Bonjour
J'ai coché aussi la case scan all users puisque nous sommes 4 à utiliser cet ordinateur.
Voici les deux rapports :
Le premier nommé OTViewIt.txt
OTViewIt logfile created on: 20/05/2009 09:46:11 - Run 4
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pascal\Bureau
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
510,01 Mb Total Physical Memory | 265,39 Mb Available Physical Memory | 52,04% Memory free
1,22 Gb Paging File | 0,98 Gb Available in Paging File | 80,29% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76,32 Gb Total Space | 27,81 Gb Free Space | 36,44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PERSO-ZISSHPXF0
Current User Name: Pascal
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2005/07/25 11:00:56 | 00,876,032 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
[2008/10/15 13:31:25 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
[2008/10/15 13:29:28 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
[2001/02/23 11:07:30 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
[2005/07/25 13:01:23 | 01,397,760 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCD.exe
[2004/11/02 20:24:46 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
[2007/03/28 01:07:42 | 00,593,920 | R--- | M] () -- C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[2001/11/06 15:35:58 | 00,172,032 | ---- | M] ( ) -- C:\Program Files\KYE\Genius WebScroll Mouse\GNETMOUS.EXE
[2001/12/11 20:06:26 | 00,073,728 | ---- | M] () -- C:\Program Files\KYE\Genius WebScroll Mouse\Emouse.exe
[2008/06/12 13:28:40 | 00,266,497 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
[2008/07/06 16:33:59 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[2008/09/04 22:31:35 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Pascal\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[1998/07/01 10:30:22 | 00,150,016 | ---- | M] () -- C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
[2008/04/14 04:34:16 | 00,421,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntvdm.exe
[1998/03/19 15:22:02 | 00,041,984 | ---- | M] (Caere Corporation) -- C:\OPLIMIT\OCRAWR32.EXE
[1998/06/25 13:27:00 | 00,092,672 | ---- | M] () -- C:\Program Files\Caere\PageKeeper30\system\PKSlapi.exe
[1998/06/25 13:26:26 | 00,034,816 | ---- | M] () -- C:\Program Files\Caere\PageKeeper30\system\PKToPass.exe
[2007/02/09 17:03:38 | 00,983,040 | R--- | M] (Teleca AB) -- C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
[2007/02/28 10:55:18 | 00,880,640 | R--- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
[2003/07/22 17:50:28 | 00,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cidaemon.exe
[2009/05/20 09:38:00 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTViewIt.exe
========== (O23) Win32 Services ==========
[2008/02/08 01:28:41 | 00,072,704 | ---- | M] (Adobe Systems) -- C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped])
[2008/10/15 13:31:25 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
[2008/10/15 13:29:28 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
[2004/07/15 01:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2005/10/28 08:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcfcoms.exe -- (dlcf_device [On_Demand | Stopped])
[2009/04/27 13:42:11 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
[2005/11/14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2005/07/25 11:00:56 | 00,876,032 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv [Auto | Running])
[2001/02/23 11:07:30 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe -- (MDM [Auto | Running])
========== Driver Services ==========
[2008/04/13 20:46:20 | 00,048,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\61883.sys -- (61883 [On_Demand | Stopped])
[2001/08/17 21:20:04 | 00,096,256 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ac97intc.sys -- (ac97intc [On_Demand | Running])
[2004/03/10 16:27:18 | 00,011,264 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\drivers\asapiW2k.sys -- (ASAPIW2k [On_Demand | Running])
[2008/06/05 01:31:05 | 00,165,376 | ---- | M] () -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt [Auto | Running])
[2008/04/13 20:46:20 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc [On_Demand | Stopped])
[2007/02/27 14:24:55 | 00,011,840 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
[2008/05/20 15:29:43 | 00,052,032 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
[2008/10/30 10:21:03 | 00,075,072 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb [System | Running])
[2008/04/13 20:39:46 | 00,206,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\dot4.sys -- (Dot4 [On_Demand | Stopped])
[2001/08/17 22:47:32 | 00,012,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\Dot4Prt.sys -- (Dot4Print [On_Demand | Stopped])
[2001/08/17 21:11:06 | 00,066,591 | ---- | M] (3Com Corporation) -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC [On_Demand | Stopped])
[2001/07/11 13:04:28 | 00,007,567 | ---- | M] ( Emouse Driver ) -- C:\WINDOWS\system32\drivers\gmfiltr.sys -- (genmcmn [On_Demand | Running])
[2002/07/15 18:58:06 | 00,169,700 | R--- | M] (Conexant Systems) -- C:\WINDOWS\system32\drivers\HSFHWCD2.sys -- (HSFHWCD2 [On_Demand | Running])
[2002/07/16 16:46:00 | 01,174,384 | R--- | M] (Conexant Systems) -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP [On_Demand | Running])
[2004/08/03 23:29:38 | 00,161,020 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x [On_Demand | Running])
[2004/08/03 23:29:38 | 00,012,415 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wadv01nt.sys -- (iAimFP0 [On_Demand | Stopped])
[2004/08/03 23:29:38 | 00,012,127 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wadv02nt.sys -- (iAimFP1 [On_Demand | Stopped])
[2004/08/03 23:29:38 | 00,011,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wadv05nt.sys -- (iAimFP2 [On_Demand | Stopped])
[2004/08/03 23:29:48 | 00,012,063 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wsiintxx.sys -- (iAimFP3 [On_Demand | Stopped])
[2004/08/03 23:29:50 | 00,019,455 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wvchntxx.sys -- (iAimFP4 [On_Demand | Stopped])
[2004/08/03 23:29:40 | 00,011,807 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wadv07nt.sys -- (iAimFP5 [On_Demand | Stopped])
[2004/08/03 23:29:40 | 00,011,295 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wadv08nt.sys -- (iAimFP6 [On_Demand | Stopped])
[2004/08/03 23:29:42 | 00,011,871 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wadv09nt.sys -- (iAimFP7 [On_Demand | Stopped])
[2004/08/03 23:29:42 | 00,029,311 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\watv01nt.sys -- (iAimTV0 [On_Demand | Stopped])
[2004/08/03 23:29:44 | 00,019,551 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\watv02nt.sys -- (iAimTV1 [On_Demand | Stopped])
[2004/08/03 23:29:44 | 00,033,599 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\watv04nt.sys -- (iAimTV3 [On_Demand | Stopped])
[2004/08/03 23:29:46 | 00,023,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\wch7xxnt.sys -- (iAimTV4 [On_Demand | Stopped])
[2004/08/03 23:29:46 | 00,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\watv10nt.sys -- (iAimTV5 [On_Demand | Stopped])
[2004/08/03 23:29:46 | 00,022,271 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\watv06nt.sys -- (iAimTV6 [On_Demand | Stopped])
[2005/07/25 10:53:28 | 00,101,504 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs [Disabled | Running])
[2005/07/25 10:53:04 | 00,029,696 | ---- | M] (Nero AG) -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass [System | Running])
[2005/07/25 12:52:59 | 00,028,672 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm [System | Running])
[2008/04/14 04:05:15 | 00,014,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid [System | Stopped])
[2008/06/05 01:31:03 | 00,018,048 | ---- | M] () -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt [Auto | Running])
[2005/01/28 15:36:00 | 00,171,008 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus [On_Demand | Running])
[2004/08/03 23:41:56 | 00,011,868 | ---- | M] (Conexant) -- C:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
[2008/04/13 20:46:10 | 00,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV [On_Demand | Stopped])
[2004/07/16 16:47:14 | 00,014,165 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI [System | Running])
[2003/07/22 18:08:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2006/11/02 17:57:04 | 00,036,624 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2006/09/05 19:58:26 | 00,061,536 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\se58bus.sys -- (se58bus [On_Demand | Stopped])
[2006/09/05 19:59:14 | 00,009,360 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\se58mdfl.sys -- (se58mdfl [On_Demand | Stopped])
[2006/09/05 19:59:18 | 00,097,088 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\se58mdm.sys -- (se58mdm [On_Demand | Stopped])
[2006/09/05 20:00:06 | 00,088,624 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\se58mgmt.sys -- (se58mgmt [On_Demand | Stopped])
[2006/09/05 19:57:54 | 00,018,704 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\se58nd5.sys -- (se58nd5 [On_Demand | Stopped])
[2006/09/05 20:00:54 | 00,086,432 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\se58obex.sys -- (se58obex [On_Demand | Stopped])
[2006/09/05 19:57:48 | 00,090,800 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\se58unic.sys -- (se58unic [On_Demand | Stopped])
[2007/11/13 12:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2001/08/17 22:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[2007/07/03 16:54:24 | 00,080,552 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus [On_Demand | Stopped])
[2007/07/03 16:57:24 | 00,011,944 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl [On_Demand | Stopped])
[2007/07/03 16:58:20 | 00,106,792 | ---- | M] (MCCI Corporation) -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm [On_Demand | Stopped])
[2007/11/08 18:03:26 | 00,021,248 | ---- | M] (AVIRA GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv [System | Running])
[2001/08/23 17:20:50 | 00,006,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\serscan.sys -- (StillCam [On_Demand | Stopped])
[2007/04/17 08:46:48 | 00,037,768 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wceusbsh.sys -- (wceusbsh [On_Demand | Stopped])
[2002/07/15 18:24:08 | 00,602,480 | R--- | M] (Conexant Systems) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf [On_Demand | Running])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.fr/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.fr/
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (790 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
{6A11553E-7737-4DA8-8FFD-B6842B415702} (HKLM) -- C:\WINDOWS\system32\rqrqpmm.dll File not found
{AA58ED58-01DD-4d91-8333-CF10577473F7} (HKLM) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
{B8DF4831-1ED2-41F3-8F79-55D9785CEBD5} (HKLM) -- C:\WINDOWS\system32\pmkhh.dll File not found
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} (HKLM) -- C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" (HKLM) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH)
"BMc337830d"=Rundll32.exe "C:\WINDOWS\system32\ldxpxlxd.dll",s File not found
"DLCFCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16 ()
"Emouse"=C:\Program Files\KYE\Genius WebScroll Mouse\Emouse.exe ()
"Gnetmous"=C:\Program Files\KYE\Genius WebScroll Mouse\gnetmous.exe ( )
"InCD"=C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
"MS32DLL"=C:\WINDOWS\MS32DLL.dll.vbs File not found
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg ()
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions ()
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\Pascal\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
"PowerBar"= File not found
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\Pascal\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
"PowerBar"= File not found
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
========== (O4) Startup Folders ==========
[2000/08/24 16:45:38 | 00,110,592 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
[2001/02/13 10:01:04 | 00,083,360 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
[1998/07/01 10:30:22 | 00,150,016 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Travaux PageKeeper.lnk = C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
[2007/12/26 15:17:06 | 05,484,544 | ---- | M] (Groupe Neuf Cegetel) -- C:\Documents and Settings\Moi\Menu Démarrer\Programmes\Démarrage\Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe
[2007/01/15 14:23:48 | 00,344,064 | ---- | M] (Sony Corporation) -- C:\Documents and Settings\Moi\Menu Démarrer\Programmes\Démarrage\Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
File not found -- C:\Documents and Settings\Moi\Menu Démarrer\Programmes\Démarrage\Outil de notification Live Search.lnk = C:\Documents and Settings\Pascal\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
[2000/08/24 16:45:38 | 00,110,592 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\Pascal\Menu Démarrer\Programmes\Démarrage\Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
[1998/07/18 11:26:06 | 00,051,360 | ---- | M] (Caere Corporation) -- C:\Documents and Settings\Pascal\Menu Démarrer\Programmes\Démarrage\OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableTaskMgr"=0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableTaskMgr"=0
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xporter vers Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2001/02/16 10:05:38 | 09,164,192 | R--- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\Software\Microsoft\Internet Explorer\MenuExt\]
E&xporter vers Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2001/02/16 10:05:38 | 09,164,192 | R--- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 04:34:13 | 01,695,232 | -HS- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 04:34:13 | 01,695,232 | -HS- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:34:13 | 01,695,232 | -HS- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:34:13 | 01,695,232 | -HS- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:34:13 | 01,695,232 | -HS- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 04:34:13 | 01,695,232 | -HS- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
Extension\.spop: -- C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll [2001/08/01 17:05:42 | 00,270,336 | ---- | M] (Intertrust Technologies, Inc.)
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab -- Shockwave Flash Object
========== (O17) DNS Name Servers ==========
{3747D9A3-5564-46DE-84DB-7729C50141B5} (Servers: | Description: Contrôleur Fast Ethernet intégré 3Com 3C920 (compatible 3C905C-TX))
{521C8A30-D346-4983-BEA0-1A82E83FBC96} (Servers: | Description: Carte réseau 1394)
{A2D361E1-B67D-476E-AD9B-41D9FA83DF4D} (Servers: | Description: )
{B58D25A7-114E-447D-9B47-D5BF1AA059FC} (Servers: | Description: Sony Ericsson Device 088 USB Ethernet Emulation (NDIS 5))
========== (O19) User Style Sheets ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles]
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
rqrqpmm: "DllName" = rqrqpmm.dll -- File not found
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6A11553E-7737-4DA8-8FFD-B6842B415702}" (HKLM) -- C:\WINDOWS\system32\rqrqpmm.dll File not found
========== LSA *Authentication Packages* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=msv1_0,C:\WINDOWS\system32\pmkhh.dll,
>File not found -- C:\WINDOWS\system32\pmkhh.dll
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2007/02/22 16:29:30 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[2009/05/20 09:36:15 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTViewIt.exe
[2009/05/20 00:30:19 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\HijackThis.lnk
[2009/05/20 00:30:18 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/05/20 00:27:35 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Pascal\Bureau\HJTInstall.exe
[2009/05/19 21:35:08 | 00,045,376 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/05/19 21:35:08 | 00,022,336 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/05/19 21:35:08 | 00,021,248 | ---- | C] (AVIRA GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/05/19 21:35:02 | 00,075,072 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/05/19 21:29:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2009/05/19 20:57:05 | 00,000,056 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\Copie de master.idx
[2009/05/19 18:24:13 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\Bonjour.doc
[2009/05/19 16:31:22 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\SP3.doc
[2009/05/17 22:52:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Bureau\lugny jessica
[2009/05/13 15:51:01 | 00,025,088 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\courrier killies stéphane.doc
[2009/05/13 00:13:52 | 00,029,696 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\Weaa 2009(2).doc
[2009/05/11 23:04:33 | 00,030,720 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\Weaa 2009.doc
[2009/05/07 02:12:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Bureau\sdcarte
[2009/05/02 00:04:07 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009/05/02 00:04:07 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009/05/01 19:48:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Bureau\DCIM
[2009/04/30 00:40:00 | 00,451,584 | ---- | C] () -- C:\Documents and Settings\Pascal\Bureau\Nuit_de_noces.pps
[2009/04/27 00:55:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Application Data\dvdcss
[2009/04/26 00:49:45 | 00,025,088 | ---- | C] () -- C:\Documents and Settings\Pascal\Mes documents\Nids.doc
[2009/04/21 23:23:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Mes documents\Guides GSM
[2009/04/20 19:40:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pascal\Mes documents\Carte mémoire Samsung
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/05/20 09:38:00 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pascal\Bureau\OTViewIt.exe
[2009/05/20 09:25:39 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/20 09:23:53 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/20 09:23:41 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/20 00:39:27 | 00,001,556 | ---- | M] () -- C:\WINDOWS\oplimit.ini
[2009/05/20 00:30:19 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\HijackThis.lnk
[2009/05/20 00:29:31 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Pascal\Bureau\HJTInstall.exe
[2009/05/19 20:56:25 | 00,000,056 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\Copie de master.idx
[2009/05/19 18:24:14 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\Bonjour.doc
[2009/05/19 16:31:23 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\SP3.doc
[2009/05/19 12:25:21 | 00,000,812 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\Club Internet.lnk
[2009/05/19 09:03:45 | 00,007,168 | -HS- | M] () -- C:\WINDOWS\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
[2009/05/16 08:38:08 | 00,000,287 | ---- | M] () -- C:\WINDOWS\SnapYa! Settings.ini
[2009/05/15 19:42:22 | 00,001,226 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/13 15:51:02 | 00,025,088 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\courrier killies stéphane.doc
[2009/05/13 10:03:34 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/05/13 02:07:15 | 00,029,696 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\Weaa 2009(2).doc
[2009/05/12 00:07:28 | 00,030,720 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\Weaa 2009.doc
[2009/05/07 09:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/02 00:04:07 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/05/02 00:04:07 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/04/30 00:41:30 | 00,451,584 | ---- | M] () -- C:\Documents and Settings\Pascal\Bureau\Nuit_de_noces.pps
[2009/04/26 22:52:36 | 00,120,832 | -HS- | M] () -- C:\Documents and Settings\Pascal\Mes documents\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Pascal\Mes documents\Thumbs.db:encryptable
[2009/04/26 22:52:09 | 00,076,800 | ---- | M] () -- C:\Documents and Settings\Pascal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/26 00:49:45 | 00,025,088 | ---- | M] () -- C:\Documents and Settings\Pascal\Mes documents\Nids.doc
[2009/04/22 23:29:03 | 00,106,328 | ---- | M] () -- C:\Documents and Settings\Pascal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
< End of report >
et le suivant nommé : Extrats.txt
OTViewIt Extras logfile created on: 20/05/2009 09:46:11 - Run 4
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pascal\Bureau
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
510,01 Mb Total Physical Memory | 265,39 Mb Available Physical Memory | 52,04% Memory free
1,22 Gb Paging File | 0,98 Gb Available in Paging File | 80,29% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76,32 Gb Total Space | 27,81 Gb Free Space | 36,44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PERSO-ZISSHPXF0
Current User Name: Pascal
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
"MaxScriptStatements"=
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=1
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DoNotAllowExceptions"=0
"DisableNotifications"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/14 04:34:21 | 00,142,848 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/14 04:34:21 | 00,142,848 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/14 04:34:13 | 01,695,232 | -HS- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
[2000/09/18 17:23:42 | 01,232,896 | ---- | M] (Visicom Media Inc.) -- C:\Program Files\FTPExpert\FTPXpert.exe:*:Enabled:FTP Expert
File not found -- C:\WINDOWS\system32\^^^^^^.exe:*:Enabled:Flash Media
[2008/04/13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
========== HKEY_USERS Protocol Defaults ==========
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned
========== HKEY_USERS Protocol Defaults ==========
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned
========== HKEY_USERS Protocol Defaults ==========
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned
========== HKEY_USERS Protocol Defaults ==========
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
shell -- shell protocol not assigned
========== (O18) Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2001/01/22 04:25:24 | 00,872,448 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\PKMCDO.DLL (cdo:{CD00020A-8B95-11D1-82DB-00C04FB1625D} (HKLM) [Microsoft PKM KnowledgePluggable Class])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2001/02/12 04:25:24 | 01,187,840 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2001/02/12 04:25:24 | 01,187,840 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2001/02/12 04:25:24 | 01,187,840 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2000/06/27 12:51:06 | 00,212,992 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\msitss.dll (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2001/02/24 03:36:24 | 07,436,272 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])
========== (O18) Protocol Filters ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2009/04/22 21:25:14 | 00,470,512 | ---- | M] (Google Inc.) C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll x-sdch:{B1759355-3EEC-4C1E-B0F1-B719FE26E377} (HKLM) [Google Dictionary Compression filter]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0014040C-78E1-11D2-B60F-006097C998E7}"=Microsoft Publisher 2000 SR-1
"{01020202-5D65-445A-B3B4-3DCE72BA0C6C}"=Encyclopédie Microsoft Encarta 2001
"{18455581-E099-4BA8-BC6B-F34B2F06600C}"=Google Toolbar for Internet Explorer
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}"=Multimedia Launcher
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=Google Toolbar for Internet Explorer
"{236BB7C4-4419-42FD-040C-2E257A25E34D}"=Adobe Photoshop CS2
"{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}"=SmartSound Quicktracks Plugin
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}"=Sony USB Driver
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}"=PowerDVD
"{786C5747-0C40-4930-9AFE-113BCE553101}"=Adobe Stock Photos 1.0
"{78DFE6C0-E0BC-11D4-91F5-00C0DF4C00AE}"=Genius WebScroll Mouse
"{8AF3E926-ED59-11D4-A44B-0000E86D2305}"=Ulead GIF Animator 5 Evaluation
"{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}"=MP3 Player Utilities 4.15
"{8EDBA74D-0686-4C99-BFDD-F894678E5101}"=Adobe Common File Installer
"{9028040C-6000-11D3-8CFE-0050048383C9}"=Microsoft Office XP Professional avec FrontPage
"{9E491AB7-4589-48CA-9CBB-874CB2788391}"=Studio 9
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1"=SIW version 2008-12-16
"{AC76BA86-7AD7-1036-7B44-A81300000003}"=Adobe Reader 8.1.4 - Français
"{B67624DE-75CE-4FAD-9F29-5C115773CE61}"=Studio 9 Content CD/DVD
"{B74D4E10-6884-0000-0000-000000000101}"=Adobe Bridge 1.0
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}"=PowerProducer
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}"=DVD Solution
"{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}"=QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{D5068583-D569-468B-9755-5FBF5848F46F}"=Sony Picture Utility
"{DD54C6DE-B787-406D-A5A7-A49E0471E45B}"=ACDSee 8
"{DDB20844-4874-11D6-B55D-0050DA3C7AAA}"=Lanceur Club Internet v6
"{E9787678-119F-4D52-B551-6739B2B22101}"=Adobe Help Center 1.0
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}"=Samsung PC Studio 3 USB Driver Installer
"{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}"=PhotoStitch
"{FE6397C1-CECA-4EC3-B064-42AED7676898}"=Sony Ericsson PC Suite
"{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}"=Disc2Phone
"003b7f45c03d76cb48a70b13dbea831b-691254322"=Explorateur du corps humain
"1000 Lettres, contrats et actes types - Version "=1000 Lettres, contrats et actes types - Version 1.0
"ACDSee"=ACDSee
"Adobe Acrobat 5.0"=Adobe Acrobat 5.0
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"Adobe Photoshop 7.0.1"=Adobe Photoshop 7.0.1
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-040C-2E257A25E34D}"=Adobe Photoshop CS2
"Agfa ScanWise 1.10"=Agfa ScanWise 1.10
"AntiVir PersonalEdition Classic"=Avira AntiVir Personal - Free Antivirus
"Architecte et construction 3D Edition spéciale Système D_is1"=Architecte et construction 3D Edition spéciale Système D
"Ashampoo Photo Illuminator"=Ashampoo Photo Illuminator
"Audacity_is1"=Audacity 1.2.3
"CDex"=CDex extraction audio
"CNXT_MODEM_USB_VID_08E3&PID_0111"=Olitec Speed'Com USB V92 Ready
"Dell Color Printer 725"=Dell Color Printer 725
"Diaporama_is1"=Diaporama version 3.0.0.1
"FLV Player"=FLV Player 2.0 (build 25)
"FreeDial"=FreeDial
"FTP Expert v1"=FTP Expert v1
"HijackThis"=HijackThis 2.0.2
"Hollywood FX 5.5 Additional Effects"=Hollywood FX 5.5 Additional Effects
"Hollywood FX for Studio"=Pinnacle Hollywood FX for Studio
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}"=SmartSound Quicktracks Plugin
"InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}"=QuickTime
"InstallShield_{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}"=Canon Utilities PhotoStitch 3.1
"InterActual Player"=InterActual Player
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.10)"=Mozilla Firefox (3.0.10)
"MSNINST"=MSN
"NeroMultiInstaller!UninstallKey"=Nero Suite
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"PageKeeperLite Uninstall"=PageKeeper Standard 3.0
"Pagicien v3"=Pagicien v3
"Photocopier_is1"=Photocopier Version 2.26
"PhotoFiltre Studio"=PhotoFiltre Studio
"proDAD-Heroglyph-1.0"=proDAD Heroglyph 1.0
"SAMSUNG Mobile Modem"=SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver"=Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem"=SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0"=SAMSUNG Mobile USB Modem 1.0 Software
"ScMgr30Uninstall"=Caere Scan Manager 4.01
"Shockwave"=Shockwave
"ST5UNST #1"=CalcEF
"ST6UNST #1"=Conjugaison
"VLC media player"=VideoLAN VLC media player 0.8.6a
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows XP Service"=Windows XP Service Pack 3
"WinRAR archiver"=Archiveur WinRAR
"WinZip"=WinZip
"WMFDist11"=Windows Media Format 11 runtime
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Experience_Malawi"=Experience_Malawi
"Google Chrome"=Google Chrome
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1935655697-789336058-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Experience_Malawi"=Experience_Malawi
"Google Chrome"=Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 17/05/2009 19:25:43 | Computer Name = PERSO-ZISSHPXF0 | Source = Google Update | ID = 20
Description =
Error - 17/05/2009 20:25:43 | Computer Name = PERSO-ZISSHPXF0 | Source = Google Update | ID = 20
Description =
Error - 18/05/2009 11:00:40 | Computer Name = PERSO-ZISSHPXF0 | Source = Application Error | ID = 1000
Description = Application défaillante iexplore.exe, version 7.0.6000.16827, module
défaillant unknown, version 0.0.0.0, adresse de défaillance 0x10053055.
Error - 18/05/2009 11:05:47 | Computer Name = PERSO-ZISSHPXF0 | Source = Application Error | ID = 1000
Description = Application défaillante iexplore.exe, version 7.0.6000.16827, module
défaillant ntdll.dll, version 5.1.2600.5755, adresse de défaillance 0x0001168b.
Error - 18/05/2009 18:08:00 | Computer Name = PERSO-ZISSHPXF0 | Source = Google Update | ID = 20
Description =
Error - 19/05/2009 02:42:39 | Computer Name = PERSO-ZISSHPXF0 | Source = Google Update | ID = 20
Description =
Error - 19/05/2009 03:24:54 | Computer Name = PERSO-ZISSHPXF0 | Source = Google Update | ID = 20
Description =
Error - 19/05/2009 09:33:00 | Computer Name = PERSO-ZISSHPXF0 | Source = Google Update | ID = 20
Description =
Error - 19/05/2009 12:17:19 | Computer Name = PERSO-ZISSHPXF0 | Source = Application Hang | ID = 1002
Description = Application bloquée WINWORD.EXE, version 10.0.2627.0, module bloqué
hungapp, version 0.0.0.0, adresse de blocage 0x00000000.
Error - 19/05/2009 12:18:43 | Computer Name = PERSO-ZISSHPXF0 | Source = Application Hang | ID = 1002
Description = Application bloquée WINWORD.EXE, version 10.0.2627.0, module bloqué
hungapp, version 0.0.0.0, adresse de blocage 0x00000000.
[ System Events ]
Error - 19/05/2009 05:13:35 | Computer Name = PERSO-ZISSHPXF0 | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
dlcf_device.
Error - 19/05/2009 05:13:35 | Computer Name = PERSO-ZISSHPXF0 | Source = Service Control Manager | ID = 7000
Description = Le service dlcf_device n'a pas pu démarrer en raison de l'erreur :
%%1053
Error - 19/05/2009 14:58:31 | Computer Name = PERSO-ZISSHPXF0 | Source = DCOM | ID = 10005
Description = DCOM a reçu l'erreur "%1053" lors de la mise en route du service dlcf_device
avec les arguments "" pour démarrer le serveur : {323CE21C-A448-40AA-BA74-7FCF1E441060}
Error - 19/05/2009 14:58:31 | Computer Name = PERSO-ZISSHPXF0 | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
dlcf_device.
Error - 19/05/2009 14:58:32 | Computer Name = PERSO-ZISSHPXF0 | Source = Service Control Manager | ID = 7000
Description = Le service dlcf_device n'a pas pu démarrer en raison de l'erreur :
%%1053
Error - 19/05/2009 14:58:44 | Computer Name = PERSO-ZISSHPXF0 | Source = DCOM | ID = 10005
Description = DCOM a reçu l'erreur "%1053" lors de la mise en route du service dlcf_device
avec les arguments "" pour démarrer le serveur : {323CE21C-A448-40AA-BA74-7FCF1E441060}
Error - 19/05/2009 15:24:52 | Computer Name = PERSO-ZISSHPXF0 | Source = DCOM | ID = 10005
Description = DCOM a reçu l'erreur "%1053" lors de la mise en route du service dlcf_device
avec les arguments "" pour démarrer le serveur : {323CE21C-A448-40AA-BA74-7FCF1E441060}
Error - 19/05/2009 15:24:52 | Computer Name = PERSO-ZISSHPXF0 | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
dlcf_device.
Error - 19/05/2009 15:24:52 | Computer Name = PERSO-ZISSHPXF0 | Source = Service Control Manager | ID = 7000
Description = Le service dlcf_device n'a pas pu démarrer en raison de l'erreur :
%%1053
Error - 19/05/2009 15:25:07 | Computer Name = PERSO-ZISSHPXF0 | Source = DCOM | ID = 10005
Description = DCOM a reçu l'erreur "%1053" lors de la mise en route du service dlcf_device
avec les arguments "" pour démarrer le serveur : {323CE21C-A448-40AA-BA74-7FCF1E441060}
< End of report >
-->Message édité par totoftotof le 20/05/2009 12:17:48<--