Logfile of random's system information tool 1.06 (written by random/random)
Run by Laurent at 2009-10-31 06:48:34
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 8 GB (19%) free of 45 GB
Total RAM: 1023 MB (36% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:49:10, on 31/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
G:\Program Files\AVG9\avgchsvx.exe
G:\Program Files\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
G:\Program Files\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\RunDLL32.exe
G:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\taskmgr.exe
G:\PROGRA~1\AVG9\avgtray.exe
G:\Program Files\Daemon Tools Lite\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
G:\Program Files\AVG9\avgwdsvc.exe
G:\Program Files\FileZilla Server\FileZilla Server.exe
G:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
G:\Program Files\AVG9\avgemc.exe
G:\Program Files\AVG9\avgnsx.exe
G:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
G:\Program Files\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
G:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Laurent\Bureau\RSIT.exe
G:\Program Files\HijackThis\Laurent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://fr.search.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://fr.search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://fr.search.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://fr.search.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - G:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - G:\Program Files\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - G:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UnlockerAssistant] "G:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [SDUpdate] G:\Program Files\Spybot - Search & Destroy\SDUpdate.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] G:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [taskmgr] C:\WINDOWS\system32\taskmgr.exe
O4 - HKLM\..\Run: [spywareblaster] G:\Program Files\SpywareBlaster\spywareblaster.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG9_TRAY] G:\PROGRA~1\AVG9\avgtray.exe
O4 - HKLM\..\Run: [avgupd.exe] G:\Program Files\AVG9\avgupd.exe
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [DAEMON Tools Lite] "G:\Program Files\Daemon Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "G:\Program Files\µTorrent\µtorrent 1.8.3.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [eMuleAutoStart] H:\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = G:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: &Download by Orbit - res://G:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://G:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://G:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://G:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr/
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - G:\Program Files\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - G:\Program Files\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - G:\Program Files\AVG9\avgwdsvc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - G:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: XIII Century Drivers Auto Removal (pr2aqvlb) (pr2aqvlb) - Cenega Publishing - C:\WINDOWS\system32\pr2aqvlb.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
End of file - 8535 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GlaryInitialize.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{988C1DB6-5C9D-45B4-A2E5-D10D11174F88}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - G:\Program Files\Orbitdownloader\orbitcth.dll [2009-10-14 179472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - G:\Program Files\AVG9\avgssie.dll [2009-10-30 1471768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - G:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-09-05 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
Locked
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - G:\Program Files\Orbitdownloader\GrabPro.dll [2009-10-14 662720]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-12-10 7311360]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit []
"UnlockerAssistant"=G:\Program Files\Unlocker\UnlockerAssistant.exe [2008-05-02 15872]
"SDUpdate"=G:\Program Files\Spybot - Search & Destroy\SDUpdate.exe [2009-01-26 1740632]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-02-25 221184]
"LogitechVideoRepair"=G:\Program Files\Logitech\Video\ISStart.exe [2004-02-25 454656]
"NVMixerTray"=C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe [2004-12-20 131072]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2008-04-13 208952]
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE [2001-08-28 44032]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2008-04-13 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-13 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-13 455168]
"taskmgr"=C:\WINDOWS\system32\taskmgr.exe [2008-04-13 143360]
"spywareblaster"=G:\Program Files\SpywareBlaster\spywareblaster.exe [2009-04-09 1340944]
"nwiz"=nwiz.exe /install []
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"AVG9_TRAY"=G:\PROGRA~1\AVG9\avgtray.exe [2009-10-30 2010904]
"avgupd.exe"=G:\Program Files\AVG9\avgupd.exe [2009-10-30 877848]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"=C:\WINDOWS\system32\sti_ci.dll [2008-04-13 138240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=G:\Program Files\Daemon Tools Lite\daemon.exe [2009-04-23 691656]
"uTorrent"=G:\Program Files\µTorrent\µtorrent 1.8.3.exe [2009-10-10 289072]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"eMuleAutoStart"=H:\eMule\emule.exe [2009-02-22 5668864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
G:\Program Files\Easy CD Creator 5\DirectCD\DirectCD.exe [2002-04-10 679936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
G:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
G:\Program Files\CloneCD\CloneCDTray.exe [2009-01-29 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskInfo]
G:\Program Files\CrystalDiskInfo\DiskInfo.exe [2008-12-28 897024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileZilla Server Interface]
G:\Program Files\FileZilla Server\FileZilla Server Interface.exe [2007-10-28 942080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HD Tune]
G:\PROGRA~1\HDTUNE~1\HDTune.exe [2008-02-09 401408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
G:\Program Files\Logitech\Video\LogiTray.exe [2004-02-25 212992]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
G:\Program Files\MessengerPlus! 3\MsgPlus.exe [2009-04-19 190024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-10-23 3885408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
G:\Program Files\QuickTime\QTTask.exe -atboottime []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
C:\PROGRA~1\FICHIE~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2002-06-09 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
G:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE [2004-01-27 184320]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Laurent^Menu Démarrer^Programmes^Démarrage^Démarrage d'Office.lnk]
G:\PROGRA~1\MICROS~3\Office\OSA.EXE [1997-01-27 51984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Laurent^Menu Démarrer^Programmes^Démarrage^Microsoft Recherche accélérée.lnk]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Laurent^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
G:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-08-18 384000]
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage
Acrobat Assistant.lnk - G:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-10-30 12464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"=G:\Program Files\DVD Region-Free\DVDShell.dll [2004-03-07 49152]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=91000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:7\Program Files\AVG8\avgemc.exe"="C:7\Program Files\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:7\Program Files\AVG8\avgupd.exe"="C:7\Program Files\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:7\Program Files\AVG8\avgnsx.exe"="C:7\Program Files\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"G:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="G:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"G:\Program Files\Windows Live\Messenger\msnmsgr.exe"="G:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"I:\Age of Empires II\age2_x1\age2_x1.exe"="I:\Age of Empires II\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"I:\Age of Empires II\empires2.exe"="I:\Age of Empires II\empires2.exe:*:Enabled:Age of Empires II"
"I:\Knights Of The Temple\Templar.exe"="I:\Knights Of The Temple\Templar.exe:*:Enabled:Templar"
"I:\Zetrix\zetrix.exe"="I:\Zetrix\zetrix.exe:*:Enabled:zetrix"
"C:\Jeux\Stronghold 2\Stronghold2NOCD.exe"="C:\Jeux\Stronghold 2\Stronghold2NOCD.exe:*:Enabled:Stronghold 2"
"I:\Age of Empires II Trial\EMPIRES2.EXE"="I:\Age of Empires II Trial\EMPIRES2.EXE:*:Enabled:Age of Empires II"
"G:\Program Files\uTorrent\uTorrent.exe"="G:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"G:\Program Files\µTorrent\uTorrent.exe"="G:\Program Files\µTorrent\uTorrent.exe:*:Enabled:µTorrent"
"H:\eMule\emule.exe"="H:\eMule\emule.exe:*:Enabled:eMule"
"G:\Program Files\Mozilla Firefox\firefox.exe"="G:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"I:\MotoGP2\motogp2.exe"="I:\MotoGP2\motogp2.exe:*:Enabled:motogp2"
"G:\Program Files\VLC\vlc.exe"="G:\Program Files\VLC\vlc.exe:*:Enabled:VLC media player"
"G:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe"="G:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe:*:Enabled:Media Player Classic"
"G:\Program Files\FileZilla\filezilla.exe"="G:\Program Files\FileZilla\filezilla.exe:*:Enabled:FileZilla FTP Client"
"D:\Jeux\Anno 1404 (demo)\Anno4.exe"="D:\Jeux\Anno 1404 (demo)\Anno4.exe:*:Enabled:ANNO 1404 (Demo)"
"D:\Jeux\Anno 1404 (demo)\tools\Benchmark.exe"="D:\Jeux\Anno 1404 (demo)\tools\Benchmark.exe:*:Enabled:ANNO 1404 (Demo) Setup Benchmark"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"L:\Jeux\Medieval - Total War\Medieval_TW.exe"="L:\Jeux\Medieval - Total War\Medieval_TW.exe:*:Enabled:Medieval_TW"
"G:\Program Files\µTorrent\µtorrent 1.8.3.exe"="G:\Program Files\µTorrent\µtorrent 1.8.3.exe:*:Enabled:µTorrent"
"I:\Paris 1313\Paris1313.exe"="I:\Paris 1313\Paris1313.exe:*:Enabled:Paris 1313"
"L:\Jeux\ParaWorld\bin\Paraworld.exe"="L:\Jeux\ParaWorld\bin\Paraworld.exe:*:Enabled:Paraworld Launcher"
"G:\Program Files\Java\jre6\bin\java.exe"="G:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary"
"L:\Jeux\XIII Century - Death or Glory\engine.exe"="L:\Jeux\XIII Century - Death or Glory\engine.exe:*:Enabled:engine"
"L:\Jeux\XIII Century - Death or Glory\editor.exe"="L:\Jeux\XIII Century - Death or Glory\editor.exe:*:Enabled:editor"
"G:\Jeux\La Bataille pour la Terre du Milieu\game.dat"="G:\Jeux\La Bataille pour la Terre du Milieu\game.dat:*:Enabled:La Bataille pour la Terre du Milieu(tm)"
"L:\Jeux\Empire Earth\Empire Earth.exe"="L:\Jeux\Empire Earth\Empire Earth.exe:*:Enabled:Empire Earth"
"c:\program files\relevantknowledge\rlvknlg.exe"="c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe"
"G:\Program Files\Orbitdownloader\orbitdm.exe"="G:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"G:\Program Files\Orbitdownloader\orbitnet.exe"="G:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"G:\Program Files\AVG9\avgemc.exe"="G:\Program Files\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"G:\Program Files\AVG9\avgupd.exe"="G:\Program Files\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"G:\Program Files\AVG9\avgnsx.exe"="G:\Program Files\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{126abf2f-c586-11de-a108-000ea6cd5e34}]
shell\AutoRun\command - Y:\setup.exe
======File associations======
.cpl - cplopen -
======List of files/folders created in the last 1 months======
2009-10-31 06:48:33 ----D---- C:\rsit
2009-10-30 20:44:38 ----A---- C:\WINDOWS\unvise32qt.exe
2009-10-30 20:42:29 ----D---- C:\Program Files\Apple Software Update
2009-10-30 17:55:32 ----HD---- C:\$AVG
2009-10-30 17:55:21 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-10-30 17:54:57 ----D---- C:\Program Files\AVG
2009-10-24 12:14:36 ----D---- C:\Documents and Settings\Laurent\Application Data\Dynamique
2009-10-24 12:14:35 ----D---- C:\Documents and Settings\Laurent\Application Data\Sites
2009-10-24 12:14:35 ----D---- C:\Documents and Settings\Laurent\Application Data\Classes de site
2009-10-24 09:28:53 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
2009-10-23 17:02:00 ----D---- C:\Program Files\Patch MsnCreative
2009-10-18 11:34:48 ----D---- C:\Program Files\Microsoft SQL Server
2009-10-18 11:34:43 ----D---- C:\Program Files\Microsoft Synchronization Services
2009-10-18 11:34:43 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-10-18 11:31:54 ----D---- C:\Program Files\Microsoft.NET
2009-10-18 11:31:54 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2009-10-18 11:31:53 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-10-18 11:31:34 ----D---- C:\Program Files\Microsoft SDKs
2009-10-18 11:30:47 ----N---- C:\WINDOWS\system32\spmsg2.dll
2009-10-18 11:30:43 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2009-10-18 11:29:02 ----D---- C:\WINDOWS\system32\XPSViewer
2009-10-18 11:28:58 ----D---- C:\Program Files\MSBuild
2009-10-18 11:28:56 ----D---- C:\WINDOWS\system32\en-US
2009-10-18 11:28:50 ----D---- C:\Program Files\Reference Assemblies
2009-10-18 11:28:22 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-10-18 11:28:22 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-10-18 11:28:22 ----N---- C:\WINDOWS\system32\prntvpt.dll
======List of files/folders modified in the last 1 months======
2009-10-31 06:48:23 ----D---- C:\WINDOWS\Prefetch
2009-10-31 06:44:29 ----D---- C:\Documents and Settings\Laurent\Application Data\uTorrent
2009-10-31 06:39:29 ----D---- C:\WINDOWS\temp
2009-10-31 06:39:29 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-10-31 06:39:29 ----AD---- C:\WINDOWS
2009-10-31 06:38:47 ----D---- C:\WINDOWS\system32
2009-10-31 06:38:46 ----D---- C:\Program Files
2009-10-31 06:36:33 ----A---- C:\WINDOWS\NeroDigital.ini
2009-10-31 06:36:14 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2009-10-30 21:05:29 ----A---- C:\WINDOWS\win.ini
2009-10-30 21:05:29 ----A---- C:\WINDOWS\system.ini
2009-10-30 20:57:57 ----SHD---- C:\WINDOWS\Installer
2009-10-30 20:42:45 ----D---- C:\WINDOWS\WinSxS
2009-10-30 20:38:41 ----D---- C:\WINDOWS\system32\CatRoot2
2009-10-30 19:59:53 ----D---- C:\Documents and Settings\Laurent\Application Data\FileZilla
2009-10-30 19:14:01 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-10-30 18:25:05 ----D---- C:\Program Files\Wave Splitter
2009-10-30 18:06:09 ----D---- C:\WINDOWS\system32\drivers
2009-10-30 17:55:32 ----D---- C:\Documents and Settings
2009-10-30 17:51:19 ----SD---- C:\Documents and Settings\Laurent\Application Data\Microsoft
2009-10-25 16:57:07 ----A---- C:\Documents and Settings\Laurent\Application Data\AutoGK.ini
2009-10-25 15:05:01 ----D---- C:\Documents and Settings\Laurent\Application Data\Canon
2009-10-24 15:18:39 ----SH---- C:\boot.ini
2009-10-24 12:12:16 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-24 10:55:45 ----D---- C:\Jeux
2009-10-23 23:21:45 ----D---- C:\Documents and Settings\Laurent\Application Data\Orbit
2009-10-23 21:08:40 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-23 17:51:08 ----HD---- C:\WINDOWS\inf
2009-10-23 16:43:16 ----D---- C:\WINDOWS\SxsCaPendDel
2009-10-18 17:09:20 ----D---- C:\WINDOWS\system32\CatRoot
2009-10-18 17:09:15 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-10-18 16:55:09 ----RSD---- C:\WINDOWS\assembly
2009-10-18 14:48:40 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-10-18 11:34:46 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2009-10-18 11:30:35 ----D---- C:\WINDOWS\system32\fr-fr
2009-10-18 11:30:20 ----D---- C:\WINDOWS\system32\mui
2009-10-18 11:29:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-18 11:28:55 ----RSD---- C:\WINDOWS\Fonts
2009-10-18 11:28:34 ----D---- C:\WINDOWS\system32\spool
2009-10-17 06:26:41 ----D---- C:\WINDOWS\Debug
2009-10-16 20:38:42 ----D---- C:\Program Files\Internet Explorer
2009-10-16 20:38:35 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-11 07:39:14 ----A---- C:\WINDOWS\quark.ini
2009-10-02 19:01:57 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-13 41856]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-10-30 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-10-30 28424]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-10-30 360584]
R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-08-20 9072]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-08-20 9200]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-04-10 236032]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-07-06 79232]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2002-04-10 117898]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-04-10 206336]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\Drivers\vmm.sys []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-07-04 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-07-04 25888]
R2 litsgt;litsgt; C:\WINDOWS\system32\DRIVERS\litsgt.sys [2009-04-24 137344]
R2 tansgt;tansgt; C:\WINDOWS\system32\DRIVERS\tansgt.sys [2009-04-24 12032]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2002-04-10 24554]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-28 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-12-10 3536768]
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2005-04-13 53376]
R3 NVENET;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2004-01-29 93764]
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2005-04-13 414464]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S3 arphyr31;arphyr31; C:\WINDOWS\system32\drivers\arphyr31.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2002-04-10 29638]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2004-02-14 469696]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avg9emc;AVG Free E-mail Scanner; G:\Program Files\AVG9\avgemc.exe [2009-10-30 906520]
R2 avg9wd;AVG Free WatchDog; G:\Program Files\AVG9\avgwdsvc.exe [2009-10-30 285392]
R2 FileZilla Server;FileZilla Server FTP server; G:\Program Files\FileZilla Server\FileZilla Server.exe [2007-10-19 584192]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-09-05 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-12-10 131139]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 pr2aqvlb;XIII Century Drivers Auto Removal (pr2aqvlb); C:\WINDOWS\system32\pr2aqvlb.exe [2008-03-14 415096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Boonty Games;Boonty Games; C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2009-04-24 69120]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------