[2012/02/08 14:13:57 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\lionel.senaud\Recent
[2012/02/07 14:46:58 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2012/02/07 12:40:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\lionel.senaud\Bureau\RK_Quarantine
[2012/02/03 13:28:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\lionel.senaud\Mes documents\releve actes
[2012/01/25 18:39:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Google Earth
[2012/01/14 17:49:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\lionel.senaud\Mes documents\Downloads
[2012/01/12 21:32:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\lionel.senaud\Mes documents\site trails
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/02/10 21:32:55 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012/02/10 21:32:00 | 000,000,250 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/02/10 21:29:03 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\lionel.senaud\Bureau\OTL.exe
[2012/02/10 21:22:00 | 000,001,070 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/10 20:34:20 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/10 20:33:46 | 000,001,066 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/10 20:33:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/10 19:37:56 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/10 17:48:12 | 000,000,022 | -HS- | M] () -- C:\WINDOWS\System5537 Data.Repository
[2012/02/10 17:48:12 | 000,000,022 | -HS- | M] () -- C:\Documents and Settings\lionel.senaud\Application Data\Sys2662.Config.Repository.bin
[2012/02/10 17:48:07 | 000,001,582 | ---- | M] () -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft\Internet Explorer\Quick Launch\jv16 PowerTools 2011.lnk
[2012/02/10 17:48:07 | 000,001,564 | ---- | M] () -- C:\Documents and Settings\lionel.senaud\Bureau\jv16 PowerTools 2011.lnk
[2012/02/10 12:37:22 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/10 12:37:21 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Firefox.lnk
[2012/02/10 10:23:08 | 000,320,336 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/09 17:58:12 | 000,019,363 | ---- | M] () -- C:\Documents and Settings\lionel.senaud\Mes documents\lio Crédit Agricole PRO.bp
[2012/02/07 20:40:30 | 000,012,428 | ---- | M] () -- C:\Documents and Settings\lionel.senaud\Application Data\wklnhst.dat
[2012/02/03 13:31:01 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Malwarebytes Anti-Malware.lnk
[2012/01/25 18:39:15 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Google Earth.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/02/10 21:32:55 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012/02/10 17:48:12 | 000,000,022 | -HS- | C] () -- C:\WINDOWS\System5537 Data.Repository
[2012/02/10 17:48:12 | 000,000,022 | -HS- | C] () -- C:\Documents and Settings\lionel.senaud\Application Data\Sys2662.Config.Repository.bin
[2012/02/10 17:48:07 | 000,001,582 | ---- | C] () -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft\Internet Explorer\Quick Launch\jv16 PowerTools 2011.lnk
[2012/02/10 17:48:07 | 000,001,564 | ---- | C] () -- C:\Documents and Settings\lionel.senaud\Bureau\jv16 PowerTools 2011.lnk
[2012/02/10 12:37:22 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/10 12:37:21 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Mozilla Firefox.lnk
[2012/02/10 12:37:21 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Mozilla Firefox.lnk
[2012/02/08 17:19:28 | 000,320,336 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/25 18:39:15 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Google Earth.lnk
[2011/01/08 21:13:43 | 000,176,592 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/03/15 09:11:57 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010/03/15 09:11:55 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/03/15 09:11:55 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/03/15 09:11:53 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/02/02 19:25:19 | 000,000,057 | ---- | C] () -- C:\WINDOWS\DcmLtbox-WS.ini
[2009/10/21 13:14:32 | 000,000,470 | ---- | C] () -- C:\WINDOWS\galss.ini
[2009/04/20 15:43:42 | 000,000,565 | ---- | C] () -- C:\WINDOWS\sesam.ini
[2009/02/10 20:43:17 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\unWdWu.exe
[2009/02/10 20:42:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\wunilog.ini
[2009/02/01 18:53:58 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/12/28 20:13:58 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\lionel.senaud\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/28 20:11:11 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\lionel.senaud\Local Settings\Application Data\fusioncache.dat
[2008/12/21 09:05:26 | 000,012,428 | ---- | C] () -- C:\Documents and Settings\lionel.senaud\Application Data\wklnhst.dat
[2008/12/16 15:14:51 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/11/21 22:44:16 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/02/04 18:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2008/01/02 17:55:06 | 000,128,577 | ---- | C] () -- C:\WINDOWS\hpoins11.dat
[2007/12/23 19:48:05 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2007/12/23 19:45:05 | 000,128,038 | ---- | C] () -- C:\WINDOWS\hpoins11.dat.temp
[2007/12/23 19:45:05 | 000,011,634 | ---- | C] () -- C:\WINDOWS\hpomdl11.dat.temp
[2007/12/22 12:23:44 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/12/22 12:16:53 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2007/12/22 12:16:25 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/11/11 19:44:59 | 000,000,335 | ---- | C] () -- C:\WINDOWS\mozregistry.dat
[2007/10/29 17:11:46 | 000,000,179 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/04/20 08:15:11 | 000,011,634 | ---- | C] () -- C:\WINDOWS\hpomdl11.dat
[2007/03/29 16:33:54 | 000,134,912 | ---- | C] () -- C:\WINDOWS\System32\drivers\cam1690.sys
[2007/03/29 16:14:10 | 000,010,997 | ---- | C] () -- C:\WINDOWS\cam1690.ini
[2007/03/28 19:26:10 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\cam1690.dll
[2007/03/23 16:34:42 | 001,597,440 | ---- | C] () -- C:\WINDOWS\StiCap1690.exe
[2007/03/09 19:17:16 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\cam1690m.dll
[2007/03/04 19:25:34 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/05/27 09:46:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/05/27 09:46:17 | 000,003,457 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/05/22 13:09:51 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/05/14 19:09:43 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2006/05/08 16:45:21 | 008,282,187 | ---- | C] () -- C:\Program Files\vlc-0.8.5-win32.exe
[2006/03/11 23:27:08 | 001,104,734 | ---- | C] () -- C:\Program Files\dvdshrink_3.2.0.16_fr.zip
[2006/03/11 22:07:51 | 000,000,042 | ---- | C] () -- C:\Program Files\default.pls
[2006/02/22 23:18:25 | 000,000,016 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2006/02/17 17:03:50 | 000,278,528 | ---- | C] () -- C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[2006/02/06 21:20:36 | 000,016,221 | ---- | C] () -- C:\WINDOWS\hpiins01.dat
[2006/01/23 17:49:57 | 000,000,385 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/01/23 17:40:49 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2006/01/23 17:40:49 | 000,036,864 | R--- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2006/01/21 21:48:17 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2006/01/21 17:24:30 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2006/01/21 17:19:07 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2006/01/21 17:19:03 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2006/01/21 16:40:22 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006/01/21 16:32:46 | 000,249,344 | R--- | C] () -- C:\WINDOWS\System32\NvRaidMan.exe
[2006/01/21 16:32:46 | 000,223,232 | R--- | C] () -- C:\WINDOWS\System32\nvsataconnection.exe
[2006/01/21 16:18:56 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/01/21 16:15:46 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/01/21 16:12:36 | 000,004,207 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/06/16 02:20:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005/06/16 02:20:00 | 001,657,376 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2005/06/16 02:20:00 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2005/06/16 02:20:00 | 001,346,080 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2005/06/16 02:20:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005/06/16 02:20:00 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005/06/16 02:20:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005/06/16 02:20:00 | 000,449,056 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2005/06/16 02:20:00 | 000,436,768 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2005/06/16 02:20:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005/01/06 15:04:00 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\unwlsdrv.exe
[2004/08/02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003/11/06 12:46:04 | 000,368,640 | ---- | C] () -- C:\WINDOWS\sjsw32.dll
[2003/04/01 10:58:02 | 000,005,260 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/01/10 17:27:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\atlw32.dll
[2001/09/28 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/09/28 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/09/28 13:00:00 | 000,525,814 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
[2001/09/28 13:00:00 | 000,455,480 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/09/28 13:00:00 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
[2001/09/28 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/09/28 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/09/28 13:00:00 | 000,089,714 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
[2001/09/28 13:00:00 | 000,075,596 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/09/28 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/09/28 13:00:00 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat
[2001/09/28 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/09/28 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/09/28 13:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001/09/28 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001/07/07 03:00:00 | 000,003,279 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI
========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. >[2011/08/15 12:26:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2011/02/14 18:40:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2011/12/06 19:31:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Andreane
[2011/12/15 20:41:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avira
[2011/02/13 21:08:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2011/11/14 09:19:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CheckPoint
[2008/12/17 14:16:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/09/08 18:40:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2009/02/22 11:44:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google Updater
[2007/12/23 19:35:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP
[2008/11/12 08:22:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2009/05/03 08:03:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hps
[2012/02/08 18:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ma-config.com
[2008/01/02 18:44:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/02/22 14:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/10/09 08:38:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2009/02/22 11:41:43 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/02/18 22:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2007/11/25 22:20:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nero
[2010/10/09 09:22:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NOS
[2006/01/21 17:39:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2008/12/05 16:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/03/15 08:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2009/02/05 18:42:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skyline
[2012/02/07 17:26:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2007/12/23 09:48:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sonic
[2009/02/22 14:12:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/03/30 17:19:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun
[2011/01/11 15:49:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tmp
[2010/10/03 18:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2006/09/09 17:23:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006/03/04 22:30:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/01/19 19:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ZoneFiveSoftware
< %ALLUSERSPROFILE%\Application Data\*.exe /s >[2011/06/06 21:52:43 | 001,560,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Setup\{AC76BA86-7AD7-1036-7B44-AA1000000001}\setup.exe
[2010/06/28 15:01:45 | 001,403,736 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\hps\7884\setup_Photocite_Collection_45.exe
[2012/02/03 13:30:33 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
< %APPDATA%\*. >[2012/02/10 17:59:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Adobe
[2011/12/19 11:24:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Ahead
[2011/09/17 14:34:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\AskToolbar
[2011/12/15 20:44:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Avira
[2011/02/13 21:08:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\AVS4YOU
[2011/01/15 16:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\BankPerfect
[2010/11/04 12:32:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\CheckPoint
[2008/12/16 19:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Common Files
[2012/02/10 17:59:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\DivX
[2012/02/10 17:59:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\dvdcss
[2009/01/14 13:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Google
[2008/12/16 19:00:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\HP
[2010/09/20 13:50:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Macromedia
[2009/02/22 14:24:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Malwarebytes
[2012/02/10 21:12:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft
[2012/02/10 18:33:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Mozilla
[2008/12/18 17:09:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\OpenOffice.org
[2011/02/21 20:28:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\skypePM
[2008/12/28 20:25:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Sun
[2009/12/06 12:05:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\TeamViewer
[2011/12/04 19:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\Thunderbird
[2010/10/03 18:58:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\TomTom
[2010/11/01 13:57:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\vlc
[2009/01/20 10:11:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lionel.senaud\Application Data\VSRevoGroup
< %APPDATA%\*.exe /s >[2009/02/09 20:24:52 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\ARPPRODUCTICON.exe
[2009/02/09 20:24:52 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut1_8527C3D5BA1D46E988D2AF25544311A3.exe
[2009/02/09 20:24:52 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\lionel.senaud\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut2_8527C3D5BA1D46E988D2AF25544311A3.exe
[2010/09/01 14:52:56 | 000,032,032 | ---- | M] (NOS Microsystems Ltd.) -- C:\Documents and Settings\lionel.senaud\Application Data\Mozilla\Firefox\Profiles\rondzn6u.Utilisateur par défaut\extensions\nostmp\content\getPlusPlus_Adobe_reg.exe
< %temp%\*.exe /s >[2012/02/07 15:06:46 | 003,904,680 | ---- | M] (Ask) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\setup.exe
[15 C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\*.tmp files -> C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\*.tmp -> ]
[2011/10/17 19:25:35 | 001,207,296 | ---- | M] (Google) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\._msige61\GoogleEarth.exe
[2011/10/17 19:03:23 | 000,050,688 | ---- | M] () -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\._msige61\program files\Google\Google Earth\client\earthflashsol.exe
[2011/10/17 19:03:16 | 000,071,680 | ---- | M] (Google) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\._msige61\program files\Google\Google Earth\client\googleearth.exe
[2011/10/17 19:03:41 | 000,293,888 | ---- | M] () -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\._msige61\program files\Google\Google Earth\client\gpsbabel.exe
[2011/10/17 19:03:16 | 000,071,680 | ---- | M] (Google) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\._msige61\program files\Google\Google Earth\plugin\geplugin.exe
[2011/10/17 19:31:16 | 001,207,296 | ---- | M] (Google) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\._msigeplugin61\GoogleEarth.exe
[2011/10/17 19:03:16 | 000,071,680 | ---- | M] (Google) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\._msigeplugin61\program files\Google\Google Earth\plugin\geplugin.exe
[2011/11/15 11:29:50 | 003,283,352 | ---- | M] (Uniblue Systems Ltd ) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\mia4C.tmp\bm_installer.exe
[2011/11/07 09:26:14 | 000,067,456 | ---- | M] (Uniblue Systems Limited) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\mia4C.tmp\data\OFFLINE\89292046\B152136D\Launcher.exe
[2011/11/07 09:26:14 | 000,025,472 | ---- | M] (Uniblue Systems Limited) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\mia4C.tmp\data\OFFLINE\89292046\B152136D\rbmonitor.exe
[2011/11/07 09:26:14 | 000,025,472 | ---- | M] (Uniblue Systems Limited) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\mia4C.tmp\data\OFFLINE\89292046\B152136D\rbnotifier.exe
[2011/11/07 09:26:14 | 000,025,992 | ---- | M] (Uniblue Systems Limited) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\mia4C.tmp\data\OFFLINE\89292046\B152136D\rb_move_serial.exe
[2011/11/07 09:26:14 | 000,025,464 | ---- | M] (Uniblue Systems Limited) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\mia4C.tmp\data\OFFLINE\89292046\B152136D\rb_ubm.exe
[2011/11/07 09:26:14 | 000,053,104 | ---- | M] (Uniblue Systems Limited) -- C:\DOCUME~1\LIONEL~1.SEN\LOCALS~1\Temp\mia4C.tmp\data\OFFLINE\89292046\B152136D\registrybooster.exe
< %SYSTEMDRIVE%\*.exe > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2006/01/21 17:11:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2006/01/21 17:11:00 | 000,634,880 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2006/01/21 17:11:00 | 000,409,600 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< MD5 for: EXPLORER.EXE >[2004/08/19 16:09:54 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=2A7BD330924252A2FD80344FC949BB72 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007/06/13 14:10:53 | 001,037,312 | ---- | M] (Microsoft Corporation) MD5=B795475444D6D57A572C14B9E1A29839 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 14:22:28 | 001,037,312 | ---- | M] (Microsoft Corporation) MD5=D0288319660EDCFED07C7E74C4EA38A5 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008/04/14 03:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 03:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\explorer.exe
[2008/04/14 03:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
< MD5 for: WINLOGON.EXE >[2004/08/19 16:10:06 | 000,506,368 | ---- | M] (Microsoft Corporation) MD5=123EEA158F74D0F67A51DCDF065D1091 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/01/13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 03:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 03:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 03:34:28 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\winlogon.exe
< HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /s > < HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s >"Debug" =
"Kmode" = %SystemRoot%\system32\win32k.sys -- [2011/11/23 15:40:17 | 001,859,712 | ---- | M] (Microsoft Corporation)
"Optional" = Posix [binary data]
"Posix" = %SystemRoot%\system32\psxss.exe
"Required" = DebugWindows [binary data]
"Windows" = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\CSRSS]
"CsrSrvSharedSectionBase" = 2137980928
< nslookup http://www.google.fr /c >Serveur : openrg.home
Address: 192.168.1.1
< hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/01/29 17:20:06 | 000,836,928 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/01/29 17:20:06 | 000,836,928 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/01/29 17:20:06 | 000,836,928 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/01/29 17:20:04 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/01/29 17:20:04 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/01/29 17:20:04 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/11/04 12:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/11/04 12:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/11/04 12:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/01/29 17:20:06 | 000,836,928 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/01/29 17:20:06 | 000,836,928 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/01/29 17:20:06 | 000,836,928 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/01/29 17:20:04 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/01/29 17:20:04 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/01/29 17:20:04 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/11/04 12:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/11/04 12:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/11/04 12:24:17 | 000,174,080 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
< > < >< End of report >