Deckard's System Scanner v20071014.68
Run by lowwa132 on 2008-08-07 21:13:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 3 Restore Point(s) --
3: 2008-08-07 19:13:08 UTC - RP3 - Deckard's System Scanner Restore Point
2: 2008-08-07 19:01:50 UTC - RP2 - Installé Java(TM) 6 Update 7
1: 2008-08-07 07:46:01 UTC - RP1 - Point de vérification système
Performed disk cleanup.
-- HijackThis (run as lowwa132.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:13:14, on 07/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Atheros\ACU.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\Logiciels\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\system32\RemoteControlService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\lowwa132\bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\lowwa132.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.fr/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.fr/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.google.fr/search?q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O20 "mafreebox.freebox.fr" /M "Stylus C82"
O4 - HKLM\..\Run: [EPSON Stylus C82 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P33 "EPSON Stylus C82 Series (Copie 1)" /O20 "mafreebox.freebox.fr" /M "Stylus C82"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Logiciels\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
O4 - Startup: GigaTribe.lnk.disabled
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{030D91A4-B77E-4460-A6A4-30B4F3802CC5}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CS1\Services\Tcpip\..\{030D91A4-B77E-4460-A6A4-30B4F3802CC5}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CS2\Services\Tcpip\..\{030D91A4-B77E-4460-A6A4-30B4F3802CC5}: NameServer = 212.27.54.252,212.27.53.252
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Freenet 0.7 darknet-8888 (freenet-darknet-8888) - Unknown owner - D:\Logiciels\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet 0.7 darknet-8888-8888 (freenet-darknet-8888-8888) - Unknown owner - D:\Logiciels\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ITE Remote Control Service (ITECIRService) - ITE Tech. Inc. - C:\WINDOWS\system32\RemoteControlService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: tinc.upi - Unknown owner - C:\Program.exe (file missing)
--
End of file - 11803 bytes
-- File Associations -----------------------------------------------------------
.txt - txtfile - DefaultIcon - %windir%\NOTEPAD.EXE,0
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfsync02 (StarForce Protection Synchronization Driver (version 2.x)) - c:\windows\system32\drivers\sfsync02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 Tosrfcom (Bluetooth RFCOMM from TOSHIBA) - c:\windows\system32\drivers\tosrfcom.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFCOMM Driver>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.4.10.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.4.10.0>
R3 tosporte (Bluetooth Port Driver from Toshiba) - c:\windows\system32\drivers\tosporte.sys <Not Verified; TOSHIBA Corporation; TOSHIBA Bluetooth Port Emulation Driver>
S3 BDFsDrv - c:\program files\softwin\bitdefender10\bdfsdrv.sys (file missing)
S3 BDRsDrv - c:\program files\softwin\bitdefender10\bdrsdrv.sys (file missing)
S3 NSNDIS5 (NSNDIS5 NDIS Protocol Driver) - c:\windows\system32\nsndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); NetStumbler>
S3 Profos - c:\program files\fichiers communs\bitdefender\bitdefender threat scanner\profos.sys (file missing)
S3 tap0901 (TAP-Win32 Adapter V9) - c:\windows\system32\drivers\tap0901.sys <Not Verified; The OpenVPN Project; TAP-Win32 Virtual Network Driver>
S3 toshidpt (TOSHIBA Bluetooth HID port driver) - c:\windows\system32\drivers\toshidpt.sys <Not Verified; TOSHIBA Corporation.; TOSHIBA Bluetooth HID Mini Port Driver>
S3 Tosrfbd (Bluetooth RFBUS from TOSHIBA) - c:\windows\system32\drivers\tosrfbd.sys <Not Verified; TOSHIBA CORPORATION; Bluetooth BUS Driver(WindowsXP,Windows2000)>
S3 Tosrfbnp (Bluetooth RFBNEP from TOSHIBA) - c:\windows\system32\drivers\tosrfbnp.sys <Not Verified; TOSHIBA Corporation; Bluetooth RFBNEP Driver from TOSHIBA>
S3 Tosrfhid (Bluetooth RFHID from TOSHIBA) - c:\windows\system32\drivers\tosrfhid.sys <Not Verified; TOSHIBA Corporation.; Bluetooth HID Driver from TOSHIBA>
S3 tosrfnds (Bluetooth Personal Area Network from TOSHIBA) - c:\windows\system32\drivers\tosrfnds.sys <Not Verified; TOSHIBA Corporation.; Bluetooth BNEP Driver from TOSHIBA>
S3 TosRfSnd (Bluetooth Audio Device (WDM) from TOSHIBA) - c:\windows\system32\drivers\tosrfsnd.sys <Not Verified; TOSHIBA Corporation; Bluetooth Audio Driver>
S3 Tosrfusb (Bluetooth USB Controller) - c:\windows\system32\drivers\tosrfusb.sys <Not Verified; TOSHIBA CORPORATION; Microsoft(R) Windows NT(R) Operating System>
S3 Trufos - c:\program files\fichiers communs\bitdefender\bitdefender threat scanner\trufos.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 ACS (Service de configuration Atheros) - c:\windows\system32\acs.exe <Not Verified; Atheros; Atheros Configuration Service (ACS)>
R2 Bonjour Service (Service Bonjour) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 ITECIRService (ITE Remote Control Service) - c:\windows\system32\remotecontrolservice.exe <Not Verified; ITE Tech. Inc.; >
S2 freenet-darknet-8888 (Freenet 0.7 darknet-8888) - d:\logiciels\freenet\bin\wrapper-windows-x86-32.exe -s d:\logiciels\freenet\wrapper.conf (file missing)
S2 freenet-darknet-8888-8888 (Freenet 0.7 darknet-8888-8888) - d:\logiciels\freenet\bin\wrapper-windows-x86-32.exe -s d:\logiciels\freenet\wrapper.conf (file missing)
S2 tinc.upi - "c:\program files\tinc\tincd" -n upi (file missing)
S3 FLEXnet Licensing Service - "c:\program files\fichiers communs\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: [CommView] Atheros AR5006X Wireless Network Adapter
Device ID: PCI\VEN_168C&DEV_001C&SUBSYS_3065168C&REV_01\4&E2974D5&0&0010
Manufacturer: TamoSoft, Inc.
Name: [CommView] Atheros AR5006X Wireless Network Adapter
PNP Device ID: PCI\VEN_168C&DEV_001C&SUBSYS_3065168C&REV_01\4&E2974D5&0&0010
Service: AR5211
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Carte réseau 1394
Device ID: V1394\NIC1394\372B2A1E01800
Manufacturer: Microsoft
Name: Carte réseau 1394
PNP Device ID: V1394\NIC1394\372B2A1E01800
Service: NIC1394
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: TAP-Win32 Adapter V9
Device ID: ROOT\NET\0000
Manufacturer: TAP-Win32 Provider V9
Name: TAP-Win32 Adapter V9
PNP Device ID: ROOT\NET\0000
Service: tap0901
-- Process Modules -------------------------------------------------------------
C:\WINDOWS\system32\winlogon.exe (pid 1536)
2005-01-27 02:47:46 1114112 --a------ C:\WINDOWS\system32\msgina.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2007-10-25 18:43:25 12930560 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-12-13 13:54:01 499200 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-12-07 20:16:50 142336 --a------ C:\WINDOWS\system32\sfc_os.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-07-05 22:52:10 219648 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:08:57 3378176 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
C:\WINDOWS\system32\svchost.exe (pid 1780)
2007-10-25 18:43:25 12930560 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-12-13 13:54:01 499200 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-07-05 22:52:10 219648 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:08:57 3378176 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
C:\WINDOWS\system32\svchost.exe (pid 1996)
2007-10-25 18:43:25 12930560 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-12-13 13:54:01 499200 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-07-05 22:52:10 219648 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:08:57 3378176 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-04-23 06:16:40 817152 --a------ C:\WINDOWS\system32\wininet.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2005-04-20 21:31:04 2137088 --a------ C:\WINDOWS\system32\netshell.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:09:21 190976 --a------ C:\WINDOWS\system32\credui.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2007-07-24 15:17:08 147456 --a------ C:\Program Files\Bonjour\mdnsNSP.dll <Not Verified; Apple Inc.; Bonjour>
2006-12-07 20:16:50 142336 --a------ C:\WINDOWS\system32\sfc_os.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:09:39 1256960 --a------ C:\WINDOWS\system32\rasdlg.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-04-23 06:16:40 1233408 --a------ C:\WINDOWS\system32\urlmon.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
C:\WINDOWS\explorer.exe (pid 1196)
2006-12-13 13:53:51 1021440 --a------ C:\WINDOWS\system32\browseui.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-12-13 13:54:01 499200 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-12-13 13:54:00 1776640 --a------ C:\WINDOWS\system32\shdocvw.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-04-23 06:16:40 817152 --a------ C:\WINDOWS\system32\wininet.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2007-10-25 18:43:25 12930560 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-07-05 22:52:10 219648 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:09:47 393728 --a------ C:\WINDOWS\system32\themeui.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:08:57 3378176 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:09:37 233984 --a------ C:\WINDOWS\system32\ntshrui.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-04-23 06:16:40 394240 --a------ C:\WINDOWS\system32\webcheck.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2004-08-19 18:09:45 147968 --a------ C:\WINDOWS\system32\stobject.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:09:21 28672 --a------ C:\WINDOWS\system32\batmeter.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-04-23 06:16:40 1233408 --a------ C:\WINDOWS\system32\urlmon.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2006-05-21 09:43:08 65536 --a------ C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
2006-05-21 09:43:14 53248 --a------ C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.dll <Not Verified; ; Y'z Shadow DLL>
2007-03-19 00:04:22 69632 --a------ C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
2005-04-20 21:31:04 2137088 --a------ C:\WINDOWS\system32\netshell.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:09:21 190976 --a------ C:\WINDOWS\system32\credui.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2007-11-27 17:25:35 172032 --a------ C:\Program Files\Illustrate\dBpoweramp\dBShell.dll <Not Verified; Illustrate; dBpoweramp>
2005-01-27 02:47:46 1114112 --a------ C:\WINDOWS\system32\msgina.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-01-11 12:28:36 94720 --a------ C:\Program Files\FileZilla Client\fzshellext.dll <Not Verified; ; fzshellext Dynamic Link Library>
2006-11-19 00:58:56 86528 --a------ C:\WINDOWS\system32\mydocs.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:08:51 689664 --a------ C:\WINDOWS\system32\shdoclc.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
C:\WINDOWS\system32\svchost.exe (pid 3872)
2007-10-25 18:43:25 12930560 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-12-13 13:54:01 499200 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2006-07-05 22:52:10 219648 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2004-08-19 18:08:57 3378176 --a------ C:\WINDOWS\system32\xpsp2res.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
-- Scheduled Tasks -------------------------------------------------------------
2008-08-01 17:00:02 410 --a------ C:\WINDOWS\Tasks\updater.exe.job
2008-04-18 20:59:46 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-07-07 and 2008-08-07 -----------------------------
2008-08-07 20:49:48 0 d-------- C:\WINDOWS\LastGood
2008-08-06 23:34:29 0 d-------- C:\Program Files\Trend Micro
2008-08-04 18:47:32 0 d-------- C:\Program Files\iPod
2008-08-04 00:50:41 53046 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-08-04 00:34:11 6120 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-08-04 00:33:36 0 d-------- C:\WINDOWS\BricoPacks
2008-08-01 14:37:51 0 d-------- C:\Program Files\Sunbelt Software
2008-08-01 14:26:00 0 d-------- C:\Program Files\Alwil Software
2008-07-30 20:24:44 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Real
2008-07-30 20:24:26 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Identities
2008-07-30 20:24:14 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-07-30 20:24:14 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-07-30 20:24:14 0 dr-h----- C:\Documents and Settings\Administrateur\SendTo
2008-07-30 20:24:14 0 dr-h----- C:\Documents and Settings\Administrateur\Recent
2008-07-30 20:24:14 0 d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-07-30 20:24:14 0 dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-07-30 20:24:14 0 dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-07-30 20:24:14 0 d--h----- C:\Documents and Settings\Administrateur\Local Settings
2008-07-30 20:24:14 0 dr------- C:\Documents and Settings\Administrateur\Favoris
2008-07-30 20:24:14 0 d--hs---- C:\Documents and Settings\Administrateur\Cookies
2008-07-30 20:24:14 0 d-------- C:\Documents and Settings\Administrateur\Bureau
2008-07-30 20:24:14 0 dr-h----- C:\Documents and Settings\Administrateur\Application Data
2008-07-30 20:24:14 0 d---s---- C:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-07-30 20:24:13 786432 --ah----- C:\Documents and Settings\Administrateur\NTUSER.DAT
2008-07-26 22:51:34 0 d-------- C:\Program Files\WebMediaPlayer
2008-07-17 19:24:48 0 d-------- C:\Films FB HD
2008-07-17 18:57:26 0 dr-h----- C:\Documents and Settings\lowwa132\Recent
2008-07-09 15:49:53 0 d-------- C:\WINDOWS\system32\logs
2008-07-09 15:49:00 0 d-------- C:\Program Files\BitDefender
-- Find3M Report ---------------------------------------------------------------
2008-08-07 21:03:37 0 d-------- C:\Program Files\Java
2008-08-04 18:46:29 0 d-------- C:\Program Files\Bonjour
2008-08-04 18:45:59 0 d-------- C:\Program Files\QuickTime
2008-08-03 21:00:57 0 d-------- C:\Documents and Settings\lowwa132\Application Data\teamspeak2
2008-08-03 20:52:32 510940 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-08-03 20:52:32 85686 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-08-01 13:04:00 0 d-------- C:\Program Files\EPSON
2008-07-30 20:11:58 0 d-------- C:\Documents and Settings\lowwa132\Application Data\Skype
2008-07-30 20:03:38 0 d-------- C:\Documents and Settings\lowwa132\Application Data\skypePM
2008-07-18 14:36:18 0 d-------- C:\Program Files\Yahoo!
2008-07-11 21:22:13 0 d-------- C:\Documents and Settings\lowwa132\Application Data\FileZilla
2008-07-09 15:49:22 0 d-------- C:\Program Files\Fichiers communs\BitDefender
2008-06-30 18:12:37 0 d-------- C:\Program Files\Free Easy Burner
2008-06-28 20:45:09 0 d-------- C:\Documents and Settings\lowwa132\Application Data\Mozilla
2008-06-20 14:07:00 0 d-------- C:\Documents and Settings\lowwa132\Application Data\Auslogics
2008-06-20 14:06:56 0 d-------- C:\Program Files\Auslogics
2008-06-10 09:00:29 0 d-------- C:\Program Files\7-Zip
2008-05-27 16:42:10 106 --a------ C:\WINDOWS\system32\inetda.dll
2008-05-27 16:16:07 81984 --a------ C:\WINDOWS\system32\bdod.bin
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
04/10/2007 22:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [04/10/2007 22:06 1135968]
[-HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [23/08/2006 16:22]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [21/10/2005 16:26]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [10/06/2008 04:27]
"ACU"="C:\Program Files\Atheros\ACU.exe" [07/08/2006 20:15]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/04/2006 00:47]
"nwiz"="nwiz.exe" [28/04/2006 00:47 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [28/04/2006 00:47]
"EPSON Stylus C82 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.exe" [15/10/2003 03:02]
"EPSON Stylus C82 Series (Copie 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.exe" [15/10/2003 03:02]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [19/07/2008 16:38]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [22/07/2008 20:42]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [27/05/2008 10:50]
"iTunesHelper"="D:\Logiciels\iTunes\iTunesHelper.exe" [30/07/2008 10:47]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 12:34]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 12:43]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [19/08/2004 18:09]
C:\Documents and Settings\lowwa132\Menu D‚marrer\Programmes\D‚marrage\
GigaTribe.lnk.disabled [10/06/2008 13:45:49]
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [19/03/2007 00:05:02]
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [01/06/2005 21:41:18]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [21/05/2006 09:43:08]
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [21/05/2006 09:43:14]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [16/06/2005 11:11:42]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"=0 (0x0)
"SynchronousUserGroupPolicy"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRemoteRecursiveEvents"=1 (0x1)
"NoLowDiskSpaceChecks"=1 (0x1)
"ForceClassicControlPanel"=1 (0x1)
"NoSimpleStartMenu"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"=0 (0x0)
"NoSaveSettings"=0 (0x0)
"NoTrayItemsDisplay"=0 (0x0)
"NoToolbarsOnTaskbar"=0 (0x0)
"LockTaskbar"=0 (0x0)
"NoResolveTrack"=0 (0x0)
"NoResolveSearch"=0 (0x0)
"NoNetworkConnections"=0 (0x0)
"NoRun"=0 (0x0)
"NoSMHelp"=0 (0x0)
"NoRecentDocsMenu"=0 (0x0)
"NoFind"=0 (0x0)
"NoSMMyPictures"=0 (0x0)
"NoRecentDocsHistory"=0 (0x0)
"NoStartMenuMFUprogramsList"=0 (0x0)
"NoUserNameInStartMenu"=0 (0x0)
"NoStartMenuMorePrograms"=0 (0x0)
"ClearRecentDocsOnExit"=0 (0x0)
"MaxRecentDocs"=15 (0xf)
"NoInstrumentation"=0 (0x0)
"MemCheckBoxInRunDlg"=1 (0x1)
"NoSMBalloonTip"=0 (0x0)
"DisallowCpl"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\DisallowCpl]
"1"=Polices
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^lowwa132^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
path=C:\Documents and Settings\lowwa132\Menu Démarrer\Programmes\Démarrage\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^lowwa132^Menu Démarrer^Programmes^Démarrage^IcoSauve.lnk]
path=C:\Documents and Settings\lowwa132\Menu Démarrer\Programmes\Démarrage\IcoSauve.lnk
backup=C:\WINDOWS\pss\IcoSauve.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
"C:\Program Files\Softwin\BitDefender10\bdagent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
"C:\Program Files\DAEMON Tools\daemon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerStrip]
c:\program files\powerstrip\pstrip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"="d:\jeux\steam\steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Alcmtr"=ALCMTR.EXE
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
-- Hosts -----------------------------------------------------------------------
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
www.032439.com
127.0.0.1 032439.com
8940 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-08-07 21:14:38 ------------