Bonsoir Grosbébé,
Voici le rapport OTL
OTL logfile created on: 2010-01-25 12:16:41 - Run 5
OTL by OldTimer - Version 3.1.25.2 Folder = C:\Users\cfred\Desktop\Bibou
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 56,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 298,09 Gb Total Space | 187,71 Gb Free Space | 62,97% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 298,09 Gb Total Space | 227,15 Gb Free Space | 76,20% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC-CFRED-RESEAU
Current User Name: cfred
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010-01-20 15:17:30 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Users\cfred\Desktop\Bibou\OTL.exe
PRC - [2010-01-02 01:40:20 | 00,638,216 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009-12-22 22:57:42 | 00,117,640 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe
PRC - [2009-10-27 22:31:14 | 00,257,440 | R--- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10d.exe
PRC - [2009-08-17 00:32:00 | 00,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009-07-14 12:29:06 | 00,215,584 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvvsvc.exe
PRC - [2009-06-30 16:10:30 | 00,116,280 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
PRC - [2009-04-11 01:28:08 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2009-04-11 01:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009-03-30 15:28:36 | 01,533,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
PRC - [2009-03-30 15:28:36 | 00,183,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
PRC - [2009-03-17 12:25:40 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2008-12-18 10:17:58 | 00,124,208 | ---- | M] (RapidSolution Software AG) -- C:\Program Files\RapidSolution\Tunebite\vcdw\VCDAudioService.exe
PRC - [2008-12-12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008-05-02 01:44:08 | 00,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008-05-02 01:42:18 | 00,059,920 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\SetPoint\LBTWiz.exe
PRC - [2008-05-02 01:42:06 | 00,121,360 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
PRC - [2008-05-02 01:40:56 | 00,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
PRC - [2008-01-19 02:33:39 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2008-01-19 02:33:37 | 00,397,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Mail\WinMail.exe
PRC - [2007-11-01 10:59:23 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\Common Files\Motive\McciCMService.exe
PRC - [2007-07-19 16:54:48 | 00,689,408 | ---- | M] (American Power Conversion Corporation) -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
PRC - [2007-07-19 16:54:40 | 00,656,640 | ---- | M] (American Power Conversion Corporation) -- C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
PRC - [2007-06-27 09:18:08 | 00,223,448 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
PRC - [2007-06-27 09:17:26 | 00,272,600 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe
PRC - [2007-06-27 09:17:12 | 00,446,680 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
PRC - [2007-06-27 09:16:02 | 00,157,912 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
PRC - [2007-06-27 09:15:14 | 00,059,096 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
PRC - [2007-06-27 09:14:46 | 00,317,656 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe
PRC - [2007-06-27 09:14:40 | 00,439,512 | ---- | M] (Intel Corporation) -- C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
PRC - [2007-06-27 09:13:56 | 00,268,504 | ---- | M] () -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
PRC - [2007-05-29 10:19:08 | 00,198,240 | ---- | M] () -- c:\hp\HPEZBTN\HPBtnSrv.exe
PRC - [2007-05-28 11:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2007-05-24 07:13:54 | 00,061,440 | ---- | M] (Hewlett-Packard) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
PRC - [2007-03-11 21:34:40 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2007-02-12 10:46:34 | 00,208,896 | ---- | M] () -- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
PRC - [2006-12-19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\Windows\System32\IoctlSvc.exe
========== Modules (SafeList) ========== MOD - [2010-01-20 15:17:30 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Users\cfred\Desktop\Bibou\OTL.exe
MOD - [2009-04-11 01:21:38 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (.1205680892)
SRV - [2009-12-22 22:57:42 | 00,117,640 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe -- (N360)
SRV - [2009-10-28 19:21:14 | 00,545,568 | ---- | M] (Apple Inc.) [On_Demand | Stopped] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009-09-24 20:27:04 | 00,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009-08-17 00:32:00 | 00,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009-07-14 12:29:06 | 00,215,584 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Windows\System32\nvvsvc.exe -- (nvsvc)
SRV - [2009-03-30 15:28:36 | 01,533,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009-03-17 12:25:40 | 00,073,728 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2009-02-20 22:05:05 | 00,133,104 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c993d1418e1bd0) Google Update Service (gupdate1c993d1418e1bd0)
SRV - [2008-12-18 10:17:58 | 00,124,208 | ---- | M] (RapidSolution Software AG) [Auto | Running] -- C:\Program Files\RapidSolution\Tunebite\vcdw\VCDAudioService.exe -- (Virtual CDAudio Service)
SRV - [2008-12-12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008-05-02 01:42:06 | 00,121,360 | ---- | M] (Logitech, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008-04-30 19:05:51 | 00,072,704 | ---- | M] (SolidWorks) [On_Demand | Stopped] -- C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2008-04-08 08:56:30 | 00,800,040 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService)
SRV - [2008-01-22 10:13:26 | 00,275,752 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2008-01-19 02:38:24 | 00,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2007-11-01 10:59:23 | 00,303,104 | ---- | M] (Motive Communications, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Motive\McciCMService.exe -- (McciCMService)
SRV - [2007-07-19 16:54:48 | 00,689,408 | ---- | M] (American Power Conversion Corporation) [Auto | Running] -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe -- (APC UPS Service)
SRV - [2007-06-27 09:18:08 | 00,223,448 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe -- (AlertService) Intel(R)
SRV - [2007-06-27 09:17:26 | 00,272,600 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe -- (QualityManager) Intel(R)
SRV - [2007-06-27 09:17:12 | 00,446,680 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe -- (Remote UI Service) Intel(R)
SRV - [2007-06-27 09:16:02 | 00,157,912 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe -- (MCLServiceATL) Intel(R)
SRV - [2007-06-27 09:15:28 | 00,039,640 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe -- (DHTRACE) Intel(R)
SRV - [2007-06-27 09:15:14 | 00,059,096 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe -- (ISSM) Intel(R)
SRV - [2007-06-27 09:14:46 | 00,317,656 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe -- (NMSCore) Intel(R)
SRV - [2007-06-27 09:13:56 | 00,268,504 | ---- | M] () [Auto | Running] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe -- (M1 Server) Intel(R) Viiv(TM)
SRV - [2007-05-29 10:19:08 | 00,198,240 | ---- | M] () [Auto | Running] -- c:\hp\HPEZBTN\HPBtnSrv.exe -- (HPBtnSrv)
SRV - [2007-05-28 11:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2007-05-24 07:13:54 | 00,061,440 | ---- | M] (Hewlett-Packard) [Auto | Running] -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service)
SRV - [2007-03-11 21:24:50 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) [On_Demand | Stopped] -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08)
SRV - [2007-02-12 10:46:34 | 00,208,896 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe -- (DQLWinService)
SRV - [2006-12-19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\Windows\System32\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
SRV - [2006-11-08 15:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Windows\System32\HPZipm12.dll -- (Pml Driver HPZ12)
SRV - [2006-11-08 15:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Windows\System32\HPZinw12.dll -- (Net Driver HPZ12)
SRV - [2006-11-02 07:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\ehome\ehstart.dll -- (ehstart)
SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://news.google.ca/news?hl=fr&tab=wn&pz=1&cf=all&ned=fr_ca&q&cf=all&cf=allIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..extensions.enabledItems:
smartwebprinting@hp.com:4.51
FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009-08-08 17:44:34 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-19 15:23:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-19 15:23:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-19 15:23:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-19 15:23:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-19 15:23:29 | 00,000,000 | ---D | M]
[2009-09-07 19:42:06 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\mozilla\Extensions
[2009-05-26 22:31:50 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\mozilla\Extensions\home2@tomtom.com
[2008-12-06 23:27:20 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\mozilla\Extensions\songbird@songbirdnest.com
[2009-12-06 22:48:33 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\mozilla\Firefox\Profiles\e3rks4v3.default\extensions
[2009-07-23 15:01:30 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\mozilla\Firefox\Profiles(78)\83luws8q.default\extensions
[2009-11-04 02:47:54 | 00,002,059 | ---- | M] () -- C:\Users\cfred\AppData\Roaming\Mozilla\FireFox\Profiles\e3rks4v3.default\searchplugins\daemon-search.xml
[2009-12-13 15:56:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-11-29 02:28:02 | 00,002,206 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O1 HOSTS File: ([2010-01-03 04:35:10 | 00,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Aide pour le lien d'Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PopupFilter Class) - {1F2E844B-8211-46ff-8262-772F03295CF4} - C:\Program Files\Aladdin Systems\Internet Cleanup\PopFiltr.dll (Aladdin Systems, Inc.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.5.2.11\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe ()
O9 - Extra Button: Afficher ou masquer l'HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: hp.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: hp.com ([]https in Trusted sites)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A}
http://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab (DjVuCtl Class)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\HPDCS {ba135f49-a12c-4e26-a2c4-6ea945999072} - Reg Error: Key error. File not found
O18 - Protocol\Handler\hppfile {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\hppsam {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\hppzip {C4E2084B-ED27-4893-A43D-488CA3F370E2} - C:\Program Files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\cfred\AppData\Roaming\Microsoft\Windows Photo Gallery\Papier peint de la Galerie de photos Windows.jpg
O24 - Desktop BackupWallPaper: C:\Users\cfred\AppData\Roaming\Microsoft\Windows Photo Gallery\Papier peint de la Galerie de photos Windows.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-03-16 10:43:50 | 00,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 14 Days ========== [2010-01-24 12:42:52 | 00,000,000 | ---D | C] -- C:\Users\cfred\DoctorWeb
[2010-01-22 19:39:26 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2010-01-22 19:36:28 | 00,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2010-01-21 13:04:51 | 00,000,000 | ---D | C] -- C:\_OTL
[2010-01-19 19:11:15 | 00,000,000 | -H-D | C] -- C:\Config.Msi
[2010-01-17 13:33:18 | 00,000,000 | ---D | C] -- C:\Users\cfred\AppData\Roaming\SUPERAntiSpyware.com
[2010-01-16 15:56:43 | 00,000,000 | ---D | C] -- C:\Users\cfred\Desktop\Bibou
========== Files - Modified Within 14 Days ========== [2010-01-25 12:18:00 | 00,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{5CAF3D54-9580-412A-8F55-E3E37F035434}.job
[2010-01-25 12:16:50 | 06,553,600 | ---- | M] () -- C:\Users\cfred\ntuser.dat
[2010-01-25 11:43:44 | 00,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010-01-25 11:43:43 | 00,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010-01-25 11:43:43 | 00,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010-01-25 11:43:42 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010-01-25 11:43:37 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010-01-25 11:43:24 | 32,204,96384 | -HS- | M] () -- C:\hiberfil.sys
[2010-01-25 02:18:37 | 00,003,335 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010-01-25 02:18:34 | 00,524,288 | -HS- | M] () -- C:\Users\cfred\ntuser.dat{c5ad1a54-cc8d-11de-96e1-00076171e5ab}.TMContainer00000000000000000001.regtrans-ms
[2010-01-25 02:18:34 | 00,065,536 | -HS- | M] () -- C:\Users\cfred\ntuser.dat{c5ad1a54-cc8d-11de-96e1-00076171e5ab}.TM.blf
[2010-01-25 02:18:29 | 02,958,012 | -H-- | M] () -- C:\Users\cfred\AppData\Local\IconCache.db
[2010-01-25 01:43:00 | 00,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010-01-24 12:34:40 | 28,511,856 | ---- | M] () -- C:\Users\cfred\Desktop\e6w6x656.exe
[2010-01-22 19:40:47 | 00,124,771 | ---- | M] () -- C:\Windows\hpgins21.dat
[2010-01-22 19:36:56 | 00,001,259 | ---- | M] () -- C:\Users\Public\Desktop\Centre de solutions HP.lnk
[2010-01-20 12:26:47 | 01,470,810 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010-01-20 12:26:47 | 00,669,328 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2010-01-20 12:26:47 | 00,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010-01-20 12:26:47 | 00,123,350 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2010-01-20 12:26:47 | 00,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010-01-17 23:21:21 | 00,019,944 | ---- | M] () -- C:\Windows\System32\drivers\atapi.sys
[2010-01-17 23:13:50 | 00,019,944 | ---- | M] () -- C:\Windows\System32\drivers\kav_atapi.sys
[2010-01-16 16:57:46 | 00,310,288 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010-01-16 01:24:44 | 00,002,671 | ---- | M] () -- C:\Users\cfred\Desktop\Microsoft Word.lnk
========== Files Created - No Company Name ========== [2010-01-24 12:34:39 | 28,511,856 | ---- | C] () -- C:\Users\cfred\Desktop\e6w6x656.exe
[2010-01-22 19:36:56 | 00,001,259 | ---- | C] () -- C:\Users\Public\Desktop\Centre de solutions HP.lnk
[2010-01-22 19:32:22 | 00,124,770 | ---- | C] () -- C:\Windows\hpgins21.dat.temp
[2010-01-22 19:32:21 | 00,000,282 | ---- | C] () -- C:\Windows\hpgmdl21.dat.temp
[2010-01-17 23:13:50 | 00,019,944 | ---- | C] () -- C:\Windows\System32\drivers\kav_atapi.sys
[2010-01-16 16:57:31 | 32,204,96384 | -HS- | C] () -- C:\hiberfil.sys
[2009-11-23 21:08:12 | 00,000,391 | ---- | C] () -- C:\Windows\CoverEdCtrl.INI
[2009-11-04 03:09:12 | 00,069,632 | R--- | C] () -- C:\Windows\System32\xmltok.dll
[2009-11-04 03:09:11 | 00,036,864 | R--- | C] () -- C:\Windows\System32\xmlparse.dll
[2009-10-28 14:29:40 | 00,000,940 | ---- | C] () -- C:\Windows\bdoscandellang.ini
[2009-08-29 13:37:41 | 00,000,000 | ---- | C] () -- C:\Windows\ViewNX.INI
[2009-08-29 11:03:19 | 00,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009-08-08 19:13:34 | 00,032,879 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009-08-08 17:17:00 | 00,032,879 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009-08-07 21:32:33 | 00,000,680 | ---- | C] () -- C:\Users\cfred\AppData\Local\d3d9caps.dat
[2009-07-04 20:31:50 | 00,000,391 | ---- | C] () -- C:\Windows\COVERE~1.INI
[2009-06-28 18:57:44 | 00,000,000 | ---- | C] () -- C:\Windows\hpqEmlSz.INI
[2009-05-30 03:32:10 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009-05-30 03:31:43 | 00,019,944 | ---- | C] () -- C:\Windows\System32\drivers\atapi.sys
[2009-05-09 23:41:35 | 00,000,206 | ---- | C] () -- C:\Windows\System32\eacaea4_d.dll
[2009-03-23 19:06:23 | 00,000,039 | ---- | C] () -- C:\Windows\Irremote.ini
[2009-01-06 20:51:52 | 00,112,689 | ---- | C] () -- C:\Users\cfred\AppData\Local\ss24.swf
[2009-01-06 20:49:11 | 00,091,376 | ---- | C] () -- C:\Users\cfred\AppData\Local\ss03.swf
[2009-01-06 20:49:08 | 00,136,773 | ---- | C] () -- C:\Users\cfred\AppData\Local\ss02.swf
[2009-01-06 20:49:01 | 00,072,682 | ---- | C] () -- C:\Users\cfred\AppData\Local\ss01.swf
[2009-01-06 20:17:52 | 00,000,268 | RH-- | C] () -- C:\ProgramData\Tables
[2009-01-06 20:17:52 | 00,000,268 | RH-- | C] () -- C:\Users\cfred\AppData\Roaming\Synth Pads
[2009-01-06 20:17:52 | 00,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdw.DAT
[2009-01-06 20:15:44 | 00,000,268 | RH-- | C] () -- C:\ProgramData\System Image Utility
[2009-01-06 20:15:44 | 00,000,268 | RH-- | C] () -- C:\Users\cfred\AppData\Roaming\Synth Basics
[2009-01-06 20:15:44 | 00,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2008-06-11 08:02:34 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008-06-11 08:02:34 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008-06-11 08:02:34 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008-06-11 08:02:34 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008-06-11 08:02:34 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008-06-11 08:02:34 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008-06-11 08:02:32 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008-06-11 08:02:32 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008-06-11 08:02:32 | 00,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008-06-05 07:58:26 | 00,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008-04-30 19:02:18 | 00,000,000 | ---- | C] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2008-04-29 18:30:00 | 00,009,728 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2008-03-28 21:44:00 | 00,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2008-03-20 20:52:53 | 00,065,536 | ---- | C] () -- C:\Windows\System32\Gif89.dll
[2008-03-17 15:01:27 | 00,000,382 | ---- | C] () -- C:\Windows\ODBC.INI
[2008-03-16 20:09:24 | 00,034,304 | ---- | C] () -- C:\Users\cfred\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-03-16 17:06:54 | 00,000,000 | ---- | C] () -- C:\Users\cfred\AppData\Roaming\wklnhst.dat
[2008-03-16 10:40:20 | 00,015,934 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008-03-16 10:25:52 | 00,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
[2008-03-16 10:25:52 | 00,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
[2007-12-20 17:55:14 | 00,110,592 | ---- | C] () -- C:\Windows\System32\hppatusg01.dll
[2007-12-20 17:54:18 | 00,126,976 | ---- | C] () -- C:\Windows\System32\HPDevEnm.dll
[2006-11-02 07:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006-11-02 02:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006-06-23 09:09:34 | 00,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll
[2006-06-13 15:35:32 | 00,053,760 | ---- | C] () -- C:\Windows\System32\zlib.dll
========== LOP Check ========== [2008-12-19 21:00:55 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Aladdin Systems
[2009-12-17 01:21:05 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\BitTorrent
[2008-04-30 19:04:46 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\DWGeditor
[2008-03-23 22:21:25 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\eMule
[2008-07-29 22:01:02 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Eyeblaster
[2009-12-13 02:18:43 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Fighters
[2009-08-08 18:07:37 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Image Zone Express
[2009-04-24 23:41:54 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\magellangps.com
[2008-08-09 18:32:14 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\MysteryStudio
[2009-01-06 20:31:35 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Nikon
[2008-08-02 00:27:47 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Printer Info Cache
[2009-12-13 01:34:20 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Songbird2
[2008-03-19 15:48:24 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\Template
[2010-01-05 22:21:42 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\uTorrent
[2009-06-22 22:54:56 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\WidgetRadioSRC.13BC082BABA5407D3C98AC73F5DE7F4088D231BF.1
[2008-03-24 18:11:03 | 00,000,000 | ---D | M] -- C:\Users\cfred\AppData\Roaming\WinBatch
[2010-01-25 02:18:37 | 00,032,588 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010-01-25 12:18:00 | 00,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{5CAF3D54-9580-412A-8F55-E3E37F035434}.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:0AC32449
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:7C412B92
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:FC2E567F
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:7B52659E
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8C6D2EC3
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:C8E82994
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:62672BC8
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:ADF211B1
< End of report >