OTListIt logfile created on: 09/02/2009 07:52:14 - Run 3
OTListIt2 by OldTimer - Version 1.0.4.1 Folder = C:\Documents and Settings\Fouzi\Bureau\Nouveau dossier (2)\logs
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free
4,00 Gb Paging File | 3,99 Gb Available in Paging File | 99,86% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,04 Gb Total Space | 96,56 Gb Free Space | 64,79% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-4CF35A70
Current User Name: Fouzi
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== [2007/08/22 02:57:14 | 00,487,424 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
[2007/08/22 02:57:14 | 00,487,424 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
[2008/06/12 14:46:25 | 00,068,865 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\sched.exe
[2008/08/07 09:17:00 | 00,149,761 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avguard.exe
[2008/07/31 14:19:32 | 00,075,008 | ---- | M] (Verdiem) -- C:\Program Files\Verdiem\Edison\edsvc.exe
[2008/11/22 03:05:37 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2006/02/17 09:35:58 | 00,127,035 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
[2008/11/04 17:00:27 | 00,107,832 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe
[2006/04/21 21:06:14 | 00,069,632 | ---- | M] () -- C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
[2007/07/24 10:15:14 | 00,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe
[2006/02/17 09:39:02 | 00,139,264 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
[2006/03/02 13:00:00 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2008/06/12 14:28:45 | 00,266,497 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgnt.exe
[2007/11/06 15:03:36 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[2006/03/02 13:00:00 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2008/10/15 08:06:26 | 00,633,632 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2007/09/20 09:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
[2009/02/08 08:39:54 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Fouzi\Bureau\Nouveau dossier (2)\logs\OTListIt2.exe
========== (O23) Win32 Services (SafeList) ========== [2008/06/12 14:46:25 | 00,068,865 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
[2008/08/07 09:17:00 | 00,149,761 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
[2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2007/08/22 02:57:14 | 00,487,424 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
[2007/08/21 20:05:00 | 00,593,920 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
[2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2008/07/31 14:19:32 | 00,075,008 | ---- | M] (Verdiem) -- C:\Program Files\Verdiem\Edison\edsvc.exe -- (edsvc [Auto | Running])
[2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2006/02/17 09:39:02 | 00,139,264 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM) [Auto | Running])
[2006/02/17 09:17:08 | 00,020,543 | ---- | M] (Apache Software Foundation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe -- (ForcewareWebInterface [Auto | Stopped])
[2006/03/02 13:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll -- (helpsvc [Auto | Running])
[2005/04/03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
[2004/08/19 15:09:32 | 00,028,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\irmon.dll -- (Irmon [Auto | Running])
[2008/11/22 03:05:37 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
[2006/11/10 18:18:02 | 00,774,144 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])
[2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2006/02/17 09:35:58 | 00,127,035 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -- (nSvcIp [Auto | Running])
[2006/02/17 09:35:42 | 00,061,503 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -- (nSvcLog [Auto | Stopped])
[2005/02/09 11:59:00 | 00,014,165 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI [Auto | Stopped])
[2008/11/04 17:00:27 | 00,107,832 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB [Auto | Running])
[2006/04/21 21:06:14 | 00,069,632 | ---- | M] () -- C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe -- (prfldsvc [Auto | Running])
[2007/07/24 10:15:14 | 00,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2 [Auto | Running])
[2007/05/28 17:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE [Auto | Stopped])
[2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
[2007/10/25 14:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
[2006/09/28 18:56:14 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WudfSvc.dll -- (WudfSvc [Auto | Running])
========== Driver Services (SafeList) ========== [2007/08/22 03:07:38 | 02,417,664 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
[2007/02/27 15:25:01 | 00,011,840 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
[2008/05/20 16:29:41 | 00,052,032 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
[2008/06/27 15:03:55 | 00,075,072 | ---- | M] (
Avira GmbH) -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb [System | Running])
[2001/08/17 21:19:20 | 00,003,712 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\ctljystk.sys -- (ctljystk [On_Demand | Stopped])
[2001/08/17 21:19:26 | 00,283,904 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\emu10k1m.sys -- (emu10k [On_Demand | Stopped])
[2001/08/17 21:19:28 | 00,006,912 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\ctlfacem.sys -- (emu10k1 [On_Demand | Stopped])
[2003/03/02 17:44:26 | 00,007,552 | ---- | M] () -- C:\WINDOWS\system32\drivers\enodpl.sys -- (enodpl [Auto | Running])
[2004/08/04 00:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum [On_Demand | Stopped])
[2005/01/07 16:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus [On_Demand | Running])
[2006/11/15 07:34:40 | 04,225,920 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService [On_Demand | Running])
[2001/08/17 20:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir [On_Demand | Running])
[2006/02/07 12:52:58 | 00,006,912 | R--- | M] (JMicron ) -- C:\WINDOWS\system32\drivers\JGOGO.sys -- (JGOGO [Boot | Running])
[2006/10/30 04:31:58 | 00,043,648 | R--- | M] (JMicron Technology Corp.) -- C:\WINDOWS\system32\drivers\jraid.sys -- (JRAID [Boot | Running])
[2007/01/04 09:07:00 | 00,171,520 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus [On_Demand | Running])
[2004/08/13 03:56:20 | 00,005,810 | R--- | M] () -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor [On_Demand | Stopped])
[2006/04/24 18:52:28 | 00,100,736 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata [Boot | Running])
[2006/02/17 12:28:30 | 00,034,176 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD [On_Demand | Stopped])
[2006/02/17 12:28:32 | 00,013,056 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus [On_Demand | Stopped])
[2004/08/09 12:29:28 | 00,053,920 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\prodrv06.sys -- (prodrv06 [System | Running])
[2004/08/09 12:33:26 | 00,114,016 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\prohlp02.sys -- (prohlp02 [Boot | Running])
[2004/07/19 15:49:54 | 00,007,040 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\prosync1.sys -- (prosync1 [Boot | Running])
[2006/04/21 08:22:24 | 00,070,912 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\system32\drivers\prvflder.sys -- (Prvflder [Auto | Running])
[2006/03/02 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2008/07/23 17:50:48 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
[2008/02/25 19:54:56 | 00,105,088 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp [On_Demand | Stopped])
[2008/09/22 00:55:56 | 00,011,973 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [Auto | Running])
[2003/12/01 16:20:52 | 00,004,832 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfhlp01.sys -- (sfhlp01 [Boot | Running])
[2001/08/17 21:19:34 | 00,036,480 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\sfmanm.sys -- (sfman [On_Demand | Stopped])
[2001/08/17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[2008/12/23 17:54:23 | 00,717,296 | ---- | M] () -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd [Boot | Running])
[2007/03/01 10:34:22 | 00,028,352 | ---- | M] (
Avira GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv [System | Running])
[2003/04/19 00:32:04 | 00,004,736 | ---- | M] () -- C:\WINDOWS\system32\drivers\tandpl.sys -- (tandpl [Auto | Running])
[2004/08/03 23:07:56 | 00,059,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio [On_Demand | Stopped])
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.01net.com/telecharger/HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.01net.com/telecharger/HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.01net.com/telecharger/HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,OpenAllHomePages =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearchHKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,UseHomepageForNewTab =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.01net.com/telecharger/HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,OpenAllHomePages =
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearchHKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,UseHomepageForNewTab =
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKU\S-1-5-21-1645522239-1965331169-682003330-1004\S-1-5-21-1645522239-1965331169-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (790 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {06EB2FBE-E7EC-4168-9B26-69485898A458} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {13E183D4-4BBE-432D-84CD-680F1C66C9A7} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {2B20E67A-8DFF-4FE8-BBFD-EF0793E0F47F} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {36E3DFB7-BB5A-4FA7-9D65-43C38E80BE86} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {431282A3-AA0E-41B4-B91C-D0DEADAAB963} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {435FC890-E0EA-4D92-9567-E4E4D95E7E88} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {447049C6-B3EE-4EA2-AFAF-BA23E01381CC} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {4D27EFD4-44F5-41FC-9A3A-8A076868BBB5} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {555B6C0B-97C4-42CA-BB03-BFCFD63485AB} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {569EF718-F44B-484C-9276-FD61945AEF27} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {578a413e-4ee4-42fd-b7cc-095978da6fe8} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {58579b73-e2a2-4b6a-a243-2a17d7620a4f} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {60F4E57A-CBEC-45FE-A696-061DB69120F7} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {731D68E0-A87A-47F9-BE77-75275AC3999A} - C:\WINDOWS\system32\pmnlmnLb.dll ()
O2 - BHO: (no name) - {75E1E749-0F2C-4488-96A8-A10A25BA272B} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {88959262-BFA2-490D-B153-DEA9F891C0AE} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (
Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {911425d1-6377-4116-8513-35fe0d7962b6} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {9E5D32BF-E4AA-4AAB-9B9E-D4AC87AD80BF} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {9F5AFDC2-298C-4133-8964-A7364F6DCE93} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {A08EFE85-0FA0-443A-9A98-33447D051367} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {ac1d21c2-8241-47e8-86d8-aee1bd280b1f} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {CD27B6AC-ED02-4F7C-9648-0C1E56CE553F} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {d5fd8047-42ed-4355-9904-9e626bf53398} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {E4380BEE-D589-440B-B51E-33DCBCB52FC0} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {e5df3590-9d37-46cf-a250-99a4653a88c2} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {EBCF7556-FEED-4932-8FBE-141812CA7248} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {EF31A357-48C8-4A71-A453-7DF40EDF0C51} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {F0DEE68F-2F32-4EF0-82C4-E742CD5D3249} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {F8B0FF64-1050-4E88-9B2B-F5A3975E67DA} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (
Avira GmbH)
O4 - HKCU..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (Piriform Ltd)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-1645522239-1965331169-682003330-1004..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (Piriform Ltd)
O4 - HKU\S-1-5-21-1645522239-1965331169-682003330-1004..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1645522239-1965331169-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: localhost (http in Trusted sites)
O15 - HKU\S-1-5-21-1645522239-1965331169-682003330-1004\..Trusted Sites: localhost (http in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_10)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
========== AppInit_DLLs ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls" = llgyck.dll
>File not found --
========== Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll -- C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
cbXQgfgG: "DllName" = Reg Error: Value DLLName does not exist or could not be read. -- File not found
========== LSA *Authentication Packages* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,C:\WINDOWS\system32\pmnlmnLb,
>[2008/12/15 18:43:01 | 00,235,008 | ---- | M] () -- C:\WINDOWS\system32\pmnlmnLb.dll
========== Safeboot Options ========== "AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== AUTOEXEC.BAT [SET PATH=C:\Program Files\Pinnacle\Shared Files;C:\Program Files\Pinnacle\Shared Files\Filter | ]
[2008/09/23 05:47:12 | 00,000,095 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ========== [6 C:\WINDOWS\*.tmp files]
[2009/02/09 07:43:23 | 00,000,000 | ---D | C] -- C:\ToolBar SD
[2009/02/09 07:36:32 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Fouzi\Bureau\HijackThis.lnk
[2009/02/09 07:36:32 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/02/09 07:36:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Fouzi\Bureau\Nouveau dossier (2)
[2009/02/08 14:44:03 | 42,668,68713 | ---- | C] () -- C:\Documents and Settings\Fouzi\Bureau\Music.rar
[2009/02/08 14:43:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Fouzi\Bureau\Music
[2009/02/08 14:07:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Fouzi\Bureau\Musique
[2009/02/08 13:04:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Fouzi\Bureau\Agraver
[2009/02/06 22:02:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/02/06 20:59:05 | 00,001,851 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\AntiVir PE Classic.lnk
[2009/02/06 20:58:58 | 00,045,376 | ---- | C] (
Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/02/06 20:58:58 | 00,022,336 | ---- | C] (
Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/02/06 20:58:57 | 00,075,072 | ---- | C] (
Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/02/06 20:58:57 | 00,028,352 | ---- | C] (
Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/02/06 20:58:56 | 00,000,000 | ---D | C] -- C:\Program Files\
Avira[2009/02/06 20:58:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\
Avira[2009/02/06 18:59:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Arovax
[2009/02/04 18:00:29 | 01,658,079 | -HS- | C] () -- C:\WINDOWS\System32\ukcnjkjh.ini
[2009/02/04 18:00:25 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\hjkjncku.VIR
[2009/02/03 17:54:55 | 01,679,263 | -HS- | C] () -- C:\WINDOWS\System32\faqdxjwf.ini
[2009/02/03 17:54:55 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\fwjxdqaf.VIR
[2009/02/03 16:42:28 | 01,677,842 | -HS- | C] () -- C:\WINDOWS\System32\bjliqijl.ini
[2009/02/02 18:17:40 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009/02/02 16:42:01 | 01,677,842 | -HS- | C] () -- C:\WINDOWS\System32\fiqebfpt.ini
[2009/02/01 10:20:23 | 01,618,956 | -HS- | C] () -- C:\WINDOWS\System32\tlxlrjte.ini
[2009/01/31 18:00:26 | 01,618,929 | -HS- | C] () -- C:\WINDOWS\System32\sektcqoj.ini
[2009/01/30 17:58:23 | 01,618,911 | -HS- | C] () -- C:\WINDOWS\System32\trecdcgy.ini
[2009/01/29 16:49:45 | 01,618,911 | -HS- | C] () -- C:\WINDOWS\System32\jfpxsvgg.ini
[2009/01/29 16:49:45 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\ggvsxpfj.VIR
[2009/01/29 11:45:49 | 01,552,200 | -HS- | C] () -- C:\WINDOWS\System32\avkrfaty.ini
[2009/01/28 18:45:03 | 00,000,000 | ---D | C] -- C:\Program Files\Pure Motion
[2009/01/28 18:45:02 | 00,000,000 | ---D | C] -- C:\Program Files\Sonic Foundry
[2009/01/28 18:44:52 | 00,000,000 | ---D | C] -- C:\Program Files\DebugMode
[2009/01/28 17:45:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DFX
[2009/01/28 17:45:09 | 00,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\DFX
[2009/01/28 11:44:51 | 01,552,191 | -HS- | C] () -- C:\WINDOWS\System32\jqrutrdj.ini
[2009/01/27 01:08:33 | 01,550,258 | -HS- | C] () -- C:\WINDOWS\System32\dwdlekry.ini
[2009/01/25 15:23:21 | 00,059,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009/01/25 15:23:21 | 00,059,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2009/01/23 03:11:53 | 01,474,100 | -HS- | C] () -- C:\WINDOWS\System32\shytkbcf.ini
[2009/01/23 03:11:52 | 00,068,096 | ---- | C] () -- C:\WINDOWS\System32\fcbktyhs.VIR
[2009/01/22 11:25:13 | 01,474,109 | -HS- | C] () -- C:\WINDOWS\System32\bvahcelb.ini
[2009/01/21 11:24:24 | 00,335,064 | ---- | C] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam_nav.dat
[2009/01/21 11:24:24 | 00,003,798 | ---- | C] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam_navps.dat
[2009/01/21 11:24:24 | 00,003,261 | ---- | C] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam.dat
[2009/01/21 11:24:22 | 00,221,184 | ---- | C] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam.exe
[2009/01/21 11:23:54 | 01,474,073 | -HS- | C] () -- C:\WINDOWS\System32\cdvmcywy.ini
[2009/01/19 17:13:01 | 01,471,324 | -HS- | C] () -- C:\WINDOWS\System32\klwoafdn.ini
[2009/01/19 17:13:01 | 00,068,608 | ---- | C] () -- C:\WINDOWS\System32\ndfaowlk.VIR
[2009/01/19 17:12:28 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\swefikag.VIR
[2009/01/19 17:12:28 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\llgyck.VIR
[2009/01/19 13:22:06 | 01,441,809 | -HS- | C] () -- C:\WINDOWS\System32\snkmletx.ini
[2009/01/19 13:22:03 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\njujmb.VIR
[2009/01/19 13:22:02 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\fttximsn.VIR
[2009/01/18 13:21:29 | 01,441,881 | -HS- | C] () -- C:\WINDOWS\System32\bdpnsvce.ini
[2009/01/18 13:20:12 | 00,103,936 | ---- | C] () -- C:\WINDOWS\System32\ptdpif.VIR
[2009/01/18 13:20:08 | 00,103,936 | ---- | C] () -- C:\WINDOWS\System32\kumbifeg.VIR
[2009/01/17 11:21:14 | 01,441,800 | -HS- | C] () -- C:\WINDOWS\System32\dkfdhfrj.ini
[2009/01/17 11:20:06 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\kmleyu.VIR
[2009/01/17 11:20:04 | 00,102,912 | ---- | C] () -- C:\WINDOWS\System32\ajmtobpo.VIR
[2009/01/16 11:08:34 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\fwujvq.VIR000
[2009/01/16 11:08:32 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\nsyfhqba.VIR
[2009/01/16 11:07:50 | 01,441,778 | -HS- | C] () -- C:\WINDOWS\System32\ukftfafl.ini
[2009/01/15 09:43:21 | 01,414,004 | -HS- | C] () -- C:\WINDOWS\System32\avrmoybt.ini
[2009/01/15 09:40:33 | 00,103,936 | ---- | C] () -- C:\WINDOWS\System32\waiklm.VIR
[2009/01/15 09:40:31 | 00,103,936 | ---- | C] () -- C:\WINDOWS\System32\gtepugrt.VIR
[2009/01/14 17:29:24 | 00,000,000 | ---D | C] -- C:\Program Files\LimeWire
[2009/01/13 20:44:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\Adobe
[2009/01/13 20:42:47 | 00,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 9.lnk
[2009/01/13 20:42:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/01/13 20:42:17 | 00,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\Adobe
[2009/01/13 20:41:41 | 00,000,000 | ---D | C] -- C:\Program Files\BoontyGames
[2009/01/13 20:41:37 | 00,000,000 | ---D | C] -- C:\Program Files\Boonty
[2009/01/13 20:38:31 | 26,596,640 | ---- | C] ( ) -- C:\Documents and Settings\Fouzi\Mes documents\AdbeRdr90_fr_FR.exe
[2009/01/13 16:11:20 | 01,387,456 | -HS- | C] () -- C:\WINDOWS\System32\nquixcqq.ini
[2009/01/13 16:09:33 | 00,104,448 | ---- | C] () -- C:\WINDOWS\System32\moxtvq.dll
[2009/01/13 16:09:32 | 00,104,448 | ---- | C] () -- C:\WINDOWS\System32\dbvnqdry.dll
[2009/01/12 10:30:16 | 00,103,424 | ---- | C] () -- C:\WINDOWS\System32\mwwmap.dll
[2009/01/12 10:30:15 | 00,103,424 | ---- | C] () -- C:\WINDOWS\System32\iplbrlxh.dll
[2009/01/12 10:28:08 | 01,298,838 | -HS- | C] () -- C:\WINDOWS\System32\wiwbdbbo.ini
[2009/01/11 15:34:45 | 00,000,000 | ---D | C] -- C:\Program Files\AceClockXP
[2009/01/11 14:33:43 | 00,000,000 | ---D | C] -- C:\Program Files\Horloge MF
[2009/01/11 14:33:01 | 04,621,722 | ---- | C] (O. Jonathan ) -- C:\Documents and Settings\Fouzi\Mes documents\horlogemf.exe
[2009/01/10 11:44:44 | 00,006,758 | ---- | C] () -- C:\MACDR001.CST
[2009/01/10 09:29:25 | 01,289,472 | -HS- | C] () -- C:\WINDOWS\System32\ohhxsonm.ini
[2009/01/10 09:27:12 | 00,103,936 | ---- | C] () -- C:\WINDOWS\System32\ptgxsust.dll
[2009/01/10 09:27:12 | 00,103,936 | ---- | C] () -- C:\WINDOWS\System32\clmvrr.dll
========== Files - Modified Within 30 Days ========== [6 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/02/09 07:53:45 | 00,397,715 | -HS- | M] () -- C:\WINDOWS\System32\bLnmlnmp.ini
[2009/02/09 07:51:35 | 00,397,699 | -HS- | M] () -- C:\WINDOWS\System32\bLnmlnmp.ini2
[2009/02/09 07:51:23 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/02/09 07:51:16 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/02/09 07:36:32 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Fouzi\Bureau\HijackThis.lnk
[2009/02/09 07:25:21 | 00,016,784 | ---- | M] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/02/09 07:24:49 | 00,104,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/08 17:34:04 | 04,776,230 | -H-- | M] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\IconCache.db
[2009/02/08 17:24:28 | 42,668,68713 | ---- | M] () -- C:\Documents and Settings\Fouzi\Bureau\Music.rar
[2009/02/08 14:09:18 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/02/08 13:32:45 | 00,000,109 | ---- | M] () -- C:\WINDOWS\disney.ini
[2009/02/08 13:31:19 | 00,245,248 | ---- | M] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/08 12:52:54 | 00,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/02/08 11:27:14 | 00,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009/02/06 20:59:05 | 00,001,851 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\AntiVir PE Classic.lnk
[2009/02/06 18:53:40 | 00,000,349 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2009/02/06 18:49:38 | 00,003,798 | ---- | M] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam_navps.dat
[2009/02/06 18:49:27 | 00,003,261 | ---- | M] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam.dat
[2009/02/06 13:24:16 | 00,000,574 | ---- | M] () -- C:\Documents and Settings\Fouzi\Mes documents\Mes dossiers de partage.lnk
[2009/02/05 20:52:22 | 01,658,079 | -HS- | M] () -- C:\WINDOWS\System32\ukcnjkjh.ini
[2009/02/04 18:00:25 | 00,068,096 | ---- | M] () -- C:\WINDOWS\System32\hjkjncku.VIR
[2009/02/03 19:47:17 | 00,000,457 | ---- | M] () -- C:\WINDOWS\MyHeritage.INI
[2009/02/03 18:45:19 | 01,679,263 | -HS- | M] () -- C:\WINDOWS\System32\faqdxjwf.ini
[2009/02/03 17:54:55 | 00,068,096 | ---- | M] () -- C:\WINDOWS\System32\fwjxdqaf.VIR
[2009/02/03 16:42:33 | 01,677,842 | -HS- | M] () -- C:\WINDOWS\System32\bjliqijl.ini
[2009/02/03 16:42:26 | 01,677,842 | -HS- | M] () -- C:\WINDOWS\System32\fiqebfpt.ini
[2009/02/02 16:42:00 | 01,618,956 | -HS- | M] () -- C:\WINDOWS\System32\tlxlrjte.ini
[2009/01/31 21:07:10 | 01,618,929 | -HS- | M] () -- C:\WINDOWS\System32\sektcqoj.ini
[2009/01/31 17:59:21 | 01,618,911 | -HS- | M] () -- C:\WINDOWS\System32\trecdcgy.ini
[2009/01/31 11:56:47 | 00,003,532 | ---- | M] () -- C:\drmHeader.bin
[2009/01/30 17:58:20 | 01,618,911 | -HS- | M] () -- C:\WINDOWS\System32\jfpxsvgg.ini
[2009/01/29 16:49:45 | 00,068,096 | ---- | M] () -- C:\WINDOWS\System32\ggvsxpfj.VIR
[2009/01/29 13:37:04 | 01,552,200 | -HS- | M] () -- C:\WINDOWS\System32\avkrfaty.ini
[2009/01/29 12:51:37 | 00,335,064 | ---- | M] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam_nav.dat
[2009/01/29 11:45:34 | 01,552,191 | -HS- | M] () -- C:\WINDOWS\System32\jqrutrdj.ini
[2009/01/28 11:44:47 | 01,550,258 | -HS- | M] () -- C:\WINDOWS\System32\dwdlekry.ini
[2009/01/26 19:40:49 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\umdf\Msft_User_WpdMtpDr_01_00_00.Wdf
[2009/01/23 19:23:54 | 01,474,100 | -HS- | M] () -- C:\WINDOWS\System32\shytkbcf.ini
[2009/01/23 03:11:52 | 00,068,096 | ---- | M] () -- C:\WINDOWS\System32\fcbktyhs.VIR
[2009/01/22 12:52:26 | 01,474,109 | -HS- | M] () -- C:\WINDOWS\System32\bvahcelb.ini
[2009/01/22 11:25:10 | 01,474,073 | -HS- | M] () -- C:\WINDOWS\System32\cdvmcywy.ini
[2009/01/22 10:59:28 | 00,002,828 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2009/01/22 10:59:22 | 00,000,088 | RHS- | M] () -- C:\Documents and Settings\All Users\Application Data\923EB3DDE0.sys
[2009/01/21 11:24:22 | 00,221,184 | ---- | M] () -- C:\Documents and Settings\Fouzi\Local Settings\Application Data\aqucgam.exe
[2009/01/20 17:13:25 | 01,471,324 | -HS- | M] () -- C:\WINDOWS\System32\klwoafdn.ini
[2009/01/19 17:13:01 | 00,068,608 | ---- | M] () -- C:\WINDOWS\System32\ndfaowlk.VIR
[2009/01/19 17:12:28 | 00,102,912 | ---- | M] () -- C:\WINDOWS\System32\swefikag.VIR
[2009/01/19 17:12:28 | 00,102,912 | ---- | M] () -- C:\WINDOWS\System32\llgyck.VIR
[2009/01/19 14:21:20 | 01,441,809 | -HS- | M] () -- C:\WINDOWS\System32\snkmletx.ini
[2009/01/19 13:22:03 | 00,102,912 | ---- | M] () -- C:\WINDOWS\System32\njujmb.VIR
[2009/01/19 13:22:03 | 00,102,912 | ---- | M] () -- C:\WINDOWS\System32\fttximsn.VIR
[2009/01/19 09:50:15 | 01,441,881 | -HS- | M] () -- C:\WINDOWS\System32\bdpnsvce.ini
[2009/01/18 13:20:11 | 00,103,936 | ---- | M] () -- C:\WINDOWS\System32\ptdpif.VIR
[2009/01/18 13:20:11 | 00,103,936 | ---- | M] () -- C:\WINDOWS\System32\kumbifeg.VIR
[2009/01/18 13:19:56 | 01,441,800 | -HS- | M] () -- C:\WINDOWS\System32\dkfdhfrj.ini
[2009/01/17 11:20:06 | 00,102,912 | ---- | M] () -- C:\WINDOWS\System32\kmleyu.VIR
[2009/01/17 11:20:06 | 00,102,912 | ---- | M] () -- C:\WINDOWS\System32\ajmtobpo.VIR
[2009/01/17 11:19:56 | 01,441,778 | -HS- | M] () -- C:\WINDOWS\System32\ukftfafl.ini
[2009/01/16 11:08:34 | 00,102,400 | ---- | M] () -- C:\WINDOWS\System32\nsyfhqba.VIR
[2009/01/16 11:08:34 | 00,102,400 | ---- | M] () -- C:\WINDOWS\System32\fwujvq.VIR000
[2009/01/16 11:07:22 | 01,414,004 | -HS- | M] () -- C:\WINDOWS\System32\avrmoybt.ini
[2009/01/15 09:40:31 | 00,103,936 | ---- | M] () -- C:\WINDOWS\System32\waiklm.VIR
[2009/01/15 09:40:31 | 00,103,936 | ---- | M] () -- C:\WINDOWS\System32\gtepugrt.VIR
[2009/01/14 20:17:08 | 01,387,456 | -HS- | M] () -- C:\WINDOWS\System32\nquixcqq.ini
[2009/01/13 20:42:47 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 9.lnk
[2009/01/13 20:41:41 | 26,596,640 | ---- | M] ( ) -- C:\Documents and Settings\Fouzi\Mes documents\AdbeRdr90_fr_FR.exe
[2009/01/13 16:09:33 | 00,104,448 | ---- | M] () -- C:\WINDOWS\System32\moxtvq.dll
[2009/01/13 16:09:33 | 00,104,448 | ---- | M] () -- C:\WINDOWS\System32\dbvnqdry.dll
[2009/01/13 10:28:38 | 01,298,838 | -HS- | M] () -- C:\WINDOWS\System32\wiwbdbbo.ini
[2009/01/12 10:30:16 | 00,103,424 | ---- | M] () -- C:\WINDOWS\System32\mwwmap.dll
[2009/01/12 10:30:16 | 00,103,424 | ---- | M] () -- C:\WINDOWS\System32\iplbrlxh.dll
[2009/01/12 10:27:30 | 01,289,472 | -HS- | M] () -- C:\WINDOWS\System32\ohhxsonm.ini
[2009/01/11 14:33:16 | 04,621,722 | ---- | M] (O. Jonathan ) -- C:\Documents and Settings\Fouzi\Mes documents\horlogemf.exe
[2009/01/10 14:34:00 | 00,006,758 | ---- | M] () -- C:\MACDR001.CST
[2009/01/10 09:27:12 | 00,103,936 | ---- | M] () -- C:\WINDOWS\System32\ptgxsust.dll
[2009/01/10 09:27:12 | 00,103,936 | ---- | M] () -- C:\WINDOWS\System32\clmvrr.dll
========== Alternate Data Streams ========== @Alternate Data Stream - 0 bytes -> %UserProfile%\Bureau\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %SystemRoot%\System32\Thumbs.db:encryptable
<End>