Je résumes un peu les symptômes de ce pc (il n'est pas à moi) qui est visiblement infecté par au moins 2 infections différentes. J'ai fait un scan avec Antivir qui m'as dis que le processus Winlogon.exe et Explorer.exe sont infectés par TROJ/Patched.gen. Il me dis aussi que Svchost est infecté par un adware suivi de tout plein de chiffres. J'ai aussi essayer Rescue me d'antivir qui lui me dis qu'il y a une infection adware/RegRevive.A dans une ligne contenant application data/opencandy/pleins de chiffres. Il m'as dis qu'il y avais un exploit java dans un fichier nommé apache/adidas.class. Il y avais aussi une autre infection dont je me rappelles pas, je n'ai pas été capable de terminer le scan avec Rescue me parce-qu'après un moment il me disait que je manquais de mémoire vive.
Les symptômes autres que le fait de ne plus avoir de processus Explorer.exe et de ne pas être capable de l'éxécuter comme nouvelle tâche, on entendais des publicités qui n'étaient pas visibles et le pc fermais de manière aléatoire.
Voici le rapport HJT:
Citation
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:14:03, on 2011-12-05
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\taskmgr.exe
F:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = GameTop Search - Find Free Full Version Games
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll
O4 - HKLM\..\Run: [combofix] C:\ComboFix\CF3734.3XE /c C:\ComboFix\Combobatch.bat
O4 - HKLM\..\RunOnce: [combofix] C:\ComboFix\CF3734.3XE /c C:\ComboFixCombobatch.bat
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_ActiveX.exe -update activex (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_ActiveX.exe -update activex (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.updat...b?1301171279171
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1301161140734
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.tous...fig_5_1_1_0.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.ad...Plus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
--
End of file - 4473 bytes
Scan saved at 20:14:03, on 2011-12-05
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\taskmgr.exe
F:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = GameTop Search - Find Free Full Version Games
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll
O4 - HKLM\..\Run: [combofix] C:\ComboFix\CF3734.3XE /c C:\ComboFix\Combobatch.bat
O4 - HKLM\..\RunOnce: [combofix] C:\ComboFix\CF3734.3XE /c C:\ComboFixCombobatch.bat
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_ActiveX.exe -update activex (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_ActiveX.exe -update activex (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.updat...b?1301171279171
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1301161140734
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.tous...fig_5_1_1_0.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.ad...Plus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
--
End of file - 4473 bytes
et le rapport OTL:
Citation
OTL logfile created on: 2011-12-05 22:44:45 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = F:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
511,42 Mb Total Physical Memory | 288,23 Mb Available Physical Memory | 56,36% Memory free
1,22 Gb Paging File | 1,04 Gb Available in Paging File | 84,93% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 20,29 Gb Free Space | 54,46% Space Free | Partition Type: NTFS
Drive F: | 1,96 Gb Total Space | 1,63 Gb Free Space | 83,46% Space Free | Partition Type: FAT
Computer Name: CLOCLO-4D55E9C4 | User Name: claudine simard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-12-04 23:15:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- F:\OTL.exe
PRC - [2011-07-21 12:20:40 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011-07-21 12:20:29 | 000,400,040 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
PRC - [2011-04-21 07:55:54 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008-04-14 07:00:00 | 000,548,864 | ---- | M] () -- C:\WINDOWS\system32\winlogon.exe
PRC - [2008-04-14 07:00:00 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\savedump.exe
========== Modules (No Company Name) ==========
MOD - [2011-07-21 15:12:32 | 000,355,688 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2008-04-14 07:00:00 | 000,548,864 | ---- | M] () -- C:\WINDOWS\system32\winlogon.exe
========== Win32 Services (SafeList) ==========
SRV - [2011-07-21 12:20:40 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011-04-21 07:55:37 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010-03-04 21:38:00 | 000,071,096 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
========== Driver Services (SafeList) ==========
DRV - [2011-07-21 12:22:41 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011-07-21 12:22:40 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010-06-17 15:28:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010-06-17 15:27:52 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010-04-28 01:44:02 | 000,054,760 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2010-02-11 07:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009-11-12 12:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = GameTop Search - Find Free Full Version Games
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 14 F8 F2 E8 F9 EB CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-04-13 00:28:19 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2011-12-05 15:50:18 | 000,000,021 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (uTorrentBar_FR Toolbar) - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar_FR Toolbar) - {05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [combofix] C:\ComboFix\CF3734.3XE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\RunOnce: [combofix] C:\ComboFix\CF3734.3XE (Microsoft Corporation)
O4 - HKLM..\RunOnceEx: [flags] Reg Error: Invalid data type. File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.updat...b?1301171279171 (MUCatalogWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1301161140734 (MUWebControl Class)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} http://fichiers.tous...fig_5_1_1_0.cab (Reg Error: Key error.)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1C8A5F89-4020-4D25-8874-62DDE846FA48}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011-03-22 23:19:40 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011-12-05 15:47:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\RK_Quarantine
[2011-12-05 14:50:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011-12-05 14:09:17 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011-12-05 14:09:16 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011-12-05 14:09:16 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011-12-05 14:09:16 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011-12-05 14:08:25 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011-12-05 00:09:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011-12-05 00:09:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-12-05 00:07:23 | 000,000,000 | ---D | C] -- C:\WinFileReplace
[2011-12-04 21:45:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Avira
[2011-12-04 21:37:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Avira
[2011-12-04 21:37:24 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011-12-04 21:37:21 | 000,138,192 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011-12-04 21:37:21 | 000,066,616 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011-12-04 21:37:21 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011-12-04 21:37:21 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011-12-04 21:37:10 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011-12-04 21:37:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2011-11-23 18:48:48 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\HiJackThis.exe
[2011-11-21 17:19:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Playrix Entertainment
[2011-11-21 17:17:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\GameTop.com
[2011-11-21 17:16:20 | 000,000,000 | ---D | C] -- C:\Program Files\GameTop.com
[2011-11-21 17:15:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3024
[2011-11-21 16:36:27 | 088,496,128 | ---- | C] (Media Contact LLC ) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\FishdomH2O.exe.vir
[2011-11-21 15:38:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\AdobeUM
[2011-11-17 13:19:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\.minecraft
[2011-11-13 09:10:06 | 000,604,160 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users.WINDOWS\Documents\kbd32.dll
[2011-11-13 09:09:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Mes documents\My eBooks
[2011-11-13 09:09:52 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\Adobe
[2011-11-11 17:24:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\Nouveau dossier (2)
[2010-03-25 03:28:46 | 401,790,922 | ---- | C] (Games ) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\HauntedManorCE.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-12-05 22:51:43 | 000,001,632 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011-12-05 22:40:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-12-05 22:40:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-12-05 15:59:33 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011-12-05 15:50:18 | 000,000,021 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011-12-05 01:36:55 | 000,000,212 | -HS- | M] () -- C:\boot.ini
[2011-12-04 21:54:56 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011-12-04 21:54:07 | 000,001,072 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-12-04 21:51:14 | 000,000,452 | ---- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{B7C888B0-7B27-492D-A0FD-345EDAF1ADB9}.job
[2011-12-04 21:37:41 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2011-12-04 21:31:11 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1482476501-1409082233-1547161642-1003.job
[2011-12-04 21:31:09 | 000,001,068 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-12-04 21:31:08 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011-11-23 18:45:34 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\zrbrbhlq.exe
[2011-11-23 18:37:00 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\HiJackThis.exe
[2011-11-23 11:42:02 | 000,000,306 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1482476501-1409082233-1547161642-1003.job
[2011-11-21 17:48:37 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011-11-21 16:41:46 | 088,496,128 | ---- | M] (Media Contact LLC ) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\FishdomH2O.exe.vir
[2011-11-19 17:57:04 | 016,636,444 | ---- | M] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\06 SEROPOSITIF BOOGIE.mp3
[2011-11-17 16:00:05 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\RegRevive.job
[2011-11-10 12:27:01 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011-11-08 14:58:33 | 000,502,986 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2011-11-08 14:58:33 | 000,434,324 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-11-08 14:58:33 | 000,082,360 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2011-11-08 14:58:33 | 000,068,896 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-11-06 04:25:52 | 000,001,097 | ---- | M] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\Raccourci vers The B52's - Love Shack.flv.lnk
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-12-05 15:47:16 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011-12-05 14:09:17 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011-12-05 14:09:16 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011-12-05 14:09:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011-12-05 14:09:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011-12-05 14:09:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011-12-04 21:37:41 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2011-11-23 18:49:51 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\zrbrbhlq.exe
[2011-11-20 19:40:49 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011-11-20 19:40:49 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011-11-06 04:25:52 | 000,001,097 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\Raccourci vers The B52's - Love Shack.flv.lnk
[2011-06-29 17:12:32 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2011-05-16 05:11:34 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2011-05-06 01:14:23 | 000,000,029 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Options
[2011-04-14 18:57:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2011-03-29 00:48:28 | 000,025,600 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-03-27 08:08:27 | 000,001,632 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011-03-26 20:52:53 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011-03-26 13:30:48 | 000,502,986 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
[2011-03-26 13:30:48 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
[2011-03-26 13:30:48 | 000,082,360 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
[2011-03-26 13:30:48 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat
[2011-03-26 13:30:12 | 000,548,864 | ---- | C] () -- C:\WINDOWS\System32\winlogon.exe
[2011-03-26 13:29:43 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2011-03-26 13:29:42 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\sdbinnst.exe
[2011-03-26 13:29:32 | 000,434,324 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2011-03-26 13:29:32 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2011-03-26 13:29:32 | 000,068,896 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2011-03-26 13:29:32 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2011-03-26 13:29:29 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2011-03-26 13:29:25 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2011-03-26 13:29:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2011-03-26 13:29:02 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2011-03-26 13:29:02 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2011-03-26 13:28:57 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\lprheelp.dll
[2011-03-26 13:28:34 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2011-03-26 13:28:13 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2011-03-26 13:28:02 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\assr_pfu.exe
[2011-03-26 10:30:02 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2011-03-26 10:30:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011-03-26 09:51:04 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011-03-26 09:49:54 | 000,102,232 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-03-26 09:42:57 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011-03-26 09:34:14 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-01-13 21:41:00 | 000,309,248 | ---- | C] () -- C:\WINDOWS\System32\sqlite36_engine.dll
[2010-01-13 21:38:00 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\DirectCOM.dll
[2001-07-12 16:14:12 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\shelexec.exe
[1998-10-10 23:07:38 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
========== LOP Check ==========
[2011-05-16 01:53:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Alwil Software
[2011-04-13 00:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Big Fish Games
[2011-04-06 02:54:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\BOONTY
[2011-06-29 17:12:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Canneverbe Limited
[2011-03-28 10:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Casual Arts
[2011-06-13 06:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\DragonsEye Studios
[2011-04-26 16:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Dying for Daylight
[2011-08-22 17:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Fenomen Games
[2011-05-17 20:42:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\GameHouse
[2011-05-28 11:03:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Gogii
[2011-04-06 02:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Intenium
[2011-04-10 10:37:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\JollyBear
[2011-03-27 19:55:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\LittleGamesCompany
[2011-03-28 13:31:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ma-config.com
[2011-05-10 17:08:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Maximize Games
[2011-05-17 19:11:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Merscom
[2011-05-16 08:10:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\MumboJumbo
[2011-05-04 00:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Namco
[2011-05-05 20:35:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Particles
[2011-04-15 02:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PlayFirst
[2011-05-16 07:51:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PlayPond
[2011-04-08 04:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Registry Helper
[2011-03-28 05:17:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\RegRevive
[2011-05-10 22:56:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SOS
[2011-04-11 18:06:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Top Evidence
[2011-04-03 11:33:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2011-03-26 20:59:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Zylom
[2011-11-17 13:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\.minecraft
[2011-05-02 12:16:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\A Gypsy's Tale - The Tower of Secrets
[2011-04-10 04:38:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Application Data
[2011-04-13 14:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Artifex Mundi
[2011-05-11 06:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Artogon
[2011-04-13 14:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Awem
[2011-03-28 22:28:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\BabylonToolbar
[2011-04-03 05:08:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Big Fish Games
[2011-08-23 06:44:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Blue Tea Games
[2011-06-29 17:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Canneverbe Limited
[2011-03-28 10:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Casual Arts
[2011-03-28 06:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Clickteam
[2011-04-03 07:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\CrazyLoader
[2011-06-13 06:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\DragonsEye Studios
[2011-04-26 16:49:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Dying for Daylight
[2011-04-26 16:49:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Dying for Daylight Shared
[2011-05-28 10:58:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Enki Games
[2011-05-16 09:41:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Enlightenus
[2011-06-01 19:19:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\ERS G-Studio
[2011-09-15 07:29:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\ERS Game Studios
[2011-06-17 00:08:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Frogwares
[2011-04-09 05:10:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\FrostWire
[2011-05-16 07:56:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Fugazo
[2011-04-10 21:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\GameHouse
[2011-04-10 04:10:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\GameHousev1002
[2011-05-16 05:17:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\GameMill Entertainment
[2011-05-16 05:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Ghost Ship Studios
[2011-03-27 20:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\HdO Adventure
[2011-03-27 19:55:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\LittleGamesCompany
[2011-07-01 04:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\MA
[2011-08-17 05:20:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\MA2
[2011-04-26 15:08:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\margrave3_full
[2011-05-10 17:08:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Maximize Games
[2011-03-27 08:08:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Meridian93
[2011-05-17 19:11:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Merscom
[2011-09-14 07:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Monkey Barrel Games
[2011-04-09 00:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\MSNInstaller
[2011-03-28 05:15:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\OpenCandy
[2011-07-08 12:55:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Orneon
[2011-07-07 23:47:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Phantasmat_bf_ce1
[2011-04-15 02:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\PlayFirst
[2011-06-01 08:33:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\PlayPond
[2011-11-21 17:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Playrix Entertainment
[2011-04-08 04:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\RegistryKeys
[2011-04-15 01:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\report
[2011-06-08 22:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\SerpentOfIsis
[2011-03-27 12:52:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\SpinTop
[2011-03-27 18:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\TikisLab
[2011-04-11 18:06:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Top Evidence
[2011-06-02 22:50:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Total Eclipse
[2011-04-04 01:50:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\UseNeXT
[2011-12-04 21:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\uTorrent
[2011-04-08 18:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Vast Studios
[2011-05-06 01:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Vogat Interactive
[2011-03-26 21:00:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Zylom
[2011-11-17 16:00:05 | 000,000,350 | ---- | M] () -- C:\WINDOWS\Tasks\RegRevive.job
[2011-12-04 21:51:14 | 000,000,452 | ---- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{B7C888B0-7B27-492D-A0FD-345EDAF1ADB9}.job
========== Purity Check ==========
< End of report >
OTL by OldTimer - Version 3.2.31.0 Folder = F:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
511,42 Mb Total Physical Memory | 288,23 Mb Available Physical Memory | 56,36% Memory free
1,22 Gb Paging File | 1,04 Gb Available in Paging File | 84,93% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 20,29 Gb Free Space | 54,46% Space Free | Partition Type: NTFS
Drive F: | 1,96 Gb Total Space | 1,63 Gb Free Space | 83,46% Space Free | Partition Type: FAT
Computer Name: CLOCLO-4D55E9C4 | User Name: claudine simard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-12-04 23:15:04 | 000,584,192 | ---- | M] (OldTimer Tools) -- F:\OTL.exe
PRC - [2011-07-21 12:20:40 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011-07-21 12:20:29 | 000,400,040 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
PRC - [2011-04-21 07:55:54 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008-04-14 07:00:00 | 000,548,864 | ---- | M] () -- C:\WINDOWS\system32\winlogon.exe
PRC - [2008-04-14 07:00:00 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\savedump.exe
========== Modules (No Company Name) ==========
MOD - [2011-07-21 15:12:32 | 000,355,688 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2008-04-14 07:00:00 | 000,548,864 | ---- | M] () -- C:\WINDOWS\system32\winlogon.exe
========== Win32 Services (SafeList) ==========
SRV - [2011-07-21 12:20:40 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011-04-21 07:55:37 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010-03-04 21:38:00 | 000,071,096 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
========== Driver Services (SafeList) ==========
DRV - [2011-07-21 12:22:41 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011-07-21 12:22:40 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010-06-17 15:28:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010-06-17 15:27:52 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010-04-28 01:44:02 | 000,054,760 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2010-02-11 07:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009-11-12 12:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = GameTop Search - Find Free Full Version Games
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 14 F8 F2 E8 F9 EB CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-04-13 00:28:19 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2011-12-05 15:50:18 | 000,000,021 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (uTorrentBar_FR Toolbar) - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar_FR Toolbar) - {05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [combofix] C:\ComboFix\CF3734.3XE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\RunOnce: [combofix] C:\ComboFix\CF3734.3XE (Microsoft Corporation)
O4 - HKLM..\RunOnceEx: [flags] Reg Error: Invalid data type. File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.updat...b?1301171279171 (MUCatalogWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1301161140734 (MUWebControl Class)
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} http://fichiers.tous...fig_5_1_1_0.cab (Reg Error: Key error.)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1C8A5F89-4020-4D25-8874-62DDE846FA48}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011-03-22 23:19:40 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011-12-05 15:47:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\RK_Quarantine
[2011-12-05 14:50:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011-12-05 14:09:17 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011-12-05 14:09:16 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011-12-05 14:09:16 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011-12-05 14:09:16 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011-12-05 14:08:25 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011-12-05 00:09:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011-12-05 00:09:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-12-05 00:07:23 | 000,000,000 | ---D | C] -- C:\WinFileReplace
[2011-12-04 21:45:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Avira
[2011-12-04 21:37:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Avira
[2011-12-04 21:37:24 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011-12-04 21:37:21 | 000,138,192 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011-12-04 21:37:21 | 000,066,616 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011-12-04 21:37:21 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011-12-04 21:37:21 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011-12-04 21:37:10 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011-12-04 21:37:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2011-11-23 18:48:48 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\HiJackThis.exe
[2011-11-21 17:19:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Playrix Entertainment
[2011-11-21 17:17:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\GameTop.com
[2011-11-21 17:16:20 | 000,000,000 | ---D | C] -- C:\Program Files\GameTop.com
[2011-11-21 17:15:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3024
[2011-11-21 16:36:27 | 088,496,128 | ---- | C] (Media Contact LLC ) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\FishdomH2O.exe.vir
[2011-11-21 15:38:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\AdobeUM
[2011-11-17 13:19:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\.minecraft
[2011-11-13 09:10:06 | 000,604,160 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users.WINDOWS\Documents\kbd32.dll
[2011-11-13 09:09:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Mes documents\My eBooks
[2011-11-13 09:09:52 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\Adobe
[2011-11-11 17:24:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\Nouveau dossier (2)
[2010-03-25 03:28:46 | 401,790,922 | ---- | C] (Games ) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\HauntedManorCE.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-12-05 22:51:43 | 000,001,632 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011-12-05 22:40:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-12-05 22:40:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-12-05 15:59:33 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011-12-05 15:50:18 | 000,000,021 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011-12-05 01:36:55 | 000,000,212 | -HS- | M] () -- C:\boot.ini
[2011-12-04 21:54:56 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011-12-04 21:54:07 | 000,001,072 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-12-04 21:51:14 | 000,000,452 | ---- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{B7C888B0-7B27-492D-A0FD-345EDAF1ADB9}.job
[2011-12-04 21:37:41 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2011-12-04 21:31:11 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1482476501-1409082233-1547161642-1003.job
[2011-12-04 21:31:09 | 000,001,068 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-12-04 21:31:08 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011-11-23 18:45:34 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\zrbrbhlq.exe
[2011-11-23 18:37:00 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\HiJackThis.exe
[2011-11-23 11:42:02 | 000,000,306 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1482476501-1409082233-1547161642-1003.job
[2011-11-21 17:48:37 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011-11-21 16:41:46 | 088,496,128 | ---- | M] (Media Contact LLC ) -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\FishdomH2O.exe.vir
[2011-11-19 17:57:04 | 016,636,444 | ---- | M] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\06 SEROPOSITIF BOOGIE.mp3
[2011-11-17 16:00:05 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\RegRevive.job
[2011-11-10 12:27:01 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011-11-08 14:58:33 | 000,502,986 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2011-11-08 14:58:33 | 000,434,324 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-11-08 14:58:33 | 000,082,360 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2011-11-08 14:58:33 | 000,068,896 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-11-06 04:25:52 | 000,001,097 | ---- | M] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\Raccourci vers The B52's - Love Shack.flv.lnk
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-12-05 15:47:16 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011-12-05 14:09:17 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011-12-05 14:09:16 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011-12-05 14:09:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011-12-05 14:09:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011-12-05 14:09:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011-12-04 21:37:41 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2011-11-23 18:49:51 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\zrbrbhlq.exe
[2011-11-20 19:40:49 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011-11-20 19:40:49 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011-11-06 04:25:52 | 000,001,097 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Bureau\Raccourci vers The B52's - Love Shack.flv.lnk
[2011-06-29 17:12:32 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2011-05-16 05:11:34 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2011-05-06 01:14:23 | 000,000,029 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Options
[2011-04-14 18:57:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2011-03-29 00:48:28 | 000,025,600 | ---- | C] () -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-03-27 08:08:27 | 000,001,632 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011-03-26 20:52:53 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011-03-26 13:30:48 | 000,502,986 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
[2011-03-26 13:30:48 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
[2011-03-26 13:30:48 | 000,082,360 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
[2011-03-26 13:30:48 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat
[2011-03-26 13:30:12 | 000,548,864 | ---- | C] () -- C:\WINDOWS\System32\winlogon.exe
[2011-03-26 13:29:43 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2011-03-26 13:29:42 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\sdbinnst.exe
[2011-03-26 13:29:32 | 000,434,324 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2011-03-26 13:29:32 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2011-03-26 13:29:32 | 000,068,896 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2011-03-26 13:29:32 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2011-03-26 13:29:29 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2011-03-26 13:29:25 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2011-03-26 13:29:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2011-03-26 13:29:02 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2011-03-26 13:29:02 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2011-03-26 13:28:57 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\lprheelp.dll
[2011-03-26 13:28:34 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2011-03-26 13:28:13 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2011-03-26 13:28:02 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\assr_pfu.exe
[2011-03-26 10:30:02 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2011-03-26 10:30:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011-03-26 09:51:04 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011-03-26 09:49:54 | 000,102,232 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-03-26 09:42:57 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011-03-26 09:34:14 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-01-13 21:41:00 | 000,309,248 | ---- | C] () -- C:\WINDOWS\System32\sqlite36_engine.dll
[2010-01-13 21:38:00 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\DirectCOM.dll
[2001-07-12 16:14:12 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\shelexec.exe
[1998-10-10 23:07:38 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
========== LOP Check ==========
[2011-05-16 01:53:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Alwil Software
[2011-04-13 00:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Big Fish Games
[2011-04-06 02:54:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\BOONTY
[2011-06-29 17:12:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Canneverbe Limited
[2011-03-28 10:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Casual Arts
[2011-06-13 06:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\DragonsEye Studios
[2011-04-26 16:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Dying for Daylight
[2011-08-22 17:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Fenomen Games
[2011-05-17 20:42:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\GameHouse
[2011-05-28 11:03:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Gogii
[2011-04-06 02:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Intenium
[2011-04-10 10:37:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\JollyBear
[2011-03-27 19:55:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\LittleGamesCompany
[2011-03-28 13:31:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ma-config.com
[2011-05-10 17:08:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Maximize Games
[2011-05-17 19:11:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Merscom
[2011-05-16 08:10:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\MumboJumbo
[2011-05-04 00:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Namco
[2011-05-05 20:35:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Particles
[2011-04-15 02:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PlayFirst
[2011-05-16 07:51:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PlayPond
[2011-04-08 04:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Registry Helper
[2011-03-28 05:17:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\RegRevive
[2011-05-10 22:56:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SOS
[2011-04-11 18:06:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Top Evidence
[2011-04-03 11:33:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
[2011-03-26 20:59:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Zylom
[2011-11-17 13:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\.minecraft
[2011-05-02 12:16:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\A Gypsy's Tale - The Tower of Secrets
[2011-04-10 04:38:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Application Data
[2011-04-13 14:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Artifex Mundi
[2011-05-11 06:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Artogon
[2011-04-13 14:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Awem
[2011-03-28 22:28:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\BabylonToolbar
[2011-04-03 05:08:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Big Fish Games
[2011-08-23 06:44:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Blue Tea Games
[2011-06-29 17:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Canneverbe Limited
[2011-03-28 10:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Casual Arts
[2011-03-28 06:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Clickteam
[2011-04-03 07:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\CrazyLoader
[2011-06-13 06:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\DragonsEye Studios
[2011-04-26 16:49:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Dying for Daylight
[2011-04-26 16:49:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Dying for Daylight Shared
[2011-05-28 10:58:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Enki Games
[2011-05-16 09:41:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Enlightenus
[2011-06-01 19:19:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\ERS G-Studio
[2011-09-15 07:29:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\ERS Game Studios
[2011-06-17 00:08:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Frogwares
[2011-04-09 05:10:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\FrostWire
[2011-05-16 07:56:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Fugazo
[2011-04-10 21:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\GameHouse
[2011-04-10 04:10:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\GameHousev1002
[2011-05-16 05:17:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\GameMill Entertainment
[2011-05-16 05:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Ghost Ship Studios
[2011-03-27 20:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\HdO Adventure
[2011-03-27 19:55:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\LittleGamesCompany
[2011-07-01 04:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\MA
[2011-08-17 05:20:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\MA2
[2011-04-26 15:08:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\margrave3_full
[2011-05-10 17:08:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Maximize Games
[2011-03-27 08:08:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Meridian93
[2011-05-17 19:11:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Merscom
[2011-09-14 07:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Monkey Barrel Games
[2011-04-09 00:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\MSNInstaller
[2011-03-28 05:15:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\OpenCandy
[2011-07-08 12:55:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Orneon
[2011-07-07 23:47:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Phantasmat_bf_ce1
[2011-04-15 02:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\PlayFirst
[2011-06-01 08:33:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\PlayPond
[2011-11-21 17:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Playrix Entertainment
[2011-04-08 04:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\RegistryKeys
[2011-04-15 01:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\report
[2011-06-08 22:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\SerpentOfIsis
[2011-03-27 12:52:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\SpinTop
[2011-03-27 18:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\TikisLab
[2011-04-11 18:06:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Top Evidence
[2011-06-02 22:50:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Total Eclipse
[2011-04-04 01:50:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\UseNeXT
[2011-12-04 21:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\uTorrent
[2011-04-08 18:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Vast Studios
[2011-05-06 01:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Vogat Interactive
[2011-03-26 21:00:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\claudine simard.CLOCLO-4D55E9C4\Application Data\Zylom
[2011-11-17 16:00:05 | 000,000,350 | ---- | M] () -- C:\WINDOWS\Tasks\RegRevive.job
[2011-12-04 21:51:14 | 000,000,452 | ---- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{B7C888B0-7B27-492D-A0FD-345EDAF1ADB9}.job
========== Purity Check ==========
< End of report >
Merci beaucoup de prendre le temps de lire mon message.

Aide












