Logfile of random's system information tool 1.06 (written by random/random)
Run by Valérie at 2009-11-11 11:02:12
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 26 GB (18%) free of 145 GB
Total RAM: 1918 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:47, on 11/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Users\Valérie\AppData\Roaming\Agence Exclusive\Update\UpdateHP.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Agence Exclusive\Agence.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Valérie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NOMG3RPZ\RSIT[1].exe
C:\Program Files\trend micro\Valérie.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.duxet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AEBHO - {0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0} - C:\Program Files\Agence Exclusive\AgenceBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Agence] "C:\Program Files\Agence Exclusive\Agence.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [Helper] C:\Users\Valérie\AppData\Roaming\Agence Exclusive\Update\UpdateHP.exe -runonce
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\addfavorites.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: envoyer le texte sélectionné par sms - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\sendsmsselectedtext.html
O8 - Extra context menu item: envoyer par sms - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\sendsms.html
O8 - Extra context menu item: envoyer un mail - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\sendmail.html
O8 - Extra context menu item: orange.fr - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\orange.html
O8 - Extra context menu item: rechercher le texte sélectionné - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\selectedsearch.html
O8 - Extra context menu item: traduire la page - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\translate.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\Valérie\AppData\Roaming\Orange\MessengerByOrange\translateSelectedText.html
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
End of file - 7977 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\User_Feed_Synchronization-{C49C3BED-13A3-4671-8F75-2F87A65C924E}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0495F4D7-9FE3-4456-AA9D-1D57E78DF5F0}]
AEBHO Class - C:\Program Files\Agence Exclusive\AgenceBHO.dll [2009-09-22 225280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-11-18 333192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll [2008-11-11 62728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-14 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [2009-10-02 762864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-08-14 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-25 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-14 256112]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Foxit Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-11-18 333192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2009-07-21 208616]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-01-15 4874240]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Google Quick Search Box"=C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-08-14 122368]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"Agence"=C:\Program Files\Agence Exclusive\Agence.exe [2009-09-22 638976]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"=C:\Windows\SMINST\launcher.exe [2007-04-03 44168]
"Helper"=C:\Users\Valérie\AppData\Roaming\Agence Exclusive\Update\UpdateHP.exe [2009-07-01 491520]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2008-11-11 218376]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2009-11-10 11:21:25 ----SHDC---- C:\Config.Msi
2009-11-10 11:17:06 ----D---- C:\Program Files\Windows Live SkyDrive
2009-11-10 11:16:46 ----D---- C:\Program Files\Windows Live
2009-11-10 09:57:52 ----D---- C:\Program Files\Agence Exclusive
2009-11-10 09:57:48 ----D---- C:\Users\Valérie\AppData\Roaming\Agence Exclusive
2009-11-07 21:04:38 ----D---- C:\Users\Valérie\AppData\Roaming\Windows Live Writer
2009-11-06 23:29:16 ----D---- C:\Users\Valérie\AppData\Roaming\Orange
2009-11-06 22:36:05 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-11-06 22:36:05 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-11-06 22:36:05 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-11-06 22:36:04 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-11-06 22:36:04 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-11-06 22:36:04 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-11-06 22:36:04 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-11-06 22:36:02 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-11-06 22:36:02 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-11-06 22:36:02 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-11-06 22:36:02 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-11-06 22:36:02 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-11-06 22:36:01 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-11-06 22:36:01 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-11-06 22:36:01 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-11-06 22:36:00 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-11-06 22:36:00 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-11-06 22:36:00 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-11-06 22:35:59 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-11-06 22:35:59 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-11-06 22:35:59 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-11-06 22:35:57 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-11-06 22:35:57 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-11-06 22:35:57 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-11-06 22:35:57 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-11-06 22:35:57 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-11-06 22:35:56 ----A---- C:\Windows\system32\xinput1_3.dll
2009-11-06 22:35:56 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-11-06 22:35:56 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-11-06 22:35:56 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-11-06 22:35:55 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-11-06 22:35:54 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-11-06 22:35:54 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-11-06 22:35:54 ----A---- C:\Windows\system32\d3dx10.dll
2009-11-06 22:35:52 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-11-06 22:35:52 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-11-06 22:35:51 ----A---- C:\Windows\system32\xinput1_2.dll
2009-11-06 22:35:51 ----A---- C:\Windows\system32\xinput1_1.dll
2009-11-06 22:35:51 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-11-06 22:35:51 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-11-06 22:35:51 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-11-06 22:35:50 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-11-06 22:35:34 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-11-06 22:35:34 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-11-06 22:35:34 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-11-06 22:35:34 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-11-06 22:35:27 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-11-06 22:35:27 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-11-06 22:35:27 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-11-06 22:35:26 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-11-06 22:35:25 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-11-06 22:32:02 ----D---- C:\Program Files\SimTractor 4.1
2009-11-04 09:54:42 ----A---- C:\Windows\system32\wups2.dll
2009-11-04 09:54:42 ----A---- C:\Windows\system32\wucltux.dll
2009-11-04 09:54:42 ----A---- C:\Windows\system32\wuaueng.dll
2009-11-04 09:54:42 ----A---- C:\Windows\system32\wuauclt.exe
2009-11-04 09:54:22 ----A---- C:\Windows\system32\wups.dll
2009-11-04 09:54:22 ----A---- C:\Windows\system32\wudriver.dll
2009-11-04 09:54:22 ----A---- C:\Windows\system32\wuapi.dll
2009-11-04 09:54:16 ----A---- C:\Windows\system32\wuwebv.dll
2009-11-04 09:54:16 ----A---- C:\Windows\system32\wuapp.exe
2009-11-03 08:57:02 ----A---- C:\Windows\system32\mshtml.dll
2009-11-02 22:38:50 ----D---- C:\Program Files\Windows Portable Devices
2009-11-02 22:36:05 ----A---- C:\Windows\system32\UIAnimation.dll
2009-11-02 22:36:03 ----A---- C:\Windows\system32\UIRibbonRes.dll
2009-11-02 22:36:03 ----A---- C:\Windows\system32\UIRibbon.dll
2009-11-02 22:35:25 ----A---- C:\Windows\system32\WMPhoto.dll
2009-11-02 22:35:23 ----A---- C:\Windows\system32\cdd.dll
2009-11-02 22:35:21 ----A---- C:\Windows\system32\XpsRasterService.dll
2009-11-02 22:35:21 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2009-11-02 22:35:21 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-11-02 22:35:21 ----A---- C:\Windows\system32\d3d10warp.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\xpsservices.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\XpsPrint.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-11-02 22:35:20 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\OpcServices.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\FntCache.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\dxdiagn.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\dxdiag.exe
2009-11-02 22:35:20 ----A---- C:\Windows\system32\DWrite.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\d3d10level9.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\d3d10core.dll
2009-11-02 22:35:20 ----A---- C:\Windows\system32\d2d1.dll
2009-11-02 22:35:19 ----A---- C:\Windows\system32\dxgi.dll
2009-11-02 22:35:19 ----A---- C:\Windows\system32\d3d11.dll
2009-11-02 22:35:19 ----A---- C:\Windows\system32\d3d10_1core.dll
2009-11-02 22:35:19 ----A---- C:\Windows\system32\d3d10_1.dll
2009-11-02 22:35:19 ----A---- C:\Windows\system32\d3d10.dll
2009-11-02 22:34:40 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2009-11-02 22:34:40 ----A---- C:\Windows\system32\wpdbusenum.dll
2009-11-02 22:34:40 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2009-11-02 22:34:34 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2009-11-02 22:34:32 ----A---- C:\Windows\system32\WpdConns.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\WPDSp.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\wpdshext.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\WpdMtpUS.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\WpdMtp.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\wpd_ci.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-11-02 22:34:31 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-11-02 22:32:35 ----A---- C:\Windows\system32\oleaccrc.dll
2009-11-02 22:32:34 ----A---- C:\Windows\system32\UIAutomationCore.dll
2009-11-02 22:32:34 ----A---- C:\Windows\system32\oleacc.dll
2009-10-28 09:21:44 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-28 09:12:53 ----A---- C:\Windows\system32\wmp.dll
2009-10-28 09:12:50 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-28 09:12:48 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-27 21:53:04 ----A---- C:\Windows\zip.exe
2009-10-27 21:53:04 ----A---- C:\Windows\SWXCACLS.exe
2009-10-27 21:53:04 ----A---- C:\Windows\SWSC.exe
2009-10-27 21:53:04 ----A---- C:\Windows\SWREG.exe
2009-10-27 21:53:04 ----A---- C:\Windows\sed.exe
2009-10-27 21:53:04 ----A---- C:\Windows\PEV.exe
2009-10-27 21:53:04 ----A---- C:\Windows\NIRCMD.exe
2009-10-27 21:53:04 ----A---- C:\Windows\MBR.exe
2009-10-27 21:53:04 ----A---- C:\Windows\grep.exe
2009-10-27 21:52:31 ----D---- C:\Windows\ERDNT
2009-10-27 21:52:22 ----SDC---- C:\ComboFix
2009-10-27 21:51:18 ----DC---- C:\Qoobox
2009-10-14 08:59:46 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-14 08:58:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-14 08:58:52 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-14 08:48:55 ----A---- C:\Windows\system32\ieframe.dll
2009-10-14 08:48:49 ----A---- C:\Windows\system32\iertutil.dll
2009-10-14 08:48:48 ----A---- C:\Windows\system32\urlmon.dll
2009-10-14 08:48:47 ----A---- C:\Windows\system32\wininet.dll
2009-10-14 08:48:46 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-14 08:48:44 ----A---- C:\Windows\system32\occache.dll
2009-10-14 08:48:44 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-14 08:48:37 ----A---- C:\Windows\system32\ieui.dll
2009-10-14 08:48:35 ----A---- C:\Windows\system32\iepeers.dll
2009-10-14 08:48:34 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-14 08:48:33 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-10-14 08:48:33 ----A---- C:\Windows\system32\iesysprep.dll
2009-10-14 08:48:32 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-14 08:48:32 ----A---- C:\Windows\system32\ie4uinit.exe
2009-10-14 08:48:31 ----A---- C:\Windows\system32\msfeedssync.exe
2009-10-14 08:48:31 ----A---- C:\Windows\system32\iesetup.dll
2009-10-14 08:48:31 ----A---- C:\Windows\system32\iernonce.dll
2009-10-14 08:46:23 ----A---- C:\Windows\system32\msasn1.dll
2009-10-14 08:42:32 ----A---- C:\Windows\system32\WMSPDMOD.DLL
======List of files/folders modified in the last 1 months======
2009-11-11 11:02:35 ----D---- C:\Windows\Prefetch
2009-11-11 11:02:28 ----D---- C:\Program Files\Trend Micro
2009-11-11 11:02:26 ----D---- C:\Windows\Temp
2009-11-11 10:32:11 ----D---- C:\Windows\Tasks
2009-11-11 09:48:29 ----D---- C:\Windows\system32\catroot
2009-11-11 09:48:27 ----D---- C:\Windows\winsxs
2009-11-11 09:48:15 ----D---- C:\Windows\system32\catroot2
2009-11-11 09:42:14 ----D---- C:\ProgramData\Kaspersky Lab
2009-11-11 09:41:49 ----D---- C:\Windows\SMINST
2009-11-10 11:21:50 ----SHD---- C:\Windows\Installer
2009-11-10 11:21:46 ----D---- C:\Windows\System32
2009-11-10 11:17:23 ----D---- C:\Program Files\Microsoft
2009-11-10 11:17:11 ----D---- C:\Program Files\Common Files\microsoft shared
2009-11-10 11:17:06 ----RD---- C:\Program Files
2009-11-10 11:15:45 ----D---- C:\Windows\Debug
2009-11-10 11:15:45 ----D---- C:\Windows
2009-11-10 10:57:37 ----D---- C:\Windows\system32\wbem
2009-11-10 10:56:45 ----SHDC---- C:\Program Files\Common Files\WindowsLiveInstaller
2009-11-10 10:56:45 ----D---- C:\Windows\system32\Tasks
2009-11-10 10:56:44 ----D---- C:\Windows\system32\spool
2009-11-10 10:56:44 ----D---- C:\Windows\system32\fr-FR
2009-11-10 10:56:44 ----D---- C:\Windows\system32\CodeIntegrity
2009-11-10 10:56:44 ----D---- C:\Windows\rescache
2009-11-10 10:56:44 ----D---- C:\Windows\inf
2009-11-10 10:56:44 ----D---- C:\Users\Valérie\AppData\Roaming\XnView
2009-11-10 10:56:43 ----D---- C:\Windows\registration
2009-11-10 10:50:53 ----SHD---- C:\System Volume Information
2009-11-10 10:07:17 ----D---- C:\Program Files\Mozilla Firefox
2009-11-10 09:58:23 ----D---- C:\Users\Valérie\AppData\Roaming\EoRezo
2009-11-07 21:13:19 ----SD---- C:\Users\Valérie\AppData\Roaming\Microsoft
2009-11-07 18:01:46 ----SD---- C:\Windows\Downloaded Program Files
2009-11-06 22:35:50 ----RSD---- C:\Windows\assembly
2009-11-06 22:35:43 ----D---- C:\Windows\Microsoft.NET
2009-11-06 22:33:25 ----D---- C:\Windows\Logs
2009-11-02 22:46:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-11-02 22:38:50 ----D---- C:\Windows\system32\drivers
2009-11-02 22:38:46 ----D---- C:\Windows\system32\zh-HK
2009-11-02 22:38:46 ----D---- C:\Windows\system32\uk-UA
2009-11-02 22:38:46 ----D---- C:\Windows\system32\sl-SI
2009-11-02 22:38:46 ----D---- C:\Windows\system32\pt-PT
2009-11-02 22:38:46 ----D---- C:\Windows\system32\pt-BR
2009-11-02 22:38:46 ----D---- C:\Windows\system32\pl-PL
2009-11-02 22:38:46 ----D---- C:\Windows\system32\nl-NL
2009-11-02 22:38:46 ----D---- C:\Windows\system32\ko-KR
2009-11-02 22:38:46 ----D---- C:\Windows\system32\it-IT
2009-11-02 22:38:46 ----D---- C:\Windows\system32\hu-HU
2009-11-02 22:38:46 ----D---- C:\Windows\system32\hr-HR
2009-11-02 22:38:46 ----D---- C:\Windows\system32\he-IL
2009-11-02 22:38:46 ----D---- C:\Windows\system32\el-GR
2009-11-02 22:38:46 ----D---- C:\Windows\system32\bg-BG
2009-11-02 22:38:45 ----D---- C:\Windows\system32\zh-TW
2009-11-02 22:38:45 ----D---- C:\Windows\system32\zh-CN
2009-11-02 22:38:45 ----D---- C:\Windows\system32\tr-TR
2009-11-02 22:38:45 ----D---- C:\Windows\system32\th-TH
2009-11-02 22:38:45 ----D---- C:\Windows\system32\sv-SE
2009-11-02 22:38:45 ----D---- C:\Windows\system32\sr-Latn-CS
2009-11-02 22:38:45 ----D---- C:\Windows\system32\sk-SK
2009-11-02 22:38:45 ----D---- C:\Windows\system32\ro-RO
2009-11-02 22:38:45 ----D---- C:\Windows\system32\lv-LV
2009-11-02 22:38:45 ----D---- C:\Windows\system32\lt-LT
2009-11-02 22:38:45 ----D---- C:\Windows\system32\ja-JP
2009-11-02 22:38:45 ----D---- C:\Windows\system32\fi-FI
2009-11-02 22:38:45 ----D---- C:\Windows\system32\et-EE
2009-11-02 22:38:45 ----D---- C:\Windows\system32\es-ES
2009-11-02 22:38:45 ----D---- C:\Windows\system32\de-DE
2009-11-02 22:38:45 ----D---- C:\Windows\system32\cs-CZ
2009-11-02 22:38:45 ----D---- C:\Windows\system32\ar-SA
2009-11-02 22:38:44 ----D---- C:\Windows\system32\ru-RU
2009-11-02 22:38:44 ----D---- C:\Windows\system32\nb-NO
2009-11-02 22:38:44 ----D---- C:\Windows\system32\en-US
2009-11-02 22:38:44 ----D---- C:\Windows\system32\da-DK
2009-11-02 20:42:06 ----N---- C:\Windows\system32\MpSigStub.exe
2009-10-29 08:31:26 ----D---- C:\Program Files\Internet Explorer
2009-10-29 08:31:25 ----D---- C:\Program Files\Windows Media Player
2009-10-28 13:55:39 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-10-28 13:54:26 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-10-28 10:32:58 ----D---- C:\Program Files\GamesBar
2009-10-14 22:03:53 ----D---- C:\ProgramData\Microsoft Help
2009-10-14 11:28:56 ----D---- C:\Windows\ehome
2009-10-14 11:28:56 ----D---- C:\Program Files\Windows Mail
2009-10-14 11:28:55 ----D---- C:\Windows\system32\migration
2009-10-14 09:41:02 ----D---- C:\Program Files\Microsoft Works
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2008-07-21 121872]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2009-02-05 239120]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2008-07-09 20496]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-01-15 2047576]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-05-03 1065384]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-05-22 7465312]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 catchme;catchme; \??\C:\Users\VALRIE~1\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVP;Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2009-07-21 208616]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-05-24 61440]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-05-22 118784]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-08 190448]
S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe []
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 IDriverT;InstallDriver Table Manager; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB9;RoxMediaDB9; c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-05-11 887544]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-05-03 74656]
-----------------EOF-----------------