Bonsoir,
Comme convenu je t'adresse, en complément d'HijackThis, le rapport d'analyse d'OTViewIt pour t'aider à découvrir l'origine de mes problèmes :
- dysfonctionnement du nouveau contrôle parental installé sur ma machine,
- déterminer si DvDsentry altère le fonctionnement de mon système informatique,
- définir si HKCU\..Run: [Windows Service Agent]hinksu.exe est un virus, malware ou autre ....
En attendant le plaisir de lire tes conclusions
Excellente soirée
I) OTViewItExtra.Txt.Bloc-notes
OTViewIt Extras logfile created on: 19/03/2009 20:44:42 - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\ALAIN\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
511,00 Mb Total Physical Memory | 296,68 Mb Available Physical Memory | 58,06% Memory free
1,22 Gb Paging File | 0,87 Gb Available in Paging File | 71,02% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,46 Gb Total Space | 50,59 Gb Free Space | 67,94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: xxxx
Current User Name: ALAIN
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=0
"DoNotAllowExceptions"=1
"DisableNotifications"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/14 03:34:21 | 00,142,848 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
File not found -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/14 03:34:21 | 00,142,848 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/04/18 20:21:09 | 00,147,456 | ---- | M] (Lime Wire, LLC) -- C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
File not found -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.0
[2009/02/01 21:03:56 | 01,032,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
[2008/04/14 03:34:13 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
[2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2009/01/06 13:06:28 | 14,294,824 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
========== (O10) Winsock2 Catalogs ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -- C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
Protocol_Catalog9\Catalog_Entries\000000000001 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000002 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000003 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000004 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000005 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000006 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000007 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000008 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000009 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000010 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000011 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000012 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000013 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000014 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000015 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000016 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000017 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000018 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000019 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000020 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000021 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000022 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000023 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000024 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000025 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000026 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000027 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000028 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000029 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000030 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000031 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000032 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000033 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000034 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000035 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000036 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000037 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000038 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
Protocol_Catalog9\Catalog_Entries\000000000039 -- C:\Program Files\Parental Filter 2\HookLib.dll ()
========== (O18) Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[2009/02/01 21:06:00 | 00,079,128 | ---- | M] (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgpp.dll (linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} (HKLM) [XPLPPFilter Class])
msdaipp: [HKLM - No CLSID value]
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[2001/06/20 10:26:46 | 00,221,184 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\msitss.dll (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])
[2007/03/14 12:10:22 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])
[2007/05/10 12:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])
========== (O18) Protocol Filters ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2007/04/19 12:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01A2E33A-8ADA-42D1-9173-8F65149E952F}"=Microsoft Money
"{02CA7E66-1AD1-4DE9-BA9E-86A0EEB019C7}"=Extension Système de Microsoft Money
"{03460014-3975-4267-9F39-1DC4745090B7}"=Encyclopédie Microsoft Encarta 2003
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}"=VERITAS RecordNow DX Update Manager
"{0BD83598-C2EF-3343-847B-7D2E84599128}"=Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}"=Dell Solution Center
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}"=Dell Picture Studio - Dell Image Expert
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}"=QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java(TM) 6 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160060}"=Java(TM) 6 Update 6
"{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{38451fbb-dd74-4661-bfdb-3238c49b2dc2}.sdb"=LM XP
"{3E31821C-7917-367E-938E-E65FC413EA31}"=Microsoft .NET Framework 3.5 Language Pack SP1 - fra
"{55BC7EFA-D832-4EE3-9DEA-49B0C07539D9}"=
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}"=MyDVD
"{64D114CE-4234-45C2-B60A-2B07D5A48F72}"=Microsoft Works 7.0
"{67633367-fb3c-4248-b6a8-22e1a7e2968b}.sdb"=Lmvoyage
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}"=PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{713E5AB1-2389-43A6-8313-CB4D3C44C4FA}"=Samsung USB Driver
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{72AD53CC-CCC0-3757-8480-9EE176866A7C}"=Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA
"{77E6B81F-DE38-40D4-988E-470E50D1E135}"=Adibou Aventure dans le corps humain 4-8 ans
"{7BA1FB62-A363-4D24-8870-45131F0D0137}"=EPSON PRINT Image Framer Tool2.0
"{7F142D56-3326-11D5-B229-002078017FBF}"=Modem Helper
"{8855FF30-19CE-4CB1-A654-87B38369CCE1}"=VERITAS RecordNow DX
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour
"{8A793FC6-6DF5-11DD-BB6A-00018021113F}"=EPSON PhotoQuicker3.4
"{9011040C-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}"=Help and Support Customization
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}"=DVDSentry
"{9E2EA164-DB68-47A1-933C-6A0FF6433051}"=Les chemins de la lecture
"{9ED6519B-324A-4C66-98EE-E3F54281BA78}"=Atlantis
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}"=Microsoft .NET Framework 3.0 Service Pack 2
"{A6B0E526-D1E8-11D5-AA2E-0008C760B784}"=Disney Peter Pan Aventures au Pays Imaginaire
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}"=Intel(R) PROSet
"{AC76BA86-7AD7-1036-7B44-A91000000001}"=Adobe Reader 9.1 - Français
"{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}"=Samsung Master
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{BAF78226-3200-4DB4-BE33-4D922A799840}"=Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}"=Microsoft .NET Framework 2.0 Service Pack 2
"{C2C30F12-3887-45DA-BBBC-FA93F8ECCEC3}"=Voyage au pays de la lecture
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}"=Microsoft .NET Framework 3.5 SP1
"{CFE6588F-C0FE-493B-BB1F-663CB7F11551}"=Parental Filter
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}"=Paint Shop Pro 7
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}"=Dell ResourceCD
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}"=Google Toolbar for Internet Explorer
"{DCDC8E79-4600-4C02-9824-CD3BB8971D4E}"=
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}"=Ad-Aware
"{E38D381A-ABCF-4D97-9D9C-B3A8529DCA15}"=OS Pack Works Suite
"{E8FB4BF9-4C95-4F39-B26D-33C31A2CEE09}"=PIF DESIGNER2.0
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}"=ScanToWeb
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}"=iTunes
"Adibou et l'Ombre Verte V.1.00 on C"=Adibou et l'Ombre Verte V.1.00 on C
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"Akakliké"=Akakliké
"Akakliké 2"=Akakliké 2
"AVG8Uninstall"=AVG Free 8.0
"BCM V.92 56K Modem"=BCM V.92 56K Modem
"CCleaner"=CCleaner (remove only)
"DivX Codec"=DivX Codec
"DivX Player"=DivX Player
"eMule"=eMule
"EPSON Printer and Utilities"=EPSON Logiciel imprimante
"FileZilla Client"=FileZilla Client 3.2.2.1
"Freeplayer"=Freeplayer
"HijackThis"=HijackThis 2.0.2
"InstallShield_{9ED6519B-324A-4C66-98EE-E3F54281BA78}"=Dell Movie Studio Diagnostics
"InstallShield_{CFE6588F-C0FE-493B-BB1F-663CB7F11551}"=Parental Filter 2
"Lapin Malin Cours Préparatoire Turbulences à Édenville !"=Lapin Malin Cours Préparatoire Turbulences à Édenville !
"Les aventures de Buzz l'Éclair"=Les aventures de Buzz l'Éclair
"LimeWire"=LimeWire 4.16.7
"Microsoft .NET Framework 3.5 Language Pack SP1 - fra"=Module linguistique Microsoft .NET Framework 3.5 SP1- fra
"Microsoft .NET Framework 3.5 SP1"=Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.7)"=Mozilla Firefox (3.0.7)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA"=NVIDIA Windows 2000/XP Display Drivers
"Paint Shop Pro 6.0"=Paint Shop Pro 6.0 Evaluation
"Pdf995"=Pdf995
"PhotoFiltre"=PhotoFiltre
"PROSet"=Intel(R) PRO Network Adapters and Drivers
"RAYMAN CP"=RAYMAN CP
"RealPlayer 6.0"=RealPlayer Basic
"Shockwave"=Shockwave
"Surfe avec moi"=Surfe avec moi
"Tarzan Jeu D'Action"=Tarzan Jeu D'Action
"TMM70DEM"=TELL ME MORE
"ViewpointMediaPlayer"=Viewpoint Media Player
"VLC media player"=VideoLAN VLC media player 0.8.1
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Lecteur Windows Media 11
"Windows XP Service"=Windows XP Service Pack 3
"WinZip"=WinZip
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Works2003Setup"=Sélecteur d'installation de Microsoft Works Suite 2003
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC"=XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP"=XML Paper Specification Shared Components Language Pack 1.0
"Xvid_is1"=Xvid 1.1.2 final uninstall
"YInstHelper"=Yahoo! Install Manager
"ZoneAlarm"=ZoneAlarm
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 29/04/2007 06:32:38 | Computer Name = xxxx | Source = Application Error | ID = 1000
Description = Application défaillante mindscape.exe, version 0.0.0.0, module défaillant
, version 0.0.0.0, adresse de défaillance 0x00000000.
Error - 14/06/2007 10:43:39 | Computer Name = xxxx | Source = Application Hang | ID = 1002
Description = Application bloquée EXPLORER.EXE, version 6.0.2800.1106, module bloqué
hungapp, version 0.0.0.0, adresse de blocage 0x00000000.
Error - 14/06/2007 11:08:31 | Computer Name = xxxx | Source = Application Hang | ID = 1002
Description = Application bloquée wmplayer.exe, version 9.0.0.2980, module bloqué
hungapp, version 0.0.0.0, adresse de blocage 0x00000000.
[ System Events ]
Error - 15/03/2009 03:50:36 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Parental Filter 2.
Error - 15/03/2009 08:55:53 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Parental Filter 2.
Error - 15/03/2009 14:13:45 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Parental Filter 2.
Error - 17/03/2009 02:19:58 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Parental Filter 2.
Error - 18/03/2009 13:32:45 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Parental Filter 2.
Error - 18/03/2009 13:33:06 | Computer Name = xxxx | Source = DCOM | ID = 10005
Description = DCOM a reçu l'erreur "%1053" lors de la mise en route du service iPod
Service avec les arguments "" pour démarrer le serveur : {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
Error - 18/03/2009 13:33:06 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Service de l’iPod.
Error - 18/03/2009 13:33:06 | Computer Name = xxxx | Source = Service Control Manager | ID = 7000
Description = Le service Service de l’iPod n'a pas pu démarrer en raison de l'erreur :
%%1053
Error - 19/03/2009 02:38:56 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Parental Filter 2.
Error - 19/03/2009 14:19:19 | Computer Name = xxxx | Source = Service Control Manager | ID = 7009
Description = Délai (30000 millisecondes) d'attente pour une connexion du service
Parental Filter 2.
< End of report >
II) OTViewBlocNotes
OTViewIt logfile created on: 19/03/2009 20:44:42 - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\ALAIN\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
511,00 Mb Total Physical Memory | 296,68 Mb Available Physical Memory | 58,06% Memory free
1,22 Gb Paging File | 0,87 Gb Available in Paging File | 71,02% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,46 Gb Total Space | 50,59 Gb Free Space | 67,94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: xxxx
Current User Name: ALAIN
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2008/07/09 08:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
[2008/06/14 18:06:53 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
[2003/08/29 03:59:24 | 00,122,880 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\BCMSMMSG.exe
[2002/08/14 18:22:52 | 00,028,672 | R--- | M] (Dell - Advanced Desktop Engineering) -- C:\WINDOWS\SYSTEM32\DSentry.exe
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2009/02/01 21:05:49 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
[2009/01/25 19:03:26 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
[2008/07/09 08:05:20 | 00,919,016 | ---- | M] (Zone Labs, LLC) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[2002/07/17 02:03:00 | 00,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
[2009/01/25 19:03:26 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2009/02/01 21:05:40 | 01,601,304 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
[2009/01/05 16:18:48 | 00,413,696 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QTTask.exe
[2009/01/06 13:06:36 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
[2008/04/14 03:34:13 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
[2004/09/10 03:16:57 | 00,053,248 | ---- | M] (Alcor Micro, Corp.) -- C:\WINDOWS\SYSTEM32\DrvMon.exe
[2003/04/24 16:58:00 | 00,069,632 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SYSTEM32\nvsvc32.exe
[2008/09/02 21:02:33 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[2008/09/16 11:16:08 | 01,833,296 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[2002/11/27 08:10:00 | 00,106,561 | ---- | M] (WinZip Computing, Inc.) -- C:\Program Files\WinZip\WZQKPICK.EXE
[2009/02/01 21:06:11 | 00,484,120 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
[2009/01/06 13:06:24 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
[2009/03/19 20:43:36 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALAIN\Bureau\OTViewIt.exe
========== (O23) Win32 Services ==========
[2008/06/14 18:06:53 | 00,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
[2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2009/02/01 21:05:49 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
[2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
[2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2002/07/17 02:03:00 | 00,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2 [Auto | Running])
[2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2008/05/24 17:35:57 | 00,138,168 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
[2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
[2009/01/06 13:06:24 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
[2009/01/25 19:03:26 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
File not found -- -- (Microsoft Agent [Auto | Stopped])
[2003/03/03 13:33:40 | 00,143,360 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
[2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2003/04/24 16:58:00 | 00,069,632 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SYSTEM32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2003/07/28 19:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2009/03/03 10:12:44 | 00,015,200 | ---- | M] (Editions Profil) -- C:\Program Files\Parental Filter 2\ServiceEpcp2.exe -- (ServiceFilterEpcp2 [Auto | Stopped])
[2008/07/09 08:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
[2006/11/03 08:59:14 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services ==========
[2002/04/01 13:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\aeaudio.sys -- (aeaudio [On_Demand | Running])
[2007/04/21 12:38:48 | 00,029,568 | ---- | M] (Alfa Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\AlfaFF.sys -- (AlfaFF [Boot | Running])
[2002/09/18 16:22:08 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\aliide.sys -- (AliIde [Disabled | Stopped])
[2008/04/13 19:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys -- (amdagp [Disabled | Stopped])
[2002/09/18 16:22:11 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\asc.sys -- (asc [Disabled | Stopped])
[2002/09/18 16:22:11 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\asc3550.sys -- (asc3550 [Disabled | Stopped])
[2003/09/19 09:51:25 | 00,008,552 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM [Auto | Running])
[2002/12/03 18:48:00 | 00,021,504 | R--- | M] (Dell Computer Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\AtlsAud.sys -- (AtlsAud [On_Demand | Running])
[2009/02/01 21:06:10 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys -- (AvgLdx86 [System | Running])
[2009/02/01 21:06:11 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys -- (AvgMfx86 [System | Running])
[2003/08/29 03:59:24 | 01,101,696 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys -- (BCMModem [On_Demand | Running])
[2002/09/18 16:22:28 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\cmdide.sys -- (CmdIde [Disabled | Stopped])
[2002/09/18 16:22:46 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\dac2w2k.sys -- (dac2w2k [Disabled | Stopped])
[2003/03/04 11:56:26 | 00,145,408 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Running])
[2002/12/04 19:08:00 | 00,134,304 | R--- | M] (Dell Computer Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\AtlsVid.sys -- (EMATCORE [On_Demand | Running])
[2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2007/07/19 14:10:28 | 00,127,768 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\SYSTEM32\DRIVERS\klif.sys -- (KLIF [System | Running])
[2001/08/17 21:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped])
[2002/09/18 16:25:59 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\mraid35x.sys -- (mraid35x [Disabled | Stopped])
[2003/04/24 16:58:00 | 01,271,706 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
[2002/11/08 13:45:06 | 00,017,217 | ---- | M] (Dell Computer Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci [System | Running])
[2002/11/11 16:52:58 | 00,009,856 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys -- (pfc [On_Demand | Running])
[2002/09/18 16:31:48 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
[2004/11/01 21:02:55 | 00,017,168 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2002/09/18 16:31:51 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ql1080.sys -- (ql1080 [Disabled | Stopped])
[2002/09/18 16:31:52 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ql12160.sys -- (ql12160 [Disabled | Stopped])
[2002/09/18 16:31:52 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ql1280.sys -- (ql1280 [Disabled | Stopped])
[2007/11/13 09:47:45 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2008/04/13 19:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys -- (sisagp [Disabled | Stopped])
[2003/02/28 09:17:18 | 00,545,024 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys -- (smwdm [On_Demand | Running])
[2002/09/18 16:34:05 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\sparrow.sys -- (Sparrow [Disabled | Stopped])
[2008/02/27 02:10:44 | 00,051,176 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\SYSTEM32\ZoneLabs\srescan.sys -- (srescan [Boot | Running])
[2002/09/18 16:34:40 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\symc810.sys -- (symc810 [Disabled | Stopped])
[2002/09/18 16:34:40 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\symc8xx.sys -- (symc8xx [Disabled | Stopped])
[2002/09/18 16:34:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\sym_hi.sys -- (sym_hi [Disabled | Stopped])
[2002/09/18 16:34:40 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\sym_u3.sys -- (sym_u3 [Disabled | Stopped])
[2002/09/18 16:35:27 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ultra.sys -- (ultra [Disabled | Stopped])
[2008/07/09 08:05:22 | 00,394,952 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\SYSTEM32\vsdatant.sys -- (vsdatant [System | Running])
[2002/09/18 16:37:48 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ws2ifsl.sys -- (WS2IFSL [System | Running])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=http://www.google.com/ie
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=http://www.google.com/ie
"SearchAssistant"=http://www.google.com/ie
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.euro.dell.com/countries/fr/fra/gen/default.htm
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.google.com
"Start Page"=http://www.google.fr/
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=http://www.google.com/ie
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.google.com/search?q=%s
"provider"=gogl
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\SYSTEM32\shdocvw.dll (Microsoft Corporation)
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = local;www.miniclip.com;<local>
========== (O1) Hosts File ==========
HOSTS File = (302931 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.123topsearch.com
127.0.0.1 123topsearch.com
127.0.0.1 www.132.com
127.0.0.1 132.com
127.0.0.1 www.136136.net
127.0.0.1 136136.net
127.0.0.1 www.163ns.com
127.0.0.1 163ns.com
10441 more lines...
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
{243B17DE-77C7-46BF-B94B-0B5F309A0E64} (HKLM) -- C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (HKLM) -- C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{97421D0D-E07F-40DF-8F07-99597B9585AD} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{A057A204-BACC-4D26-9990-79A187E2698E} (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)
{AA58ED58-01DD-4d91-8333-CF10577473F7} (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
"{F2E259E8-0FC8-438C-A6E0-342DD80FA53E}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"BCMSMMSG"=BCMSMMSG.exe (Broadcom Corporation)
"DVDSentry"=C:\WINDOWS\System32\DSentry.exe (Dell - Advanced Desktop Engineering)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"LOGGING_FILTER"="C:\Program Files\Parental Filter 2\LoggingEpcp2.exe" start (Editions Profil)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r (VERITAS Software, Inc.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Zone Labs, LLC)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvMon.exe"=C:\WINDOWS\System32\DrvMon.exe (Alcor Micro, Corp.)
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" (Microsoft Corporation)
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
"Windows Service Agent"=hinksu.exe File not found
========== (O4) Startup Folders ==========
[2002/11/27 08:10:00 | 00,106,561 | ---- | M] (WinZip Computing, Inc.) -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"HonorAutoRunSetting"=1
"NoCDBurning"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
"NoViewOnDrive"=0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableRegistryTools"=0
"DisableTaskMgr"=0
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xporter vers Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Recherche -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2008/09/15 13:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
{E023F504-0C5A-4750-A1E7-A9046DEA8A21}: Button: MoneySide -- %ProgramFiles%\Microsoft Money\System\mnyside.dll [2002/07/17 11:00:00 | 00,163,906 | ---- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 03:34:13 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/14 03:34:13 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2002/09/18 16:26:55 | 00,945,693 | ---- | M] (Microsoft Corporation)
CmdMapping\\{193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{688DC797-DC11-46A7-9F1B-445F4F58CE6E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Recherche] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> [2008/09/15 13:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
CmdMapping\\{E023F504-0C5A-4750-A1E7-A9046DEA8A21} [HKLM] -> %ProgramFiles%\Microsoft Money\System\mnyside.dll [MoneySide] -> [2002/07/17 11:00:00 | 00,163,906 | ---- | M] (Microsoft Corporation)
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 19:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 03:34:13 | 01,695,232 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s
PluginsPageFriendlyName: "" = Bibliothèque de contrôles ActiveX Microsoft
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
49 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
: msn in Poste de travail
48 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}: C:\Program Files\Yahoo!\Common\yinsthelper.dll -- YInstStarter Class
{74D05D43-3236-11D4-BDCD-00C04F9A3B61}:
http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housec(...) -- HouseCall Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab -- Java Plug-in 1.6.0_06
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab -- Shockwave Flash Object
DirectAnimation Java Classes:
file://C:\WINDOWS\Java\classes\dajava.cab -- Reg Error: Key does not exist or could not be opened.
Microsoft XML Parser for Java:
file://C:\WINDOWS\Java\classes\xmldso.cab -- Reg Error: Key does not exist or could not be opened.
========== (O17) DNS Name Servers ==========
{3C80B075-F706-4460-8C01-6A930B8AD94F} (Servers: | Description: )
{A59CCAFF-722D-4515-9202-FEE01B0B353A} (Servers: | Description: Carte réseau 1394)
{DAD7E784-7820-4C45-8C53-CCA95A8A871A} (Servers: | Description: Intel(R) PRO/100 VE Network Connection)
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
avgrsstarter: "DllName" = avgrsstx.dll -- C:\WINDOWS\SYSTEM32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
========== (O21) SSODL Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"ThunderAdvise"={97421D0D-E07F-40DF-8F07-99597B9585AD} (HKLM) -- CLSID or file not found.
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2002/09/18 11:35:52 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[3 C:\WINDOWS\System32\*.tmp files]
[8 C:\WINDOWS\*.tmp files]
[2009/03/19 20:43:32 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ALAIN\Bureau\OTViewIt.exe
[2009/03/15 18:34:05 | 00,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 9.lnk
[2009/03/15 18:14:54 | 00,000,000 | ---D | C] -- C:\Program Files\Freeplayer
[2009/03/15 18:11:20 | 12,015,715 | ---- | C] () -- C:\Documents and Settings\ALAIN\Bureau\Freeplayer-Win32-20070531.exe
[2009/03/15 17:52:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ALAIN\Application Data\FileZilla
[2009/03/15 17:51:48 | 00,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[2009/03/15 17:47:28 | 03,861,671 | ---- | C] () -- C:\Documents and Settings\ALAIN\Bureau\FileZilla_3.2.2.1_win32-setup.exe
[2009/03/15 09:08:30 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\ALAIN\Bureau\HijackThis.lnk
[2009/03/15 09:08:28 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/03/15 09:07:24 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\ALAIN\Bureau\hijackthis_hijackthis_2.02_anglais_17891.exe
[2009/03/14 15:24:38 | 00,001,641 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Parental Filter 2.lnk
[2009/03/14 15:22:52 | 00,000,000 | ---D | C] -- C:\Program Files\Parental Filter 2
[2009/03/14 15:12:33 | 99,491,608 | ---- | C] () -- C:\Documents and Settings\ALAIN\Bureau\parentalfilter2.exe
[2009/03/13 08:41:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2009/03/11 19:01:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ALAIN\Local Settings\Application Data\Logging - ALAIN
[2009/03/11 18:27:19 | 00,027,264 | ---- | C] (Editions Profil) -- C:\WINDOWS\System32\EPSE.dll
[2009/03/09 20:30:29 | 01,089,883 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/03/08 23:24:03 | 00,000,000 | ---D | C] -- C:\2840d7e910af7b85c3
[2009/03/08 21:58:39 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/03/08 21:50:23 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/03/08 21:50:21 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2009/03/08 21:47:46 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/03/08 21:44:51 | 00,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2009/03/08 21:38:29 | 00,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2009/03/08 21:36:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2009/03/07 20:42:42 | 00,000,000 | ---D | C] -- C:\unzipped
[2009/03/07 20:41:13 | 00,001,518 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
[2009/03/07 20:41:12 | 00,000,750 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\WinZip.lnk
[2009/03/07 19:43:45 | 00,015,872 | ---- | C] () -- C:\Documents and Settings\ALAIN\Mes documents\MarmaraBodrum09.xls
[2009/03/01 16:27:22 | 00,000,000 | ---- | C] () -- C:\WINDOWS\viewer.INI
[2009/02/25 11:46:31 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\ALAIN\Mes documents\FreeJulienCOURBET.doc
[2009/02/25 10:04:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ALAIN\Application Data\Apple Computer
[2009/02/25 10:00:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\ALAIN\Local Settings\Application Data\Apple Computer
[2009/02/24 17:12:24 | 00,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\iTunes.lnk
[2009/02/24 17:10:22 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/02/24 17:10:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/02/24 17:10:11 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/02/24 17:09:41 | 00,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2009/02/24 17:08:53 | 00,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\QuickTime Player.lnk
[2009/02/24 17:08:25 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/02/24 17:08:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/24 17:07:44 | 00,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/24 17:07:34 | 00,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2009/02/24 17:07:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/02/24 17:06:54 | 00,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\Apple
[2009/02/24 17:06:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
========== Files - Modified Within 30 Days ==========
[3 C:\WINDOWS\System32\*.tmp files]
[8 C:\WINDOWS\*.tmp files]
[2009/03/19 20:45:45 | 28,971,040 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009/03/19 20:43:36 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ALAIN\Bureau\OTViewIt.exe
[2009/03/19 19:19:57 | 00,358,382 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/03/19 19:16:53 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/03/19 19:16:10 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\BOOTSTAT.DAT:KAVICHS
[2009/03/19 19:16:08 | 53,589,1968 | -HS- | M] () -- C:\hiberfil.sys
[2009/03/19 12:01:46 | 00,340,292 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009/03/19 07:45:41 | 34,193,526 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/19 07:45:41 | 00,041,402 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/18 18:29:26 | 00,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
@Alternate Data Stream - 228 bytes -> C:\WINDOWS\System32\WPA.DBL:KAVICHS
[2009/03/15 18:34:06 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Adobe Reader 9.lnk
[2009/03/15 18:11:20 | 12,015,715 | ---- | M] () -- C:\Documents and Settings\ALAIN\Bureau\Freeplayer-Win32-20070531.exe
[2009/03/15 17:47:31 | 03,861,671 | ---- | M] () -- C:\Documents and Settings\ALAIN\Bureau\FileZilla_3.2.2.1_win32-setup.exe
[2009/03/15 09:08:30 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\ALAIN\Bureau\HijackThis.lnk
[2009/03/15 09:07:26 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\ALAIN\Bureau\hijackthis_hijackthis_2.02_anglais_17891.exe
[2009/03/14 15:24:38 | 00,001,641 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Parental Filter 2.lnk
[2009/03/14 15:16:28 | 99,491,608 | ---- | M] () -- C:\Documents and Settings\ALAIN\Bureau\parentalfilter2.exe
[2009/03/14 14:20:16 | 00,002,551 | ---- | M] () -- C:\Documents and Settings\ALAIN\Bureau\Microsoft Office Excel 2003.lnk
[2009/03/11 18:19:38 | 00,027,264 | ---- | M] (Editions Profil) -- C:\WINDOWS\System32\EPSE.dll
[2009/03/11 18:04:15 | 00,075,928 | ---- | M] () -- C:\Documents and Settings\ALAIN\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/11 17:57:24 | 00,286,112 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\FNTCACHE.DAT:KAVICHS
[2009/03/08 23:36:34 | 01,066,796 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 23:36:34 | 00,506,402 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2009/03/08 23:36:34 | 00,438,036 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2009/03/08 23:36:34 | 00,083,194 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2009/03/08 23:36:34 | 00,069,668 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2009/03/08 17:22:27 | 00,000,673 | ---- | M] () -- C:\WINDOWS\WIN.INI
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\WIN.INI:KAVICHS
[2009/03/08 17:22:27 | 00,000,253 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\SYSTEM.INI:KAVICHS
[2009/03/08 17:22:27 | 00,000,216 | RHS- | M] () -- C:\boot.ini
[2009/03/07 21:13:01 | 00,015,872 | ---- | M] () -- C:\Documents and Settings\ALAIN\Mes documents\MarmaraBodrum09.xls
[2009/03/07 20:41:13 | 00,001,518 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
[2009/03/07 20:41:12 | 00,000,750 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\WinZip.lnk
[2009/03/07 19:42:38 | 02,821,514 | -H-- | M] () -- C:\Documents and Settings\ALAIN\Local Settings\Application Data\IconCache.db
[2009/03/07 11:41:31 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\iTunes.lnk
[2009/03/03 22:55:37 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\ALAIN\Bureau\CCleaner.lnk
[2009/03/01 16:27:22 | 00,000,000 | ---- | M] () -- C:\WINDOWS\viewer.INI
[2009/02/28 10:21:03 | 00,302,931 | R--- | M] () -- C:\WINDOWS\System32\drivers\ETC\HOSTS
[2009/02/25 12:55:00 | 24,768,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/02/25 12:11:25 | 00,025,600 | ---- | M] () -- C:\Documents and Settings\ALAIN\Mes documents\FreeJulienCOURBET.doc
[2009/02/25 10:23:59 | 00,002,573 | ---- | M] () -- C:\Documents and Settings\ALAIN\Bureau\Microsoft Office Word 2003.lnk
[2009/02/24 17:08:53 | 00,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\QuickTime Player.lnk
[2009/02/24 17:07:45 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/19 19:19:32 | 00,401,372 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
< End of report >
Bonne réception et merci d'avance pour ta très sympathique coopération