Log OTL :OTL logfile created on: 02/04/2011 14:42:17 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Jean-Marc\Bureau
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 76,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 220,70 Gb Total Space | 203,97 Gb Free Space | 92,42% Space Free | Partition Type: NTFS
Drive G: | 245,06 Gb Total Space | 215,60 Gb Free Space | 87,98% Space Free | Partition Type: NTFS
Computer Name: JMG-D703818D69D | User Name: Jean-Marc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/04/02 13:53:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jean-Marc\Bureau\OTL.exe
PRC - [2011/04/02 11:52:15 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/04/02 11:51:52 | 000,421,032 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2011/04/02 11:51:51 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/04/02 11:51:48 | 000,339,624 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
PRC - [2011/04/02 11:51:47 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/04/02 11:51:46 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/12/20 19:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/12/20 19:08:56 | 000,443,728 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2010/12/14 15:50:22 | 001,517,376 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
PRC - [2009/10/29 20:13:58 | 001,732,960 | ---- | M] (Diskeeper Corporation) -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2008/04/13 19:34:04 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ========== MOD - [2011/04/02 13:53:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jean-Marc\Bureau\OTL.exe
MOD - [2010/09/22 19:12:42 | 000,378,264 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\pdfshell.dll
MOD - [2010/08/23 18:12:39 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/07/12 02:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2009/02/27 18:37:16 | 000,311,296 | ---- | M] () -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\pdfshell.FRA
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/04/02 11:52:15 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/04/02 11:51:52 | 000,421,032 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2011/04/02 11:51:48 | 000,339,624 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2011/04/02 11:51:47 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/12/23 19:45:58 | 000,496,128 | ---- | M] (Crawler.com) [Disabled | Stopped] -- C:\Program Files\Spyware Terminator\sp_rsser.exe -- (sp_rssrv)
SRV - [2010/12/20 19:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/12/20 16:55:14 | 000,251,760 | ---- | M] (CybelSoft) [Disabled | Stopped] -- C:\Program Files\ma-config.com\maconfservice.exe -- (maconfservice)
SRV - [2010/12/14 15:50:22 | 001,517,376 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/12/14 15:48:10 | 000,029,504 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010/12/10 14:29:00 | 000,092,008 | ---- | M] (TomTom) [Disabled | Stopped] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/10/29 20:13:58 | 001,732,960 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2009/01/07 18:21:08 | 000,026,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\spupdsvc.exe -- (spupdsvc)
SRV - [2008/11/04 01:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2007/03/06 17:55:24 | 000,105,248 | ---- | M] (Labtec Inc.) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2006/10/26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006/10/26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe -- (MDM)
SRV - [2003/03/09 21:31:02 | 000,065,795 | ---- | M] (HP) [Disabled | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ========== DRV - [2011/04/02 11:52:30 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/04/02 11:52:30 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2011/04/02 11:52:29 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/04/02 11:51:46 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010/12/23 19:45:58 | 000,142,592 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
DRV - [2010/12/20 19:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/12/20 16:49:07 | 000,023,568 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AdfuUd.sys -- (AdfuUd)
DRV - [2010/11/29 20:27:40 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010/09/01 12:46:09 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2010/09/01 12:45:54 | 000,036,992 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SISAGPX.sys -- (sisagp)
DRV - [2010/08/30 12:19:54 | 000,014,336 | ---- | M] (CybelSoft) [Kernel | On_Demand | Stopped] -- C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys -- (driverhardwarev2)
DRV - [2009/12/30 12:20:54 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/10/21 01:04:34 | 000,041,120 | ---- | M] (Diskeeper Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKRtWrt.sys -- (DKRtWrt)
DRV - [2008/09/24 10:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2008/04/13 11:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008/04/13 09:35:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C)
DRV - [2007/03/06 17:54:40 | 000,041,376 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/03/06 17:52:46 | 002,261,792 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/03/06 17:50:30 | 001,669,664 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/03/06 17:48:46 | 001,273,504 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007/03/06 17:48:46 | 000,014,240 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2007/02/20 15:31:14 | 000,008,652 | ---- | M] (author Ing. Igor Cesko and Atmel corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVR309.sys -- (AVR309Prj)
DRV - [2001/08/17 22:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://fr.msn.com/?ocid=iehpIE - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
IE - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Rechercher MyStart"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://pro.orange.fr/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/25 23:30:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 23:30:30 | 000,000,000 | ---D | M]
[2010/09/01 08:27:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jean-Marc\Application Data\Mozilla\Extensions
[2010/08/31 22:43:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jean-Marc\Application Data\Mozilla\Extensions\home2@tomtom.com
[2011/03/27 21:34:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jean-Marc\Application Data\Mozilla\Firefox\Profiles\gab16dup.default\extensions
[2011/03/25 20:11:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/12/23 19:16:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JEAN-MARC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\GAB16DUP.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/03/25 23:29:59 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/12/23 19:16:04 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/25 23:30:09 | 000,001,516 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
[2011/03/25 23:30:09 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/03/25 23:30:09 | 000,001,822 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
[2011/03/25 23:30:09 | 000,001,154 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
[2011/03/25 23:30:09 | 000,001,426 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
[2011/03/25 23:30:09 | 000,000,956 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: ([2011/03/12 12:49:44 | 000,465,879 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ___id___.c.mystat-in.net
O1 - Hosts: 127.0.0.1 0.r.msn.com
O1 - Hosts: 127.0.0.1 005.free-counter.co.uk
O1 - Hosts: 127.0.0.1 006.free-counter.co.uk
O1 - Hosts: 127.0.0.1 007.free-counter.co.uk
O1 - Hosts: 127.0.0.1 008.free-counter.co.uk
O1 - Hosts: 127.0.0.1 008.free-counters.co.uk
O1 - Hosts: 127.0.0.1 00fun.com
O1 - Hosts: 127.0.0.1 011707160008.c.mystat-in.net
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 061606084448.c.mystat-in.net
O1 - Hosts: 127.0.0.1 070806142521.c.mystat-in.net
O1 - Hosts: 127.0.0.1 08search.com
O1 - Hosts: 127.0.0.1 090906042103.c.mystat-in.net
O1 - Hosts: 127.0.0.1 092706152958.c.mystat-in.net
O1 - Hosts: 127.0.0.1 0d7292.r.axf8.net
O1 - Hosts: 127.0.0.1 0f36f3.r.axf8.net
O1 - Hosts: 127.0.0.1 1.adbrite.com
O1 - Hosts: 127.0.0.1 1.googlenews.xorg.pl
O1 - Hosts: 127.0.0.1 1.marketbanker.com
O1 - Hosts: 127.0.0.1 1.ofsnetwork.com
O1 - Hosts: 127.0.0.1 1.sharkadnetwork.com
O1 - Hosts: 127.0.0.1 100.mbn.com.ua
O1 - Hosts: 127.0.0.1 100.topnews.ru
O1 - Hosts: 14771 more lines...
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 0
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 0
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogoff = 0
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 1
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
O7 - HKU\S-1-5-21-1292428093-1214440339-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microso ... 3330059484 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Jean-Marc\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jean-Marc\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O27 - HKLM IFEO\presentationhost.exe: Debugger - "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe" (TuneUp Software)
O27 - HKLM IFEO\tomtomhome.exe: Debugger - "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe" (TuneUp Software)
O27 - HKLM IFEO\uninstall tomtom home.exe: Debugger - "C:\Program Files\TuneUp Utilities 2011\TUAutoReactivator32.exe" (TuneUp Software)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/31 22:11:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ========== [2011/04/02 13:58:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/04/02 13:56:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ERUNT
[2011/04/02 13:56:04 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/04/02 13:55:01 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Jean-Marc\Bureau\erunt-setup.exe
[2011/04/02 13:53:12 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jean-Marc\Bureau\OTL.exe
[2011/04/02 11:57:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean-Marc\Application Data\Avira
[2011/04/02 11:55:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Avira
[2011/04/02 11:54:33 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/04/02 11:54:24 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/04/02 11:54:24 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/04/02 11:54:24 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/04/02 11:54:24 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/04/02 11:54:23 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/04/02 11:54:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2011/04/01 21:14:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jean-Marc\Menu Démarrer\Programmes\HiJackThis
[2011/04/01 21:14:41 | 000,000,000 | ---D | C] -- C:\Program Files\Hijackthis
[2011/04/01 16:49:10 | 000,000,000 | ---D | C] -- G:\Documents de Jean-Marc\Nouveau dossier
[2011/03/19 16:22:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Jean-Marc\Recent
[2011/03/13 16:21:47 | 000,000,000 | ---D | C] -- G:\Documents de Jean-Marc\Leroux
========== Files - Modified Within 30 Days ========== [2011/04/02 14:29:28 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/02 14:18:24 | 000,002,623 | ---- | M] () -- C:\Documents and Settings\Jean-Marc\Bureau\Microsoft Office Outlook 2007.lnk
[2011/04/02 14:02:24 | 000,191,052 | ---- | M] () -- C:\Documents and Settings\Jean-Marc\Bureau\00-PAD-nickW.pdf
[2011/04/02 13:56:31 | 000,000,000 | -HS- | M] () -- C:\DkHyperbootSync
[2011/04/02 13:55:10 | 000,005,024 | ---- | M] () -- C:\Documents and Settings\Jean-Marc\Bureau\erunt-loc_fr.zip
[2011/04/02 13:55:01 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Jean-Marc\Bureau\erunt-setup.exe
[2011/04/02 13:53:32 | 000,000,395 | ---- | M] () -- C:\Documents and Settings\Jean-Marc\Bureau\scan.zip
[2011/04/02 13:53:14 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jean-Marc\Bureau\OTL.exe
[2011/04/02 13:45:09 | 000,000,316 | -HS- | M] () -- C:\WINDOWS\tasks\VXIL.job
[2011/04/02 13:45:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/02 11:52:30 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/04/02 11:52:30 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/04/02 11:52:29 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/04/02 11:52:29 | 000,022,360 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/04/02 11:52:28 | 000,045,416 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/04/02 11:31:37 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rundll32.exe
[2011/04/01 21:42:56 | 000,002,548 | ---- | M] () -- C:\config.xml
[2011/04/01 21:38:55 | 000,018,782 | ---- | M] () -- C:\WINDOWS\System32\RW_AppData.dat
[2011/04/01 21:38:55 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\RW_FileType.dat
[2011/04/01 21:21:23 | 000,006,944 | ---- | M] () -- C:\WINDOWS\System32\RW_{5644215A-B53C-11DF-8969-0010DCEFD6C2}.dat
[2011/04/01 21:21:23 | 000,000,360 | ---- | M] () -- C:\WINDOWS\System32\RW_FileFlag.dat
[2011/04/01 21:15:40 | 000,002,567 | ---- | M] () -- C:\Documents and Settings\Jean-Marc\Bureau\HiJackThis.lnk
[2011/04/01 13:49:59 | 000,000,528 | ---- | M] () -- C:\hpfr3420.xml
[2011/04/01 08:47:46 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Skype.lnk
[2011/03/29 11:30:00 | 000,251,915 | ---- | M] () -- G:\Documents de Jean-Marc\IRKG 1.JPG
[2011/03/29 11:30:00 | 000,230,268 | ---- | M] () -- G:\Documents de Jean-Marc\IRKG2.JPG
[2011/03/29 11:30:00 | 000,228,687 | ---- | M] () -- G:\Documents de Jean-Marc\IRKG5.JPG
[2011/03/29 11:30:00 | 000,226,755 | ---- | M] () -- G:\Documents de Jean-Marc\IRKG4.JPG
[2011/03/29 11:30:00 | 000,218,436 | ---- | M] () -- G:\Documents de Jean-Marc\IRKG.JPG
[2011/03/29 11:30:00 | 000,215,188 | ---- | M] () -- G:\Documents de Jean-Marc\IRKG3.JPG
[2011/03/27 09:30:56 | 000,005,096 | ---- | M] () -- C:\WINDOWS\System32\RW_{44988DC3-B544-11DF-A928-806D6172696F}.dat
[2011/03/27 08:51:32 | 000,561,650 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2011/03/27 08:51:32 | 000,489,040 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/27 08:51:32 | 000,099,068 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2011/03/27 08:51:32 | 000,083,456 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/21 14:01:26 | 000,632,481 | ---- | M] () -- G:\Documents de Jean-Marc\Commande de porte de garage roulante RTS04XL.pdf
[2011/03/21 10:18:00 | 004,086,236 | ---- | M] () -- G:\Documents de Jean-Marc\Porte BFA à affleurement de façade GUTTOMAT.pdf
[2011/03/19 21:38:51 | 000,375,467 | ---- | M] () -- G:\Documents de Jean-Marc\doc4.jpg
[2011/03/19 21:38:50 | 000,407,406 | ---- | M] () -- G:\Documents de Jean-Marc\doc3.jpg
[2011/03/19 21:38:48 | 000,306,921 | ---- | M] () -- G:\Documents de Jean-Marc\doc2.jpg
[2011/03/19 21:38:46 | 000,130,667 | ---- | M] () -- G:\Documents de Jean-Marc\doc.jpg
[2011/03/18 15:43:06 | 000,992,319 | ---- | M] () -- G:\Documents de Jean-Marc\Commande de porte de garage roulante RTS 03 L.pdf
[2011/03/18 14:42:42 | 000,931,109 | ---- | M] () -- G:\Documents de Jean-Marc\Pose porte roulante.jpg
[2011/03/18 14:39:28 | 000,423,532 | ---- | M] () -- G:\Documents de Jean-Marc\Commande de porte de garage roulante RTS 03 M.pdf
[2011/03/14 19:30:00 | 000,044,780 | ---- | M] () -- G:\Documents de Jean-Marc\Info partenaire _Février_2011_.pdf
[2011/03/14 12:17:00 | 000,484,449 | ---- | M] () -- G:\Documents de Jean-Marc\Elektromaten notice en Français du coffret 970.pdf
[2011/03/14 12:17:00 | 000,360,922 | ---- | M] () -- G:\Documents de Jean-Marc\Elektromaten notice en Français des moteurs.pdf
[2011/03/10 10:09:19 | 000,044,780 | ---- | M] () -- G:\Documents de Jean-Marc\Partnerinfo_2_2011_F nouveau profil fermeture AVALON.pdf
[2011/03/05 15:12:03 | 000,000,398 | ---- | M] () -- C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1296911482.job
========== Files Created - No Company Name ========== [2011/04/02 14:02:24 | 000,191,052 | ---- | C] () -- C:\Documents and Settings\Jean-Marc\Bureau\00-PAD-nickW.pdf
[2011/04/02 13:55:10 | 000,005,024 | ---- | C] () -- C:\Documents and Settings\Jean-Marc\Bureau\erunt-loc_fr.zip
[2011/04/02 13:53:29 | 000,000,395 | ---- | C] () -- C:\Documents and Settings\Jean-Marc\Bureau\scan.zip
[2011/04/02 13:15:14 | 000,000,000 | -HS- | C] () -- C:\DkHyperbootSync
[2011/04/01 21:14:42 | 000,002,567 | ---- | C] () -- C:\Documents and Settings\Jean-Marc\Bureau\HiJackThis.lnk
[2011/03/29 11:30:00 | 000,251,915 | ---- | C] () -- G:\Documents de Jean-Marc\IRKG 1.JPG
[2011/03/29 11:30:00 | 000,230,268 | ---- | C] () -- G:\Documents de Jean-Marc\IRKG2.JPG
[2011/03/29 11:30:00 | 000,228,687 | ---- | C] () -- G:\Documents de Jean-Marc\IRKG5.JPG
[2011/03/29 11:30:00 | 000,226,755 | ---- | C] () -- G:\Documents de Jean-Marc\IRKG4.JPG
[2011/03/29 11:30:00 | 000,218,436 | ---- | C] () -- G:\Documents de Jean-Marc\IRKG.JPG
[2011/03/29 11:30:00 | 000,215,188 | ---- | C] () -- G:\Documents de Jean-Marc\IRKG3.JPG
[2011/03/25 23:30:44 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Mozilla Firefox.lnk
[2011/03/21 14:01:26 | 000,632,481 | ---- | C] () -- G:\Documents de Jean-Marc\Commande de porte de garage roulante RTS04XL.pdf
[2011/03/20 15:37:00 | 004,086,236 | ---- | C] () -- G:\Documents de Jean-Marc\Porte BFA à affleurement de façade GUTTOMAT.pdf
[2011/03/19 19:15:23 | 000,306,921 | ---- | C] () -- G:\Documents de Jean-Marc\doc2.jpg
[2011/03/19 17:00:28 | 000,375,467 | ---- | C] () -- G:\Documents de Jean-Marc\doc4.jpg
[2011/03/19 16:44:01 | 000,407,406 | ---- | C] () -- G:\Documents de Jean-Marc\doc3.jpg
[2011/03/19 16:44:01 | 000,130,667 | ---- | C] () -- G:\Documents de Jean-Marc\doc.jpg
[2011/03/18 15:43:06 | 000,992,319 | ---- | C] () -- G:\Documents de Jean-Marc\Commande de porte de garage roulante RTS 03 L.pdf
[2011/03/18 14:39:28 | 000,423,532 | ---- | C] () -- G:\Documents de Jean-Marc\Commande de porte de garage roulante RTS 03 M.pdf
[2011/03/18 13:40:12 | 000,931,109 | ---- | C] () -- G:\Documents de Jean-Marc\Pose porte roulante.jpg
[2011/03/14 19:30:00 | 000,044,780 | ---- | C] () -- G:\Documents de Jean-Marc\Info partenaire _Février_2011_.pdf
[2011/03/14 12:17:00 | 000,484,449 | ---- | C] () -- G:\Documents de Jean-Marc\Elektromaten notice en Français du coffret 970.pdf
[2011/03/14 12:17:00 | 000,360,922 | ---- | C] () -- G:\Documents de Jean-Marc\Elektromaten notice en Français des moteurs.pdf
[2011/03/10 10:09:19 | 000,044,780 | ---- | C] () -- G:\Documents de Jean-Marc\Partnerinfo_2_2011_F nouveau profil fermeture AVALON.pdf
[2011/03/03 15:05:48 | 000,000,316 | -HS- | C] () -- C:\WINDOWS\tasks\VXIL.job
[2011/02/05 15:03:06 | 000,019,558 | ---- | C] () -- C:\WINDOWS\hpoins01.dat
[2011/02/05 15:03:06 | 000,016,606 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat
[2010/12/23 19:45:58 | 000,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2010/09/19 15:39:58 | 000,018,782 | ---- | C] () -- C:\WINDOWS\System32\RW_AppData.dat
[2010/09/19 15:39:58 | 000,006,944 | ---- | C] () -- C:\WINDOWS\System32\RW_{5644215A-B53C-11DF-8969-0010DCEFD6C2}.dat
[2010/09/19 15:39:58 | 000,005,096 | ---- | C] () -- C:\WINDOWS\System32\RW_{44988DC3-B544-11DF-A928-806D6172696F}.dat
[2010/09/19 15:39:58 | 000,000,360 | ---- | C] () -- C:\WINDOWS\System32\RW_FileFlag.dat
[2010/09/19 15:39:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\RW_FileType.dat
[2010/09/01 12:48:13 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010/09/01 12:45:22 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\Jean-Marc\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 12:43:28 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2010/09/01 12:43:09 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2010/09/01 12:13:16 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Jean-Marc\Local Settings\Application Data\fusioncache.dat
[2010/09/01 10:17:38 | 000,051,370 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/09/01 10:13:34 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/09/01 08:26:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/09/01 00:00:10 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/08/31 23:59:13 | 000,259,840 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/31 22:12:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/08/31 22:08:57 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/05/03 05:46:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/03 05:46:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008/05/03 05:46:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/05/03 05:46:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/05/03 05:46:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/05/03 05:46:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/05/03 05:46:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/05/03 05:46:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008/05/03 05:46:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/04/13 19:50:22 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/13 19:34:00 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\ctfmon.exe
[2007/03/06 17:50:30 | 001,669,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2006/12/30 19:27:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/05 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/05 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/05 14:00:00 | 000,561,650 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
[2004/08/05 14:00:00 | 000,489,040 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/05 14:00:00 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
[2004/08/05 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/05 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/05 14:00:00 | 000,099,068 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
[2004/08/05 14:00:00 | 000,083,456 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/05 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/05 14:00:00 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat
[2004/08/05 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/05 14:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/05 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/03/09 21:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
========== LOP Check ========== [2010/08/31 22:30:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
[2010/12/23 18:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ma-config.com
[2011/04/01 20:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2011/01/29 20:24:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2010/09/19 15:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2010/12/23 19:56:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/12/23 19:08:03 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2010/08/31 22:43:47 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2011/03/24 15:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Béatrice\Application Data\Icones
[2010/12/23 20:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Béatrice\Application Data\TuneUp Software
[2011/04/01 17:00:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jean-Marc\Application Data\Spyware Terminator
[2010/12/23 23:19:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jean-Marc\Application Data\StopFlash
[2010/08/31 22:43:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jean-Marc\Application Data\TomTom
[2010/12/23 19:08:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jean-Marc\Application Data\TuneUp Software
[2010/12/23 20:24:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sybille\Application Data\TuneUp Software
[2011/03/05 15:12:03 | 000,000,398 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1296911482.job
[2011/04/02 13:45:09 | 000,000,316 | -HS- | M] () -- C:\WINDOWS\Tasks\VXIL.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2010/08/31 20:02:34 | 014,966,800 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >[2010/08/31 20:02:34 | 014,966,800 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: CTFMON.EXE >[2010/09/01 08:36:38 | 000,036,864 | ---- | M] () MD5=18747FCB2508EEEC79415B32F63F3654 -- C:\WINDOWS\system32\ctfmon.exe
[2010/09/01 08:36:38 | 000,036,864 | ---- | M] () MD5=18747FCB2508EEEC79415B32F63F3654 -- C:\WINDOWS\system32\dllcache\ctfmon.exe
< MD5 for: EVENTLOG.DLL >[2008/04/13 19:33:26 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/13 19:33:26 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=4EC800BDF80521B0207BD2301DFC7D14 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >[2008/04/13 19:34:04 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\explorer.exe
[2008/04/13 19:34:04 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: NETLOGON.DLL >[2008/04/13 19:33:36 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/13 19:33:36 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=04821179C3171554C1BD1F9888A113E2 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >[2008/04/13 19:33:42 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/13 19:33:42 | 000,187,392 | ---- | M] (Microsoft Corporation) MD5=973B36634C544948C663E8269AA1B3A3 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USERINIT.EXE >[2008/04/13 19:34:28 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/13 19:34:28 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2008/04/13 19:34:30 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/13 19:34:30 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles >[2011/04/02 13:45:09 | 000,000,316 | -HS- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\Tasks\VXIL.job
========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\rundll32.exe:SummaryInformation
< End of report >
"On a trouvé, en bonne politique [actuelle], à faire mourir ceux, qui en travaillant la terre, font vivre les autres"