS\win.ini
[2004-08-05 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[5 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2013-07-18 18:03:24 | 01,825,892 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Mes documents\margaux1.JPG
[2013-07-18 18:03:06 | 01,800,380 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Mes documents\margaux.JPG
[2009-04-18 13:36:56 | 00,000,776 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Configure FileMenu Tools.lnk
[2009-04-18 13:31:58 | 00,001,851 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\
AntiVir PE Classic.lnk
[2009-04-18 13:20:00 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-04-18 13:04:20 | 00,001,376 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Bureau\FindyKill.lnk
[2009-04-18 13:03:03 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Propriétaire\Bureau\OTListIt2.exe
[2009-04-18 12:42:25 | 00,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-04-17 22:38:55 | 00,000,738 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-04-17 22:23:24 | 00,001,732 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\WiFi Station.lnk
[2009-04-17 22:23:24 | 00,001,563 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WiFi Station.lnk
[2009-04-16 12:34:00 | 01,076,371 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Bureau\constat2_avril09.PDF
[2009-04-16 12:32:43 | 00,025,713 | ---- | M] () -- C:\WINDOWS\CSTBox.INI
[2009-04-16 12:32:17 | 01,490,670 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Bureau\constat1_avril09.PDF
[2009-04-14 21:06:12 | 00,001,621 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Bureau\Travel Agency.lnk
[2009-04-14 14:55:22 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-04-11 17:56:52 | 00,046,080 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-04-10 22:11:40 | 04,238,934 | -H-- | M] () -- C:\Documents and Settings\Propriétaire\Local Settings\Application Data\IconCache.db
[2009-04-10 16:41:20 | 00,000,630 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Bureau\µTorrent.lnk
[2009-04-10 16:22:00 | 00,000,853 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Mes documents\Raccourci vers utorrent.lnk
[2009-04-10 13:52:08 | 00,001,955 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Bureau\Jouer à Jack Keane.lnk
[2009-04-09 20:05:29 | 00,000,630 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Mes documents\µTorrent.lnk
[2009-04-09 20:05:15 | 00,270,128 | ---- | M] (BitTorrent, Inc.) -- C:\Documents and Settings\Propriétaire\Mes documents\utorrent.exe
[2009-04-09 18:43:12 | 00,000,145 | ---- | M] () -- C:\WINDOWS\GAME.INI
[2009-04-06 20:04:26 | 00,024,364 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Mes documents\Poste.jpg
[2009-04-04 19:08:22 | 04,628,357 | ---- | M] () -- C:\Documents and Settings\Propriétaire\Bureau\Christophe Willem - Berlin.mp3
[2009-03-29 20:55:49 | 00,022,024 | ---- | M] (
Prevx) -- C:\WINDOWS\System32\drivers\pxscan.sys
[2009-03-29 20:55:45 | 00,000,048 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009-03-22 21:14:09 | 00,003,072 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009-03-22 20:58:50 | 00,400,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF32472.exe
[2009-03-22 19:33:35 | 00,152,904 | ---- | M] () -- C:\WINDOWS\System32\vghd.scr
[2009-03-22 19:33:32 | 00,000,001 | ---- | M] () -- C:\WINDOWS\System32\uniq.tll
[2009-03-22 17:35:53 | 00,000,071 | ---- | M] () -- C:\WINDOWS\Pex.INI
========== Alternate Data Streams ==========
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A688EF17
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5D351BC6
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\PnkBstrA.txt:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\ntdll.dll:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\lsasrv.dll:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\dllhst3g.exe:SummaryInformation
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E66FFABE
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A2349A15
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4DDCE10B
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A4E5024A
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:77846FFE
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E55CE2D1
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0D31DA45
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BD9F7