Ci-joint le rapport OTListIT2.txt :
OTListIt logfile created on: 08/02/2009 23:19:02 - Run 4
OTListIt2 by OldTimer - Version 1.0.4.1 Folder = C:\Documents and Settings\Pascal\Bureau
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
511,48 Mb Total Physical Memory | 246,77 Mb Available Physical Memory | 48,25% Memory free
1,22 Gb Paging File | 1,00 Gb Available in Paging File | 82,34% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,22 Gb Total Space | 9,83 Gb Free Space | 13,24% Space Free | Partition Type: NTFS
Drive D: | 72,27 Gb Total Space | 71,53 Gb Free Space | 98,98% Space Free | Partition Type: NTFS
Drive E: | 2,55 Gb Total Space | 2,55 Gb Free Space | 99,83% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PIV3000
Current User Name: Pascal
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 60 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
[2009/01/23 18:39:42 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG7\avgamsvr.exe
[2009/01/23 18:34:54 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG7\avgupsvc.exe
[2009/01/23 18:39:43 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG7\avgemc.exe
[2008/12/20 11:41:39 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2008/05/03 05:46:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
[2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
[2004/08/19 16:10:06 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
[2001/10/22 14:33:58 | 00,045,056 | ---- | M] (Sharp Corporation) -- C:\WINDOWS\system32\SCUSAPI.exe
[2006/08/19 11:37:06 | 00,049,152 | ---- | M] (ZSMCSNAP) -- C:\WINDOWS\ZSSnp211.EXE
[2009/01/30 01:27:29 | 00,049,152 | ---- | M] () -- C:\WINDOWS\Domino.EXE
[2008/12/20 11:41:39 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2009/01/23 18:39:43 | 00,590,848 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG7\avgcc.exe
[2003/07/08 15:25:22 | 00,925,770 | ---- | M] () -- C:\Program Files\modem ADSL USB\modem ADSL USB\DSLMON.exe
[2009/02/07 20:20:33 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTListIt2.exe
========== (O23) Win32 Services (SafeList) ==========
[2004/07/15 01:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2009/01/23 18:39:42 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG7\avgamsvr.exe -- (Avg7Alrt [Auto | Running])
[2009/01/23 18:34:54 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG7\avgupsvc.exe -- (Avg7UpdSvc [Auto | Running])
[2009/01/23 18:39:43 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG7\avgemc.exe -- (AVGEMS [Auto | Running])
[2005/10/17 08:28:11 | 00,054,784 | ---- | M] (Macrovision) -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA [Disabled | Stopped])
[2004/08/19 16:09:38 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [On_Demand | Stopped])
[2004/10/22 02:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2003/05/14 11:29:54 | 00,753,716 | ---- | M] () -- C:\Program Files\Ahead\InCD\incdsrv.exe -- (InCDsrv [Disabled | Stopped])
[2008/12/20 11:41:39 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
[2005/01/26 15:30:04 | 00,053,337 | ---- | M] (Sony Corporation) -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV [On_Demand | Stopped])
[2008/05/03 05:46:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2005/01/26 15:25:34 | 00,053,337 | ---- | M] (Sony Corporation) -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR [On_Demand | Stopped])
[2007/12/28 18:42:09 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Disabled | Stopped])
[2005/01/26 15:20:14 | 00,069,718 | ---- | M] (Sony Corporation) -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV [On_Demand | Stopped])
[2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
[2007/01/19 11:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
[2006/04/03 17:12:14 | 00,014,032 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend [Disabled | Stopped])
========== Driver Services (SafeList) ==========
[2002/10/11 18:19:00 | 00,046,551 | ---- | M] (Analog Deivces) -- C:\WINDOWS\system32\drivers\adildr.sys -- (ADILOADER [Auto | Stopped])
[2002/11/22 22:14:36 | 00,122,505 | ---- | M] (Analog Devices Inc.) -- C:\WINDOWS\system32\drivers\adiusbaw.sys -- (adiusbaw [On_Demand | Running])
[2004/02/24 04:08:52 | 00,400,384 | ---- | M] (Sensaura) -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS [On_Demand | Running])
[2004/03/19 13:02:08 | 00,613,244 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
[2009/01/23 18:39:37 | 00,821,856 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avg7core.sys -- (Avg7Core [System | Running])
[2009/01/23 18:34:58 | 00,004,224 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avg7rsw.sys -- (Avg7RsW [System | Running])
[2009/01/23 18:34:58 | 00,027,776 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avg7rsxp.sys -- (Avg7RsXP [System | Running])
[2009/01/23 18:39:47 | 00,010,760 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avgclean.sys -- (AvgClean [System | Running])
[2009/01/23 18:35:00 | 00,004,960 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdi.sys -- (AvgTdi [Auto | Running])
[2005/10/17 08:28:09 | 00,012,464 | ---- | M] (Macrovision Europe Ltd) -- C:\WINDOWS\system32\drivers\CdaC15BA.SYS -- (CdaC15BA [Auto | Running])
[2003/12/03 17:44:58 | 00,013,566 | ---- | M] (B.H.A Corporation) -- C:\WINDOWS\system32\drivers\cdrbsvsd.sys -- (cdrbsvsd [System | Running])
[2002/11/18 14:51:40 | 00,377,358 | ---- | M] (C-Media Inc) -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci [On_Demand | Stopped])
[2006/08/12 02:28:58 | 00,798,464 | ---- | M] (C-Media Inc) -- C:\WINDOWS\system32\drivers\cmuda3.sys -- (cmuda3 [On_Demand | Running])
[2003/05/14 11:31:32 | 00,085,296 | ---- | M] () -- C:\WINDOWS\system32\drivers\incdfs.sys -- (InCDfs [Disabled | Running])
[2003/05/14 11:31:58 | 00,026,336 | ---- | M] (Ahead Software) -- C:\WINDOWS\system32\drivers\incdpass.sys -- (InCDPass [System | Running])
[2003/04/25 13:13:42 | 00,023,920 | ---- | M] (Ahead Software AG) -- C:\WINDOWS\system32\drivers\incdrm.sys -- (incdrm [System | Running])
[2004/03/12 18:23:56 | 00,845,092 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\Ctxs51.sys -- (Intels51 [On_Demand | Running])
[2008/05/03 05:46:00 | 06,554,496 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
[2001/08/28 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2007/03/08 00:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2001/08/17 22:05:16 | 00,028,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\OVCD.sys -- (QCDonner [On_Demand | Running])
[2004/08/03 22:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139 [On_Demand | Running])
[2001/10/22 14:33:46 | 00,031,728 | ---- | M] (Sharp Corporation) -- C:\WINDOWS\system32\drivers\SCUSPAC.SYS -- (SCUSMFP1 [Auto | Running])
[2001/10/22 14:33:46 | 00,022,796 | ---- | M] (Sharp Corporation) -- C:\WINDOWS\system32\drivers\SCUSPRO.SYS -- (SCUSMFP2 [Auto | Running])
[2001/10/22 14:33:58 | 00,025,768 | ---- | M] (Sharp Corporation) -- C:\WINDOWS\system32\drivers\SCUSUSB.SYS -- (SCUSUSB [On_Demand | Stopped])
[2005/04/20 17:15:52 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [Auto | Running])
[2005/08/10 13:44:04 | 00,050,688 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01 [Boot | Running])
[2005/05/16 14:20:39 | 00,006,656 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02 [Boot | Running])
[2005/04/14 13:12:32 | 00,019,968 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02 [Boot | Running])
[2005/11/03 15:40:07 | 00,063,488 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfvfs02.sys -- (sfvfs02 [Boot | Running])
[2001/08/17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[2005/12/22 12:24:50 | 00,080,272 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus [On_Demand | Stopped])
[2005/12/22 12:24:52 | 00,010,864 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl [On_Demand | Stopped])
[2005/12/22 12:24:52 | 00,137,884 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm [On_Demand | Stopped])
[2009/02/07 10:02:09 | 00,102,664 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm [Auto | Running])
[2001/08/28 13:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [System | Running])
[2006/10/18 09:23:40 | 00,391,866 | ---- | M] (ZSMC Corporation) -- C:\WINDOWS\system32\drivers\ZS211.sys -- (ZSMC211 [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://windowsupdate.microsoft.com/
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://windowsupdate.microsoft.com/
HKU\S-1-5-21-1177238915-1409082233-839522115-1003\S-1-5-21-1177238915-1409082233-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (23 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Aide pour le lien d'Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (dcads) - {b9a85eaa-c89c-66bd-46c6-097f778c6d43} - C:\WINDOWS\system32\nso8.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\..\Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP (GRISOFT, s.r.o.)
O4 - HKLM..\Run: [Domino] C:\WINDOWS\Domino.exe ()
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [SCUSAPI] SCUSAPI.exe (Sharp Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe (ZSMCSNAP)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
O4 - HKU\S-1-5-18..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
O4 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\DSLMON.lnk = C:\Program Files\modem ADSL USB\modem ADSL USB\DSLMON.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe (Sony Corporation.)
O4 - Startup: C:\Documents and Settings\Cathy\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Léa\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Pascal\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\Thomas\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ShutdownWithoutLogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLastUserName = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 41 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: 39 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Sites: 40 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Sites: 40 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1177238915-1409082233-839522115-1003\..Trusted Sites: 39 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C}
http://messenger.zone.msn.com/binary/ms ... b31267.cab (Checkers Class)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC}
http://messenger.zone.msn.com/binary/Me ... b31267.cab (MessengerStatsClient Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/ ... mv9dmo.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
http://messenger.zone.msn.com/binary/Me ... b31267.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: DirectAnimation Java Classes (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: Microsoft XML Parser for Java (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" (HKLM) -- C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== Safeboot Options ==========
"AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2004/11/18 16:08:40 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 60 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/02/07 20:20:26 | 00,419,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTListIt2.exe
[2009/02/07 20:17:54 | 00,000,000 | ---D | C] -- C:\HJThis
[2009/02/07 17:57:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2009/02/07 10:04:48 | 00,102,664 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/02/07 09:36:41 | 00,002,120 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009/02/07 09:36:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Bureau\SmitfraudFix
[2009/02/07 09:18:55 | 00,000,000 | ---D | C] -- C:\VundoFix Backups
[2009/02/07 08:47:43 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\CCleaner.lnk
[2009/02/07 08:47:42 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/02/07 08:37:33 | 00,576,868 | ---- | C] (IL-MAFIOSO ) -- C:\Documents and Settings\Pascal\Bureau\Navilog1.exe
[2009/02/07 08:36:46 | 01,661,793 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\SmitfraudFix.exe
[2009/02/07 08:36:32 | 00,096,978 | ---- | C] (Business Information Solutions) -- C:\Documents and Settings\Pascal\Bureau\VirtumundoBeGone.exe
[2009/02/07 00:27:40 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2009/02/07 00:27:32 | 00,000,000 | ---D | C] -- C:\rsit
[2009/02/07 00:15:15 | 00,781,851 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\RSIT.exe
[2009/02/06 22:58:58 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2009/02/06 22:55:41 | 00,348,160 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTMoveIt3.exe
[2009/02/06 21:32:50 | 00,000,000 | ---D | C] -- C:\ToolBar SD
[2009/02/06 21:32:08 | 00,343,017 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\ToolBarSD.exe
[2009/02/06 20:27:46 | 00,000,080 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\fix.reg
[2009/02/03 09:15:35 | 00,085,664 | ---- | C] () -- C:\WINDOWS\System32\98a5e3ff-62f9-4650-087a-5f2f16a23de3.exe
[2009/02/03 03:13:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/02/02 23:31:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Bureau\backups
[2009/02/02 22:55:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Bureau\GenProc
[2009/01/30 01:09:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Application Data\SUPERAntiSpyware.com
[2009/01/30 01:09:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/01/30 00:21:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Application Data\Malwarebytes
[2009/01/30 00:21:44 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Malwarebytes' Anti-Malware.lnk
[2009/01/30 00:21:43 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/30 00:21:40 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/30 00:21:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/30 00:21:38 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/29 23:54:00 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/01/29 23:10:25 | 00,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 8.lnk
[2009/01/29 22:24:51 | 00,000,212 | ---- | C] () -- C:\Boot.bak
[2009/01/29 22:24:49 | 00,263,488 | ---- | C] () -- C:\cmldr
[2009/01/29 22:24:41 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/01/29 22:23:37 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/01/29 22:23:37 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/01/29 22:23:37 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/01/29 22:23:37 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/29 22:23:37 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/01/29 22:23:37 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/29 22:23:37 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/29 22:23:37 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/29 22:23:37 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/01/29 22:23:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/29 22:22:48 | 03,048,418 | R--- | C] () -- C:\Documents and Settings\Pascal\Bureau\ComboFix.exe
[2009/01/29 21:32:54 | 00,132,597 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\Flash_Disinfector.exe
[2009/01/29 16:20:56 | 00,669,696 | ---- | C] () -- C:\WINDOWS\System32\nso8.dll
[2009/01/29 00:18:03 | 00,009,668 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\cc_20090129_001800.reg
[2009/01/28 23:05:32 | 00,038,748 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\cc_20090128_230526.reg
[2009/01/23 20:17:45 | 00,000,512 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily).job
[2009/01/23 18:35:01 | 00,010,760 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avgclean.sys
[2009/01/23 18:35:01 | 00,001,532 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\AVG 7.5.lnk
[2009/01/23 18:35:00 | 00,026,952 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/23 18:35:00 | 00,004,960 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdi.sys
[2009/01/23 18:34:58 | 00,027,776 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avg7rsxp.sys
[2009/01/23 18:34:58 | 00,004,224 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avg7rsw.sys
[2009/01/23 18:34:56 | 00,821,856 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avg7core.sys
[2009/01/06 16:31:29 | 00,000,000 | RH-D | C] -- C:\$VAULT$.AVG
[2008/12/26 15:59:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/12/26 15:59:30 | 00,008,192 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\E_DCINST.DLL
[2008/12/26 15:59:25 | 00,078,848 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\E_FD4BEDE.DLL
[2008/12/26 15:59:24 | 00,086,528 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\System32\E_FLBEDE.DLL
[2008/12/15 15:04:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Bureau\2008 PHOTOS MAISON CATHY
[2008/12/12 17:59:57 | 00,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Winamp.lnk
[2008/12/12 17:57:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Application Data\Winamp
========== Files - Modified Within 60 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/02/08 23:09:09 | 00,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2009/02/08 23:09:09 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2009/02/08 23:08:32 | 00,176,754 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/02/08 23:07:48 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/02/08 23:05:38 | 04,302,902 | -H-- | M] () -- C:\Documents and Settings\Pascal\Local Settings\Application Data\IconCache.db
[2009/02/08 22:42:39 | 00,000,211 | ---- | M] () -- C:\WINDOWS\spnutmp.ini
[2009/02/08 22:36:53 | 00,085,664 | ---- | M] () -- C:\WINDOWS\System32\98a5e3ff-62f9-4650-087a-5f2f16a23de3.exe
[2009/02/08 16:02:55 | 00,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2009/02/08 16:02:55 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2009/02/08 10:01:35 | 00,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2009/02/08 10:01:35 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2009/02/07 22:46:35 | 00,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2009/02/07 22:46:34 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009/02/07 22:10:22 | 00,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2009/02/07 22:10:22 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009/02/07 21:15:24 | 00,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/02/07 21:15:24 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/02/07 20:27:22 | 01,661,793 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\SmitfraudFix.exe
[2009/02/07 20:20:33 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTListIt2.exe
[2009/02/07 20:12:59 | 00,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2009/02/07 20:12:58 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009/02/07 17:51:24 | 00,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2009/02/07 17:51:24 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2009/02/07 17:33:00 | 00,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2009/02/07 17:33:00 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009/02/07 17:31:27 | 00,000,512 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily).job
[2009/02/07 17:31:27 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/02/07 15:42:11 | 00,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2009/02/07 15:42:11 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2009/02/07 15:00:46 | 00,000,838 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/02/07 15:00:46 | 00,000,282 | RHS- | M] () -- C:\boot.ini
[2009/02/07 15:00:46 | 00,000,280 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/02/07 14:16:45 | 00,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2009/02/07 14:16:45 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2009/02/07 14:02:16 | 00,002,120 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009/02/07 11:53:45 | 00,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2009/02/07 11:53:44 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2009/02/07 11:37:26 | 00,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2009/02/07 11:37:26 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2009/02/07 10:02:09 | 00,102,664 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/02/07 09:46:19 | 00,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2009/02/07 09:46:19 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2009/02/07 08:47:43 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\CCleaner.lnk
[2009/02/07 08:37:38 | 00,576,868 | ---- | M] (IL-MAFIOSO ) -- C:\Documents and Settings\Pascal\Bureau\Navilog1.exe
[2009/02/07 08:36:36 | 00,096,978 | ---- | M] (Business Information Solutions) -- C:\Documents and Settings\Pascal\Bureau\VirtumundoBeGone.exe
[2009/02/07 01:03:31 | 00,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2009/02/07 01:03:30 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2009/02/07 00:55:35 | 00,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2009/02/07 00:55:35 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2009/02/07 00:15:48 | 00,781,851 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\RSIT.exe
[2009/02/06 23:43:09 | 00,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2009/02/06 23:43:09 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2009/02/06 23:41:20 | 00,161,936 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/06 23:37:27 | 00,033,112 | ---- | M] () -- C:\Documents and Settings\Pascal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/06 23:02:22 | 00,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2009/02/06 23:02:22 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2009/02/06 22:55:46 | 00,348,160 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTMoveIt3.exe
[2009/02/06 22:40:41 | 00,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2009/02/06 22:40:40 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2009/02/06 22:05:37 | 00,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2009/02/06 22:05:36 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2009/02/06 21:32:13 | 00,343,017 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\ToolBarSD.exe
[2009/02/06 20:27:46 | 00,000,080 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\fix.reg
[2009/02/01 14:24:30 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/01/30 01:27:29 | 00,049,152 | ---- | M] () -- C:\WINDOWS\Domino.EXE
[2009/01/30 00:21:44 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Malwarebytes' Anti-Malware.lnk
[2009/01/29 23:10:25 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 8.lnk
[2009/01/29 22:21:14 | 03,048,418 | R--- | M] () -- C:\Documents and Settings\Pascal\Bureau\ComboFix.exe
[2009/01/29 21:32:59 | 00,132,597 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\Flash_Disinfector.exe
[2009/01/29 19:51:22 | 00,000,584 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\Mes dossiers de partage.lnk
[2009/01/29 16:20:56 | 00,669,696 | ---- | M] () -- C:\WINDOWS\System32\nso8.dll
[2009/01/29 00:18:44 | 00,009,668 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\cc_20090129_001800.reg
[2009/01/28 23:05:55 | 00,038,748 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\cc_20090128_230526.reg
[2009/01/28 20:45:50 | 00,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Winamp.lnk
[2009/01/26 08:57:03 | 00,143,872 | ---- | M] () -- C:\Documents and Settings\Pascal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/23 18:39:47 | 00,010,760 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avgclean.sys
[2009/01/23 18:39:37 | 00,821,856 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avg7core.sys
[2009/01/23 18:39:37 | 00,026,952 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/23 18:35:01 | 00,001,532 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\AVG 7.5.lnk
[2009/01/23 18:35:00 | 00,004,960 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdi.sys
[2009/01/23 18:34:58 | 00,027,776 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avg7rsxp.sys
[2009/01/23 18:34:58 | 00,004,224 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\avg7rsw.sys
[2009/01/14 16:11:32 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/12/15 15:02:50 | 00,000,836 | ---- | M] () -- C:\Documents and Settings\Pascal\Application Data\ViewerApp.dat
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> %SystemRoot%\Domino.EXE:SummaryInformation
@Alternate Data Stream - 0 bytes -> %SystemRoot%\Domino.EXE:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
<End>