probleme de lenteur virus
Posté : 12 mars 2010, 10:41
bonjour si quelqu'un pouvait m'aidez je lui en serai reconnaissant j'ai mon ordi qui bloque tres souvent et des que je m' ai firewall de orange alors la je ne peu meme plus m'en servire je vous envoie un rapport rsit encore merci
Logfile of random's system information tool 1.06 (written by random/random)
Run by laurent at 2010-03-12 09:17:42
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 83 GB (36%) free of 229 GB
Total RAM: 2942 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:17:44, on 12/03/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\RocketDock\RocketDock.exe
C:\Users\laurent\Desktop\RSIT.exe
C:\Program Files\trend micro\laurent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbShar.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbShar.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACADF4AA-9401-4703-A580-0E8B7825E8C3}: NameServer = 80.10.246.1,81.253.149.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Service Google Update (gupdate1ca07a254b84d94) (gupdate1ca07a254b84d94) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 6461 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for laurent.job
C:\Windows\tasks\Registry_Doktor.job
C:\Windows\tasks\User_Feed_Synchronization-{24255D18-ACDF-4D67-8B95-ACF0285207E4}.job
C:\Windows\tasks\User_Feed_Synchronization-{7BB5A7D6-4D74-4667-8423-FC185771004F}.job
C:\Windows\tasks\User_Feed_Synchronization-{9F35D321-6275-4B84-8313-D4C1F81386E6}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-05-08 1262888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{280b5d37-4a76-467a-b3d6-942fca90acde}]
Shareware.Pro-FR Toolbar - C:\Program Files\Shareware.Pro-FR\tbShar.dll [2009-02-16 1882136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-03-20 2226048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-08-10 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-03-20 2226048]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
- barre d'outils Orange - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll [2009-08-05 2268464]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{280b5d37-4a76-467a-b3d6-942fca90acde} - Shareware.Pro-FR Toolbar - C:\Program Files\Shareware.Pro-FR\tbShar.dll [2009-02-16 1882136]
{D3028143-6145-4318-99D3-3EDCE54A95A9} - barre d'outils Orange - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll [2009-08-05 2268464]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpiderMessenger"= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"eMuleAutoStart"=C:\Program Files\eMule\emule.exe -AutoStart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe [2009-02-03 1004544]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
C:\Windows\KHALMNPR.EXE [2009-06-17 55824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kjnljo]
c:\users\laurent\appdata\local\kjnljo.exe kjnljo []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe [2010-01-15 557056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
C:\Windows\KHALMNPR.EXE [2009-06-17 55824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2009-10-14 2793304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MailNotifier]
C:\Program Files\Orange\MailNotifier\MailNotifier.exe [2009-10-12 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe /command:faststart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Windows\RtHDVCpl.exe [2006-11-09 3784704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPAMfighter Agent]
C:\Program Files\SPAMfighter\SFAgent.exe update delay 60 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2009-05-07 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2008-03-25 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LOGITE~1.EXE -startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
C:\PROGRA~1\Logitech\SetPoint\SetPoint.exe [2009-07-20 813584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^laurent^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Outil de détection de support de Cyber-shot Viewer.lnk]
C:\PROGRA~1\Sony\SONYPI~1\VOLUME~1\SPUVOL~1.EXE [2005-10-28 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDriveAutoRun"=255
"HonorAutoRunSetting"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{837bb11f-0fe8-11de-b652-001921ddd7c3}]
shell\AutoRun\command - F:\
shell\explore\command - F:\RECYCLER\autorun.exe -ExploreCurDir
shell\open\command - F:\RECYCLER\autorun.exe -OpenCurDir
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 2 months======
2010-03-11 19:54:59 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-11 14:37:34 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-11 14:36:23 ----A---- C:\Windows\system32\httpapi.dll
2010-03-11 05:14:47 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-03-11 05:14:34 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-03-08 16:43:51 ----D---- C:\Users\laurent\AppData\Roaming\Malwarebytes
2010-03-08 16:43:15 ----D---- C:\ProgramData\Malwarebytes
2010-03-08 16:43:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-08 10:26:50 ----D---- C:\Ad-Remover
2010-03-07 16:47:47 ----RASHD---- C:\autorun.inf
2010-03-07 16:42:54 ----A---- C:\UsbFix.txt
2010-03-07 16:08:58 ----D---- C:\UsbFix
2010-03-07 10:35:36 ----D---- C:\Program Files\trend micro
2010-03-07 10:35:31 ----D---- C:\rsit
2010-03-06 19:06:14 ----D---- C:\ProgramData\Alwil Software
2010-03-06 18:42:09 ----A---- C:\Windows\wininit.ini
2010-03-04 19:11:24 ----A---- C:\Windows\ntbtlog.txt
2010-02-26 12:16:57 ----D---- C:\Users\laurent\AppData\Roaming\Uniblue
2010-02-26 12:16:46 ----D---- C:\Program Files\Uniblue
2010-02-24 07:25:52 ----A---- C:\Windows\system32\jscript.dll
2010-02-24 07:25:10 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 07:24:12 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 07:24:10 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 07:24:04 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 07:24:03 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 07:24:03 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 07:24:03 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 07:24:02 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 07:24:02 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 07:24:02 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 07:23:22 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 07:23:20 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 07:23:20 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-02-20 16:34:34 ----D---- C:\Games
2010-02-12 19:10:30 ----A---- C:\Windows\system32\quartz.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\msyuv.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\msrle32.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-12 19:10:23 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-12 19:10:21 ----A---- C:\Windows\system32\msvfw32.dll
2010-02-12 19:10:21 ----A---- C:\Windows\system32\avifil32.dll
2010-01-31 10:03:35 ----D---- C:\Program Files\SPAMfighter
2010-01-31 10:01:41 ----D---- C:\Users\laurent\AppData\Roaming\SPAMfighter
2010-01-23 14:43:04 ----D---- C:\Users\laurent\AppData\Roaming\Nokia Ovi Suite
2010-01-22 10:50:57 ----D---- C:\ProgramData\Installations
2010-01-22 09:51:44 ----D---- C:\ProgramData\Nokia
2010-01-22 09:27:03 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 09:27:02 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 09:27:01 ----A---- C:\Windows\system32\iertutil.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\occache.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\msfeedssync.exe
2010-01-22 09:26:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-22 09:26:59 ----A---- C:\Windows\system32\ieui.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iesysprep.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iesetup.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iernonce.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iepeers.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\ie4uinit.exe
2010-01-21 21:28:52 ----D---- C:\Users\laurent\AppData\Roaming\Nokia
2010-01-21 21:28:48 ----D---- C:\ProgramData\PC Suite
2010-01-21 21:28:47 ----D---- C:\Users\laurent\AppData\Roaming\PC Suite
2010-01-21 21:04:26 ----D---- C:\ProgramData\NokiaMusic
2010-01-21 19:38:43 ----D---- C:\Program Files\DIFX
2010-01-21 19:34:34 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-01-21 19:33:57 ----D---- C:\ProgramData\OviInstallerCache
2010-01-21 19:33:57 ----D---- C:\Program Files\Nokia
2010-01-17 10:53:20 ----D---- C:\ProgramData\LightScribe
2010-01-15 18:41:22 ----A---- C:\Windows\lgfwup.ini
2010-01-15 18:41:19 ----A---- C:\Windows\system32\Vb6stkit.dll
2010-01-15 18:41:19 ----A---- C:\Windows\system32\VB6KO.DLL
2010-01-15 18:41:19 ----A---- C:\Windows\system32\lgfwunis.exe
2010-01-15 18:41:18 ----D---- C:\Program Files\lg_fwupdate
2010-01-15 18:37:58 ----D---- C:\MyWorks
2010-01-15 18:34:46 ----D---- C:\Program Files\CyberLink
2010-01-15 11:28:01 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-01-15 11:08:33 ----D---- C:\ProgramData\Symantec
2010-01-15 11:08:33 ----D---- C:\ProgramData\Norton
2010-01-15 11:08:33 ----D---- C:\Program Files\Norton Security Scan
2010-01-15 11:08:31 ----D---- C:\ProgramData\NortonInstaller
2010-01-15 11:08:31 ----D---- C:\Program Files\NortonInstaller
======List of files/folders modified in the last 2 months======
2010-03-12 09:17:36 ----D---- C:\Windows\Temp
2010-03-12 08:33:26 ----D---- C:\Windows\Tasks
2010-03-11 19:56:56 ----D---- C:\Windows\winsxs
2010-03-11 19:56:26 ----D---- C:\Windows\System32
2010-03-11 19:56:08 ----D---- C:\Windows\system32\catroot
2010-03-11 19:54:37 ----SHD---- C:\System Volume Information
2010-03-11 19:31:09 ----D---- C:\Windows\Prefetch
2010-03-11 18:58:23 ----RD---- C:\Program Files
2010-03-11 18:58:22 ----D---- C:\ProgramData\eMule
2010-03-11 18:17:17 ----D---- C:\ProgramData\f-secure
2010-03-11 18:17:16 ----D---- C:\Windows\system32\drivers
2010-03-11 18:16:44 ----D---- C:\Windows\inf
2010-03-11 18:16:42 ----D---- C:\Windows
2010-03-11 16:46:48 ----D---- C:\Windows\system32\catroot2
2010-03-11 16:37:47 ----D---- C:\Program Files\Movie Maker
2010-03-11 16:37:46 ----D---- C:\Program Files\Windows Mail
2010-03-11 14:57:11 ----SHD---- C:\Windows\Installer
2010-03-11 14:57:09 ----D---- C:\ProgramData\Microsoft Help
2010-03-11 14:49:54 ----D---- C:\Windows\Debug
2010-03-10 18:33:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-10 18:20:45 ----D---- C:\ProgramData\fssg
2010-03-09 19:26:59 ----D---- C:\Windows\WindowsMobile
2010-03-08 21:30:10 ----SHD---- C:\$RECYCLE.BIN
2010-03-08 19:33:09 ----HD---- C:\ProgramData
2010-03-08 18:56:04 ----D---- C:\Program Files\Orange
2010-03-06 19:53:37 ----D---- C:\Windows\system32\Tasks
2010-03-06 19:06:14 ----D---- C:\Program Files\Alwil Software
2010-03-06 18:58:55 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-06 17:58:34 ----D---- C:\Windows\Minidump
2010-03-06 12:44:35 ----D---- C:\Users\laurent\AppData\Roaming\Mozilla
2010-03-06 12:42:55 ----D---- C:\Program Files\Mozilla Firefox
2010-03-04 19:55:59 ----SD---- C:\Windows\Downloaded Program Files
2010-03-03 22:59:38 ----RD---- C:\Users
2010-03-02 06:30:12 ----A---- C:\Windows\system32\mrt.exe
2010-02-27 11:15:52 ----D---- C:\Program Files\Common Files
2010-02-25 00:44:44 ----D---- C:\Windows\rescache
2010-02-25 00:23:34 ----RSD---- C:\Windows\Fonts
2010-02-25 00:23:34 ----D---- C:\Windows\system32\fr-FR
2010-02-25 00:23:34 ----D---- C:\Windows\AppPatch
2010-02-24 09:16:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-02-14 11:44:54 ----D---- C:\Program Files\QUAD Utilities
2010-02-14 11:42:52 ----DC---- C:\Windows\system32\DRVSTORE
2010-02-14 11:40:15 ----RSD---- C:\Windows\assembly
2010-02-14 11:35:11 ----D---- C:\Windows\Globalization
2010-02-13 00:36:43 ----D---- C:\Program Files\Google
2010-02-12 18:51:22 ----D---- C:\Windows\pss
2010-02-12 18:33:29 ----D---- C:\Windows\system32\Msdtc
2010-02-12 18:33:25 ----D---- C:\Windows\system32\wbem
2010-02-12 18:32:24 ----D---- C:\Windows\system32\config
2010-02-12 18:30:26 ----D---- C:\Program Files\Internet Explorer
2010-02-12 18:30:25 ----D---- C:\Windows\system32\spool
2010-02-12 18:30:25 ----D---- C:\Windows\system32\CodeIntegrity
2010-02-12 18:29:44 ----HD---- C:\$WINDOWS.~Q
2010-02-12 18:28:27 ----HD---- C:\$INPLACE.~TR
2010-02-12 18:28:23 ----D---- C:\Windows\registration
2010-02-07 16:44:54 ----D---- C:\Users\laurent\AppData\Roaming\Image Zone Express
2010-02-04 06:23:41 ----D---- C:\Windows\system32\LogFiles
2010-01-30 20:08:50 ----D---- C:\Users\laurent\AppData\Roaming\Skype
2010-01-30 18:28:50 ----D---- C:\Users\laurent\AppData\Roaming\skypePM
2010-01-22 11:09:50 ----D---- C:\Windows\system32\migration
2010-01-21 19:55:00 ----D---- C:\Windows\Downloaded Installations
2010-01-21 19:54:42 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-21 13:37:37 ----D---- C:\Program Files\Microsoft Silverlight
2010-01-17 10:49:16 ----D---- C:\ProgramData\CyberLink
2010-01-16 18:33:15 ----D---- C:\ProgramData\Google Updater
2010-01-16 15:34:45 ----D---- C:\Program Files\OrangeHSS
2010-01-15 21:33:00 ----D---- C:\Windows\system32\Macromed
2010-01-15 19:25:10 ----D---- C:\Temp
2010-01-15 18:57:49 ----D---- C:\Users\laurent\AppData\Roaming\CyberLink
2010-01-15 18:42:45 ----AD---- C:\ProgramData\TEMP
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2006-11-08 1647976]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\Windows\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\Windows\system32\DRIVERS\L8042mou.Sys [2009-06-17 63248]
R3 LMouKE;SetPoint Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouKE.Sys [2009-06-17 79248]
R3 LVPr2Mon;LVPr2Mon Driver; C:\Windows\system32\Drivers\LVPr2Mon.sys [2009-10-07 25752]
R3 LVRS;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs.sys [2008-07-26 627864]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2008-07-26 41752]
R3 LVUVC;Logitech QuickCam S5500(UVC); C:\Windows\system32\DRIVERS\lvuvc.sys [2008-07-26 4658584]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-06-19 7468128]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 194560]
S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 RT73;Belkin Wireless G Plus MIMO USB Network Adapter Driver; C:\Windows\system32\DRIVERS\rt73.sys [2005-11-24 245248]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C:\Windows\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\Windows\system32\DRIVERS\ZTEusbser6k.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe [2008-06-20 65536]
R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 154136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-06-19 118784]
R2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2007-03-20 65536]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S2 gupdate1ca07a254b84d94;Service Google Update (gupdate1ca07a254b84d94); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-07-18 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-10 190448]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 GoogleDesktopManager;GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [2007-03-20 81408]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by laurent at 2010-03-12 09:17:42
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 83 GB (36%) free of 229 GB
Total RAM: 2942 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:17:44, on 12/03/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\RocketDock\RocketDock.exe
C:\Users\laurent\Desktop\RSIT.exe
C:\Program Files\trend micro\laurent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbShar.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Shareware.Pro-FR Toolbar - {280b5d37-4a76-467a-b3d6-942fca90acde} - C:\Program Files\Shareware.Pro-FR\tbShar.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACADF4AA-9401-4703-A580-0E8B7825E8C3}: NameServer = 80.10.246.1,81.253.149.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Service Google Update (gupdate1ca07a254b84d94) (gupdate1ca07a254b84d94) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 6461 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for laurent.job
C:\Windows\tasks\Registry_Doktor.job
C:\Windows\tasks\User_Feed_Synchronization-{24255D18-ACDF-4D67-8B95-ACF0285207E4}.job
C:\Windows\tasks\User_Feed_Synchronization-{7BB5A7D6-4D74-4667-8423-FC185771004F}.job
C:\Windows\tasks\User_Feed_Synchronization-{9F35D321-6275-4B84-8313-D4C1F81386E6}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-05-08 1262888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{280b5d37-4a76-467a-b3d6-942fca90acde}]
Shareware.Pro-FR Toolbar - C:\Program Files\Shareware.Pro-FR\tbShar.dll [2009-02-16 1882136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-03-20 2226048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-08-10 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-03-20 2226048]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
- barre d'outils Orange - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll [2009-08-05 2268464]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{280b5d37-4a76-467a-b3d6-942fca90acde} - Shareware.Pro-FR Toolbar - C:\Program Files\Shareware.Pro-FR\tbShar.dll [2009-02-16 1882136]
{D3028143-6145-4318-99D3-3EDCE54A95A9} - barre d'outils Orange - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000315.dll [2009-08-05 2268464]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpiderMessenger"= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"eMuleAutoStart"=C:\Program Files\eMule\emule.exe -AutoStart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe [2009-02-03 1004544]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
C:\Windows\KHALMNPR.EXE [2009-06-17 55824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kjnljo]
c:\users\laurent\appdata\local\kjnljo.exe kjnljo []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe [2010-01-15 557056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
C:\Windows\KHALMNPR.EXE [2009-06-17 55824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2009-10-14 2793304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MailNotifier]
C:\Program Files\Orange\MailNotifier\MailNotifier.exe [2009-10-12 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe /command:faststart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Windows\RtHDVCpl.exe [2006-11-09 3784704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPAMfighter Agent]
C:\Program Files\SPAMfighter\SFAgent.exe update delay 60 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2009-05-07 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2008-03-25 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LOGITE~1.EXE -startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
C:\PROGRA~1\Logitech\SetPoint\SetPoint.exe [2009-07-20 813584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^laurent^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Outil de détection de support de Cyber-shot Viewer.lnk]
C:\PROGRA~1\Sony\SONYPI~1\VOLUME~1\SPUVOL~1.EXE [2005-10-28 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDriveAutoRun"=255
"HonorAutoRunSetting"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{837bb11f-0fe8-11de-b652-001921ddd7c3}]
shell\AutoRun\command - F:\
shell\explore\command - F:\RECYCLER\autorun.exe -ExploreCurDir
shell\open\command - F:\RECYCLER\autorun.exe -OpenCurDir
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 2 months======
2010-03-11 19:54:59 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-11 14:37:34 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-11 14:36:23 ----A---- C:\Windows\system32\httpapi.dll
2010-03-11 05:14:47 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-03-11 05:14:34 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-03-08 16:43:51 ----D---- C:\Users\laurent\AppData\Roaming\Malwarebytes
2010-03-08 16:43:15 ----D---- C:\ProgramData\Malwarebytes
2010-03-08 16:43:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-08 10:26:50 ----D---- C:\Ad-Remover
2010-03-07 16:47:47 ----RASHD---- C:\autorun.inf
2010-03-07 16:42:54 ----A---- C:\UsbFix.txt
2010-03-07 16:08:58 ----D---- C:\UsbFix
2010-03-07 10:35:36 ----D---- C:\Program Files\trend micro
2010-03-07 10:35:31 ----D---- C:\rsit
2010-03-06 19:06:14 ----D---- C:\ProgramData\Alwil Software
2010-03-06 18:42:09 ----A---- C:\Windows\wininit.ini
2010-03-04 19:11:24 ----A---- C:\Windows\ntbtlog.txt
2010-02-26 12:16:57 ----D---- C:\Users\laurent\AppData\Roaming\Uniblue
2010-02-26 12:16:46 ----D---- C:\Program Files\Uniblue
2010-02-24 07:25:52 ----A---- C:\Windows\system32\jscript.dll
2010-02-24 07:25:10 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 07:24:12 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 07:24:10 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 07:24:04 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 07:24:03 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 07:24:03 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 07:24:03 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 07:24:02 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 07:24:02 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 07:24:02 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 07:23:22 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 07:23:20 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 07:23:20 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-02-20 16:34:34 ----D---- C:\Games
2010-02-12 19:10:30 ----A---- C:\Windows\system32\quartz.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\msyuv.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\msrle32.dll
2010-02-12 19:10:25 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-12 19:10:23 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-12 19:10:21 ----A---- C:\Windows\system32\msvfw32.dll
2010-02-12 19:10:21 ----A---- C:\Windows\system32\avifil32.dll
2010-01-31 10:03:35 ----D---- C:\Program Files\SPAMfighter
2010-01-31 10:01:41 ----D---- C:\Users\laurent\AppData\Roaming\SPAMfighter
2010-01-23 14:43:04 ----D---- C:\Users\laurent\AppData\Roaming\Nokia Ovi Suite
2010-01-22 10:50:57 ----D---- C:\ProgramData\Installations
2010-01-22 09:51:44 ----D---- C:\ProgramData\Nokia
2010-01-22 09:27:03 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 09:27:02 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 09:27:01 ----A---- C:\Windows\system32\iertutil.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\occache.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-22 09:27:00 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\msfeedssync.exe
2010-01-22 09:26:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-22 09:26:59 ----A---- C:\Windows\system32\ieui.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iesysprep.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iesetup.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iernonce.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\iepeers.dll
2010-01-22 09:26:59 ----A---- C:\Windows\system32\ie4uinit.exe
2010-01-21 21:28:52 ----D---- C:\Users\laurent\AppData\Roaming\Nokia
2010-01-21 21:28:48 ----D---- C:\ProgramData\PC Suite
2010-01-21 21:28:47 ----D---- C:\Users\laurent\AppData\Roaming\PC Suite
2010-01-21 21:04:26 ----D---- C:\ProgramData\NokiaMusic
2010-01-21 19:38:43 ----D---- C:\Program Files\DIFX
2010-01-21 19:34:34 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-01-21 19:33:57 ----D---- C:\ProgramData\OviInstallerCache
2010-01-21 19:33:57 ----D---- C:\Program Files\Nokia
2010-01-17 10:53:20 ----D---- C:\ProgramData\LightScribe
2010-01-15 18:41:22 ----A---- C:\Windows\lgfwup.ini
2010-01-15 18:41:19 ----A---- C:\Windows\system32\Vb6stkit.dll
2010-01-15 18:41:19 ----A---- C:\Windows\system32\VB6KO.DLL
2010-01-15 18:41:19 ----A---- C:\Windows\system32\lgfwunis.exe
2010-01-15 18:41:18 ----D---- C:\Program Files\lg_fwupdate
2010-01-15 18:37:58 ----D---- C:\MyWorks
2010-01-15 18:34:46 ----D---- C:\Program Files\CyberLink
2010-01-15 11:28:01 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-01-15 11:08:33 ----D---- C:\ProgramData\Symantec
2010-01-15 11:08:33 ----D---- C:\ProgramData\Norton
2010-01-15 11:08:33 ----D---- C:\Program Files\Norton Security Scan
2010-01-15 11:08:31 ----D---- C:\ProgramData\NortonInstaller
2010-01-15 11:08:31 ----D---- C:\Program Files\NortonInstaller
======List of files/folders modified in the last 2 months======
2010-03-12 09:17:36 ----D---- C:\Windows\Temp
2010-03-12 08:33:26 ----D---- C:\Windows\Tasks
2010-03-11 19:56:56 ----D---- C:\Windows\winsxs
2010-03-11 19:56:26 ----D---- C:\Windows\System32
2010-03-11 19:56:08 ----D---- C:\Windows\system32\catroot
2010-03-11 19:54:37 ----SHD---- C:\System Volume Information
2010-03-11 19:31:09 ----D---- C:\Windows\Prefetch
2010-03-11 18:58:23 ----RD---- C:\Program Files
2010-03-11 18:58:22 ----D---- C:\ProgramData\eMule
2010-03-11 18:17:17 ----D---- C:\ProgramData\f-secure
2010-03-11 18:17:16 ----D---- C:\Windows\system32\drivers
2010-03-11 18:16:44 ----D---- C:\Windows\inf
2010-03-11 18:16:42 ----D---- C:\Windows
2010-03-11 16:46:48 ----D---- C:\Windows\system32\catroot2
2010-03-11 16:37:47 ----D---- C:\Program Files\Movie Maker
2010-03-11 16:37:46 ----D---- C:\Program Files\Windows Mail
2010-03-11 14:57:11 ----SHD---- C:\Windows\Installer
2010-03-11 14:57:09 ----D---- C:\ProgramData\Microsoft Help
2010-03-11 14:49:54 ----D---- C:\Windows\Debug
2010-03-10 18:33:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-10 18:20:45 ----D---- C:\ProgramData\fssg
2010-03-09 19:26:59 ----D---- C:\Windows\WindowsMobile
2010-03-08 21:30:10 ----SHD---- C:\$RECYCLE.BIN
2010-03-08 19:33:09 ----HD---- C:\ProgramData
2010-03-08 18:56:04 ----D---- C:\Program Files\Orange
2010-03-06 19:53:37 ----D---- C:\Windows\system32\Tasks
2010-03-06 19:06:14 ----D---- C:\Program Files\Alwil Software
2010-03-06 18:58:55 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-06 17:58:34 ----D---- C:\Windows\Minidump
2010-03-06 12:44:35 ----D---- C:\Users\laurent\AppData\Roaming\Mozilla
2010-03-06 12:42:55 ----D---- C:\Program Files\Mozilla Firefox
2010-03-04 19:55:59 ----SD---- C:\Windows\Downloaded Program Files
2010-03-03 22:59:38 ----RD---- C:\Users
2010-03-02 06:30:12 ----A---- C:\Windows\system32\mrt.exe
2010-02-27 11:15:52 ----D---- C:\Program Files\Common Files
2010-02-25 00:44:44 ----D---- C:\Windows\rescache
2010-02-25 00:23:34 ----RSD---- C:\Windows\Fonts
2010-02-25 00:23:34 ----D---- C:\Windows\system32\fr-FR
2010-02-25 00:23:34 ----D---- C:\Windows\AppPatch
2010-02-24 09:16:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-02-14 11:44:54 ----D---- C:\Program Files\QUAD Utilities
2010-02-14 11:42:52 ----DC---- C:\Windows\system32\DRVSTORE
2010-02-14 11:40:15 ----RSD---- C:\Windows\assembly
2010-02-14 11:35:11 ----D---- C:\Windows\Globalization
2010-02-13 00:36:43 ----D---- C:\Program Files\Google
2010-02-12 18:51:22 ----D---- C:\Windows\pss
2010-02-12 18:33:29 ----D---- C:\Windows\system32\Msdtc
2010-02-12 18:33:25 ----D---- C:\Windows\system32\wbem
2010-02-12 18:32:24 ----D---- C:\Windows\system32\config
2010-02-12 18:30:26 ----D---- C:\Program Files\Internet Explorer
2010-02-12 18:30:25 ----D---- C:\Windows\system32\spool
2010-02-12 18:30:25 ----D---- C:\Windows\system32\CodeIntegrity
2010-02-12 18:29:44 ----HD---- C:\$WINDOWS.~Q
2010-02-12 18:28:27 ----HD---- C:\$INPLACE.~TR
2010-02-12 18:28:23 ----D---- C:\Windows\registration
2010-02-07 16:44:54 ----D---- C:\Users\laurent\AppData\Roaming\Image Zone Express
2010-02-04 06:23:41 ----D---- C:\Windows\system32\LogFiles
2010-01-30 20:08:50 ----D---- C:\Users\laurent\AppData\Roaming\Skype
2010-01-30 18:28:50 ----D---- C:\Users\laurent\AppData\Roaming\skypePM
2010-01-22 11:09:50 ----D---- C:\Windows\system32\migration
2010-01-21 19:55:00 ----D---- C:\Windows\Downloaded Installations
2010-01-21 19:54:42 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-21 13:37:37 ----D---- C:\Program Files\Microsoft Silverlight
2010-01-17 10:49:16 ----D---- C:\ProgramData\CyberLink
2010-01-16 18:33:15 ----D---- C:\ProgramData\Google Updater
2010-01-16 15:34:45 ----D---- C:\Program Files\OrangeHSS
2010-01-15 21:33:00 ----D---- C:\Windows\system32\Macromed
2010-01-15 19:25:10 ----D---- C:\Temp
2010-01-15 18:57:49 ----D---- C:\Users\laurent\AppData\Roaming\CyberLink
2010-01-15 18:42:45 ----AD---- C:\ProgramData\TEMP
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2006-11-08 1647976]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\Windows\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\Windows\system32\DRIVERS\L8042mou.Sys [2009-06-17 63248]
R3 LMouKE;SetPoint Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouKE.Sys [2009-06-17 79248]
R3 LVPr2Mon;LVPr2Mon Driver; C:\Windows\system32\Drivers\LVPr2Mon.sys [2009-10-07 25752]
R3 LVRS;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs.sys [2008-07-26 627864]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2008-07-26 41752]
R3 LVUVC;Logitech QuickCam S5500(UVC); C:\Windows\system32\DRIVERS\lvuvc.sys [2008-07-26 4658584]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-06-19 7468128]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 194560]
S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 RT73;Belkin Wireless G Plus MIMO USB Network Adapter Driver; C:\Windows\system32\DRIVERS\rt73.sys [2005-11-24 245248]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C:\Windows\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\Windows\system32\DRIVERS\ZTEusbser6k.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe [2008-06-20 65536]
R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 154136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-06-19 118784]
R2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2007-03-20 65536]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S2 gupdate1ca07a254b84d94;Service Google Update (gupdate1ca07a254b84d94); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-07-18 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-10 190448]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 GoogleDesktopManager;GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe [2007-03-20 81408]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------