Infecté par crypt .xpack.gen

jojo -  
 gen-hackman -
Bonjour,
voici le rapport antivir :


Avira AntiVir Personal
Date de création du fichier de rapport : lundi 8 juin 2009 21:29

La recherche porte sur 1457764 souches de virus.

Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
Numéro de série : 0000149996-ADJIE-0000001
Plateforme : Windows XP
Version de Windows : (Service Pack 3) [5.1.2600]
Mode Boot : Démarré normalement
Identifiant : SYSTEM
Nom de l'ordinateur : M-276D85A429674

Informations de version :
BUILD.DAT : 9.0.0.65 17959 Bytes 22/04/2009 12:06:00
AVSCAN.EXE : 9.0.3.6 466689 Bytes 21/04/2009 12:20:54
AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 19:33:26
ANTIVIR2.VDF : 7.1.4.38 2692096 Bytes 29/05/2009 19:52:15
ANTIVIR3.VDF : 7.1.4.66 237568 Bytes 07/06/2009 20:09:02
Version du moteur : 8.2.0.180
AEVDF.DLL : 8.1.1.1 106868 Bytes 17/05/2009 19:49:39
AESCRIPT.DLL : 8.1.2.0 389497 Bytes 17/05/2009 19:49:38
AESCN.DLL : 8.1.2.3 127347 Bytes 17/05/2009 19:49:36
AERDL.DLL : 8.1.1.3 438645 Bytes 29/10/2008 17:24:41
AEPACK.DLL : 8.1.3.18 401783 Bytes 27/05/2009 19:49:04
AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 19:01:56
AEHEUR.DLL : 8.1.0.129 1761655 Bytes 17/05/2009 19:49:30
AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 19:01:56
AEGEN.DLL : 8.1.1.44 348532 Bytes 17/05/2009 19:49:21
AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 13:32:40
AECORE.DLL : 8.1.6.12 180599 Bytes 27/05/2009 19:49:03
AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
AVPREF.DLL : 9.0.0.1 43777 Bytes 03/12/2008 10:39:26
AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 17/02/2009 12:49:32
RCTEXT.DLL : 9.0.37.0 88321 Bytes 15/04/2009 09:07:05

Configuration pour la recherche actuelle :
Nom de la tâche...............................: Contrôle intégral du système
Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
Documentation.................................: bas
Action principale.............................: interactif
Action secondaire.............................: ignorer
Recherche sur les secteurs d'amorçage maître..: marche
Recherche sur les secteurs d'amorçage.........: marche
Secteurs d'amorçage...........................: C:,
Recherche dans les programmes actifs..........: marche
Recherche en cours sur l'enregistrement.......: marche
Recherche de Rootkits.........................: marche
Contrôle d'intégrité de fichiers système......: arrêt
Fichier mode de recherche.....................: Tous les fichiers
Recherche sur les archives....................: marche
Limiter la profondeur de récursivité..........: 20
Archive Smart Extensions......................: marche
Heuristique de macrovirus.....................: marche
Heuristique fichier...........................: moyen

Début de la recherche : lundi 8 juin 2009 21:29

La recherche d'objets cachés commence.
Une instance de la bibliothèque ARK fonctionne déjà.

La recherche sur les processus démarrés commence :
Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
Processus de recherche 'firefox.exe' - '1' module(s) sont contrôlés
Processus de recherche 'skypePM.exe' - '1' module(s) sont contrôlés
Processus de recherche 'PCLEScheduler.exe' - '1' module(s) sont contrôlés
Processus de recherche 'BTTray.exe' - '1' module(s) sont contrôlés
Processus de recherche 'GoogleUpdate.exe' - '1' module(s) sont contrôlés
Processus de recherche 'TeaTimer.exe' - '1' module(s) sont contrôlés
Processus de recherche 'COCIManager.exe' - '1' module(s) sont contrôlés
Processus de recherche 'Skype.exe' - '1' module(s) sont contrôlés
Processus de recherche 'steam.exe' - '1' module(s) sont contrôlés
Processus de recherche 'GoogleToolbarNotifier.exe' - '1' module(s) sont contrôlés
Processus de recherche 'dpupdchk.exe' - '1' module(s) sont contrôlés
Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
Processus de recherche 'ipoint.exe' - '1' module(s) sont contrôlés
Processus de recherche 'itype.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
Processus de recherche 'lxcgcoms.exe' - '1' module(s) sont contrôlés
Processus de recherche 'realsched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'ezprint.exe' - '1' module(s) sont contrôlés
Processus de recherche 'Communications_Helper.exe' - '1' module(s) sont contrôlés
Processus de recherche 'RTHDCPL.exe' - '1' module(s) sont contrôlés
Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'LVPrcSrv.exe' - '1' module(s) sont contrôlés
Processus de recherche 'LVComSer.exe' - '1' module(s) sont contrôlés
Processus de recherche 'jqs.exe' - '1' module(s) sont contrôlés
Processus de recherche 'btwdins.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
Processus de recherche 'aawservice.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'nvsvc32.exe' - '1' module(s) sont contrôlés
Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
'49' processus ont été contrôlés avec '49' modules

La recherche sur les secteurs d'amorçage maître commence :
Secteur d'amorçage maître HD0
[INFO] Aucun virus trouvé !

La recherche sur les secteurs d'amorçage commence :
Secteur d'amorçage 'C:\'
[INFO] Aucun virus trouvé !

La recherche sur les renvois aux fichiers exécutables (registre) commence :
Le registre a été contrôlé ( '62' fichiers).


La recherche sur les fichiers sélectionnés commence :

Recherche débutant dans 'C:\'
C:\pagefile.sys
[AVERTISSEMENT] Impossible d'ouvrir le fichier !
[REMARQUE] Ce fichier est un fichier système Windows.
[REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\AVSCAN-20090606-212220-FF1E9A52\ARKF0.tmp
[RESULTAT] Contient le cheval de Troie TR/Crypt.XPACK.Gen
C:\System Volume Information\_restore{C42B8AA5-9C56-4F3F-AC0C-C82A8EA94EE0}\RP303\A0130570.exe
[0] Type d'archive: CAB SFX (self extracting)
--> \Awy\nvawy.inf
[AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
[AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
C:\WINDOWS\system32\drivers\sptd.sys
[AVERTISSEMENT] Impossible d'ouvrir le fichier !

Début de la désinfection :
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\AVSCAN-20090606-212220-FF1E9A52\ARKF0.tmp
[RESULTAT] Contient le cheval de Troie TR/Crypt.XPACK.Gen
[AVERTISSEMENT] Erreur lors de la création d'une copie de sécurité du fichier. Le fichier n'a pas été supprimé. Code d'erreur : 26003
[AVERTISSEMENT] Impossible de supprimer le fichier !
[REMARQUE] Tentative en cours d'exécuter l'action à l'aide de la bibliothèque ARK.
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a787eaa.qua' !


Fin de la recherche : lundi 8 juin 2009 23:10
Temps nécessaire: 1:39:35 Heure(s)

La recherche a été effectuée intégralement

7649 Les répertoires ont été contrôlés
424519 Des fichiers ont été contrôlés
1 Des virus ou programmes indésirables ont été trouvés
0 Des fichiers ont été classés comme suspects
0 Des fichiers ont été supprimés
0 Des virus ou programmes indésirables ont été réparés
1 Les fichiers ont été déplacés dans la quarantaine
0 Les fichiers ont été renommés
2 Impossible de contrôler des fichiers
424516 Fichiers non infectés
4782 Les archives ont été contrôlées
5 Avertissements
2 Consignes
A voir également:

104 réponses

jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 617
 
tu dis avoir pu brancher ton scanner as tu essaié avec ta clé usb
0
jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 617
 
je viens de demander à lyonnais 92 de passer voir car sur ton rapport perso je vois cela [2009/06/11 23:13:00 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe
et je préfère confirmation , moi je te le ferais virer avec otmoveit mais lyonnais lui utilise un cript pour OTL, il vient de me dire qu'il passera demain car la il est tard et fatigué
0
Utilisateur anonyme
 
Hello Jacques,

PEV.exe est un petit programme utilisé par Combofix.

Il n'est pas infectieux.

++
0
jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 617
 
C_XX bonjour et merci pour la confirmation , sinon as tu une idée de ce qu'il se passe avec le reboot du pc dés qu'il introduit une clé usb
0
Utilisateur anonyme
 
Re,
Non aucune idée, désolé :/.
++
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

le script OTL :

Double clic sur OTL.exe pour le lancer.


Copie la liste qui se trouve en gras ci-dessous,

et colle-la dans la zone sous Customs Scans/Fixes


:OTL
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
[2009/06/01 01:27:15 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt19.sqm
[2009/06/01 01:27:15 | 00,000,232 | -H-- | C] () -- C:\sqmdata19.sqm
[2009/06/01 01:27:02 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt18.sqm
[2009/06/01 01:27:02 | 00,000,232 | -H-- | C] () -- C:\sqmdata18.sqm
[2009/06/01 01:26:50 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt17.sqm
[2009/06/01 01:26:50 | 00,000,232 | -H-- | C] () -- C:\sqmdata17.sqm
[2009/05/26 19:41:47 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt16.sqm
[2009/05/26 19:41:47 | 00,000,232 | -H-- | C] () -- C:\sqmdata16.sqm
[2009/05/26 12:00:34 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt15.sqm
[2009/05/26 12:00:34 | 00,000,232 | -H-- | C] () -- C:\sqmdata15.sqm
[2009/05/26 11:42:25 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt14.sqm
[2009/05/26 11:42:25 | 00,000,232 | -H-- | C] () -- C:\sqmdata14.sqm
[2009/05/26 11:42:13 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt13.sqm
[2009/05/26 11:42:13 | 00,000,232 | -H-- | C] () -- C:\sqmdata13.sqm
[2009/05/26 11:41:40 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt12.sqm
[2009/05/26 11:41:40 | 00,000,232 | -H-- | C] () -- C:\sqmdata12.sqm
[2009/05/26 11:39:52 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt11.sqm
[2009/05/26 11:39:52 | 00,000,232 | -H-- | C] () -- C:\sqmdata11.sqm
[2009/05/26 11:38:18 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt10.sqm
[2009/05/26 11:38:18 | 00,000,232 | -H-- | C] () -- C:\sqmdata10.sqm
[2009/05/26 11:30:05 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt09.sqm
[2009/05/26 11:30:05 | 00,000,232 | -H-- | C] () -- C:\sqmdata09.sqm
[2009/05/25 13:38:26 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt08.sqm
[2009/05/25 13:38:26 | 00,000,232 | -H-- | C] () -- C:\sqmdata08.sqm
[2009/05/25 13:36:44 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt07.sqm
[2009/05/25 13:36:44 | 00,000,232 | -H-- | C] () -- C:\sqmdata07.sqm
[2009/05/25 13:36:20 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt06.sqm
[2009/05/25 13:36:20 | 00,000,232 | -H-- | C] () -- C:\sqmdata06.sqm
[2009/05/25 13:35:34 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt05.sqm
[2009/05/25 13:35:34 | 00,000,232 | -H-- | C] () -- C:\sqmdata05.sqm
[2009/05/25 13:32:58 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt04.sqm
[2009/05/25 13:32:58 | 00,000,232 | -H-- | C] () -- C:\sqmdata04.sqm
[2009/05/25 13:02:50 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt03.sqm
[2009/05/25 13:02:50 | 00,000,232 | -H-- | C] () -- C:\sqmdata03.sqm
[2009/05/25 12:53:59 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt02.sqm
[2009/05/25 12:53:59 | 00,000,232 | -H-- | C] () -- C:\sqmdata02.sqm
[2009/05/25 12:51:43 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt01.sqm
[2009/05/25 12:51:43 | 00,000,232 | -H-- | C] () -- C:\sqmdata01.sqm
[2009/05/25 12:51:11 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt00.sqm
[2009/05/25 12:51:11 | 00,000,232 | -H-- | C] () -- C:\sqmdata00.sqm



Clique sur RunFix pour lancer la suppression.


Poste le rapport.

==============
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
JOJO
 
une première fois OTL n'a pas fait redémarrer l'ordi
à la deuxième oui

========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Expl orer not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1844237615-2052111302-725345543-1004\Software\P­olicies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\M­icrosoft\Windows\CurrentVersion\policies\Explorer not found.
Registry key HKEY_USERS\S-1-5-21-1844237615-2052111302-725345543-1004_Classes\So­ftware\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:lsdelete scheduled to be deleted on reboot.
File C:\WINDOWS\System32\lsdelete.exe not found.
File C:\sqmnoopt19.sqm not found.
File C:\sqmdata19.sqm not found.
File C:\sqmnoopt18.sqm not found.
File C:\sqmdata18.sqm not found.
File C:\sqmnoopt17.sqm not found.
File C:\sqmdata17.sqm not found.
File C:\sqmnoopt16.sqm not found.
File C:\sqmdata16.sqm not found.
File C:\sqmnoopt15.sqm not found.
File C:\sqmdata15.sqm not found.
File C:\sqmnoopt14.sqm not found.
File C:\sqmdata14.sqm not found.
File C:\sqmnoopt13.sqm not found.
File C:\sqmdata13.sqm not found.
File C:\sqmnoopt12.sqm not found.
File C:\sqmdata12.sqm not found.
File C:\sqmnoopt11.sqm not found.
File C:\sqmdata11.sqm not found.
File C:\sqmnoopt10.sqm not found.
File C:\sqmdata10.sqm not found.
File C:\sqmnoopt09.sqm not found.
File C:\sqmdata09.sqm not found.
File C:\sqmnoopt08.sqm not found.
File C:\sqmdata08.sqm not found.
File C:\sqmnoopt07.sqm not found.
File C:\sqmdata07.sqm not found.
File C:\sqmnoopt06.sqm not found.
File C:\sqmdata06.sqm not found.
File C:\sqmnoopt05.sqm not found.
File C:\sqmdata05.sqm not found.
File C:\sqmnoopt04.sqm not found.
File C:\sqmdata04.sqm not found.
File C:\sqmnoopt03.sqm not found.
File C:\sqmdata03.sqm not found.
File C:\sqmnoopt02.sqm not found.
File C:\sqmdata02.sqm not found.
File C:\sqmnoopt01.sqm not found.
File C:\sqmdata01.sqm not found.
File C:\sqmnoopt00.sqm not found.
File C:\sqmdata00.sqm not found.

OTL by OldTimer - Version 2.1.1.0 log created on 06132009_193149

Files moved on Reboot...

Registry entries deleted on Reboot...
Registry delete failed. :HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:lsdelete scheduled to be deleted on reboot.
0
jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 617
 
JOJO bonjour, on va attendre lyonnais pour voir ce qu'il en pense , sinon as tu réussi à connecter une clé usb sans le reboot du pc !!!
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

refais tourner OTL et poste le rapport (toujours sous la forme d'un lien cijoint).
0
JOJO
 
http://www.cijoint.fr/cjlink.php?file=cj200906/cij8KtsLVJ.txt
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

on réessaye comme ça :

Double clic sur OTL.exe pour le lancer.


Copie la liste qui se trouve en gras ci-dessous,

et colle-la dans la zone sous Customs Scans/Fixes


:OTL
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Expl­orer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\Software\P­olicies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\M­icrosoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004_Classes\So­ftware\Policies\Microsoft\Internet Explorer\Control Panel present
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
[2009/06/01 01:27:15 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt19.sqm
[2009/06/01 01:27:15 | 00,000,232 | -H-- | C] () -- C:\sqmdata19.sqm
[2009/06/01 01:27:02 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt18.sqm
[2009/06/01 01:27:02 | 00,000,232 | -H-- | C] () -- C:\sqmdata18.sqm
[2009/06/01 01:26:50 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt17.sqm
[2009/06/01 01:26:50 | 00,000,232 | -H-- | C] () -- C:\sqmdata17.sqm
[2009/05/26 19:41:47 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt16.sqm
[2009/05/26 19:41:47 | 00,000,232 | -H-- | C] () -- C:\sqmdata16.sqm
[2009/05/26 12:00:34 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt15.sqm
[2009/05/26 12:00:34 | 00,000,232 | -H-- | C] () -- C:\sqmdata15.sqm
[2009/05/26 11:42:25 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt14.sqm
[2009/05/26 11:42:25 | 00,000,232 | -H-- | C] () -- C:\sqmdata14.sqm
[2009/05/26 11:42:13 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt13.sqm
[2009/05/26 11:42:13 | 00,000,232 | -H-- | C] () -- C:\sqmdata13.sqm
[2009/05/26 11:41:40 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt12.sqm
[2009/05/26 11:41:40 | 00,000,232 | -H-- | C] () -- C:\sqmdata12.sqm
[2009/05/26 11:39:52 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt11.sqm
[2009/05/26 11:39:52 | 00,000,232 | -H-- | C] () -- C:\sqmdata11.sqm
[2009/05/26 11:38:18 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt10.sqm
[2009/05/26 11:38:18 | 00,000,232 | -H-- | C] () -- C:\sqmdata10.sqm
[2009/05/26 11:30:05 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt09.sqm
[2009/05/26 11:30:05 | 00,000,232 | -H-- | C] () -- C:\sqmdata09.sqm
[2009/05/25 13:38:26 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt08.sqm
[2009/05/25 13:38:26 | 00,000,232 | -H-- | C] () -- C:\sqmdata08.sqm
[2009/05/25 13:36:44 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt07.sqm
[2009/05/25 13:36:44 | 00,000,232 | -H-- | C] () -- C:\sqmdata07.sqm
[2009/05/25 13:36:20 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt06.sqm
[2009/05/25 13:36:20 | 00,000,232 | -H-- | C] () -- C:\sqmdata06.sqm
[2009/05/25 13:35:34 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt05.sqm
[2009/05/25 13:35:34 | 00,000,232 | -H-- | C] () -- C:\sqmdata05.sqm
[2009/05/25 13:32:58 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt04.sqm
[2009/05/25 13:32:58 | 00,000,232 | -H-- | C] () -- C:\sqmdata04.sqm
[2009/05/25 13:02:50 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt03.sqm
[2009/05/25 13:02:50 | 00,000,232 | -H-- | C] () -- C:\sqmdata03.sqm
[2009/05/25 12:53:59 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt02.sqm
[2009/05/25 12:53:59 | 00,000,232 | -H-- | C] () -- C:\sqmdata02.sqm
[2009/05/25 12:51:43 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt01.sqm
[2009/05/25 12:51:43 | 00,000,232 | -H-- | C] () -- C:\sqmdata01.sqm
[2009/05/25 12:51:11 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt00.sqm
[2009/05/25 12:51:11 | 00,000,232 | -H-- | C] () -- C:\sqmdata00.sqm




Clique sur RunFix pour lancer la suppression.


Poste le rapport.
0
jojo
 
window n'a pas trouvé OTL.exe au redémarrage...
0
jojo
 
je ne sais pas coimment c'est possible mais OTL.EXE a disparu de son emplacement depuis le redémarrage...
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Re,

recommence la procédure du post 32.
0
jojo
 
http://www.cijoint.fr/cjlink.php?file=cj200906/cijrtCvpgU.txt

OTL logfile created on: 15/06/2009 00:54:29 - Run 6
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\m\Mes documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

1023,23 Mb Total Physical Memory | 470,45 Mb Available Physical Memory | 45,98% Memory free
2,40 Gb Paging File | 1,87 Gb Available in Paging File | 77,99% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 78,13 Gb Total Space | 21,42 Gb Free Space | 27,42% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: M-276D85A429674
Current User Name: m
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

[color=orange]========== Processes (SafeList) ==========/color

PRC - [2009/01/16 03:42:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/11/23 01:17:42 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2009/04/01 15:46:04 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2008/04/13 19:34:04 | 01,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009/03/02 13:09:54 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2007/05/30 14:31:10 | 00,312,880 | ---- | M] (GRISOFT s.r.o.) -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
PRC - [2003/09/19 15:37:20 | 00,135,168 | ---- | M] (WIDCOMM, Inc.) -- C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/02/05 18:18:48 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2008/02/05 18:20:42 | 00,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/02/05 18:18:48 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2008/12/18 12:05:40 | 00,457,248 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2008/12/18 12:05:40 | 00,191,008 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2008/02/13 13:02:46 | 00,564,496 | ---- | M] () -- C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2005/08/01 09:05:04 | 00,094,208 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 2300 Series\ezprint.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2005/07/25 16:25:18 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcgcoms.exe
PRC - [2009/05/04 11:54:09 | 00,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
PRC - [2009/03/02 13:08:11 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008/02/13 13:02:46 | 00,564,496 | ---- | M] () -- C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2008/04/27 18:26:22 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/06/11 01:12:27 | 01,217,784 | ---- | M] (Valve Corporation) -- C:\program files\steam\steam.exe
PRC - [2008/02/13 13:02:24 | 00,405,776 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
PRC - [2008/09/16 13:16:08 | 01,833,296 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/03/24 10:38:11 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Documents and Settings\m\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
PRC - [2003/09/19 15:46:14 | 00,503,869 | ---- | M] (WIDCOMM, Inc.) -- C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
PRC - [2003/03/31 18:22:50 | 00,237,568 | ---- | M] (Pinnacle Systems GmbH, Braunschweig) -- C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
PRC - [2009/06/05 05:54:50 | 00,759,280 | ---- | M] (Google Inc.) -- C:\Documents and Settings\m\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2008/05/11 13:19:30 | 05,423,104 | ---- | M] (http://www.emule-project.net) -- C:\Program Files\eMule\emule.exe
PRC - [2009/06/05 05:54:50 | 00,759,280 | ---- | M] (Google Inc.) -- C:\Documents and Settings\m\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2009/06/05 05:54:50 | 00,759,280 | ---- | M] (Google Inc.) -- C:\Documents and Settings\m\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2009/06/15 00:54:10 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\m\Mes documents\Downloads\OTL (1).exe

[color=orange]========== Win32 Services (SafeList) ==========/color

SRV - [2008/11/23 01:17:42 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
SRV - [2009/04/01 15:46:04 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running])
SRV - [2009/03/02 13:09:54 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007/05/30 14:31:10 | 00,312,880 | ---- | M] (GRISOFT s.r.o.) -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe -- (AVG Anti-Spyware Guard [Auto | Running])
SRV - [2003/09/19 15:37:20 | 00,135,168 | ---- | M] (WIDCOMM, Inc.) -- C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe -- (btwdins [Auto | Running])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/12/18 12:05:40 | 00,457,248 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM) [Auto | Running])
SRV - [2009/04/26 21:09:30 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008/04/13 19:33:40 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/04/13 19:33:28 | 00,029,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll -- (Irmon [Auto | Running])
SRV - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2008/02/05 18:18:48 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer [Auto | Running])
SRV - [2008/02/05 18:20:42 | 00,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv [Auto | Running])
SRV - [2008/02/05 18:22:36 | 00,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher [Auto | Stopped])
SRV - [2005/07/25 16:25:18 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcgcoms.exe -- (lxcg_device [On_Demand | Running])
SRV - [2009/05/29 17:13:20 | 00,234,864 | ---- | M] (CybelSoft) -- C:\Program Files\ma-config.com\maconfservice.exe -- (maconfservice [On_Demand | Stopped])
SRV - [2008/12/18 12:05:40 | 00,191,008 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp [Auto | Running])
SRV - [2009/01/16 03:42:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003/07/28 19:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
SRV - File not found -- -- (vkservice [Auto | Stopped])
SRV - [2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
SRV - [2006/11/03 09:59:14 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

[color=orange]========== Driver Services (SafeList) ==========/color

DRV - [2007/05/30 14:10:42 | 00,011,000 | ---- | M] () -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys -- (AVG Anti-Spyware Driver [System | Running])
DRV - [2007/05/30 14:10:42 | 00,010,872 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys -- (AvgAsCln [System | Running])
DRV - [2009/02/13 12:34:33 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio [System | Running])
DRV - [2009/03/24 16:07:58 | 00,055,640 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avgntflt.sys -- (avgntflt [Auto | Running])
DRV - [2009/03/30 10:32:47 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2004/02/06 06:44:18 | 00,016,512 | R--- | M] (Com21, Inc) -- C:\WINDOWS\system32\DRIVERS\Brndis.sys -- (Brndis [On_Demand | Stopped])
DRV - [2003/09/19 15:11:16 | 01,257,418 | ---- | M] (WIDCOMM, Inc.) -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL [Boot | Running])
DRV - [2003/09/19 15:14:42 | 00,022,183 | ---- | M] () -- C:\WINDOWS\system32\drivers\btserial.sys -- (BTSERIAL [Auto | Running])
DRV - [2003/09/19 15:14:14 | 00,222,876 | ---- | M] (WIDCOMM, Inc.) -- C:\WINDOWS\system32\drivers\btslbcsp.sys -- (BTSLBCSP [Auto | Running])
DRV - [2009/05/29 17:16:48 | 00,014,336 | ---- | M] (CybelSoft) -- C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys -- (driverhardwarev2 [On_Demand | Stopped])
DRV - [2007/08/27 15:12:06 | 00,031,128 | ---- | M] (FreeBox SA) -- C:\WINDOWS\system32\DRIVERS\fbxusb32.sys -- (fbxusb [On_Demand | Stopped])
DRV - [2008/04/13 11:45:30 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2008/04/13 09:36:06 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2002/04/14 17:23:00 | 00,016,588 | ---- | M] (The freeware company) -- C:\Documents and Settings\m\Bureau\MoreTV 3.53\HWIONT.sys -- (HWIONT [On_Demand | Stopped])
DRV - [2007/11/27 20:06:42 | 04,630,016 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2001/08/17 23:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\irsir.sys -- (irsir [On_Demand | Running])
DRV - [2008/09/26 11:52:00 | 00,020,240 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys -- (L8042Kbd [On_Demand | Stopped])
DRV - [2008/09/26 11:52:00 | 00,035,472 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys -- (LHidFilt [On_Demand | Stopped])
DRV - [2008/09/26 11:53:00 | 00,037,392 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys -- (LMouFilt [On_Demand | Stopped])
DRV - [2008/09/26 11:53:00 | 00,028,816 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\System32\Drivers\LUsbFilt.Sys -- (LUsbFilt [On_Demand | Stopped])
DRV - [2008/02/05 18:18:12 | 00,689,176 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys -- (LVcKap [On_Demand | Stopped])
DRV - [2008/02/05 18:20:08 | 00,025,624 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon [On_Demand | Running])
DRV - [2008/02/06 04:21:24 | 00,041,752 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta [On_Demand | Running])
DRV - [2001/08/18 00:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Running])
DRV - [2009/01/16 03:42:00 | 06,305,120 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2008/08/01 10:36:20 | 00,054,784 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2008/08/01 10:36:26 | 00,022,016 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2008/08/25 02:22:40 | 00,014,208 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvsmu.sys -- (nvsmu [On_Demand | Running])
DRV - [2009/01/23 23:33:05 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Stopped])
DRV - [2002/11/11 20:52:54 | 00,006,400 | ---- | M] (Pinnacle Systems) -- C:\WINDOWS\system32\DRIVERS\pctvvbi.sys -- (pctvvbi [On_Demand | Running])
DRV - [2008/02/06 04:17:26 | 00,013,848 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\lv302af.sys -- (pepifilter [On_Demand | Stopped])
DRV - [2002/06/17 15:09:56 | 00,014,604 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc [On_Demand | Running])
DRV - [2008/02/06 04:17:36 | 02,570,520 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LV302V32.SYS -- (PID_PEPI [On_Demand | Stopped])
DRV - [2004/08/05 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2003/02/10 16:14:00 | 00,017,664 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\DRIVERS\rob_a.sys -- (ROB_A [Auto | Stopped])
DRV - [2003/04/11 18:26:08 | 00,125,568 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\drivers\rob_v.sys -- (ROB_V [Auto | Stopped])
DRV - [2007/11/13 12:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2006/01/18 14:08:54 | 00,402,432 | ---- | M] (ZyDAS Technology Corporation) -- C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys -- (SG762_XP [On_Demand | Stopped])
DRV - [2009/03/24 14:54:10 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2009/02/13 12:49:30 | 00,028,376 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2008/04/13 11:45:14 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV - [2008/04/13 18:57:14 | 00,032,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\wceusbsh.sys -- (wceusbsh [System | Stopped])
DRV - [2006/01/18 14:08:56 | 00,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\Drivers\ZDPSp50.sys -- (ZDPSp50 [On_Demand | Running])

[color=orange]========== Standard Registry (SafeList) ==========/color


[color=orange]========== Internet Explorer ==========/color

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\S-1-5-21-1844237615-2052111302-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=orange]========== FireFox ==========/color

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.fr/?gws_rd=ssl"
FF - prefs.js..extensions.enabledItems: {e411bb40-b04c-11d8-92e7-00d09e0179f2}:3.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {bb628310-0ab7-11db-9cd8-0800200c9a66}:3.5.0.0
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11


FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/10 16:17:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/14 00:17:07 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/14 00:17:07 | 00,000,000 | ---D | M]

[2008/07/07 00:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Extensions
[2008/07/07 00:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/14 23:28:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions
[2009/04/02 01:17:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/23 13:01:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}
[2008/12/13 00:14:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\{e411bb40-b04c-11d8-92e7-00d09e0179f2}
[2009/05/15 00:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\firefox@tvunetworks.com
[2008/05/03 19:31:03 | 00,001,678 | ---- | M] () -- C:\Documents and Settings\m\Application Data\Mozilla\FireFox\Profiles\bupj6usf.default\searchplugins\blurps.xml
[2009/03/24 14:57:25 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\m\Application Data\Mozilla\FireFox\Profiles\bupj6usf.default\searchplugins\daemon-search.xml
[2009/06/14 23:28:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/14 00:17:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/04/21 05:38:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/09 22:33:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/12/10 16:17:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/01 02:15:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/14 00:17:02 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/14 00:17:02 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/12/19 21:46:04 | 00,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2008/12/19 21:46:04 | 00,000,757 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2008/12/19 21:46:04 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/19 21:46:04 | 00,000,748 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MediaDICO-fr.xml
[2008/12/19 21:46:04 | 00,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2008/12/19 21:46:04 | 00,000,652 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Aide pour le lien d'Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized (GRISOFT s.r.o.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min (Avira GmbH)
O4 - HKLM..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe" (Lexmark International Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
O4 - HKLM..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" (Lexmark International, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [Google Update] "C:\Documents and Settings\m\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [Steam] "c:\program files\steam\steam.exe" -silent (Valve Corporation)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [OTL] "C:\Documents and Settings\m\Mes documents\Downloads\OTL.exe" (OldTimer Tools)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk = C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe (WIDCOMM, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Pinnacle Scheduler.lnk = C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe (Pinnacle Systems GmbH, Braunschweig)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = C:\Program Files\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter\WLANUTL.exe ( )
O4 - Startup: C:\Documents and Settings\m\Menu Démarrer\Programmes\Démarrage\Registration-PCTV.lnk = C:\Program Files\Pinnacle\Pinnacle PCTV\ERegister\RegTool.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} https://www.eset.com/ (Reg Error: Key error.)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} http://charon888.free.fr/plugins/hardwaredetection_2_0_4_13.cab (HardwareDetection Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab (ChessControl Class)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab (MSN Games – Backgammon)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Fichiers communs\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (GRISOFT s.r.o.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/20 04:25:14 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/06/11 01:14:41 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/15 00:54:12 | 00,000,000 | ---D | M]

[color=orange]========== Files/Folders - Created Within 30 Days ==========/color

[8 C:\WINDOWS\System32\*.tmp files]
[11 C:\WINDOWS\*.tmp files]
[2009/06/14 23:22:03 | 00,000,000 | ---D | C] -- C:\_OTL
[2009/06/14 21:30:00 | 15,507,437 | ---- | C] () -- C:\Documents and Settings\m\Mes documents\La guerre russo-japonaise.pdf
[2009/06/12 21:31:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Application Data\Grisoft
[2009/06/12 21:31:35 | 00,000,849 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\AVG Anti-Spyware.lnk
[2009/06/12 21:31:30 | 00,010,872 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\AvgAsCln.sys
[2009/06/12 21:31:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/06/12 21:31:24 | 00,000,000 | ---D | C] -- C:\Program Files\Grisoft
[2009/06/12 21:30:22 | 12,413,440 | ---- | C] () -- C:\Documents and Settings\m\Bureau\avg-anti-spyware_avg_anti-spyware_7.5.1.36_francais_27645.exe
[2009/06/11 23:36:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Local Settings\temp
[2009/06/11 23:14:47 | 00,000,216 | ---- | C] () -- C:\Boot.bak
[2009/06/11 23:14:44 | 00,263,488 | ---- | C] () -- C:\cmldr
[2009/06/11 23:14:43 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/06/11 23:13:00 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/06/11 23:12:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/11 23:12:46 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF6892.exe
[2009/06/11 19:58:38 | 00,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2009/06/11 19:52:46 | 00,006,045 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2009/06/11 01:30:47 | 00,001,372 | ---- | C] () -- C:\Documents and Settings\m\Bureau\FindyKill V5.002.lnk
[2009/06/11 01:30:46 | 00,000,000 | ---D | C] -- C:\FindyKill
[2009/06/11 01:14:41 | 00,000,000 | RHSD | C] -- C:\autorun.inf
[2009/06/11 00:26:13 | 00,001,336 | ---- | C] () -- C:\Documents and Settings\m\Bureau\UsbFix V3.029.lnk
[2009/06/11 00:26:12 | 00,000,000 | ---D | C] -- C:\UsbFix
[2009/06/09 13:51:05 | 00,426,346 | ---- | C] () -- C:\Documents and Settings\m\Mes documents\cc_20090609_135104.reg
[2009/06/04 13:50:15 | 00,000,000 | ---D | C] -- C:\Program Files\FireFly Studios
[2009/06/04 13:50:14 | 00,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2009/06/04 11:14:59 | 00,079,871 | ---- | C] () -- C:\Documents and Settings\m\Bureau\Conditions_Specifiques_de_Vente_Pret_a_Expedier_Lettre_Max_Classique_et_Monaco-2.pdf
[2009/05/31 23:31:11 | 00,077,221 | ---- | C] () -- C:\Documents and Settings\m\Bureau\Invoice_Apr-01-09_Apr-30-09.csv
[2009/05/27 11:59:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Bureau\Bureau
[2009/05/24 20:25:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Bureau\Nouveau dossier
[2009/05/24 14:42:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Mes documents\FFOutput
[2009/05/23 13:23:28 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidserv.dll
[2009/05/23 13:07:36 | 00,018,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nuidfltr.sys
[2009/05/18 00:10:42 | 75,087,2474 | ---- | C] () -- C:\Documents and Settings\m\Bureau\NBA.2009.5.16.Kobe.Doin.Work.x264-albert.mp4
[2009/05/17 16:21:53 | 00,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\Logitech
[2009/05/16 22:40:16 | 00,479,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_0.dll
[2009/05/16 22:40:15 | 01,420,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_37.dll
[2009/05/16 22:40:15 | 00,462,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_37.dll
[2009/05/16 22:40:15 | 00,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_0.dll
[2009/05/16 22:40:15 | 00,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_3.dll
[2009/05/16 22:40:14 | 03,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_37.dll
[2009/05/16 22:40:14 | 00,267,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_10.dll
[2009/05/16 22:40:13 | 01,374,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_36.dll
[2009/05/16 22:40:13 | 00,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_36.dll
[2009/05/16 22:40:12 | 03,734,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_36.dll
[2009/05/16 22:40:11 | 00,267,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_9.dll
[2009/05/16 22:40:10 | 03,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_35.dll
[2009/05/16 22:40:10 | 01,358,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_35.dll
[2009/05/16 22:40:10 | 00,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_35.dll
[2009/05/16 22:39:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xlive
[2009/05/16 22:12:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Mes documents\Battlefield 2142
[2009/05/16 22:11:57 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\m\Application Data\SecuROM
[2009/05/16 22:11:56 | 00,107,888 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009/05/16 21:47:56 | 00,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Avira AntiVir Control Center.lnk
[2009/05/16 21:47:23 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/05/16 21:47:23 | 00,055,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/05/16 21:47:23 | 00,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/05/16 21:47:23 | 00,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/05/16 21:47:11 | 00,000,000 | ---D | C] -- C:\Program Files\Avira
[2009/05/16 21:47:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2009/05/16 21:32:10 | 00,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2009/05/16 21:23:01 | 30,143,928 | ---- | C] () -- C:\Documents and Settings\m\Bureau\avira_antivir_personal_free.exe
[2009/05/01 00:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/01 00:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/05/01 00:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/05/01 00:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/04/19 01:47:50 | 00,000,379 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/03/30 15:38:00 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\DataMatrix.dll
[2009/03/30 15:38:00 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\PDF417.dll
[2009/03/24 14:54:09 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/03/24 14:19:03 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2009/03/20 13:11:41 | 01,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgusb1.dll
[2009/03/20 13:11:41 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcgvs.dll
[2009/03/20 13:11:40 | 01,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgserv.dll
[2009/03/20 13:11:40 | 00,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgprox.dll
[2009/03/20 13:11:40 | 00,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgpplc.dll
[2009/03/20 13:11:39 | 00,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomc.dll
[2009/03/20 13:11:39 | 00,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcglmpm.dll
[2009/03/20 13:11:39 | 00,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomm.dll
[2009/03/20 13:11:34 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\lxcgjswr.dll
[2009/03/20 13:11:34 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\lxcginsr.dll
[2009/03/20 13:11:33 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\lxcgcur.dll
[2009/03/12 14:31:51 | 00,000,536 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2009/01/12 16:25:33 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008/11/29 15:24:34 | 00,014,025 | ---- | C] () -- C:\WINDOWS\TWAINCAP.INI
[2008/11/29 15:21:42 | 00,138,752 | ---- | C] () -- C:\WINDOWS\System32\Mase32.dll
[2008/11/29 15:21:42 | 00,057,856 | ---- | C] () -- C:\WINDOWS\System32\Masd32.dll
[2008/11/29 15:21:41 | 00,196,096 | ---- | C] () -- C:\WINDOWS\System32\Macd32.dll
[2008/11/29 15:21:41 | 00,136,192 | ---- | C] () -- C:\WINDOWS\System32\Mamc32.dll
[2008/11/29 15:21:41 | 00,027,648 | ---- | C] () -- C:\WINDOWS\System32\Ma32.dll
[2008/11/23 01:43:15 | 00,000,225 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/10/02 19:33:35 | 00,000,173 | ---- | C] () -- C:\WINDOWS\OPHC.INI
[2008/10/02 19:31:03 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\OPHCTH32.DLL
[2008/10/02 19:31:03 | 00,000,640 | R--- | C] () -- C:\WINDOWS\System32\OPHCTH16.DLL
[2008/07/21 19:51:01 | 00,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/07/21 19:51:01 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/05/29 01:54:31 | 00,001,162 | ---- | C] () -- C:\WINDOWS\System32\W32N55.INI
[2008/05/11 22:12:55 | 00,066,482 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2008/02/05 18:20:08 | 00,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/12/05 01:41:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/26 21:56:28 | 00,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2005/03/14 15:38:28 | 00,000,469 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2004/08/05 14:00:00 | 00,000,648 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/05 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/09/19 15:35:38 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\btsendto_ie.dll
[2003/09/19 15:34:40 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\btsendto_wab.dll
[2003/09/19 15:27:38 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2003/09/19 15:14:42 | 00,022,183 | ---- | C] () -- C:\WINDOWS\System32\drivers\btserial.sys
[2003/03/24 10:38:06 | 02,842,624 | ---- | C] () -- C:\WINDOWS\System32\btrez.dll
[2002/05/15 23:29:04 | 00,000,607 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2001/11/23 18:18:00 | 00,000,597 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 13:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

[color=orange]========== Files - Modified Within 30 Days ==========/color

[8 C:\WINDOWS\System32\*.tmp files]
[11 C:\WINDOWS\*.tmp files]
[2009/06/14 23:28:15 | 01,033,152 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/06/14 23:28:15 | 00,473,864 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2009/06/14 23:28:15 | 00,405,888 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/06/14 23:28:15 | 00,077,468 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2009/06/14 23:28:15 | 00,063,470 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/06/14 23:25:19 | 00,202,392 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/06/14 23:24:08 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\m\Local Settings\desktop.ini
[2009/06/14 23:23:43 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/14 23:23:37 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/14 21:30:12 | 00,122,368 | -HS- | M] () -- C:\Documents and Settings\m\Mes documents\Thumbs.db
[2009/06/14 21:30:01 | 15,507,437 | ---- | M] () -- C:\Documents and Settings\m\Mes documents\La guerre russo-japonaise.pdf
[2009/06/14 20:55:40 | 00,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-2052111302-725345543-1004.job
[2009/06/14 07:00:51 | 00,002,252 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Google Chrome.lnk
[2009/06/12 21:31:35 | 00,000,849 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\AVG Anti-Spyware.lnk
[2009/06/12 21:31:09 | 12,413,440 | ---- | M] () -- C:\Documents and Settings\m\Bureau\avg-anti-spyware_avg_anti-spyware_7.5.1.36_francais_27645.exe
[2009/06/12 11:35:54 | 00,115,768 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/11 23:32:19 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/06/11 23:32:08 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/06/11 23:14:47 | 00,000,286 | RHS- | M] () -- C:\boot.ini
[2009/06/11 23:08:34 | 00,401,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF6892.exe
[2009/06/11 20:01:03 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/11 01:30:47 | 00,001,372 | ---- | M] () -- C:\Documents and Settings\m\Bureau\FindyKill V5.002.lnk
[2009/06/11 00:26:13 | 00,001,336 | ---- | M] () -- C:\Documents and Settings\m\Bureau\UsbFix V3.029.lnk
[2009/06/09 13:51:11 | 00,426,346 | ---- | M] () -- C:\Documents and Settings\m\Mes documents\cc_20090609_135104.reg
[2009/06/09 13:41:09 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\m\Bureau\CCleaner.lnk
[2009/06/08 16:22:51 | 00,002,193 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Steam.lnk
[2009/06/08 13:50:28 | 00,933,772 | -HS- | M] () -- C:\Documents and Settings\m\Bureau\Thumbs.db
[2009/06/08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009/06/04 11:15:00 | 00,079,871 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Conditions_Specifiques_de_Vente_Pret_a_Expedier_Lettre_Max_Classique_et_Monaco-2.pdf
[2009/06/01 18:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/31 23:31:13 | 00,077,221 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Invoice_Apr-01-09_Apr-30-09.csv
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/18 15:17:08 | 75,087,2474 | ---- | M] () -- C:\Documents and Settings\m\Bureau\NBA.2009.5.16.Kobe.Doin.Work.x264-albert.mp4
[2009/05/16 22:11:56 | 00,107,888 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009/05/16 21:47:56 | 00,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Avira AntiVir Control Center.lnk
[2009/05/16 21:26:40 | 30,143,928 | ---- | M] () -- C:\Documents and Settings\m\Bureau\avira_antivir_personal_free.exe

[color=orange]========== LOP Check ==========/color

[2009/06/12 21:31:28 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/12/28 15:02:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/05/16 21:47:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avira
[2008/07/21 19:52:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2009/03/24 14:57:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/01/21 19:40:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2009/06/12 21:31:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/11/23 01:18:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/06/21 15:14:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/06/11 18:45:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ma-config.com
[2009/04/12 20:45:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/19 01:45:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/04/25 20:00:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2009/04/12 22:14:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/11/25 00:49:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/03/12 14:31:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/06/11 10:48:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/09/21 20:41:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/04/20 06:12:33 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Application Data
[2008/04/20 04:25:12 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Default User\Application Data\Microsoft
[2008/04/28 14:28:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data
[2008/04/28 14:29:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2008/06/11 10:49:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/06/12 21:31:40 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\m\Application Data
[2008/04/22 19:21:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\Adobe
[2009/05/15 00:47:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\AVS4YOU
[2009/03/24 14:58
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

maintenant le post 50.
0
jojo
 
j'ai fait ce que tas dit
mais pas de rapport
lordi a redemarre mais sans afficher de rapport
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

regarde dans C:\_OTL ou dans le répertoire où tu as mis OTL.

Si tu ne trouves rien, fais une recherche sur les fichiers avec l'extension txt récemment créés.
0
jojo
 
http://www.cijoint.fr/cjlink.php?file=cj200906/cijWaogzwn.txt

OTL logfile created on: 15/06/2009 15:36:15 - Run 8
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\m\Mes documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

1023,23 Mb Total Physical Memory | 450,61 Mb Available Physical Memory | 44,04% Memory free
2,40 Gb Paging File | 1,91 Gb Available in Paging File | 79,67% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 78,13 Gb Total Space | 21,40 Gb Free Space | 27,40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: M-276D85A429674
Current User Name: m
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

[color=orange]========== Processes (SafeList) ==========[/color]

PRC - [2009/01/16 03:42:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/11/23 01:17:42 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008/04/13 19:34:04 | 01,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009/04/01 15:46:04 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2007/11/22 16:40:32 | 16,858,112 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2008/02/13 13:02:46 | 00,564,496 | ---- | M] () -- C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2008/10/15 02:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
PRC - [2005/08/01 09:05:04 | 00,094,208 | ---- | M] (Lexmark International Inc.) -- C:\Program Files\Lexmark 2300 Series\ezprint.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/03/02 13:09:54 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/05/04 11:54:09 | 00,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
PRC - [2009/03/02 13:08:11 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2007/05/30 14:31:10 | 00,312,880 | ---- | M] (GRISOFT s.r.o.) -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
PRC - [2008/04/27 18:26:22 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/04/23 17:45:34 | 22,058,792 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
PRC - [2008/09/16 13:16:08 | 01,833,296 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2003/09/19 15:37:20 | 00,135,168 | ---- | M] (WIDCOMM, Inc.) -- C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/03/24 10:38:11 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Documents and Settings\m\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
PRC - [2008/02/05 18:18:48 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2003/09/19 15:46:14 | 00,503,869 | ---- | M] (WIDCOMM, Inc.) -- C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
PRC - [2008/02/05 18:20:42 | 00,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/02/05 18:18:48 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2003/03/31 18:22:50 | 00,237,568 | ---- | M] (Pinnacle Systems GmbH, Braunschweig) -- C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
PRC - [2008/12/18 12:05:40 | 00,457,248 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2008/12/18 12:05:40 | 00,191,008 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2008/02/13 13:02:24 | 00,405,776 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
PRC - [2005/07/25 16:25:18 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcgcoms.exe
PRC - [2008/04/23 17:45:36 | 00,076,744 | R--- | M] (Skype Technologies) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe
PRC - [2009/02/06 12:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2009/06/15 00:54:10 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\m\Mes documents\Downloads\OTL (1).exe

[color=orange]========== Win32 Services (SafeList) ==========[/color]

SRV - [2008/11/23 01:17:42 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
SRV - [2009/04/01 15:46:04 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running])
SRV - [2009/03/02 13:09:54 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007/05/30 14:31:10 | 00,312,880 | ---- | M] (GRISOFT s.r.o.) -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe -- (AVG Anti-Spyware Guard [Auto | Running])
SRV - [2003/09/19 15:37:20 | 00,135,168 | ---- | M] (WIDCOMM, Inc.) -- C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe -- (btwdins [Auto | Running])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/12/18 12:05:40 | 00,457,248 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM) [Auto | Running])
SRV - [2009/04/26 21:09:30 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008/04/13 19:33:40 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/04/13 19:33:28 | 00,029,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll -- (Irmon [Auto | Running])
SRV - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2008/02/05 18:18:48 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer [Auto | Running])
SRV - [2008/02/05 18:20:42 | 00,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv [Auto | Running])
SRV - [2008/02/05 18:22:36 | 00,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher [Auto | Stopped])
SRV - [2005/07/25 16:25:18 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcgcoms.exe -- (lxcg_device [On_Demand | Running])
SRV - [2009/05/29 17:13:20 | 00,234,864 | ---- | M] (CybelSoft) -- C:\Program Files\ma-config.com\maconfservice.exe -- (maconfservice [On_Demand | Stopped])
SRV - [2008/12/18 12:05:40 | 00,191,008 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp [Auto | Running])
SRV - [2009/01/16 03:42:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003/07/28 19:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
SRV - File not found -- -- (vkservice [Auto | Stopped])
SRV - [2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
SRV - [2006/11/03 09:59:14 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

[color=orange]========== Driver Services (SafeList) ==========[/color]

DRV - [2007/05/30 14:10:42 | 00,011,000 | ---- | M] () -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys -- (AVG Anti-Spyware Driver [System | Running])
DRV - [2007/05/30 14:10:42 | 00,010,872 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys -- (AvgAsCln [System | Running])
DRV - [2009/02/13 12:34:33 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio [System | Running])
DRV - [2009/03/24 16:07:58 | 00,055,640 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avgntflt.sys -- (avgntflt [Auto | Running])
DRV - [2009/03/30 10:32:47 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2004/02/06 06:44:18 | 00,016,512 | R--- | M] (Com21, Inc) -- C:\WINDOWS\system32\DRIVERS\Brndis.sys -- (Brndis [On_Demand | Stopped])
DRV - [2003/09/19 15:11:16 | 01,257,418 | ---- | M] (WIDCOMM, Inc.) -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL [Boot | Running])
DRV - [2003/09/19 15:14:42 | 00,022,183 | ---- | M] () -- C:\WINDOWS\system32\drivers\btserial.sys -- (BTSERIAL [Auto | Running])
DRV - [2003/09/19 15:14:14 | 00,222,876 | ---- | M] (WIDCOMM, Inc.) -- C:\WINDOWS\system32\drivers\btslbcsp.sys -- (BTSLBCSP [Auto | Running])
DRV - [2009/05/29 17:16:48 | 00,014,336 | ---- | M] (CybelSoft) -- C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys -- (driverhardwarev2 [On_Demand | Stopped])
DRV - [2007/08/27 15:12:06 | 00,031,128 | ---- | M] (FreeBox SA) -- C:\WINDOWS\system32\DRIVERS\fbxusb32.sys -- (fbxusb [On_Demand | Stopped])
DRV - [2008/04/13 11:45:30 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2008/04/13 09:36:06 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2002/04/14 17:23:00 | 00,016,588 | ---- | M] (The freeware company) -- C:\Documents and Settings\m\Bureau\MoreTV 3.53\HWIONT.sys -- (HWIONT [On_Demand | Stopped])
DRV - [2007/11/27 20:06:42 | 04,630,016 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2001/08/17 23:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\irsir.sys -- (irsir [On_Demand | Running])
DRV - [2008/09/26 11:52:00 | 00,020,240 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys -- (L8042Kbd [On_Demand | Stopped])
DRV - [2008/09/26 11:52:00 | 00,035,472 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys -- (LHidFilt [On_Demand | Stopped])
DRV - [2008/09/26 11:53:00 | 00,037,392 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys -- (LMouFilt [On_Demand | Stopped])
DRV - [2008/09/26 11:53:00 | 00,028,816 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\System32\Drivers\LUsbFilt.Sys -- (LUsbFilt [On_Demand | Stopped])
DRV - [2008/02/05 18:18:12 | 00,689,176 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys -- (LVcKap [On_Demand | Stopped])
DRV - [2008/02/05 18:20:08 | 00,025,624 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon [On_Demand | Running])
DRV - [2008/02/06 04:21:24 | 00,041,752 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta [On_Demand | Running])
DRV - [2001/08/18 00:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Running])
DRV - [2009/01/16 03:42:00 | 06,305,120 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2008/08/01 10:36:20 | 00,054,784 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2008/08/01 10:36:26 | 00,022,016 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2008/08/25 02:22:40 | 00,014,208 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvsmu.sys -- (nvsmu [On_Demand | Running])
DRV - [2009/01/23 23:33:05 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Stopped])
DRV - [2002/11/11 20:52:54 | 00,006,400 | ---- | M] (Pinnacle Systems) -- C:\WINDOWS\system32\DRIVERS\pctvvbi.sys -- (pctvvbi [On_Demand | Running])
DRV - [2008/02/06 04:17:26 | 00,013,848 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\lv302af.sys -- (pepifilter [On_Demand | Stopped])
DRV - [2002/06/17 15:09:56 | 00,014,604 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc [On_Demand | Running])
DRV - [2008/02/06 04:17:36 | 02,570,520 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LV302V32.SYS -- (PID_PEPI [On_Demand | Stopped])
DRV - [2004/08/05 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2003/02/10 16:14:00 | 00,017,664 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\DRIVERS\rob_a.sys -- (ROB_A [Auto | Stopped])
DRV - [2003/04/11 18:26:08 | 00,125,568 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\drivers\rob_v.sys -- (ROB_V [Auto | Stopped])
DRV - [2007/11/13 12:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2006/01/18 14:08:54 | 00,402,432 | ---- | M] (ZyDAS Technology Corporation) -- C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys -- (SG762_XP [On_Demand | Stopped])
DRV - [2009/03/24 14:54:10 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2009/02/13 12:49:30 | 00,028,376 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2008/04/13 11:45:14 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV - [2008/04/13 18:57:14 | 00,032,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\wceusbsh.sys -- (wceusbsh [System | Stopped])
DRV - [2006/01/18 14:08:56 | 00,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\Drivers\ZDPSp50.sys -- (ZDPSp50 [On_Demand | Running])

[color=orange]========== Standard Registry (SafeList) ==========[/color]


[color=orange]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\S-1-5-21-1844237615-2052111302-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=orange]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.fr/?gws_rd=ssl"
FF - prefs.js..extensions.enabledItems: {e411bb40-b04c-11d8-92e7-00d09e0179f2}:3.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {bb628310-0ab7-11db-9cd8-0800200c9a66}:3.5.0.0
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11


FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/10 16:17:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/14 00:17:07 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/14 00:17:07 | 00,000,000 | ---D | M]

[2008/07/07 00:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Extensions
[2008/07/07 00:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/14 23:28:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions
[2009/04/02 01:17:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/23 13:01:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}
[2008/12/13 00:14:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\{e411bb40-b04c-11d8-92e7-00d09e0179f2}
[2009/05/15 00:33:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\mozilla\Firefox\Profiles\bupj6usf.default\extensions\firefox@tvunetworks.com
[2008/05/03 19:31:03 | 00,001,678 | ---- | M] () -- C:\Documents and Settings\m\Application Data\Mozilla\FireFox\Profiles\bupj6usf.default\searchplugins\blurps.xml
[2009/03/24 14:57:25 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\m\Application Data\Mozilla\FireFox\Profiles\bupj6usf.default\searchplugins\daemon-search.xml
[2009/06/14 23:28:30 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/14 00:17:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/04/21 05:38:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/09 22:33:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/12/10 16:17:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/01 02:15:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/14 00:17:02 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/14 00:17:02 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/12/19 21:46:04 | 00,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2008/12/19 21:46:04 | 00,000,757 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2008/12/19 21:46:04 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/19 21:46:04 | 00,000,748 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MediaDICO-fr.xml
[2008/12/19 21:46:04 | 00,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2008/12/19 21:46:04 | 00,000,652 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Aide pour le lien d'Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized (GRISOFT s.r.o.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min (Avira GmbH)
O4 - HKLM..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe" (Lexmark International Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
O4 - HKLM..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" (Lexmark International, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [Google Update] "C:\Documents and Settings\m\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [Steam] "c:\program files\steam\steam.exe" -silent (Valve Corporation)
O4 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk = C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe (WIDCOMM, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Pinnacle Scheduler.lnk = C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe (Pinnacle Systems GmbH, Braunschweig)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = C:\Program Files\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter\WLANUTL.exe ( )
O4 - Startup: C:\Documents and Settings\m\Menu Démarrer\Programmes\Démarrage\Registration-PCTV.lnk = C:\Program Files\Pinnacle\Pinnacle PCTV\ERegister\RegTool.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\S-1-5-21-1844237615-2052111302-725345543-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm ()
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} https://www.eset.com/ (Reg Error: Key error.)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} http://charon888.free.fr/plugins/hardwaredetection_2_0_4_13.cab (HardwareDetection Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} https://zone.msn.com/en/utility/handler404.aspx?404;http://zone.msn.com:80/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab (ChessControl Class)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab (MSN Games – Backgammon)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Fichiers communs\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (GRISOFT s.r.o.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/20 04:25:14 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/06/11 01:14:41 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/15 15:33:21 | 00,000,000 | ---D | M]

[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]

[8 C:\WINDOWS\System32\*.tmp files]
[11 C:\WINDOWS\*.tmp files]
[2009/06/14 21:30:00 | 15,507,437 | ---- | C] () -- C:\Documents and Settings\m\Mes documents\La guerre russo-japonaise.pdf
[2009/06/12 21:31:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Application Data\Grisoft
[2009/06/12 21:31:35 | 00,000,849 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\AVG Anti-Spyware.lnk
[2009/06/12 21:31:30 | 00,010,872 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\AvgAsCln.sys
[2009/06/12 21:31:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/06/12 21:31:24 | 00,000,000 | ---D | C] -- C:\Program Files\Grisoft
[2009/06/12 21:30:22 | 12,413,440 | ---- | C] () -- C:\Documents and Settings\m\Bureau\avg-anti-spyware_avg_anti-spyware_7.5.1.36_francais_27645.exe
[2009/06/11 23:36:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Local Settings\temp
[2009/06/11 23:14:47 | 00,000,216 | ---- | C] () -- C:\Boot.bak
[2009/06/11 23:14:44 | 00,263,488 | ---- | C] () -- C:\cmldr
[2009/06/11 23:14:43 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/06/11 23:13:00 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/06/11 23:12:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/11 23:12:46 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF6892.exe
[2009/06/11 19:58:38 | 00,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2009/06/11 19:52:46 | 00,006,045 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2009/06/11 01:30:47 | 00,001,372 | ---- | C] () -- C:\Documents and Settings\m\Bureau\FindyKill V5.002.lnk
[2009/06/11 01:30:46 | 00,000,000 | ---D | C] -- C:\FindyKill
[2009/06/11 01:14:41 | 00,000,000 | RHSD | C] -- C:\autorun.inf
[2009/06/11 00:26:13 | 00,001,336 | ---- | C] () -- C:\Documents and Settings\m\Bureau\UsbFix V3.029.lnk
[2009/06/11 00:26:12 | 00,000,000 | ---D | C] -- C:\UsbFix
[2009/06/09 13:51:05 | 00,426,346 | ---- | C] () -- C:\Documents and Settings\m\Mes documents\cc_20090609_135104.reg
[2009/06/04 13:50:15 | 00,000,000 | ---D | C] -- C:\Program Files\FireFly Studios
[2009/06/04 13:50:14 | 00,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2009/06/04 11:14:59 | 00,079,871 | ---- | C] () -- C:\Documents and Settings\m\Bureau\Conditions_Specifiques_de_Vente_Pret_a_Expedier_Lettre_Max_Classique_et_Monaco-2.pdf
[2009/05/31 23:31:11 | 00,077,221 | ---- | C] () -- C:\Documents and Settings\m\Bureau\Invoice_Apr-01-09_Apr-30-09.csv
[2009/05/27 11:59:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Bureau\Bureau
[2009/05/24 20:25:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Bureau\Nouveau dossier
[2009/05/24 14:42:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Mes documents\FFOutput
[2009/05/23 13:23:28 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidserv.dll
[2009/05/23 13:07:36 | 00,018,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nuidfltr.sys
[2009/05/18 00:10:42 | 75,087,2474 | ---- | C] () -- C:\Documents and Settings\m\Bureau\NBA.2009.5.16.Kobe.Doin.Work.x264-albert.mp4
[2009/05/17 16:21:53 | 00,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\Logitech
[2009/05/16 22:40:16 | 00,479,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_0.dll
[2009/05/16 22:40:15 | 01,420,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_37.dll
[2009/05/16 22:40:15 | 00,462,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_37.dll
[2009/05/16 22:40:15 | 00,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_0.dll
[2009/05/16 22:40:15 | 00,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_3.dll
[2009/05/16 22:40:14 | 03,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_37.dll
[2009/05/16 22:40:14 | 00,267,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_10.dll
[2009/05/16 22:40:13 | 01,374,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_36.dll
[2009/05/16 22:40:13 | 00,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_36.dll
[2009/05/16 22:40:12 | 03,734,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_36.dll
[2009/05/16 22:40:11 | 00,267,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_9.dll
[2009/05/16 22:40:10 | 03,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_35.dll
[2009/05/16 22:40:10 | 01,358,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_35.dll
[2009/05/16 22:40:10 | 00,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_35.dll
[2009/05/16 22:39:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xlive
[2009/05/16 22:12:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\m\Mes documents\Battlefield 2142
[2009/05/16 22:11:57 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\m\Application Data\SecuROM
[2009/05/16 22:11:56 | 00,107,888 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009/05/16 21:47:56 | 00,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Avira AntiVir Control Center.lnk
[2009/05/16 21:47:23 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/05/16 21:47:23 | 00,055,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/05/16 21:47:23 | 00,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/05/16 21:47:23 | 00,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/05/16 21:47:11 | 00,000,000 | ---D | C] -- C:\Program Files\Avira
[2009/05/16 21:47:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2009/05/16 21:32:10 | 00,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2009/05/16 21:23:01 | 30,143,928 | ---- | C] () -- C:\Documents and Settings\m\Bureau\avira_antivir_personal_free.exe
[2009/05/01 00:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/01 00:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/05/01 00:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/05/01 00:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/04/19 01:47:50 | 00,000,379 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/03/30 15:38:00 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\DataMatrix.dll
[2009/03/30 15:38:00 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\PDF417.dll
[2009/03/24 14:54:09 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/03/24 14:19:03 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2009/03/20 13:11:41 | 01,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgusb1.dll
[2009/03/20 13:11:41 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcgvs.dll
[2009/03/20 13:11:40 | 01,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgserv.dll
[2009/03/20 13:11:40 | 00,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgprox.dll
[2009/03/20 13:11:40 | 00,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgpplc.dll
[2009/03/20 13:11:39 | 00,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomc.dll
[2009/03/20 13:11:39 | 00,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcglmpm.dll
[2009/03/20 13:11:39 | 00,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomm.dll
[2009/03/20 13:11:34 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\lxcgjswr.dll
[2009/03/20 13:11:34 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\lxcginsr.dll
[2009/03/20 13:11:33 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\lxcgcur.dll
[2009/03/12 14:31:51 | 00,000,536 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2009/01/12 16:25:33 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008/11/29 15:24:34 | 00,014,025 | ---- | C] () -- C:\WINDOWS\TWAINCAP.INI
[2008/11/29 15:21:42 | 00,138,752 | ---- | C] () -- C:\WINDOWS\System32\Mase32.dll
[2008/11/29 15:21:42 | 00,057,856 | ---- | C] () -- C:\WINDOWS\System32\Masd32.dll
[2008/11/29 15:21:41 | 00,196,096 | ---- | C] () -- C:\WINDOWS\System32\Macd32.dll
[2008/11/29 15:21:41 | 00,136,192 | ---- | C] () -- C:\WINDOWS\System32\Mamc32.dll
[2008/11/29 15:21:41 | 00,027,648 | ---- | C] () -- C:\WINDOWS\System32\Ma32.dll
[2008/11/23 01:43:15 | 00,000,225 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/10/02 19:33:35 | 00,000,173 | ---- | C] () -- C:\WINDOWS\OPHC.INI
[2008/10/02 19:31:03 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\OPHCTH32.DLL
[2008/10/02 19:31:03 | 00,000,640 | R--- | C] () -- C:\WINDOWS\System32\OPHCTH16.DLL
[2008/07/21 19:51:01 | 00,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/07/21 19:51:01 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/05/29 01:54:31 | 00,001,162 | ---- | C] () -- C:\WINDOWS\System32\W32N55.INI
[2008/05/11 22:12:55 | 00,066,482 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2008/02/05 18:20:08 | 00,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/12/05 01:41:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/26 21:56:28 | 00,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2005/03/14 15:38:28 | 00,000,469 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2004/08/05 14:00:00 | 00,000,648 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/05 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/09/19 15:35:38 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\btsendto_ie.dll
[2003/09/19 15:34:40 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\btsendto_wab.dll
[2003/09/19 15:27:38 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2003/09/19 15:14:42 | 00,022,183 | ---- | C] () -- C:\WINDOWS\System32\drivers\btserial.sys
[2003/03/24 10:38:06 | 02,842,624 | ---- | C] () -- C:\WINDOWS\System32\btrez.dll
[2002/05/15 23:29:04 | 00,000,607 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2001/11/23 18:18:00 | 00,000,597 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 13:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

[color=orange]========== Files - Modified Within 30 Days ==========[/color]

[8 C:\WINDOWS\System32\*.tmp files]
[11 C:\WINDOWS\*.tmp files]
[2009/06/15 15:37:57 | 00,473,864 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2009/06/15 15:37:57 | 00,405,888 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/06/15 15:37:57 | 00,077,468 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2009/06/15 15:37:57 | 00,063,470 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/06/15 15:37:56 | 01,033,152 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/06/15 15:33:35 | 00,202,392 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/06/15 15:33:30 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/15 15:33:29 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\m\Local Settings\desktop.ini
[2009/06/15 15:33:24 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/14 21:30:12 | 00,122,368 | -HS- | M] () -- C:\Documents and Settings\m\Mes documents\Thumbs.db
[2009/06/14 21:30:01 | 15,507,437 | ---- | M] () -- C:\Documents and Settings\m\Mes documents\La guerre russo-japonaise.pdf
[2009/06/14 20:55:40 | 00,001,078 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-2052111302-725345543-1004.job
[2009/06/14 07:00:51 | 00,002,252 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Google Chrome.lnk
[2009/06/12 21:31:35 | 00,000,849 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\AVG Anti-Spyware.lnk
[2009/06/12 21:31:09 | 12,413,440 | ---- | M] () -- C:\Documents and Settings\m\Bureau\avg-anti-spyware_avg_anti-spyware_7.5.1.36_francais_27645.exe
[2009/06/12 11:35:54 | 00,115,768 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/11 23:32:19 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/06/11 23:32:08 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/06/11 23:14:47 | 00,000,286 | RHS- | M] () -- C:\boot.ini
[2009/06/11 23:08:34 | 00,401,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF6892.exe
[2009/06/11 20:01:03 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/11 01:30:47 | 00,001,372 | ---- | M] () -- C:\Documents and Settings\m\Bureau\FindyKill V5.002.lnk
[2009/06/11 00:26:13 | 00,001,336 | ---- | M] () -- C:\Documents and Settings\m\Bureau\UsbFix V3.029.lnk
[2009/06/09 13:51:11 | 00,426,346 | ---- | M] () -- C:\Documents and Settings\m\Mes documents\cc_20090609_135104.reg
[2009/06/09 13:41:09 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\m\Bureau\CCleaner.lnk
[2009/06/08 16:22:51 | 00,002,193 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Steam.lnk
[2009/06/08 13:50:28 | 00,933,772 | -HS- | M] () -- C:\Documents and Settings\m\Bureau\Thumbs.db
[2009/06/08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009/06/04 11:15:00 | 00,079,871 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Conditions_Specifiques_de_Vente_Pret_a_Expedier_Lettre_Max_Classique_et_Monaco-2.pdf
[2009/06/01 18:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/31 23:31:13 | 00,077,221 | ---- | M] () -- C:\Documents and Settings\m\Bureau\Invoice_Apr-01-09_Apr-30-09.csv
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/18 15:17:08 | 75,087,2474 | ---- | M] () -- C:\Documents and Settings\m\Bureau\NBA.2009.5.16.Kobe.Doin.Work.x264-albert.mp4
[2009/05/16 22:11:56 | 00,107,888 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009/05/16 21:47:56 | 00,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Avira AntiVir Control Center.lnk
[2009/05/16 21:26:40 | 30,143,928 | ---- | M] () -- C:\Documents and Settings\m\Bureau\avira_antivir_personal_free.exe

[color=orange]========== LOP Check ==========[/color]

[2009/06/12 21:31:28 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/12/28 15:02:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/05/16 21:47:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avira
[2008/07/21 19:52:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2009/03/24 14:57:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/01/21 19:40:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2009/06/12 21:31:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/11/23 01:18:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/06/21 15:14:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/06/11 18:45:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ma-config.com
[2009/04/12 20:45:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/19 01:45:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/04/25 20:00:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2009/04/12 22:14:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/11/25 00:49:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/03/12 14:31:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/06/11 10:48:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/09/21 20:41:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/04/20 06:12:33 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Application Data
[2008/04/20 04:25:12 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Default User\Application Data\Microsoft
[2008/04/28 14:28:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data
[2008/04/28 14:29:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2008/06/11 10:49:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/06/12 21:31:40 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\m\Application Data
[2008/04/22 19:21:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\Adobe
[2009/05/15 00:47:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\AVS4YOU
[2009/03/24 14:58:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\DAEMON Tools
[2009/03/24 15:01:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\DAEMON Tools Lite
[2009/03/24 14:58:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\DAEMON Tools Pro
[2008/08/19 21:34:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\Application Data\dvdcss
[2008/09/20 22:17:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\m\
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

les restrictions sont recréées.

Tu es administrateur de ton ordi sur la session que tu utilises ?

Quels sont tes soucis actuels ?
0
jojo
 
SALUT

EZN ALLUMANT OTL ce rapport s'est affiché tout seul


========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Expl­­orer not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1844237615-2052111302-725345543-1004\Software\P­­olicies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-1844237615-2052111302-725345543-1004\SOFTWARE\M­­icrosoft\Windows\CurrentVersion\policies\Explorer not found.
Registry key HKEY_USERS\S-1-5-21-1844237615-2052111302-725345543-1004_Classes\So­­ftware\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:lsdelete scheduled to be deleted on reboot.
File C:\WINDOWS\System32\lsdelete.exe not found.
File C:\sqmnoopt19.sqm not found.
File C:\sqmdata19.sqm not found.
File C:\sqmnoopt18.sqm not found.
File C:\sqmdata18.sqm not found.
File C:\sqmnoopt17.sqm not found.
File C:\sqmdata17.sqm not found.
File C:\sqmnoopt16.sqm not found.
File C:\sqmdata16.sqm not found.
File C:\sqmnoopt15.sqm not found.
File C:\sqmdata15.sqm not found.
File C:\sqmnoopt14.sqm not found.
File C:\sqmdata14.sqm not found.
File C:\sqmnoopt13.sqm not found.
File C:\sqmdata13.sqm not found.
File C:\sqmnoopt12.sqm not found.
File C:\sqmdata12.sqm not found.
File C:\sqmnoopt11.sqm not found.
File C:\sqmdata11.sqm not found.
File C:\sqmnoopt10.sqm not found.
File C:\sqmdata10.sqm not found.
File C:\sqmnoopt09.sqm not found.
File C:\sqmdata09.sqm not found.
File C:\sqmnoopt08.sqm not found.
File C:\sqmdata08.sqm not found.
File C:\sqmnoopt07.sqm not found.
File C:\sqmdata07.sqm not found.
File C:\sqmnoopt06.sqm not found.
File C:\sqmdata06.sqm not found.
File C:\sqmnoopt05.sqm not found.
File C:\sqmdata05.sqm not found.
File C:\sqmnoopt04.sqm not found.
File C:\sqmdata04.sqm not found.
C:\sqmnoopt03.sqm moved successfully.
C:\sqmdata03.sqm moved successfully.
C:\sqmnoopt02.sqm moved successfully.
C:\sqmdata02.sqm moved successfully.
C:\sqmnoopt01.sqm moved successfully.
C:\sqmdata01.sqm moved successfully.
C:\sqmnoopt00.sqm moved successfully.
C:\sqmdata00.sqm moved successfully.

OTL by OldTimer - Version 2.1.1.0 log created on 06152009_232811

Files moved on Reboot...

Registry entries deleted on Reboot...
Registry delete failed. :HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:lsdelete scheduled to be deleted on reboot.
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

on va essayer comme ça :

débranche ton imprimante

Panneau de configuration, Imprimantes et télécopieurs.

Clic droit sur ton imprimante et Supprimer.

Fais redémarrer l'ordi.

Vérifie que l'imprimante est bien supprimé de la liste dans le panneau de configuration.

Branche l'imprimante.

Il se passe quoi ?

0