rapport suite :
========== Driver Services (SafeList) ========== DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/08/09 21:44:11 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/08/09 21:44:10 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2011/04/27 13:19:28 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2010/06/24 14:00:14 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010/04/27 03:25:16 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2010/04/27 03:25:16 | 000,100,224 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bserd.sys -- (ss_bserd)
DRV - [2010/04/27 03:25:16 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2010/04/27 03:25:16 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2010/02/25 13:51:17 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2009/12/11 21:37:43 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/07/26 20:17:18 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/06/26 21:01:00 | 009,777,376 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/04/11 05:45:24 | 000,113,664 | ---- | M] (
Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rmcast.sys -- (RMCAST)
DRV - [2009/04/11 05:42:52 | 000,031,616 | ---- | M] (
Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009/03/30 09:32:47 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2009/02/13 11:34:33 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/02/08 12:12:50 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf.sys -- (npf)
DRV - [2009/01/22 16:06:34 | 000,030,816 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iqvw32.sys -- (NAL)
DRV - [2008/12/07 12:44:54 | 000,030,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2008/05/28 11:33:14 | 000,083,288 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2008/03/07 12:39:50 | 000,045,848 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2008/02/26 08:17:30 | 000,493,568 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2008/01/15 00:56:30 | 000,218,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2007/11/30 16:23:02 | 000,097,216 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2007/07/16 11:28:06 | 000,088,320 | ---- | M] (Philips Applied Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\phaudlwr.sys -- (phaudlwr)
DRV - [2007/07/06 19:26:34 | 003,033,856 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\spc1300.sys -- (SPC1300) USB2.0 PC Camera (SPC1300)
DRV - [2005/12/12 18:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\
Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktopIE - HKLM\SOFTWARE\
Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop IE - HKU\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\
Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\SOFTWARE\
Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://fr.msn.com/?ocid=iehpIE - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\SOFTWARE\
Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
IE - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\SOFTWARE\
Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 DF A9 3B 96 A4 CC 01 [binary data]
IE - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\SOFTWARE\
Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\..\URLSearchHook: {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - No CLSID value found
IE - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\Software\
Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\Software\
Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=18&q="
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.laposte.net/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems:
en-GB@dictionaries.addons.mozilla.org:1.19.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems:
quickstores@quickstores.de:1.2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=18&tid={798335B0-69FA-29ED-46A9-D38DEC793439}&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@
Microsoft.com/NpCtrl,version=1.0: C:\Program Files\
Microsoft Silverlight\4.0.60831.0\npctrl.dll (
Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@
microsoft.com/OfficeLive,version=1.5: C:\Program Files\
Microsoft\Office Live\npOLW.dll (
Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@
microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (
Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@
microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (
Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@
microsoft.com/WPF,version=3.5: C:\Windows\
Microsoft.NET\
Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (
Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.6.0: C:\Users\Benoit BERQUIN\AppData\Local\Yahoo!\BrowserPlus\2.6.0\Plugins\npybrowserplus_2.6.0.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/19 20:13:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 23:05:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/14 15:25:43 | 000,000,000 | ---D | M]
[2008/08/27 21:18:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benoit BERQUIN\AppData\Roaming\mozilla\Extensions
[2011/11/10 21:49:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benoit BERQUIN\AppData\Roaming\mozilla\Firefox\Profiles\1r61jjw5.default\extensions
[2011/03/07 17:57:40 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Benoit BERQUIN\AppData\Roaming\mozilla\Firefox\Profiles\1r61jjw5.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/10 21:49:18 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Benoit BERQUIN\AppData\Roaming\mozilla\Firefox\Profiles\1r61jjw5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/12/12 13:39:08 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Benoit BERQUIN\AppData\Roaming\mozilla\Firefox\Profiles\1r61jjw5.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2010/09/05 15:06:45 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Users\Benoit BERQUIN\AppData\Roaming\mozilla\Firefox\Profiles\1r61jjw5.default\extensions\quickstores@quickstores.de
[2010/08/30 20:09:50 | 000,001,819 | ---- | M] () -- C:\Users\Benoit BERQUIN\AppData\Roaming\Mozilla\Firefox\Profiles\1r61jjw5.default\searchplugins\bing.xml
[2011/11/11 23:05:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/27 23:09:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2010/09/04 12:43:15 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\quickstores@quickstores.de
() (No name found) -- C:\USERS\BENOIT BERQUIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1R61JJW5.DEFAULT\EXTENSIONS\{398E77B8-2304-11DC-8314-0800200C9A66}.XPI
() (No name found) -- C:\USERS\BENOIT BERQUIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1R61JJW5.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\BENOIT BERQUIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1R61JJW5.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
[2011/11/11 23:05:14 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,001,822 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010/01/01 09:00:00 | 000,001,154 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2009/09/06 18:00:20 | 000,003,700 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fast.png
[2009/09/06 18:00:21 | 000,001,963 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fast.xml
[2010/01/01 09:00:00 | 000,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2010/01/01 09:00:00 | 000,000,956 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
========== Chrome ========== CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\11.0.696.65\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\
Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin:
Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007
Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin:
Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\
Microsoft\Office Live\npOLW.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\11.0.696.65\pdf.dll
CHR - plugin: Chrome NaCl (Disabled) = C:\Program Files\Google\Chrome\Application\11.0.696.65\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\11.0.696.65\gears.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.6.0 (Enabled) = C:\Users\Benoit BERQUIN\AppData\Local\Yahoo!\BrowserPlus\2.6.0\Plugins\npybrowserplus_2.6.0.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\
Microsoft.NET\
Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Benoit BERQUIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0\
O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Aide pour le lien d'Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (XBTBPos00 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()
O3 - HKLM\..\Toolbar: (Fast Browser Search) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()
O3 - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001\..\Toolbar\WebBrowser: (Fast Browser Search) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PC Cleaners] C:\Program Files\PC Cleaners\PCCleaners.exe (PC Cleaners Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (
Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (
Microsoft Corporation)
O4 - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001..\Run: [Neuf Media Center] C:\Program Files\SFR\Media Center\MediaCenter.exe (SFR)
O4 - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001..\Run: [Shareaza] C:\Program Files\Shareaza\Shareaza.exe (Shareaza Development Team)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O4 - HKU\S-1-5-21-3017553372-3954341448-1392868311-1001..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/5.0_(Windows;_U;_Windows_NT_6.0;_fr;_rv:1.9.1.7)_Gecko/20091221_Firefox/3.5.7_(.NET_CLR_3.5.30729)_FBSMTWB" -"http://pbskids.org/caillou_french/games/dresscaillou/index.html" File not found
O4 - Startup: C:\Users\Benoit BERQUIN\AppData\Roaming\
Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Benoit BERQUIN\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Benoit BERQUIN\AppData\Roaming\
Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\
Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\
Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\
Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Download with &Shareaza - C:\Program Files\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O8 - Extra context menu item:
Télécharger avec Mipony - C:\Program Files\MiPony\Browser\IEContext.htm ()
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (
Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (
Microsoft Corporation)
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .csm - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .csml - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .cub - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .cube - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .dx - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .emb - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .embl - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .gau - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .jdx - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .mol - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .mop - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .pdb - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .rxn - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .scr - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .skc - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .spt - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .tgf - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O12 - Plugin for: .xyz - C:\Program Files\Internet Explorer\PLUGINS\npchime.dll (MDL Information Systems, Inc (Elsevier MDL))
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://a1540.g.akamai.net/7/1540/52/200 ... plugin.cab (QuickTime Object)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CFA543A3-B428-4FEB-85BC-B39FF003487B}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F269576C-6660-4226-B035-4C4BC807206D}: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (aacext.dll) -C:\Windows\System32\aacext.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (
Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (
Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Benoit BERQUIN\Pictures\2010_07_28\IMG_4918.JPG
O24 - Desktop BackupWallPaper: C:\Users\Benoit BERQUIN\Pictures\2010_07_28\IMG_4918.JPG
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/27 17:50:58 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{3f758e10-aa97-11df-854d-001bfcc41d10}\Shell\Shell00\Command - "" = F:\Start.exe
O33 - MountPoints2\{ec4ba948-6127-11dc-8955-001bfcc41d10}\Shell\AutoRun\command - "" = L:\Delivery\DeliveryReader.exe
O33 - MountPoints2\{ec4ba94b-6127-11dc-8955-001bfcc41d10}\Shell - "" = AutoRun
O33 - MountPoints2\{ec4ba94b-6127-11dc-8955-001bfcc41d10}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (
Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ========== [2011/11/20 15:28:45 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/11/20 15:26:57 | 000,000,000 | ---D | C] -- C:\ProgramData\
Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/11/20 15:26:56 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/11/20 15:21:58 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Benoit BERQUIN\Desktop\OTL.exe
[2011/11/20 14:50:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011/11/20 14:50:07 | 000,000,000 | ---D | C] -- C:\rsit
[2011/11/19 17:33:54 | 000,000,000 | ---D | C] -- C:\ProgramData\
Microsoft\Windows\Start Menu\Programs\Multi Virus Cleaner 2011
[2011/11/19 17:19:07 | 000,000,000 | ---D | C] -- C:\Users\Benoit BERQUIN\AppData\Roaming\PC Cleaners
[2011/11/19 17:19:04 | 000,000,000 | ---D | C] -- C:\ProgramData\
Microsoft\Windows\Start Menu\Programs\PC Cleaners
[2011/11/19 17:19:01 | 005,359,888 | ---- | C] (PC Cleaners) -- C:\Windows\uninst.exe
[2011/11/19 17:18:57 | 000,000,000 | ---D | C] -- C:\ProgramData\PC1Data
[2011/11/19 17:18:57 | 000,000,000 | ---D | C] -- C:\Program Files\PC Cleaners
[2011/11/19 15:54:35 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2011/11/19 11:57:01 | 000,000,000 | ---D | C] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Malwarebytes
[2011/11/19 11:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\
Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/19 11:56:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/19 11:56:51 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/11/19 11:56:51 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/13 15:12:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\FEB5AE06E59209DD765AAADF8E7B6660
[2011/10/27 23:09:01 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/10/27 23:09:01 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/10/27 23:09:01 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/10/27 11:41:58 | 000,000,000 | ---D | C] -- C:\Users\Benoit BERQUIN\{a352e744-845d-4576-946d-ab47b1323ecf}
[2011/10/27 11:36:22 | 000,000,000 | ---D | C] -- C:\Windows\System32\System32
[2007/12/27 11:09:06 | 000,250,544 | ---- | C] (KeyWorks Software) -- C:\Program Files\Common Files\keyhelp.ocx
[34 C:\Users\Benoit BERQUIN\AppData\Roaming\*.tmp files -> C:\Users\Benoit BERQUIN\AppData\Roaming\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/11/20 15:44:04 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011/11/20 15:27:00 | 000,000,875 | ---- | M] () -- C:\Users\Benoit BERQUIN\AppData\Roaming\
Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/11/20 15:26:57 | 000,000,695 | ---- | M] () -- C:\Users\Benoit BERQUIN\Desktop\NTREGOPT.lnk
[2011/11/20 15:26:57 | 000,000,676 | ---- | M] () -- C:\Users\Benoit BERQUIN\Desktop\ERUNT.lnk
[2011/11/20 15:22:00 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Benoit BERQUIN\Desktop\OTL.exe
[2011/11/20 14:53:01 | 000,001,056 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 14:40:21 | 000,001,139 | ---- | M] () -- C:\Users\Benoit BERQUIN\.eInstructionDeviceManagerPreferences.xml
[2011/11/20 14:40:17 | 000,000,049 | ---- | M] () -- C:\Users\Benoit BERQUIN\DeviceManagerState.properties
[2011/11/20 14:36:15 | 000,032,726 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011/11/20 14:36:14 | 000,032,726 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/11/20 14:36:13 | 000,459,264 | ---- | M] () -- C:\Windows\System32\aacext.dll
[2011/11/20 14:36:11 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 14:36:00 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 14:36:00 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 14:35:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/19 23:15:39 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011/11/19 16:44:09 | 005,359,888 | ---- | M] (PC Cleaners) -- C:\Windows\uninst.exe
[2011/11/19 15:44:45 | 000,027,077 | ---- | M] () -- C:\Windows\System32\GnuHashes.ini
[2011/11/19 11:56:56 | 000,000,868 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/19 11:38:32 | 000,000,396 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\cc_20111119_113826.reg
[2011/11/19 11:38:04 | 000,109,538 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\cc_20111119_113743.reg
[2011/11/15 21:57:00 | 000,000,512 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/11/11 14:44:27 | 000,001,466 | ---- | M] () -- C:\Users\Benoit BERQUIN\.recently-used.xbel
[2011/11/11 14:38:50 | 001,630,992 | ---- | M] () -- C:\Windows\System32\sysperf.exe
[2011/11/05 11:12:59 | 000,305,218 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112582.jpg
[2011/11/05 11:12:58 | 000,333,447 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112581.jpg
[2011/11/05 11:12:55 | 000,331,024 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112551.jpg
[2011/11/05 11:12:55 | 000,321,584 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112552.jpg
[2011/11/05 11:12:55 | 000,303,359 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112553.jpg
[2011/11/05 11:12:46 | 000,331,024 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112461.jpg
[2011/11/05 11:12:46 | 000,321,584 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112462.jpg
[2011/11/05 11:12:46 | 000,303,359 | ---- | M] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112463.jpg
[2011/11/02 09:28:23 | 000,098,816 | ---- | M] () -- C:\Users\Benoit BERQUIN\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/02 09:24:02 | 000,725,536 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2011/11/02 09:24:02 | 000,637,106 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/11/02 09:24:02 | 000,147,284 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2011/11/02 09:24:02 | 000,120,610 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/10/26 13:42:37 | 000,000,361 | ---- | M] () -- C:\Windows\Flash.ini
[34 C:\Users\Benoit BERQUIN\AppData\Roaming\*.tmp files -> C:\Users\Benoit BERQUIN\AppData\Roaming\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/11/20 15:44:04 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011/11/20 15:27:00 | 000,000,875 | ---- | C] () -- C:\Users\Benoit BERQUIN\AppData\Roaming\
Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/11/20 15:26:57 | 000,000,695 | ---- | C] () -- C:\Users\Benoit BERQUIN\Desktop\NTREGOPT.lnk
[2011/11/20 15:26:57 | 000,000,676 | ---- | C] () -- C:\Users\Benoit BERQUIN\Desktop\ERUNT.lnk
[2011/11/20 14:36:13 | 000,459,264 | ---- | C] () -- C:\Windows\System32\aacext.dll
[2011/11/19 15:44:45 | 000,027,077 | ---- | C] () -- C:\Windows\System32\GnuHashes.ini
[2011/11/19 11:56:56 | 000,000,868 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/19 11:38:29 | 000,000,396 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\cc_20111119_113826.reg
[2011/11/19 11:37:49 | 000,109,538 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\cc_20111119_113743.reg
[2011/11/13 15:12:35 | 001,630,992 | ---- | C] () -- C:\Windows\System32\sysperf.exe
[2011/11/11 14:44:27 | 000,001,466 | ---- | C] () -- C:\Users\Benoit BERQUIN\.recently-used.xbel
[2011/11/05 11:12:59 | 000,305,218 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112582.jpg
[2011/11/05 11:12:58 | 000,333,447 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112581.jpg
[2011/11/05 11:12:55 | 000,331,024 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112551.jpg
[2011/11/05 11:12:55 | 000,321,584 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112552.jpg
[2011/11/05 11:12:55 | 000,303,359 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112553.jpg
[2011/11/05 11:12:46 | 000,331,024 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112461.jpg
[2011/11/05 11:12:46 | 000,321,584 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112462.jpg
[2011/11/05 11:12:46 | 000,303,359 | ---- | C] () -- C:\Users\Benoit BERQUIN\Documents\Capt-1112463.jpg
[2011/05/21 12:29:10 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011/05/21 12:29:10 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011/04/27 13:19:32 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011/04/27 13:19:30 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011/04/27 13:19:30 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011/04/27 13:19:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011/04/27 13:19:30 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2010/10/06 13:56:40 | 000,344,160 | ---- | C] () -- C:\Windows\System32\RASWIN.EXE
[2010/10/05 09:38:58 | 000,000,548 | ---- | C] () -- C:\Program Files\Common Files\eInstruction.ini
[2010/09/04 16:44:09 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat
[2010/08/23 11:28:06 | 000,000,291 | ---- | C] () -- C:\Windows\DeVisu.ini
[2010/02/21 22:50:01 | 000,000,127 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2010/01/21 13:22:44 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2010/01/17 17:53:01 | 000,000,361 | ---- | C] () -- C:\Windows\Flash.ini
[2009/12/24 09:13:09 | 000,032,726 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/12/23 09:03:58 | 000,032,726 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/10/06 08:16:00 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/09/17 13:19:56 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/17 13:19:55 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/16 18:58:36 | 000,171,780 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2009/08/31 13:45:43 | 000,000,102 | ---- | C] () -- C:\Users\Benoit BERQUIN\AppData\Local\fusioncache.dat
[2009/05/25 19:22:27 | 000,169,648 | ---- | C] () -- C:\Windows\hpqins00.dat
[2009/02/15 13:35:07 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/02/08 12:12:50 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2009/01/30 19:56:31 | 000,000,048 | ---- | C] () -- C:\Windows\wininit.ini
[2009/01/18 18:58:47 | 000,000,043 | ---- | C] () -- C:\Windows\System32\calibration.dat
[2009/01/15 18:57:22 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2009/01/01 13:31:00 | 000,000,000 | ---- | C] () -- C:\Windows\plclient.INI
[2008/12/29 12:37:36 | 000,004,761 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008/12/07 12:44:54 | 000,030,088 | ---- | C] () -- C:\Windows\System32\drivers\btnetBus.sys
[2008/11/29 20:04:08 | 000,004,096 | -H-- | C] () -- C:\Users\Benoit BERQUIN\AppData\Local\keyfile3.drm
[2008/09/18 20:01:25 | 000,000,240 | ---- | C] () -- C:\Users\Benoit BERQUIN\AppData\Roaming\Solve Elec 2.1 Prefs
[2008/09/09 07:21:13 | 000,145,689 | ---- | C] () -- C:\Windows\hpoins18.dat.temp
[2008/09/09 07:21:13 | 000,006,600 | ---- | C] () -- C:\Windows\hpomdl18.dat.temp
[2008/08/19 07:30:45 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/07/20 18:26:34 | 000,618,496 | ---- | C] () -- C:\Windows\System32\stlpmt45.dll
[2008/07/20 18:26:33 | 000,204,800 | ---- | C] () -- C:\Windows\System32\LPNG.DLL
[2008/06/01 08:27:08 | 000,159,991 | ---- | C] () -- C:\Windows\Sqirlz Morph Uninstaller.exe
[2008/05/18 19:52:56 | 000,001,024 | ---- | C] () -- C:\Users\Benoit BERQUIN\AppData\Roaming\WavCodec.wff
[2008/04/14 08:55:46 | 000,105,220 | ---- | C] () -- C:\Windows\hpqins16.dat
[2008/02/05 12:37:59 | 000,028,672 | ---- | C] () -- C:\Windows\System32\drivers\spc1300c.sys
[2008/02/05 12:37:58 | 003,033,856 | ---- | C] () -- C:\Windows\System32\drivers\spc1300.sys
[2007/12/28 11:39:28 | 000,000,000 | ---- | C] () -- C:\Windows\OpPrintServer.INI
[2007/12/02 16:24:37 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2007/12/02 16:03:41 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2007/08/30 18:15:29 | 000,000,000 | ---- | C] () -- C:\Windows\Videodeluxe.INI
[2007/08/30 18:00:54 | 000,006,423 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2007/08/30 07:45:34 | 000,003,654 | ---- | C] () -- C:\Windows\System32\drivers\Sonyhcp.dll
[2007/08/27 08:56:53 | 000,098,816 | ---- | C] () -- C:\Users\Benoit BERQUIN\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/25 20:54:35 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2007/08/25 20:01:22 | 000,145,689 | ---- | C] () -- C:\Windows\hpoins18.dat
[2007/06/28 03:12:59 | 000,725,536 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2007/06/28 03:12:59 | 000,340,236 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2007/06/28 03:12:59 | 000,147,284 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2007/06/28 03:12:59 | 000,037,390 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2007/06/27 17:43:22 | 000,111,416 | ---- | C] () -- C:\Windows\hpqins13.dat
[2007/06/27 17:28:44 | 000,061,440 | ---- | C] () -- C:\Windows\System32\OsdRemove.exe
[2007/06/27 17:25:49 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom24.dll
[2007/06/27 17:25:49 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes24.dll
[2007/03/06 09:47:24 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2007/01/12 06:07:48 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2007/01/12 06:07:48 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/11/02 13:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,463,568 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,637,106 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,120,610 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/06/23 09:09:34 | 000,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll
[2003/12/09 14:09:26 | 000,036,864 | ---- | C] () -- C:\Windows\System32\Nmea.dll
[2003/11/27 14:50:26 | 000,139,264 | ---- | C] () -- C:\Windows\System32\ConversApi.dll
[2003/10/03 10:18:40 | 000,049,152 | ---- | C] () -- C:\Windows\System32\OgcDrvSilva.dll
[2003/10/03 10:18:32 | 000,057,344 | ---- | C] () -- C:\Windows\System32\OgcDrvSena.dll
[2003/10/03 10:18:26 | 000,061,440 | ---- | C] () -- C:\Windows\System32\OgcDrvMlr.dll
[2003/10/03 10:18:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\OgcDrvMagellan.dll
[2003/10/03 10:18:12 | 000,086,016 | ---- | C] () -- C:\Windows\System32\OgcDrvGarmin.dll
[2003/10/03 07:13:40 | 000,036,864 | ---- | C] () -- C:\Windows\System32\Ogc.dll
[2002/11/25 14:11:22 | 000,688,128 | ---- | C] () -- C:\Windows\System32\BCGCB474.dll
[2002/01/13 16:12:02 | 000,188,416 | ---- | C] () -- C:\Windows\System32\CP30FW.DLL
[2001/12/19 08:07:50 | 000,040,960 | ---- | C] () -- C:\Windows\System32\BCGCBResFRA.dll
========== LOP Check ========== [2010/04/05 10:37:11 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\2020 Fusion
[2009/05/24 08:30:53 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Advanced Chemistry Development
[2010/12/08 14:42:50 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Delivery
[2011/11/20 14:39:19 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Dropbox
[2008/01/02 21:38:32 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\eMule
[2011/08/28 11:11:01 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\eTeks
[2009/09/06 17:32:09 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\GTCO CalComp
[2011/11/11 14:44:27 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\gtk-2.0
[2008/08/28 13:39:13 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Généatique2009
[2010/09/03 16:28:59 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Image Zone Express
[2008/03/08 11:42:33 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Inkscape
[2009/10/20 09:40:25 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\IObit
[2011/08/28 10:39:15 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\LiveCAD3
[2011/10/27 08:43:57 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Mipony
[2010/12/27 16:21:50 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\MP-Manager
[2010/12/27 14:53:38 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\MPMAN
[2007/09/01 08:59:57 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\muvee Technologies
[2010/01/21 12:40:04 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\NCH Swift Sound
[2007/12/23 10:06:40 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Nvu
[2009/02/11 16:23:41 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\OpenOffice.org
[2009/09/16 20:26:27 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Overlook
[2011/11/19 17:19:07 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\PC Cleaners
[2007/09/16 13:46:56 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Printer Info Cache
[2007/08/30 19:21:17 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Publish Providers
[2010/09/04 13:13:08 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\QuickStoresToolbar
[2011/05/25 19:42:00 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Samsung
[2009/01/01 13:30:51 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\ScanSoft
[2010/12/03 14:46:40 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Shareaza
[2008/05/27 15:10:35 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\Sony
[2009/05/03 20:17:24 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\TeamViewer
[2007/11/07 17:07:23 | 000,000,000 | ---D | M] -- C:\Users\Benoit BERQUIN\AppData\Roaming\WinBatch
[2011/11/15 21:57:00 | 000,000,512 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/11/19 23:15:43 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==================== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2008/01/19 08:42:25 | 000,056,376 | ---- | M] (
Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | ---- | M] (
Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | ---- | M] (
Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | ---- | M] (
Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 10:49:52 | 000,053,864 | ---- | M] (
Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 10:49:52 | 000,053,864 | ---- | M] (
Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >[2009/04/11 07:32:26 | 000,019,944 | ---- | M] (
Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | ---- | M] (
Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | ---- | M] (
Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 08:41:30 | 000,021,560 | ---- | M] (
Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/19 08:41:30 | 000,021,560 | ---- | M] (
Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 10:49:36 | 000,019,048 | ---- | M] (
Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/02/24 09:36:58 | 000,021,560 | ---- | M] (
Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/02/24 09:36:58 | 000,021,560 | ---- | M] (
Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/02/24 09:36:58 | 000,021,560 | ---- | M] (
Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
< MD5 for: CNGAUDIT.DLL >[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (
Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 10:46:03 | 000,011,776 | ---- | M] (
Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: CTFMON.EXE >[2006/11/02 10:45:00 | 000,008,704 | ---- | M] (
Microsoft Corporation) MD5=22BFD03DF51065A9ED8D17F8FB72296B -- C:\Windows\System32\ctfmon.exe
[2006/11/02 10:45:00 | 000,008,704 | ---- | M] (
Microsoft Corporation) MD5=22BFD03DF51065A9ED8D17F8FB72296B -- C:\Windows\winsxs\x86_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.0.6000.16386_none_9af9cad793a67953\ctfmon.exe
< MD5 for: EXPLORER.EXE >[2008/10/29 07:20:29 | 002,923,520 | ---- | M] (
Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 07:29:41 | 002,927,104 | ---- | M] (
Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 04:59:17 | 002,927,616 | ---- | M] (
Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007/11/17 09:53:59 | 002,923,520 | ---- | M] (
Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007/11/17 09:53:58 | 002,923,520 | ---- | M] (
Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (
Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (
Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 03:15:02 | 002,923,520 | ---- | M] (
Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 10:45:07 | 002,923,520 | ---- | M] (
Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 08:33:10 | 002,927,104 | ---- | M] (
Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: IASTOR.SYS >[2007/03/21 13:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\hp\DRIVERS\Intel_raid_ICH9\iastor.sys
[2007/03/21 13:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\drivers\iaStor.sys
[2007/03/21 13:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys
[2007/03/21 13:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Windows\System32\DriverStore\FileRepository\iastor.inf_5f6e7be5\iaStor.sys
< MD5 for: IASTORV.SYS >[2008/01/19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: NETLOGON.DLL >[2006/11/02 10:46:11 | 000,559,616 | ---- | M] (
Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/11 07:28:23 | 000,592,896 | ---- | M] (
Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009/04/11 07:28:23 | 000,592,896 | ---- | M] (
Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 08:35:36 | 000,592,384 | ---- | M] (
Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVSTOR.SYS >[2006/11/02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys