Posté(e) (modifié)

Bonjour voila je viens poster sur ce forum car j'ai quelques doutes sur un programme qui se lance à chaque démarrage de windows et dont il est impossible d'empêcher son ouverture à partir de TuneUp Utilities ou bien de CCleaner. Le nom du programme est svchost.exe accompagné bizarrement de l'icone du jeu Mafia II (que je viens d'installer)(voir image). J'aimerais savoir ce qu'est ce programme et s'il est inutile au démarrage, supprimer son ouverture. Je précise que l'antivirus que j'utilisais jusqu'à présent était Microsoft Security Essentials que je vais remplacer par Kaspersky 2011. Merci d'avance bye




Oui je comprends bien mais celui-la est considéré comme un processus et là il est dans ma liste de programmes au démarrage de windows ce qui, de plus, n'était pas le cas auparavant donc il est forcément dispensable je me trompe?



Il faut afficher les fichiers cachés.

Dans le panneau de configuration > Options des dossiers > onglet Affichage > coche la case adéquate.


Je t'invite a faire un scan avec ce programme :

downlo10.gifTélécharge et installe Malwarebytes Anti-Malware de RubbeR DuckY


arrow210.gif Double-clique sur le fichier mbam-setup-1.46.exe (sous Vista et 7 autorise les modifications)

A la fin de l'installation, veille à ce que les options suivantes soient cochées

  • -Mettre à jour Malwarebytes' Anti-Malware
    -Exécuter Malwarebytes' Anti-Malware

arrow210.gif Clique sur Terminer

Une fenêtre Mise à jour de Malwarebytes' Anti-Malware va s'ouvrir avec une barre de progression.

Puis une autre annonçant le succès de la mise à jour de la base de données. Clique sur OK.

Le programme s'ouvre sur l'onglet Recherche.

Coche casev10.jpgExécuter un examen rapide, clique sur le bouton recher10.jpg


arrow210.gif A la fin du scan, sélectionne tout et clique sur Supprimer la sélection


arrow210.gifPoste le rapport qui s'ouvre après cette suppression.

Redémarre le pc si cela est demandé

Tu peux retrouver le rapport dans l'onglet Rapports/Logs avec la date et l'heure d'exécution.


Puis à poster un rapport établi avec celui-ci

downlo10.gifTélécharge OTL de OldTimer sur ton bureau.

arrow210.gif Clique sur OTL.exe

arrow210.gif Coche :

En haut, à droite

  • -Tous les utilisateurs
    -Avec analyse 64 bits sera coché automatiquement si c'est la cas de ton système.
    -Rapport standard

En bas, à droite

  • -Recherche LOP
    -Recherche Purity


Processus, Services, Drivers, Registre:Standard, Modules, Pilotes doivent être sur [Avec liste blanche] par défaut.

Registre : approfondi est sur Aucun.




arrow210.gifClique sur le bouton [Analyse] en haut en bleu.

L'analyse va prendre une ou deux minutes.

Une fois celle-ci terminée un rapport va s'ouvrir

arrow210.gifTu postes ce rapport par copier-coller et tu le fermes.

Tu fermes aussi le fichier Extras.txt dans la barre des tâches, il sera demandé en cas de nécessité.

Ils seront sauvegardés sur le bureau (OTL.txt et Extras.txt) ou dans le dossier où se trouve OTL.exe.

icon_e10.gif En cas de difficulté pour poster les rapports par copier-coller, tu peux les héberger sur

Poste les liens obtenus dans ce cas.




J'avais déjà coché la case pour voir les fichiers et dossiers cachés c'est pour cela que ça me surprend de ne pas voir le dossier Temp. Bref je viens de changer d'antivirus pour ESET NOD32 antivirus et il me détecte un cheval de troie dans le meme dossier ( C:\Users\Florent\AppData\Roaming\Temps\svchost.exe ) Le problème c'est qu'il me le met en quarantaine mais il réapparait direct.

J'ai exécuté le scan Malwarebytes Anti-Malware et voici le rapport :


Malwarebytes' Anti-Malware 1.46


Version de la base de données: 4483


Windows 6.1.7600

Internet Explorer 8.0.7600.16385


26/08/2010 14:40:40

mbam-log-2010-08-26 (14-40-40).txt


Type d'examen: Examen rapide

Elément(s) analysé(s): 129111

Temps écoulé: 3 minute(s), 4 seconde(s)


Processus mémoire infecté(s): 0

Module(s) mémoire infecté(s): 0

Clé(s) du Registre infectée(s): 2

Valeur(s) du Registre infectée(s): 0

Elément(s) de données du Registre infecté(s): 0

Dossier(s) infecté(s): 0

Fichier(s) infecté(s): 3


Processus mémoire infecté(s):

(Aucun élément nuisible détecté)


Module(s) mémoire infecté(s):

(Aucun élément nuisible détecté)


Clé(s) du Registre infectée(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5pysgyo0-orwm-t8ks-720r-xnvf486cb317} (Generic.Bot.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.


Valeur(s) du Registre infectée(s):

(Aucun élément nuisible détecté)


Elément(s) de données du Registre infecté(s):

(Aucun élément nuisible détecté)


Dossier(s) infecté(s):

(Aucun élément nuisible détecté)


Fichier(s) infecté(s):

C:\Users\Florent\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.

C:\Users\Florent\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Quarantined and deleted successfully.

C:\Users\Florent\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Delete on reboot.





Ainsi que le rapport OTL :



OTL logfile created on: 26/08/2010 14:46:47 - Run 1

OTL by OldTimer - Version Folder = C:\Users\Florent\Desktop

64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy


4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 68,00% Memory free

8,00 Gb Paging File | 7,00 Gb Available in Paging File | 83,00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 465,66 Gb Total Space | 153,08 Gb Free Space | 32,87% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded


Computer Name: FLORENT-PC

Current User Name: Florent

Logged in as Administrator.


Current Boot Mode: Normal

Scan Mode: All users

Include 64bit Scans

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard


========== Processes (SafeList) ==========


PRC - [2010/08/26 14:44:50 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Florent\Desktop\OTL.exe

PRC - [2010/08/26 00:01:53 | 000,218,464 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe

PRC - [2010/08/12 14:16:26 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

PRC - [2010/07/25 16:30:23 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

PRC - [2010/07/01 14:55:42 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe

PRC - [2009/10/12 19:13:20 | 000,226,816 | ---- | M] () -- C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe

PRC - [2009/10/12 12:13:06 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe

PRC - [2007/02/14 12:11:18 | 000,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe



========== Modules (SafeList) ==========


MOD - [2010/08/26 14:44:50 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Florent\Desktop\OTL.exe

MOD - [2009/07/14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx

MOD - [2009/07/14 03:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\\comctl32.dll



========== Win32 Services (SafeList) ==========


SRV:64bit: - File not found [Auto | Running] -- C:\Windows\SysNative\PnkBstrB.exe -- (PnkBstrB)

SRV:64bit: - File not found [Auto | Running] -- C:\Windows\SysNative\PnkBstrA.exe -- (PnkBstrA)

SRV:64bit: - File not found [On_Demand | Stopped] -- C:\Windows\SysNative\GameMon.des -- (npggsvc)

SRV:64bit: - [2010/08/12 21:37:08 | 000,036,160 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)

SRV:64bit: - [2010/08/12 14:18:40 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)

SRV:64bit: - [2010/08/12 14:16:26 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)

SRV:64bit: - [2010/07/16 09:10:20 | 000,341,504 | ---- | M] (CybelSoft) [On_Demand | Stopped] -- C:\Program Files\\maconfservice.exe -- (maconfservice)

SRV:64bit: - [2010/05/27 18:59:40 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)

SRV - [2010/08/26 01:16:32 | 000,607,040 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)

SRV - [2010/08/26 00:01:53 | 000,218,464 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)

SRV - [2010/08/12 21:41:32 | 001,403,200 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)

SRV - [2010/08/12 21:37:02 | 000,030,016 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)

SRV - [2010/07/01 14:55:42 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)

SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)

SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2009/12/16 19:26:00 | 003,453,712 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWow64\GameMon.des -- (npggsvc)

SRV - [2009/12/08 20:01:46 | 000,320,760 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)



========== Driver Services (SafeList) ==========


DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\npptNT2.sys -- (NPPTNT2)

DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\LVPr2M64.sys -- (LVPr2M64)

DRV:64bit: - [2010/07/29 13:31:26 | 000,168,544 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)

DRV:64bit: - [2010/07/29 13:31:26 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)

DRV:64bit: - [2010/07/29 13:31:26 | 000,126,320 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)

DRV:64bit: - [2010/05/27 19:39:12 | 006,856,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)

DRV:64bit: - [2010/05/27 19:39:12 | 006,856,192 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)

DRV:64bit: - [2010/05/27 18:25:36 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

DRV:64bit: - [2010/05/06 11:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)

DRV:64bit: - [2010/03/22 17:57:20 | 000,347,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2010/02/11 15:35:36 | 000,015,872 | ---- | M] (CybelSoft) [Kernel | On_Demand | Stopped] -- C:\Program Files\\Drivers\driverhardwarev2x64.sys -- (driverhardwarev2x64)

DRV:64bit: - [2010/02/03 15:56:56 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)

DRV:64bit: - [2009/12/19 18:30:28 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)

DRV:64bit: - [2009/09/23 03:32:39 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)

DRV:64bit: - [2009/09/23 03:32:33 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)

DRV:64bit: - [2009/09/01 14:29:56 | 000,157,712 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (kl1)

DRV:64bit: - [2009/08/13 23:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)

DRV:64bit: - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/06/10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)

DRV:64bit: - [2009/06/10 22:35:38 | 000,707,072 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364)

DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/05/14 03:26:24 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)

DRV:64bit: - [2009/05/05 06:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)

DRV:64bit: - [2008/09/17 15:14:00 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)

DRV:64bit: - [2005/11/07 15:33:12 | 000,021,120 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\DB3G.sys -- (Razerlow)

DRV - [2009/10/14 08:24:44 | 000,011,856 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)

DRV - [2004/12/30 23:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)



========== Standard Registry (SafeList) ==========



========== Internet Explorer ==========


IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = - YOU Start!



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0




IE - HKU\S-1-5-21-632694530-1312670099-419506812-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google

IE - HKU\S-1-5-21-632694530-1312670099-419506812-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN : Hotmail, Messenger, Bing, Actualité et Sport

IE - HKU\S-1-5-21-632694530-1312670099-419506812-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr

IE - HKU\S-1-5-21-632694530-1312670099-419506812-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 85 5A 83 BB 73 76 CA 01 [binary data]

IE - HKU\S-1-5-21-632694530-1312670099-419506812-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========


FF - prefs.js..browser.startup.homepage: ""

FF - prefs.js..extensions.enabledItems:

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20



FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/14 20:47:32 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/14 20:47:32 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Thunderbird\Extensions\\ C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/08/26 14:25:43 | 000,000,000 | ---D | M]


[2009/12/06 16:18:22 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\mozilla\Extensions

[2010/08/26 13:26:34 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\mozilla\Firefox\Profiles\i34tdw65.default\extensions

[2010/06/30 23:57:13 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\mozilla\Firefox\Profiles\i34tdw65.default\extensions\

[2009/12/23 17:23:05 | 000,005,254 | ---- | M] () -- C:\Users\Florent\AppData\Roaming\Mozilla\FireFox\Profiles\i34tdw65.default\searchplugins\ustart.xml

[2010/08/26 13:38:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2010/06/23 21:25:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

[2010/04/12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

[2010/03/11 21:14:54 | 000,001,516 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-france.xml

[2010/03/11 21:14:54 | 000,001,822 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml

[2010/03/11 21:14:54 | 000,000,757 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-france.xml

[2009/12/09 00:16:44 | 000,000,748 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\MediaDICO-fr.xml

[2010/03/11 21:14:54 | 000,001,426 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-fr.xml

[2010/03/23 23:14:29 | 000,000,956 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-france.xml


O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)

O4 - HKLM..\Run: [Diamondback] C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe ()

O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-632694530-1312670099-419506812-1000..\Run: [razertra MFC Application] C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe ()

O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found

O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O7 - HKU\S-1-5-21-632694530-1312670099-419506812-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_21)

O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} (Java Plug-in 1.6.0_21)


O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (" control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_20)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} (Java Plug-in 1.6.0_20)


O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =

O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\ [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\ [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*


========== Files/Folders - Created Within 30 Days ==========


[2010/08/26 14:44:40 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Florent\Desktop\OTL.exe

[2010/08/26 14:36:28 | 000,000,000 | ---D | C] -- C:\Users\Florent\AppData\Roaming\Malwarebytes

[2010/08/26 14:36:22 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

[2010/08/26 14:36:21 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2010/08/26 14:36:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2010/08/26 14:36:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2010/08/26 14:35:47 | 006,153,376 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Florent\Desktop\mbam-setup-1.46.exe

[2010/08/26 14:29:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET

[2010/08/26 14:26:06 | 000,000,000 | ---D | C] -- C:\Users\Florent\AppData\Local\ESET

[2010/08/26 14:25:43 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET

[2010/08/26 14:25:43 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2010/08/26 14:15:06 | 000,000,000 | -HSD | C] -- C:\Config.Msi

[2010/08/26 13:37:57 | 000,000,000 | -H-D | C] -- C:\ProgramData\AVP9

[2010/08/26 12:37:35 | 000,000,000 | ---D | C] -- C:\Users\Florent\Documents\ANTIVIRUS ESET NOD32 Antivirus

[2010/08/26 12:34:41 | 000,000,000 | -H-D | C] -- C:\ProgramData\AVP11

[2010/08/26 11:36:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ZHPDiag

[2010/08/26 09:10:29 | 000,468,480 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll

[2010/08/26 09:10:29 | 000,183,296 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe

[2010/08/26 09:10:29 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe

[2010/08/26 09:10:29 | 000,165,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe

[2010/08/26 09:10:23 | 000,000,000 | ---D | C] -- C:\Program Files\Java

[2010/08/26 01:13:54 | 000,000,000 | RHSD | C] -- C:\Users\Florent\AppData\Roaming\Temps

[2010/08/26 01:10:05 | 000,000,000 | ---D | C] -- C:\Users\Florent\Desktop\Phx_data

[2010/08/26 00:37:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation

[2010/08/26 00:34:36 | 000,000,000 | RHSD | C] -- C:\Windows\SysWow64\Temps

[2010/08/26 00:31:11 | 000,000,000 | ---D | C] -- C:\Users\Florent\AppData\Local\2K Games

[2010/08/25 14:53:15 | 000,861,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll

[2010/08/24 01:59:04 | 000,000,000 | ---D | C] -- C:\Users\Florent\AppData\Roaming\vlc

[2010/08/17 12:01:15 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft

[2010/08/14 20:47:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime

[2010/08/14 20:47:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer

[2010/08/11 13:26:56 | 005,507,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe

[2010/08/11 13:26:55 | 003,955,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe

[2010/08/11 13:26:55 | 003,899,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe

[2010/08/11 13:26:51 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll

[2010/08/11 13:26:50 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll

[2010/08/11 13:26:50 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll

[2010/08/11 13:26:50 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll

[2010/08/11 13:26:50 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe

[2010/08/11 13:26:50 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe

[2010/08/11 13:26:48 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll

[2010/08/11 13:26:48 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rtutils.dll

[2010/08/11 13:26:47 | 000,082,944 | ---- | C] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll

[2010/08/10 13:40:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Antimalware

[2010/08/10 05:15:58 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\Windows\SysWow64\QuickTimeVR.qtx

[2010/08/10 05:15:58 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\Windows\SysWow64\QuickTime.qts

[2010/08/02 00:45:04 | 000,000,000 | ---D | C] -- C:\Windows\Minidump

[2010/07/29 13:31:26 | 000,168,544 | ---- | C] (ESET) -- C:\Windows\SysNative\drivers\eamonm.sys

[2010/07/29 13:31:26 | 000,141,264 | ---- | C] (ESET) -- C:\Windows\SysNative\drivers\ehdrv.sys

[2010/07/29 13:31:26 | 000,126,320 | ---- | C] (ESET) -- C:\Windows\SysNative\drivers\epfwwfpr.sys

[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]


========== Files - Modified Within 30 Days ==========


[2010/08/26 14:44:50 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Florent\Desktop\OTL.exe

[2010/08/26 14:42:02 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2010/08/26 14:41:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2010/08/26 14:41:54 | 3220,525,056 | -HS- | M] () -- C:\hiberfil.sys

[2010/08/26 14:41:21 | 002,359,296 | -HS- | M] () -- C:\Users\Florent\NTUSER.DAT

[2010/08/26 14:41:20 | 001,751,327 | -H-- | M] () -- C:\Users\Florent\AppData\Local\IconCache.db

[2010/08/26 14:36:24 | 000,000,987 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/08/26 14:36:04 | 006,153,376 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Florent\Desktop\mbam-setup-1.46.exe

[2010/08/26 14:29:43 | 000,000,847 | ---- | M] () -- C:\Users\Public\Desktop\Mise à jour des licences ESET.lnk

[2010/08/26 14:02:40 | 000,015,008 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2010/08/26 14:02:40 | 000,015,008 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2010/08/26 12:23:34 | 000,001,011 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk

[2010/08/26 11:52:08 | 3286,925,311 | ---- | M] () -- C:\Users\Florent\Desktop\VD.PC-ELiTE (UpByTheUploader19 For Wawa Mania).iso

[2010/08/26 09:10:24 | 000,468,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll

[2010/08/26 09:10:24 | 000,183,296 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe

[2010/08/26 09:10:24 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe

[2010/08/26 09:10:24 | 000,165,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe

[2010/08/26 01:25:19 | 022,702,126 | ---- | M] () -- C:\Users\Florent\Desktop\Mafia_II_-_Crack__ByTheUploader19_.rar

[2010/08/26 01:16:31 | 000,002,169 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Maintenance en 1 clic.lnk

[2010/08/26 01:16:31 | 000,002,119 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities.lnk

[2010/08/26 01:13:50 | 000,058,736 | ---- | M] () -- C:\Users\Florent\AppData\Local\GDIPFONTCACHEV1.DAT

[2010/08/26 01:13:39 | 000,276,640 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2010/08/26 01:10:21 | 000,000,500 | ---- | M] () -- C:\Users\Florent\Desktop\Phx_settings.ini

[2010/08/26 01:10:11 | 000,000,673 | ---- | M] () -- C:\Users\Public\Desktop\Phoenix.lnk

[2010/08/26 00:01:53 | 000,218,464 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr

[2010/08/26 00:01:53 | 000,218,464 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe

[2010/08/24 01:58:33 | 000,001,026 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk

[2010/08/23 23:34:56 | 000,000,063 | ---- | M] () -- C:\Users\Florent\Documents\aionmemo_58dd93a8.dat

[2010/08/12 21:42:10 | 000,034,624 | ---- | M] (TuneUp Software) -- C:\Windows\SysNative\TURegOpt.exe

[2010/08/12 21:37:16 | 000,025,920 | ---- | M] (TuneUp Software) -- C:\Windows\SysNative\authuitu.dll

[2010/08/12 21:37:12 | 000,021,312 | ---- | M] (TuneUp Software) -- C:\Windows\SysWow64\authuitu.dll

[2010/08/12 21:37:08 | 000,036,160 | ---- | M] (TuneUp Software) -- C:\Windows\SysNative\uxtuneup.dll

[2010/08/12 21:37:02 | 000,030,016 | ---- | M] (TuneUp Software) -- C:\Windows\SysWow64\uxtuneup.dll

[2010/08/10 05:15:58 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\Windows\SysWow64\QuickTimeVR.qtx

[2010/08/10 05:15:58 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\Windows\SysWow64\QuickTime.qts

[2010/08/04 10:17:54 | 000,000,967 | ---- | M] () -- C:\Users\Florent\Desktop\CCleaner.lnk

[2010/07/29 13:31:26 | 000,168,544 | ---- | M] (ESET) -- C:\Windows\SysNative\drivers\eamonm.sys

[2010/07/29 13:31:26 | 000,141,264 | ---- | M] (ESET) -- C:\Windows\SysNative\drivers\ehdrv.sys

[2010/07/29 13:31:26 | 000,126,320 | ---- | M] (ESET) -- C:\Windows\SysNative\drivers\epfwwfpr.sys

[2010/07/29 08:30:34 | 000,082,944 | ---- | M] (Radius Inc.) -- C:\Windows\SysWow64\iccvid.dll

[2010/07/28 14:53:40 | 008,578,951 | ---- | M] ($t@t!c_V()!D) -- C:\Users\Florent\Desktop\Phoenix.exe

[2010/07/27 22:04:19 | 000,001,743 | ---- | M] () -- C:\Users\Florent\Desktop\Divinity2.exe - Raccourci.lnk

[2010/07/27 21:40:00 | 000,001,100 | ---- | M] () -- C:\Users\Florent\Desktop\Mount&Blade Warband.lnk

[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]


========== Files Created - No Company Name ==========


[2010/08/26 14:36:24 | 000,000,987 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/08/26 14:29:43 | 000,000,847 | ---- | C] () -- C:\Users\Public\Desktop\Mise à jour des licences ESET.lnk

[2010/08/26 11:43:54 | 3286,925,311 | ---- | C] () -- C:\Users\Florent\Desktop\VD.PC-ELiTE (UpByTheUploader19 For Wawa Mania).iso

[2010/08/26 01:22:36 | 022,702,126 | ---- | C] () -- C:\Users\Florent\Desktop\Mafia_II_-_Crack__ByTheUploader19_.rar

[2010/08/26 01:10:11 | 000,000,673 | ---- | C] () -- C:\Users\Public\Desktop\Phoenix.lnk

[2010/08/26 01:10:05 | 000,000,500 | ---- | C] () -- C:\Users\Florent\Desktop\Phx_settings.ini

[2010/08/26 01:10:01 | 008,578,951 | ---- | C] ($t@t!c_V()!D) -- C:\Users\Florent\Desktop\Phoenix.exe

[2010/08/24 01:58:33 | 000,001,026 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk

[2010/08/23 13:38:18 | 000,218,464 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe

[2010/07/27 22:04:19 | 000,001,743 | ---- | C] () -- C:\Users\Florent\Desktop\Divinity2.exe - Raccourci.lnk

[2010/05/10 22:21:56 | 000,000,036 | ---- | C] () -- C:\Users\Florent\AppData\Local\housecall.guid.cache

[2010/05/03 17:03:11 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib

[2010/04/16 22:26:30 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll

[2010/04/02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\SysWow64\

[2010/03/26 19:21:27 | 000,000,095 | ---- | C] () -- C:\Users\Florent\AppData\Local\fusioncache.dat

[2010/02/28 16:15:11 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini

[2009/12/30 15:38:33 | 000,000,000 | ---- | C] () -- C:\Windows\ACTIVEJP.INI

[2009/12/23 00:15:07 | 001,578,582 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2009/12/19 19:19:35 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini

[2009/12/19 14:06:30 | 000,000,050 | ---- | C] () -- C:\Windows\MegaManager.INI

[2009/12/06 14:30:59 | 000,024,576 | R--- | C] () -- C:\Windows\SysWow64\AsIO.dll

[2009/12/06 14:30:59 | 000,013,368 | R--- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys

[2009/12/06 14:29:39 | 000,030,613 | ---- | C] () -- C:\Windows\Ascd_log.ini

[2009/12/06 14:28:26 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini

[2009/12/06 14:28:22 | 000,025,642 | ---- | C] () -- C:\Windows\Ascd_tmp.ini

[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll

[2009/07/13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

[2009/04/02 14:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS


========== LOP Check ==========


[2010/06/14 13:40:16 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\abgx360

[2010/03/16 19:51:27 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Astroburn Lite

[2010/05/15 13:21:01 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Azureus

[2010/03/28 19:53:12 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Bioshock2

[2009/12/19 19:11:53 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\DAEMON Tools Lite

[2010/02/16 16:06:30 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\DeepBurner

[2010/06/01 19:57:03 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\FrostWire

[2009/12/06 21:48:20 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\GetRightToGo

[2010/01/08 21:57:54 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\gtk-2.0

[2010/04/03 01:21:24 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\IconChanger

[2010/06/10 18:29:09 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\ImgBurn

[2010/01/06 20:14:09 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Leadertech

[2010/04/05 00:24:10 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Mount&Blade

[2010/05/01 20:04:56 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Mount&Blade Warband

[2010/08/26 00:01:57 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Mumble

[2010/05/30 16:48:00 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\SystemRequirementsLab

[2010/08/26 14:41:17 | 000,000,000 | RHSD | M] -- C:\Users\Florent\AppData\Roaming\Temps

[2010/08/03 14:56:38 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\TS3Client

[2009/12/06 19:08:53 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\TuneUp Software

[2010/05/02 00:18:05 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\Ubisoft

[2009/12/19 13:48:18 | 000,000,000 | ---D | M] -- C:\Users\Florent\AppData\Roaming\VitySoft

[2010/08/25 14:44:42 | 000,032,496 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT


========== Purity Check ==========




========== Alternate Data Streams ==========


@Alternate Data Stream - 24 bytes -> C:\Windows:5655BB45D402DFF0

< End of report >



Voila merci d'avance pour ta prochaine réponse nardino




Assure toi d'avoir fermé le maximum d'appalications, avant de faire ce qui suit.

Désactive ton antivirus.

Double clique sur OTL.exe pour le lancer.

Sous l'emplacement "Personnalisation" copie colle la liste ci-dessous et sous Rapport en haut, coche Rapport standard :









Clique sur le bouton "Correction". Ne change aucun réglage. Le scan sera rapide.

Le pc va redémarrer.

Copie-colle dans ta prochaine réponse le contenu des deux fichiers de rapports, sauvegardés au même endroit qu'OTL.exe.




J'ai fait ce que tu m'as demandé mais je n'ai qu'un rapport au final, le voici :


User: Florent

->Temp folder emptied: 71648759 bytes

->Temporary Internet Files folder emptied: 870997 bytes

->Java cache emptied: 39912830 bytes

->FireFox cache emptied: 75629472 bytes

->Flash cache emptied: 7348 bytes


User: Public


%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 311296 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 264000 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50540 bytes

RecycleBin emptied: 20063555 bytes


Total Files Cleaned = 199,00 mb



OTL by OldTimer - Version log created on 08262010_191141


Files\Folders moved on Reboot...

C:\Users\Florent\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.


Registry entries deleted on Reboot...

  • Créer...