OTS logfile created on: 18/03/2010 19:01:58 - Run 1
OTS by OldTimer - Version 3.1.27.1 Folder = D:\Nicolas\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 56,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 75,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111,69 Gb Total Space | 32,61 Gb Free Space | 29,19% Space Free | Partition Type: NTFS
Drive D: | 108,19 Gb Total Space | 59,60 Gb Free Space | 55,09% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC-DE-NICOLAS
Current User Name: Nicolas
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots.exe -> D:\Nicolas\Downloads\OTS.exe -> [2010/03/18 18:59:53 | 000,637,440 | ---- | M] (OldTimer Tools)
safari.exe -> C:\Program Files\Safari\Safari.exe -> [2009/11/05 21:14:44 | 001,794,848 | ---- | M] (Apple Inc.)
explorer.exe -> C:\Windows\explorer.exe -> [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation)
itouch-server-win.exe -> C:\Program Files\Logitech Touch Mouse Server\iTouch-Server-Win.exe -> [2009/10/23 22:59:56 | 000,228,352 | ---- | M] (Logitech, Inc.)
cvhsvc.exe -> C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE -> [2009/09/26 07:35:02 | 000,819,600 | ---- | M] (Microsoft Corporation)
sftvsa.exe -> C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -> [2009/09/23 15:04:56 | 000,203,608 | ---- | M] (Microsoft Corporation)
sftlist.exe -> C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -> [2009/09/23 15:04:52 | 000,447,832 | ---- | M] (Microsoft Corporation)
avguard.exe -> C:\Program Files\Avira\AntiVir Desktop\avguard.exe -> [2009/08/22 23:18:16 | 000,185,089 | ---- | M] (Avira GmbH)
sched.exe -> C:\Program Files\Avira\AntiVir Desktop\sched.exe -> [2009/07/15 13:13:36 | 000,108,289 | ---- | M] (Avira GmbH)
snmp.exe -> C:\Windows\System32\snmp.exe -> [2009/07/14 02:14:39 | 000,047,616 | ---- | M] (Microsoft Corporation)
conhost.exe -> C:\Windows\System32\conhost.exe -> [2009/07/14 02:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation)
wlidsvc.exe -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -> [2009/03/30 15:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation)
wlidsvcm.exe -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe -> [2009/03/30 15:28:36 | 000,183,152 | ---- | M] (Microsoft Corporation)
avgnt.exe -> C:\Program Files\Avira\AntiVir Desktop\avgnt.exe -> [2009/03/02 12:08:11 | 000,209,153 | ---- | M] (Avira GmbH)
evteng.exe -> C:\Program Files\Intel\WiFi\bin\EvtEng.exe -> [2009/02/27 06:54:22 | 000,870,672 | ---- | M] (Intel(R) Corporation)
regsrvc.exe -> C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -> [2009/02/27 05:38:38 | 000,473,360 | ---- | M] (Intel(R) Corporation)
rthdvcpl.exe -> C:\Windows\RtHDVCpl.exe -> [2007/12/14 09:56:00 | 004,702,208 | ---- | M] (Realtek Semiconductor)
qtzgacer.exe -> C:\Program Files\Launch Manager\QtZgAcer.EXE -> [2007/12/14 09:56:00 | 000,707,080 | ---- | M] (Dritek System Inc.)
iaantmon.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2007/12/14 09:55:00 | 000,354,840 | ---- | M] (Intel Corporation)
iaanotif.exe -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe -> [2007/12/14 09:55:00 | 000,174,616 | ---- | M] (Intel Corporation)
syntpstart.exe -> C:\Program Files\Synaptics\SynTP\SynTPStart.exe -> [2007/12/14 09:55:00 | 000,102,400 | ---- | M] (Synaptics, Inc.)
rs_service.exe -> C:\Program Files\Acer\Acer VCM\RS_Service.exe -> [2007/09/28 19:18:24 | 000,233,472 | ---- | M] (Acer Inc.)
erecoveryservice.exe -> C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -> [2007/09/10 15:28:18 | 000,057,344 | ---- | M] (Acer Inc.)
rocketdock.exe -> C:\Program Files\RocketDock\RocketDock.exe -> [2007/09/02 12:58:52 | 000,495,616 | ---- | M] ()
starwindserviceae.exe -> C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -> [2007/05/28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software)
alaunchsvc.exe -> C:\Acer\ALaunch\ALaunchSvc.exe -> [2007/01/26 14:24:42 | 000,050,688 | ---- | M] ()
mobilityservice.exe -> C:\Acer\Mobility Center\MobilityService.exe -> [2006/11/24 12:57:54 | 000,107,008 | ---- | M] ()
[Modules - Safe List]
ots.exe -> D:\Nicolas\Downloads\OTS.exe -> [2010/03/18 18:59:53 | 000,637,440 | ---- | M] (OldTimer Tools)
sspicli.dll -> C:\Windows\System32\sspicli.dll -> [2009/07/14 02:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation)
sechost.dll -> C:\Windows\System32\sechost.dll -> [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation)
samcli.dll -> C:\Windows\System32\samcli.dll -> [2009/07/14 02:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation)
profapi.dll -> C:\Windows\System32\profapi.dll -> [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation)
netutils.dll -> C:\Windows\System32\netutils.dll -> [2009/07/14 02:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation)
kernelbase.dll -> C:\Windows\System32\KernelBase.dll -> [2009/07/14 02:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation)
dwmapi.dll -> C:\Windows\System32\dwmapi.dll -> [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation)
devobj.dll -> C:\Windows\System32\devobj.dll -> [2009/07/14 02:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation)
cryptbase.dll -> C:\Windows\System32\cryptbase.dll -> [2009/07/14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation)
cfgmgr32.dll -> C:\Windows\System32\cfgmgr32.dll -> [2009/07/14 02:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation)
comctl32.dll -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll -> [2009/07/14 02:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(cvhsvc) Client Virtualization Handler [Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE -> [2009/09/26 07:35:02 | 000,819,600 | ---- | M] (Microsoft Corporation)
(osppsvc) Office Software Protection Platform [On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -> [2009/09/26 04:28:22 | 004,639,136 | ---- | M] (Microsoft Corporation)
(sftvsa) Application Virtualization Service Agent [On_Demand | Running] -> C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -> [2009/09/23 15:04:56 | 000,203,608 | ---- | M] (Microsoft Corporation)
(sftlist) Application Virtualization Client [Auto | Running] -> C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -> [2009/09/23 15:04:52 | 000,447,832 | ---- | M] (Microsoft Corporation)
(AntiVirService) Avira AntiVir Guard [Auto | Running] -> C:\Program Files\Avira\AntiVir Desktop\avguard.exe -> [2009/08/22 23:18:16 | 000,185,089 | ---- | M] (Avira GmbH)
(fsssvc) Service Windows Live Contrôle parental [On_Demand | Stopped] -> C:\Program Files\Windows Live\Family Safety\fsssvc.exe -> [2009/08/05 21:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation)
(AntiVirSchedulerService) Avira AntiVir Planificateur [Auto | Running] -> C:\Program Files\Avira\AntiVir Desktop\sched.exe -> [2009/07/15 13:13:36 | 000,108,289 | ---- | M] (Avira GmbH)
(WwanSvc) Service de configuration automatique WWAN [On_Demand | Stopped] -> C:\Windows\System32\wwansvc.dll -> [2009/07/14 02:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation)
(WbioSrvc) Service de biométrie Windows [On_Demand | Stopped] -> C:\Windows\System32\wbiosrvc.dll -> [2009/07/14 02:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation)
(Power) Alimentation [Auto | Running] -> C:\Windows\System32\umpo.dll -> [2009/07/14 02:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation)
(Themes) Thèmes [Auto | Running] -> C:\Windows\System32\themeservice.dll -> [2009/07/14 02:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation)
(sppuinotify) Service de notification SPP [On_Demand | Stopped] -> C:\Windows\System32\sppuinotify.dll -> [2009/07/14 02:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation)
(RpcEptMapper) Mappeur de point de terminaison RPC [Unknown | Running] -> C:\Windows\System32\RpcEpMap.dll -> [2009/07/14 02:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation)
(SensrSvc) Brillance adaptative [On_Demand | Stopped] -> C:\Windows\System32\sensrsvc.dll -> [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation)
(PNRPsvc) Protocole PNRP [On_Demand | Stopped] -> C:\Windows\System32\pnrpsvc.dll -> [2009/07/14 02:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation)
(p2pimsvc) Gestionnaire d’identité réseau homologue [On_Demand | Stopped] -> C:\Windows\System32\pnrpsvc.dll -> [2009/07/14 02:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation)
(HomeGroupProvider) Fournisseur HomeGroup [On_Demand | Running] -> C:\Windows\System32\provsvc.dll -> [2009/07/14 02:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation)
(PNRPAutoReg) Service de publication des noms d’ordinateurs PNRP [On_Demand | Stopped] -> C:\Windows\System32\pnrpauto.dll -> [2009/07/14 02:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation)
(WinDefend) Windows Defender [On_Demand | Stopped] -> C:\Program Files\Windows Defender\mpsvc.dll -> [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation)
(HomeGroupListener) Écouteur HomeGroup [On_Demand | Stopped] -> C:\Windows\System32\ListSvc.dll -> [2009/07/14 02:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation)
(FontCache) Service de cache de police Windows [On_Demand | Stopped] -> C:\Windows\System32\FntCache.dll -> [2009/07/14 02:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation)
(Dhcp) Client DHCP [Auto | Running] -> C:\Windows\System32\dhcpcore.dll -> [2009/07/14 02:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation)
(defragsvc) Défragmenteur de disque [On_Demand | Stopped] -> C:\Windows\System32\defragsvc.dll -> [2009/07/14 02:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation)
(BDESVC) Service de chiffrement de lecteur BitLocker [Unknown | Stopped] -> C:\Windows\System32\bdesvc.dll -> [2009/07/14 02:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation)
(AxInstSV) Programme d’installation ActiveX (AxInstSV) [On_Demand | Stopped] -> C:\Windows\System32\AxInstSv.dll -> [2009/07/14 02:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation)
(AppIDSvc) Identité de l’application [On_Demand | Stopped] -> C:\Windows\System32\appidsvc.dll -> [2009/07/14 02:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation)
(SNMP) Service SNMP [Auto | Running] -> C:\Windows\System32\snmp.exe -> [2009/07/14 02:14:39 | 000,047,616 | ---- | M] (Microsoft Corporation)
(sppsvc) Protection logicielle [Auto | Stopped] -> C:\Windows\System32\sppsvc.exe -> [2009/07/14 02:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation)
(wlidsvc) Windows Live ID Sign-in Assistant [Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -> [2009/03/30 15:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation)
(EvtEng) Intel(R) PROSet/Wireless Event Log [Auto | Running] -> C:\Program Files\Intel\WiFi\bin\EvtEng.exe -> [2009/02/27 06:54:22 | 000,870,672 | ---- | M] (Intel(R) Corporation)
(RegSrvc) Intel(R) PROSet/Wireless Registry Service [Auto | Running] -> C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -> [2009/02/27 05:38:38 | 000,473,360 | ---- | M] (Intel(R) Corporation)
(IAANTMON) Intel(R) Matrix Storage Event Monitor [Auto | Running] -> C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -> [2007/12/14 09:55:00 | 000,354,840 | ---- | M] (Intel Corporation)
(RS_Service) Raw Socket Service [Auto | Running] -> C:\Program Files\Acer\Acer VCM\RS_Service.exe -> [2007/09/28 19:18:24 | 000,233,472 | ---- | M] (Acer Inc.)
(eRecoveryService) eRecovery Service [Auto | Running] -> C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -> [2007/09/10 15:28:18 | 000,057,344 | ---- | M] (Acer Inc.)
(StarWindServiceAE) StarWind AE Service [Auto | Running] -> C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -> [2007/05/28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software)
(ALaunchService) ALaunch Service [Auto | Running] -> C:\Acer\ALaunch\ALaunchSvc.exe -> [2007/01/26 14:24:42 | 000,050,688 | ---- | M] ()
(MobilityService) MobilityService [Auto | Running] -> C:\Acer\Mobility Center\MobilityService.exe -> [2006/11/24 12:57:54 | 000,107,008 | ---- | M] ()
[Driver Services - Safe List]
(avgntflt) avgntflt [File_System | Auto | Running] -> C:\Windows\System32\drivers\avgntflt.sys -> [2009/12/10 22:46:18 | 000,056,816 | ---- | M] (Avira GmbH)
(sptd) sptd [Kernel | Boot | Running] -> C:\Windows\System32\Drivers\sptd.sys -> [2009/11/07 12:24:20 | 000,721,904 | ---- | M] ()
(Sftredir) Sftredir [File_System | On_Demand | Running] -> C:\Windows\System32\drivers\Sftredirlh.sys -> [2009/09/23 15:04:56 | 000,021,848 | ---- | M] (Microsoft Corporation)
(sftvol) sftvol [Kernel | On_Demand | Running] -> C:\Program Files\Microsoft Application Virtualization Client\drivers\sftvollh.sys -> [2009/09/23 15:04:56 | 000,014,680 | ---- | M] (Microsoft Corporation)
(sftplay) sftplay [Kernel | On_Demand | Running] -> C:\Program Files\Microsoft Application Virtualization Client\drivers\sftplaylh.sys -> [2009/09/23 15:04:54 | 000,190,312 | ---- | M] (Microsoft Corporation)
(sftfs) sftfs [Kernel | On_Demand | Running] -> C:\Program Files\Microsoft Application Virtualization Client\drivers\sftfslh.sys -> [2009/09/23 15:04:50 | 000,543,064 | ---- | M] (Microsoft Corporation)
(nvlddmkm) nvlddmkm [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\nvlddmkm.sys -> [2009/08/06 17:16:00 | 009,824,000 | ---- | M] (NVIDIA Corporation)
(fssfltr) fssfltr [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\fssfltr.sys -> [2009/08/05 21:48:42 | 000,054,632 | ---- | M] (Microsoft Corporation)
(ssmdrv) ssmdrv [Kernel | System | Running] -> C:\Windows\System32\drivers\ssmdrv.sys -> [2009/07/15 13:13:36 | 000,028,520 | ---- | M] (Avira GmbH)
(cmdide) cmdide [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\cmdide.sys -> [2009/07/14 02:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.)
(adpahci) adpahci [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\adpahci.sys -> [2009/07/14 02:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.)
(adp94xx) adp94xx [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\adp94xx.sys -> [2009/07/14 02:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.)
(amdsbs) amdsbs [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\amdsbs.sys -> [2009/07/14 02:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.)
(adpu320) adpu320 [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\adpu320.sys -> [2009/07/14 02:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.)
(arcsas) arcsas [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\arcsas.sys -> [2009/07/14 02:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.)
(amdsata) amdsata [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\amdsata.sys -> [2009/07/14 02:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices)
(arc) arc [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\arc.sys -> [2009/07/14 02:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.)
(amdxata) amdxata [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\amdxata.sys -> [2009/07/14 02:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices)
(aliide) aliide [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\aliide.sys -> [2009/07/14 02:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.)
(nvstor) nvstor [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\nvstor.sys -> [2009/07/14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation)
(nvraid) nvraid [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\nvraid.sys -> [2009/07/14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation)
(nfrd960) nfrd960 [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\nfrd960.sys -> [2009/07/14 02:20:44 | 000,044,624 | ---- | M] (IBM Corporation)
(LSI_SAS) LSI_SAS [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\lsi_sas.sys -> [2009/07/14 02:20:37 | 000,089,168 | ---- | M] (LSI Corporation)
(iaStorV) iaStorV [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\iaStorV.sys -> [2009/07/14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation)
(MegaSR) MegaSR [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\MegaSR.sys -> [2009/07/14 02:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.)
(KSecPkg) KSecPkg [Kernel | Boot | Running] -> C:\Windows\System32\Drivers\ksecpkg.sys -> [2009/07/14 02:20:36 | 000,133,200 | ---- | M] (Microsoft Corporation)
(LSI_SCSI) LSI_SCSI [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\lsi_scsi.sys -> [2009/07/14 02:20:36 | 000,096,848 | ---- | M] (LSI Corporation)
(LSI_FC) LSI_FC [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\lsi_fc.sys -> [2009/07/14 02:20:36 | 000,095,824 | ---- | M] (LSI Corporation)
(LSI_SAS2) LSI_SAS2 [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\lsi_sas2.sys -> [2009/07/14 02:20:36 | 000,054,864 | ---- | M] (LSI Corporation)
(iirsp) iirsp [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\iirsp.sys -> [2009/07/14 02:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH)
(megasas) megasas [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\megasas.sys -> [2009/07/14 02:20:36 | 000,030,800 | ---- | M] (LSI Corporation)
(hwpolicy) Hardware Policy Driver [Kernel | Boot | Running] -> C:\Windows\System32\drivers\hwpolicy.sys -> [2009/07/14 02:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation)
(elxstor) elxstor [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\elxstor.sys -> [2009/07/14 02:20:28 | 000,453,712 | ---- | M] (Emulex)
(aic78xx) aic78xx [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\djsvs.sys -> [2009/07/14 02:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.)
(HpSAMD) HpSAMD [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\HpSAMD.sys -> [2009/07/14 02:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company)
(FsDepends) File System Dependency Minifilter [File_System | On_Demand | Stopped] -> C:\Windows\System32\drivers\fsdepends.sys -> [2009/07/14 02:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation)
(vsmraid) vsmraid [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\vsmraid.sys -> [2009/07/14 02:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd)
(vhdmp) vhdmp [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\vhdmp.sys -> [2009/07/14 02:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation)
(vdrvroot) Pilote d’énumérateur de lecteur virtuel Microsoft [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\vdrvroot.sys -> [2009/07/14 02:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation)
(WIMMount) WIMMount [File_System | On_Demand | Stopped] -> C:\Windows\System32\drivers\wimmount.sys -> [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation)
(viaide) viaide [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\viaide.sys -> [2009/07/14 02:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.)
(ql2300) ql2300 [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\ql2300.sys -> [2009/07/14 02:19:04 | 001,383,488 | ---- | M] (QLogic Corporation)
(rdyboost) ReadyBoost [Kernel | Boot | Running] -> C:\Windows\System32\drivers\rdyboost.sys -> [2009/07/14 02:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation)
(ql40xx) ql40xx [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\ql40xx.sys -> [2009/07/14 02:19:04 | 000,106,064 | ---- | M] (QLogic Corporation)
(SiSRaid4) SiSRaid4 [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\sisraid4.sys -> [2009/07/14 02:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems)
(pcw) Performance Counters for Windows Driver [Kernel | Boot | Running] -> C:\Windows\System32\drivers\pcw.sys -> [2009/07/14 02:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation)
(SiSRaid2) SiSRaid2 [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\SiSRaid2.sys -> [2009/07/14 02:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.)
(stexstor) stexstor [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\stexstor.sys -> [2009/07/14 02:19:04 | 000,021,072 | ---- | M] (Promise Technology)
(CNG) CNG [Kernel | Boot | Running] -> C:\Windows\System32\Drivers\cng.sys -> [2009/07/14 02:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation)
(Brserid) Brother MFC Serial Port Interface Driver (WDM) [Kernel | On_Demand | Stopped] -> C:\Windows\System32\Drivers\Brserid.sys -> [2009/07/14 01:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.)
(rdpbus) Remote Desktop Device Redirector Bus Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\rdpbus.sys -> [2009/07/14 01:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation)
(RDPREFMP) Reflector Display Driver used to gain access to graphics data [Kernel | System | Running] -> C:\Windows\System32\drivers\RDPREFMP.sys -> [2009/07/14 01:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation)
(RasAgileVpn) WAN Miniport (IKEv2) [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\agilevpn.sys -> [2009/07/14 00:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation)
(WfpLwf) WFP Lightweight Filter [Kernel | System | Running] -> C:\Windows\System32\drivers\wfplwf.sys -> [2009/07/14 00:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation)
(NdisCap) NDIS Capture LightWeight Filter [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\ndiscap.sys -> [2009/07/14 00:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation)
(vwifibus) Pilote de bus WiFi virtuel [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\vwifibus.sys -> [2009/07/14 00:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation)
(1394ohci) Contrôleur d’hôte compatible OHCI 1394 [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\1394ohci.sys -> [2009/07/14 00:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation)
(UmPass) Microsoft UMPass Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\umpass.sys -> [2009/07/14 00:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation)
(WinUsb) WinUsb [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\winusb.sys -> [2009/07/14 00:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation)
(mshidkmdf) Pass-through HID to KMDF Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\mshidkmdf.sys -> [2009/07/14 00:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation)
(MTConfig) Microsoft Input Configuration Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\MTConfig.sys -> [2009/07/14 00:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation)
(CompositeBus) Pilote de l’énumérateur de bus composite [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\CompositeBus.sys -> [2009/07/14 00:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation)
(AppID) Pilote AppID [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\appid.sys -> [2009/07/14 00:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation)
(scfilter) Pilote de filtre de classe PnP de carte à puce [Kernel | Unknown | Stopped] -> C:\Windows\System32\drivers\scfilter.sys -> [2009/07/14 00:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation)
(discache) System Attribute Cache [Kernel | System | Running] -> C:\Windows\System32\drivers\discache.sys -> [2009/07/14 00:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation)
(HidBatt) HID UPS Battery Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\HidBatt.sys -> [2009/07/14 00:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation)
(AcpiPmi) ACPI Power Meter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\acpipmi.sys -> [2009/07/14 00:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation)
(AmdPPM) AMD Processor Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\amdppm.sys -> [2009/07/14 00:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation)
(hcw85cir) Hauppauge Consumer Infrared Receiver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\hcw85cir.sys -> [2009/07/13 23:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.)
(BrUsbMdm) Brother MFC USB Fax Only Modem [Kernel | On_Demand | Stopped] -> C:\Windows\System32\Drivers\BrUsbMdm.sys -> [2009/07/13 23:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.)
(BrUsbSer) Brother MFC USB Serial WDM Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\Drivers\BrUsbSer.sys -> [2009/07/13 23:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.)
(BrSerWdm) Brother WDM Serial driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\Drivers\BrSerWdm.sys -> [2009/07/13 23:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.)
(BrFiltLo) Brother USB Mass-Storage Lower Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\BrFiltLo.sys -> [2009/07/13 23:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.)
(BrFiltUp) Brother USB Mass-Storage Upper Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\BrFiltUp.sys -> [2009/07/13 23:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.)
(netw5v32) Pilote de carte de liaison WiFi sans fil Intel(R) 5000 Series pour Windows Vista 32 bits [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\netw5v32.sys -> [2009/07/13 23:02:51 | 004,231,168 | ---- | M] (Intel Corporation)
(b57nd60x) Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\b57nd60x.sys -> [2009/07/13 23:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation)
(ebdrv) Broadcom NetXtreme II 10 GigE VBD [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\evbdx.sys -> [2009/07/13 23:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation)
(b06bdrv) Broadcom NetXtreme II VBD [Kernel | On_Demand | Stopped] -> C:\Windows\system32\DRIVERS\bxvbdx.sys -> [2009/07/13 23:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation)
(VClone) VClone [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\VClone.sys -> [2009/05/23 00:08:32 | 000,029,696 | ---- | M] (Elaborate Bytes AG)
(avipbb) avipbb [Kernel | System | Running] -> C:\Windows\System32\drivers\avipbb.sys -> [2009/03/30 09:32:47 | 000,096,104 | ---- | M] (Avira GmbH)
(ElbyCDIO) ElbyCDIO Driver [Kernel | System | Running] -> C:\Windows\System32\drivers\ElbyCDIO.sys -> [2009/02/17 18:11:30 | 000,024,232 | ---- | M] (Elaborate Bytes AG)
(avgio) avgio [Kernel | System | Running] -> C:\Program Files\Avira\AntiVir Desktop\avgio.sys -> [2009/02/13 11:34:33 | 000,011,608 | ---- | M] (Avira GmbH)
(NTIDrvr) Upper Class Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\NTIDrvr.sys -> [2007/12/21 06:07:59 | 000,006,144 | ---- | M] (NewTech Infosystems, Inc.)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\RTKVHDA.sys -> [2007/12/14 09:56:00 | 001,950,552 | ---- | M] (Realtek Semiconductor Corp.)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\HSX_DPV.sys -> [2007/12/14 09:56:00 | 000,984,064 | ---- | M] (Conexant Systems, Inc.)
(winachsf) winachsf [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\HSX_CNXT.sys -> [2007/12/14 09:56:00 | 000,660,480 | ---- | M] (Conexant Systems, Inc.)
(iaStor) Intel AHCI Controller [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\iaStor.sys -> [2007/12/14 09:56:00 | 000,277,784 | ---- | M] (Intel Corporation)
(HSXHWAZL) HSXHWAZL [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\HSXHWAZL.sys -> [2007/12/14 09:56:00 | 000,208,384 | ---- | M] (Conexant Systems, Inc.)
(winbondcir) Winbond IR Transceiver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\winbondcir.sys -> [2007/12/14 09:56:00 | 000,043,008 | ---- | M] (Winbond Electronics Corporation)
(DKbFltr) Dritek Keyboard Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\DKbFltr.sys -> [2007/12/14 09:56:00 | 000,021,264 | ---- | M] (Dritek System Inc.)
(XAudio) XAudio [Kernel | Auto | Running] -> C:\Windows\System32\drivers\XAudio.sys -> [2007/12/14 09:56:00 | 000,008,704 | ---- | M] (Conexant Systems, Inc.)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\SynTP.sys -> [2007/12/14 09:55:00 | 000,192,816 | ---- | M] (Synaptics, Inc.)
(NETw4v32) Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\NETw4v32.sys -> [2007/09/26 12:12:22 | 002,251,776 | ---- | M] (Intel Corporation)
(CrystalSysInfo) CrystalSysInfo [Kernel | On_Demand | Stopped] -> C:\Program Files\MediaCoder iPod Edition\SysInfo.sys -> [2007/09/25 15:59:46 | 000,015,152 | ---- | M] ()
(rimmptsk) rimmptsk [Kernel | Auto | Running] -> C:\Windows\System32\drivers\rimmptsk.sys -> [2007/08/08 20:42:08 | 000,045,568 | ---- | M] (REDC)
(rismxdp) Ricoh xD-Picture Card Driver [Kernel | Auto | Running] -> C:\Windows\System32\drivers\rixdptsk.sys -> [2007/07/30 11:54:02 | 000,038,400 | ---- | M] (REDC)
(rimsptsk) rimsptsk [Kernel | Auto | Running] -> C:\Windows\System32\drivers\rimsptsk.sys -> [2007/07/30 10:42:58 | 000,043,008 | ---- | M] (REDC)
(BDASwCap) AVerMedia A310 BDA DVBT Capture Device [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\AVerA310Cap.sys -> [2007/07/10 03:16:00 | 000,042,240 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.)
(A310) AVerMedia A310 DVB-T [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\AVerA310USB.sys -> [2007/07/10 03:16:00 | 000,026,368 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.)
(int15) int15 [Kernel | Auto | Running] -> C:\Acer\Empowering Technology\eRecovery\int15.sys -> [2007/07/03 10:05:20 | 000,015,392 | ---- | M] (Acer, Inc.)
(SNP2UVC) USB2.0 PC Camera (SNP2UVC) [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\snp2uvc.sys -> [2007/06/12 10:38:26 | 001,729,152 | ---- | M] ()
(VNUSB) VN Series Device [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\VNUSB.sys -> [2006/04/07 17:06:38 | 000,038,496 | ---- | M] (OLYMPUS IMAGING CORP.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" ->
http://fr.fr.acer.yahoo.com ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\] > -> ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\: Main\\"SearchMigratedDefaultName" -> Yahoo! Search ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\: Main\\"SearchMigratedDefaultURL" ->
http://search.yahoo.com/search [...] 8&fr=b1ie7 ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\: Main\\"Start Page" ->
http://google.fr/ ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\: Main\\"StartPageCache" -> 1 ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\: "ProxyOverride" -> *.local ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
< FireFox Extensions [User Folders] > ->
< HOSTS File > ([2006/09/18 22:41:30 | 000,000,736 | ---- | M] - 20 lines) -> C:\Windows\System32\drivers\etc\hosts ->
Reset Hosts
::1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} [HKLM] -> C:\Program Files\FlashGet\jccatch.dll [FGCatchUrl] -> [2007/08/06 10:11:58 | 000,094,308 | ---- | M] (www.flashget.com)
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} [HKLM] -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Browser Helper] -> [2009/02/12 14:19:32 | 002,217,848 | ---- | M] (Microsoft Corporation)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [Google Toolbar Notifier BHO] -> [2009/07/15 15:14:53 | 000,668,656 | ---- | M] (Google Inc.)
{F156768E-81EF-470C-9057-481BA8380DBA} [HKLM] -> C:\Program Files\FlashGet\getflash.dll [FlashGet GetFlash Class] -> [2007/05/18 17:13:10 | 000,163,840 | ---- | M] (www.flashget.com)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"avgnt" -> C:\Program Files\Avira\AntiVir Desktop\avgnt.exe ["C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min] -> [2009/03/02 12:08:11 | 000,209,153 | ---- | M] (Avira GmbH)
"IAAnotif" -> C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe] -> [2007/12/14 09:55:00 | 000,174,616 | ---- | M] (Intel Corporation)
"LManager" -> C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE] -> [2007/12/14 09:56:00 | 000,707,080 | ---- | M] (Dritek System Inc.)
"LXBUCATS" -> C:\Windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.DLL [rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16] -> [2007/02/22 04:12:02 | 000,073,728 | ---- | M] ()
"NvCplDaemon" -> C:\Windows\System32\NvCpl.DLL [RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup] -> [2009/08/06 18:48:22 | 013,797,920 | ---- | M] (NVIDIA Corporation)
"PLFSet" -> C:\Windows\PLFSet.DLL [rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting] -> [2007/04/25 13:47:34 | 000,045,056 | ---- | M] ( )
"RtHDVCpl" -> C:\Windows\RtHDVCpl.exe [RtHDVCpl.exe] -> [2007/12/14 09:56:00 | 004,702,208 | ---- | M] (Realtek Semiconductor)
"Skytel" -> C:\Windows\SkyTel.exe [Skytel.exe] -> [2007/12/14 09:56:00 | 001,826,816 | ---- | M] (Realtek Semiconductor Corp.)
"SynTPStart" -> C:\Program Files\Synaptics\SynTP\SynTPStart.exe [C:\Program Files\Synaptics\SynTP\SynTPStart.exe] -> [2007/12/14 09:55:00 | 000,102,400 | ---- | M] (Synaptics, Inc.)
< RunOnce [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->
"mctadmin" -> C:\Windows\System32\mctadmin.exe [C:\Windows\System32\mctadmin.exe] -> [2009/07/14 02:14:23 | 000,093,696 | ---- | M] (Microsoft Corporation)
< RunOnce [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->
"mctadmin" -> C:\Windows\System32\mctadmin.exe [C:\Windows\System32\mctadmin.exe] -> [2009/07/14 02:14:23 | 000,093,696 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"RocketDock" -> C:\Program Files\RocketDock\RocketDock.exe ["C:\Program Files\RocketDock\RocketDock.exe"] -> [2007/09/02 12:58:52 | 000,495,616 | ---- | M] ()
< Software Policy Settings [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [255] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" -> [5] -> File not found
\\"ConsentPromptBehaviorUser" -> [3] -> File not found
\\"HideLegacyLogonScripts" -> [0] -> File not found
\\"HideLogoffScripts" -> [0] -> File not found
\\"HideStartupScripts" -> [0] -> File not found
\\"RunLogonScriptSync" -> [1] -> File not found
\\"RunStartupScriptSync" -> [1] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"HideLegacyLogonScripts" -> [0] -> File not found
\\"HideLogoffScripts" -> [0] -> File not found
\\"HideStartupScripts" -> [0] -> File not found
\\"RunLogonScriptSync" -> [1] -> File not found
\\"RunStartupScriptSync" -> [1] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\Software\Microsoft\Internet Explorer\MenuExt\ ->
&Télécharger avec FlashGet -> C:\Program Files\FlashGet\jc_link.htm [C:\Program Files\FlashGet\jc_link.htm] -> [2007/05/18 17:13:10 | 000,001,898 | ---- | M] ()
&Tout télécharger avec FlashGet -> C:\Program Files\FlashGet\jc_all.htm [C:\Program Files\FlashGet\jc_all.htm] -> [2007/05/18 17:13:10 | 000,001,049 | ---- | M] ()
E&xporter vers Microsoft Excel -> C:\Programmes\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [Button: Ajout Direct] -> [2009/07/26 19:17:14 | 000,186,192 | ---- | M] (Microsoft Corporation)
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [Menu: &Ajout Direct dans Windows Live Writer] -> [2009/07/26 19:17:14 | 000,186,192 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll [Button: Envoyer à OneNote] -> [2008/10/25 06:52:00 | 000,604,056 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll [Menu: &Envoyer à OneNote] -> [2008/10/25 06:52:00 | 000,604,056 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL [Button: Research] -> [2009/03/06 03:04:56 | 000,039,464 | ---- | M] (Microsoft Corporation)
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}:Exec [HKLM] -> C:\Program Files\FlashGet\FlashGet.exe [Button: FlashGet] -> [2007/09/25 09:10:50 | 002,007,088 | ---- | M] (FlashGet.com)
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}:Exec [HKLM] -> C:\Program Files\FlashGet\FlashGet.exe [Menu: FlashGet] -> [2007/09/25 09:10:50 | 002,007,088 | ---- | M] (FlashGet.com)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" ->
http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. ->
line6.net .
localhost .[http] -> Trusted sites ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\] > -> HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-4119355899-2911314421-214302231-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{04CB5B64-5915-4629-B869-8945CEBADD21} [HKLM] ->
https://static.impots.gouv.fr/ [...] rtdgi1.cab [Module de délivrance de certificat MINEFI] ->
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} [HKLM] ->
http://webscanner.kaspersky.fr [...] nicode.cab [CKAVWebScan Object] ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] ->
http://download.macromedia.com [...] tor/sw.cab [Shockwave ActiveX Control] ->
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] ->
http://download.microsoft.com/ [...] ontrol.cab [Windows Genuine Advantage Validation Tool] ->
{1E54D648-B804-468d-BC78-4AFFED8E262F} [HKLM] ->
http://www.nvidia.com/content/ [...] ab_nvd.cab [System Requirements Lab Class] ->
{39B0684F-D7BF-4743-B050-FDC3F48F7E3B} [HKLM] ->
http://www.fileplanet.com/fpdl [...] .7.109.cab [CDownloadCtrl Object] ->
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] ->
http://dlm.tools.akamai.com/dl [...] .2.4.8.cab [DLM Control] ->
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} [HKLM] ->
http://download.divx.com/playe [...] Plugin.cab [DivXBrowserPlugin Object] ->
{88764F69-3831-4EC1-B40B-FF21D8381345} [HKLM] ->
https://static.impots.gouv.fr/ [...] DP-1.1.cab [AdVerifierADPCtrl Class] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] ->
http://java.sun.com/update/1.6 [...] s-i586.cab [Java Plug-in 1.6.0_14] ->
{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [HKLM] ->
http://java.sun.com/update/1.6 [...] s-i586.cab [Java Plug-in 1.6.0_14] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] ->
http://java.sun.com/update/1.6 [...] s-i586.cab [Java Plug-in 1.6.0_14] ->
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] ->
http://platformdl.adobe.com/NO [...] 1.6/gp.cab [Reg Error: Key error.] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.1.254 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{ECAD6550-649C-45FE-AF24-1D83F1F6C410}\\DhcpNameServer -> 192.168.1.254 (Liaison WiFi sans fil Intel(R) 4965AGN) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\Windows\explorer.exe -> [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
SystemPropertiesPerformance.exe -> C:\Windows\System32\SystemPropertiesPerformance.exe -> [2009/07/14 02:14:42 | 000,081,920 | ---- | M] (Microsoft Corporation)
/pagefile -> -> File not found
*MultiFile Done* -> ->
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Stub Execution Hook] -> [2009/02/12 14:19:32 | 002,217,848 | ---- | M] (Microsoft Corporation)
< LSA Security Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
*LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
pku2u -> C:\Windows\System32\pku2u.dll -> [2009/07/14 02:16:12 | 000,186,880 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"C:\Acer\Empowering Technology\eDataSecurity\decryption.exe" -> C:\Acer\Empowering Technology\eDataSecurity\decryption.exe [C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption] -> File not found
"C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe" -> C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe [C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu] -> File not found
"C:\Acer\Empowering Technology\eDataSecurity\encryption.exe" -> C:\Acer\Empowering Technology\eDataSecurity\encryption.exe [C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption] -> File not found
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> Pilote de CD-ROM ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\autoexec.bat [REM Dummy file for NTVDM | ] -> C:\autoexec.bat [ NTFS ] -> [2009/06/10 22:42:20 | 000,000,024 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
[Registry - Additional Scans - Safe List]
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
batfile [open] -> "%1" %* ->
cmdfile [open] -> "%1" %* ->
comfile [open] -> "%1" %* ->
cplfile [cplopen] -> %SystemRoot%\System32\control.exe "%1",%* -> [2009/07/14 02:14:15 | 000,113,152 | ---- | M] (Microsoft Corporation)
exefile [open] -> "%1" %* ->
hlpfile [open] -> %SystemRoot%\winhlp32.exe %1 -> [2009/07/14 02:14:45 | 000,009,728 | ---- | M] (Microsoft Corporation)
htmlfile [edit] -> "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 -> [2008/11/10 09:50:30 | 000,068,472 | ---- | M] (Microsoft Corporation)
htmlfile [print] -> "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 -> [2008/11/10 09:50:30 | 000,068,472 | ---- | M] (Microsoft Corporation)
piffile [open] -> "%1" %* ->
scrfile [config] -> "%1" ->
scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2009/07/14 02:14:08 | 000,128,000 | ---- | M] (Microsoft Corporation)
scrfile [open] -> "%1" /S ->
Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 ->
Directory [cmd] -> cmd.exe /s /k pushd "%V" -> [2009/07/14 02:14:15 | 000,301,568 | ---- | M] (Microsoft Corporation)
Directory [find] -> %SystemRoot%\Explorer.exe -> [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation)
Directory [OneNote.Open] -> C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" -> File not found
Folder [open] -> %SystemRoot%\Explorer.exe -> [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation)
Drive [find] -> %SystemRoot%\Explorer.exe -> [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation)
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
[Files/Folders - Created Within 30 Days]
Trend Micro -> C:\Program Files\Trend Micro -> [2010/03/18 15:42:07 | 000,000,000 | ---D | C]
RootRepeal -> C:\RootRepeal -> [2010/03/18 15:36:04 | 000,000,000 | ---D | C]
Vega5maj -> C:\Vega5maj -> [2010/03/15 19:48:50 | 000,000,000 | ---D | C]
Vega5 -> C:\Vega5 -> [2010/03/15 19:48:50 | 000,000,000 | ---D | C]
browserchoice.exe -> C:\Windows\System32\browserchoice.exe -> [2010/03/15 15:50:33 | 000,293,376 | ---- | C] (Microsoft Corporation)
Applications -> C:\Users\Nicolas\Bureau\Applications -> [2010/03/13 16:32:17 | 000,000,000 | -H-D | C]
Outils -> C:\Users\Nicolas\Bureau\Outils -> [2010/03/12 23:14:39 | 000,000,000 | RH-D | C]
Multimedia -> C:\Users\Nicolas\Bureau\Multimedia -> [2010/03/12 23:00:06 | 000,000,000 | RH-D | C]
Image -> C:\Users\Nicolas\Bureau\Image -> [2010/03/12 19:50:07 | 000,000,000 | RH-D | C]
Energie -> C:\Users\Nicolas\Bureau\Energie -> [2010/03/12 19:43:14 | 000,000,000 | -H-D | C]
Digital Wave Player -> D:\Nicolas\Documents\Digital Wave Player -> [2010/03/11 22:38:47 | 000,000,000 | ---D | C]
SNWValid.dll -> C:\Windows\System32\SNWValid.dll -> [2010/03/11 21:55:32 | 000,231,936 | R--- | C] (Cendant Software)
SierraNW.dll -> C:\Windows\System32\SierraNW.dll -> [2010/03/11 21:55:31 | 001,022,976 | R--- | C] (Cendant Software)
IsUninst.Exe -> C:\Windows\IsUninst.Exe -> [2010/03/11 21:55:28 | 000,327,168 | ---- | C] (InstallShield Software Corporation)
MFC250.DLL -> C:\Windows\System32\MFC250.DLL -> [2010/03/11 21:54:46 | 000,320,880 | R--- | C] (Microsoft Corporation)
MFCOLEUI.DLL -> C:\Windows\System32\MFCOLEUI.DLL -> [2010/03/11 21:54:46 | 000,146,976 | R--- | C] (Microsoft Corporation)
MFCO250.DLL -> C:\Windows\System32\MFCO250.DLL -> [2010/03/11 21:54:46 | 000,125,344 | R--- | C] (Microsoft Corporation)
MFCD250.DLL -> C:\Windows\System32\MFCD250.DLL -> [2010/03/11 21:54:46 | 000,051,920 | R--- | C] (Microsoft Corporation)
MFCN250.DLL -> C:\Windows\System32\MFCN250.DLL -> [2010/03/11 21:54:46 | 000,011,072 | R--- | C] (Microsoft Corporation)
Sierra On-Line -> C:\Program Files\Sierra On-Line -> [2010/03/11 21:54:30 | 000,000,000 | ---D | C]
SIERRA -> C:\SIERRA -> [2010/03/11 21:54:30 | 000,000,000 | ---D | C]
Unity -> C:\Users\Nicolas\AppData\Local\Unity -> [2010/03/11 20:12:53 | 000,000,000 | ---D | C]
jscript.dll -> C:\Windows\System32\jscript.dll -> [2010/02/24 18:39:12 | 000,716,800 | ---- | C] (Microsoft Corporation)
CPFilters.dll -> C:\Windows\System32\CPFilters.dll -> [2010/02/24 18:39:09 | 000,641,536 | ---- | C] (Microsoft Corporation)
psisdecd.dll -> C:\Windows\System32\psisdecd.dll -> [2010/02/24 18:39:09 | 000,465,408 | ---- | C] (Microsoft Corporation)
msdri.dll -> C:\Windows\System32\msdri.dll -> [2010/02/24 18:39:09 | 000,417,792 | ---- | C] (Microsoft Corporation)
MSNP.ax -> C:\Windows\System32\MSNP.ax -> [2010/02/24 18:39:09 | 000,204,288 | ---- | C] (Microsoft Corporation)
tzres.dll -> C:\Windows\System32\tzres.dll -> [2010/02/24 18:39:06 | 000,002,048 | ---- | C] (Microsoft Corporation)
LiveCAD3 -> C:\Users\Nicolas\AppData\Roaming\LiveCAD3 -> [2010/02/21 22:59:39 | 000,000,000 | ---D | C]
XAudio2_6.dll -> C:\Windows\System32\XAudio2_6.dll -> [2010/02/21 22:59:32 | 000,528,216 | ---- | C] (Microsoft Corporation)
xactengine3_6.dll -> C:\Windows\System32\xactengine3_6.dll -> [2010/02/21 22:59:32 | 000,238,936 | ---- | C] (Microsoft Corporation)
XAPOFX1_4.dll -> C:\Windows\System32\XAPOFX1_4.dll -> [2010/02/21 22:59:32 | 000,074,072 | ---- | C] (Microsoft Corporation)
X3DAudio1_7.dll -> C:\Windows\System32\X3DAudio1_7.dll -> [2010/02/21 22:59:31 | 000,022,360 | ---- | C] (Microsoft Corporation)
XAudio2_5.dll -> C:\Windows\System32\XAudio2_5.dll -> [2010/02/21 22:59:30 | 000,515,416 | ---- | C] (Microsoft Corporation)
XAPOFX1_3.dll -> C:\Windows\System32\XAPOFX1_3.dll -> [2010/02/21 22:59:30 | 000,069,464 | ---- | C] (Microsoft Corporation)
d3dcsx_42.dll -> C:\Windows\System32\d3dcsx_42.dll -> [2010/02/21 22:59:29 | 005,501,792 | ---- | C] (Microsoft Corporation)
D3DCompiler_42.dll -> C:\Windows\System32\D3DCompiler_42.dll -> [2010/02/21 22:59:29 | 001,974,616 | ---- | C] (Microsoft Corporation)
d3dx10_42.dll -> C:\Windows\System32\d3dx10_42.dll -> [2010/02/21 22:59:29 | 000,453,456 | ---- | C] (Microsoft Corporation)
xactengine3_5.dll -> C:\Windows\System32\xactengine3_5.dll -> [2010/02/21 22:59:29 | 000,238,936 | ---- | C] (Microsoft Corporation)
d3dx11_42.dll -> C:\Windows\System32\d3dx11_42.dll -> [2010/02/21 22:59:29 | 000,235,344 | ---- | C] (Microsoft Corporation)
D3DX9_42.dll -> C:\Windows\System32\D3DX9_42.dll -> [2010/02/21 22:59:28 | 001,892,184 | ---- | C] (Microsoft Corporation)
XAudio2_2.dll -> C:\Windows\System32\XAudio2_2.dll -> [2010/02/21 22:59:27 | 000,509,448 | ---- | C] (Microsoft Corporation)
XAPOFX1_1.dll -> C:\Windows\System32\XAPOFX1_1.dll -> [2010/02/21 22:59:27 | 000,068,616 | ---- | C] (Microsoft Corporation)
xactengine3_2.dll -> C:\Windows\System32\xactengine3_2.dll -> [2010/02/21 22:59:26 | 000,238,088 | ---- | C] (Microsoft Corporation)
msdownld.tmp -> C:\Windows\msdownld.tmp -> [2010/02/21 22:44:12 | 000,000,000 | -H-D | C]
directx -> C:\Windows\System32\directx -> [2010/02/21 22:44:09 | 000,000,000 | ---D | C]
LiveCAD -> C:\Program Files\LiveCAD -> [2010/02/21 22:43:50 | 000,000,000 | ---D | C]
My Stationery -> D:\Nicolas\Documents\My Stationery -> [2010/02/20 16:25:50 | 000,000,000 | R-SD | C]
Bouygues-BboxMini.649F13D0CDF968A472A16014E8BC8A2ED131D04E.1 -> C:\Users\Nicolas\AppData\Roaming\Bouygues-BboxMini.649F13D0CDF968A472A16014E8BC8A2ED131D04E.1 -> [2010/02/19 17:43:12 | 000,000,000 | ---D | C]
Bouygues Telecom Mes services en un clic -> C:\Program Files\Bouygues Telecom Mes services en un clic -> [2010/02/19 17:43:09 | 000,000,000 | ---D | C]
Adobe AIR -> C:\Program Files\Common Files\Adobe AIR -> [2010/02/19 17:43:07 | 000,000,000 | ---D | C]
Plans -> D:\Nicolas\Documents\Plans -> [2010/02/18 21:23:40 | 000,000,000 | ---D | C]
LXBUhcp.dll -> C:\Windows\System32\LXBUhcp.dll -> [2009/08/23 14:30:56 | 000,323,584 | ---- | C] ( )
lxdehcp.dll -> C:\Windows\System32\lxdehcp.dll -> [2009/05/14 20:19:28 | 000,434,176 | ---- | C] ( )
PLFSet.dll -> C:\Windows\PLFSet.dll -> [2008/01/20 17:48:05 | 000,045,056 | ---- | C] ( )
rsnp2uvc.dll -> C:\Windows\System32\rsnp2uvc.dll -> [2008/01/20 17:48:04 | 000,172,032 | ---- | C] ( )
csnp2uvc.dll -> C:\Windows\System32\csnp2uvc.dll -> [2008/01/20 17:48:04 | 000,053,248 | ---- | C] ( )
lxdepmui.dll -> C:\Windows\System32\lxdepmui.dll -> [2007/05/17 15:08:58 | 000,647,168 | ---- | C] ( )
lxdeserv.dll -> C:\Windows\System32\lxdeserv.dll -> [2007/05/17 15:06:39 | 001,200,128 | ---- | C] ( )
lxdelmpm.dll -> C:\Windows\System32\lxdelmpm.dll -> [2007/05/17 15:00:32 | 000,565,248 | ---- | C] ( )
lxdecomm.dll -> C:\Windows\System32\lxdecomm.dll -> [2007/05/17 15:00:32 | 000,364,544 | ---- | C] ( )
lxdeinpa.dll -> C:\Windows\System32\lxdeinpa.dll -> [2007/05/17 15:00:32 | 000,356,352 | ---- | C] ( )
lxdehbn3.dll -> C:\Windows\System32\lxdehbn3.dll -> [2007/05/17 14:59:33 | 000,663,552 | ---- | C] ( )
lxdeusb1.dll -> C:\Windows\System32\lxdeusb1.dll -> [2007/05/17 14:57:52 | 000,950,272 | ---- | C] ( )
lxdecomc.dll -> C:\Windows\System32\lxdecomc.dll -> [2007/05/17 14:56:55 | 000,860,160 | ---- | C] ( )
lxdeiesc.dll -> C:\Windows\System32\lxdeiesc.dll -> [2007/05/17 14:52:56 | 000,339,968 | ---- | C] ( )
lxdeprox.dll -> C:\Windows\System32\lxdeprox.dll -> [2007/05/17 14:51:29 | 000,053,248 | ---- | C] ( )
2 C:\Windows\*.tmp files -> C:\Windows\*.tmp ->
[Files/Folders - Modified Within 30 Days]
NTUSER.DAT -> C:\Users\Nicolas\NTUSER.DAT -> [2010/03/18 19:03:51 | 006,553,600 | -HS- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2010/03/18 18:26:57 | 000,067,584 | --S- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2010/03/18 17:16:00 | 000,001,054 | ---- | M] ()
settings.dat -> C:\Windows\System32\settings.dat -> [2010/03/18 15:48:28 | 000,000,000 | ---- | M] ()
RootRepeal.zip -> C:\RootRepeal.zip -> [2010/03/18 15:33:17 | 000,464,491 | ---- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2010/03/18 14:16:00 | 000,001,050 | ---- | M] ()
Google Software Updater.job -> C:\Windows\tasks\Google Software Updater.job -> [2010/03/18 14:10:18 | 000,001,002 | ---- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> [2010/03/17 19:53:48 | 000,009,504 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> [2010/03/17 19:53:48 | 000,009,504 | -H-- | M] ()
GlaryInitialize.job -> C:\Windows\tasks\GlaryInitialize.job -> [2010/03/17 19:46:38 | 000,000,316 | ---- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2010/03/17 19:46:22 | 000,000,006 | -H-- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2010/03/17 19:46:10 | 2414,682,112 | -HS- | M] ()
IconCache.db -> C:\Users\Nicolas\AppData\Local\IconCache.db -> [2010/03/17 18:43:53 | 007,543,752 | -H-- | M] ()
nicolasmasson.mny -> D:\Nicolas\Documents\nicolasmasson.mny -> [2010/03/17 18:40:21 | 004,231,168 | ---- | M] ()
nicolasmasson.mbf -> D:\Nicolas\Documents\nicolasmasson.mbf -> [2010/03/17 18:40:17 | 004,232,584 | R--- | M] ()
Local.doc -> C:\Users\Nicolas\Bureau\Local.doc -> [2010/03/14 15:51:56 | 000,102,400 | ---- | M] ()
ntuser.pol -> C:\ProgramData\ntuser.pol -> [2010/03/12 22:42:01 | 000,000,290 | RHS- | M] ()
theme.themepack -> C:\Users\Nicolas\AppData\Roaming\theme.themepack -> [2010/03/12 18:49:28 | 000,929,107 | ---- | M] ()
SIERRA.INI -> C:\Windows\SIERRA.INI -> [2010/03/11 21:56:16 | 000,000,284 | ---- | M] ()
PerfStringBackup.INI -> C:\Windows\System32\PerfStringBackup.INI -> [2010/02/26 15:02:55 | 001,533,788 | ---- | M] ()
perfh00C.dat -> C:\Windows\System32\perfh00C.dat -> [2010/02/26 15:02:55 | 000,698,204 | ---- | M] ()
perfh009.dat -> C:\Windows\System32\perfh009.dat -> [2010/02/26 15:02:55 | 000,610,538 | ---- | M] ()
perfc00C.dat -> C:\Windows\System32\perfc00C.dat -> [2010/02/26 15:02:55 | 000,128,748 | ---- | M] ()
perfc009.dat -> C:\Windows\System32\perfc009.dat -> [2010/02/26 15:02:55 | 000,104,598 | ---- | M] ()
2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp ->
2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp ->
2 C:\Windows\*.tmp files -> C:\Windows\*.tmp ->
[Files - No Company Name]
settings.dat -> C:\Windows\System32\settings.dat -> [2010/03/18 15:48:28 | 000,000,000 | ---- | C] ()
RootRepeal.zip -> C:\RootRepeal.zip -> [2010/03/18 15:33:17 | 000,464,491 | ---- | C] ()
Local.doc -> C:\Users\Nicolas\Bureau\Local.doc -> [2010/03/14 15:19:19 | 000,102,400 | ---- | C] ()
theme.themepack -> C:\Users\Nicolas\AppData\Roaming\theme.themepack -> [2010/03/12 18:49:27 | 000,929,107 | ---- | C] ()
SIERRA.INI -> C:\Windows\SIERRA.INI -> [2010/03/11 21:53:58 | 000,000,284 | ---- | C] ()
SoftWriting.ini -> C:\Windows\SoftWriting.ini -> [2010/02/02 22:44:26 | 000,000,327 | ---- | C] ()
OdiOlDVR.dll -> C:\Windows\System32\OdiOlDVR.dll -> [2009/12/16 15:46:34 | 000,114,688 | ---- | C] ()
OdiAPI.dll -> C:\Windows\System32\OdiAPI.dll -> [2009/12/16 15:46:34 | 000,053,248 | ---- | C] ()
EhStorAuthn.dll -> C:\Windows\System32\EhStorAuthn.dll -> [2009/10/20 16:58:50 | 000,117,248 | ---- | C] ()
ImportClient.INI -> C:\Windows\ImportClient.INI -> [2009/08/27 01:34:13 | 000,000,075 | ---- | C] ()
LXBUinst.dll -> C:\Windows\System32\LXBUinst.dll -> [2009/08/23 14:30:56 | 000,274,432 | ---- | C] ()
DeskHack.dll -> C:\Windows\System32\DeskHack.dll -> [2009/07/24 13:58:53 | 000,012,800 | ---- | C] ()
AVSredirect.dll -> C:\Windows\System32\AVSredirect.dll -> [2009/07/21 00:39:15 | 000,027,648 | ---- | C] ()
GlobalUserInterface.CompositeFont -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont -> [2009/07/14 05:52:31 | 000,043,318 | ---- | C] ()
GlobalSerif.CompositeFont -> C:\Windows\Fonts\GlobalSerif.CompositeFont -> [2009/07/14 05:52