OTL.txt : 2ème partie
--------------------------
O1 HOSTS File: (791 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Download Manager Browser Helper Object) - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\Programmes\Common Files\fluxDVD\Download Manager\XEBDLHelper.dll File not found
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmes\Spybot - Search & Destroy\SDHelper.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {64F56FC1-1272-44CD-BA6E-39723696E350} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live ID) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O3 - HKLM\..\Toolbar: (Systran40premi.IEPlugIn) - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\
Premium\IEPlugIn.dll (SYSTRAN)
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar avec bloqueur de fenêtres pop-up) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O3 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\
Avira\AntiVir Desktop\avgnt.exe (
Avira GmbH)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKU\.DEFAULT..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [EPSON Stylus DX9400F Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICFE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe (The Eraser Project)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [imprimante wifi] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICFE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [MediaDICO9Il] C:\Program Files\Micro Application\9 Dictionnaires Illustrés\LanceMediaDICO9Il.exe (L'Aventure Multimedia)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [RocketDock] H:\Programmes\RocketDock-v1.3.5\RocketDock.exe File not found
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [Stylus DX9400F(Réseau)] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICFE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000..\Run: [Veoh] C:\Program Files\Veoh Networks\Veoh\VeohClient.exe (Veoh Networks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmes\Spybot - Search & Destroy\SDHelper.dll File not found
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: canalplay.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: canalplusactive.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\..Trusted Domains: canalplay.com ([]* in Sites de confiance)
O15 - HKU\S-1-5-21-3323605061-1442029127-536464899-1000\..Trusted Domains: canalplusactive.com ([]* in Sites de confiance)
O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683}
http://install.anark.com/client/version ... Client.cab (Anark Client 4.0 ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E}
http://dev.srtest.com/srl_bin/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A}
http://housecall65.trendmicro.com/house ... hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034}
http://intel-drv-cdn.systemrequirements ... b_srlx.cab (System Requirements Lab Class)
O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE}
http://photoservice.fujicolor.de/ips-op ... anvasx.cab (JordanUploader Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/v ... .2.4.1.cab (DLM Control)
O16 - DPF: {5D2CF9D0-113A-476B-986F-288B54571614}
http://www.devalvr.com/instalacion/plug ... plugin.php (DevalVR Control)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3}
http://www.extrafilm.fr/ImageUploader5.cab (Image Uploader Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://www.zebulon.fr/scan8/oscan8.cab (Reg Error: Key error.)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737}
http://chez-gercha.spaces.live.com/Phot ... dfr-fr.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/softwa ... Plugin.cab (Reg Error: Key error.)
O16 - DPF: {B9907873-6560-4A36-B76B-9DADE84A7F55}
http://www.fnacmusic.com/telechargement ... sicDnl.CAB (Reg Error: Key error.)
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243}
http://copainsdavant.linternaute.com/ht ... oader5.cab (Reg Error: Key error.)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9}
http://ax.emsisoft.com/asquared.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7}
http://www.photodex.com/pxplay.cab (Photodex Presenter AX control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programmes\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll File not found
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programmes\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - AppInit_DLLs: (eNetHook.dll) - C:\Windows\System32\eNetHook.dll (acer)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\Explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/10 12:17:28 | 00,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/07/11 17:50:04 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2008/07/11 17:50:04 | 00,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{290c9b32-0e69-11de-9c97-0016d353e0d9}\Shell\AutoRun\command - "" = H:\start\host\PStart.exe -- File not found
O33 - MountPoints2\{95b76a40-c783-11dc-9a06-0016d353e0d9}\Shell\Auto\command - "" = C:\Windows\System32\cmd.exe -- [2008/01/19 09:33:04 | 00,318,976 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{cb8e31be-076e-11de-9fc8-0016d353e0d9}\Shell\AutoRun\command - "" = H:\start\host\PStart.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/10/13 18:53:40 | 00,000,000 | ---D | C] -- C:\ProgramData\
Avira
[2009/10/24 09:42:09 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/10/22 12:58:49 | 00,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2009/10/21 11:26:14 | 00,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan
[1 C:\Users\Gerard\AppData\Roaming\*.tmp files]
[2009/10/18 14:50:08 | 00,000,000 | ---D | C] -- C:\Users\Gerard\AppData\Roaming\codeblocks
[2009/10/13 13:31:12 | 00,000,000 | ---D | C] -- C:\Users\Gerard\AppData\Roaming\HouseCall 6.6
[2009/10/24 09:42:17 | 00,000,000 | ---D | C] -- C:\Users\Gerard\AppData\Roaming\Malwarebytes
[2009/10/22 21:30:04 | 00,000,000 | ---D | C] -- C:\Users\Gerard\AppData\Roaming\VirtuaWin
[1 C:\Users\Gerard\AppData\Roaming\*.tmp files]
[2009/10/21 12:11:35 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2009/10/13 18:53:40 | 00,000,000 | ---D | C] -- C:\Program Files\
Avira
[2009/10/18 14:49:34 | 00,000,000 | ---D | C] -- C:\Program Files\CodeBlocks
[2009/09/27 17:42:57 | 00,000,000 | ---D | C] -- C:\Program Files\denouvel
[2009/09/25 17:08:56 | 00,000,000 | ---D | C] -- C:\Program Files\HomePlayer
[2009/10/24 09:42:08 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/10 17:13:12 | 00,000,000 | ---D | C] -- C:\Program Files\Maxthon3
[2009/10/22 21:29:58 | 00,000,000 | ---D | C] -- C:\Program Files\VirtuaWin
[2009/10/24 09:42:12 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/10/24 09:42:09 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/10/24 09:38:19 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Users\Gerard\Desktop\OTL.exe
[2009/10/23 20:58:08 | 01,925,024 | ---- | C] (Adobe Systems Incorporated) -- C:\Users\Gerard\Desktop\Install Flash Player 10 Plugin.exe
[2009/10/23 20:57:55 | 01,962,544 | ---- | C] (Adobe Systems Incorporated) -- C:\Users\Gerard\Desktop\Install Flash Player 10 ActiveX.exe
[2009/10/21 12:11:34 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/10/21 09:39:34 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2009/10/21 09:39:34 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2009/10/21 09:39:34 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2009/10/20 16:37:08 | 00,000,000 | ---D | C] -- C:\Users\Gerard\Desktop\Photoshop CS
[2009/10/20 09:27:31 | 02,421,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2009/10/20 09:27:31 | 01,929,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuaueng.dll
[2009/10/20 09:27:31 | 00,053,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuauclt.exe
[2009/10/20 09:27:31 | 00,044,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2009/10/20 09:27:00 | 00,575,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2009/10/20 09:27:00 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2009/10/20 09:27:00 | 00,035,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2009/10/20 09:26:50 | 00,171,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2009/10/20 09:26:50 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2009/10/16 11:03:37 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll
[2009/10/16 11:03:24 | 03,600,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2009/10/16 11:03:24 | 03,548,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2009/10/16 11:02:45 | 05,940,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/10/16 11:02:42 | 11,069,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009/10/16 11:02:40 | 01,985,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009/10/16 11:02:40 | 01,208,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009/10/16 11:02:40 | 00,916,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009/10/16 11:02:40 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/10/16 11:02:40 | 00,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2009/10/16 11:02:40 | 00,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll
[2009/10/16 11:02:39 | 01,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2009/10/16 11:02:39 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2009/10/16 11:02:39 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2009/10/16 11:02:38 | 01,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009/10/16 11:02:38 | 00,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2009/10/16 11:02:38 | 00,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2009/10/16 11:02:38 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2009/10/16 11:02:38 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2009/10/16 11:02:38 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2009/10/16 11:02:38 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009/10/16 11:02:38 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2009/10/16 11:02:38 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2009/10/16 11:02:30 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msasn1.dll
[2009/10/16 11:02:23 | 00,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys
[2009/10/16 11:02:18 | 00,604,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMSPDMOD.DLL
[2009/10/13 18:53:42 | 00,096,104 | ---- | C] (
Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2009/10/13 18:53:41 | 00,055,656 | ---- | C] (
Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2009/10/13 16:57:18 | 00,102,664 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2009/10/13 13:31:11 | 00,000,000 | ---D | C] -- C:\Windows\System32\HouseCall 6.6
[2009/10/03 10:38:18 | 00,195,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2009/09/27 17:42:42 | 00,796,672 | ---- | C] (Qsc) -- C:\Windows\GPInstall.exe
[2009/09/24 20:57:35 | 00,000,000 | ---D | C] -- C:\Users\Gerard\Documents\EpsonNet Config
[2006/12/10 12:29:16 | 00,053,248 | ---- | C] ( ) -- C:\Windows\System32\Interop.Shell32.dll
[2004/12/13 08:57:36 | 00,065,536 | ---- | C] ( ) -- C:\Windows\System32\RCCOLLAB.DLL
[2004/11/29 16:08:30 | 00,127,059 | ---- | C] ( ) -- C:\Windows\System32\DSLLK189.dll
========== Files - Modified Within 30 Days ==========
[1 C:\Windows\*.tmp files]
[1 C:\Users\Gerard\AppData\Roaming\*.tmp files]
[2009/10/24 10:28:46 | 00,001,000 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2009/10/24 10:26:36 | 00,352,615 | -H-- | M] () -- C:\Windows\System32\drivers\vsconfig.xml
[2009/10/24 10:26:25 | 00,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/24 10:26:23 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/24 10:26:21 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/24 10:26:21 | 00,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/24 10:26:13 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/10/24 10:26:07 | 21,460,91008 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/24 10:23:58 | 04,215,884 | -H-- | M] () -- C:\Users\Gerard\AppData\Local\IconCache.db
[2009/10/24 10:05:01 | 00,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/24 09:42:15 | 00,000,822 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/24 09:37:54 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Users\Gerard\Desktop\OTL.exe
[2009/10/23 20:50:53 | 00,001,534 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091023_205046.reg
[2009/10/23 19:49:18 | 00,000,380 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091023_194913.reg
[2009/10/23 18:10:36 | 00,035,416 | ---- | M] () -- C:\Users\Gerard\AppData\Roaming\nvModes.001
[2009/10/23 16:02:44 | 00,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{0A37CAE0-30C9-4127-AB71-691537B0F7BA}.job
[2009/10/23 15:08:40 | 00,022,222 | ---- | M] () -- C:\Users\Gerard\Desktop\CA20091023_1500.odt
[2009/10/23 11:15:10 | 00,036,619 | ---- | M] () -- C:\Users\Gerard\Desktop\index.pdf
[2009/10/22 12:58:17 | 00,000,304 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091022_125813.reg
[2009/10/22 11:54:20 | 00,045,114 | ---- | M] () -- C:\Users\Gerard\Desktop\ADHERENTS 2009-2010(2).pdf
[2009/10/21 12:31:33 | 00,003,360 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091021_123123.reg
[2009/10/20 22:11:44 | 01,497,408 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/10/20 22:11:44 | 00,678,956 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2009/10/20 22:11:44 | 00,595,506 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/10/20 22:11:44 | 00,128,004 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2009/10/20 22:11:44 | 00,104,940 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/10/20 10:19:40 | 00,073,312 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\drivers\adfs.sys
[2009/10/16 20:51:20 | 00,044,925 | ---- | M] () -- C:\Users\Gerard\Desktop\ADHERENTS 2009-2010.pdf
[2009/10/15 10:54:41 | 00,003,252 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091015_105429.reg
[2009/10/15 09:37:16 | 00,000,967 | ---- | M] () -- C:\Users\Public\Desktop\PicturesToExe 6.021.lnk
[2009/10/14 07:12:51 | 00,000,682 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091014_071244.reg
[2009/10/13 18:57:03 | 00,055,656 | ---- | M] (
Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2009/10/13 18:57:03 | 00,028,520 | ---- | M] (
Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2009/10/13 18:44:03 | 00,000,304 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091013_184359.reg
[2009/10/13 18:32:50 | 00,108,683 | ---- | M] () -- C:\Users\Gerard\Desktop\image_1.jpg
[2009/10/13 11:39:44 | 00,000,290 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2009/10/10 17:06:07 | 00,000,304 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091010_170603.reg
[2009/10/10 16:05:22 | 00,001,130 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091010_160515.reg
[2009/10/10 16:04:55 | 00,021,856 | ---- | M] () -- C:\Users\Gerard\Documents\cc_20091010_160444.reg
[2009/10/10 15:39:55 | 00,001,602 | ---- | M] () -- C:\Users\Gerard\Desktop\DivX Movies.lnk
[2009/10/10 15:19:38 | 00,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2009/10/10 11:05:17 | 00,007,314 | ---- | M] () -- C:\Users\Gerard\AppData\Roaming\UserTile.png
[2009/10/10 10:44:17 | 00,000,359 | ---- | M] () -- C:\Users\Gerard\Desktop\Contacts.lnk
[2009/10/03 19:37:11 | 00,191,488 | ---- | M] () -- C:\Users\Gerard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/03 16:42:24 | 00,171,125 | ---- | M] () -- C:\Users\Gerard\Desktop\Favoris.htm
[2009/10/03 12:28:47 | 00,001,294 | ---- | M] () -- C:\Windows\MultiTimer.ini
[2009/10/02 20:01:57 | 25,198,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe
[2009/10/02 11:31:19 | 00,011,270 | -HS- | M] () -- C:\Windows\System32\KGyGaAvL.sys
[2009/10/01 10:29:14 | 00,195,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2009/09/27 17:42:43 | 00,796,672 | ---- | M] (Qsc) -- C:\Windows\GPInstall.exe
[2009/09/27 11:00:35 | 00,000,029 | ---- | M] () -- C:\Windows\DEBUGSM.INI
========== Files - No Company Name ==========
[2009/10/24 09:42:15 | 00,000,822 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/23 20:50:49 | 00,001,534 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091023_205046.reg
[2009/10/23 19:49:17 | 00,000,380 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091023_194913.reg
[2009/10/23 15:08:38 | 00,022,222 | ---- | C] () -- C:\Users\Gerard\Desktop\CA20091023_1500.odt
[2009/10/23 11:15:10 | 00,036,619 | ---- | C] () -- C:\Users\Gerard\Desktop\index.pdf
[2009/10/22 12:58:15 | 00,000,304 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091022_125813.reg
[2009/10/22 11:54:19 | 00,045,114 | ---- | C] () -- C:\Users\Gerard\Desktop\ADHERENTS 2009-2010(2).pdf
[2009/10/21 12:31:28 | 00,003,360 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091021_123123.reg
[2009/10/16 20:51:19 | 00,044,925 | ---- | C] () -- C:\Users\Gerard\Desktop\ADHERENTS 2009-2010.pdf
[2009/10/15 10:54:37 | 00,003,252 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091015_105429.reg
[2009/10/15 09:37:16 | 00,000,967 | ---- | C] () -- C:\Users\Public\Desktop\PicturesToExe 6.021.lnk
[2009/10/14 07:12:46 | 00,000,682 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091014_071244.reg
[2009/10/13 18:44:01 | 00,000,304 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091013_184359.reg
[2009/10/13 18:32:49 | 00,108,683 | ---- | C] () -- C:\Users\Gerard\Desktop\image_1.jpg
[2009/10/10 17:06:05 | 00,000,304 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091010_170603.reg
[2009/10/10 16:05:18 | 00,001,130 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091010_160515.reg
[2009/10/10 16:04:47 | 00,021,856 | ---- | C] () -- C:\Users\Gerard\Documents\cc_20091010_160444.reg
[2009/10/10 15:39:55 | 00,001,602 | ---- | C] () -- C:\Users\Gerard\Desktop\DivX Movies.lnk
[2009/10/10 10:44:05 | 00,000,359 | ---- | C] () -- C:\Users\Gerard\Desktop\Contacts.lnk
[2009/09/27 17:42:43 | 00,008,784 | ---- | C] () -- C:\Windows\F_France.gpl
[2009/09/27 11:00:35 | 00,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
[2009/09/12 22:07:34 | 00,000,000 | ---- | C] () -- C:\Windows\YASolitaire.INI
[2009/07/24 10:07:19 | 00,000,108 | ---- | C] () -- C:\Windows\WFT-E2Utility.INI
[2009/07/11 21:04:40 | 00,001,294 | ---- | C] () -- C:\Windows\MultiTimer.ini
[2009/06/27 10:30:57 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/04/02 18:55:34 | 00,059,904 | ---- | C] () -- C:\Windows\System32\zlib1.dll
[2009/04/02 17:53:47 | 00,000,052 | ---- | C] () -- C:\Windows\Relax.ini
[2009/03/24 11:46:32 | 04,215,884 | -H-- | C] () -- C:\Users\Gerard\AppData\Local\IconCache.db
[2009/03/02 22:59:01 | 00,000,088 | RHS- | C] () -- C:\ProgramData\F8D6994E2E.sys
[2009/03/02 22:59:00 | 00,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2009/01/05 21:44:29 | 00,001,704 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\mdb.bin
[2008/12/18 00:25:31 | 00,025,433 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\mdbu.bin
[2008/11/12 11:56:40 | 00,007,314 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\UserTile.png
[2008/07/10 09:06:05 | 00,000,691 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\GetValue.vbs
[2008/07/10 09:06:05 | 00,000,035 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\SetValue.bat
[2008/07/07 16:51:51 | 00,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008/06/27 11:45:04 | 00,015,190 | ---- | C] () -- C:\Windows\M3000Twn.ini
[2008/05/06 22:33:55 | 00,000,680 | ---- | C] () -- C:\Users\Gerard\AppData\Local\d3d9caps.dat
[2008/02/01 13:14:15 | 00,000,665 | ---- | C] () -- C:\Windows\CEL.INI
[2008/02/01 13:14:15 | 00,000,038 | ---- | C] () -- C:\Windows\progman.ini
[2008/01/26 13:13:35 | 00,000,025 | ---- | C] () -- C:\Windows\CDE80211_10100.ini
[2008/01/26 12:14:20 | 00,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2008/01/26 12:08:33 | 00,000,025 | ---- | C] () -- C:\Windows\CDE DX9400FDEFGIPS.ini
[2008/01/20 22:21:47 | 00,000,031 | ---- | C] () -- C:\Windows\e2eSoft.ini
[2008/01/20 19:16:16 | 00,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008/01/20 16:19:42 | 00,000,088 | RHS- | C] () -- C:\Windows\System32\F8D6994E2E.sys
[2007/12/18 23:22:00 | 00,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2007/12/10 19:35:07 | 00,000,037 | ---- | C] () -- C:\Windows\DeliveryReader.INI
[2007/12/03 15:58:38 | 00,020,480 | ---- | C] () -- C:\Windows\System32\ptevideo.dll
[2007/11/13 13:33:30 | 00,011,268 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate
[2007/10/19 13:53:56 | 00,524,288 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2007/10/05 21:03:52 | 00,000,025 | ---- | C] () -- C:\Windows\System32\lsrc.dll
[2007/09/29 12:20:18 | 00,000,059 | ---- | C] () -- C:\Windows\ANS2000.INI
[2007/09/29 12:20:18 | 00,000,020 | -H-- | C] () -- C:\Windows\akebook.ini
[2007/09/29 12:20:18 | 00,000,004 | -H-- | C] () -- C:\Windows\a3kebook.ini
[2007/09/20 15:29:12 | 00,000,094 | ---- | C] () -- C:\Users\Gerard\AppData\Local\fusioncache.dat
[2007/09/18 10:00:02 | 00,000,056 | RHS- | C] () -- C:\Windows\System32\2E4E99D6F8.sys
[2007/08/20 21:06:48 | 00,000,134 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\nero_photoshow_express_4_eu.txt
[2007/08/20 20:24:36 | 00,000,067 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\nero_photoshow_express_45_efigs_eu.txt
[2007/08/20 19:44:55 | 00,006,411 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007/07/26 23:25:03 | 00,091,536 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2007/07/26 20:59:38 | 00,000,382 | ---- | C] () -- C:\Windows\ODBC.INI
[2007/07/25 18:21:24 | 00,011,270 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2007/07/25 18:21:24 | 00,000,088 | RHS- | C] () -- C:\Windows\System32\F794E0FD01.sys
[2007/07/23 21:56:21 | 00,001,971 | ---- | C] () -- C:\Windows\Media9Il.INI
[2007/07/23 21:03:18 | 00,000,000 | ---- | C] () -- C:\Windows\OpPrintServer.INI
[2007/07/21 19:04:16 | 00,524,288 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2007/07/21 19:04:15 | 00,139,264 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2007/07/21 19:04:13 | 00,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2007/07/21 19:04:12 | 00,010,752 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2007/07/17 09:21:50 | 00,015,576 | ---- | C] () -- C:\Windows\System32\drivers\usbbc.sys
[2007/07/17 09:21:49 | 00,003,953 | ---- | C] () -- C:\Windows\System32\coinst.dll
[2007/07/14 02:30:37 | 00,015,190 | ---- | C] () -- C:\Windows\M2000T07.ini
[2007/07/13 23:01:09 | 00,191,488 | ---- | C] () -- C:\Users\Gerard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/07/13 18:02:04 | 00,076,584 | ---- | C] () -- C:\Windows\System32\drivers\int15.sys
[2007/07/13 18:02:04 | 00,015,656 | ---- | C] () -- C:\Windows\System32\drivers\int15_64.sys
[2007/07/13 18:00:49 | 00,065,536 | ---- | C] () -- C:\Windows\System32\NATTraversal.dll
[2007/07/13 17:53:05 | 00,000,037 | ---- | C] () -- C:\Windows\Acer.ini
[2007/07/13 17:52:40 | 00,035,416 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\nvModes.001
[2007/07/13 17:52:38 | 00,035,416 | ---- | C] () -- C:\Users\Gerard\AppData\Roaming\nvModes.dat
[2007/07/13 17:51:03 | 00,098,032 | ---- | C] () -- C:\Users\Gerard\AppData\Local\GDIPFONTCACHEV1.DAT
[2007/01/25 03:52:26 | 00,065,536 | ---- | C] () -- C:\Program Files\Common Files\NMSAccessU.exe
[2007/01/24 13:05:16 | 00,029,184 | ---- | C] () -- C:\Windows\System32\kWab.dll
[2007/01/02 18:54:14 | 00,266,240 | ---- | C] () -- C:\Windows\System32\NotesExtmngr.dll
[2007/01/02 18:53:54 | 00,204,800 | ---- | C] () -- C:\Windows\System32\NotesActnMenu.dll
[2007/01/02 18:53:20 | 00,086,016 | ---- | C] () -- C:\Windows\System32\MSNSpook.dll
[2007/01/02 18:52:40 | 00,037,376 | ---- | C] () -- C:\Windows\System32\MsnChatHook_org.dll
[2007/01/02 18:52:28 | 00,028,672 | ---- | C] () -- C:\Windows\System32\BatchCrypto.dll
[2007/01/02 18:52:26 | 00,073,728 | ---- | C] () -- C:\Windows\System32\APISlice.dll
[2007/01/02 18:52:18 | 00,063,488 | ---- | C] () -- C:\Windows\System32\ShowErrMsg.dll
[2006/12/25 15:44:48 | 00,022,016 | ---- | C] () -- C:\Windows\System32\MailFormat_U.dll
[2006/12/10 22:10:33 | 00,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2006/12/10 12:29:18 | 00,331,776 | ---- | C] () -- C:\Windows\System32\ScrollBarLib.dll
[2006/12/10 12:17:45 | 00,013,952 | ---- | C] () -- C:\Windows\System32\drivers\UBHelper.sys
[2006/12/10 12:16:35 | 00,198,144 | ---- | C] () -- C:\Windows\System32\_psisdecd.dll
[2006/12/02 09:24:39 | 00,872,448 | ---- | C] () -- C:\Windows\iconv.dll
[2006/12/02 09:24:39 | 00,743,424 | ---- | C] () -- C:\Windows\libxml2.dll
[2006/12/02 09:24:39 | 00,204,800 | ---- | C] () -- C:\Windows\Capsule.dll
[2006/12/02 09:24:39 | 00,000,041 | ---- | C] () -- C:\Windows\PreLaunch.ini
[2006/12/02 09:24:38 | 01,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2006/11/02 14:50:50 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 14:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 12:25:21 | 00,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006/11/02 12:23:31 | 00,000,288 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 12:23:31 | 00,000,277 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 09:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005/06/11 11:47:00 | 00,045,056 | ---- | C] () -- C:\Windows\System32\fpprintmon.dll
[2005/03/14 14:38:28 | 00,000,469 | ---- | C] () -- C:\Windows\bdoscandellang.ini
[2004/10/27 00:39:05 | 03,375,104 | ---- | C] () -- C:\Windows\System32\qt-mt331.dll
[2002/06/06 02:01:58 | 00,029,696 | ---- | C] () -- C:\Windows\System32\asutl8.dll
[2002/03/21 15:39:02 | 00,073,728 | ---- | C] () -- C:\Windows\System32\UNACEV2.DLL
[2001/12/26 16:12:30 | 00,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/03 23:46:38 | 00,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 16:33:56 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/23 22:04:36 | 00,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
[1999/03/17 15:24:26 | 00,000,136 | ---- | C] () -- C:\Windows\System32\mstraps.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:0F8F5844
@Alternate Data Stream - 1240 bytes -> C:\ProgramData\Microsoft:CrFS6XYA7pju0y73nCQle
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:B623B5B8
@Alternate Data Stream - 1159 bytes -> C:\ProgramData\Microsoft:pavNxcPO6nIZtHEdFmIBzX0I
@Alternate Data Stream - 1149 bytes -> C:\Users\Gerard\AppData\Local\Temp:LUqGZvRFHaFyiqbjVAimNaOne4f
@Alternate Data Stream - 1140 bytes -> C:\Program Files\Common Files\System:3Q5qu5nwFk5ud1i9I5Vh47dfyqs
@Alternate Data Stream - 1041 bytes -> C:\ProgramData\Microsoft:vfXiOBYkhAfpZLSrlQw
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:9F683177
<End>