OTListIt logfile created on: 12/02/2009 13:01:34 - Run 2
OTListIt2 by OldTimer - Version 2.0.0.11 Folder = C:\Documents and Settings\Jérôme Dumont\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,60 Gb Available Physical Memory | 80,26% Memory free
3,85 Gb Paging File | 3,52 Gb Available in Paging File | 91,51% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 233,75 Gb Total Space | 54,46 Gb Free Space | 23,30% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,87 Gb Total Space | 0,07 Gb Free Space | 3,84% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: EXILIAN
Current User Name: Jérôme Dumont
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008/04/14 03:34:03 | 01,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/07/19 16:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2008/07/19 16:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/10/02 16:44:24 | 00,460,168 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\AskService.exe
PRC - [2008/11/10 05:43:40 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/01/13 20:34:37 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2009/01/13 20:34:42 | 00,202,448 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe
PRC - [2008/07/19 16:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2008/07/23 16:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2006/03/02 01:22:04 | 00,577,536 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
PRC - [2008/07/19 16:38:34 | 00,078,008 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2007/11/13 23:47:52 | 00,278,528 | R--- | M] (France Telecom SA) -- C:\Program Files\CardDetector\ICON225\CardDetector.exe
PRC - [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2008/11/10 05:43:42 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/01/19 15:14:38 | 00,278,528 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk.exe
PRC - [2008/04/14 03:34:13 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2004/12/14 19:53:38 | 00,454,656 | ---- | M] () -- C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/02/12 12:54:05 | 00,491,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jérôme Dumont\Bureau\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/10/02 16:44:24 | 00,460,168 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\AskService.exe -- (ASKService [Auto | Running])
SRV - [2005/09/23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/07/19 16:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2008/07/19 16:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2008/07/19 16:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2008/07/23 16:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2005/09/23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/04/14 03:33:38 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2008/11/10 05:43:40 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2006/08/11 22:42:50 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Stopped])
SRV - [2009/01/13 20:34:37 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2009/01/13 20:34:42 | 00,202,448 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB [Auto | Running])
SRV - [2006/11/03 09:59:14 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2006/09/28 18:56:14 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WudfSvc.dll -- (WudfSvc [Auto | Running])
========== Driver Services (SafeList) ==========
DRV - [2008/07/19 16:32:15 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2006/03/20 23:45:52 | 03,960,000 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM [On_Demand | Running])
DRV - [2006/06/18 23:40:44 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2008/07/19 16:37:42 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2008/07/19 16:37:21 | 00,094,416 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2008/07/19 16:33:42 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2008/07/19 16:35:18 | 00,078,416 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2008/07/19 16:32:36 | 00,042,912 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2003/08/13 12:25:02 | 00,182,380 | ---- | M] (Divio Inc.) -- C:\WINDOWS\system32\drivers\pcam812.sys -- (DCamUSBNW812 [On_Demand | Running])
DRV - [2008/04/13 19:36:40 | 00,046,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gagp30kx.sys -- (gagp30kx [Boot | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2007/11/13 22:29:24 | 00,095,744 | R--- | M] (Option NV) -- C:\WINDOWS\system32\drivers\Gt51Ip.sys -- (GT72NDISIPXP [On_Demand | Stopped])
DRV - [2007/11/13 22:29:24 | 00,051,968 | R--- | M] (Option N.V.) -- C:\WINDOWS\system32\drivers\gt72ubus.sys -- (GT72UBUS [On_Demand | Stopped])
DRV - [2007/11/13 22:29:24 | 00,008,064 | R--- | M] (Option N.V.) -- C:\WINDOWS\system32\drivers\gtptser.sys -- (GTPTSER [On_Demand | Stopped])
DRV - [2003/02/07 08:39:34 | 00,009,808 | ---- | M] (Divio Inc.) -- C:\WINDOWS\system32\drivers\lower812.sys -- (Lower812 [On_Demand | Running])
DRV - [2008/11/11 14:58:00 | 00,023,096 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\system32\drivers\MusCAudio.sys -- (MusCAudio [On_Demand | Stopped])
DRV - [2006/08/11 22:42:42 | 03,958,496 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2009/01/13 20:34:51 | 00,138,376 | ---- | M] () -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK [On_Demand | Stopped])
DRV - [2006/03/02 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2006/02/26 22:46:20 | 00,081,408 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp [On_Demand | Running])
DRV - [2004/08/03 23:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139 [On_Demand | Stopped])
DRV - [2008/04/13 17:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2007/07/03 16:54:24 | 00,080,552 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus [On_Demand | Stopped])
DRV - [2007/07/03 16:57:24 | 00,011,944 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl [On_Demand | Stopped])
DRV - [2007/07/03 16:58:20 | 00,106,792 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm [On_Demand | Stopped])
DRV - [2008/11/07 22:11:45 | 00,005,632 | ---- | M] () -- C:\WINDOWS\system32\drivers\StarOpen.sys -- (StarOpen [System | Running])
DRV - [2008/04/13 19:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio [On_Demand | Running])
DRV - [2004/09/17 10:17:00 | 00,253,440 | R--- | M] (Marvell Semiconductor, Inc) -- C:\WINDOWS\system32\drivers\Mrv8000c.sys -- (W8335XP [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-823518204-1220945662-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-823518204-1220945662-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\S-1-5-21-823518204-1220945662-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
IE - HKU\S-1-5-21-823518204-1220945662-725345543-1004\S-1-5-21-823518204-1220945662-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (790 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-823518204-1220945662-725345543-1004\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CardDetectorICON225] C:\Program Files\CardDetector\ICON225\CardDetector.exe (France Telecom SA)
O4 - HKLM..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [eiaqk] "c:\documents and settings\jérôme dumont\local settings\application data\eiaqk.exe" eiaqk ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-823518204-1220945662-725345543-1004..\Run: [eiaqk] "c:\documents and settings\jérôme dumont\local settings\application data\eiaqk.exe" eiaqk ()
O4 - HKU\S-1-5-21-823518204-1220945662-725345543-1004..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Wireless Configuration Utility HW.51.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-823518204-1220945662-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}
http://webscanner.kaspersky.fr/kavwebscan_unicode.cab (CKAVWebScan Object)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/ms ... b56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/FR-FR/a-U ... E_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA}
http://www.inoculer.com/antivirus/Msie/bitdefender.cab (AvxScanOnline Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/26 18:18:39 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{654f458e-c9e2-11dd-966e-0018f392b7d9}\Shell - "" = AutoRun
O33 - MountPoints2\{654f458e-c9e2-11dd-966e-0018f392b7d9}\Shell\AutoRun\command - "" = E:\AutoRunCardDetector.exe -- File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/02/12 12:59:43 | 00,087,552 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\VACFix.exe
[2009/02/12 12:59:43 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.exe
[2009/02/12 12:59:43 | 00,082,944 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\IEDFix.C.exe
[2009/02/12 12:59:43 | 00,082,432 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\404Fix.exe
[2009/02/12 12:59:43 | 00,080,384 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\o4Patch.exe
[2009/02/12 12:59:43 | 00,078,336 | ---- | C] (S!Ri.URZ) -- C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/02/12 12:59:43 | 00,025,600 | ---- | C] () -- C:\WINDOWS\System32\WS2Fix.exe
[2009/02/12 12:59:42 | 00,289,144 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\VCCLSID.exe
[2009/02/12 12:59:42 | 00,288,417 | ---- | C] (S!Ri) -- C:\WINDOWS\System32\SrchSTS.exe
[2009/02/12 12:59:42 | 00,135,168 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swreg.exe
[2009/02/12 12:59:42 | 00,079,360 | ---- | C] (SteelWerX) -- C:\WINDOWS\System32\swxcacls.exe
[2009/02/12 12:59:42 | 00,053,248 | ---- | C] (
http://www.beyondlogic.org) -- C:\WINDOWS\System32\Process.exe
[2009/02/12 12:59:42 | 00,051,200 | ---- | C] () -- C:\WINDOWS\System32\dumphive.exe
[2009/02/12 12:59:42 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\swsc.exe
[2009/02/12 12:59:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jérôme Dumont\Bureau\SmitfraudFix
[2009/02/12 12:55:56 | 00,005,382 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\Document.rtf
[2009/02/12 12:54:50 | 01,661,962 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\SmitfraudFix.exe
[2009/02/12 12:54:05 | 00,491,008 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jérôme Dumont\Bureau\OTListIt2.exe
[2009/02/12 12:50:38 | 00,001,654 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\HijackThis.lnk
[2009/02/12 12:49:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jérôme Dumont\Mes documents\Hijackthis
[2009/02/12 12:44:42 | 00,925,592 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Jérôme Dumont\Bureau\ccsetup216_slim.exe
[2009/02/12 12:43:28 | 00,096,978 | ---- | C] (Business Information Solutions) -- C:\Documents and Settings\Jérôme Dumont\Bureau\VirtumundoBeGone.exe
[2009/02/11 19:10:53 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/02/11 13:44:44 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/02/10 21:37:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Kaspersky Lab
[2009/02/10 21:30:56 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/02/10 21:25:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\avxoscan
[2009/02/10 20:20:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2009/02/09 17:58:24 | 00,011,551 | -HS- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{639762B0-92B8-4034-B3B9-839266EB0220}_Large.jpg
[2009/02/09 17:58:24 | 00,002,638 | -HS- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{639762B0-92B8-4034-B3B9-839266EB0220}_Small.jpg
[2009/02/08 20:44:51 | 05,694,924 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\YUI - 12.TOKYO.mp3
[2009/02/07 23:48:35 | 00,000,209 | ---- | C] () -- C:\WINDOWS\yesmessenger.ini
[2009/02/07 23:47:38 | 00,000,000 | ---D | C] -- C:\Program Files\YesMessenger
[2009/02/01 12:01:41 | 00,008,163 | -HS- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{FE685E8C-9FCC-4C56-829B-AEFA13E0BD20}_Large.jpg
[2009/02/01 12:01:41 | 00,002,207 | -HS- | C] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{FE685E8C-9FCC-4C56-829B-AEFA13E0BD20}_Small.jpg
[2009/01/25 20:39:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jérôme Dumont\Mes documents\Muse - discography
[2009/01/19 22:12:23 | 00,011,153 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Mes documents\sigrid ohhh.rtf
[2009/01/19 18:49:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2009/01/19 15:14:38 | 00,335,064 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk_nav.dat
[2009/01/19 15:14:38 | 00,278,528 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk.exe
[2009/01/19 15:14:38 | 00,003,410 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk.dat
[2009/01/19 15:14:38 | 00,001,312 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk_navps.dat
[2009/01/17 23:58:06 | 00,001,201 | ---- | C] () -- C:\Documents and Settings\Jérôme Dumont\Mes documents\moi-c-tt@hotmail.fr Archive des dossiers de partage.lnk
[2009/01/16 18:09:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jérôme Dumont\Application Data\DivX
[2009/01/16 00:11:00 | 00,000,000 | ---D | C] -- C:\Program Files\DivX
[2009/01/13 20:34:51 | 00,138,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/01/13 20:34:45 | 00,202,448 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2009/01/13 20:34:37 | 00,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2009/01/13 20:16:44 | 00,000,000 | ---D | C] -- C:\Program Files\Call of Duty
[2009/01/13 20:15:49 | 00,000,745 | ---- | C] () -- C:\WINDOWS\CoD.INI
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/02/12 13:02:04 | 00,001,312 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk_navps.dat
[2009/02/12 13:01:59 | 00,003,410 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk.dat
[2009/02/12 12:55:56 | 00,005,382 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\Document.rtf
[2009/02/12 12:55:30 | 01,661,962 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\SmitfraudFix.exe
[2009/02/12 12:54:05 | 00,491,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jérôme Dumont\Bureau\OTListIt2.exe
[2009/02/12 12:53:47 | 00,001,654 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\HijackThis.lnk
[2009/02/12 12:44:42 | 00,925,592 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Jérôme Dumont\Bureau\ccsetup216_slim.exe
[2009/02/12 12:43:28 | 00,096,978 | ---- | M] (Business Information Solutions) -- C:\Documents and Settings\Jérôme Dumont\Bureau\VirtumundoBeGone.exe
[2009/02/12 11:43:36 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/02/12 11:43:31 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/02/11 23:16:42 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/02/11 23:09:55 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/02/11 23:03:25 | 00,132,096 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/11 12:19:54 | 00,081,191 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/02/10 19:38:07 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/02/09 17:58:25 | 00,000,368 | -HS- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\desktop.ini
[2009/02/09 17:58:22 | 00,011,551 | -HS- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\Folder.jpg
[2009/02/09 17:58:22 | 00,011,551 | -HS- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{639762B0-92B8-4034-B3B9-839266EB0220}_Large.jpg
[2009/02/09 17:58:20 | 00,002,638 | -HS- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArtSmall.jpg
[2009/02/09 17:58:20 | 00,002,638 | -HS- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{639762B0-92B8-4034-B3B9-839266EB0220}_Small.jpg
[2009/02/08 20:58:54 | 05,694,924 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\YUI - 12.TOKYO.mp3
[2009/02/07 23:49:57 | 00,000,209 | ---- | M] () -- C:\WINDOWS\yesmessenger.ini
[2009/02/05 12:19:47 | 00,013,760 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/02/04 00:21:12 | 21,244,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/02/02 00:17:56 | 00,458,648 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2009/02/02 00:17:56 | 00,392,432 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/02/02 00:17:56 | 00,071,488 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2009/02/02 00:17:56 | 00,058,732 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/02/02 00:17:55 | 00,992,010 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/01 12:01:40 | 00,008,163 | -HS- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{FE685E8C-9FCC-4C56-829B-AEFA13E0BD20}_Large.jpg
[2009/02/01 12:01:37 | 00,002,207 | -HS- | M] () -- C:\Documents and Settings\Jérôme Dumont\Bureau\AlbumArt_{FE685E8C-9FCC-4C56-829B-AEFA13E0BD20}_Small.jpg
[2009/01/29 20:25:49 | 00,335,064 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk_nav.dat
[2009/01/20 13:26:35 | 00,011,153 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Mes documents\sigrid ohhh.rtf
[2009/01/19 15:14:38 | 00,278,528 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Local Settings\Application Data\eiaqk.exe
[2009/01/17 23:59:55 | 00,001,201 | ---- | M] () -- C:\Documents and Settings\Jérôme Dumont\Mes documents\moi-c-tt@hotmail.fr Archive des dossiers de partage.lnk
[2009/01/16 21:15:42 | 03,594,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2009/01/16 21:15:42 | 03,594,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/13 20:34:51 | 00,138,376 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/01/13 20:34:42 | 00,202,448 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2009/01/13 20:34:37 | 00,066,872 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2009/01/13 20:23:08 | 00,000,745 | ---- | M] () -- C:\WINDOWS\CoD.INI
<End>