[OK] dll mystérieuse

Modérateur: Modérateurs et Modératrices

[OK] dll mystérieuse

Messagede claude0207 » 05 Mar 2009, 09:06

Bonjour

depuis quelques jours, à l'ouverture de Windows, je reçois le message suivant: Ouverture urqNDUIM.DLL impossible, accès refusé. chemin: c:\users\mon nom\appdata\local\temp\urqNDUIM.dll je suis allé à sa rencontre pour essayer d'apprivoiser la bête (autorisations, lecture uniquement, cache etc...) rien n'y fait. Si je la supprime le message devient "dll. manquante"
Mon problème est que je n'arrive pas à déterminé de manière simple le programme demandeur.
Si quelqu'un peut m'eviter le fastidieux demarrage sélectif à répétition en enlevant à chaque fois un log. du menu démarrer jusqu'à le trouver. Merci.
claude0207
 
Messages: 49
Inscription: 23 Juil 2007, 08:00
Localisation: Huy - Belgique

Messagede nickW » 05 Mar 2009, 09:33

Bonjour,

Un fichier DLL qui est appelé à chaque démarrage ..... tout en étant placé dans un dossier temporaire, cela semble suspect.

Création de deux rapports détaillés sur ton système:

Étape 1: OTListIt2 (de OldTimer), téléchargement
Télécharger OTListIt2.exe depuis http://oldtimer.geekstogo.com/OTListIt2.exe
Enregistrer ce fichier sur le Bureau.


Étape 2: OTListIt2 (de OldTimer)
Fermer toutes les fenêtres de programme ouvertes.

Faire un clic droit sur OTListIt2.exe puis choisir "Exécuter en tant qu'Administrateur" pour lancer l'outil.

L'écran principal de OTListIt2 s'affiche:
Image

Si ce n'est déjà fait, dans le paragraphe Extra Registry, cocher le bouton-radio Use SafeList

Cocher (en haut) la case située devant Scan All Users: Image

Puis cliquer sur le bouton Run Scan: Image

Laisser l'outil travailler sans l'interrompre.
Lorsque l'outil a terminé, il y a ouverture d'une fenêtre du Bloc-notes contenant un rapport (log).
Fermer le Bloc-notes.
Le second rapport est visible dans la Barre des tâches. Le fermer également.
Fermer la fenêtre de OTListIt2.


Étape 3: Résultats
Envoyer en réponse dans deux messages distincts (à cause de la longueur des logs):
*- les deux rapports de OTListIt2 (contenu des fichiers OTListIt.txt et Extras.txt situés sur le Bureau).
Les rapports envoyés sur le forum doivent se terminer par une ligne contenant <End>. Si ce n'est pas le cas, ils sont incomplets, et doivent alors être découpés en plusieurs messages.

Note importante: Pour l'envoi de ta(tes) réponse(s), il ne faut pas créer un nouveau sujet, mais cliquer sur le bouton "Répondre"
Image pour continuer dans ce fil de discussion.



PS:
Attention aux multi-demandes. Il ne faut pas suivre en même temps les conseils de deux forums distincts.
http://soswindows.forumactif.com/forum- ... -t2627.htm

A suivre,
nickW - Image
30/07/2012: Plus de désinfection de PC jusqu'à nouvel ordre.
Pas de demande d'analyse de log en MP (Message Privé)
Mes configs
Avatar de l’utilisateur
nickW
Modérateur
 
Messages: 21698
Inscription: 20 Mai 2004, 17:41
Localisation: Dordogne/Île de France

dll mytérieuse

Messagede claude0207 » 05 Mar 2009, 10:06

OTListIt logfile created on: 5/03/2009 10:00:26 - Run 7
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\claude\Desktop
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 0000080c | Country: Belgique | Language: FRB | Date Format: d/MM/yyyy

2,00 Gb Total Physical Memory | 1,12 Gb Available Physical Memory | 56,07% Memory free
4,00 Gb Paging File | 3,29 Gb Available in Paging File | 82,24% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 29,30 Gb Total Space | 13,01 Gb Free Space | 44,42% Space Free | Partition Type: NTFS
Drive D: | 47,04 Gb Total Space | 32,49 Gb Free Space | 69,08% Space Free | Partition Type: NTFS
Drive E: | 76,33 Gb Total Space | 29,10 Gb Free Space | 38,13% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC-DE-CLAUDE
Current User Name: claude
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/03/03 15:05:02 | 00,079,400 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe
PRC - [2009/02/05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/02/25 19:18:14 | 00,425,080 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe
PRC - [2007/06/28 23:02:08 | 01,049,856 | ---- | M] (O&O Software GmbH) -- C:\Windows\system32\oodag.exe
PRC - [2009/01/14 17:53:02 | 00,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/03/02 17:58:54 | 00,603,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe
PRC - [2009/02/05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2008/01/18 23:33:12 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2008/01/18 23:38:40 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2004/06/18 09:31:02 | 00,067,584 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SOUNDMAN.EXE
PRC - [2007/06/28 23:01:00 | 02,512,128 | ---- | M] (O&O Software GmbH) -- C:\Windows\System32\oodtray.exe
PRC - [2009/02/05 22:08:45 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2007/10/10 06:28:32 | 00,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2006/05/04 06:58:56 | 00,998,912 | ---- | M] () -- C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe
PRC - [2008/03/03 15:05:04 | 00,959,976 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2007/02/09 15:48:00 | 00,516,096 | ---- | M] (Sergio Santos) -- C:\Program Files\sTabLauncher\sTabLauncher.exe
PRC - [2008/04/01 10:39:48 | 00,486,856 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe
PRC - [2003/02/06 16:47:12 | 00,053,248 | ---- | M] (RagTime GmbH) -- C:\Program Files\RagTime Solo\Konni\KonniSymbol.exe
PRC - [2009/02/10 13:42:56 | 05,391,192 | ---- | M] (Innovative Solutions) -- C:\Program Files\Innovative Solutions\DriverMax\devices.exe
PRC - [2008/01/18 23:33:12 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/01/18 23:33:40 | 00,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wbem\wmiprvse.exe
PRC - [2009/03/05 09:38:55 | 00,498,176 | ---- | M] (OldTimer Tools) -- C:\Users\claude\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/02/25 19:18:14 | 00,425,080 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe -- (a2free [Auto | Running])
SRV - [2008/01/05 03:25:58 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009/02/05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/01/05 03:26:42 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/01/18 23:33:10 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 13:34:14 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 13:34:14 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2008/01/05 03:21:54 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/01/05 03:21:40 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/01/05 03:21:40 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/02/28 18:07:48 | 00,529,704 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2007/06/28 23:02:08 | 01,049,856 | ---- | M] (O&O Software GmbH) -- C:\Windows\system32\oodag.exe -- (O&O Defrag [Auto | Running])
SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2009/01/14 17:53:02 | 00,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort [Auto | Running])
SRV - [2007/04/21 14:54:10 | 00,052,080 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe -- (Start BT in service [On_Demand | Stopped])
SRV - [2009/03/02 17:58:48 | 00,360,192 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag [On_Demand | Stopped])
SRV - [2009/03/02 17:58:54 | 00,603,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc [Auto | Running])
SRV - [2008/12/11 13:31:36 | 00,027,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp [Auto | Running])
SRV - [2008/03/03 15:05:02 | 00,079,400 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
SRV - [2008/01/18 23:38:26 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2008/01/18 23:33:40 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2006/11/02 10:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 10:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 10:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 10:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])
DRV - [2004/02/24 04:08:52 | 00,400,384 | ---- | M] (Sensaura) -- C:\Windows\system32\drivers\ALCXSENS.SYS -- (ALCXSENS [On_Demand | Running])
DRV - [2004/06/21 09:53:20 | 00,626,204 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2006/11/02 10:49:20 | 00,014,952 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\system32\drivers\aliide.sys -- (aliide [Disabled | Stopped])
DRV - [2006/11/02 10:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arc.sys -- (arc [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])
DRV - [2009/02/05 22:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\Windows\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 22:06:59 | 00,051,792 | ---- | M] (ALWIL Software) -- C:\Windows\system32\DRIVERS\aswMonFlt.sys -- (aswMonFlt [Auto | Running])
DRV - [2009/02/05 22:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr [System | Running])
DRV - [2009/02/05 22:07:23 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 22:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2006/11/02 08:30:53 | 00,464,384 | ---- | M] (Broadcom Corporation) -- C:\Windows\system32\DRIVERS\bcmwl6.sys -- (BCM43XV [On_Demand | Running])
DRV - [2007/03/05 05:51:24 | 00,034,576 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\blueletaudio.sys -- (BlueletAudio [On_Demand | Running])
DRV - [2007/03/05 06:00:04 | 00,027,792 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio [On_Demand | Running])
DRV - [2006/11/02 09:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 09:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 09:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserid.sys -- (Brserid [Disabled | Stopped])
DRV - [2006/11/02 09:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 09:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 09:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer [On_Demand | Stopped])
DRV - [2007/03/05 05:59:04 | 00,018,320 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\btnetdrv.sys -- (BT [On_Demand | Running])
DRV - [2002/07/16 20:59:28 | 00,085,231 | ---- | M] (iuLab software) -- C:\Windows\system32\drivers\BT848.sys -- (BT848 [Auto | Running])
DRV - [2007/03/05 06:01:18 | 00,039,184 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\btcusb.sys -- (Btcsrusb [On_Demand | Running])
DRV - [2007/03/05 05:55:12 | 00,020,880 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\vbtenum.sys -- (BTHidEnum [Boot | Running])
DRV - [2007/03/05 05:56:18 | 00,035,600 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\BTHidMgr.sys -- (BTHidMgr [Boot | Running])
DRV - [2001/10/08 21:12:18 | 00,009,187 | ---- | M] (iuLab software, Conexant Systems, Inc.) -- C:\Windows\system32\drivers\BTTUNER.sys -- (BTTUNER [Auto | Running])
DRV - [2001/10/08 21:12:18 | 00,008,193 | ---- | M] (iuLab software, Conexant Systems, Inc.) -- C:\Windows\system32\drivers\BTXBAR.sys -- (BTXBAR [Auto | Running])
DRV - [2006/11/02 10:49:28 | 00,016,488 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])
DRV - [2006/11/02 08:30:54 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\Windows\system32\DRIVERS\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])
DRV - [2006/11/02 10:51:34 | 00,316,520 | ---- | M] (Emulex) -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs [Disabled | Stopped])
DRV - [2006/11/02 10:51:25 | 00,232,040 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV [Disabled | Stopped])
DRV - [2006/11/02 10:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])
DRV - [2006/11/02 10:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 10:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])
DRV - [2006/11/02 10:50:04 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 10:50:05 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
DRV - [2006/11/02 10:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\megasas.sys -- (megasas [Disabled | Stopped])
DRV - [2006/11/02 10:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 10:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 08:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])
DRV - [2006/11/02 08:30:56 | 00,429,056 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\DRIVERS\nvm60x32.sys -- (NVENETFD [On_Demand | Running])
DRV - [2007/12/11 17:06:00 | 08,238,688 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\DRIVERS\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])
DRV - [2006/11/02 10:50:24 | 00,088,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])
DRV - [2006/11/02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor [Disabled | Stopped])
DRV - [2009/03/02 03:02:24 | 00,240,128 | ---- | M] (PARADOX) -- C:\Windows\System32\drivers\royal.sys -- (OemBiosDevice [Boot | Stopped])
DRV - [2004/03/17 19:29:50 | 00,058,841 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\Pv848.sys -- (Pv848 [Auto | Running])
DRV - [2004/04/27 05:58:04 | 00,017,691 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\system32\drivers\PHTUNER.sys -- (PVTUNER [Auto | Running])
DRV - [2004/02/26 09:36:58 | 00,006,841 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\system32\drivers\PvXBAR.sys -- (PVXBAR [Auto | Running])
DRV - [2006/11/02 10:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])
DRV - [2007/10/30 19:05:00 | 00,009,088 | ---- | M] () -- C:\Program Files\RivaTuner v2.06\RivaTuner32.sys -- (RivaTuner32 [On_Demand | Running])
DRV - [2008/01/18 21:57:16 | 00,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Running])
DRV - [2006/11/02 07:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])
DRV - [2004/02/09 08:27:04 | 00,097,857 | ---- | M] (Silicon Image, Inc) -- C:\Windows\system32\DRIVERS\SI3114R.sys -- (SI3114r [Boot | Running])
DRV - [2003/10/15 03:28:16 | 00,010,240 | ---- | M] (Silicon Image, Inc.) -- C:\Windows\system32\DRIVERS\SiWinAcc.sys -- (SiFilter [Boot | Running])
DRV - [2006/11/02 10:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 10:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
DRV - [2009/03/03 15:20:53 | 00,717,296 | ---- | M] () -- C:\Windows\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006/11/02 10:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 10:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 10:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 10:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])
DRV - [2006/11/02 10:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
DRV - [2007/03/05 05:52:18 | 00,034,448 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\VComm.sys -- (VComm [On_Demand | Running])
DRV - [2007/03/05 05:53:18 | 00,044,304 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\VcommMgr.sys -- (VcommMgr [On_Demand | Running])
DRV - [2006/11/02 10:49:30 | 00,017,512 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\system32\drivers\viaide.sys -- (viaide [Disabled | Stopped])
DRV - [2008/03/03 15:06:04 | 00,279,440 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\system32\DRIVERS\vsdatant.sys -- (Vsdatant [System | Running])
DRV - [2006/11/02 10:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/intl/fr/
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\S-1-5-21-1232965312-3791907715-587907267-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - presf.js..browser.search.defaulturl: "http://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.be/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6
FF - prefs.js..browser.search.defaultenginename: "chrome://browser-region/locale/region.properties"
FF - prefs.js..browser.startup.homepage: "http://www.google.be/intl/fr/"
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/03 12:24:21 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/03 15:30:20 00,000,000 | ---D | M]
FF - C:\Users\claude\AppData\Roaming\mozilla\Extensions [2009/03/03 12:24:22 00,000,000 | ---D | M]
FF - C:\Users\claude\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/03/03 12:24:22 00,000,000 | ---D | M]
FF - C:\Users\claude\AppData\Roaming\mozilla\Firefox\Profiles\7s5sy1kp.default\extensions [2009/03/03 20:04:14 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions [2009/03/04 13:36:42 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/03 12:24:10 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [2009/03/03 13:23:10 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/03/03 14:53:58 00,000,000 | ---D | M]

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe File not found
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart (NVIDIA Corporation)
O4 - HKLM..\Run: [OODefragTray] C:\Windows\system32\oodtray.exe (O&O Software GmbH)
O4 - HKLM..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S ()
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe --background ()
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" ()
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent (Innovative Solutions)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [Konni Symbol Autostart] "C:\Program Files\RagTime Solo\Konni\KonniSymbol.exe" (RagTime GmbH)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [MSServer] rundll32.exe C:\Users\claude\AppData\Local\Temp\urqNDUlM.dll,#1 ()
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [sTabLauncher] C:\Program Files\sTabLauncher\sTabLauncher.exe (Sergio Santos)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programmes\Microsoft Office\Office12\REFIEBAR.DLL File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Programmes\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{c7133eca-06ca-11de-88a1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c7133eca-06ca-11de-88a1-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Bin\Assetup.exe -- File not found
O33 - MountPoints2\{f9ef825d-082c-11de-a05b-00030d000001}\Shell - "" = AutoRun
O33 - MountPoints2\{f9ef825d-082c-11de-a05b-00030d000001}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -- File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/03/05 09:38:08 | 00,498,176 | ---- | C] (OldTimer Tools) -- C:\Users\claude\Desktop\OTListIt2.exe
[2009/03/04 22:17:08 | 00,005,358 | ---- | C] () -- D:\claude Taillard\Documents\cc_20090304_2217.reg
[2009/03/04 22:07:23 | 00,000,000 | ---D | C] -- C:\Program Files\RivaTuner v2.06
[2009/03/04 21:26:12 | 00,000,000 | ---D | C] -- C:\Program Files\NeoTracePro
[2009/03/04 21:01:59 | 00,114,688 | ---- | C] (vbAccelerator) -- C:\Windows\System32\cTreeOpt6.ocx
[2009/03/04 21:01:57 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6STKIT.DLL
[2009/03/04 21:01:55 | 00,000,000 | ---D | C] -- C:\Program Files\ZGuideTV
[2009/03/04 19:49:26 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/03/04 19:44:06 | 00,000,000 | ---D | C] -- C:\ProgramData\PC Drivers HeadQuarters
[2009/03/04 19:44:04 | 00,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters
[2009/03/04 19:43:30 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Downloaded Installations
[2009/03/04 15:36:06 | 00,000,000 | ---D | C] -- D:\claude Taillard\Documents\My Drivers
[2009/03/04 15:36:06 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Innovative Solutions
[2009/03/04 15:32:33 | 00,000,000 | ---D | C] -- C:\Program Files\Innovative Solutions
[2009/03/04 15:02:03 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\DivX
[2009/03/04 15:02:02 | 00,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009/03/04 13:39:07 | 00,012,791 | ---- | C] () -- D:\claude Taillard\Documents\Dis-moi... Le silence fait si mal....docx
[2009/03/04 13:29:57 | 00,011,310 | ---- | C] () -- D:\claude Taillard\Documents\Penser à quelqu.docx
[2009/03/04 13:15:07 | 00,010,845 | ---- | C] () -- D:\claude Taillard\Documents\Tu vas partir pour retrouver John et toi seule sais ce qui se passera.docx
[2009/03/04 09:53:38 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuaueng.dll
[2009/03/04 09:53:38 | 01,524,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2009/03/04 09:53:38 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuauclt.exe
[2009/03/04 09:53:38 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2009/03/04 09:53:25 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2009/03/04 09:53:25 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2009/03/04 09:53:25 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2009/03/04 09:53:15 | 00,162,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2009/03/04 09:53:15 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2009/03/03 23:00:44 | 00,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2009/03/03 23:00:42 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\uTorrent
[2009/03/03 22:14:23 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\U3
[2009/03/03 21:57:00 | 00,000,000 | ---D | C] -- C:\Program Files\DreamMail4
[2009/03/03 21:34:18 | 00,000,000 | ---D | C] -- C:\Windows\Sun
[2009/03/03 19:56:58 | 00,008,314 | ---- | C] () -- C:\Windows\System32\BIN_STRSBW.SPT
[2009/03/03 18:57:36 | 00,000,000 | ---D | C] -- C:\Program Files\aMSN
[2009/03/03 18:34:37 | 00,024,576 | ---- | C] () -- C:\Users\claude\Desktop\urqNDUlM.dll
[2009/03/03 15:55:30 | 00,005,571 | ---- | C] () -- C:\Windows\System32\vsconfig.xml
[2009/03/03 15:55:29 | 00,054,672 | ---- | C] (Zone Labs Inc.) -- C:\Windows\System32\vsutil_loc040c.dll
[2009/03/03 15:55:16 | 01,086,952 | ---- | C] (Python Software Foundation) -- C:\Windows\System32\zpeng24.dll
[2009/03/03 15:55:15 | 00,000,000 | ---D | C] -- C:\Program Files\Zone Labs
[2009/03/03 15:55:14 | 00,000,000 | ---D | C] -- C:\ProgramData\CheckPoint
[2009/03/03 15:54:33 | 00,352,615 | -H-- | C] () -- C:\Windows\System32\drivers\vsconfig.xml
[2009/03/03 15:54:33 | 00,000,000 | ---D | C] -- C:\Windows\System32\ZoneLabs
[2009/03/03 15:53:49 | 00,000,000 | ---D | C] -- C:\Windows\Internet Logs
[2009/03/03 15:37:32 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/03/03 15:36:26 | 00,016,318 | ---- | C] () -- D:\claude Taillard\Documents\cc_20090303_1536.reg
[2009/03/03 15:26:35 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2009/03/03 15:20:53 | 00,717,296 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/03/03 15:20:44 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\DAEMON Tools
[2009/03/03 15:15:14 | 00,000,000 | ---D | C] -- C:\Program Files\ABBYY PDF Transformer 1.0
[2009/03/03 15:09:40 | 00,000,000 | ---D | C] -- C:\DVR107D
[2009/03/03 15:08:08 | 00,000,000 | ---D | C] -- C:\DVR112D
[2009/03/03 15:00:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2009/03/03 15:00:31 | 00,000,000 | ---D | C] -- C:\Program Files\DivX
[2009/03/03 14:57:56 | 00,000,000 | ---D | C] -- C:\ProgramData\DVD Shrink
[2009/03/03 14:57:54 | 00,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
[2009/03/03 14:51:50 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\DVDFab
[2009/03/03 14:50:21 | 00,000,000 | ---D | C] -- C:\Program Files\DVDFab HD Decrypter 4
[2009/03/03 14:45:26 | 00,000,000 | ---D | C] -- C:\ProgramData\eXPert PDF 4
[2009/03/03 14:25:43 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\RagTime
[2009/03/03 14:25:33 | 00,000,000 | ---D | C] -- C:\Program Files\RagTime Solo
[2009/03/03 14:25:16 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2009/03/03 14:25:16 | 00,000,000 | RHS- | C] () -- C:\IO.SYS
[2009/03/03 14:14:34 | 00,001,501 | ---- | C] () -- C:\Windows\bizpub32.INI
[2009/03/03 14:14:31 | 00,565,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp50.DLL
[2009/03/03 14:14:31 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFC30.DLL
[2009/03/03 14:14:31 | 00,133,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFCANS32.DLL
[2009/03/03 14:14:31 | 00,027,025 | ---- | C] () -- C:\Windows\System32\OLE2.REG
[2009/03/03 14:14:31 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFCUIA32.DLL
[2009/03/03 14:14:30 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SVRAPI.DLL
[2009/03/03 14:13:57 | 00,000,000 | ---D | C] -- C:\Program Files\MySoftware
[2009/03/03 14:13:57 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\MySoftware
[2009/03/03 14:12:22 | 00,000,000 | ---D | C] -- C:\GRAPHPAP
[2009/03/03 14:11:37 | 00,014,336 | ---- | C] () -- C:\Windows\System32\vsmon1.dll
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\Windows\My Documents
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\ProgramData\eXPert PDF Jobs
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\ProgramData\eXPert PDF
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\Program Files\Visagesoft
[2009/03/03 14:07:31 | 00,000,000 | ---D | C] -- C:\Program Files\CartaGoGo
[2009/03/03 14:06:29 | 00,000,000 | ---D | C] -- C:\Program Files\Anagramme
[2009/03/03 14:06:24 | 00,253,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2009/03/03 14:06:23 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\ST6UNST.EXE
[2009/03/03 14:00:15 | 00,000,000 | ---D | C] -- C:\Program Files\AbiSuite2
[2009/03/03 13:56:57 | 00,000,000 | ---D | C] -- C:\Program Files\Micro Application
[2009/03/03 13:52:59 | 00,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2009/03/03 13:48:53 | 00,000,070 | ---- | C] () -- C:\Windows\divxhistory.ini
[2009/03/03 13:48:18 | 00,000,000 | ---- | C] () -- C:\Windows\WD.INI
[2009/03/03 13:48:10 | 00,000,000 | ---D | C] -- C:\DivxHistory
[2009/03/03 13:44:53 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\vlc
[2009/03/03 13:38:34 | 00,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2009/03/03 13:37:21 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Todae
[2009/03/03 13:26:52 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Winamp
[2009/03/03 13:26:52 | 00,000,000 | ---D | C] -- C:\Program Files\Winamp
[2009/03/03 13:20:47 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Sun
[2009/03/03 13:08:16 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\sTabLauncher
[2009/03/03 13:07:24 | 00,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2009/03/03 13:07:02 | 00,000,000 | ---D | C] -- C:\Program Files\VistaCodecPack
[2009/03/03 13:04:19 | 00,000,000 | ---D | C] -- C:\Windows\System32\URTTEMP
[2009/03/03 13:02:31 | 00,002,391 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\sTabLauncher.lnk
[2009/03/03 13:02:30 | 00,000,000 | ---D | C] -- C:\Program Files\sTabLauncher
[2009/03/03 12:32:33 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msadox.dll
[2009/03/03 12:32:33 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msado27.tlb
[2009/03/03 12:32:33 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msado20.tlb
[2009/03/03 12:32:33 | 00,024,626 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrrnfr.dll
[2009/03/03 12:32:32 | 01,287,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSXML5.DLL
[2009/03/03 12:32:32 | 00,647,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCOMCT2.OCX
[2009/03/03 12:32:32 | 00,608,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comctl32.ocx
[2009/03/03 12:32:32 | 00,155,136 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/03/03 12:32:32 | 00,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCFR.DLL
[2009/03/03 12:32:32 | 00,140,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMDLG32.OCX
[2009/03/03 12:32:32 | 00,119,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6FR.DLL
[2009/03/03 12:32:32 | 00,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMCTLFR.DLL
[2009/03/03 12:32:32 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCC2FR.DLL
[2009/03/03 12:32:32 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RCHTXFR.DLL
[2009/03/03 12:32:32 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMDLGFR.DLL
[2009/03/03 12:32:32 | 00,026,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\HH.EXE
[2009/03/03 12:32:32 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\stdftfr.dll
[2009/03/03 12:24:22 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/03/03 12:24:16 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Mozilla
[2009/03/03 12:24:16 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Mozilla
[2009/03/03 12:24:08 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/03/03 12:12:06 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\MetaProducts
[2009/03/03 12:12:06 | 00,000,000 | ---D | C] -- C:\Program Files\Download Express
[2009/03/02 21:14:24 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009/03/02 21:13:59 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2009/03/02 21:12:39 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2009/03/02 21:12:28 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2009/03/02 21:12:09 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2009/03/02 21:11:46 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2009/03/02 20:33:43 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Microsoft Games
[2009/03/02 20:02:48 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2009/03/02 19:21:52 | 00,004,608 | ---- | C] () -- C:\Users\claude\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/02 19:02:46 | 00,000,000 | -H-D | C] -- C:\Windows\Icons
[2009/03/02 18:16:42 | 00,000,000 | ---D | C] -- C:\Program Files\a-squared Free
[2009/03/02 17:58:54 | 00,603,904 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe
[2009/03/02 17:58:52 | 00,027,904 | ---- | C] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll
[2009/03/02 17:58:52 | 00,017,152 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2009/03/02 17:58:48 | 00,360,192 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TuneUpDefragService.exe
[2009/03/02 17:58:24 | 00,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2009
[2009/03/02 17:58:23 | 00,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2009/03/02 17:57:34 | 00,000,000 | -HSD | C] -- C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/03/02 16:38:57 | 00,774,144 | ---- | C] () -- C:\Windows\System32\NEROINSTAEC43759.DB
[2009/03/02 16:12:01 | 00,000,000 | ---D | C] -- C:\ProgramData\Bluetooth
[2009/03/02 16:06:52 | 00,000,000 | ---D | C] -- C:\Program Files\IVT Corporation
[2009/03/02 16:05:16 | 00,059,033 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\PH848.sys
[2009/03/02 16:05:16 | 00,058,841 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Pv848.sys
[2009/03/02 16:05:16 | 00,000,000 | ---D | C] -- C:\Program Files\Hercules
[2009/03/02 16:02:19 | 00,036,864 | ---- | C] (Agfa-Gevaert N.V.) -- C:\Windows\System32\agusbsti.dll
[2009/03/02 16:02:19 | 00,032,768 | ---- | C] () -- C:\Windows\System32\Snape20.bin
[2009/03/02 16:00:54 | 00,097,857 | ---- | C] (Silicon Image, Inc) -- C:\Windows\System32\drivers\SI3114r.sys
[2009/03/02 16:00:54 | 00,010,240 | ---- | C] (Silicon Image, Inc.) -- C:\Windows\System32\drivers\SiWinAcc.sys
[2009/03/02 15:53:52 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/03/02 15:53:52 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/03/02 15:44:14 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Macromedia
[2009/03/02 15:44:14 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Adobe
[2009/03/02 15:44:11 | 00,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2009/03/02 14:51:17 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Ahead
[2009/03/02 14:49:41 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Nero
[2009/03/02 14:46:28 | 00,000,000 | ---D | C] -- C:\ProgramData\Nero
[2009/03/02 14:46:28 | 00,000,000 | ---D | C] -- C:\Program Files\Nero
[2009/03/02 14:46:28 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2009/03/02 14:41:07 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2009/03/02 14:41:05 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2009/03/02 14:19:09 | 00,000,000 | ---D | C] -- C:\Program Files\Foxit Software
[2009/03/02 14:03:32 | 00,000,510 | ---- | C] () -- C:\Windows\tasks\Maintenance en 1 clic.job
[2009/03/02 14:03:26 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\TuneUp Software
[2009/03/02 13:00:13 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2009/03/02 12:59:23 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2009/03/02 12:59:22 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2009/03/02 12:57:54 | 00,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2009/03/02 12:57:54 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2009/03/02 12:54:05 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2009/03/02 12:52:18 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Microsoft Help
[2009/03/02 12:52:01 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2009/03/02 12:51:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2009/03/02 12:51:20 | 00,000,000 | RH-D | C] -- C:\MSOCache
[2009/03/02 12:43:25 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/03/02 12:36:30 | 00,000,000 | ---D | C] -- C:\Program Files\Soft4Ever
[2009/03/02 12:31:54 | 00,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2009/03/02 12:12:50 | 00,000,000 | ---- | C] () -- C:\Users\claude\AppData\Roaming\sversion.ini
[2009/03/02 12:08:17 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Sun
[2009/03/02 12:08:00 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/03/02 12:07:59 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2009/03/02 12:07:21 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2009/03/02 12:06:57 | 00,000,000 | ---D | C] -- C:\Program Files\StarOffice7
[2009/03/02 12:04:35 | 00,069,632 | ---- | C] () -- C:\Windows\uinst001.exe
[2009/03/02 11:59:02 | 00,000,000 | ---D | C] -- C:\Windows\System32\oodag
[2009/03/02 11:55:41 | 00,029,371 | ---- | C] () -- C:\Windows\System32\oodbs.lor
[2009/03/02 11:54:25 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/03/02 11:54:24 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/03/02 11:54:22 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/03/02 11:54:13 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/03/02 11:54:13 | 01,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFC71.dll
[2009/03/02 11:54:13 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCP71.dll
[2009/03/02 11:54:13 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/03/02 11:54:13 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCR71.dll
[2009/03/02 11:54:13 | 00,051,792 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/03/02 11:54:09 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/03/02 11:47:55 | 00,000,000 | ---- | C] () -- C:\Windows\OODCNT.INI
[2009/03/02 11:45:56 | 00,000,000 | ---D | C] -- C:\Program Files\OO Software
[2009/03/02 11:44:58 | 00,000,000 | -HSD | C] -- C:\Windows\Installer
[2009/03/02 11:35:16 | 00,000,000 | ---D | C] -- C:\Programme sans install
[2009/03/02 11:21:09 | 00,171,136 | RHS- | C] () -- C:\grldr
[2009/03/02 11:09:16 | 00,000,000 | ---D | C] -- C:\PerfLogs
[2009/03/02 10:54:01 | 00,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SPWizUI.dll
[2009/03/02 10:54:01 | 00,047,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SPReview.exe
[2009/03/02 10:44:48 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\recdisc.exe
[2009/03/02 10:44:47 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdspres.dll
[2009/03/02 10:44:29 | 00,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vsp1cln.exe
[2009/03/02 10:44:25 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sxproxy.dll
[2009/03/02 10:44:24 | 00,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spp.dll
[2009/03/02 10:44:05 | 01,696,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2009/03/02 10:44:05 | 01,400,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2009/03/02 10:44:05 | 00,647,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrepl40.dll
[2009/03/02 10:44:05 | 00,464,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msra.exe
[2009/03/02 10:44:05 | 00,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscp.dll
[2009/03/02 10:44:05 | 00,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrd3x40.dll
[2009/03/02 10:44:05 | 00,333,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2009/03/02 10:44:05 | 00,248,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
[2009/03/02 10:44:05 | 00,206,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstask.dll
[2009/03/02 10:44:05 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2009/03/02 10:44:05 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssha.dll
[2009/03/02 10:44:05 | 00,167,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2009/03/02 10:44:05 | 00,163,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\msrpc.sys
[2009/03/02 10:44:05 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrdc.dll
[2009/03/02 10:44:05 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
[2009/03/02 10:44:05 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssitlb.dll
[2009/03/02 10:44:05 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msstrc.dll
[2009/03/02 10:44:05 | 00,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2009/03/02 10:44:05 | 00,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssprxy.dll
[2009/03/02 10:44:05 | 00,031,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mssmbios.sys
[2009/03/02 10:44:05 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscb.dll
[2009/03/02 10:44:05 | 00,006,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mstee.sys
[2009/03/02 10:44:05 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mspqm.sys
[2009/03/02 10:44:04 | 02,061,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstscax.dll
[2009/03/02 10:44:04 | 01,386,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvbvm60.dll
[2009/03/02 10:44:04 | 01,332,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml6.dll
[2009/03/02 10:44:04 | 01,190,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3.dll
[2009/03/02 10:44:04 | 00,680,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcrt.dll
[2009/03/02 10:44:04 | 00,677,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstsc.exe
[2009/03/02 10:44:04 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009/03/02 10:44:04 | 00,450,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxbde40.dll
[2009/03/02 10:44:04 | 00,307,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxclu.dll
[2009/03/02 10:44:04 | 00,282,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstext40.dll
[2009/03/02 10:44:04 | 00,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mycomput.dll
[2009/03/02 10:44:04 | 00,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mswsock.dll
[2009/03/02 10:44:04 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mystify.scr
[2009/03/02 10:44:04 | 00,210,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll
[2009/03/02 10:44:04 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msutb.dll
[2009/03/02 10:44:04 | 00,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPMONTR.DLL
[2009/03/02 10:44:04 | 00,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mydocs.dll
[2009/03/02 10:44:04 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtstocom.exe
[2009/03/02 10:44:04 | 00,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvfw32.dll
[2009/03/02 10:44:04 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxoci.dll
[2009/03/02 10:44:04 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPHLPR.DLL
[2009/03/02 10:44:04 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstlsapi.dll
[2009/03/02 10:44:04 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\napdsnap.dll
[2009/03/02 10:44:04 | 00,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MuiUnattend.exe
[2009/03/02 10:44:04 | 00,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NapiNSP.dll
[2009/03/02 10:44:04 | 00,049,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mup.sys
[2009/03/02 10:44:04 | 00,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NAPCRYPT.DLL
[2009/03/02 10:44:04 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\napipsec.dll
[2009/03/02 10:44:04 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxlegih.dll
[2009/03/02 10:44:04 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mtxdm.dll
[2009/03/02 10:44:04 | 00,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mspclock.sys
[2009/03/02 10:44:03 | 01,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVidCtl.dll
[2009/03/02 10:44:03 | 01,052,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtctm.dll
[2009/03/02 10:44:03 | 00,564,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll
[2009/03/02 10:44:03 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009/03/02 10:44:03 | 00,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msexcl40.dll
[2009/03/02 10:44:03 | 00,312,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mswmdm.dll
[2009/03/02 10:44:03 | 00,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcuiu.dll
[2009/03/02 10:44:03 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2009/03/02 10:44:03 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvidc32.dll
[2009/03/02 10:44:03 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\msfs.sys
[2009/03/02 10:44:03 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcVSp1res.dll
[2009/03/02 10:44:03 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2009/03/02 10:44:03 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
[2009/03/02 10:44:01 | 03,578,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009/03/02 10:44:01 | 00,557,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtcprx.dll
[2009/03/02 10:44:01 | 00,506,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2ENC.DLL
[2009/03/02 10:44:01 | 00,476,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmled.dll
[2009/03/02 10:44:01 | 00,415,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2009/03/02 10:44:01 | 00,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2ADEC.DLL
[2009/03/02 10:44:01 | 00,344,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtckrm.dll
[2009/03/02 10:44:01 | 00,329,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdrm.dll
[2009/03/02 10:44:01 | 00,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdelta.dll
[2009/03/02 10:44:01 | 00,299,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjtes40.dll
[2009/03/02 10:44:01 | 00,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdt.dll
[2009/03/02 10:44:01 | 00,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdt.exe
[2009/03/02 10:44:01 | 00,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdadiag.dll
[2009/03/02 10:44:01 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdart.dll
[2009/03/02 10:44:01 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtc.exe
[2009/03/02 10:44:01 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdtclog.dll
[2009/03/02 10:44:01 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msctfui.dll
[2009/03/02 10:44:01 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshta.exe
[2009/03/02 10:44:01 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdmo.dll
[2009/03/02 10:44:01 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msg.exe
[2009/03/02 10:44:01 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsCtfMonitor.dll
[2009/03/02 10:44:01 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msmmsp.dll
[2009/03/02 10:44:01 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\mskssrv.sys
[2009/03/02 10:44:01 | 00,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf
[2009/03/02 10:44:00 | 02,085,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msi.dll
[2009/03/02 10:44:00 | 00,588,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSMPEG2VDEC.DLL
[2009/03/02 10:44:00 | 00,485,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspaint.exe
[2009/03/02 10:44:00 | 00,475,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msidcrl30.dll
[2009/03/02 10:44:00 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspbde40.dll
[2009/03/02 10:44:00 | 00,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll
[2009/03/02 10:44:00 | 00,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msieftp.dll
[2009/03/02 10:44:00 | 00,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msltus40.dll
[2009/03/02 10:44:00 | 00,205,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msoeacct.dll
[2009/03/02 10:44:00 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msorcl32.dll
[2009/03/02 10:44:00 | 00,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msnetobj.dll
[2009/03/02 10:44:00 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2009/03/02 10:44:00 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msoert2.dll
[2009/03/02 10:44:00 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2009/03/02 10:44:00 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msiexec.exe
[2009/03/02 10:44:00 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msobjs.dll
[2009/03/02 10:44:00 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msident.dll
[2009/03/02 10:44:00 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mspatcha.dll
[2009/03/02 10:44:00 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msidle.dll
[2009/03/02 10:43:59 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0047.dll
[2009/03/02 10:43:59 | 03,104,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\NlsData0046.dll
[2009/03/02 10:43:59 | 01,589,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msjet40.dll
[2009/03/02 10:43:59 | 00,408,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msinfo32.exe
[2009/03/02 10:43:59 | 00,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll
[2009/03/02 10:43:59 | 00,181,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\msiscsi.sys
[2009/03/02 10:43:59 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msimtf.dll
[2009/03/02 10:43:59 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msisip.dll
[2009/03/02 10:43:59 | 00,016,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\msisadrv.sys
[2009/03/02 10:43:58 | 04,495,360 | ---- | C] (Microso
claude0207
 
Messages: 49
Inscription: 23 Juil 2007, 08:00
Localisation: Huy - Belgique

dll mystérieuse

Messagede claude0207 » 05 Mar 2009, 10:08

OTListIt Extras logfile created on: 5/03/2009 10:00:26 - Run 7
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\claude\Desktop
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 0000080c | Country: Belgique | Language: FRB | Date Format: d/MM/yyyy

2,00 Gb Total Physical Memory | 1,12 Gb Available Physical Memory | 56,07% Memory free
4,00 Gb Paging File | 3,29 Gb Available in Paging File | 82,24% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 29,30 Gb Total Space | 13,01 Gb Free Space | 44,42% Space Free | Partition Type: NTFS
Drive D: | 47,04 Gb Total Space | 32,49 Gb Free Space | 69,08% Space Free | Partition Type: NTFS
Drive E: | 76,33 Gb Total Space | 29,10 Gb Free Space | 38,13% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC-DE-CLAUDE
Current User Name: claude
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1232965312-3791907715-587907267-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A722192-4AEA-4911-9F71-EBECEDC970B5}" = Newsflash
"{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}" = Cool & Quiet
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live
"{22101996-62AE-4369-8CEF-581A12221033}" = Nero 8
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{462E5968-A02C-4C0A-9F74-1C4DA758CD80}" = sTabLauncher
"{4837718C-5B6E-4496-B283-FFFB5A937825}" = ABBYY PDF Transformer 1.0
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{53480330-E1D1-41CA-B8F8-7F78644F7F50}" = O&O Defrag Professional Edition
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{63DC2DA0-2A6C-4C38-9249-B75395458657}" = Windows Live Mail
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A2079AB-8C05-4258-BFC9-B72D0D3D9E37}" = Holiday & Events Designer
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{720E749E-2449-406B-B0E7-9EBCEFDBAC37}" = Hercules Smart TV Drivers
"{7370DF47-B4F9-4279-BFC3-3F09919F720D}" = Installation Windows Live
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E9D738A-2C30-4574-90FE-E6B4F6065D48}" = Bluesoleil3.2.2.8 Release 070421
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-040C-0000-0000000FF1CE}" = Microsoft Office Access MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007
"{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007
"{90120000-0019-040C-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (French) 2007
"{90120000-001A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007
"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007
"{90120000-0044-040C-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 3.81
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{A6E92CAB-9E63-46DC-8ABF-0CAFF7B7CD02}" = eXPert PDF 4
"{B056DB05-BF39-49A0-AAB8-C8FA49D9660C}" = Micro Application - PrintPratic 3
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BB6694FB-30D9-42A8-A15E-019F127EE494}" = Wireless-G PCI Adapter
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}" = Assistant de connexion Windows Live
"{F7D27C70-90F5-49B9-B188-0A133C0CE353}" = Windows Live Toolbar
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"AbiWord2" = AbiWord 2.6.3
"AbiwordToolsPlugins" = AbiWord Tools Plugins
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"aMSN" = aMSN 0.97.2
"a-squared Free_is1" = a-squared Free 4.0
"avast!" = avast! Antivirus
"CartaGoGo v3.1.8_is1" = CartaGoGo v3.1.8
"CCleaner" = CCleaner (remove only)
"DMX4_is1" = DriverMax 4
"DownloadExpress" = MetaProducts Download Express
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab HD Decrypter 4_is1" = DVDFab HD Decrypter 4.0.5.0
"EncVorbis" = EncVorbis 1.1
"Foxit Reader" = Foxit Reader
"IrfanView" = IrfanView (remove only)
"Live Media" = Todae - Live Media
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"NeoTrace Pro 3.25" = NeoTrace Pro 3.25
"NVIDIA Drivers" = NVIDIA Drivers
"PROPLUS" = Microsoft Office Professional Plus 2007
"RagTime Solo" = RagTime Solo
"Revo Uninstaller" = Revo Uninstaller 1.34
"RivaTuner" = RivaTuner v2.06
"ST6UNST #1" = Anagramme
"Trillian" = Trillian
"VLC media player" = VideoLAN VLC media player 0.8.6c
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Installation Windows Live
"ZGuideTV_is1" = ZGuideTV 1.0.0.6
"ZoneAlarm" = ZoneAlarm

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DivxHistory" = DivxHistory
"uTorrent" = µTorrent

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DivxHistory" = DivxHistory
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/03/2009 14:44:28 | Computer Name = PC-de-claude | Source = SideBySide | ID = 16842785
Description = La création du contexte d’activation a échoué pour « C:\Program Files\PC
Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.DirectX.dll ».
Assembly
dépendant Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé.

Error - 4/03/2009 14:44:28 | Computer Name = PC-de-claude | Source = SideBySide | ID = 16842785
Description = La création du contexte d’activation a échoué pour « C:\Program Files\PC
Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.DirectX.dll ».
Assembly
dépendant Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé.

Error - 4/03/2009 14:44:29 | Computer Name = PC-de-claude | Source = SideBySide | ID = 16842785
Description = La création du contexte d’activation a échoué pour « C:\Program Files\PC
Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.DirectX.dll ».
Assembly
dépendant Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé.

Error - 4/03/2009 15:35:34 | Computer Name = PC-de-claude | Source = Application Error | ID = 1000
Description = Application défaillante ZGuideTV.exe, version 2.1.0.129, horodatage
0x482317cd, module défaillant unknown, version 0.0.0.0, horodatage 0x00000000,
code d’exception 0xc0000005, décalage d’erreur 0x0075c528, ID du processus 0x5a8,
heure de début de l’application 0x01c99cfe974c0f97.

Error - 4/03/2009 17:19:19 | Computer Name = PC-de-claude | Source = VSS | ID = 13
Description =

Error - 4/03/2009 17:19:19 | Computer Name = PC-de-claude | Source = VSS | ID = 12289
Description =

Error - 4/03/2009 17:19:19 | Computer Name = PC-de-claude | Source = VSS | ID = 13
Description =

Error - 4/03/2009 17:19:19 | Computer Name = PC-de-claude | Source = VSS | ID = 12289
Description =

Error - 4/03/2009 17:19:19 | Computer Name = PC-de-claude | Source = VSS | ID = 13
Description =

Error - 4/03/2009 17:19:19 | Computer Name = PC-de-claude | Source = VSS | ID = 12289
Description =

[ System Events ]
Error - 4/03/2009 4:54:24 | Computer Name = PC-de-claude | Source = Microsoft-Windows-Servicing | ID = 4385
Description =

Error - 4/03/2009 4:54:24 | Computer Name = PC-de-claude | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 4/03/2009 4:54:24 | Computer Name = PC-de-claude | Source = Microsoft-Windows-Servicing | ID = 4385
Description =

Error - 4/03/2009 4:54:24 | Computer Name = PC-de-claude | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 4/03/2009 4:54:24 | Computer Name = PC-de-claude | Source = Microsoft-Windows-Servicing | ID = 4385
Description =

Error - 4/03/2009 10:16:52 | Computer Name = PC-de-claude | Source = bowser | ID = 8003
Description =

Error - 4/03/2009 11:09:21 | Computer Name = PC-de-claude | Source = netbt | ID = 4321
Description = Le nom "WORKGROUP :1d" n'a pas pu être enregistré sur l'interface
avec l'adresse IP 192.168.1.16. L'ordinateur avec l'adresse IP 192.168.1.17 n'a
pas permis que le nom soit réclamé par cet ordinateur.

Error - 4/03/2009 17:02:23 | Computer Name = PC-de-claude | Source = HTTP | ID = 15016
Description =

Error - 4/03/2009 17:02:38 | Computer Name = PC-de-claude | Source = Server | ID = 2505
Description = Le serveur n'a pas pu se lier au transport \Device\NetBT_Tcpip_{5690F6C2-F763-4391-9209-0212E03B2722}
car un autre ordinateur du réseau porte le même nom. Le serveur n'a pas pu démarrer.

Error - 5/03/2009 3:24:22 | Computer Name = PC-de-claude | Source = HTTP | ID = 15016
Description =


<End>
claude0207
 
Messages: 49
Inscription: 23 Juil 2007, 08:00
Localisation: Huy - Belgique

dll mystérieuse

Messagede claude0207 » 05 Mar 2009, 10:20

Merci pour la rapidité de ta réponse.

je soulève encore deux points:

- Il m'a semblé avoir vu sur l'icône de la dll le logo de msn live (avant que je la désinstalle une première fois)
j'ai bien sûr désinstallé depuis msn live au profit de aMSN

- Avast détecte la dll comme: urqNDUIM.dll = win32: agent - zgk (trj)

merci
claude0207
 
Messages: 49
Inscription: 23 Juil 2007, 08:00
Localisation: Huy - Belgique

Messagede nickW » 05 Mar 2009, 11:40

Re-Bonjour,


Le log OTListIt.Txt est incomplet.

Peux-tu envoyer en réponse:

1/ ce que contient le paragraphe
========== Files - Modified Within 30 Days ==========
en supprimant toutes les lignes relatives à l'installation du système, c'est-à-dire celles qui sont antérieures à 2009/03/02 10:54:01 (les lignes sont classées en ordre chronologique).

2/ le reste du log (fin du log).


Ceci fait, effectuer une autre recherche:

Étape 1: Malwarebytes' Anti-Malware, installation
Télécharger Malwarebytes' Anti-Malware depuis l'un des liens ci-dessous:
http://www.besttechie.net/tools/mbam-setup.exe
http://www.malwarebytes.org/mbam/program/mbam-setup.exe

Enregistrer ce fichier sur le Bureau.
Faire un double clic sur mbam-setup.exe pour lancer l'installation (Accepter le contrat de licence, puis valider les options par défaut).
Sur le dernier écran de la procédure d'installation, cocher la case située devant "Mettre à jour Malwarebytes' Anti-Malware", puis cliquer sur le bouton "Terminer".


Étape 2: Pas de processus de contrôle en temps réel
Désactiver le module résident de l'antivirus et celui de l'antispyware.
Image avast!: clic droit sur l'icône dans la SysBarre (à coté de l'horloge), puis "Arrêter la protection résidente"
Image Windows Defender: Démarrer---->Tous les programmes---->Windows Defender; cliquer sur "Outils", puis sur "Options"; Sous "Options de protection en temps réel", désactiver la case à cocher "Utiliser la protection en temps réel (recommandé)", puis cliquer sur "Enregistrer"


Étape 3: Malwarebytes' Anti-Malware, recherche
Fermer toutes les fenêtres de programme ouvertes.
Lancer Malwarebytes' Anti-Malware via le Menu Démarrer.
Dans l'onglet Paramètres, vérifier que toutes les cases sont cochées sauf "Créer une option dans le menu contextuel pour analyser des fichiers (clic droit)".
Dans l'onglet Mise à jour, cliquer sur le bouton Recherche de mise à jour et installer toutes les mises à jour trouvées.
Dans l'onglet Recherche, cocher le bouton radio situé devant "Exécuter un examen rapide" puis cliquer sur le bouton Rechercher.
Attendre sans rien faire d'autre la fin de la recherche; dans la fenêtre annonçant la fin de l'analyse, cliquer sur OK; puis cliquer sur le bouton "Afficher les résultats".

Cliquer sur le bouton "Enregistrer le rapport", valider la sauvegarde, puis cliquer sur le bouton "Quitter"


Étape 4: Processus de contrôle en temps réel
Important: Réactiver le module résident de l'antivirus et celui de l'antispyware.


Étape 5: Résultats
Envoyer en réponse:
*- le log de Malwarebytes' Anti-Malware (contenu du fichier mbam-log-*-**-**** (**-**-**).txt situé dans le dossier SystemDrive\Documents and Settings\<tonprofil>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs / *-**-**** (**-**-**) représente la date [mois-jour-année] et l'heure [hh-mn-ss])
[SystemDrive représente la partition sur laquelle est installé le système, généralement C:]


A suivre,
nickW - Image
30/07/2012: Plus de désinfection de PC jusqu'à nouvel ordre.
Pas de demande d'analyse de log en MP (Message Privé)
Mes configs
Avatar de l’utilisateur
nickW
Modérateur
 
Messages: 21698
Inscription: 20 Mai 2004, 17:41
Localisation: Dordogne/Île de France

Messagede claude0207 » 05 Mar 2009, 11:55

OTListIt logfile created on: 5/03/2009 10:00:26 - Run 7
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\claude\Desktop
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 0000080c | Country: Belgique | Language: FRB | Date Format: d/MM/yyyy

2,00 Gb Total Physical Memory | 1,12 Gb Available Physical Memory | 56,07% Memory free
4,00 Gb Paging File | 3,29 Gb Available in Paging File | 82,24% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 29,30 Gb Total Space | 13,01 Gb Free Space | 44,42% Space Free | Partition Type: NTFS
Drive D: | 47,04 Gb Total Space | 32,49 Gb Free Space | 69,08% Space Free | Partition Type: NTFS
Drive E: | 76,33 Gb Total Space | 29,10 Gb Free Space | 38,13% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC-DE-CLAUDE
Current User Name: claude
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/03/03 15:05:02 | 00,079,400 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe
PRC - [2009/02/05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/02/25 19:18:14 | 00,425,080 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe
PRC - [2007/06/28 23:02:08 | 01,049,856 | ---- | M] (O&O Software GmbH) -- C:\Windows\system32\oodag.exe
PRC - [2009/01/14 17:53:02 | 00,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/03/02 17:58:54 | 00,603,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe
PRC - [2009/02/05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2008/01/18 23:33:12 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2008/01/18 23:38:40 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2004/06/18 09:31:02 | 00,067,584 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SOUNDMAN.EXE
PRC - [2007/06/28 23:01:00 | 02,512,128 | ---- | M] (O&O Software GmbH) -- C:\Windows\System32\oodtray.exe
PRC - [2009/02/05 22:08:45 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2007/10/10 06:28:32 | 00,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2006/05/04 06:58:56 | 00,998,912 | ---- | M] () -- C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe
PRC - [2008/03/03 15:05:04 | 00,959,976 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2007/02/09 15:48:00 | 00,516,096 | ---- | M] (Sergio Santos) -- C:\Program Files\sTabLauncher\sTabLauncher.exe
PRC - [2008/04/01 10:39:48 | 00,486,856 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe
PRC - [2003/02/06 16:47:12 | 00,053,248 | ---- | M] (RagTime GmbH) -- C:\Program Files\RagTime Solo\Konni\KonniSymbol.exe
PRC - [2009/02/10 13:42:56 | 05,391,192 | ---- | M] (Innovative Solutions) -- C:\Program Files\Innovative Solutions\DriverMax\devices.exe
PRC - [2008/01/18 23:33:12 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/01/18 23:33:40 | 00,245,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wbem\wmiprvse.exe
PRC - [2009/03/05 09:38:55 | 00,498,176 | ---- | M] (OldTimer Tools) -- C:\Users\claude\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/02/25 19:18:14 | 00,425,080 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe -- (a2free [Auto | Running])
SRV - [2008/01/05 03:25:58 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009/02/05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/01/05 03:26:42 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/01/18 23:33:10 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 13:34:14 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 13:34:14 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2008/01/05 03:21:54 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/01/05 03:21:40 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/01/05 03:21:40 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/02/28 18:07:48 | 00,529,704 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2007/06/28 23:02:08 | 01,049,856 | ---- | M] (O&O Software GmbH) -- C:\Windows\system32\oodag.exe -- (O&O Defrag [Auto | Running])
SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2009/01/14 17:53:02 | 00,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort [Auto | Running])
SRV - [2007/04/21 14:54:10 | 00,052,080 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe -- (Start BT in service [On_Demand | Stopped])
SRV - [2009/03/02 17:58:48 | 00,360,192 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag [On_Demand | Stopped])
SRV - [2009/03/02 17:58:54 | 00,603,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc [Auto | Running])
SRV - [2008/12/11 13:31:36 | 00,027,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp [Auto | Running])
SRV - [2008/03/03 15:05:02 | 00,079,400 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
SRV - [2008/01/18 23:38:26 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2008/01/18 23:33:40 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2006/11/02 10:51:38 | 00,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 10:51:32 | 00,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 10:51:00 | 00,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 10:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])
DRV - [2004/02/24 04:08:52 | 00,400,384 | ---- | M] (Sensaura) -- C:\Windows\system32\drivers\ALCXSENS.SYS -- (ALCXSENS [On_Demand | Running])
DRV - [2004/06/21 09:53:20 | 00,626,204 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2006/11/02 10:49:20 | 00,014,952 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\system32\drivers\aliide.sys -- (aliide [Disabled | Stopped])
DRV - [2006/11/02 10:50:09 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arc.sys -- (arc [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])
DRV - [2009/02/05 22:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\Windows\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 22:06:59 | 00,051,792 | ---- | M] (ALWIL Software) -- C:\Windows\system32\DRIVERS\aswMonFlt.sys -- (aswMonFlt [Auto | Running])
DRV - [2009/02/05 22:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr [System | Running])
DRV - [2009/02/05 22:07:23 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 22:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2006/11/02 08:30:53 | 00,464,384 | ---- | M] (Broadcom Corporation) -- C:\Windows\system32\DRIVERS\bcmwl6.sys -- (BCM43XV [On_Demand | Running])
DRV - [2007/03/05 05:51:24 | 00,034,576 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\blueletaudio.sys -- (BlueletAudio [On_Demand | Running])
DRV - [2007/03/05 06:00:04 | 00,027,792 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio [On_Demand | Running])
DRV - [2006/11/02 09:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 09:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 09:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserid.sys -- (Brserid [Disabled | Stopped])
DRV - [2006/11/02 09:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 09:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 09:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer [On_Demand | Stopped])
DRV - [2007/03/05 05:59:04 | 00,018,320 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\btnetdrv.sys -- (BT [On_Demand | Running])
DRV - [2002/07/16 20:59:28 | 00,085,231 | ---- | M] (iuLab software) -- C:\Windows\system32\drivers\BT848.sys -- (BT848 [Auto | Running])
DRV - [2007/03/05 06:01:18 | 00,039,184 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\btcusb.sys -- (Btcsrusb [On_Demand | Running])
DRV - [2007/03/05 05:55:12 | 00,020,880 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\vbtenum.sys -- (BTHidEnum [Boot | Running])
DRV - [2007/03/05 05:56:18 | 00,035,600 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\BTHidMgr.sys -- (BTHidMgr [Boot | Running])
DRV - [2001/10/08 21:12:18 | 00,009,187 | ---- | M] (iuLab software, Conexant Systems, Inc.) -- C:\Windows\system32\drivers\BTTUNER.sys -- (BTTUNER [Auto | Running])
DRV - [2001/10/08 21:12:18 | 00,008,193 | ---- | M] (iuLab software, Conexant Systems, Inc.) -- C:\Windows\system32\drivers\BTXBAR.sys -- (BTXBAR [Auto | Running])
DRV - [2006/11/02 10:49:28 | 00,016,488 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])
DRV - [2006/11/02 08:30:54 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\Windows\system32\DRIVERS\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])
DRV - [2006/11/02 10:51:34 | 00,316,520 | ---- | M] (Emulex) -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,037,480 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs [Disabled | Stopped])
DRV - [2006/11/02 10:51:25 | 00,232,040 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV [Disabled | Stopped])
DRV - [2006/11/02 10:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])
DRV - [2006/11/02 10:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 10:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])
DRV - [2006/11/02 10:50:04 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 10:50:05 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 10:50:10 | 00,065,640 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
DRV - [2006/11/02 10:49:53 | 00,028,776 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\megasas.sys -- (megasas [Disabled | Stopped])
DRV - [2006/11/02 10:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 10:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 08:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])
DRV - [2006/11/02 08:30:56 | 00,429,056 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\DRIVERS\nvm60x32.sys -- (NVENETFD [On_Demand | Running])
DRV - [2007/12/11 17:06:00 | 08,238,688 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\DRIVERS\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])
DRV - [2006/11/02 10:50:24 | 00,088,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])
DRV - [2006/11/02 10:50:13 | 00,040,040 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor [Disabled | Stopped])
DRV - [2009/03/02 03:02:24 | 00,240,128 | ---- | M] (PARADOX) -- C:\Windows\System32\drivers\royal.sys -- (OemBiosDevice [Boot | Stopped])
DRV - [2004/03/17 19:29:50 | 00,058,841 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\drivers\Pv848.sys -- (Pv848 [Auto | Running])
DRV - [2004/04/27 05:58:04 | 00,017,691 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\system32\drivers\PHTUNER.sys -- (PVTUNER [Auto | Running])
DRV - [2004/02/26 09:36:58 | 00,006,841 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\system32\drivers\PvXBAR.sys -- (PVXBAR [Auto | Running])
DRV - [2006/11/02 10:51:45 | 00,900,712 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])
DRV - [2007/10/30 19:05:00 | 00,009,088 | ---- | M] () -- C:\Program Files\RivaTuner v2.06\RivaTuner32.sys -- (RivaTuner32 [On_Demand | Running])
DRV - [2008/01/18 21:57:16 | 00,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Running])
DRV - [2006/11/02 07:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])
DRV - [2004/02/09 08:27:04 | 00,097,857 | ---- | M] (Silicon Image, Inc) -- C:\Windows\system32\DRIVERS\SI3114R.sys -- (SI3114r [Boot | Running])
DRV - [2003/10/15 03:28:16 | 00,010,240 | ---- | M] (Silicon Image, Inc.) -- C:\Windows\system32\DRIVERS\SiWinAcc.sys -- (SiFilter [Boot | Running])
DRV - [2006/11/02 10:50:10 | 00,038,504 | ---- | M] (Silicon Integrated Systems Corp.) -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 10:50:16 | 00,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
DRV - [2009/03/03 15:20:53 | 00,717,296 | ---- | M] () -- C:\Windows\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006/11/02 10:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 10:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 10:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 10:51:25 | 00,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])
DRV - [2006/11/02 10:50:45 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
DRV - [2007/03/05 05:52:18 | 00,034,448 | ---- | M] (IVT Corporation.) -- C:\Windows\system32\DRIVERS\VComm.sys -- (VComm [On_Demand | Running])
DRV - [2007/03/05 05:53:18 | 00,044,304 | ---- | M] (IVT Corporation.) -- C:\Windows\System32\Drivers\VcommMgr.sys -- (VcommMgr [On_Demand | Running])
DRV - [2006/11/02 10:49:30 | 00,017,512 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\system32\drivers\viaide.sys -- (viaide [Disabled | Stopped])
DRV - [2008/03/03 15:06:04 | 00,279,440 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\system32\DRIVERS\vsdatant.sys -- (Vsdatant [System | Running])
DRV - [2006/11/02 10:50:41 | 00,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/intl/fr/
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\S-1-5-21-1232965312-3791907715-587907267-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - presf.js..browser.search.defaulturl: "http://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.be/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6
FF - prefs.js..browser.search.defaultenginename: "chrome://browser-region/locale/region.properties"
FF - prefs.js..browser.startup.homepage: "http://www.google.be/intl/fr/"
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/03 12:24:21 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/03 15:30:20 00,000,000 | ---D | M]
FF - C:\Users\claude\AppData\Roaming\mozilla\Extensions [2009/03/03 12:24:22 00,000,000 | ---D | M]
FF - C:\Users\claude\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/03/03 12:24:22 00,000,000 | ---D | M]
FF - C:\Users\claude\AppData\Roaming\mozilla\Firefox\Profiles\7s5sy1kp.default\extensions [2009/03/03 20:04:14 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions [2009/03/04 13:36:42 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/03 12:24:10 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [2009/03/03 13:23:10 00,000,000 | ---D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/03/03 14:53:58 00,000,000 | ---D | M]

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe File not found
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart (NVIDIA Corporation)
O4 - HKLM..\Run: [OODefragTray] C:\Windows\system32\oodtray.exe (O&O Software GmbH)
O4 - HKLM..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S ()
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF\vspdfprsrv.exe --background ()
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" ()
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent (Innovative Solutions)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [Konni Symbol Autostart] "C:\Program Files\RagTime Solo\Konni\KonniSymbol.exe" (RagTime GmbH)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [MSServer] rundll32.exe C:\Users\claude\AppData\Local\Temp\urqNDUlM.dll,#1 ()
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKU\S-1-5-21-1232965312-3791907715-587907267-1000..\Run: [sTabLauncher] C:\Program Files\sTabLauncher\sTabLauncher.exe (Sergio Santos)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programmes\Microsoft Office\Office12\REFIEBAR.DLL File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Programmes\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{c7133eca-06ca-11de-88a1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c7133eca-06ca-11de-88a1-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Bin\Assetup.exe -- File not found
O33 - MountPoints2\{f9ef825d-082c-11de-a05b-00030d000001}\Shell - "" = AutoRun
O33 - MountPoints2\{f9ef825d-082c-11de-a05b-00030d000001}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -- File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/03/05 09:38:08 | 00,498,176 | ---- | C] (OldTimer Tools) -- C:\Users\claude\Desktop\OTListIt2.exe
[2009/03/04 22:17:08 | 00,005,358 | ---- | C] () -- D:\claude Taillard\Documents\cc_20090304_2217.reg
[2009/03/04 22:07:23 | 00,000,000 | ---D | C] -- C:\Program Files\RivaTuner v2.06
[2009/03/04 21:26:12 | 00,000,000 | ---D | C] -- C:\Program Files\NeoTracePro
[2009/03/04 21:01:59 | 00,114,688 | ---- | C] (vbAccelerator) -- C:\Windows\System32\cTreeOpt6.ocx
[2009/03/04 21:01:57 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6STKIT.DLL
[2009/03/04 21:01:55 | 00,000,000 | ---D | C] -- C:\Program Files\ZGuideTV
[2009/03/04 19:49:26 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/03/04 19:44:06 | 00,000,000 | ---D | C] -- C:\ProgramData\PC Drivers HeadQuarters
[2009/03/04 19:44:04 | 00,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters
[2009/03/04 19:43:30 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Downloaded Installations
[2009/03/04 15:36:06 | 00,000,000 | ---D | C] -- D:\claude Taillard\Documents\My Drivers
[2009/03/04 15:36:06 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Innovative Solutions
[2009/03/04 15:32:33 | 00,000,000 | ---D | C] -- C:\Program Files\Innovative Solutions
[2009/03/04 15:02:03 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\DivX
[2009/03/04 15:02:02 | 00,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009/03/04 13:39:07 | 00,012,791 | ---- | C] () -- D:\claude Taillard\Documents\Dis-moi... Le silence fait si mal....docx
[2009/03/04 13:29:57 | 00,011,310 | ---- | C] () -- D:\claude Taillard\Documents\Penser à quelqu.docx
[2009/03/04 13:15:07 | 00,010,845 | ---- | C] () -- D:\claude Taillard\Documents\Tu vas partir pour retrouver John et toi seule sais ce qui se passera.docx
[2009/03/04 09:53:38 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuaueng.dll
[2009/03/04 09:53:38 | 01,524,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2009/03/04 09:53:38 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuauclt.exe
[2009/03/04 09:53:38 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2009/03/04 09:53:25 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2009/03/04 09:53:25 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2009/03/04 09:53:25 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2009/03/04 09:53:15 | 00,162,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2009/03/04 09:53:15 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2009/03/03 23:00:44 | 00,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2009/03/03 23:00:42 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\uTorrent
[2009/03/03 22:14:23 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\U3
[2009/03/03 21:57:00 | 00,000,000 | ---D | C] -- C:\Program Files\DreamMail4
[2009/03/03 21:34:18 | 00,000,000 | ---D | C] -- C:\Windows\Sun
[2009/03/03 19:56:58 | 00,008,314 | ---- | C] () -- C:\Windows\System32\BIN_STRSBW.SPT
[2009/03/03 18:57:36 | 00,000,000 | ---D | C] -- C:\Program Files\aMSN
[2009/03/03 18:34:37 | 00,024,576 | ---- | C] () -- C:\Users\claude\Desktop\urqNDUlM.dll
[2009/03/03 15:55:30 | 00,005,571 | ---- | C] () -- C:\Windows\System32\vsconfig.xml
[2009/03/03 15:55:29 | 00,054,672 | ---- | C] (Zone Labs Inc.) -- C:\Windows\System32\vsutil_loc040c.dll
[2009/03/03 15:55:16 | 01,086,952 | ---- | C] (Python Software Foundation) -- C:\Windows\System32\zpeng24.dll
[2009/03/03 15:55:15 | 00,000,000 | ---D | C] -- C:\Program Files\Zone Labs
[2009/03/03 15:55:14 | 00,000,000 | ---D | C] -- C:\ProgramData\CheckPoint
[2009/03/03 15:54:33 | 00,352,615 | -H-- | C] () -- C:\Windows\System32\drivers\vsconfig.xml
[2009/03/03 15:54:33 | 00,000,000 | ---D | C] -- C:\Windows\System32\ZoneLabs
[2009/03/03 15:53:49 | 00,000,000 | ---D | C] -- C:\Windows\Internet Logs
[2009/03/03 15:37:32 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/03/03 15:36:26 | 00,016,318 | ---- | C] () -- D:\claude Taillard\Documents\cc_20090303_1536.reg
[2009/03/03 15:26:35 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2009/03/03 15:20:53 | 00,717,296 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/03/03 15:20:44 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\DAEMON Tools
[2009/03/03 15:15:14 | 00,000,000 | ---D | C] -- C:\Program Files\ABBYY PDF Transformer 1.0
[2009/03/03 15:09:40 | 00,000,000 | ---D | C] -- C:\DVR107D
[2009/03/03 15:08:08 | 00,000,000 | ---D | C] -- C:\DVR112D
[2009/03/03 15:00:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2009/03/03 15:00:31 | 00,000,000 | ---D | C] -- C:\Program Files\DivX
[2009/03/03 14:57:56 | 00,000,000 | ---D | C] -- C:\ProgramData\DVD Shrink
[2009/03/03 14:57:54 | 00,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
[2009/03/03 14:51:50 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\DVDFab
[2009/03/03 14:50:21 | 00,000,000 | ---D | C] -- C:\Program Files\DVDFab HD Decrypter 4
[2009/03/03 14:45:26 | 00,000,000 | ---D | C] -- C:\ProgramData\eXPert PDF 4
[2009/03/03 14:25:43 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\RagTime
[2009/03/03 14:25:33 | 00,000,000 | ---D | C] -- C:\Program Files\RagTime Solo
[2009/03/03 14:25:16 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2009/03/03 14:25:16 | 00,000,000 | RHS- | C] () -- C:\IO.SYS
[2009/03/03 14:14:34 | 00,001,501 | ---- | C] () -- C:\Windows\bizpub32.INI
[2009/03/03 14:14:31 | 00,565,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp50.DLL
[2009/03/03 14:14:31 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFC30.DLL
[2009/03/03 14:14:31 | 00,133,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFCANS32.DLL
[2009/03/03 14:14:31 | 00,027,025 | ---- | C] () -- C:\Windows\System32\OLE2.REG
[2009/03/03 14:14:31 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFCUIA32.DLL
[2009/03/03 14:14:30 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SVRAPI.DLL
[2009/03/03 14:13:57 | 00,000,000 | ---D | C] -- C:\Program Files\MySoftware
[2009/03/03 14:13:57 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\MySoftware
[2009/03/03 14:12:22 | 00,000,000 | ---D | C] -- C:\GRAPHPAP
[2009/03/03 14:11:37 | 00,014,336 | ---- | C] () -- C:\Windows\System32\vsmon1.dll
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\Windows\My Documents
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\ProgramData\eXPert PDF Jobs
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\ProgramData\eXPert PDF
[2009/03/03 14:11:29 | 00,000,000 | ---D | C] -- C:\Program Files\Visagesoft
[2009/03/03 14:07:31 | 00,000,000 | ---D | C] -- C:\Program Files\CartaGoGo
[2009/03/03 14:06:29 | 00,000,000 | ---D | C] -- C:\Program Files\Anagramme
[2009/03/03 14:06:24 | 00,253,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2009/03/03 14:06:23 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\ST6UNST.EXE
[2009/03/03 14:00:15 | 00,000,000 | ---D | C] -- C:\Program Files\AbiSuite2
[2009/03/03 13:56:57 | 00,000,000 | ---D | C] -- C:\Program Files\Micro Application
[2009/03/03 13:52:59 | 00,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2009/03/03 13:48:53 | 00,000,070 | ---- | C] () -- C:\Windows\divxhistory.ini
[2009/03/03 13:48:18 | 00,000,000 | ---- | C] () -- C:\Windows\WD.INI
[2009/03/03 13:48:10 | 00,000,000 | ---D | C] -- C:\DivxHistory
[2009/03/03 13:44:53 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\vlc
[2009/03/03 13:38:34 | 00,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2009/03/03 13:37:21 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Todae
[2009/03/03 13:26:52 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Winamp
[2009/03/03 13:26:52 | 00,000,000 | ---D | C] -- C:\Program Files\Winamp
[2009/03/03 13:20:47 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Sun
[2009/03/03 13:08:16 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\sTabLauncher
[2009/03/03 13:07:24 | 00,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2009/03/03 13:07:02 | 00,000,000 | ---D | C] -- C:\Program Files\VistaCodecPack
[2009/03/03 13:04:19 | 00,000,000 | ---D | C] -- C:\Windows\System32\URTTEMP
[2009/03/03 13:02:31 | 00,002,391 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\sTabLauncher.lnk
[2009/03/03 13:02:30 | 00,000,000 | ---D | C] -- C:\Program Files\sTabLauncher
[2009/03/03 12:32:33 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msadox.dll
[2009/03/03 12:32:33 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msado27.tlb
[2009/03/03 12:32:33 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msado20.tlb
[2009/03/03 12:32:33 | 00,024,626 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\scrrnfr.dll
[2009/03/03 12:32:32 | 01,287,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSXML5.DLL
[2009/03/03 12:32:32 | 00,647,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCOMCT2.OCX
[2009/03/03 12:32:32 | 00,608,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comctl32.ocx
[2009/03/03 12:32:32 | 00,155,136 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/03/03 12:32:32 | 00,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCMCFR.DLL
[2009/03/03 12:32:32 | 00,140,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMDLG32.OCX
[2009/03/03 12:32:32 | 00,119,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\VB6FR.DLL
[2009/03/03 12:32:32 | 00,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMCTLFR.DLL
[2009/03/03 12:32:32 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCC2FR.DLL
[2009/03/03 12:32:32 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RCHTXFR.DLL
[2009/03/03 12:32:32 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CMDLGFR.DLL
[2009/03/03 12:32:32 | 00,026,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\HH.EXE
[2009/03/03 12:32:32 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\stdftfr.dll
[2009/03/03 12:24:22 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/03/03 12:24:16 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Mozilla
[2009/03/03 12:24:16 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Mozilla
[2009/03/03 12:24:08 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/03/03 12:12:06 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\MetaProducts
[2009/03/03 12:12:06 | 00,000,000 | ---D | C] -- C:\Program Files\Download Express
[2009/03/02 21:14:24 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009/03/02 21:13:59 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2009/03/02 21:12:39 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2009/03/02 21:12:28 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2009/03/02 21:12:09 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2009/03/02 21:11:46 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2009/03/02 20:33:43 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Microsoft Games
[2009/03/02 20:02:48 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2009/03/02 19:21:52 | 00,004,608 | ---- | C] () -- C:\Users\claude\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/02 19:02:46 | 00,000,000 | -H-D | C] -- C:\Windows\Icons
[2009/03/02 18:16:42 | 00,000,000 | ---D | C] -- C:\Program Files\a-squared Free
[2009/03/02 17:58:54 | 00,603,904 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe
[2009/03/02 17:58:52 | 00,027,904 | ---- | C] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll
[2009/03/02 17:58:52 | 00,017,152 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2009/03/02 17:58:48 | 00,360,192 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TuneUpDefragService.exe
[2009/03/02 17:58:24 | 00,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2009
[2009/03/02 17:58:23 | 00,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2009/03/02 17:57:34 | 00,000,000 | -HSD | C] -- C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/03/02 16:38:57 | 00,774,144 | ---- | C] () -- C:\Windows\System32\NEROINSTAEC43759.DB
[2009/03/02 16:12:01 | 00,000,000 | ---D | C] -- C:\ProgramData\Bluetooth
[2009/03/02 16:06:52 | 00,000,000 | ---D | C] -- C:\Program Files\IVT Corporation
[2009/03/02 16:05:16 | 00,059,033 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\PH848.sys
[2009/03/02 16:05:16 | 00,058,841 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Pv848.sys
[2009/03/02 16:05:16 | 00,000,000 | ---D | C] -- C:\Program Files\Hercules
[2009/03/02 16:02:19 | 00,036,864 | ---- | C] (Agfa-Gevaert N.V.) -- C:\Windows\System32\agusbsti.dll
[2009/03/02 16:02:19 | 00,032,768 | ---- | C] () -- C:\Windows\System32\Snape20.bin
[2009/03/02 16:00:54 | 00,097,857 | ---- | C] (Silicon Image, Inc) -- C:\Windows\System32\drivers\SI3114r.sys
[2009/03/02 16:00:54 | 00,010,240 | ---- | C] (Silicon Image, Inc.) -- C:\Windows\System32\drivers\SiWinAcc.sys
[2009/03/02 15:53:52 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/03/02 15:53:52 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/03/02 15:44:14 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Macromedia
[2009/03/02 15:44:14 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Adobe
[2009/03/02 15:44:11 | 00,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2009/03/02 14:51:17 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Ahead
[2009/03/02 14:49:41 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Nero
[2009/03/02 14:46:28 | 00,000,000 | ---D | C] -- C:\ProgramData\Nero
[2009/03/02 14:46:28 | 00,000,000 | ---D | C] -- C:\Program Files\Nero
[2009/03/02 14:46:28 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2009/03/02 14:41:07 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2009/03/02 14:41:05 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2009/03/02 14:19:09 | 00,000,000 | ---D | C] -- C:\Program Files\Foxit Software
[2009/03/02 14:03:32 | 00,000,510 | ---- | C] () -- C:\Windows\tasks\Maintenance en 1 clic.job
[2009/03/02 14:03:26 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\TuneUp Software
[2009/03/02 13:00:13 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2009/03/02 12:59:23 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2009/03/02 12:59:22 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2009/03/02 12:57:54 | 00,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2009/03/02 12:57:54 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2009/03/02 12:54:05 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2009/03/02 12:52:18 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\Microsoft Help
[2009/03/02 12:52:01 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2009/03/02 12:51:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2009/03/02 12:51:20 | 00,000,000 | RH-D | C] -- C:\MSOCache
[2009/03/02 12:43:25 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/03/02 12:36:30 | 00,000,000 | ---D | C] -- C:\Program Files\Soft4Ever
[2009/03/02 12:31:54 | 00,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2009/03/02 12:12:50 | 00,000,000 | ---- | C] () -- C:\Users\claude\AppData\Roaming\sversion.ini
[2009/03/02 12:08:17 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Roaming\Sun
[2009/03/02 12:08:00 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/03/02 12:07:59 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2009/03/02 12:07:21 | 00,000,000 | ---D | C] -- C:\Users\claude\AppData\Local\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2009/03/02 12:06:57 | 00,000,000 | ---D | C] -- C:\Program Files\StarOffice7
[2009/03/02 12:04:35 | 00,069,632 | ---- | C] () -- C:\Windows\uinst001.exe
[2009/03/02 11:59:02 | 00,000,000 | ---D | C] -- C:\Windows\System32\oodag
[2009/03/02 11:55:41 | 00,029,371 | ---- | C] () -- C:\Windows\System32\oodbs.lor
[2009/03/02 11:54:25 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/03/02 11:54:24 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/03/02 11:54:22 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/03/02 11:54:13 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/03/02 11:54:13 | 01,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFC71.dll
[2009/03/02 11:54:13 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCP71.dll
[2009/03/02 11:54:13 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/03/02 11:54:13 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCR71.dll
[2009/03/02 11:54:13 | 00,051,792 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/03/02 11:54:09 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
---- | C] () -- D:\claude Taillard\Documents\sanaa.jpg

========== Files - Modified Within 30 Days ==========

[1 C:\Windows\System32\drivers\*.tmp files]
[2009/03/05 10:00:03 | 00,000,510 | ---- | M] () -- C:\Windows\tasks\Maintenance en 1 clic.job
[2009/03/05 09:38:55 | 00,498,176 | ---- | M] (OldTimer Tools) -- C:\Users\claude\Desktop\OTListIt2.exe
[2009/03/05 09:01:15 | 00,000,452 | -HS- | M] () -- C:\Users\claude\Desktop\desktop.ini
[2009/03/05 08:33:17 | 00,002,391 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\sTabLauncher.lnk
[2009/03/05 08:24:26 | 00,004,096 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/03/05 08:24:26 | 00,004,096 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/03/05 08:24:22 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/03/05 08:24:20 | 00,352,615 | -H-- | M] () -- C:\Windows\System32\drivers\vsconfig.xml
[2009/03/05 08:24:08 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/03/05 08:23:46 | 00,029,371 | ---- | M] () -- C:\Windows\System32\oodbs.lor
[2009/03/04 22:39:00 | 03,388,462 | -H-- | M] () -- C:\Users\claude\AppData\Local\IconCache.db
[2009/03/04 22:17:10 | 00,005,358 | ---- | M] () -- D:\claude Taillard\Documents\cc_20090304_2217.reg
[2009/03/04 15:02:02 | 00,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2009/03/04 15:02:00 | 00,004,608 | ---- | M] () -- C:\Users\claude\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/04 13:58:52 | 00,012,791 | ---- | M] () -- D:\claude Taillard\Documents\Dis-moi... Le silence fait si mal....docx
[2009/03/04 13:29:58 | 00,011,310 | ---- | M] () -- D:\claude Taillard\Documents\Penser à quelqu.docx
[2009/03/04 13:15:07 | 00,010,845 | ---- | M] () -- D:\claude Taillard\Documents\Tu vas partir pour retrouver John et toi seule sais ce qui se passera.docx
[2009/03/03 22:14:14 | 01,507,016 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/03/03 22:14:14 | 00,681,948 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2009/03/03 22:14:14 | 00,598,652 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/03/03 22:14:14 | 00,129,090 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2009/03/03 22:14:14 | 00,105,922 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/03/03 20:01:30 | 00,008,314 | ---- | M] () -- C:\Windows\System32\BIN_STRSBW.SPT
[2009/03/03 18:34:37 | 00,024,576 | ---- | M] () -- C:\Users\claude\Desktop\urqNDUlM.dll
[2009/03/03 15:55:30 | 00,005,571 | ---- | M] () -- C:\Windows\System32\vsconfig.xml
[2009/03/03 15:36:30 | 00,016,318 | ---- | M] () -- D:\claude Taillard\Documents\cc_20090303_1536.reg
[2009/03/03 15:20:53 | 00,717,296 | ---- | M] () -- C:\Windows\System32\drivers\sptd.sys
[2009/03/03 14:45:11 | 00,113,952 | ---- | M] () -- C:\Users\claude\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/03/03 14:39:47 | 00,407,136 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/03/03 14:25:16 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/03/03 14:25:16 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/03/03 14:15:15 | 00,001,501 | ---- | M] () -- C:\Windows\bizpub32.INI
[2009/03/03 14:06:24 | 00,253,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2009/03/03 14:06:23 | 00,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\ST6UNST.EXE
[2009/03/03 13:48:53 | 00,000,070 | ---- | M] () -- C:\Windows\divxhistory.ini
[2009/03/03 13:48:18 | 00,000,000 | ---- | M] () -- C:\Windows\WD.INI
[2009/03/03 12:24:22 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/03/03 08:38:36 | 00,000,398 | -HS- | M] () -- D:\claude Taillard\Documents\desktop.ini
[2009/03/02 17:58:54 | 00,603,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe
[2009/03/02 17:58:48 | 00,360,192 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TuneUpDefragService.exe
[2009/03/02 15:53:51 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/03/02 12:53:24 | 00,000,219 | ---- | M] () -- C:\Windows\win.ini
[2009/03/02 12:32:50 | 00,000,000 | ---- | M] () -- C:\Users\claude\AppData\Roaming\sversion.ini
[2009/03/02 12:09:38 | 00,069,632 | ---- | M] () -- C:\Windows\uinst001.exe
[2009/03/02 11:47:55 | 00,000,000 | ---- | M] () -- C:\Windows\OODCNT.INI
[2009/03/02 11:21:09 | 00,171,136 | RHS- | M] () -- C:\grldr
[2009/03/02 11:16:46 | 00,000,749 | RH-- | M] () -- C:\Windows\WindowsShell.Manifest
[2009/03/02 11:16:46 | 00,000,280 | -HS- | M] () -- C:\Users\Public\Documents\desktop.ini
[2009/03/02 11:16:46 | 00,000,174 | -HS- | M] () -- C:\Users\Public\Desktop\desktop.ini
[2009/03/02 11:16:46 | 00,000,174 | -HS- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2009/03/02 11:00:46 | 00,101,888 | ---- | M] (Infineon Technologies AG) -- C:\Windows\System32\ifxcardm.dll
[2009/03/02 11:00:46 | 00,052,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe
[2009/03/02 11:00:38 | 00,082,432 | ---- | M] (Gemalto, Inc.) -- C:\Windows\System32\axaltocm.dll
[2009/03/02 10:54:29 | 00,131,072 | ---- | M] () -- C:\Windows\SPInstall.etl

<End>
claude0207
 
Messages: 49
Inscription: 23 Juil 2007, 08:00
Localisation: Huy - Belgique

Messagede claude0207 » 05 Mar 2009, 12:14

Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1820
Windows 6.0.6001 Service Pack 1

5/03/2009 12:11:33
mbam-log-2009-03-05 (12-11-27).txt

Type de recherche: Examen rapide
Eléments examinés: 57295
Temps écoulé: 2 minute(s), 28 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msserver (Trojan.Vundo) -> No action taken.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Users\claude\AppData\Local\Temp\urqNDUlM.dll (Trojan.Vundo) -> No action taken.
C:\Users\claude\Desktop\urqNDUlM.dll (Trojan.Vundo) -> No action taken.
claude0207
 
Messages: 49
Inscription: 23 Juil 2007, 08:00
Localisation: Huy - Belgique

fin

Messagede claude0207 » 05 Mar 2009, 12:25

J'ai résolu le problème en faisant un fix error après avoir sauvegardé le fichier de rapport de malwarebytes.
Je n'ai plus de message d'erreur concernant le dll. au demarrage de windows
Merci beaucoup pour cette aide précieuse et, au combien, rapide... Super!
claude0207
 
Messages: 49
Inscription: 23 Juil 2007, 08:00
Localisation: Huy - Belgique

Messagede nickW » 05 Mar 2009, 15:31

Re-re-Bonjour,

Puisque tu t'es débrouillé tout seul .....


Une p'tite remarque:
Le nom exact du fichier était urqNDUlM.dll, avec un un "L" minuscule et non un un "i" majuscule.



Quelques autres conseils:

ImageUn conseil important:
Il faut créer un nouveau point de restauration système.
Après nettoyage du PC, il faut créer un nouveau point de restauration qui sera utilisable en cas de problème.
Voir ce tutoriel - paragraphe "Créer un point de restauration". Merci à libellules.ch


ImageUn conseil important:
Installer la nouvelle version de Java de Sun.

Version actuelle: Java SE Runtime Environment (JRE) 6 Update 12
*- http://java.sun.com/javase/downloads/index.jsp (prendre le fichier jre-6u12-windows-i586-p.exe, 15,52 MB)

Puis en désinstaller toutes les versions obsolètes dont les failles sont utilisées par les "malveillants".
Page d'Assiste: http://assiste.com.free.fr/p/abc/c/anti_java.html

Pour la suppression des anciennes versions:

Étape 1: Contrôle des comptes utilisateurs, désactivation
Désactiver l'UAC - User Account Control - contrôle des comptes utilisateurs:
Note importante: Ne pas oublier de le réactiver après la désinfection.
  • Démarrer ----> Panneau de Configuration
  • En mode d'affichage par défaut, cliquer sur Comptes d'utilisateurs; cliquer de nouveau sur Comptes d'utilisateurs
  • En mode d'affichage "Classique", faire un double clic sur Comptes d'utilisateurs
  • Cliquer sur Activer ou désactiver le contrôle des comptes d'utilisateurs (en bas)
  • Décocher la case située devant Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur
    Note: Si l'UAC était déjà désactivé, cliquer sur Annuler, quitter le Panneau de configuration et passer au téléchargement - pas de redémarrage requis
  • Cliquer sur OK pour valider.
  • Un message prévient que l'ordinateur doit redémarrer; cliquer sur OK. L'ordinateur doit maintenant redémarrer.


Étape 2: JavaRa (de Fred de Vries et Paul McLain)
Télécharger JavaRa depuis cette page: http://raproducts.org/
(Dans l'article JavaRa, cliquer sur Download Windows Binary (.zip file)).
Enregistrer le fichier JavaRa.zip sur le Bureau.
Créer un nouveau dossier nommé JavaRa et y décompresser la totalité de l'archive (clic droit, puis Extraire tout).
Ouvrir le dossier JavaRa, faire un clic droit sur JavaRa.exe puis choisir "Exécuter en tant qu'Administrateur" pour lancer l'outil.

Sous "Select the language of your choice below" choisir (via la liste déroulante) Français et cliquer sur le bouton Select.

Cliquer sur le bouton Effacer les anciennes versions et valider ce choix en cliquant sur Oui ("Êtes-vous sûr de vouloir poursuivre?").

Cliquer deux fois sur OK.
Un rapport va s'afficher dans le Bloc-notes. Fermer le Bloc-notes.
Fermer JavaRa.

Étape 3: Contrôle des comptes utilisateurs, réactivation
Réactiver le contrôle des comptes utilisateurs (UAC-User Account Control).


ImageUn conseil:
La version gratuite de MBAM (Malwarebytes' Anti-Malware) reste utilisable pour effectuer des analyses à la demande.
Tu peux donc choisir de la laisser installée, et de l'utiliser de temps en temps (pour faire du "nettoyage") en faisant une mise à jour manuelle avant de demander l'examen.


Voilì, voilò, voilà.

Salut,

PS:
Si tu considères que ce sujet est clos, peux-tu mettre [OK] devant le titre du premier message. Voir ICI.
Merci.
nickW - Image
30/07/2012: Plus de désinfection de PC jusqu'à nouvel ordre.
Pas de demande d'analyse de log en MP (Message Privé)
Mes configs
Avatar de l’utilisateur
nickW
Modérateur
 
Messages: 21698
Inscription: 20 Mai 2004, 17:41
Localisation: Dordogne/Île de France

Suivante

Retourner vers Windows (toutes versions) et moi

Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 9 invités