Puis voici le premier rapport otl.text
OTL logfile created on: 2009-12-02 06:03:50 - Run 1
OTL by OldTimer - Version 3.1.11.4 Folder = C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: yyyy-MM-dd
767.48 Mb Total Physical Memory | 354.35 Mb Available Physical Memory | 46.17% Memory free
1.83 Gb Paging File | 1.32 Gb Available in Paging File | 72.13% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.36 Gb Total Space | 16.92 Gb Free Space | 23.72% Space Free | Partition Type: NTFS
Drive D: | 71.82 Gb Total Space | 71.81 Gb Free Space | 99.99% Space Free | Partition Type: FAT32
Drive E: | 7.08 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ACER
Current User Name: RAMIRO RUIZ Evelyne
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2009-12-01 00:45:21 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\OTL.exe
PRC - [2009-08-19 11:59:31 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009-07-13 23:47:30 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009-05-19 10:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009-03-02 12:08:11 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009-02-06 16:07:48 | 00,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2009-01-09 19:58:10 | 07,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009-01-09 19:57:04 | 07,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2008-09-16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
PRC - [2008-08-21 02:18:00 | 00,443,968 | ---- | M] (Google Inc.) -- C:\Program Files\Picasa2\PicasaMediaDetector.exe
PRC - [2008-06-10 03:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2008-06-10 03:27:03 | 00,329,104 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
PRC - [2008-01-02 20:15:26 | 00,103,712 | R--- | M] (MacroGaming LTD.) -- C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
PRC - [2007-09-03 17:13:54 | 00,081,920 | ---- | M] (FirebirdSQL Project) -- C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
PRC - [2007-09-03 17:13:48 | 02,002,944 | ---- | M] (FirebirdSQL Project) -- C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
PRC - [2007-08-30 17:43:18 | 00,103,664 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
PRC - [2007-07-18 21:08:05 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007-06-13 14:22:28 | 01,037,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007-03-11 21:34:40 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2007-03-11 21:32:42 | 00,151,552 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
PRC - [2007-03-11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2006-07-11 23:19:00 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2006-06-01 14:40:54 | 00,413,696 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
PRC - [2006-06-01 01:48:00 | 16,208,384 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe
PRC - [2006-02-17 14:26:32 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
PRC - [2005-11-16 19:25:14 | 00,745,472 | ---- | M] (X-Micro Technology Corp.) -- C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
PRC - [2005-07-15 21:38:33 | 00,139,264 | R--- | M] () -- C:\Program Files\MioNet\MioNetManager.exe
PRC - [2005-07-12 18:54:32 | 00,278,528 | ---- | M] () -- C:\Program Files\Philips\SPC 200NC PC Camera\TrayMin200.exe
PRC - [2004-06-09 14:37:02 | 00,040,960 | ---- | M] (BIGDOG) -- C:\WINDOWS\VM_STI.EXE
PRC - [2004-06-04 05:09:14 | 00,045,161 | ---- | M] () -- C:\Program Files\MioNet\jvm\bin\MioNet.exe
========== Modules (SafeList) ========== MOD - [2009-12-01 00:45:21 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\OTL.exe
MOD - [2008-01-02 20:14:20 | 00,022,304 | ---- | M] (MacroGaming) -- C:\Program Files\Macrogaming\SweetIM\mgAdaptersProxy.dll
MOD - [2006-08-25 16:51:12 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2006-07-11 18:35:38 | 00,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Macrogaming\SweetIM\msvcr71.dll
========== Win32 Services (SafeList) ========== SRV - [2009-08-19 11:59:31 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009-08-05 21:48:42 | 00,704,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009-07-13 23:47:30 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009-05-19 10:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009-03-24 12:12:40 | 00,183,280 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2009-03-03 08:36:45 | 00,651,720 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008-09-16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0)
SRV - [2007-09-03 17:13:54 | 00,081,920 | ---- | M] (FirebirdSQL Project) -- C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance)
SRV - [2007-09-03 17:13:48 | 02,002,944 | ---- | M] (FirebirdSQL Project) -- C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe -- (FirebirdServerDefaultInstance)
SRV - [2007-03-11 22:02:52 | 00,131,072 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc)
SRV - [2007-03-11 21:24:50 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08)
SRV - [2006-11-08 16:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\HPZipm12.dll -- (Pml Driver HPZ12)
SRV - [2006-11-08 16:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\HPZinw12.dll -- (Net Driver HPZ12)
SRV - [2006-07-11 23:19:00 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2006-02-17 14:26:32 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2005-11-14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005-07-15 21:38:33 | 00,139,264 | R--- | M] () -- C:\Program Files\MioNet\MioNetManager.exe -- (MioNet)
========== Driver Services (SafeList) ========== DRV - [2009-08-19 11:59:31 | 00,055,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009-08-05 21:48:42 | 00,054,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009-07-13 23:47:30 | 00,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009-03-30 09:32:47 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009-02-13 11:34:33 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008-11-20 20:19:06 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2007-11-13 11:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2007-03-08 05:20:50 | 00,021,568 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12)
DRV - [2007-03-08 05:20:49 | 00,016,496 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12)
DRV - [2007-03-08 05:20:48 | 00,049,920 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZid412.sys -- (HPZid412)
DRV - [2006-12-13 09:34:06 | 00,031,400 | ---- | M] (Exent Technologies Ltd.) -- C:\Program Files\Player Metaboli\X4HSX32.sys -- (X4HSX32)
DRV - [2006-08-28 14:22:52 | 00,097,184 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\SE26mdm.sys -- (SE26mdm)
DRV - [2006-08-28 14:22:50 | 00,009,360 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\SE26mdfl.sys -- (SE26mdfl)
DRV - [2006-08-28 14:22:46 | 00,061,600 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\SE26bus.sys -- (SE26bus) Sony Ericsson Device 038 Driver driver (WDM)
DRV - [2006-08-11 18:52:28 | 00,006,144 | ---- | M] (NewTech Infosystems, Inc.) -- C:\WINDOWS\system32\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV - [2006-07-11 23:19:00 | 03,934,592 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006-06-29 09:53:00 | 00,244,864 | ---- | M] (Marvell) -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2006-06-28 18:39:02 | 00,089,344 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvraid.sys -- (nvraid) NVIDIA nForce(tm)
DRV - [2006-06-28 18:38:56 | 00,105,088 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvatabus.sys -- (nvatabus)
DRV - [2006-06-18 22:40:44 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006-06-05 21:09:26 | 04,284,928 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005-10-28 10:38:18 | 00,402,432 | ---- | M] (ZyDAS Technology Corporation) -- C:\WINDOWS\system32\drivers\ZD1211BU.sys -- (ZD1211BU(ZyDAS)) ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2005-10-04 14:38:24 | 00,280,064 | ---- | M] (ZyDAS Technology Corporation) -- C:\WINDOWS\system32\drivers\ZD1211U.sys -- (ZD1211U(ZyDAS)) ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2005-01-13 14:46:16 | 00,069,632 | ---- | M] () -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2005-01-07 16:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004-12-17 03:14:44 | 00,013,952 | ---- | M] () -- C:\WINDOWS\system32\drivers\UBHelper.sys -- (UBHelper)
DRV - [2004-11-10 18:13:32 | 00,093,351 | ---- | M] (VM) -- C:\WINDOWS\system32\drivers\usbVM31b.sys -- (ZSMC301b)
DRV - [2004-10-25 12:40:58 | 00,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - [2004-08-10 21:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..browser.startup.homepage: "http://moteur.chat-land.org/"
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009-11-25 07:15:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-11-30 11:01:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-11-30 11:01:53 | 00,000,000 | ---D | M]
[2008-09-14 13:46:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\Mozilla\Extensions
[2009-11-30 11:12:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\Mozilla\Firefox\Profiles\c6utgk28.default\extensions
[2009-11-30 11:12:25 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009-12-01 19:46:13 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\browserhighlighter@ebay.com
[2009-11-30 11:01:46 | 00,001,516 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
[2009-11-30 11:01:46 | 00,001,822 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
[2009-11-30 11:01:46 | 00,000,757 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
[2009-11-30 11:01:47 | 00,001,426 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
[2009-11-30 11:01:47 | 00,000,652 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: (686 bytes) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE (BIGDOG)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe File not found
O4 - HKLM..\Run: [EoEngine] File not found
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.com File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe (MacroGaming LTD.)
O4 - HKCU..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - HKCU..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe (MacroGaming LTD.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe (X-Micro Technology Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\TrayMin300.exe.lnk = C:\Program Files\Philips\SPC 200NC PC Camera\TrayMin200.exe ()
O4 - Startup: C:\Documents and Settings\RAMIRO RUIZ Evelyne\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 () -
file:///C:/DOCUME~1/RAMIRO~1/LOCALS~1/Temp/msoclip1/01/clip_image002.jpgO24 - Desktop Components:1 () -
file:///C:/DOCUME~1/RAMIRO~1/LOCALS~1/Temp/msoclip1/01/clip_image002.gifO24 - Desktop Components:2 () -
http://ubayp.com/propertypictures/149_Ashbury_SF_2.jpgO24 - Desktop Components:3 (Ma page d'accueil) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-08-11 18:52:52 | 00,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2009-12-01 01:08:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\bibou
[2009-12-01 00:48:24 | 00,000,000 | ---D | C] -- C:\_OTL
[2009-12-01 00:45:16 | 00,535,552 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\OTL.exe
[2009-12-01 00:43:44 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009-12-01 00:39:53 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\erunt-setup.exe
[2009-11-27 22:48:34 | 00,000,000 | ---D | C] -- C:\rsit
[2009-11-27 19:32:31 | 04,045,528 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\mbam-setup.exe
[2009-11-27 00:06:28 | 00,341,504 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\TFC.exe
[2009-11-25 22:27:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Mes documents\canovas concours2009reduc
[2009-11-19 04:45:53 | 00,332,800 | ---- | C] (gunsmiths) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Local Settings\Application Data\fsexj.exe
[7 C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\*.tmp files -> C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\*.tmp -> ]
[5 C:\Documents and Settings\RAMIRO RUIZ Evelyne\Mes documents\*.tmp files -> C:\Documents and Settings\RAMIRO RUIZ Evelyne\Mes documents\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2009-12-02 05:35:59 | 00,001,000 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009-12-01 01:07:42 | 00,073,451 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-12-01 01:07:01 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-12-01 01:06:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-12-01 01:06:58 | 80,483,5328 | -HS- | M] () -- C:\hiberfil.sys
[2009-12-01 01:06:20 | 00,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2009-12-01 01:06:18 | 06,815,744 | -H-- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\NTUSER.DAT
[2009-12-01 01:06:18 | 00,000,284 | -HS- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\ntuser.ini
[2009-12-01 01:00:05 | 00,228,109 | ---- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\Navilog1.exe
[2009-12-01 00:45:21 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\OTL.exe
[2009-12-01 00:43:45 | 00,000,615 | ---- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\NTREGOPT.lnk
[2009-12-01 00:43:45 | 00,000,596 | ---- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\ERUNT.lnk
[2009-12-01 00:40:03 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\erunt-setup.exe
[2009-11-29 22:54:44 | 00,284,153 | ---- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\gmer.zip
[2009-11-27 22:53:10 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\RSIT.exe
[2009-11-27 19:33:55 | 00,000,700 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Malwarebytes' Anti-Malware.lnk
[2009-11-27 19:32:31 | 04,045,528 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\mbam-setup.exe
[2009-11-27 00:06:34 | 00,341,504 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\TFC.exe
[2009-11-26 03:01:23 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-11-25 22:32:39 | 03,072,237 | ---- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Mes documents\DSCF6614.jpg
[2009-11-25 07:15:05 | 00,001,606 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Firefox.lnk
[2009-11-22 04:10:57 | 00,001,733 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 9.lnk
[2009-11-21 12:17:18 | 00,292,352 | ---- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\gmer.exe
[2009-11-19 04:45:53 | 00,332,800 | ---- | M] (gunsmiths) -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Local Settings\Application Data\fsexj.exe
[2009-11-13 03:17:21 | 00,255,064 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-11-12 18:41:52 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-11-04 13:48:18 | 00,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2009-11-03 00:30:16 | 04,287,130 | -H-- | M] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Local Settings\Application Data\IconCache.db
[7 C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\*.tmp files -> C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\*.tmp -> ]
[5 C:\Documents and Settings\RAMIRO RUIZ Evelyne\Mes documents\*.tmp files -> C:\Documents and Settings\RAMIRO RUIZ Evelyne\Mes documents\*.tmp -> ]
========== Files Created - No Company Name ========== [2009-12-01 01:00:05 | 00,228,109 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\Navilog1.exe
[2009-12-01 00:43:45 | 00,000,615 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\NTREGOPT.lnk
[2009-12-01 00:43:45 | 00,000,596 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\ERUNT.lnk
[2009-11-30 00:56:24 | 00,292,352 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\gmer.exe
[2009-11-29 22:54:21 | 00,284,153 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\gmer.zip
[2009-11-27 22:53:09 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Bureau\RSIT.exe
[2009-11-27 19:33:55 | 00,000,700 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Malwarebytes' Anti-Malware.lnk
[2009-11-25 22:32:35 | 03,072,237 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Mes documents\DSCF6614.jpg
[2009-11-22 04:10:55 | 00,001,733 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 9.lnk
[2009-09-07 22:31:41 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-02-14 19:35:18 | 00,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\addr_file.html
[2007-12-25 21:45:14 | 00,007,039 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007-10-29 19:04:32 | 00,023,552 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007-07-06 18:43:45 | 00,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT
[2007-05-30 23:15:47 | 00,000,497 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007-01-29 08:43:20 | 00,000,294 | ---- | C] () -- C:\WINDOWS\PowerOption.ini
[2007-01-23 17:20:48 | 00,000,142 | ---- | C] () -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Local Settings\Application Data\fusioncache.dat
[2006-08-11 18:56:06 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006-08-11 18:54:50 | 00,000,050 | ---- | C] () -- C:\WINDOWS\commercial.ini
[2006-08-11 18:54:22 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\MWLPS.dll
[2006-08-11 18:53:12 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIBUN4.dll
[2006-08-11 18:52:28 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll
[2006-08-11 18:52:28 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMP3.dll
[2006-08-11 18:52:28 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIFCD3.dll
[2006-08-11 18:52:28 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK7.dll
[2006-07-11 23:19:00 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006-07-11 23:19:00 | 01,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006-07-11 23:19:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006-07-11 23:19:00 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-07-11 23:19:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006-07-11 23:19:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006-07-11 23:19:00 | 00,196,608 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005-10-31 03:17:38 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2005-10-26 07:25:28 | 00,008,073 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005-10-12 17:43:40 | 00,000,095 | ---- | C] () -- C:\WINDOWS\alaunch.ini
[2005-08-05 14:38:54 | 00,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005-07-12 13:44:42 | 00,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL
[2005-04-04 08:44:04 | 00,000,258 | ---- | C] () -- C:\WINDOWS\Clearlnk.ini
[2004-12-17 03:14:44 | 00,013,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\UBHelper.sys
[2004-08-10 21:00:00 | 00,003,712 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004-03-23 15:38:00 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll
[2001-12-26 14:12:30 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001-09-03 21:46:38 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001-07-30 14:33:56 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001-07-23 20:04:36 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1999-01-22 19:46:58 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ========== [2008-01-20 23:21:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg7
[2008-11-19 17:10:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EBP
[2007-07-06 18:43:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2009-03-03 08:47:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2007-12-20 22:36:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Exetender
[2007-11-14 23:15:59 | 00,000,000 | R--D | M] -- C:\Documents and Settings\All Users\Application Data\sansendommagement
[2009-04-06 14:32:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2007-12-17 16:28:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009-04-29 12:52:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TerraTec
[2007-07-06 18:43:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2008-11-19 17:10:34 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{C8DB1474-929D-4C8B-A9D1-364CB144A9BB}
[2008-01-20 23:11:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\AVG7
[2007-11-27 09:47:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\Leadertech
[2007-07-06 18:45:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\Nikon
[2009-03-08 20:40:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\OpenOffice.org
[2007-11-14 23:20:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\sansendommagement
[2009-04-29 12:52:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\TerraTec
[2008-11-07 15:32:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\RAMIRO RUIZ Evelyne\Application Data\Windows Media Metering
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2003-04-10 15:04:02 | 00,000,006 | ---- | M] () -- C:\ad.dll
[2009-03-03 08:47:05 | 00,000,000 | ---- | M] () -- C:\AdobeDebug.txt
[2003-04-10 15:04:12 | 00,000,006 | ---- | M] () -- C:\ap.dll
[2003-04-10 15:04:12 | 00,000,006 | ---- | M] () -- C:\as.dll
[2006-08-11 18:52:52 | 00,000,050 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007-01-23 17:19:39 | 00,000,221 | RHS- | M] () -- C:\boot.ini
[2004-08-10 21:00:00 | 00,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2009-12-01 01:07:35 | 00,001,245 | ---- | M] () -- C:\cleannavi.txt
[2006-08-11 18:29:28 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009-12-01 01:06:58 | 80,483,5328 | -HS- | M] () -- C:\hiberfil.sys
[2006-08-11 18:29:28 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2006-08-11 18:29:28 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004-08-10 21:00:00 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2004-08-10 21:00:00 | 00,251,712 | RHS- | M] () -- C:\ntldr
[2009-12-01 01:06:57 | 12,079,59552 | -HS- | M] () -- C:\pagefile.sys
[2006-08-11 20:18:22 | 00,000,079 | ---- | M] () -- C:\preload.aaa
[2008-01-20 22:40:29 | 00,005,402 | ---- | M] () -- C:\rapport.txt
[2007-12-22 00:03:48 | 00,014,898 | ---- | M] () -- C:\RECUP.DOC
[2006-08-11 18:41:40 | 00,000,499 | ---- | M] () -- C:\RHDSetup.log
[2008-02-14 19:45:44 | 74,844,734 | ---- | M] () -- C:\Sauv.reg
[2009-05-03 19:28:50 | 00,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2009-05-18 22:41:52 | 00,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2009-09-02 17:51:15 | 00,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2009-09-03 01:01:47 | 00,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2008-02-11 11:16:09 | 00,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2008-02-11 11:16:09 | 00,000,172 | -H-- | M] () -- C:\sqmdata05.sqm
[2008-02-11 11:16:09 | 00,000,172 | -H-- | M] () -- C:\sqmdata06.sqm
[2008-02-11 11:16:09 | 00,000,172 | -H-- | M] () -- C:\sqmdata07.sqm
[2008-03-22 21:07:18 | 00,000,232 | -H-- | M] () -- C:\sqmdata08.sqm
[2008-04-23 19:38:38 | 00,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2008-04-23 19:38:38 | 00,000,148 | -H-- | M] () -- C:\sqmdata10.sqm
[2008-10-12 22:43:52 | 00,000,304 | -H-- | M] () -- C:\sqmdata11.sqm
[2008-11-12 16:58:58 | 00,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2009-01-16 00:38:09 | 00,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2009-01-16 00:38:09 | 00,000,148 | -H-- | M] () -- C:\sqmdata14.sqm
[2009-01-30 19:24:25 | 00,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2009-02-21 18:56:13 | 00,000,232 | -H-- | M] () -- C:\sqmdata16.sqm
[2009-02-22 22:13:09 | 00,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2009-02-26 22:16:07 | 00,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2009-02-26 22:16:25 | 00,000,268 | -H-- | M] () -- C:\sqmdata19.sqm
[2009-09-02 17:51:15 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009-09-03 01:01:47 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2008-02-11 11:14:59 | 00,000,136 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2008-02-11 11:16:09 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2008-02-11 11:16:09 | 00,000,172 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2008-02-11 11:16:09 | 00,000,172 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2008-02-11 11:16:09 | 00,000,172 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2008-03-22 21:07:18 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2008-04-23 19:38:38 | 00,000,136 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2008-10-12 22:43:52 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2008-11-12 16:58:58 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2009-01-16 00:38:08 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2009-01-16 00:38:09 | 00,000,136 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2009-01-30 19:24:25 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2009-02-21 18:56:12 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2009-02-22 22:13:09 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2009-02-26 22:16:07 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2009-02-26 22:16:25 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2009-05-03 19:28:50 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2009-05-18 22:41:52 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2008-02-14 19:46:44 | 00,002,505 | ---- | M] () -- C:\TCleaner.txt
[2008-02-08 22:12:05 | 00,000,152 | ---- | M] () -- C:\YServer.txt
< %PROGRAMFILES%\*.* > < %PROGRAMFILES%\*. >[2006-09-30 07:10:20 | 00,000,000 | ---D | M] -- C:\Program Files\Acer WLAN 11g USB Dongle
[2009-11-22 04:10:28 | 00,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009-09-07 21:57:13 | 00,000,000 | ---D | M] -- C:\Program Files\Ahead
[2007-09-21 18:58:31 | 00,000,000 | ---D | M] -- C:\Program Files\Alwil Software
[2009-05-11 19:11:31 | 00,000,000 | ---D | M] -- C:\Program Files\Avira
[2008-11-14 01:14:23 | 00,000,000 | ---D | M] -- C:\Program Files\CE project
[2006-09-30 07:10:25 | 00,000,000 | ---D | M] -- C:\Program Files\commercial
[2006-08-11 18:27:20 | 00,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2006-09-30 07:10:25 | 00,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2006-09-30 07:10:30 | 00,000,000 | ---D | M] -- C:\Program Files\DIFX
[2007-11-11 20:01:19 | 00,000,000 | ---D | M] -- C:\Program Files\Disc2Phone
[2008-11-19 17:10:24 | 00,000,000 | ---D | M] -- C:\Program Files\EBP
[2009-12-01 00:43:48 | 00,000,000 | ---D | M] -- C:\Program Files\ERUNT
[2009-09-17 19:46:45 | 00,000,000 | ---D | M] -- C:\Program Files\Fichiers communs
[2009-03-10 23:21:47 | 00,000,000 | ---D | M] -- C:\Program Files\Firebird
[2009-10-23 23:37:55 | 00,000,000 | ---D | M] -- C:\Program Files\Foci - Photo et Loisirs numeriques
[2006-09-30 07:10:35 | 00,000,000 | ---D | M] -- C:\Program Files\FrenchOtto
[2006-09-30 07:10:35 | 00,000,000 | ---D | M] -- C:\Program Files\GemMasterFrench
[2009-01-24 22:55:40 | 00,000,000 | ---D | M] -- C:\Program Files\Google
[2007-05-15 09:35:12 | 00,000,000 | ---D | M] -- C:\Program Files\Grisoft
[2008-01-23 02:27:27 | 00,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2007-12-25 21:52:50 | 00,000,000 | ---D | M] -- C:\Program Files\HP
[2009-03-10 23:21:45 | 00,000,000 | ---D | M] -- C:\Program Files\ImobilPro v.5.0
[2009-09-07 21:56:15 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009-10-16 02:15:37 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2008-09-13 13:36:15 | 00,000,000 | ---D | M] -- C:\Program Files\Java
[2009-03-08 20:38:24 | 00,000,000 | ---D | M] -- C:\Program Files\JRE
[2008-09-11 20:52:48 | 00,000,000 | ---D | M] -- C:\Program Files\Macrogaming
[2009-11-27 19:34:59 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008-08-15 09:36:22 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009-09-17 19:59:15 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2007-05-17 08:53:59 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2007-09-21 19:54:51 | 00,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009-03-08 20:14:39 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2009-09-19 02:08:27 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2009-09-17 20:00:39 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2009-09-17 20:01:34 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Sync Framework
[2009-03-08 20:16:29 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2007-05-30 23:11:42 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Works Suite 2002
[2009-12-01 01:02:57 | 00,000,000 | ---D | M] -- C:\Program Files\MioNet
[2006-09-30 07:10:36 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2009-12-01 19:45:41 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009-08-15 13:02:17 | 00,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2007-01-23 17:25:30 | 00,000,000 | ---D | M] -- C:\Program Files\MSN
[2006-09-30 07:10:37 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2007-12-27 09:36:09 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2009-04-07 02:00:30 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2009-12-01 01:07:37 | 00,000,000 | ---D | M] -- C:\Program Files\Navilog1
[2006-09-30 07:10:38 | 00,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2007-04-27 20:43:51 | 00,000,000 | ---D | M] -- C:\Program Files\Neuf
[2006-09-30 07:10:41 | 00,000,000 | ---D | M] -- C:\Program Files\NewTech Infosystems
[2007-07-06 18:39:59 | 00,000,000 | ---D | M] -- C:\Program Files\Nikon
[2007-05-15 09:29:05 | 00,000,000 | ---D | M] -- C:\Program Files\Norton AntiVirus
[2006-09-30 07:10:56 | 00,000,000 | ---D | M] -- C:\Program Files\Oca History Tool
[2006-09-30 07:10:56 | 00,000,000 | ---D | M] -- C:\Program Files\Online Services
[2008-09-14 16:54:54 | 00,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.2
[2008-09-14 17:31:54 | 00,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 2.4
[2009-03-08 20:38:21 | 00,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 3
[2009-08-13 02:01:39 | 00,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2009-09-07 21:56:18 | 00,000,000 | ---D | M] -- C:\Program Files\Philips
[2009-11-13 19:55:46 | 00,000,000 | ---D | M] -- C:\Program Files\Picasa2
[2007-12-20 22:36:42 | 00,000,000 | ---D | M] -- C:\Program Files\Player Metaboli
[2006-09-30 07:10:56 | 00,000,000 | ---D | M] -- C:\Program Files\Realtek
[2009-08-15 13:02:08 | 00,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2008-11-14 12:55:01 | 00,000,000 | ---D | M] -- C:\Program Files\RescuePRO
[2006-09-30 07:11:00 | 00,000,000 | ---D | M] -- C:\Program Files\Services en ligne
[2009-05-15 19:05:18 | 00,000,000 | R--D | M] -- C:\Program Files\Skype
[2009-04-06 14:32:26 | 00,000,000 | ---D | M] -- C:\Program Files\SmartSound Software
[2007-05-15 09:29:05 | 00,000,000 | ---D | M] -- C:\Program Files\Symantec
[2009-04-29 12:52:00 | 00,000,000 | ---D | M] -- C:\Program Files\TerraTec
[2008-09-09 21:36:46 | 00,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2006-08-11 18:40:40 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009-09-17 20:02:05 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2009-09-17 19:58:58 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2007-09-14 15:06:29 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2007-09-14 15:09:41 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2006-09-30 07:11:00 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2006-09-30 07:11:01 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Plus
[2006-08-11 18:28:26 | 00,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2007-12-18 00:53:58 | 00,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2006-09-30 07:11:02 | 00,000,000 | ---D | M] -- C:\Program Files\xerox
[2008-09-11 20:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2009-04-19 22:00:38 | 00,000,000 | ---D | M] -- C:\Program Files\Zuma Deluxe
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-11-26 02:02:01
========== Alternate Data Streams ========== @Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >