OTViewIt logfile created on: 30/03/2009 19:36:13 - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\user\Bureau
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
478,48 Mb Total Physical Memory | 208,94 Mb Available Physical Memory | 43,67% Memory free
1,10 Gb Paging File | 0,74 Gb Available in Paging File | 67,34% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 12,26 Gb Free Space | 41,84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 45,23 Gb Total Space | 32,18 Gb Free Space | 71,16% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-3393F246B5
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
[color=orange]========== Processes ==========
/color
[2008/10/15 13:31:25 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
[2008/10/15 13:29:28 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
[2006/01/24 21:15:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
[2008/12/06 10:24:13 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
[2006/03/02 23:00:00 | 00,033,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2005/05/20 12:11:06 | 00,925,696 | R--- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
[2006/07/21 08:32:58 | 00,126,976 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
[2007/02/16 10:54:04 | 00,282,624 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\QuickTime\qttask.exe
[2008/06/12 13:28:40 | 00,266,497 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
[2005/09/08 00:35:36 | 00,716,800 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
[2005/03/14 10:37:48 | 01,057,280 | ---- | M] (SFX TEAM) -- C:\Program Files\SuperCopier2\SuperCopier2.exe
[2007/01/19 21:55:02 | 05,674,352 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe
[2007/01/19 21:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe
[2008/10/16 14:09:44 | 00,051,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauclt.exe
[2006/05/27 04:26:14 | 00,268,800 | ---- | M] (Fengtao Software Inc.) -- C:\Program Files\DVD Region+CSS Free\DVDRegionFree.exe
[2009/03/30 19:28:31 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Bureau\OTViewIt.exe
[2006/09/01 05:33:02 | 00,115,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
[color=orange]========== (O23) Win32 Services ==========
/color
[2008/10/15 13:31:25 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
[2008/10/15 13:29:28 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
[2005/09/23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2005/09/23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
File not found -- -- (DllSrv Service Controler [Auto | Stopped])
File not found -- -- (iPod Service [On_Demand | Stopped])
[2006/01/24 21:15:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
[2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2008/12/06 10:24:13 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
[2007/01/19 21:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])
[2006/10/24 20:14:56 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[color=orange]========== Driver Services ==========
/color
[2005/10/05 20:21:10 | 00,141,312 | R--- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService [On_Demand | Running])
[2005/03/04 23:53:00 | 00,127,872 | R--- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (AEAudioService [On_Demand | Running])
[2005/03/10 00:53:00 | 00,043,008 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8 [System | Running])
[2007/02/01 00:33:46 | 00,005,632 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avgarkt.sys -- (AVG Anti-Rootkit [Boot | Running])
[2007/01/18 23:00:28 | 00,003,968 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\AvgArCln.sys -- (AvgArCln [System | Running])
[2007/02/27 14:24:55 | 00,011,840 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
[2008/05/20 15:29:43 | 00,052,032 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
[2008/10/30 10:21:03 | 00,075,072 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb [System | Running])
[2004/10/28 00:21:30 | 00,145,920 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService [On_Demand | Stopped])
[2004/10/28 00:21:36 | 00,138,240 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus [On_Demand | Running])
[2004/08/13 13:56:20 | 00,005,810 | R--- | M] () -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor [On_Demand | Running])
[2006/01/24 21:15:00 | 03,535,520 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
[2006/01/27 17:04:16 | 00,099,584 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata [Boot | Running])
[2006/02/17 13:28:30 | 00,034,176 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
[2006/02/17 13:28:32 | 00,013,056 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
[2006/03/02 23:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2009/03/29 08:32:14 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV [System | Running])
[2009/02/17 11:43:30 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Stopped])
[2009/02/17 11:43:28 | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL [System | Running])
[2007/11/27 14:56:28 | 00,055,168 | ---- | M] (Macrovision Europe Ltd) -- C:\WINDOWS\system32\drivers\sdcplh.sys -- (sdcplh [System | Running])
[2006/03/02 23:00:00 | 00,027,440 | ---- | M] () -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2005/08/11 16:49:28 | 00,393,088 | R--- | M] (Sensaura) -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService [On_Demand | Running])
[2007/11/08 18:03:26 | 00,021,248 | ---- | M] (AVIRA GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv [System | Running])
[2006/03/02 23:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [Disabled | Stopped])
[color=orange]========== (R ) Internet Explorer ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=
http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=
http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=
http://www.google.fr/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[color=orange]========== (O1) Hosts File ==========
/color
HOSTS File = (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
[color=orange]========== (O2) BHO's ==========
/color
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
[color=orange]========== (O4) Run Keys ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"SMSTray"=C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe (SAMSUNG ELECTRONICS)
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray (Analog Devices, Inc.)
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=C:\Program Files\SuperCopier2\SuperCopier2.exe (SFX TEAM)
[color=orange]========== (O4) Startup Folders ==========
/color
[color=orange]========== (O6 & O7) Current Version Policies ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[color=orange]========== (O8) IE Context Menu Extensions ==========
/color
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xporter vers Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [2006/10/27 15:07:36 | 17,891,112 | ---- | M] (Microsoft Corporation)
[color=orange]========== (O9) IE Extensions ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [2006/10/26 20:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/20 01:22:10 | 01,667,584 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/20 01:22:10 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/20 01:22:10 | 01,667,584 | ---- | M] (Microsoft Corporation)
[color=orange]========== (O12) Internet Explorer Plugins ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
[color=orange]========== (O13) Default Prefixes ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=
http://
[color=orange]========== (O15) Trusted Sites ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
119 domain(s) and sub-domain(s) not assigned to a zone.
[color=orange]========== (O16) DPF ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}:
http://webscanner.kaspersky.fr/kavwebscan_unicode.cab -- CKAVWebScan Object
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}:
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
[color=orange]========== (O17) DNS Name Servers ==========
/color
{22240D4A-9243-4831-9D7A-11818F52135F} (Servers: | Description: NVIDIA nForce Networking Controller)
[color=orange]========== (O20) Winlogon Notify Settings ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
!SASWinLogon: "DllName" = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll -- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
[color=orange]========== Shell Execute Hooks ==========
/color
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
"{93994DE8-8239-4655-B1D1-5F4E91300429}" (HKLM) -- C:\Program Files\DVD Region+CSS Free\DVDShell.dll (Fengtao Software Inc.)
[color=orange]========== Safeboot Options ==========
/color
"AlternateShell"=cmd.exe
[color=orange]========== CDRom AutoRun Settings ==========
/color
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
[color=orange]========== Autorun Files on Drives ==========
/color
AUTOEXEC.BAT []
[2007/06/16 15:02:34 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
[color=orange]========== Files/Folders - Created Within 30 Days ==========
/color
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/03/30 19:28:31 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Bureau\OTViewIt.exe
[2009/03/30 15:49:35 | 24,768,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/03/29 19:45:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Kaspersky Lab
[2009/03/25 07:32:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2009/03/25 07:07:51 | 00,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/03/25 07:07:51 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/03/25 07:07:50 | 00,459,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/03/25 07:07:50 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/03/25 07:07:49 | 02,455,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2009/03/25 07:07:49 | 01,048,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/03/25 07:07:48 | 00,383,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/03/25 07:07:47 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icardie.dll
[2009/03/25 07:07:46 | 06,066,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/03/25 06:35:58 | 02,182,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2009/03/25 06:35:58 | 02,138,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2009/03/25 06:35:57 | 02,059,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2009/03/25 06:35:56 | 02,017,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2009/03/24 20:07:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie7updates
[2009/03/24 16:50:40 | 00,453,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2009/03/24 13:38:19 | 00,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2009/03/24 13:38:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2009/03/24 10:08:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\WMTools Downloaded Files
[2009/03/24 09:33:59 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/03/24 07:51:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2009/03/23 13:00:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/03/23 12:16:03 | 00,000,216 | ---- | C] () -- C:\Boot.bak
[2009/03/23 12:16:00 | 00,263,488 | ---- | C] () -- C:\cmldr
[2009/03/23 12:15:59 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/03/23 12:11:41 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/03/23 12:11:41 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/03/23 12:11:41 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/03/23 12:11:41 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/03/23 12:11:41 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/03/23 12:11:41 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/03/23 12:11:41 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/03/23 12:11:41 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/03/23 12:11:41 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/03/23 12:09:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/03/23 12:09:49 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/03/22 10:38:37 | 00,000,123 | ---- | C] () -- C:\WINDOWS\tmpcpyis.bat
[2009/03/22 10:38:37 | 00,000,122 | ---- | C] () -- C:\WINDOWS\tmpdelis.bat
[2009/03/22 10:38:37 | 00,000,026 | ---- | C] () -- C:\WINDOWS\winstart.bat
[2009/03/22 10:37:45 | 01,053,184 | ---- | C] (Cendant Software) -- C:\WINDOWS\System32\SierraNW.dll
[2009/03/22 10:37:45 | 00,490,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Oleaut32.1
[2009/03/22 10:37:44 | 00,231,936 | ---- | C] (Cendant Software) -- C:\WINDOWS\System32\SNWValid.dll
[2009/03/22 10:37:44 | 00,000,000 | ---D | C] -- C:\WINDOWS\solcache
[2009/03/22 10:36:04 | 00,000,326 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/03/22 10:35:17 | 00,001,202 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/03/21 14:41:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2009/03/21 08:39:36 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2009/03/20 18:51:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/03/20 18:51:33 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/03/20 18:51:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
[2009/03/18 18:27:14 | 00,045,376 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2009/03/18 18:27:14 | 00,022,336 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/03/18 18:27:14 | 00,021,248 | ---- | C] (AVIRA GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/03/18 18:27:13 | 00,075,072 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2009/03/18 18:27:12 | 00,000,000 | ---D | C] -- C:\Program Files\Avira
[2009/03/18 18:27:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2009/03/18 17:49:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Mes documents\ccleaner
[2009/03/18 17:41:01 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/03/17 13:10:11 | 00,031,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbccgp.sys
[2009/03/13 18:49:42 | 00,000,579 | ---- | C] () -- C:\Documents and Settings\user\Mes documents\Mes dossiers de partage.lnk
[2009/03/13 17:18:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Cool Record Edit Pro
[2009/03/13 17:15:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Free Sound Recorder
[2009/03/13 17:15:15 | 00,602,112 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioTransform2.dll
[2009/03/13 17:15:15 | 00,479,232 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioVisualization2.dll
[2009/03/13 17:15:15 | 00,417,792 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTTextToAudio2.dll
[2009/03/13 17:15:15 | 00,348,160 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTWMAFile2.dll
[2009/03/13 17:15:15 | 00,113,486 | ---- | C] () -- C:\WINDOWS\System32\NCTWMAProfiles.prx
[2009/03/13 17:15:14 | 01,986,560 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioFile2.dll
[2009/03/13 17:15:14 | 01,212,416 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioInformation2.dll
[2009/03/13 17:15:14 | 00,880,640 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioEditor2.dll
[2009/03/13 17:15:14 | 00,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioRecord2.dll
[2009/03/13 17:15:14 | 00,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioPlayer2.dll
[2009/03/13 17:15:13 | 00,835,584 | ---- | C] (NCT) -- C:\WINDOWS\System32\NCTAudioCDGrabber2.dll
[2009/03/13 17:15:12 | 00,000,000 | ---D | C] -- C:\Program Files\Free Sound Recorder
[2009/03/11 18:50:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Macromedia
[2009/03/11 17:57:38 | 00,000,000 | ---D | C] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2009/03/10 21:31:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Mes documents\Mes fichiers reçus
[2009/03/10 11:11:22 | 00,003,968 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\AvgArCln.sys
[2009/03/09 18:41:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Malwarebytes
[2009/03/09 18:41:30 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/09 18:41:28 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/09 18:41:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/09 18:41:25 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/09 08:39:05 | 00,000,000 | RHSD | C] -- C:\RESTORE
[2009/03/07 23:40:20 | 00,000,268 | -H-- | C] () -- C:\sqmdata05.sqm
[2009/03/07 23:40:20 | 00,000,244 | -H-- | C] () -- C:\sqmnoopt05.sqm
[2009/03/06 18:20:45 | 00,000,000 | R--D | C] -- C:\Documents and Settings\user\Mes documents\Mes images
[2009/03/05 21:05:41 | 00,000,010 | R--- | C] () -- C:\WINDOWS\PhotoprnLE.SN
[2009/03/01 19:12:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Mes documents\image
[color=orange]========== Files - Modified Within 30 Days ==========
/color
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/03/30 19:33:35 | 00,000,579 | ---- | M] () -- C:\Documents and Settings\user\Mes documents\Mes dossiers de partage.lnk
[2009/03/30 19:28:31 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Bureau\OTViewIt.exe
[2009/03/30 15:49:57 | 00,000,067 | ---- | M] () -- C:\WINDOWS\DVDRegionFree.INI
[2009/03/30 15:48:18 | 00,043,531 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/03/30 15:47:36 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/03/30 15:47:26 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/03/30 12:46:19 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/03/30 09:22:31 | 05,334,548 | -H-- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2009/03/26 18:08:16 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/03/26 18:08:00 | 00,263,824 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/25 20:29:04 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/03/24 10:11:19 | 00,156,672 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/23 12:58:49 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/03/23 12:16:03 | 00,000,286 | RHS- | M] () -- C:\boot.ini
[2009/03/23 10:40:12 | 00,068,856 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/22 10:38:37 | 00,001,202 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/03/22 10:38:37 | 00,000,123 | ---- | M] () -- C:\WINDOWS\tmpcpyis.bat
[2009/03/22 10:38:37 | 00,000,122 | ---- | M] () -- C:\WINDOWS\tmpdelis.bat
[2009/03/22 10:38:37 | 00,000,026 | ---- | M] () -- C:\WINDOWS\winstart.bat
[2009/03/22 10:37:58 | 00,000,326 | ---- | M] () -- C:\WINDOWS\SIERRA.INI
[2009/03/21 14:43:06 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/03/17 20:12:31 | 00,003,072 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/03/17 19:48:47 | 00,999,660 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/17 19:48:47 | 00,460,986 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2009/03/17 19:48:47 | 00,395,200 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/17 19:48:47 | 00,072,126 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2009/03/17 19:48:47 | 00,059,440 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/03/07 23:40:20 | 00,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2009/03/07 23:40:20 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009/03/05 21:05:41 | 00,000,010 | R--- | M] () -- C:\WINDOWS\PhotoprnLE.SN
[2009/03/05 21:05:33 | 00,000,183 | ---- | M] () -- C:\WINDOWS\photoprn.ini
[2009/03/01 00:20:00 | 00,022,328 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/01 00:19:53 | 00,107,832 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe
< End of report >