UC en permanence a 100 %

Fermé
Oxay Messages postés 104 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 11 juin 2017 - 22 juil. 2009 à 18:41
fix200 Messages postés 3243 Date d'inscription dimanche 28 décembre 2008 Statut Contributeur sécurité Dernière intervention 7 février 2011 - 27 juil. 2009 à 16:00
Bonjour,

mon UC est toujours à 100 % j'ai fait un rapport random's information tools,

Merci pour votre aide.


Logfile of random's system information tool 1.06 (written by random/random)
Run by Xavier at 2009-07-22 18:39:10
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 17 GB (23%) free of 73 GB
Total RAM: 2038 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:39:21, on 22/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Xavier\Bureau\RSIT.exe
C:\Program Files\trend micro\Xavier.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.r4v3n.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 88.198.6.227 l2authd.lineage2.com # m0o age
O1 - Hosts: 88.198.6.227 L2testauthd.lineage2.com #m0o age
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Policies\Explorer\Run: [none] C:\Program Files\Video ActiveX Object\pmsngr.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - https://www.f-secure.com/en/home/support
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E5BCAA2-E3A4-43EF-A395-394669155BD0}: NameServer = 212.27.54.252,215.27.53.252
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

43 réponses

fix200 Messages postés 3243 Date d'inscription dimanche 28 décembre 2008 Statut Contributeur sécurité Dernière intervention 7 février 2011 158
27 juil. 2009 à 11:35
Supprime tes cracks ,

Puis :

Relances OTL COMME EXPLIQUE : https://forums.commentcamarche.net/forum/affich-13492961-uc-en-permanence-a-100?page=2#20

+
0
Oxay Messages postés 104 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 11 juin 2017
27 juil. 2009 à 15:43
Pour le crack j'ai supprimé suuelement le fichier .exe, dois je supprimer aussi tout le fichier qui le contient?





Voici le rappport :


OTL logfile created on: 27/07/2009 15:33:34 - Run 3
OTL by OldTimer - Version 3.0.10.0 Folder = C:\Documents and Settings\Xavier\Bureau\PLUMEAU POUR PC
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

1,99 Gb Total Physical Memory | 1,41 Gb Available Physical Memory | 70,73% Memory free
2,58 Gb Paging File | 2,09 Gb Available in Paging File | 81,03% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71,45 Gb Total Space | 28,69 Gb Free Space | 40,16% Space Free | Partition Type: NTFS
Drive D: | 683,54 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DBV8W02J
Current User Name: Xavier
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2009/07/11 06:03:52 | 00,362,184 | ---- | M] (Tall Emu) -- C:\Program Files\Tall Emu\Online Armor\OAcat.exe
PRC - [2009/07/11 06:03:44 | 03,142,344 | ---- | M] (Tall Emu) -- C:\Program Files\Tall Emu\Online Armor\oasrv.exe
PRC - [2009/05/13 16:47:40 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/05/11 10:15:13 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/02/15 15:53:13 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/04/14 04:34:03 | 01,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009/03/02 13:08:11 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009/07/11 06:03:32 | 02,121,416 | ---- | M] (Tall Emu) -- C:\Program Files\Tall Emu\Online Armor\oaui.exe
PRC - [2009/02/06 19:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2009/07/11 06:03:42 | 01,033,928 | ---- | M] (Tall Emu) -- C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
PRC - [2009/02/06 18:07:48 | 00,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/12/19 14:54:18 | 07,678,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/08/11 17:46:50 | 21,741,864 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
PRC - [2008/08/11 17:46:50 | 00,076,744 | R--- | M] (Skype Technologies) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe
PRC - [2009/07/23 17:27:55 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Xavier\Bureau\PLUMEAU POUR PC\OTL.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2006/12/31 15:15:28 | 00,072,704 | ---- | M] (Adobe Systems) -- C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [Disabled | Stopped])
SRV - [2009/05/13 16:47:40 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running])
SRV - [2009/05/11 10:15:13 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2007/03/20 03:19:14 | 00,263,168 | ---- | M] (Ares Development Group) -- C:\Program Files\Ares\chatServer.exe -- (AresChatServer [Disabled | Stopped])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/12/20 15:32:08 | 00,069,120 | ---- | M] (BOONTY) -- C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe -- (Boonty Games [On_Demand | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/04/14 04:33:38 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [Disabled | Stopped])
SRV - [2006/06/14 16:23:58 | 00,323,584 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPodService [On_Demand | Stopped])
SRV - [2009/02/15 15:53:13 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2004/11/19 13:26:40 | 00,147,456 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc [Disabled | Stopped])
SRV - [2009/07/11 06:03:52 | 00,362,184 | ---- | M] (Tall Emu) -- C:\Program Files\Tall Emu\Online Armor\OAcat.exe -- (OAcat [Auto | Running])
SRV - [2004/09/29 12:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Disabled | Stopped])
SRV - File not found -- -- (Slave [Disabled | Stopped])
SRV - [2009/07/11 06:03:44 | 03,142,344 | ---- | M] (Tall Emu) -- C:\Program Files\Tall Emu\Online Armor\oasrv.exe -- (SvcOnlineArmor [Auto | Running])
SRV - [2006/11/03 10:59:14 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [Disabled | Stopped])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2001/08/17 23:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde [Disabled | Stopped])
DRV - [2008/04/13 20:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp [Disabled | Stopped])
DRV - [2001/08/17 23:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc [Disabled | Stopped])
DRV - [2001/08/17 23:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550 [Disabled | Stopped])
DRV - [2009/02/13 12:34:33 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio [System | Running])
DRV - [2009/03/24 16:07:58 | 00,055,640 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avgntflt.sys -- (avgntflt [Auto | Running])
DRV - [2009/03/30 10:32:47 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2001/08/23 19:04:44 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde [Disabled | Stopped])
DRV - [2001/08/17 23:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k [Disabled | Stopped])
DRV - [2004/12/01 05:22:00 | 00,087,488 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb [Boot | Running])
DRV - [2004/11/23 04:56:00 | 00,040,480 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\drvnddm.sys -- (drvnddm [Auto | Running])
DRV - [2004/10/14 10:30:46 | 00,155,648 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Running])
DRV - [2005/02/02 01:21:04 | 00,014,408 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2008/04/13 18:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2005/03/08 06:43:25 | 00,051,120 | R--- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2005/03/08 06:43:26 | 00,016,496 | R--- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2005/03/08 06:43:27 | 00,021,744 | R--- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2005/07/20 01:34:22 | 01,049,180 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running])
DRV - [2001/08/17 23:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x [Disabled | Stopped])
DRV - [2004/08/04 00:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Stopped])
DRV - [2009/07/11 05:17:00 | 00,200,784 | ---- | M] (Tall Emu) -- C:\WINDOWS\System32\drivers\OADriver.sys -- (OADevice [System | Running])
DRV - [2009/07/11 05:17:14 | 00,024,656 | ---- | M] (Tall Emu) -- C:\WINDOWS\System32\drivers\OAmon.sys -- (OAmon [System | Running])
DRV - [2009/07/11 06:04:40 | 00,029,776 | ---- | M] (Tall Emu Pty Ltd) -- C:\WINDOWS\System32\drivers\OAnet.sys -- (OAnet [System | Running])
DRV - [2002/06/10 15:16:34 | 00,371,766 | ---- | M] (Philips Semiconductors) -- C:\WINDOWS\System32\DRIVERS\CamDrL21.sys -- (PhilCam8116 [On_Demand | Running])
DRV - [2004/03/30 17:29:48 | 00,374,816 | R--- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\PRISMA02.sys -- (PRISM_A02 [On_Demand | Stopped])
DRV - [2004/08/05 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2007/08/16 00:33:10 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2001/08/17 23:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080 [Disabled | Stopped])
DRV - [2001/08/17 23:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160 [Disabled | Stopped])
DRV - [2001/08/17 23:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280 [Disabled | Stopped])
DRV - [2007/11/13 12:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008/04/13 20:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp [Disabled | Stopped])
DRV - [2001/08/17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
DRV - [2001/08/18 00:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow [Disabled | Stopped])
DRV - [2004/07/14 13:29:04 | 00,005,627 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\sscdbhk5.sys -- (sscdbhk5 [System | Running])
DRV - [2009/05/11 10:11:52 | 00,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2004/07/14 13:28:50 | 00,023,545 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\ssrtln.sys -- (ssrtln [System | Running])
DRV - [2005/08/17 08:41:08 | 01,022,040 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\System32\drivers\sthda.sys -- (STHDA [On_Demand | Running])
DRV - [2001/08/18 00:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810 [Disabled | Stopped])
DRV - [2001/08/18 00:07:36 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx [Disabled | Stopped])
DRV - [2001/08/18 00:07:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi [Disabled | Stopped])
DRV - [2001/08/18 00:07:42 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3 [Disabled | Stopped])
DRV - [2004/12/06 03:05:00 | 00,025,883 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnboio.sys -- (tfsnboio [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,034,843 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsncofs.sys -- (tfsncofs [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,004,123 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsndrct.sys -- (tfsndrct [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,002,271 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsndres.sys -- (tfsndres [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,086,586 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnifs.sys -- (tfsnifs [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,015,227 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnopio.sys -- (tfsnopio [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,006,363 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnpool.sys -- (tfsnpool [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,098,714 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnudf.sys -- (tfsnudf [Auto | Running])
DRV - [2004/12/06 03:05:00 | 00,100,603 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnudfa.sys -- (tfsnudfa [Auto | Running])
DRV - [2006/08/07 05:16:00 | 00,076,560 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys -- (tmcomm [Auto | Running])
DRV - [2001/08/17 23:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra [Disabled | Stopped])
DRV - [2008/04/13 20:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Running])
DRV - [2005/08/30 00:05:00 | 00,021,344 | ---- | M] (LG Electronics Inc.) -- C:\WINDOWS\System32\DRIVERS\lgusbbus.sys -- (usbbus [On_Demand | Stopped])
DRV - [2005/08/30 00:05:00 | 00,038,144 | ---- | M] (LG Electronics Inc.) -- C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys -- (UsbDiag [On_Demand | Stopped])
DRV - [2005/08/30 00:05:00 | 00,039,248 | ---- | M] (LG Electronics Inc.) -- C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys -- (USBModem [On_Demand | Stopped])

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = https://www.dell.com/fr-fr
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.dell.com/fr-fr
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = https://www.dell.com/fr-fr
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.dell.com/fr-fr
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_search_url = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/saautosearch.aspx
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\S-1-5-21-2624756784-3029327782-2234701255-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\S-1-5-21-2624756784-3029327782-2234701255-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.free.fr:3128

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..network.proxy.http: "213.41.71.164"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.type: 4

FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/19 22:26:57 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/05/31 15:13:25 | 00,000,000 | ---D | M]

[2009/06/17 18:02:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\mozilla\Firefox\Profiles\ra8a3qlo.default\extensions
[2007/10/19 16:40:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\mozilla\Firefox\Profiles\ra8a3qlo.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/31 15:56:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\mozilla\Firefox\Profiles\ra8a3qlo.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/06/08 11:23:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\mozilla\Firefox\Profiles\ra8a3qlo.default\extensions\searchrecs@veoh.com
[2009/06/17 18:02:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2008/12/19 14:54:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/01/14 13:06:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/01/15 19:52:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/15 16:36:18 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/14 12:46:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/02/15 15:53:36 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2008/12/19 14:54:23 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\talkback@mozilla.org
[2008/12/19 14:54:07 | 00,067,688 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jar50.dll
[2008/12/19 14:54:08 | 00,054,368 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jsd3250.dll
[2008/12/19 14:54:08 | 00,034,944 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\myspell.dll
[2008/12/19 14:54:09 | 00,046,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\spellchk.dll
[2008/12/19 14:54:09 | 00,172,136 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\xpinstal.dll
[2007/08/07 14:35:32 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/02/15 15:53:13 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/11/06 18:33:48 | 01,332,224 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2008/07/23 18:47:46 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2008/12/19 14:54:20 | 00,022,656 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/05/28 11:42:35 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2007/05/28 11:42:36 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2007/05/28 11:42:36 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2007/05/28 11:42:36 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2007/05/28 11:42:36 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2007/05/28 11:42:36 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2007/05/28 11:42:36 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/12/19 14:54:22 | 00,001,529 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2008/12/19 14:54:22 | 00,001,072 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2008/12/19 14:54:22 | 00,002,368 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/19 14:54:22 | 00,000,760 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\MediaDICO-fr.xml
[2008/12/19 14:54:22 | 00,001,441 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2008/12/19 14:54:22 | 00,000,664 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Tall Emu\Online Armor\oaui.exe (Tall Emu)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
O4 - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Xavier\Menu Démarrer\Programmes\Démarrage\adsl TV.LNK = C:\Program Files\adslTV\adsltv.exe (adsltv.org)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-20\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-2624756784-3029327782-2234701255-1006\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Fichiers communs\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/html - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Tall Emu\Online Armor\oaevent.dll (Tall Emu)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/20 12:37:16 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [1998/12/13 16:43:32 | 00,000,040 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\SETUP.EXE -- [1998/12/01 14:04:40 | 00,025,600 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2009/07/27 15:31:43 | 00,000,011 | ---- | C] () -- C:\AuResult.ini
[2009/07/26 21:16:56 | 21,371,49440 | -HS- | C] () -- C:\hiberfil.sys
[2009/07/26 20:47:51 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\Ad-remover.lnk
[2009/07/26 20:47:51 | 00,000,000 | ---D | C] -- C:\Program Files\Ad-remover
[2009/07/25 12:25:08 | 00,000,688 | ---- | C] () -- C:\Documents and Settings\Xavier\Menu Démarrer\Programmes\Démarrage\adsl TV.LNK
[2009/07/25 02:19:40 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009/07/25 02:19:40 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009/07/24 13:09:46 | 00,000,466 | ---- | C] () -- C:\WINDOWS\tasks\Wise Registry Cleaner 4.job
[2009/07/24 13:07:45 | 00,000,000 | ---D | C] -- C:\Program Files\Wise Registry Cleaner
[2009/07/24 13:05:10 | 00,004,472 | ---- | C] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090724_1305.reg
[2009/07/24 12:06:21 | 22,075,43807 | ---- | C] () -- C:\Documents and Settings\Xavier\Mes documents\adsl TV 2009-07-24 12-06-10 France 24 (Web TV).mpg
[2009/07/23 23:00:56 | 00,002,086 | ---- | C] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090723_2300.reg
[2009/07/23 20:53:31 | 00,000,654 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\adsl TV.lnk
[2009/07/23 20:52:48 | 00,000,000 | ---D | C] -- C:\Program Files\adslTV
[2009/07/23 20:51:47 | 29,351,126 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\setup-adsltv.exe
[2009/07/23 18:26:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/07/23 18:23:17 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/07/23 18:21:49 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/07/23 18:21:45 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/07/23 18:21:44 | 01,985,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/07/23 18:21:44 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/07/23 18:21:42 | 11,064,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/07/23 18:20:41 | 17,001,840 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Xavier\Bureau\IE8-WindowsXP-x86-FRA.exe
[2009/07/23 17:54:02 | 00,000,000 | ---D | C] -- C:\_OTL
[2009/07/23 17:19:24 | 00,036,490 | ---- | C] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090723_1719.reg
[2009/07/23 00:05:43 | 00,000,000 | ---D | C] -- C:\rsit
[2009/07/22 23:58:29 | 00,000,164 | ---- | C] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090722_2358.reg
[2009/07/22 23:57:57 | 00,315,914 | ---- | C] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090722_2357.reg
[2009/07/22 23:50:39 | 00,000,000 | ---D | C] -- C:\_OTM
[2009/07/22 21:39:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Bureau\Upload_Me
[2009/07/22 21:16:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Application Data\OnlineArmor
[2009/07/22 21:16:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\OnlineArmor
[2009/07/22 21:15:55 | 00,024,656 | ---- | C] (Tall Emu) -- C:\WINDOWS\System32\drivers\OAmon.sys
[2009/07/22 21:15:54 | 00,200,784 | ---- | C] (Tall Emu) -- C:\WINDOWS\System32\drivers\OADriver.sys
[2009/07/22 21:15:54 | 00,029,776 | ---- | C] (Tall Emu Pty Ltd) -- C:\WINDOWS\System32\drivers\OAnet.sys
[2009/07/22 21:15:53 | 00,000,000 | ---D | C] -- C:\Program Files\Tall Emu
[2009/07/22 21:15:06 | 10,233,408 | ---- | C] (Tall Emu Pty Ltd ) -- C:\Documents and Settings\Xavier\Bureau\OnlineArmor_Setup_Free_FRA.exe
[2009/07/22 21:07:13 | 00,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Avira AntiVir Control Center.lnk
[2009/07/22 21:07:03 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/07/22 21:07:03 | 00,055,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/07/22 21:07:03 | 00,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/07/22 21:07:03 | 00,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/07/22 21:07:01 | 00,000,000 | ---D | C] -- C:\Program Files\Avira
[2009/07/22 21:07:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2009/07/22 21:03:28 | 32,373,416 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\avira_antivir_personal_fr.exe
[2009/07/22 20:10:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Bureau\PLUMEAU POUR PC
[2009/07/22 20:00:27 | 00,000,000 | ---D | C] -- C:\Program Files\WinDirStat
[2009/07/22 19:19:13 | 00,000,000 | ---D | C] -- C:\UsbFix
[2009/07/22 18:57:34 | 00,000,000 | ---D | C] -- C:\Program Files\Navilog1
[2009/07/22 18:44:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Application Data\Malwarebytes
[2009/07/22 18:44:14 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/22 18:44:12 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/22 18:44:12 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/22 18:44:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/07/22 18:43:10 | 03,775,176 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Xavier\Bureau\mbam-setup.exe
[2009/07/22 18:23:09 | 57,062,576 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\TRACE_BOOT+DRIVERS_1_1.BIN
[2009/07/22 18:19:38 | 00,336,752 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\BootVis-Tool.exe
[2009/07/22 18:00:33 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1}
[2009/07/18 14:56:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Bureau\Adobe Premiere Pro CS3
[2009/07/18 11:31:26 | 00,023,923 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\DETRESSE2.sxw
[2009/07/18 10:29:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Local Settings\Application Data\P5
[2009/07/18 10:29:54 | 00,000,000 | ---D | C] -- C:\Winamax
[2009/07/18 10:25:01 | 01,063,336 | ---- | C] (winamax ) -- C:\Documents and Settings\Xavier\Bureau\Install_Winamax.exe
[2009/07/16 01:53:49 | 00,003,913 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\6208_101626037790_546852790_2586424_3628578_s.jpg
[2009/07/14 21:41:26 | 00,000,000 | ---D | C] -- C:\Program Files\Return to Castle Wolfenstein Multiplayer DEMO
[2009/07/13 13:18:27 | 00,028,672 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\virelangues.doc
[2009/07/09 11:30:39 | 00,000,731 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\Raccourci vers IMG_0041.JPG.lnk
[2009/07/08 18:38:31 | 00,041,984 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\cv_ab_2009_ITALIANO_1_without_foto.doc
[2009/07/06 18:14:23 | 00,020,992 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\la detresse version finale 1.doc
[2009/07/05 21:19:11 | 00,028,160 | ---- | C] () -- C:\Documents and Settings\Xavier\Bureau\la detresse 2.doc
[2009/06/28 16:11:36 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Xavier\Mes documents\XAVIER LOTEGUYCV.doc
[2009/06/27 23:14:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Local Settings\Application Data\SecondLife
[2009/06/27 23:14:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Xavier\Application Data\SecondLife
[2009/06/21 03:17:39 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008/07/23 18:50:52 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 18:47:34 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/07/23 18:47:34 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/07/23 18:46:38 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/05/16 11:22:19 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/03/28 18:03:11 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2008/03/18 09:19:33 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008/03/18 09:19:27 | 00,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/03/18 09:19:24 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/03/18 09:19:24 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007/10/25 11:26:48 | 00,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007/08/13 01:37:24 | 00,000,060 | ---- | C] () -- C:\WINDOWS\yesmessenger.ini
[2007/06/02 22:02:02 | 00,000,119 | ---- | C] () -- C:\WINDOWS\Title.INI
[2007/01/02 17:22:42 | 00,000,028 | ---- | C] () -- C:\WINDOWS\MotionDVSTUDIO.INI
[2006/12/30 20:29:27 | 00,000,177 | ---- | C] () -- C:\WINDOWS\game.ini
[2006/09/28 11:55:17 | 00,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2006/08/08 18:23:07 | 00,000,221 | ---- | C] () -- C:\WINDOWS\NCLogConfig.ini
[2006/05/30 11:36:40 | 00,006,372 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/04/13 01:56:08 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2006/04/01 18:03:17 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/01/14 21:36:35 | 00,000,379 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/01/12 22:36:09 | 00,000,241 | ---- | C] () -- C:\WINDOWS\QSync.INI
[2006/01/12 22:35:09 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\LVUI2RC.dll
[2006/01/12 22:35:08 | 00,005,187 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/01/12 22:34:36 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\MimicICM.dll
[2006/01/05 14:55:18 | 00,000,370 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006/01/05 14:50:19 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/12/31 13:37:33 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/12/31 13:34:26 | 00,000,245 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/12/31 13:12:34 | 00,000,537 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/04/09 19:04:54 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/12/20 12:08:28 | 00,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/08/20 12:45:35 | 00,000,829 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/20 12:34:09 | 00,003,712 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/20 12:24:08 | 00,000,762 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/20 12:24:06 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/09/01 11:51:02 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\Installrt2500qa.dll
[2001/07/06 16:30:00 | 00,003,279 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[1 C:\Documents and Settings\Xavier\Mes documents\*.tmp files]
[2009/07/27 15:31:43 | 00,000,011 | ---- | M] () -- C:\AuResult.ini
[2009/07/27 15:19:04 | 00,000,688 | ---- | M] () -- C:\Documents and Settings\Xavier\Menu Démarrer\Programmes\Démarrage\adsl TV.LNK
[2009/07/27 15:18:24 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/07/27 15:17:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/07/27 15:17:54 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/07/27 15:17:53 | 21,371,49440 | -HS- | M] () -- C:\hiberfil.sys
[2009/07/26 21:16:08 | 00,000,762 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/07/26 21:16:08 | 00,000,227 | -HS- | M] () -- C:\boot.ini
[2009/07/26 21:16:08 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/07/26 20:55:29 | 02,111,524 | -H-- | M] () -- C:\Documents and Settings\Xavier\Local Settings\Application Data\IconCache.db
[2009/07/26 20:47:51 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\Ad-remover.lnk
[2009/07/26 16:41:33 | 00,151,552 | ---- | M] () -- C:\Documents and Settings\Xavier\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/25 02:19:40 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/07/25 02:19:40 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/07/24 13:19:25 | 22,075,43807 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\adsl TV 2009-07-24 12-06-10 France 24 (Web TV).mpg
[2009/07/24 13:09:46 | 00,000,466 | ---- | M] () -- C:\WINDOWS\tasks\Wise Registry Cleaner 4.job
[2009/07/24 13:05:12 | 00,004,472 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090724_1305.reg
[2009/07/23 23:00:58 | 00,002,086 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090723_2300.reg
[2009/07/23 20:53:31 | 00,000,654 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\adsl TV.lnk
[2009/07/23 20:52:27 | 29,351,126 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\setup-adsltv.exe
[2009/07/23 18:26:30 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/07/23 18:20:52 | 17,001,840 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Xavier\Bureau\IE8-WindowsXP-x86-FRA.exe
[2009/07/23 17:59:53 | 01,019,954 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/23 17:59:53 | 00,469,348 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2009/07/23 17:59:53 | 00,401,384 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/07/23 17:59:53 | 00,075,158 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2009/07/23 17:59:53 | 00,061,968 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/07/23 17:58:24 | 00,000,698 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/07/23 17:19:26 | 00,036,490 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090723_1719.reg
[2009/07/22 23:58:46 | 00,000,164 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090722_2358.reg
[2009/07/22 23:58:12 | 00,315,914 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\cc_20090722_2357.reg
[2009/07/22 21:16:18 | 00,000,060 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.idx
[2009/07/22 21:15:39 | 10,233,408 | ---- | M] (Tall Emu Pty Ltd ) -- C:\Documents and Settings\Xavier\Bureau\OnlineArmor_Setup_Free_FRA.exe
[2009/07/22 21:07:13 | 00,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Avira AntiVir Control Center.lnk
[2009/07/22 21:04:13 | 32,373,416 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\avira_antivir_personal_fr.exe
[2009/07/22 18:43:41 | 03,775,176 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Xavier\Bureau\mbam-setup.exe
[2009/07/22 18:23:27 | 57,062,576 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\TRACE_BOOT+DRIVERS_1_1.BIN
[2009/07/22 18:19:37 | 00,336,752 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\BootVis-Tool.exe
[2009/07/18 11:31:24 | 00,023,923 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\DETRESSE2.sxw
[2009/07/18 10:25:06 | 01,063,336 | ---- | M] (winamax ) -- C:\Documents and Settings\Xavier\Bureau\Install_Winamax.exe
[2009/07/16 01:53:49 | 00,003,913 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\6208_101626037790_546852790_2586424_3628578_s.jpg
[2009/07/13 13:36:34 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/13 13:36:12 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/13 13:18:27 | 00,028,672 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\virelangues.doc
[2009/07/13 13:06:49 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\XAVIER LOTEGUY CV ART.doc
[2009/07/11 06:04:40 | 00,029,776 | ---- | M] (Tall Emu Pty Ltd) -- C:\WINDOWS\System32\drivers\OAnet.sys
[2009/07/11 05:17:14 | 00,024,656 | ---- | M] (Tall Emu) -- C:\WINDOWS\System32\drivers\OAmon.sys
[2009/07/11 05:17:00 | 00,200,784 | ---- | M] (Tall Emu) -- C:\WINDOWS\System32\drivers\OADriver.sys
[2009/07/09 11:30:39 | 00,000,731 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\Raccourci vers IMG_0041.JPG.lnk
[2009/07/08 18:38:29 | 00,041,984 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\cv_ab_2009_ITALIANO_1_without_foto.doc
[2009/07/07 17:10:56 | 24,539,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/07/06 18:14:23 | 00,020,992 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\la detresse version finale 1.doc
[2009/07/05 21:19:09 | 00,028,160 | ---- | M] () -- C:\Documents and Settings\Xavier\Bureau\la detresse 2.doc
[2009/07/01 09:08:06 | 00,101,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/06/28 16:11:36 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Xavier\Mes documents\XAVIER LOTEGUYCV.doc

[color=#E56717]========== LOP Check ==========[/color]

[2008/02/27 12:42:21 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Administrateur\Application Data
[2005/12/31 13:35:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\Corel
[2005/12/31 13:32:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
[2009/07/22 21:16:16 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/07/22 18:00:45 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1}
[2008/12/20 15:32:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BOONTY
[2006/09/14 17:36:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/07/23 09:23:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OnlineArmor
[2007/01/02 15:56:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Panasonic
[2007/12/05 15:20:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PIXELA
[2006/01/12 14:13:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Prism
[2004/08/20 12:46:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2005/12/31 13:32:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/06/21 02:47:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/14 20:57:04 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Claude\Application Data
[2005/12/31 13:35:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Claude\Application Data\Corel
[2006/07/06 21:54:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Claude\Application Data\Corel Photo Album
[2007/02/09 15:40:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Claude\Application Data\Image Zone Express
[2006/12/10 13:16:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Claude\Application Data\LG Electronics
[2005/12/31 13:32:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Claude\Application Data\You've Got Pictures Screensaver
[2005/12/31 13:26:06 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Application Data
[2005/12/31 13:35:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Corel
[2005/12/31 13:32:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\You've Got Pictures Screensaver
[2008/02/27 12:42:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data
[2004/08/20 12:41:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data
[2006/01/05 18:27:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Propriétaire\Application Data
[2006/01/05 18:27:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Propriétaire\Application Data\You've Got Pictures Screensaver
[2009/07/23 17:54:03 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Xavier\Application Data
[2006/04/10 01:07:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\Ahead
[2005/12/31 13:35:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\Corel
[2006/01/05 15:10:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\Corel Photo Album
[2006/10/12 12:01:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\CyberLink
[2009/07/23 21:29:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\dvdcss
[2006/01/12 22:34:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\FotoWire
[2008/02/19 19:58:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\gtk-2.0
[2006/12/07 23:14:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\Image Zone Express
[2006/04/27 22:20:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\Leadertech
[2006/12/07 14:08:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\LG Electronics
[2009/03/23 20:17:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\MP-Manager
[2009/07/22 21:16:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\OnlineArmor
[2007/01/02 17:23:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\Opera
[2009/06/27 23:14:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\SecondLife
[2006/05/18 21:07:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\teamspeak2
[2007/04/03 13:13:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\Template
[2005/12/31 13:32:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Xavier\Application Data\You've Got Pictures Screensaver
[2004/08/05 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/07/27 15:17:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/07/24 13:09:46 | 00,000,466 | ---- | M] () -- C:\WINDOWS\Tasks\Wise Registry Cleaner 4.job

[color=#E56717]========== Purity Check ==========[/color]


< End of report >
0
fix200 Messages postés 3243 Date d'inscription dimanche 28 décembre 2008 Statut Contributeur sécurité Dernière intervention 7 février 2011 158
27 juil. 2009 à 16:00
Re ,

Heu ... FAUT LIRE L'AMI ! -_-""

Je 'ai dit de le transférer pas cijoint !

bref ...

Désinstalle :
-> Usbfix
-> AD-Remover
-> SMITFRAUDFIX
-> Gmer
-> msnfix

Ensuite :

Résai ici (ne fixe pas les lignes de hijackthis) : https://forums.commentcamarche.net/forum/affich-13492961-uc-en-permanence-a-100?page=2#33

+
0