Bonsoir,
Suite à un plantage de mon pc : au démarrage il n'affiche que mon fond d'écran - sans barre des taches et sans icônes. La souris bouge - mais Ctrl+Alt+Del ne répond pas ni Ctrl+maj+Escap.
J'ai uniquement accès à mon ordi en mode sans échec. J'en ai profité pour suivre les conseils de Lance-yien et utilisé Malwarebytes' Anti-Malware (qui m'a trouvé 13 infections)!! et j'ai bien coché et cliqué sur "Supprimer la sélection".
J'ai téléchargé OTL et Copié/Collé les lignes (commençant par netsvcs) dans l'espace sous "Personnalisation". Je vais donc vous poster les rapports d'OTL en espérant n'avoir pas fait n'importe quoi et que vous pourrez m'aider.
Avec tous mes remerciements
Rapport Otl.txt
OTL logfile created on: 22/04/2011 21:44:11 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Administrateur\Bureau
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
767,00 Mb Total Physical Memory | 561,00 Mb Available Physical Memory | 73,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 96,00% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111,78 Gb Total Space | 66,40 Gb Free Space | 59,40% Space Free | Partition Type: NTFS
Drive F: | 1,95 Gb Total Space | 1,94 Gb Free Space | 99,42% Space Free | Partition Type: FAT
Computer Name: NONY-1E7567D401 | User Name: Administrateur | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/04/22 21:36:54 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrateur\Bureau\OTL.exe
PRC - [2007/06/13 15:22:28 | 001,037,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/07/05 22:52:10 | 000,577,536 | ---- | M] () -- C:\WINDOWS\system32\notepad.exe
========== Modules (SafeList) ==========
MOD - [2011/04/22 21:36:54 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrateur\Bureau\OTL.exe
MOD - [2006/08/25 09:51:14 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (wscsvc)
SRV - [2011/02/23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/06/14 14:39:26 | 001,053,424 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Orange\OrangeUpdate\Service\OUCore.exe -- (Orange update Core Service)
SRV - [2009/08/24 12:22:34 | 000,069,632 | ---- | M] (France Telecom SA) [Auto | Stopped] -- C:\Program Files\Fichiers communs\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe -- (FTRTSVC)
SRV - [2009/07/20 12:28:10 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2009/06/02 10:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009/04/30 13:23:26 | 000,090,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service)
SRV - [2009/04/08 12:38:14 | 000,092,008 | ---- | M] (TomTom) [Auto | Stopped] -- C:\Documents and Settings\Famille NONY\Mes documents\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2007/06/11 21:28:58 | 000,446,464 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe -- (ADSLAutoconnect)
SRV - [2007/03/28 19:42:42 | 000,029,704 | ---- | M] (TuneUp Software GmbH) [Auto | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2007/02/05 11:11:18 | 000,075,320 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe -- (SSScsiSV)
SRV - [2007/02/05 11:11:16 | 000,112,184 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe -- (SonicStage Back-End Service)
SRV - [2007/01/31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Stopped] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2007/01/26 12:39:06 | 000,075,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe -- (ICScsiSV)
SRV - [2007/01/26 12:38:48 | 000,067,760 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe -- (IcVzMonLauncher)
SRV - [2007/01/26 12:38:48 | 000,043,184 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe -- (Image Converter video recording monitor for VAIO Entertainment)
SRV - [2006/12/14 03:21:20 | 000,045,056 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2006/12/14 03:02:08 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2006/12/14 02:46:16 | 000,057,344 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2005/11/14 02:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004/12/24 15:51:24 | 000,106,496 | ---- | M] () [Auto | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe -- (BlueSoleil Hid Service)
SRV - [2003/08/11 10:44:16 | 000,065,795 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\hpzipm12.exe -- (Pml Driver HPZ12)
SRV - [2003/07/28 20:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 15:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 15:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009/08/24 12:22:58 | 000,034,688 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcampr5.sys -- (PCAMPR5)
DRV - [2009/08/24 12:22:58 | 000,032,128 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcandis5.sys -- (PCANDIS5)
DRV - [2009/08/05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009/06/17 18:56:24 | 000,079,248 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2009/06/17 18:56:16 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009/06/17 18:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009/06/17 18:55:58 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidEqd.sys -- (LHidEqd)
DRV - [2009/06/17 18:55:50 | 000,040,720 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV - [2009/06/17 18:55:34 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
DRV - [2009/06/17 18:55:26 | 000,063,248 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2009/06/17 18:55:18 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/05/27 11:41:46 | 000,122,152 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdm.sys -- (s0017mdm)
DRV - [2008/05/27 11:41:46 | 000,117,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM)
DRV - [2008/05/27 11:41:46 | 000,111,912 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017obex.sys -- (s0017obex)
DRV - [2008/05/27 11:41:46 | 000,090,536 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM)
DRV - [2008/05/27 11:41:46 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdfl.sys -- (s0017mdfl)
DRV - [2008/05/27 11:41:44 | 000,115,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM)
DRV - [2008/05/27 11:41:44 | 000,025,768 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS)
DRV - [2007/06/21 22:46:16 | 000,043,488 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2007/01/25 16:37:16 | 004,027,456 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006/05/03 18:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/01/17 14:48:34 | 000,023,000 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2005/01/13 15:20:36 | 000,012,500 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2004/11/05 11:39:08 | 000,082,148 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2004/10/19 13:40:56 | 000,028,207 | ---- | M] (IVT Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2004/10/19 13:37:38 | 000,061,312 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2004/10/19 11:39:26 | 000,020,096 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2004/09/21 18:15:34 | 000,010,804 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BtNetDrv.sys -- (BT)
DRV - [2004/05/21 21:15:50 | 000,163,328 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV532AV.SYS -- (PID_0920) Logitech QuickCam Express(PID_0920)
DRV - [2004/05/21 21:15:31 | 000,019,968 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2004/03/02 09:26:58 | 000,050,007 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\adildr.sys -- (ADILOADER) General Purpose USB Driver (adildr.sys)
DRV - [2004/03/02 09:24:16 | 000,127,065 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\adiusbaw.sys -- (adiusbaw)
DRV - [2002/07/17 09:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/07/07 20:28:43 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2011/04/22 18:57:01 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Elf 1 Toolbar) - {22e03916-85c5-44b0-8dc9-1830c11238d9} - C:\Program Files\Elf_1\prxtbElf0.dll (Conduit Ltd.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (OrangeMenu Object) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - File not found
O2 - BHO: (Fast Browser Search Toolbar Helper) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - File not found
O3 - HKLM\..\Toolbar: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - File not found
O3 - HKLM\..\Toolbar: (Elf 1 Toolbar) - {22e03916-85c5-44b0-8dc9-1830c11238d9} - C:\Program Files\Elf_1\prxtbElf0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (barre d'outils Orange) - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000320.dll (Orange)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [browserSessionManager] C:\Documents and Settings\Famille NONY\Bureau\Navigateur\SessionManager\SessionManager.exe (France Telecom SA)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [HPpromo psc 1300 series] C:\Program Files\HP\Digital Imaging\Promotions\HPpromo.exe (hp)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Nokia FastStart] C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe (Nokia)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe (France Telecom SA)
O4 - HKLM..\Run: [WMAAD] C:\Program Files\Sony\WALKMAN Launcher\WMAAD.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe (IVT Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O16 - DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} http://logicielsgratuits.orange.fr/download_service/Install/OrangeInstaller.cab (OrangeInstaller_ModuleIE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1292745066468 (WUWebControl Class)
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-2.0.cab (AdSignerLCContrl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.dvsd - C:\Program Files\Fichiers communs\Sony Shared\VideoLib\sonydv.dll (Sony Corporation)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2011/04/22 21:37:15 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrateur\Bureau\OTL.exe
[2011/04/22 21:35:52 | 007,025,088 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrateur\Bureau\mbam-rules.exe
[2011/04/22 21:27:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/04/22 19:06:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
[2011/04/22 19:06:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/04/22 19:06:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Malwarebytes' Anti-Malware
[2011/04/22 19:06:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/04/22 19:06:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/22 19:06:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/22 18:27:58 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/04/22 18:27:58 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/04/22 18:27:58 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/04/22 18:27:58 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/04/22 18:27:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/04/22 18:27:33 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/22 15:33:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/04/22 15:16:39 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft
[2011/04/22 15:16:39 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrateur\Application Data\Microsoft
[2011/04/22 15:16:39 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrateur\SendTo
[2011/04/22 15:16:39 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrateur\Application Data
[2011/04/22 15:16:39 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrateur\Menu Démarrer
[2011/04/22 15:16:39 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
[2011/04/22 15:16:39 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Accessoires
[2011/04/22 15:16:39 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrateur\Cookies
[2011/04/22 15:16:39 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrateur\Voisinage réseau
[2011/04/22 15:16:39 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrateur\Voisinage d'impression
[2011/04/22 15:16:39 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrateur\Recent
[2011/04/22 15:16:39 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrateur\Modèles
[2011/04/22 15:16:39 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrateur\Local Settings
[2011/04/22 15:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur\Mes documents
[2011/04/22 15:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur\Application Data\Macromedia
[2011/04/22 15:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur\Favoris
[2011/04/22 15:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur\Bureau
[2011/04/07 19:49:32 | 000,371,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/04/07 19:35:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\avast! Internet Security
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3014 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/22 21:44:33 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011/04/22 21:38:10 | 000,879,081 | ---- | M] () -- C:\Documents and Settings\Administrateur\Bureau\SecurityCheck.exe
[2011/04/22 21:37:20 | 007,025,088 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrateur\Bureau\mbam-rules.exe
[2011/04/22 21:36:54 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrateur\Bureau\OTL.exe
[2011/04/22 21:15:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/22 18:57:01 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/22 13:40:08 | 000,001,050 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/22 12:15:26 | 000,001,054 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/21 21:28:33 | 000,001,000 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/04/21 19:59:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/04/19 19:47:19 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/07 19:49:31 | 000,003,121 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/04/07 19:35:44 | 000,001,705 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\avast! Internet Security.lnk
[2011/04/01 17:15:00 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\Maintenance en 1 clic.job
[2011/03/31 23:39:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/28 21:39:04 | 000,518,368 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2011/03/28 21:39:04 | 000,449,162 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/28 21:39:04 | 000,088,598 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2011/03/28 21:39:04 | 000,074,610 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/25 08:17:01 | 000,001,818 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Google Chrome.lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3014 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/22 21:44:33 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011/04/22 21:38:06 | 000,879,081 | ---- | C] () -- C:\Documents and Settings\Administrateur\Bureau\SecurityCheck.exe
[2011/04/22 18:27:58 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/04/22 18:27:58 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/04/22 18:27:58 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/04/22 18:27:58 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/04/22 18:27:58 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/04/22 15:16:40 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Assistance à distance.lnk
[2011/04/07 19:35:44 | 000,001,705 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\avast! Internet Security.lnk
[2010/07/31 09:28:02 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/07/09 23:09:51 | 000,200,584 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/06/04 14:15:30 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008/04/22 19:07:29 | 000,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2007/12/09 21:07:07 | 000,532,480 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2007/08/11 22:47:20 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\InstMed.exe
[2007/08/11 22:46:52 | 000,000,272 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2007/08/11 22:46:22 | 000,081,920 | R--- | C] () -- C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
[2007/08/11 22:44:40 | 000,163,328 | R--- | C] () -- C:\WINDOWS\System32\drivers\LV532AV.SYS
[2007/06/21 22:22:05 | 000,034,480 | ---- | C] () -- C:\WINDOWS\hpomdl03.dat
[2007/06/21 22:22:05 | 000,028,942 | ---- | C] () -- C:\WINDOWS\hpoins03.dat
[2007/06/20 19:23:52 | 000,013,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2007/06/20 19:23:52 | 000,012,500 | ---- | C] () -- C:\WINDOWS\System32\drivers\vbtenum.sys
[2007/06/11 21:19:45 | 000,019,968 | R--- | C] () -- C:\WINDOWS\System32\drivers\LVUSBSta.sys
[2007/06/11 21:19:45 | 000,005,993 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007/06/11 19:16:12 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/06/10 14:15:26 | 000,000,154 | ---- | C] () -- C:\WINDOWS\adidsl.ini
[2007/06/10 14:15:26 | 000,000,021 | ---- | C] () -- C:\WINDOWS\Fast800.ini
[2007/06/10 14:15:15 | 001,531,904 | ---- | C] () -- C:\WINDOWS\adiras.exe
[2007/06/10 14:15:15 | 000,000,893 | ---- | C] () -- C:\WINDOWS\adiras.ini
[2007/06/10 14:15:12 | 000,127,456 | ---- | C] () -- C:\WINDOWS\System32\ipdetect.exe
[2007/06/10 14:15:07 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\coclassfast.dll
[2007/06/10 14:15:06 | 000,046,892 | ---- | C] () -- C:\WINDOWS\System32\adadix16.dll
[2007/06/10 14:14:57 | 000,143,360 | ---- | C] () -- C:\WINDOWS\autoclk.exe
[2007/06/10 14:14:57 | 000,022,395 | ---- | C] () -- C:\WINDOWS\System32\drivers\fpga.bin
[2007/06/10 07:28:10 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007/06/10 07:27:30 | 000,577,536 | ---- | C] () -- C:\WINDOWS\notepad.exe
[2007/06/10 07:26:26 | 000,249,496 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/06/10 06:29:23 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2007/06/10 06:28:38 | 000,000,385 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/06/10 06:27:54 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2007/06/10 06:26:49 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/06/10 06:26:40 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007/06/10 06:06:50 | 002,111,096 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2007/06/10 05:51:56 | 000,069,120 | ---- | C] () -- C:\WINDOWS\System32\TransBar.exe
[2007/06/10 05:51:56 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\SMPSeesaw.exe
[2007/06/10 05:51:55 | 000,591,552 | ---- | C] () -- C:\WINDOWS\System32\Ntest.exe
[2007/06/10 05:51:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SendToRemove.exe
[2007/06/10 05:51:55 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\SendToAdd.exe
[2007/06/10 05:51:55 | 000,032,610 | ---- | C] () -- C:\WINDOWS\System32\Refresh.exe
[2007/06/10 05:51:54 | 000,742,912 | ---- | C] () -- C:\WINDOWS\System32\deadlink.exe
[2007/06/10 05:51:54 | 000,079,872 | ---- | C] () -- C:\WINDOWS\System32\Enregistrer sous Editeur.exe
[2007/06/10 05:51:54 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\Aide.exe
[2007/06/10 05:51:54 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\Enregistrer sous Test.exe
[2007/06/10 05:51:28 | 000,002,844 | ---- | C] () -- C:\WINDOWS\System32\faview_lng.ini
[2007/06/10 05:51:28 | 000,002,588 | ---- | C] () -- C:\WINDOWS\System32\shman_lng.ini
[2007/06/10 05:51:28 | 000,002,323 | ---- | C] () -- C:\WINDOWS\System32\Starter.ini
[2007/06/10 05:51:28 | 000,001,723 | ---- | C] () -- C:\WINDOWS\System32\WinAudit.ini
[2007/06/10 05:51:28 | 000,001,239 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2007/06/10 05:51:28 | 000,000,047 | ---- | C] () -- C:\WINDOWS\System32\TransBar.ini
[2007/06/10 05:47:38 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2007/06/10 05:41:38 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/07/23 19:13:33 | 000,031,232 | ---- | C] () -- C:\WINDOWS\System32\cmdow.exe
[2006/07/05 22:52:10 | 000,577,536 | ---- | C] () -- C:\WINDOWS\System32\notepad.exe
[2006/07/05 22:52:10 | 000,476,672 | ---- | C] () -- C:\WINDOWS\System32\7za442.exe
[2006/04/28 22:05:14 | 000,127,614 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2005/09/02 01:53:02 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\sleep.exe
[2004/08/19 18:23:25 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/02 16:20:39 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003/08/11 10:44:18 | 000,565,248 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2002/09/06 21:59:59 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002/09/06 21:59:59 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2002/09/06 21:59:59 | 000,518,368 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
[2002/09/06 21:59:59 | 000,449,162 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2002/09/06 21:59:59 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
[2002/09/06 21:59:59 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2002/09/06 21:59:59 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2002/09/06 21:59:59 | 000,088,598 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
[2002/09/06 21:59:59 | 000,074,610 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2002/09/06 21:59:59 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2002/09/06 21:59:59 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat
[2002/09/06 21:59:59 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2002/09/06 21:59:59 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2002/09/06 21:59:59 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/06/10 06:42:36 | 000,000,900 | RHS- | M] () -- C:\boot.ini
[2002/09/06 21:59:59 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2004/08/04 01:00:07 | 000,263,488 | RHS- | M] () -- C:\cmldr
[2011/04/22 21:27:52 | 000,013,571 | ---- | M] () -- C:\ComboFix.txt
[2007/06/10 05:44:37 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007/06/10 07:29:02 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2008/04/22 19:07:40 | 000,001,119 | ---- | M] () -- C:\INSTALL.LOG
[2007/08/11 22:46:46 | 000,035,485 | ---- | M] () -- C:\Installer.log
[2007/06/10 05:44:37 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/08/11 22:46:38 | 000,000,183 | ---- | M] () -- C:\LogiSetup.log
[2007/06/10 05:44:37 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2007/08/11 22:56:48 | 000,058,728 | ---- | M] () -- C:\MSIInstall.log
[2004/08/04 00:38:33 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2004/08/04 00:59:43 | 000,251,712 | RHS- | M] () -- C:\ntldr
[2011/04/22 21:14:46 | 1207,959,552 | -HS- | M] () -- C:\pagefile.sys
[2011/04/22 21:44:33 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2009/02/22 11:55:23 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2007/06/25 22:25:12 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2007/07/25 20:23:52 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2007/09/02 00:57:11 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2007/10/28 17:25:43 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2007/11/11 20:40:10 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2007/12/11 23:42:40 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2008/01/10 00:46:15 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2008/06/08 19:36:56 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2008/06/22 20:09:14 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2008/06/23 14:04:27 | 000,000,232 | -H-- | M] () -- C:\sqmdata10.sqm
[2008/07/07 19:12:33 | 000,000,232 | -H-- | M] () -- C:\sqmdata11.sqm
[2008/07/07 22:41:38 | 000,000,232 | -H-- | M] () -- C:\sqmdata12.sqm
[2008/07/24 19:16:52 | 000,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2008/08/07 23:37:05 | 000,000,232 | -H-- | M] () -- C:\sqmdata14.sqm
[2008/08/08 19:14:45 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2008/08/30 22:14:07 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2008/12/08 21:27:35 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2008/12/08 21:27:39 | 000,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2009/01/07 19:37:43 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2009/02/22 11:55:22 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2007/06/25 22:25:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2007/07/25 20:23:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2007/09/02 00:57:11 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2007/10/28 17:25:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2007/11/11 20:40:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2007/12/11 23:42:40 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2008/01/10 00:46:15 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2008/06/08 19:36:55 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2008/06/22 20:09:13 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2008/06/23 14:04:27 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2008/07/07 19:12:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2008/07/07 22:41:38 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2008/07/24 19:16:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2008/08/07 23:37:05 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2008/08/08 19:14:45 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2008/08/30 22:14:07 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2008/12/08 21:27:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008/12/08 21:27:39 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2009/01/07 19:37:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2001/01/10 12:23:58 | 000,162,304 | ---- | M] () -- C:\UNWISE.EXE
[2007/06/10 06:11:25 | 000,000,056 | ---- | M] () -- C:\XP_Version.txt
[2009/02/04 23:45:06 | 000,000,110 | ---- | M] () -- C:\_dele.bat
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007/06/10 07:25:29 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007/06/10 07:25:29 | 002,220,032 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007/06/10 07:25:28 | 000,430,080 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2011/02/23 15:54:57 | 000,030,680 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aavmker4.sys
[2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys
[2011/02/23 15:55:44 | 000,096,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswmon.sys
[2011/02/23 15:55:47 | 000,102,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswmon2.sys
[2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswRdr.sys
[2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSnx.sys
[2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSP.sys
[2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswTdi.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-03-28 06:43:18
< End of report >