--------- Logfile of AD-Remover 1.0.7.8 by C_XX ---------
# START at: 10:34:16 | Dim 21/12/2008 | Microsoft® Windows XP™ SP2 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: WINDOWS_XP | USER: Administrateur ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
# Internet Explorer v6.0.2900.2180
--------- [ RUNNING PROCESSES: 28 ] ---------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\AxBx\VirusKeeper 2008 Pro Evaluation\VirusKeeper.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Menara\dslmon.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\ntvdm.exe
-----------------------------------
+-----------------------| Boonty/Boonty Games Elements found :
"Boonty Games" (service)
.
"HKEY_CURRENT_USER\SOFTWARE\Boonty"
"HKEY_LOCAL_MACHINE\Software\Boonty"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Boonty Games"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_BOONTY_GAMES"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Boonty Games"
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Boonty Games"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Boonty Games"
.
[18/11/2008 20:47|d--------] C:\PROGRA~1\FICHIE~1\BOONTY~1
[18/11/2008 20:47|d--------] C:\PROGRA~1\FICHIE~1\BOONTY~1\Service
[18/11/2008 20:47|--a------] C:\PROGRA~1\FICHIE~1\BOONTY~1\Service\Boonty.exe
[25/11/2008 17:14|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\BOONTY
[25/11/2008 17:14|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\BOONTY\Licenses
[26/11/2008 17:07|-r-------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\BOONTY\Licenses\B360D000.dat
[29/11/2008 17:23|d--------] C:\DOCUME~1\ALLUSE~1.WIN\MENUDM~1\PROGRA~1\BOONTY~1
[25/11/2008 17:13|--a------] C:\DOCUME~1\ALLUSE~1.WIN\MENUDM~1\PROGRA~1\BOONTY~1\JEUXTL~2.LNK
[18/11/2008 20:46|--a------] C:\DOCUME~1\ALLUSE~1.WIN\MENUDM~1\PROGRA~1\BOONTY~1\JEUXTL~1.URL
[19/11/2008 13:18|--a------] C:\DOCUME~1\ALLUSE~1.WIN\MENUDM~1\PROGRA~1\BOONTY~1\JEUXTL~1.LNK
+-----------------------| Eorezo Elements found :
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
"HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run" /v "EoEngine"
.
[26/10/2008 19:55|d--------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo
[26/10/2008 19:18|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\cmhost.cyp
[26/10/2008 19:19|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\CONFME~1.CYP
[26/10/2008 19:18|d--------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\db
[26/10/2008 19:19|d--------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\EODESK~1
[26/10/2008 19:45|d--------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\eoStats
[26/10/2008 19:18|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\host.cyp
[26/10/2008 19:55|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\user.cyp
[26/10/2008 19:18|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\db\cat.cyp
[26/10/2008 19:19|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\EODESK~1\config.xml
[26/10/2008 19:19|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\EODESK~1\EODESK~1.HTM
[26/10/2008 19:19|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\EODESK~1\USERCO~1.XML
[26/10/2008 19:46|--a------] C:\DOCUME~1\ADMINI~1.WIN\APPLIC~1\EoRezo\eoStats\eoStats.txt
+-----------------------| Everest Poker Elements found :
.
+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :
"Mywebsearchservice" (service)
.
"HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss"
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MyWebSearchService"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MYWEBSEARCHSERVICE"
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MyWebSearchService"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_MYWEBSEARCHSERVICE"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7}"
.
[11/11/2008 12:46|--a------] C:\PROGRA~1\WINDOW~4\MESSEN~1\riched20.dll
[11/11/2008 12:46|--a------] C:\PROGRA~1\WINDOW~4\MESSEN~1\riched20.dll
[11/11/2008 12:46|--a------] C:\PROGRA~1\WINDOW~4\MESSEN~1\riched20.dll
[11/11/2008 12:46|--a------] C:\PROGRA~1\WINDOW~4\MESSEN~1\msimg32.dll
[11/11/2008 12:46|--a------] C:\PROGRA~1\WINDOW~4\MESSEN~1\msimg32.dll
[11/11/2008 12:46|--a------] C:\PROGRA~1\WINDOW~4\MESSEN~1\msimg32.dll
+-----------------------| It's TV Elements found :
.
+-----------------------| Sweetim Elements found :
"HKEY_CLASSES_ROOT\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}"
"HKEY_CLASSES_ROOT\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}"
"HKEY_CLASSES_ROOT\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}"
"HKEY_CLASSES_ROOT\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}"
"HKEY_CLASSES_ROOT\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
"HKEY_CLASSES_ROOT\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632"
"HKEY_CLASSES_ROOT\SWEETIE.IEToolbar"
"HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1"
"HKEY_CLASSES_ROOT\SWEETIE.SWEETIE"
"HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3"
"HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook"
"HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1"
"HKEY_CLASSES_ROOT\Toolbar3.SWEETIE"
"HKEY_CLASSES_ROOT\Toolbar3.SWEETIE.1"
"HKEY_CLASSES_ROOT\Typelib\{EEE6C35E-6118-11DC-9C72-001320C79847}"
"HKEY_CLASSES_ROOT\Typelib\{EEE6C35F-6118-11DC-9C72-001320C79847}"
"HKEY_CLASSES_ROOT\MgMediaPlayer.GifAnimator"
"HKEY_CLASSES_ROOT\MgMediaPlayer.GifAnimator.1"
"HKEY_CURRENT_USER\SOFTWARE\SweetIM"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0337C6624F0C5E94F8025AF6F9288257"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D91C9455EF645794DA45B5738EF76F2E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{EEE6C35B-6118-11DC-9C72-001320C79847}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run" /v "SweetIM"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{266C7330-C0F4-49E5-8F20-A56F9F822875}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5549C19D-46FE-4975-AD54-5B37E87FF6E2}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0337C6624F0C5E94F8025AF6F9288257"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D91C9455EF645794DA45B5738EF76F2E"
"HKEY_LOCAL_MACHINE\SOFTWARE\SweetIM"
.
[18/12/2008 21:40|d--------] C:\PROGRA~1\SweetIM
[22/11/2008 21:24|d--------] C:\PROGRA~1\SweetIM\MESSEN~1
[08/10/2008 11:56|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\default.xml
[08/10/2008 12:11|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGADAP~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGAIMA~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGAIMM~1.DLL
[08/10/2008 12:11|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGARCH~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\mgcommon.dll
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGCOMM~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\mgconfig.dll
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGFLAS~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGHOOK~1.DLL
[08/10/2008 12:12|--a------] C:\PROGRA~1\SweetIM\MESSEN~1\MGICQA~1.DLL
[08/10/2008 12:12|--a------] C:\PROGRA~1\SweetIM\MESSEN~1\MGICQM~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGIEPL~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\mglogger.dll
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGMEDI~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGMSNA~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGMSNM~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGSIMC~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGSWEE~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGUPDA~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGXML_~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGYAHO~1.DLL
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\MGYAHO~2.DLL
[11/07/2006 18:35|--a------] C:\PROGRA~1\SweetIM\MESSEN~1\msvcp71.dll
[11/07/2006 18:35|--a------] C:\PROGRA~1\SweetIM\MESSEN~1\msvcr71.dll
[22/11/2008 21:24|d--------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1
[08/10/2008 12:12|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\SweetIM.exe
[22/11/2008 21:24|d--------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1\images
[08/10/2008 11:56|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1\images\AUDIBL~1.PNG
[08/10/2008 11:56|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1\images\DISPLA~1.PNG
[08/10/2008 11:56|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1\images\EMOTIC~1.PNG
[08/10/2008 11:56|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1\images\NUDGEB~1.PNG
[08/10/2008 11:56|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1\images\SOUNDF~1.PNG
[08/10/2008 11:56|-ra------] C:\PROGRA~1\SweetIM\MESSEN~1\RESOUR~1\images\WINKSB~1.PNG
[22/11/2008 21:24|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM
[22/11/2008 21:24|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1
[22/11/2008 21:24|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf
[22/11/2008 21:24|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data
[22/11/2008 21:24|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\logs
[22/11/2008 21:24|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\update
[08/10/2008 11:56|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\adapter.xml
[08/10/2008 11:56|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\AUTOUP~1.XML
[08/10/2008 11:56|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\logger.xml
[08/10/2008 11:56|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\messages.xml
[08/10/2008 11:56|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\sweetim.xml
[08/10/2008 11:56|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\SWEETI~1.XML
[05/12/2008 08:49|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users
[23/11/2008 12:47|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\AAR_SC~1.FR
[22/11/2008 21:26|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\MAIN_U~1.XML
[04/12/2008 11:55|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\NARUTO~1.FR
[05/12/2008 12:47|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\ROCK_R~1.FR
[05/12/2008 08:49|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SCREAM~1.COM
[24/11/2008 22:11|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SHIZUK~1.FR
[21/12/2008 10:27|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\AAR_SC~1.FR\CONTEN~1.XML
[23/11/2008 12:47|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\AAR_SC~1.FR\EMOTIC~1.XML
[23/11/2008 12:47|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\AAR_SC~1.FR\USER_C~1.XML
[19/12/2008 14:27|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\NARUTO~1.FR\CONTEN~1.XML
[04/12/2008 11:55|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\NARUTO~1.FR\EMOTIC~1.XML
[04/12/2008 11:55|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\NARUTO~1.FR\USER_C~1.XML
[05/12/2008 12:47|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\ROCK_R~1.FR\CONTEN~1.XML
[05/12/2008 12:47|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\ROCK_R~1.FR\EMOTIC~1.XML
[05/12/2008 12:47|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\ROCK_R~1.FR\USER_C~1.XML
[05/12/2008 08:49|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SCREAM~1.COM\CONTEN~1.XML
[05/12/2008 08:49|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SCREAM~1.COM\EMOTIC~1.XML
[05/12/2008 08:49|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SCREAM~1.COM\USER_C~1.XML
[20/12/2008 17:21|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SHIZUK~1.FR\CONTEN~1.XML
[24/11/2008 22:11|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SHIZUK~1.FR\EMOTIC~1.XML
[27/11/2008 17:20|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SHIZUK~1.FR\LASTUS~1.XML
[22/11/2008 21:26|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\conf\users\SHIZUK~1.FR\USER_C~1.XML
[19/12/2008 21:54|d--------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1
[21/03/2007 20:27|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00010893.dat
[13/05/2007 21:13|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0001089A.dat
[13/05/2007 21:13|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0001089D.dat
[13/08/2007 22:21|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\000108A9.dat
[16/12/2007 10:54|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\000108C2.dat
[14/08/2008 12:34|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0001093C.dat
[16/12/2005 12:23|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0002006A.dat
[16/12/2005 12:23|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0002006E.dat
[16/12/2005 12:23|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020071.dat
[16/12/2005 12:23|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020073.dat
[16/12/2005 12:23|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020077.dat
[10/01/2007 11:27|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0002013F.dat
[01/03/2007 16:52|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020148.dat
[13/05/2007 21:13|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020158.dat
[09/10/2007 11:41|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020185.dat
[16/12/2007 10:53|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020201.dat
[14/09/2008 12:12|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\000202ED.dat
[23/10/2008 13:14|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00020309.dat
[26/06/2008 14:54|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\000300A1.dat
[11/07/2007 13:20|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00050005.dat
[22/05/2008 21:20|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\000601B4.dat
[10/04/2008 20:26|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00080011.dat
[12/05/2008 04:29|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00080017.dat
[22/05/2008 21:20|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0008001A.dat
[23/06/2008 17:32|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00080024.dat
[07/10/2008 11:55|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0008005C.dat
[23/10/2008 13:14|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00080060.dat
[09/11/2008 11:40|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00080063.dat
[07/12/2008 09:54|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\00080088.dat
[07/12/2008 09:54|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\0008008D.dat
[01/07/2008 00:38|-ra------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\02050002.dat
[19/12/2008 21:54|--a------] C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SweetIM\MESSEN~1\data\CONTEN~1\CACHE_~1.DAT
+-----------------------| ADDED SCAN :
+---------- Scanning prefs.js ... ( # Mozilla User Preferences )
...\x56p5ehg.default\prefs.js :
~~~~ Mozilla FireFox version 3.0.3 ~~~~
Start Page : "
http://www.lo.st"
+----------+
+---------------------------------------------------------------------------+
+--[HKEY_CURRENT_USER\..\Run]
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
+--[HKEY_LOCAL_MACHINE\..\Run]
NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
EoEngine REG_SZ
fnp REG_SZ C:\WINDOWS\system32\fnp.exe \j
VirusKeeper REG_SZ C:\Program Files\AxBx\VirusKeeper 2008 Pro Evaluation\VirusKeeper.exe
SweetIM REG_SZ C:\Program Files\SweetIM\Messenger\SweetIM.exe
!AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
+--[HKEY_USERS\.DEFAULT\..\Run]
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://search.conduit.com/?SearchSource=10&ctid=CT1392740
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
+---------------------------------------------------------------------------+
- "C:\AD-report-Scan-21.12.2008.log" (~27071 bytes)
# END at: 10:35:52 | 21/12/2008 - Time elapsed: 96.7 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 322 lines ]
+---------------------------------------------------------------------------+