Je ne sais pas si quelque chose va apparaître. Je l'avais détruit mais l'ai récupéré par S.V.info_restore et n'ai pas vraiment envie de le remettre en place :-)
Voilà ce qu'il en dit:
Nom de fichier original: A0085744.exe
Dossier d'origine donc Restore
Description du virus Win32:VB-IUC
_________________________________________
Hijack main tx:
Deckard's System Scanner v20071014.68
Run by William on 2008-06-09 09:18:00
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
16: 2008-06-09 07:18:05 UTC - RP218 - Deckard's System Scanner Restore Point
15: 2008-06-09 06:52:08 UTC - RP217 - Opération de restauration
14: 2008-06-09 06:48:07 UTC - RP216 - Mettre à jour vers un pilote non signé
13: 2008-06-09 06:23:29 UTC - RP215 - Lundi9
12: 2008-06-08 12:03:12 UTC - RP214 - Made by Registry Mechanic O
-- First Restore Point --
1: 2008-06-06 14:57:47 UTC - RP203 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as William.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:21:03, on 09/06/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\William\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\William.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (disabled by BHODemon)
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - Startup: ClocX.lnk = C:\Program Files\ClocX\ClocX.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection_2_0_4_12.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NoiseCtl - Fujitsu Siemens Computers - C:\Program Files\Fujitsu Siemens\Xontrol\NoiseCtl.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/William/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
End of file - 7182 bytes
-- File Associations -----------------------------------------------------------
[COLOR=red].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[COLOR=red].cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
[COLOR=red].txt - txtfile - DefaultIcon - C:\Program Files\EditPad.exe,0
[COLOR=red].txt - txtfile - shell\open\command - C:\Program Files\EditPad.exe "%1"
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 DigiFilter - c:\windows\system32\drivers\digifilt.sys <Not Verified; Digidesign, A Division of Avid Technology, Inc.; Pro Tools®>
R0 TPkd - c:\windows\system32\drivers\tpkd.sys <Not Verified; PACE Anti-Piracy, Inc.; InterLok(R)>
R1 Asapi - c:\windows\system32\drivers\asapi.sys <Not Verified; VOB Computersysteme GmbH; asapi>
R1 FileDisk - c:\windows\system32\drivers\filedisk.sys <Not Verified; Bo Brantén; filedisk>
R1 NetworkX - c:\windows\system32\ckldrv.sys
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
R3 USBMM4X4 (Midiman USB MidiSport 4x4 Midi Driver) - c:\windows\system32\drivers\usbmm4x4.sys <Not Verified; Doug Fetter Software Wizardry; Midiman USB MidiSport 4x4 Midi Interface>
S2 BCMNTIO - c:\progra~1\norton~1\diagno~1\bcmntio.sys (file missing)
S2 MAPMEM - c:\progra~1\norton~1\diagno~1\mapmem.sys (file missing)
S3 DELTA (Service for Delta Driver (WDM)) - c:\windows\system32\drivers\delta.sys (file missing)
S3 ma763008 (M-Audio Ozone) - c:\windows\system32\drivers\ma763008.sys (file missing)
S3 MADFU008 - c:\windows\system32\drivers\madfu008.sys (file missing)
S3 PCIUtil (PCI Utility) - c:\docume~1\william\locals~1\temp\pciutil.sys (file missing)
S3 SymIMMP - c:\windows\system32\drivers\symim.sys (file missing)
S3 tap0801 (TAP-Win32 Adapter V8) - c:\windows\system32\drivers\tap0801.sys <Not Verified; The OpenVPN Project; TAP-Win32 Virtual Network Driver>
S3 USB44LDR (Midiman USB MidiSport 4x4 Loader) - c:\windows\system32\drivers\usb44ldr.sys <Not Verified; MIDIMAN; Midiman USB MidiSport 4x4 Loader>
S3 USBNZ1X1 (M-Audio Ozone Midi) - c:\windows\system32\drivers\usbnz1x1.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Crypkey License - crypserv.exe <Not Verified; CrypKey (Canada) Ltd.; CrypKey Software Licensing System>
S3 LiveUpdate - "c:\program files\symantec\liveupdate\lucomserver_3_4.exe" (file missing)
S3 NoiseCtl - c:\program files\fujitsu siemens\xontrol\noisectl.exe <Not Verified; Fujitsu Siemens Computers; NoiseCtl utility and service>
S4 Automatic LiveUpdate Scheduler (Planificateur LiveUpdate automatique) - "c:\program files\symantec\liveupdate\aluschedulersvc.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-06-09 08:55:32 316 --a------ C:\WINDOWS\Tasks\GlaryInitialize.job
2008-06-08 13:32:53 110 --a------ C:\WINDOWS\Tasks\Low Battery Alarm Program.job
-- Files created between 2008-05-09 and 2008-06-09 -----------------------------
2008-06-09 09:20:53 0 d-------- C:\Program Files\Trend Micro
2008-06-08 12:37:51 4142592 --a------ C:\WINDOWS\system32\qtintf.dll <Not Verified; Borland Software Corporation; Delphi-Qt2.x Interface Library>
2008-06-08 12:37:48 0 d-------- C:\Program Files\APC
2008-06-08 10:02:52 0 d-------- C:\Documents and Settings\William\AppVerifierLogs
2008-06-08 09:59:56 0 d-------- C:\Documents and Settings\William\Application Data\Microsoft Corporation
2008-06-08 01:49:17 0 dr-h----- C:\Documents and Settings\William\Recent
2008-06-07 16:45:56 53248 --a------ C:\WINDOWS\system32\CSVer.dll <Not Verified; Windows XP Bundled build C-Centric Single User; Windows XP Bundled build C-Centric Single User CSVer>
2008-06-04 19:08:58 164352 --a------ C:\WINDOWS\system32\unrar.dll
2008-06-04 19:08:56 217088 --a------ C:\WINDOWS\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2008-06-04 19:08:56 159839 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-06-04 19:08:56 755027 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-06-04 19:08:55 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-04 19:08:55 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-06-04 19:08:55 682496 --a------ C:\WINDOWS\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2008-06-04 19:08:54 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-04 19:08:53 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-06-04 16:26:04 0 d-------- C:\Program Files\Xilisoft
2008-06-03 16:48:14 11910 --a------ C:\WINDOWS\system32\GENMIDI.DLL
2008-06-03 16:48:14 851968 --a------ C:\b4
2008-06-03 16:45:19 0 d-------- C:\Program Files\BBE
2008-06-03 16:27:47 0 d-------- C:\Program Files\VB
2008-06-03 16:25:37 0 d-------- C:\Program Files\timeworks
2008-06-03 16:23:25 0 d-------- C:\Program Files\TCWorks
2008-06-03 16:23:09 0 d-------- C:\Program Files\audio
2008-06-03 16:21:23 28160 --a------ C:\WINDOWS\system32\Rdcdnt.dll <Not Verified; TC Works GmbH; TC Works GmbH RDCDNT>
2008-06-03 16:21:23 28160 --a------ C:\WINDOWS\system32\Rdcd32.dll <Not Verified; TC Works GmbH; TC Works GmbH RDCD32>
2008-06-03 16:21:23 3824 --a------ C:\WINDOWS\system32\Rdcd16.dll <Not Verified; TC Works GmbH; TC Works GmbH RDCD16>
2008-06-03 16:18:55 0 d-------- C:\Program Files\Antares Audio Technologies
2008-06-03 16:09:59 101376 --a------ C:\WINDOWS\system32\synsoacc.dll <Not Verified; 007; >
2008-06-03 16:09:48 61952 --a------ C:\WINDOWS\system32\Decdnet.dll <Not Verified; RealNetworks, Inc.; RealAudio(tm) Shared Component (32-bit)>
2008-06-03 16:09:33 0 d-------- C:\Program Files\Steinberg
2008-06-01 13:06:24 204288 --a------ C:\WINDOWS\system32\M-AudioTaskBarIcon.exe <Not Verified; Avid Technology, Inc.; TaskBarIconApplet>
2008-06-01 13:06:21 82944 --a------ C:\WINDOWS\system32\USBMN1X1.DLL <Not Verified; M-Audio; M-Audio USB Midi 1x1 Midi Interface>
2008-06-01 13:06:21 22208 --a------ C:\WINDOWS\system32\drivers\USBMN1X1.SYS <Not Verified; M-Audio; M-Audio USB Midi 1x1 Midi Interface>
2008-05-28 13:30:25 0 d-------- C:\WINDOWS\l2schemas
2008-05-28 13:30:24 0 d-------- C:\WINDOWS\system32\fr
2008-05-28 13:30:24 0 d-------- C:\WINDOWS\system32\bits
2008-05-28 13:28:24 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-26 09:27:07 280 --a------ C:\WINDOWS\system32\PDBootState
2008-05-22 16:24:27 0 d-------- C:\Program Files\Sony Setup
2008-05-22 16:08:25 0 d-------- C:\Documents and Settings\William\Application Data\gtk-2.0
2008-05-22 16:08:14 0 d-------- C:\Documents and Settings\William\.thumbnails
2008-05-22 16:07:01 0 d-------- C:\Documents and Settings\William\.gimp-2.4
2008-05-21 16:54:23 13 -r-hs---- C:\WINDOWS\system32\Mediav_6_4.dll
2008-05-21 15:33:52 0 d-------- C:\Documents and Settings\William\Application Data\dvdcss
2008-05-21 15:31:19 0 d-------- C:\Program Files\WinXMedia
2008-05-21 15:26:59 0 d-------- C:\Documents and Settings\William\Application Data\DivX
2008-05-21 15:24:09 0 d-------- C:\Program Files\DivX
2008-05-20 14:23:22 45056 --a------ C:\WINDOWS\system32\wnaspi32.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-05-20 14:23:22 16512 --a------ C:\WINDOWS\system32\drivers\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-05-20 14:23:22 4672 --a------ C:\WINDOWS\system\wowpost.exe <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-05-20 14:23:22 5600 --a------ C:\WINDOWS\system\winaspi.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-05-20 14:17:45 0 d-------- C:\Program Files\Maxtor
2008-05-20 13:41:09 4 --a------ C:\WINDOWS\vx86036.dat
2008-05-20 13:40:58 69632 --a------ C:\WINDOWS\system32\Crypserv.exe <Not Verified; CrypKey (Canada) Ltd.; CrypKey Software Licensing System>
2008-05-20 13:40:58 31846 --a------ C:\WINDOWS\system32\Ckldrv.sys
2008-05-20 13:40:58 27648 -ra------ C:\WINDOWS\Setup_ck.exe
2008-05-20 13:40:58 18432 --a------ C:\WINDOWS\Setup_ck.dll
2008-05-20 13:40:58 11776 --a------ C:\WINDOWS\Ckrfresh.exe
2008-05-20 13:40:58 165888 --a------ C:\WINDOWS\Ckconfig.exe <Not Verified; Kenonic Controls; CKCONFIG Application>
2008-05-19 12:19:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-05-15 17:42:32 0 d-------- C:\Program Files\ma-config.com
2008-05-15 17:42:32 0 d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-05-09 18:34:28 0 d-------- C:\Documents and Settings\LocalService\Application Data\DivX
2008-05-09 18:05:33 0 d-------- C:\Documents and Settings\William\Application Data\NCH Software
2008-05-09 14:19:44 0 d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-05-09 14:19:43 0 d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-05-09 14:19:42 0 d-------- C:\Program Files\NCH Software
2008-05-09 14:19:15 0 d-------- C:\Program Files\NCH Swift Sound
2008-05-09 14:19:15 0 d-------- C:\Documents and Settings\William\Application Data\NCH Swift Sound
-- Find3M Report ---------------------------------------------------------------
2008-06-08 20:59:14 513910 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-06-08 20:59:14 85936 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-06-08 12:37:39 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-08 11:47:39 0 d-------- C:\Program Files\Fichiers communs
2008-06-07 18:54:57 0 d-------- C:\Documents and Settings\William\Application Data\Uniblue
2008-06-02 15:43:55 0 d-------- C:\Program Files\Tweak-XP Pro 4
2008-06-01 13:06:21 0 d-------- C:\Program Files\M-Audio
2008-06-01 08:39:08 724992 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2008-05-28 13:30:39 0 d-------- C:\Program Files\Messenger
2008-05-28 13:30:24 0 d-------- C:\Program Files\Movie Maker
2008-05-28 13:28:12 0 d-------- C:\Program Files\Windows NT
2008-05-23 02:03:29 1028 -----n--- C:\Documents and Settings\William\Application Data\AVIEncoder.wff
2008-05-20 14:47:47 0 d-------- C:\Documents and Settings\William\Application Data\Skype
2008-05-20 14:36:46 0 d-------- C:\Documents and Settings\William\Application Data\skypePM
2008-05-19 12:20:14 0 d-------- C:\Program Files\Avanquest update
2008-05-17 14:37:11 0 d-------- C:\Program Files\Raxco
2008-05-10 18:33:56 0 d-------- C:\Documents and Settings\William\Application Data\Macromedia
2008-05-10 15:11:34 0 d-------- C:\Documents and Settings\William\Application Data\Adobe
2008-05-10 15:11:16 1821 --a------ C:\WINDOWS\mozver.dat
2008-05-07 17:48:38 0 d-------- C:\Program Files\Motorola Phone Tools
2008-05-07 17:47:38 0 d-------- C:\Program Files\Common Files
2008-05-04 17:43:28 0 d-------- C:\Documents and Settings\William\Application Data\ItsLabel
2008-05-04 17:40:38 0 d-------- C:\Program Files\Alwil Software
2008-04-28 06:30:57 0 d-------- C:\Program Files\Glary Utilities
2008-04-25 05:28:27 0 d-------- C:\Documents and Settings\William\Application Data\GlarySoft
2008-04-25 04:39:35 69632 --a------ C:\WINDOWS\ALCMTR.EXE <Not Verified; Realtek Semiconductor Corp.; Realtek AC97 Audio - Event Monitor>
2008-04-21 23:20:28 0 d-------- C:\Documents and Settings\William\Application Data\123 Free Solitaire
2008-04-21 20:46:16 0 d-------- C:\Program Files\Encore 4.5.3
2008-04-21 16:40:56 10471 --a------ C:\Program Files\uninstal.log
2008-04-21 11:42:12 0 d-------- C:\Program Files\Fichiers communs\Motorola Shared
2008-04-20 17:52:10 0 d-------- C:\Program Files\Fichiers communs\LogiShrd
2008-04-20 17:27:06 0 d-------- C:\Program Files\Fichiers communs\Logitech
2008-04-20 01:41:08 0 d-------- C:\Program Files\InstantTimeZone
2008-04-19 23:11:03 0 d-------- C:\Program Files\ClocX
2008-04-18 19:43:30 0 d-------- C:\Program Files\Recuva
2008-04-18 15:25:52 0 d-------- C:\Program Files\PasseMemo
2008-04-16 19:41:21 0 d-------- C:\Program Files\Realtek
2008-04-14 18:09:09 0 d-------- C:\Program Files\3D Reversi Deluxe Demo
2008-04-14 17:51:53 0 d-------- C:\Program Files\500 Jeux de patience
2008-04-14 17:37:36 276 -rah----- C:\MSDOS.SYS
2008-04-09 17:26:52 0 d-------- C:\Program Files\Skype
2008-04-09 17:26:50 0 d-------- C:\Program Files\Fichiers communs\Skype
2008-04-09 13:37:30 0 d-------- C:\Program Files\MSXML 6.0
2008-04-09 02:34:03 0 d-------- C:\Program Files\MSBuild
2008-04-09 02:31:21 0 d-------- C:\Program Files\Reference Assemblies
2008-04-08 20:07:52 540672 --a------ C:\WINDOWS\system32\msvcp80.dll <Not Verified; Microsoft Corporation; Microsoft® Visual Studio® .NET>
2008-03-27 21:48:12 700 -----n--- C:\Documents and Settings\William\Application Data\.googlewebacchosts
2008-03-25 17:10:58 286720 --a------ C:\WINDOWS\iun507.exe <Not Verified; Indigo Rose Corporation; Setup Factory 5.0 Uninstaller>
2008-03-24 11:35:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2008-03-24 11:35:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-03-24 11:35:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-03-24 11:35:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-03-24 11:35:00 1482752 --a------ C:\WINDOWS\system32\nview.dll
2008-03-24 11:35:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2008-03-24 11:35:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2008-03-24 11:35:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
2008-03-23 13:16:30 23704 --a------ C:\WINDOWS\system32\emptyregdb.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [25/10/2007 17:33]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [16/05/2008 01:19]
C:\Documents and Settings\William\Menu D‚marrer\Programmes\D‚marrage\
ClocX.lnk - C:\Program Files\ClocX\ClocX.exe [26/07/2007 17:43:14]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe [08/06/2008 12:37:50]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearRecentDocsOnExit"=0 (0x0)
"NoViewOnDrive"=0 (0x0)
"ForceActiveDesktopOn"=0 (0x0)
"NoRecentDocsMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\wupdmgr.exe]
Debugger=ntsd
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= :\WINDOWS\system32\srrstr.dll scecli scecli scecli scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeltaIITaskbarApp]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
HDAShCut.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Sony Ericsson PC Suite"="D:\Programs\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"High Definition Audio Property Page Shortcut"=HDAShCut.exe
"RTHDCPL"=RTHDCPL.EXE
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Alcmtr"=ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
8713 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-09 09:23:11 ------------