I,fevtion rootkit

Fermé
denver - 15 oct. 2010 à 11:19
 Utilisateur anonyme - 15 oct. 2010 à 14:19
Bonjour,

pc ram bug je pensse que je suis veroler meme malwar ne trouve rien rootkit possible que fair svp je suis novice
A voir également:

24 réponses

OTL logfile created on: 15/10/2010 13:53:27 - Run 3
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\$\Bureau
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 77,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 92,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 115,14 Gb Total Space | 71,96 Gb Free Space | 62,50% Space Free | Partition Type: NTFS
Drive D: | 111,74 Gb Total Space | 110,15 Gb Free Space | 98,58% Space Free | Partition Type: NTFS
Drive E: | 5,99 Gb Total Space | 3,64 Gb Free Space | 60,79% Space Free | Partition Type: FAT32

Computer Name: OEM-2B7087C8C3D | User Name: $ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2010/10/15 11:35:03 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
PRC - [2010/07/11 23:22:34 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
PRC - [2010/03/04 23:38:02 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2009/10/15 10:53:54 | 000,959,808 | ---- | M] (SFR) -- C:\Program Files\SFR\Kit\9props.exe
PRC - [2009/09/30 20:58:42 | 000,026,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2009/04/02 18:05:22 | 000,102,400 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2009/03/31 09:39:36 | 000,233,472 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2008/04/14 04:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/12/13 10:45:34 | 000,176,128 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
PRC - [2005/10/12 13:30:42 | 000,139,264 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2005/10/12 13:30:24 | 000,086,140 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2001/11/12 13:31:48 | 000,020,480 | ---- | M] (X10) -- C:\Program Files\Common Files\X10\Common\X10nets.exe


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2010/10/15 11:35:03 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
MOD - [2008/04/14 04:32:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2010/03/04 23:38:02 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2009/03/31 09:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2008/04/07 09:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2005/12/13 10:45:34 | 000,176,128 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe -- (ELService)
SRV - [2005/10/12 13:30:24 | 000,086,140 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMon) Intel(R)
SRV - [2005/10/06 18:12:44 | 000,856,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Connect 2\wmccds.exe -- (WMConnectCDS)
SRV - [2005/04/04 01:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2001/11/12 13:31:48 | 000,020,480 | ---- | M] (X10) [Auto | Running] -- C:\Program Files\Common Files\X10\Common\X10nets.exe -- (x10nets)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys -- (USBModem)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys -- (UsbDiag)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgusbbus.sys -- (usbbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\TfSysMon.sys -- (TfSysMon)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgvmodem.sys -- (LGVMODEM)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgbtbus.sys -- (lgbusenum)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lgbtport.sys -- (LgBttPort)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\$\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\avfsfilter.sys -- (AVFSFilter)
DRV - [2010/10/10 15:17:53 | 000,013,440 | ---- | M] (ICSI Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBCRFT.SYS -- (CardReaderFilter)
DRV - [2010/09/13 16:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2009/12/19 13:12:39 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/03/31 09:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/03/20 10:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009/03/20 10:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2009/03/20 10:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2008/05/06 08:01:50 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2008/04/13 20:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2008/04/13 20:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) Pilote USB audio (WDM)
DRV - [2008/04/13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/01/14 12:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ManyCam.sys -- (ManyCam)
DRV - [2007/10/25 17:26:10 | 000,005,632 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2007/09/17 15:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006/03/17 17:24:10 | 001,520,640 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/12/13 10:45:20 | 000,007,808 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ELacpi.sys -- (ELacpi)
DRV - [2005/12/13 10:45:18 | 000,007,040 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELmon.sys -- (ELmon)
DRV - [2005/12/13 10:45:00 | 000,006,912 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELkbd.sys -- (ELkbd)
DRV - [2005/12/13 10:44:58 | 000,006,528 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELmou.sys -- (ELmou)
DRV - [2005/12/13 10:44:56 | 000,010,112 | ---- | M] (Intel Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ELhid.sys -- (ELhid)
DRV - [2005/12/06 12:16:20 | 000,826,752 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid)
DRV - [2005/10/12 13:07:12 | 000,874,240 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iastor)
DRV - [2005/06/13 11:50:38 | 000,007,040 | ---- | M] (X10 Wireless Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\x10hid.sys -- (X10Hid)
DRV - [2005/05/12 14:39:56 | 001,287,296 | ---- | M] (C-Media Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmudax.sys -- (cmudax)
DRV - [2004/03/17 16:10:40 | 000,113,664 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2004/01/21 03:14:46 | 000,005,915 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2004/01/21 03:14:42 | 000,271,360 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LV302AV.SYS -- (PID_08A0) Labtec WebCam Pro(PID_08A0)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: "Rechercher MyStart"
FF - prefs.js..browser.search.param.yahoooe÷-fr: "chr-greentree_ff&type=867034"
FF - prefs.js..browser.search.selectedEngine: "Rechercher MyStart"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.fr/?client=firefox-a&rls=org.mozilla:fr:official&gws_rd=ssl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: radiobar@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.0.232
FF - prefs.js..keyword.URL: "http://redirecterror.sfr.fr/?q="

FF - user.js..keyword.URL: "http://redirecterror.sfr.fr/?q="

FF - HKLM\software\mozilla\Firefox\extensions\\FFToolbar@bitdefender.com: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/20 16:54:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/11 23:23:59 | 000,000,000 | ---D | M]

[2009/12/18 21:44:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Mozilla\Extensions
[2010/10/14 19:49:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\extensions
[2010/01/04 12:08:01 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/02 11:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\extensions\radiobar@toolbar
[2010/06/09 10:23:59 | 000,002,650 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\searchplugins\bing.xml
[2010/08/02 00:24:19 | 000,002,139 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Mozilla\Firefox\Profiles\swtbzr4m.default\searchplugins\MyStart Search.xml
[2010/10/14 19:49:55 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/01/12 18:23:17 | 000,000,000 | ---D | M] (PHPNukeFR Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{1c491116-c175-45e1-a570-6fb14fea8b7b}
[2010/07/31 13:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2010/03/15 12:24:33 | 000,001,516 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
[2010/03/15 12:24:33 | 000,001,822 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010/03/15 12:24:33 | 000,000,757 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
[2010/03/15 12:24:33 | 000,001,426 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
[2010/03/25 01:17:32 | 000,000,956 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: ([2010/10/15 13:34:39 | 000,000,794 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Objet d'aide à la navigation SFR) - {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll (SFR)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [Cmaudio] File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005..\Run: [Connexion SFR 9props.exe] C:\Program Files\SFR\Kit\9props.exe (SFR)
O4 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-619478507-2902194733-1154510819-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O9 - Extra Button: PMU Poker - {06568ceb-5721-47d4-9d93-7e604fcbaeab} - C:\Program Files\PMU\PMUPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PMU Poker - {06568ceb-5721-47d4-9d93-7e604fcbaeab} - C:\Program Files\PMU\PMUPoker\RunApp.exe File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/... (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/... (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\$\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\$\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/10/15 13:48:54 | 000,000,004 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/10/15 12:10:07 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010/10/15 12:10:07 | 000,000,000 | RHSD | M] - D:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010/10/15 12:10:08 | 000,000,000 | RHSD | M] - E:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{1ed882c4-2ced-11df-bd69-0016175c9a93}\Shell - "" = AutoRun
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

[color=#E56717]========== Files/Folders - Created Within 90 Days ==========[/color]

[2010/10/15 12:13:42 | 000,000,000 | ---D | C] -- C:\Kill'em
[2010/10/15 12:10:07 | 000,000,000 | RHSD | C] -- C:\Autorun.inf
[2010/10/15 12:07:11 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010/10/15 11:58:18 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Remover
[2010/10/15 11:35:03 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
[2010/10/12 13:13:53 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\$\Recent
[2010/10/11 15:34:25 | 000,000,000 | ---D | C] -- C:\Program Files\List_Kill'em
[2010/10/11 15:31:51 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2010/10/10 19:17:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Local Settings\Application Data\AVG Security Toolbar
[2010/10/10 15:16:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\AVG10
[2010/10/10 15:15:30 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/10/10 15:14:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/10 15:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/10/08 22:28:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\Nouveau dossier (2)
[2010/10/08 22:27:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2010/10/08 22:27:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\AVS4YOU
[2010/10/08 22:27:22 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\AVSMedia
[2010/10/08 22:27:21 | 000,000,000 | ---D | C] -- C:\Program Files\AVS4YOU
[2010/10/08 18:56:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Bureau\Nouveau dossier
[2010/09/29 19:59:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\My Art
[2010/09/27 18:12:01 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/09/25 18:22:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Local Settings\Application Data\WinAVI
[2010/09/25 18:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\PcSetup
[2010/09/24 13:47:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\clp
[2010/09/24 13:46:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Fighters
[2010/09/24 13:46:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Local Settings\Application Data\PackageAware
[2010/09/18 13:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\NPS
[2010/09/13 16:27:24 | 000,025,680 | ---- | C] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\AVGIDSEH.sys
[2010/09/13 11:51:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\Téléchargements
[2010/09/12 16:47:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Mes documents\Nouveau dossier
[2010/09/11 13:14:33 | 000,000,000 | ---D | C] -- C:\Program Files\dpp
[2010/09/11 13:11:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Auslogics
[2010/09/04 20:41:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\ESET
[2010/09/04 18:36:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Local Settings\Application Data\ESET
[2010/08/21 02:07:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TrackMania
[2010/08/13 20:20:38 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\$\Application Data\SecuROM
[2010/08/08 01:26:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Lavasoft
[2010/08/01 17:58:43 | 000,000,000 | ---D | C] -- C:\Program Files\PMU
[2010/07/26 15:25:17 | 000,000,000 | ---D | C] -- C:\Program Files\Xenocode
[2010/07/26 15:25:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Local Settings\Application Data\Xenocode
[2010/07/25 14:15:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\PhotoFiltre
[2010/07/22 16:17:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/07/22 16:17:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\PC Suite
[2010/07/22 16:15:00 | 000,090,624 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcls.dll
[2010/07/22 16:14:58 | 000,021,632 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\pccsmcfd.sys
[2010/07/22 16:14:48 | 000,121,856 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdm.sys
[2010/07/22 16:14:48 | 000,090,112 | ---- | C] (MCCI) -- C:\WINDOWS\System32\drivers\ss_bbus.sys
[2010/07/22 16:14:48 | 000,014,976 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bmdfl.sys
[2010/07/22 16:14:48 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcmnt.sys
[2010/07/22 16:14:48 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bcm.sys
[2010/07/22 16:14:47 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwhnt.sys
[2010/07/22 16:14:47 | 000,012,160 | ---- | C] (MCCI Corporation) -- C:\WINDOWS\System32\drivers\ss_bwh.sys
[2010/07/22 16:12:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Samsung_USB_Drivers
[2010/07/22 16:12:55 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2010/07/22 16:12:15 | 000,233,472 | ---- | C] (Teruten) -- C:\WINDOWS\System32\FsUsbExService.Exe
[2010/07/22 16:12:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Samsung
[2010/07/22 16:11:50 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
[2010/07/22 16:11:48 | 000,000,000 | ---D | C] -- C:\Program Files\PC Connectivity Solution
[2010/07/22 16:11:17 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2010/07/22 14:50:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS
[2010/07/22 14:50:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS\0207030.022
[2010/07/17 16:56:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2010/07/17 16:56:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2010/07/17 16:56:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/07/17 16:26:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\$\Application Data\Camfrog
[2010/07/17 16:26:17 | 000,000,000 | ---D | C] -- C:\Program Files\Camfrog
[2009/12/19 13:39:59 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\$\Application Data\pcouffin.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 90 Days ==========[/color]

[2010/10/15 13:49:53 | 000,505,356 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2010/10/15 13:49:53 | 000,436,180 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/15 13:49:53 | 000,082,646 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2010/10/15 13:49:53 | 000,069,500 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/10/15 13:48:54 | 000,000,004 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/10/15 13:34:39 | 000,000,794 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/15 12:49:55 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-619478507-2902194733-1154510819-1005.job
[2010/10/15 12:49:51 | 000,002,048 | ---- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/15 12:49:48 | 2145,898,496 | -HS- | M] () -- C:\hiberfil.sys
[2010/10/15 12:13:42 | 000,001,624 | ---- | M] () -- C:\Documents and Settings\$\Bureau\List_Kill'em.lnk
[2010/10/15 12:10:07 | 000,014,426 | ---- | M] () -- C:\UsbFix_Upload_Me_OEM-2B7087C8C3D.zip
[2010/10/15 11:58:18 | 000,001,558 | ---- | M] () -- C:\Documents and Settings\$\Bureau\AD-R.lnk
[2010/10/15 11:35:03 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\$\Bureau\OTL.exe
[2010/10/15 11:08:51 | 000,033,280 | ---- | M] () -- C:\Documents and Settings\$\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/11 15:31:53 | 000,000,771 | ---- | M] () -- C:\Documents and Settings\$\Bureau\EVEREST Home Edition.lnk
[2010/10/10 16:38:01 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-619478507-2902194733-1154510819-1005.job
[2010/10/10 15:17:53 | 000,013,440 | ---- | M] (ICSI Technology Ltd.) -- C:\WINDOWS\System32\drivers\USBCRFT.SYS
[2010/10/10 15:11:15 | 000,003,072 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/10/09 10:56:47 | 000,000,768 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Microsoft\Internet Explorer\Quick Launch\DeepBurner.lnk
[2010/10/09 10:56:47 | 000,000,750 | ---- | M] () -- C:\Documents and Settings\$\Bureau\DeepBurner.lnk
[2010/10/09 10:55:29 | 000,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\$\Application Data\pcouffin.sys
[2010/10/09 10:55:29 | 000,007,887 | ---- | M] () -- C:\Documents and Settings\$\Application Data\pcouffin.cat
[2010/10/05 17:36:00 | 000,000,492 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/10/02 13:47:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/30 12:20:35 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/13 16:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- C:\WINDOWS\System32\drivers\AVGIDSEH.sys
[2010/09/06 12:23:04 | 000,417,917 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100927-181935.backup
[2010/09/03 19:43:48 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\$\Local Settings\Application Data\housecall.guid.cache
[2010/08/28 17:00:41 | 000,417,006 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100906-122304.backup
[2010/08/13 14:15:55 | 000,101,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/22 16:15:11 | 000,001,805 | ---- | M] () -- C:\Documents and Settings\$\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung New PC Studio.lnk
[2010/07/22 16:12:05 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\$\Application Data\$_hpcst$.hpc
[2010/07/22 14:05:27 | 000,000,052 | ---- | M] () -- C:\WINDOWS\System32\ashttpstats.csv
[2010/07/22 13:57:41 | 000,000,376 | ---- | M] () -- C:\Documents and Settings\$\Application Dataprivacy.xml
[2010/07/17 16:56:32 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\NSS\0207030.022\isolate.ini
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2010/10/15 12:13:42 | 000,001,624 | ---- | C] () -- C:\Documents and Settings\$\Bureau\List_Kill'em.lnk
[2010/10/15 12:10:07 | 000,014,426 | ---- | C] () -- C:\UsbFix_Upload_Me_OEM-2B7087C8C3D.zip
[2010/10/15 11:58:18 | 000,001,558 | ---- | C] () -- C:\Documents and Settings\$\Bureau\AD-R.lnk
[2010/10/11 15:31:52 | 000,000,771 | ---- | C] () -- C:\Documents and Settings\$\Bureau\EVEREST Home Edition.lnk
[2010/10/09 10:56:47 | 000,000,768 | ---- | C] () -- C:\Documents and Settings\$\Application Data\Microsoft\Internet Explorer\Quick Launch\DeepBurner.lnk
[2010/10/09 10:56:47 | 000,000,750 | ---- | C] () -- C:\Documents and Settings\$\Bureau\DeepBurner.lnk
[2010/09/03 19:43:48 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\$\Local Settings\Application Data\housecall.guid.cache
[2010/08/28 16:20:52 | 2145,898,496 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/22 16:15:11 | 000,001,805 | ---- | C] () -- C:\Documents and Settings\$\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung New PC Studio.lnk
[2010/07/22 16:12:15 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/07/22 16:12:15 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/07/22 16:12:05 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\$\Application Data\$_hpcst$.hpc
[2010/07/17 16:56:32 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NSS\0207030.022\isolate.ini
[2010/06/13 17:32:21 | 000,000,025 | ---- | C] () -- C:\Documents and Settings\$\Application Data\bdfvconp.ini
[2010/04/20 16:14:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CleanUp.INI
[2009/12/20 20:43:59 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\$\Application Data\PnkBstrK.sys
[2009/12/20 02:04:07 | 000,033,280 | ---- | C] () -- C:\Documents and Settings\$\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/19 13:40:11 | 000,001,041 | ---- | C] () -- C:\Documents and Settings\$\Application Data\vso_ts_preview.xml
[2009/12/19 13:39:59 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\$\Application Data\pcouffin.cat
[2009/12/19 13:12:38 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/12/18 22:14:24 | 000,017,191 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/12/18 21:33:51 | 000,000,266 | ---- | C] () -- C:\WINDOWS\Dit.INI
[2009/12/18 20:42:17 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/12/18 20:37:35 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\$\Local Settings\Application Data\fusioncache.dat
[2009/11/12 14:48:58 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\StarOpen.sys
[2009/08/03 00:21:54 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/10/25 17:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2006/05/02 14:50:54 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/05/02 13:37:15 | 000,003,712 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/05/02 13:18:16 | 000,000,821 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/05/02 09:52:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\34CoInstaller.dll
[2006/05/02 09:37:12 | 000,000,734 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/04/28 11:18:51 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/12/21 16:05:13 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2005/08/05 15:38:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[1999/01/27 14:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll

[color=#E56717]========== LOP Check ==========[/color]

[2010/09/11 13:11:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Auslogics
[2010/10/10 15:16:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\AVG10
[2010/07/17 16:28:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Camfrog
[2010/02/25 20:10:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Canneverbe Limited
[2010/03/14 15:01:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Capturino
[2010/02/13 16:13:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\CopyTransPhoto
[2009/12/20 17:18:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\DAEMON Tools Lite
[2010/01/20 19:38:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\DeepBurner
[2010/09/25 18:33:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Fighters
[2010/01/12 18:07:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\FreeAudioPack
[2010/05/05 19:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\GetRightToGo
[2009/12/23 22:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Leadertech
[2009/12/21 14:42:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\ManyCam
[2010/07/22 16:17:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\PC Suite
[2010/07/25 15:47:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\PhotoFiltre
[2010/07/22 16:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Samsung
[2010/03/19 02:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\TeamViewer
[2010/01/02 14:46:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\TuneUp Software
[2010/03/28 04:25:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Uniblue
[2010/10/15 12:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\uTorrent
[2010/10/09 10:55:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\Vso
[2010/02/13 16:19:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\$\Application Data\WindSolutions
[2010/10/10 15:11:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/10/11 13:22:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/07/22 14:06:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BitDefender
[2010/02/25 20:10:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2010/09/25 10:31:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\clp
[2010/10/10 15:15:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/19 13:12:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/03/28 01:52:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2010/10/10 15:14:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/07/22 16:17:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/06/14 12:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/21 18:12:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrackMania
[2010/02/08 17:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/06/14 12:02:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2009/12/23 14:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2010/02/13 16:19:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2010/02/08 17:59:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010/01/15 21:03:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/01/02 14:46:01 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010/01/04 14:22:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2006/05/02 10:51:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\X10 Commander
[2010/10/05 17:36:00 | 000,000,492 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 165 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:663565B1
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
0
Utilisateur anonyme
15 oct. 2010 à 14:04
tu n'as pas resuivi les instructions correctement
0
comment sa ? jai refait un scan comme tu ma dit et je te lais envoyer
0
Utilisateur anonyme
15 oct. 2010 à 14:19
non

tu as cliqué sur quick scan j'avais demandé analyse
tu as selectionné 90j j'en avais demandé 60
tu as posté ici et non sur cijoint.fr comme demandé

ce n'est pas ce qui etait demandé
0