Bonjour,
Voici le rapport OTListIt2 :
OTListIt logfile created on: 24/04/2009 11:32:27 - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\NouvelAdministrateur\Bureau
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
511,53 Mb Total Physical Memory | 153,49 Mb Available Physical Memory | 30,01% Memory free
1,22 Gb Paging File | 0,70 Gb Available in Paging File | 57,43% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 43,96 Gb Total Space | 21,47 Gb Free Space | 48,83% Space Free | Partition Type: NTFS
Drive D: | 67,83 Gb Total Space | 31,65 Gb Free Space | 46,67% Space Free | Partition Type: NTFS
Drive E: | 3,96 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
Drive G: | 4,31 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 232,88 Gb Total Space | 122,71 Gb Free Space | 52,69% Space Free | Partition Type: NTFS
Computer Name: MAISON
Current User Name: NouvelAdministrateur
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008/12/17 00:01:07 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\PROTECTION\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008/10/15 14:31:25 | 00,068,865 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\sched.exe
PRC - [2008/10/15 14:29:28 | 00,151,297 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avguard.exe
PRC - [2005/09/23 08:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
PRC - [2006/01/04 17:39:13 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
PRC - [2008/12/16 16:37:29 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/05/03 06:46:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2002/09/20 16:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PRC - [2008/07/09 10:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2005/06/02 16:54:34 | 00,086,606 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2004/08/04 00:54:50 | 01,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008/06/12 14:28:40 | 00,266,497 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgnt.exe
PRC - [2008/07/09 10:05:20 | 00,919,016 | ---- | M] (Zone Labs, LLC) -- C:\Program Files\PROTECTION\ZoneAlarm\zlclient.exe
PRC - [2009/03/05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\PROTECTION\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2004/08/04 00:54:50 | 01,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008/06/12 14:28:40 | 00,266,497 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgnt.exe
PRC - [2008/07/09 10:05:20 | 00,919,016 | ---- | M] (Zone Labs, LLC) -- C:\Program Files\PROTECTION\ZoneAlarm\zlclient.exe
PRC - [2006/11/13 15:07:02 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PRC - [2009/03/05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\PROTECTION\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2006/11/13 15:06:52 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe
PRC - [2009/04/18 18:54:25 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/04/24 11:30:09 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\NouvelAdministrateur\Bureau\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/12/17 00:01:07 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\PROTECTION\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
SRV - [2008/10/15 14:31:25 | 00,068,865 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
SRV - [2008/10/15 14:29:28 | 00,151,297 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2005/09/23 08:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [Auto | Running])
SRV - [2006/01/04 17:39:13 | 00,046,080 | ---- | M] (C-Dilla Ltd) -- C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE -- (C-DillaSrv [Auto | Running])
SRV - [2005/06/02 16:54:34 | 00,086,606 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8 [Auto | Running])
SRV - [2005/09/23 08:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [Disabled | Stopped])
SRV - [2004/08/04 00:54:36 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Disabled | Stopped])
SRV - [2008/12/16 16:37:29 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe -- (MDM [Disabled | Stopped])
SRV - [2008/05/03 06:46:00 | 00,159,812 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2006/10/26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2002/09/20 16:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [Auto | Running])
SRV - [2007/01/19 12:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [Disabled | Stopped])
SRV - [2008/07/09 10:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
========== Driver Services (SafeList) ==========
DRV - [2002/04/01 08:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
DRV - [2003/06/19 09:30:18 | 00,752,764 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Stopped])
DRV - [2005/02/16 10:06:18 | 00,018,816 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\Drivers\APLMp50.sys -- (APLMp50 [On_Demand | Stopped])
DRV - [2008/11/25 12:40:01 | 00,008,552 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM [Auto | Running])
DRV - [2004/08/04 00:38:44 | 00,701,440 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [System | Stopped])
DRV - [2007/02/27 15:24:55 | 00,011,840 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
DRV - [2008/05/20 16:29:43 | 00,052,032 | ---- | M] (
Avira GmbH) -- C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
DRV - [2008/10/30 11:21:03 | 00,075,072 | ---- | M] (
Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2001/08/17 22:28:04 | 00,067,167 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys -- (basic2 [On_Demand | Stopped])
DRV - [2006/01/04 17:39:13 | 00,058,160 | ---- | M] (Macrovision) -- C:\WINDOWS\System32\drivers\CDANT.SYS -- (C-Dilla [On_Demand | Stopped])
DRV - [2006/07/24 19:08:41 | 00,012,464 | ---- | M] (Macrovision Europe Ltd) -- C:\WINDOWS\System32\drivers\CdaC15BA.SYS -- (CdaC15BA [Auto | Running])
DRV - [2001/08/17 20:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- C:\WINDOWS\System32\DRIVERS\fetnd5.sys -- (FETNDIS [On_Demand | Running])
DRV - [2004/08/04 01:05:42 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2001/08/17 22:28:10 | 00,542,879 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys -- (hsf_msft [On_Demand | Stopped])
DRV - [2007/07/19 16:10:28 | 00,127,768 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\system32\DRIVERS\klif.sys -- (KLIF [System | Running])
DRV - [2001/08/17 21:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped])
DRV - [2001/08/17 23:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Stopped])
DRV - [2004/08/03 22:59:52 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])
DRV - [2008/05/03 06:46:00 | 06,554,496 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2006/11/25 12:27:34 | 00,017,134 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\PCANDIS5.SYS -- (PCANDIS5 [On_Demand | Stopped])
DRV - [2003/03/21 13:34:08 | 00,009,856 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc [On_Demand | Running])
DRV - [2004/05/05 22:48:40 | 00,004,228 | ---- | M] (PowerQuest Corporation) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv [System | Running])
DRV - [2001/09/28 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2001/08/17 22:28:10 | 00,057,471 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys -- (Rksample [On_Demand | Stopped])
DRV - [2001/09/28 14:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Stopped])
DRV - [2008/11/02 10:44:10 | 00,056,572 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])
DRV - [2006/10/06 22:55:43 | 00,012,464 | ---- | M] (Macrovision Europe Ltd) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2003/07/15 16:00:00 | 00,578,368 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
DRV - [2001/11/05 10:23:14 | 00,006,097 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\DRIVERS\sonyhcb.sys -- (sonyhcb [Boot | Running])
DRV - [2001/11/05 10:23:52 | 00,299,923 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\DRIVERS\sonyhcs.sys -- (sonyhcs [On_Demand | Stopped])
DRV - [2007/01/14 21:29:01 | 00,639,224 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2008/02/27 04:10:44 | 00,051,176 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\System32\ZoneLabs\srescan.sys -- (srescan [Boot | Running])
DRV - [2007/11/08 19:03:26 | 00,021,248 | ---- | M] (
AVIRA GmbH) -- C:\WINDOWS\system32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2007/05/02 12:11:16 | 00,083,592 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\ss_bus.sys -- (ss_bus [On_Demand | Stopped])
DRV - [2007/05/02 12:11:18 | 00,015,112 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys -- (ss_mdfl [On_Demand | Stopped])
DRV - [2007/05/02 12:11:18 | 00,109,704 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\DRIVERS\ss_mdm.sys -- (ss_mdm [On_Demand | Stopped])
DRV - [2006/07/24 17:05:00 | 00,005,632 | ---- | M] () -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen [System | Running])
DRV - [2007/07/19 16:10:28 | 00,127,768 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\system32\drivers\klif.sys -- (TSP [On_Demand | Stopped])
DRV - [2004/08/04 00:07:56 | 00,059,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV - [2005/10/21 03:47:05 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\usb8023x.sys -- (usb_rndisx [On_Demand | Stopped])
DRV - [2006/02/23 12:38:32 | 00,009,728 | R--- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32 [Boot | Running])
DRV - [2008/07/09 10:05:22 | 00,394,952 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsdatant.sys -- (vsdatant [System | Running])
DRV - [2002/10/24 10:07:00 | 00,006,912 | ---- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\Drivers\vulfnth.sys -- (vulfnths [On_Demand | Stopped])
DRV - [2002/11/13 11:34:06 | 00,010,496 | ---- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\Drivers\vulfntr.sys -- (vulfntrs [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ixquick.fr/
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\S-1-5-21-1757981266-1343024091-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
IE - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\S-1-5-21-1757981266-1343024091-725345543-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.ixquick.com/fra/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: unplug@compunach:2.003
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/16 16:37:32 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/18 18:54:36 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/18 18:54:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Components: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS [2009/03/20 19:51:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS [2009/02/02 12:15:57 | 00,000,000 | ---D | M]
[2009/01/02 23:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NouvelAdministrateur\Application Data\mozilla\Extensions
[2009/01/02 23:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NouvelAdministrateur\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/21 18:04:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NouvelAdministrateur\Application Data\mozilla\Firefox\Profiles\legnr8m7.default\extensions
[2009/04/20 21:32:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NouvelAdministrateur\Application Data\mozilla\Firefox\Profiles\legnr8m7.default\extensions\unplug@compunach
[2009/04/24 11:15:54 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/04/18 18:54:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/09/08 20:51:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2008/12/16 16:37:55 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/18 18:54:25 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/18 18:54:25 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/11/28 21:22:45 | 00,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2008/11/28 21:22:45 | 00,000,757 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2008/11/28 21:22:45 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/11/28 21:22:45 | 00,000,748 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MediaDICO-fr.xml
[2008/11/28 21:22:45 | 00,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2008/11/28 21:22:45 | 00,000,652 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
[2009/04/03 18:02:40 | 00,000,815 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (304439 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1
www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1
www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.com
O1 - Hosts: 127.0.0.1
www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 10508 more lines...
O2 - BHO: (Aide pour le lien d'Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {2B60FCB3-C93D-4ECF-ACC3-EE4D19E6AF3C} - C:\WINDOWS\system32\nmewtmsg.dll File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\PROTECTION\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\
Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (
Avira GmbH)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\PROTECTION\ZoneAlarm\zlclient.exe" (Zone Labs, LLC)
O4 - HKU\S-1-5-21-1757981266-1343024091-725345543-1003..\Run: [SpybotSD TeaTimer] C:\Program Files\PROTECTION\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-1757981266-1343024091-725345543-1006..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (Microsoft Corporation)
O4 - HKU\S-1-5-21-1757981266-1343024091-725345543-1006..\Run: [SpybotSD TeaTimer] C:\Program Files\PROTECTION\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\PROTECTION\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 51 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 51 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Domains: 3 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-20\..Trusted Domains: 3 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\..Trusted Sites: ([]msn in Poste de travail)
O15 - HKU\S-1-5-21-1757981266-1343024091-725345543-1003\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1757981266-1343024091-725345543-1006\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupda ... 4735226994 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftup ... 3661829911 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/C ... 0320833333 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{A67E149E-EC81-4BA0-8709-7161CE1F8206}\\NameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/12/08 19:07:51 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/03/24 17:14:06 | 00,000,306 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2006/03/03 21:00:48 | 00,000,049 | R--- | M] () - G:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2006/03/20 18:54:59 | 00,679,936 | R--- | M] () - G:\autorun.exe -- [ CDFS ]
O33 - MountPoints2\D\Shell - "" = Autorun
O33 - MountPoints2\D\Shell\Open\command - "" = RECYCLER\S-5-0-28-100027012-100003264-100018669-6903.com d:\
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe -- [2006/03/20 18:54:59 | 00,679,936 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[6 C:\WINDOWS\*.tmp files]
[2009/04/24 11:30:08 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\NouvelAdministrateur\Bureau\OTListIt2.exe
[2009/04/22 11:35:47 | 12,994,5558 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\avant supp MPC.reg
[2009/04/22 11:29:46 | 00,077,588 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\autoplayhandlers_backup.reg
[2009/04/22 11:28:36 | 00,073,728 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\CleanHandlers.exe
[2009/04/22 10:58:14 | 16,124,4560 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\avant supp alcohol.reg
[2009/04/21 20:38:22 | 00,001,056 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Spybot - Search & Destroy.lnk
[2009/04/20 20:32:50 | 00,000,552 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Raccourci vers Bureau.lnk
[2009/04/20 17:55:13 | 00,054,700 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\3.png
[2009/04/20 17:05:41 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2009/04/20 16:37:09 | 00,389,632 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\NouvelAdministrateur\Bureau\OTMoveIt3.exe
[2009/04/20 16:29:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/20 16:23:38 | 00,000,712 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\NTREGOPT.lnk
[2009/04/20 16:23:38 | 00,000,693 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\ERUNT.lnk
[2009/04/20 16:21:29 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\NouvelAdministrateur\Bureau\erunt-setup.exe
[2009/04/18 14:21:14 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/18 14:21:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NouvelAdministrateur\Application Data\Sun
[2009/04/18 14:12:15 | 00,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2009/04/18 12:26:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NouvelAdministrateur\Bureau\SmitfraudFix
[2009/04/18 12:16:56 | 01,831,231 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\SmitfraudFix.exe
[2009/04/17 14:28:57 | 00,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2009/04/17 14:24:16 | 00,000,000 | ---D | C] -- C:\Program Files\Open Office
[2009/04/04 11:41:56 | 00,021,298 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\recycler.jpg
[2009/04/04 11:39:33 | 00,018,279 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\restore.jpg
[2009/04/04 10:31:22 | 00,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Navilog1.lnk
[2009/04/04 10:31:21 | 00,000,000 | ---D | C] -- C:\Program Files\Navilog1
[2009/04/04 10:30:40 | 00,210,432 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Composition1.pub
[2009/04/03 21:48:50 | 00,001,480 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009/04/03 21:05:19 | 00,000,829 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Raccourci vers HijackThis.exe.lnk
[2009/04/03 18:14:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NouvelAdministrateur\Bureau\pad_fichiers
[2009/04/03 18:14:07 | 00,103,903 | ---- | C] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\pad.htm
[2009/04/01 09:41:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Outils
[2009/03/31 17:53:44 | 00,137,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSMAPI32.OCX
[2009/03/31 17:53:43 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2009/03/31 17:53:40 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSMPIDE.DLL
[2009/03/31 17:53:40 | 00,000,000 | ---D | C] -- C:\Program Files\PDFCreator
[2009/02/24 16:57:00 | 00,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/02/24 14:09:31 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/02/24 14:09:30 | 00,383,238 | ---- | C] () -- C:\WINDOWS\System32\libmp3lame-0.dll
[2008/12/20 15:57:40 | 00,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2008/07/18 10:56:05 | 00,000,074 | ---- | C] () -- C:\WINDOWS\Babyegg.INI
[2008/05/03 06:46:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/03 06:46:00 | 01,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/05/03 06:46:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/05/03 06:46:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/05/03 06:46:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/03/17 19:43:31 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/12/05 11:08:14 | 00,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\IMPLODE.DLL
[2007/12/05 11:08:12 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll
[2007/12/05 11:03:35 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\lftif60n.dll
[2007/12/05 11:03:35 | 00,043,008 | ---- | C] () -- C:\WINDOWS\System32\ltfil60n.dll
[2007/12/05 11:03:35 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\lfpsd60n.dll
[2007/12/05 11:03:35 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\lftga60n.dll
[2007/12/05 11:03:35 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwpg60n.dll
[2007/12/05 11:03:35 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwmf60n.dll
[2007/12/05 11:03:34 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\lffax60n.dll
[2007/12/05 11:03:34 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\lfpng60n.dll
[2007/12/05 11:03:34 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\lfpcx60n.dll
[2007/12/05 11:03:34 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfpct60n.dll
[2007/12/05 11:03:34 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfeps60n.dll
[2007/12/05 11:03:34 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\lfmsp60n.dll
[2007/12/05 11:03:34 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\lfmac60n.dll
[2007/12/05 11:03:33 | 00,141,824 | ---- | C] () -- C:\WINDOWS\System32\lfcmp60n.dll
[2007/12/05 11:03:33 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\lfbmp60n.dll
[2007/12/05 11:03:25 | 00,021,986 | ---- | C] () -- C:\WINDOWS\crwd32.ini
[2007/06/30 21:43:30 | 00,002,813 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2007/06/01 14:32:47 | 00,000,173 | ---- | C] () -- C:\WINDOWS\APACHEAV.SYS
[2007/03/31 09:43:01 | 00,021,904 | ---- | C] () -- C:\WINDOWS\System32\imsinstall_loc040c.dll
[2007/03/31 09:43:01 | 00,017,808 | ---- | C] () -- C:\WINDOWS\System32\imslsp_install_loc040c.dll
[2007/03/29 10:54:55 | 00,000,239 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/03/22 17:13:15 | 00,036,363 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2007/01/14 21:29:01 | 00,639,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2006/09/08 21:02:23 | 00,000,724 | ---- | C] () -- C:\WINDOWS\wacam.ini
[2006/09/02 19:18:44 | 00,000,532 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2006/09/01 14:23:17 | 00,000,021 | ---- | C] () -- C:\WINDOWS\kit.ini
[2006/08/08 19:19:21 | 00,038,609 | ---- | C] () -- C:\WINDOWS\unvpeye.ini
[2006/07/27 11:05:11 | 00,796,584 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/06/03 00:15:44 | 00,294,912 | ---- | C] () -- C:\WINDOWS\System32\LDecVorbis.dll
[2006/05/24 19:37:27 | 00,045,568 | RHS- | C] () -- C:\WINDOWS\System32\cygz.dll
[2006/05/24 19:37:27 | 00,027,648 | -HS- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2006/04/05 20:10:30 | 00,069,632 | R--- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2006/04/05 20:10:30 | 00,036,864 | R--- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2006/03/20 20:10:01 | 00,000,972 | ---- | C] () -- C:\WINDOWS\disney.ini
[2006/02/24 10:41:59 | 00,438,272 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/02/24 10:41:59 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\libfaac.dll
[2006/02/23 18:36:20 | 01,798,144 | ---- | C] () -- C:\WINDOWS\System32\ltmm_n.dll
[2006/02/23 18:36:20 | 00,262,144 | ---- | C] () -- C:\WINDOWS\System32\LMOggSpl.dll
[2006/02/23 18:36:20 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\LMOggMux.dll
[2006/02/10 21:48:58 | 00,000,014 | ---- | C] () -- C:\WINDOWS\AKA2.INI
[2006/02/10 21:48:58 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2006/02/10 20:51:45 | 00,000,043 | ---- | C] () -- C:\WINDOWS\akaklike.ini
[2005/12/02 21:51:26 | 00,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2005/07/04 11:23:31 | 00,001,891 | ---- | C] () -- C:\WINDOWS\System32\MSMINI.DLL
[2005/06/08 15:48:15 | 00,000,000 | ---- | C] () -- C:\WINDOWS\WATCH.INI
[2005/06/08 15:36:37 | 00,077,796 | ---- | C] () -- C:\WINDOWS\System32\Wndtc32.dll
[2005/05/28 19:45:16 | 00,000,076 | ---- | C] () -- C:\WINDOWS\EXE.INI
[2005/05/28 19:06:59 | 00,000,229 | ---- | C] () -- C:\WINDOWS\provw.ini
[2005/01/08 22:15:04 | 00,003,712 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/11/23 21:51:16 | 00,002,801 | ---- | C] () -- C:\WINDOWS\tabled32.ini
[2004/11/07 13:07:12 | 00,000,039 | ---- | C] () -- C:\WINDOWS\dversion.ini
[2004/09/29 10:59:26 | 00,000,000 | ---- | C] () -- C:\WINDOWS\bbcauto.INI
[2004/09/01 16:17:53 | 00,000,171 | ---- | C] () -- C:\WINDOWS\SOFTPEG.INI
[2004/08/31 17:56:22 | 00,000,009 | ---- | C] () -- C:\WINDOWS\atlas-fra.INI
[2004/08/04 02:54:38 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/08/04 00:54:28 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/06/16 14:17:05 | 00,000,114 | ---- | C] () -- C:\WINDOWS\CDSFDB01.INI
[2004/06/16 14:16:57 | 00,001,104 | ---- | C] () -- C:\WINDOWS\CDSFUNST.INI
[2004/05/20 15:03:18 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2004/05/19 14:55:40 | 00,000,253 | ---- | C] () -- C:\WINDOWS\Creator.INI
[2004/05/11 16:33:37 | 00,000,040 | ---- | C] () -- C:\WINDOWS\INTER.INI
[2004/05/08 10:57:27 | 00,000,499 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2004/05/07 18:00:20 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2004/05/07 18:00:20 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2004/05/07 18:00:20 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2004/04/30 17:24:10 | 00,000,757 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2004/04/30 14:43:20 | 00,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2004/04/29 11:21:03 | 00,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2004/04/29 11:20:49 | 00,003,289 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2004/04/29 11:20:48 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2004/04/21 14:59:52 | 00,045,056 | R--- | C] () -- C:\WINDOWS\System32\memtest.dll
[2004/04/21 14:59:50 | 00,036,076 | R--- | C] () -- C:\WINDOWS\System32\drivers\vgauti.sys
[2004/04/21 14:59:50 | 00,036,076 | R--- | C] () -- C:\WINDOWS\System32\drivers\msicpl.sys
[2004/03/24 09:22:26 | 00,138,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\PFC027.SYS
[2004/03/02 09:42:43 | 00,000,139 | ---- | C] () -- C:\WINDOWS\msicpl.ini
[2004/01/08 10:30:22 | 00,011,170 | ---- | C] () -- C:\WINDOWS\System32\PA207USD.DLL
[2003/12/09 18:27:20 | 00,000,385 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/12/09 16:36:58 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2002/05/28 03:52:36 | 00,106,496 | ---- | C] () -- C:\WINDOWS\japi.dll
[2001/08/28 14:00:00 | 00,001,362 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/28 14:00:00 | 00,000,243 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/06/24 11:32:44 | 00,172,032 | ---- | C] () -- C:\WINDOWS\japi2.dll
[1997/06/14 10:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\drivers\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/04/24 11:36:43 | 07,598,112 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009/04/24 11:30:09 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\NouvelAdministrateur\Bureau\OTListIt2.exe
[2009/04/24 11:24:45 | 00,171,848 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/04/24 08:07:29 | 00,358,385 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/04/24 08:06:47 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/24 08:06:30 | 00,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/24 08:06:28 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/23 21:12:26 | 00,092,984 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009/04/22 11:47:30 | 00,077,588 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\autoplayhandlers_backup.reg
[2009/04/22 11:36:03 | 12,994,5558 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\avant supp MPC.reg
[2009/04/22 10:58:33 | 16,124,4560 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\avant supp alcohol.reg
[2009/04/21 20:45:20 | 00,304,439 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/21 20:38:22 | 00,001,056 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Spybot - Search & Destroy.lnk
[2009/04/21 20:19:11 | 00,000,114 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090421-204520.backup
[2009/04/21 18:04:08 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\lmhosts
[2009/04/21 18:00:45 | 00,309,200 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090421-201842.backup
[2009/04/21 18:00:45 | 00,309,200 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090421-201911.backup
[2009/04/21 17:53:05 | 00,000,239 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/04/21 16:56:59 | 00,309,200 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090421-180045.backup
[2009/04/21 07:31:31 | 00,469,192 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/20 20:37:29 | 00,210,432 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Composition1.pub
[2009/04/20 20:32:50 | 00,000,552 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Raccourci vers Bureau.lnk
[2009/04/20 17:55:13 | 00,054,700 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\3.png
[2009/04/20 16:37:14 | 00,389,632 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\NouvelAdministrateur\Bureau\OTMoveIt3.exe
[2009/04/20 16:23:38 | 00,000,712 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\NTREGOPT.lnk
[2009/04/20 16:23:38 | 00,000,693 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\ERUNT.lnk
[2009/04/20 16:21:33 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\NouvelAdministrateur\Bureau\erunt-setup.exe
[2009/04/18 16:21:54 | 02,624,744 | -H-- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Local Settings\Application Data\IconCache.db
[2009/04/18 16:11:21 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/18 13:24:06 | 00,001,480 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009/04/18 13:24:02 | 00,309,074 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090421-165659.backup
[2009/04/18 12:17:26 | 01,831,231 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\SmitfraudFix.exe
[2009/04/04 11:41:56 | 00,021,298 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\recycler.jpg
[2009/04/04 11:39:33 | 00,018,279 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\restore.jpg
[2009/04/04 10:31:22 | 00,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Navilog1.lnk
[2009/04/03 23:20:12 | 00,011,264 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/03 22:37:31 | 00,308,259 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090418-095521.backup
[2009/04/03 21:55:58 | 00,301,151 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090403-223731.backup
[2009/04/03 21:05:19 | 00,000,829 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\Raccourci vers HijackThis.exe.lnk
[2009/04/03 18:14:09 | 00,103,903 | ---- | M] () -- C:\Documents and Settings\NouvelAdministrateur\Bureau\pad.htm
[2009/04/03 17:27:04 | 00,459,780 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2009/04/03 17:27:04 | 00,393,638 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/03 17:27:04 | 00,072,118 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2009/04/03 17:27:04 | 00,059,268 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/03 17:27:03 | 00,996,874 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/03 17:27:03 | 00,344,358 | ---- | M] () -- C:\WINDOWS\System32\perfh040.dat
[2009/04/03 17:27:03 | 00,041,106 | ---- | M] () -- C:\WINDOWS\System32\perfc040.dat
<End>