Here are the results :
OTL logfile created on: 2012-03-03 14:59:46 - Run 1
OTL by OldTimer - Version 3.2.35.0 Folder = C:\Users\Serge\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c0c | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
4,00 Gb Total Physical Memory | 2,53 Gb Available Physical Memory | 63,15% Memory free
8,00 Gb Paging File | 6,34 Gb Available in Paging File | 79,28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284,93 Gb Total Space | 131,73 Gb Free Space | 46,23% Space Free | Partition Type: NTFS
Drive D: | 13,16 Gb Total Space | 2,65 Gb Free Space | 20,17% Space Free | Partition Type: NTFS
Drive E: | 580,20 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive F: | 14,89 Gb Total Space | 14,70 Gb Free Space | 98,67% Space Free | Partition Type: FAT32
Computer Name: SERGE-PC | User Name: Serge | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Users\Serge\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe ()
PRC - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe (CyberLink)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
PRC - c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Broadcom Corporation.)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\fr_FR\AcroIEFavClient.FRA ()
MOD - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\fr_FR\AcroTray.FRA ()
MOD - C:\Windows\SysWOW64\KBDDGR1.DLL ()
MOD - C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
MOD - C:\Windows\SysWOW64\vaultclii.dll ()
MOD - C:\Windows\SysWOW64\PortableDeviceWMDRRM.dll ()
MOD - C:\Windows\SysWOW64\NlsLexiicons0816.dll ()
MOD - C:\Program Files (x86)\Epson Software\Event Manager\Assistants\Scan Assistant\ScanEngine.dll ()
MOD - C:\Program Files (x86)\Epson Software\Event Manager\Assistants\Scan Assistant\Satwain.dll ()
========== Win32 Services (SafeList) ========== SRV:
64bit: - (btwdins) -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe (Symantec Corporation)
SRV - (CLHNServiceForPowerDVD) -- C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe ()
SRV - (CyberLink PowerDVD 11.0 Service) -- C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe (CyberLink)
SRV - (CyberLink PowerDVD 11.0 Monitor Service) -- C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe (CyberLink)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (EpsonBidirectionalService) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ========== DRV:
64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.sys (Symantec Corporation)
DRV:
64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\symnets.sys (Symantec Corporation)
DRV:
64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\Ironx64.sys (Symantec Corporation)
DRV:
64bit: - (ccSet_NIS) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.sys (Symantec Corporation)
DRV:
64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS64.sys (Symantec Corporation)
DRV:
64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (ANDModem) -- C:\Windows\SysNative\drivers\lgandmodem64.sys (LG Electronics Inc.)
DRV:
64bit: - (AndDiag) -- C:\Windows\SysNative\drivers\lganddiag64.sys (LG Electronics Inc.)
DRV:
64bit: - (AndGps) -- C:\Windows\SysNative\drivers\lgandgps64.sys (LG Electronics Inc.)
DRV:
64bit: - (Andbus) -- C:\Windows\SysNative\drivers\lgandbus64.sys (LG Electronics Inc.)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:
64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:
64bit: - (androidusb) -- C:\Windows\SysNative\drivers\lgandadb.sys (Google Inc)
DRV:
64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (smserial) -- C:\Windows\SysNative\drivers\smserial.sys (Motorola Inc.)
DRV:
64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:
64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:
64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:
64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:
64bit: - (MODEMCSA) -- C:\Windows\SysNative\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV:
64bit: - (netw5v64) Intel® -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:
64bit: - (SSPORT) -- C:\Windows\SysNative\drivers\SSPORT.SYS (Samsung Electronics)
DRV:
64bit: - (HpqRemHid) -- C:\Windows\SysNative\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV:
64bit: - (rismxdp) -- C:\Windows\SysNative\drivers\rixdpx64.sys (REDC)
DRV:
64bit: - (rimmptsk) -- C:\Windows\SysNative\drivers\rimmpx64.sys (REDC)
DRV:
64bit: - (rimsptsk) -- C:\Windows\SysNative\drivers\rimspx64.sys (REDC)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\VirusDefs\20120302.017\ex64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\VirusDefs\20120302.017\eng64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\IPSDefs\20120303.003\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\BASHDefs\20120215.001\BHDrvx64.sys (Symantec Corporation)
DRV - (ntk_PowerDVD) -- C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys (Cyberlink Corp.)
DRV - ({329F96B6-DF1E-4328-BFDA-39EA953C1312}) -- C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl (CyberLink Corp.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://ca.msn.com/defaultf.aspx?lang=fr-ca&OCID=iehpIE - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-CA
IE - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C2 F9 53 31 72 F9 CC 01 [binary data]
IE - HKU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Serge\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012-02-11 00:56:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\IPSFFPlgn\ [2012-02-27 10:56:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\coFFPlgn\ [2012-03-03 14:01:00 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2008-04-03 20:46:27 | 000,000,922 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activation.quicken.ca
O1 - Hosts: 127.0.0.1 activation.fr.quicken.ca
O1 - Hosts: 127.0.0.1 activation.intuit.ca
O1 - Hosts: 127.0.0.1 activation.quicktax.ca
O1 - Hosts: 127.0.0.1 docs.quicktaxweb.ca
O1 - Hosts: 127.0.0.1 ps.intuitcanada.com
O1 - Hosts: 127.0.0.1 support.intuitcanada.com
O2:
64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:
64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Adobe PDF Link Helper) - {316723C4-4E4A-01D3-7723-2F122F4F5815} - C:\Windows\SysWOW64\PortableDeviceWMDRRM.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {521A0DD6-456A-6ADF-543B-4241076D59AD} - C:\Windows\SysWOW64\vaultclii.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\CoIEPlg.dll (Symantec Corporation)
O4:
64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [messagepdf] C:\Windows\SysWow64\14R7PBCHMO92KFL1IPJP14\formodpar.exe ()
O4 - HKLM..\Run: [RemoteControl11] C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKU\S-1-5-21-1365876331-3669831383-1828126602-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1365876331-3669831383-1828126602-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1365876331-3669831383-1828126602-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1365876331-3669831383-1828126602-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:
64bit: - Extra context menu item: &Envoyer à OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8:
64bit: - Extra context menu item: Ajouter à la file d'attente le lien ciblé - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm ()
O8:
64bit: - Extra context menu item: Ajouter à un fichier PDF existant - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Ajouter cette page à la file d'attente de BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm ()
O8:
64bit: - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convertir au format Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convertir la cible du lien au format Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8:
64bit: - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8:
64bit: - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:
64bit: - Extra context menu item: Ouvrir cette page avec BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebid.htm ()
O8:
64bit: - Extra context menu item: Ouvrir cette page avec BID Link Explorer - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm ()
O8:
64bit: - Extra context menu item: Ouvrir le lien ciblé avec BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm ()
O8 - Extra context menu item: &Envoyer à OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Ajouter à la file d'attente le lien ciblé - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkqueue.htm ()
O8 - Extra context menu item: Ajouter à un fichier PDF existant - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Ajouter cette page à la file d'attente de BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidqueue.htm ()
O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convertir au format Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Ouvrir cette page avec BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebid.htm ()
O8 - Extra context menu item: Ouvrir cette page avec BID Link Explorer - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlinkexplorer.htm ()
O8 - Extra context menu item: Ouvrir le lien ciblé avec BID - C:\Program Files (x86)\Bulk Image Downloader\iemenu\iebidlink.htm ()
O9:
64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:
64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Envoyer à Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Envoyer au périphérique &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/ractrl.cab?lmi=724 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.200.243.189 24.200.210.241 24.200.228.113
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7C840BF-3126-4DE9-BC12-1B032BD47E33}: DhcpNameServer = 24.200.243.189 24.200.210.241 24.200.228.113
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\intu-ir2008 - No CLSID value found
O18:
64bit: - Protocol\Handler\intu-ir2009 - No CLSID value found
O18:
64bit: - Protocol\Handler\intu-ir2010 - No CLSID value found
O18:
64bit: - Protocol\Handler\intu-ir2011 - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\intu-ir2008 {729D3592-92E7-4cbc-8E44-3C22B3F457B3} - C:\Program Files (x86)\ImpotRapide 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-ir2009 {E4616804-F2F8-4839-B728-5305004DA6A7} - C:\Program Files (x86)\ImpotRapide 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-ir2010 {A344EB2D-3A0F-48fa-A073-2E649BAEC9B3} - C:\Program Files (x86)\ImpotRapide 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-ir2011 {DFF68B15-A8D3-420b-B32C-E9554E2F5C15} - C:\Program Files (x86)\ImpotRapide 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28:
64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005-09-11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O32 - AutoRun File - [2006-09-28 17:15:29 | 000,000,056 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012-03-03 14:58:54 | 000,585,216 | ---- | C] (OldTimer Tools) -- C:\Users\Serge\Desktop\OTL.exe
[2012-03-03 13:59:48 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012-03-03 12:52:34 | 004,730,880 | ---- | C] (AVAST Software) -- C:\Users\Serge\Desktop\aswMBR.exe
[2012-03-03 12:52:20 | 002,062,896 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Serge\Desktop\tdsskiller.exe
[2012-03-03 11:40:40 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012-03-03 11:40:40 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012-03-03 11:40:40 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012-03-03 11:40:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012-03-02 09:24:21 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{7B679783-FBDB-49F0-A44D-814C516C74A4}
[2012-03-02 09:24:17 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{C4B593AA-0A61-4F15-8806-8374257BCCAE}
[2012-03-01 21:02:26 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012-03-01 18:25:08 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012-03-01 15:44:45 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012-03-01 14:52:19 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\ReelDealWildWestShootOut
[2012-03-01 09:25:23 | 000,000,000 | ---D | C] -- C:\Users\Serge\Documents\Mes fichiers reçus
[2012-03-01 09:09:14 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{6E54E8EF-4A1D-4937-B67E-917EA5201437}
[2012-03-01 09:09:09 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{8677ADA5-E702-423B-A89A-B94F527094B6}
[2012-03-01 09:09:09 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{6DB6168B-E39D-486D-BB79-5379ED3E1EBD}
[2012-02-28 17:42:51 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\iwin
[2012-02-28 17:41:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deal Or No Deal
[2012-02-28 11:39:16 | 004,424,615 | R--- | C] (Swearware) -- C:\Users\Serge\Desktop\ComboFix.exe
[2012-02-28 10:06:51 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{18AEBBCC-029C-4855-9650-EA4068A7A91B}
[2012-02-27 22:06:23 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{06940DC7-4735-4D1F-A918-4CCD97AFCC5A}
[2012-02-27 22:06:14 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{4477F146-6E63-48AF-9DBD-EB18058FE75B}
[2012-02-27 19:08:06 | 000,000,000 | ---D | C] -- C:\Users\Serge\Desktop\impot
[2012-02-27 18:27:14 | 000,055,384 | ---- | C] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys
[2012-02-27 18:23:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2012-02-27 18:15:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012-02-27 18:15:14 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012-02-27 17:41:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012-02-27 17:41:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012-02-27 17:20:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImpotRapide 2008
[2012-02-27 17:18:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AnswerWorks 4.0
[2012-02-27 17:18:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImpotRapide 2009
[2012-02-27 17:16:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImpotRapide 2010
[2012-02-27 11:00:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2012-02-27 10:57:58 | 000,000,000 | ---D | C] -- C:\Users\Serge\Documents\Symantec
[2012-02-27 10:56:24 | 000,175,736 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012-02-27 10:56:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012-02-27 10:56:24 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012-02-27 10:56:02 | 000,405,624 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\symnets.sys
[2012-02-27 10:56:01 | 001,092,728 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA64.sys
[2012-02-27 10:56:01 | 000,738,936 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.sys
[2012-02-27 10:56:01 | 000,451,192 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS64.sys
[2012-02-27 10:56:01 | 000,190,072 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\Ironx64.sys
[2012-02-27 10:56:01 | 000,167,048 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.sys
[2012-02-27 10:56:01 | 000,037,496 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.sys
[2012-02-27 10:55:54 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NISx64
[2012-02-27 10:55:54 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NISx64\1305000.091
[2012-02-27 10:55:52 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2012-02-27 10:55:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Internet Security
[2012-02-27 10:55:02 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2012-02-27 10:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2012-02-27 10:50:52 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2012-02-27 10:50:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2012-02-27 09:56:34 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{4BCC11EB-390D-4E86-9A40-64417F19227E}
[2012-02-27 09:56:30 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{5B20BA59-B5A3-4E64-9155-4157E265475B}
[2012-02-26 13:23:05 | 000,000,000 | ---D | C] -- C:\ProgramData\rionix
[2012-02-26 13:22:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\New Yankee in King Arthurs Court
[2012-02-26 12:57:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\2029
[2012-02-26 12:56:53 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\2086
[2012-02-26 11:50:30 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{B33AA28D-34BE-48C8-BE53-D6959A271D15}
[2012-02-26 11:50:19 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{5D735E0A-A87E-46C8-AC71-003F77760AE1}
[2012-02-25 22:41:11 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{5FFF2C2A-B175-4848-BEBC-201539EEC6F2}
[2012-02-25 22:40:59 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\{13ED3BCF-C4F0-4A4A-8DEE-EE5106314F52}
[2012-02-25 22:40:46 | 000,000,000 | ---D | C] -- C:\Users\Serge\Tracing
[2012-02-25 22:02:24 | 000,000,000 | ---D | C] -- C:\Windows\fr
[2012-02-25 22:00:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2012-02-25 21:58:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2012-02-25 21:57:19 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_5.dll
[2012-02-25 21:57:19 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll
[2012-02-25 21:57:18 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_42.dll
[2012-02-25 21:57:18 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_42.dll
[2012-02-25 21:56:44 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_32.dll
[2012-02-25 21:56:44 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_32.dll
[2012-02-25 21:54:57 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Windows Live
[2012-02-25 21:54:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2012-02-23 20:27:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Boss Media
[2012-02-23 20:27:51 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Boss Media
[2012-02-23 20:25:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Safari
[2012-02-23 20:24:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012-02-23 20:24:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012-02-23 18:24:43 | 000,000,000 | -H-D | C] -- C:\Users\Public\Documents\wlast
[2012-02-20 21:19:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Games
[2012-02-19 19:04:17 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Amulet_of_time
[2012-02-19 19:02:30 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amulet of Time - Shadow of la Rochelle
[2012-02-19 14:25:54 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\mIRC
[2012-02-19 14:25:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mIRC
[2012-02-19 14:25:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\mIRC
[2012-02-18 21:40:16 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012-02-18 21:40:16 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012-02-18 21:40:15 | 002,308,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012-02-18 21:40:15 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012-02-18 21:40:15 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012-02-18 21:40:14 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012-02-18 21:40:14 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012-02-18 21:40:13 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012-02-18 21:40:13 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012-02-18 21:40:12 | 001,493,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012-02-18 21:40:12 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012-02-18 21:30:07 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maestro 2- Notes of Life - Standard With Guide
[2012-02-16 21:26:52 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\GameDevo
[2012-02-16 21:23:32 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012-02-16 21:22:04 | 000,466,456 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2012-02-16 21:22:04 | 000,444,952 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2012-02-16 21:22:04 | 000,122,904 | ---- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll
[2012-02-16 21:22:04 | 000,109,080 | ---- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll
[2012-02-16 21:22:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL
[2012-02-16 21:20:08 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malice - Two Sisters Survey
[2012-02-16 21:20:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malice - Two Sisters Survey
[2012-02-16 21:20:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malice - Two Sisters Survey
[2012-02-16 21:14:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foxy Games
[2012-02-16 21:11:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Big Fish Games
[2012-02-16 21:11:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\bfgclient
[2012-02-16 21:10:39 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache
[2012-02-15 15:44:34 | 000,509,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntshrui.dll
[2012-02-15 15:44:33 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl
[2012-02-15 15:44:33 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl
[2012-02-15 15:44:26 | 000,634,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll
[2012-02-14 22:57:11 | 000,000,000 | ---D | C] -- C:\Users\Serge\Desktop\Nouveau dossier (4)
[2012-02-14 22:45:57 | 001,490,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01007.dll
[2012-02-14 22:45:57 | 000,708,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinUSBCoInstaller.dll
[2012-02-13 17:54:18 | 000,031,744 | ---- | C] (Google Inc) -- C:\Windows\SysNative\drivers\lgandadb.sys
[2012-02-13 17:54:16 | 000,034,304 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandmodem64.sys
[2012-02-13 17:54:15 | 000,027,648 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lganddiag64.sys
[2012-02-13 17:54:15 | 000,027,136 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandgps64.sys
[2012-02-13 17:54:15 | 000,019,456 | ---- | C] (LG Electronics Inc.) -- C:\Windows\SysNative\drivers\lgandbus64.sys
[2012-02-12 23:23:44 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\funkitron
[2012-02-11 12:49:13 | 000,000,000 | ---D | C] -- C:\Users\Serge\Documents\Bulk Image Downloader
[2012-02-11 12:47:46 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GotCLIP Downloader
[2012-02-11 12:47:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GotCLIP Downloader
[2012-02-11 12:36:16 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\BID
[2012-02-11 12:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bulk Image Downloader
[2012-02-11 12:36:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bulk Image Downloader
[2012-02-11 12:21:00 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Youtube Downloader HD
[2012-02-11 12:20:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youtube Downloader HD
[2012-02-11 12:20:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Youtube Downloader HD
[2012-02-11 11:41:21 | 000,000,000 | ---D | C] -- C:\ProgramData\SSScan
[2012-02-11 11:41:12 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\SSScan
[2012-02-11 11:41:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers
[2012-02-11 11:40:43 | 000,000,000 | ---D | C] -- C:\Windows\twain_64
[2012-02-11 11:40:17 | 000,280,064 | ---- | C] (Samsung Electronics) -- C:\Windows\SysNative\snWIAMUI.dll
[2012-02-11 01:05:25 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 11
[2012-02-11 01:03:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CyberLink
[2012-02-11 01:00:31 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2012-02-11 00:58:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
[2012-02-11 00:24:30 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\NVIDIA
[2012-02-11 00:23:35 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Facebook
[2012-02-10 23:32:52 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\MediaShow
[2012-02-10 23:31:58 | 000,000,000 | ---D | C] -- C:\Users\Serge\Documents\CyberLink
[2012-02-10 23:30:54 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\MediaServer
[2012-02-10 23:30:54 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CyberLink
[2012-02-10 23:30:48 | 000,000,000 | ---D | C] -- C:\ProgramData\PDVD
[2012-02-10 23:30:33 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\CyberLink
[2012-02-10 23:30:27 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\CyberLink
[2012-02-10 23:30:27 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2012-02-10 23:26:25 | 000,000,000 | ---D | C] -- C:\ProgramData\install_clap
[2012-02-10 21:53:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitTorrent
[2012-02-10 21:52:21 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\BitTorrent
[2012-02-07 21:48:44 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Alawar
[2012-02-07 21:48:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Alawar
[2012-02-05 08:33:26 | 000,000,000 | ---D | C] -- C:\Users\Serge\.jIRC
[2012-02-04 14:31:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LGMobile Support Tool
[2012-02-04 14:29:44 | 001,919,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdfcoinstaller01005.dll
[2012-02-04 13:28:16 | 000,000,000 | ---D | C] -- C:\ProgramData\LGMOBILEAX
[2012-02-04 11:54:47 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\GetRightToGo
[2012-02-04 11:54:47 | 000,000,000 | ---D | C] -- C:\Users\Serge\Documents\Downloads
[2012-02-04 11:15:17 | 000,000,000 | ---D | C] -- C:\LGP999
[2012-02-04 11:11:54 | 000,000,000 | ---D | C] -- C:\LG_USB
[2012-02-04 09:46:29 | 000,655,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr90.dll
[2012-02-04 09:46:29 | 000,568,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp90.dll
[2012-02-04 09:46:29 | 000,224,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcm90.dll
[2012-02-04 09:45:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LG Electronics
[2012-02-03 22:47:00 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\ERS Game Studios
[2012-02-03 22:20:38 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Périphériques Bluetooth
[2012-02-03 22:17:30 | 000,000,000 | ---D | C] -- C:\Users\Serge\Documents\Dossier Echanges Bluetooth
[2012-02-03 22:17:30 | 000,000,000 | ---D | C] -- C:\Users\Serge\AppData\Local\Broadcom
[2012-02-03 22:16:08 | 000,132,648 | ---- | C] (Broadcom Corporation.) -- C:\Windows\SysNative\drivers\btwavdt.sys
[2012-02-03 22:16:08 | 000,098,344 | ---- | C] (Broadcom Corporation.) -- C:\Windows\SysNative\drivers\btwaudio.sys
[2012-02-03 22:16:08 | 000,035,104 | ---- | C] (Broadcom Corporation.) -- C:\Windows\SysNative\drivers\btwl2cap.sys
[2012-02-03 22:16:08 | 000,021,160 | ---- | C] (Broadcom Corporation.) -- C:\Windows\SysNative\drivers\btwrchid.sys
[2012-02-03 22:15:46 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM
[2012-02-03 22:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2012-02-03 22:13:49 | 000,000,000 | ---D | C] -- C:\system.sav
[2012-02-03 22:07:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hewlett-Packard
[2012-02-03 21:10:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unknown Device Identifier 8.00
[2012-02-03 21:10:25 | 000,000,000 | ---D | C] -- C:\Program Files\Unknown Device Identifier
[2012-02-03 13:57:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Belarc
[2012-02-03 12:03:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2012-02-03 12:02:54 | 003,074,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2012-02-03 12:02:54 | 000,837,952 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\easyupdatusapiu64.dll
[2012-02-03 12:02:02 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2012-02-03 11:58:04 | 024,742,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2012-02-03 11:58:04 | 018,871,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2012-02-03 11:58:04 | 008,791,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2012-02-03 11:58:04 | 007,041,856 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2012-02-03 11:58:04 | 001,454,400 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvgenco64.dll
[2012-02-03 11:58:04 | 000,068,928 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2012-02-03 11:58:04 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2012-02-03 11:58:03 | 024,796,992 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2012-02-03 11:58:03 | 017,248,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2012-02-03 11:58:03 | 007,581,504 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2012-02-03 11:58:03 | 005,578,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2012-02-03 11:58:03 | 002,542,912 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2012-02-03 11:58:03 | 002,458,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2012-02-03 11:58:03 | 002,401,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2012-02-03 11:58:03 | 002,232,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2012-02-03 11:58:03 | 002,099,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2012-02-03 11:58:03 | 001,533,248 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco64.dll
[2012-02-03 11:57:40 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2012-02-03 11:56:55 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2012-02-03 11:05:18 | 001,071,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpluir.dll
[2012-02-03 11:05:18 | 000,388,640 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvexpbar.dll
[2012-02-02 15:26:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
========== Files - Modified Within 30 Days ========== [2012-03-03 14:58:58 | 000,585,216 | ---- | M] (OldTimer Tools) -- C:\Users\Serge\Desktop\OTL.exe
[2012-03-03 14:06:31 | 000,014,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-03-03 14:06:31 | 000,014,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-03-03 13:59:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-03-03 13:59:06 | 3219,988,480 | -HS- | M] () -- C:\hiberfil.sys
[2012-03-03 12:52:42 | 004,730,880 | ---- | M] (AVAST Software) -- C:\Users\Serge\Desktop\aswMBR.exe
[2012-03-03 12:52:20 | 002,062,896 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Serge\Desktop\tdsskiller.exe
[2012-03-03 12:28:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1365876331-3669831383-1828126602-1001UA.job
[2012-03-01 21:08:31 | 000,002,413 | ---- | M] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2012-03-01 18:29:57 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2012-03-01 18:29:57 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2012-02-28 17:42:13 | 000,001,200 | ---- | M] () -- C:\Users\Public\Desktop\Deal Or No Deal.lnk
[2012-02-28 11:39:16 | 004,424,615 | R--- | M] (Swearware) -- C:\Users\Serge\Desktop\ComboFix.exe
[2012-02-27 22:00:44 | 000,419,384 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012-02-27 19:04:28 | 000,345,600 | ---- | M] () -- C:\Users\Serge\Desktop\impot.exe
[2012-02-27 18:27:14 | 000,055,384 | ---- | M] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys
[2012-02-27 18:24:17 | 002,125,276 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\Cat.DB
[2012-02-27 18:15:14 | 000,002,975 | ---- | M] () -- C:\Users\Serge\Desktop\HiJackThis.lnk
[2012-02-27 17:20:46 | 000,001,907 | ---- | M] () -- C:\Users\Public\Desktop\ImpôtRapide 2008.lnk
[2012-02-27 17:18:40 | 000,001,055 | ---- | M] () -- C:\Users\Public\Desktop\ImpôtRapide 2009.lnk
[2012-02-27 17:16:07 | 000,001,907 | ---- | M] () -- C:\Users\Public\Desktop\ImpôtRapide 2010.lnk
[2012-02-27 16:33:43 | 000,050,575 | ---- | M] () -- C:\Users\Serge\Documents\billets madonna.pdf
[2012-02-27 10:59:33 | 000,004,782 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\VT20111023.022
[2012-02-27 10:56:24 | 000,175,736 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012-02-27 10:56:24 | 000,007,488 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012-02-27 10:56:24 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012-02-27 10:56:15 | 000,002,588 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012-02-27 10:55:42 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012-02-27 10:55:31 | 000,702,600 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2012-02-27 10:55:31 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012-02-27 10:55:31 | 000,130,274 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2012-02-27 10:55:31 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012-02-27 10:50:53 | 000,001,298 | ---- | M] () -- C:\Users\Serge\Desktop\Fichiers d’installation Norton.lnk
[2012-02-26 13:22:27 | 000,001,338 | ---- | M] () -- C:\Users\Public\Desktop\New Yankee in King Arthurs Court.lnk
[2012-02-26 00:28:01 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1365876331-3669831383-1828126602-1001Core.job
[2012-02-23 20:25:46 | 000,002,515 | ---- | M] () -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2012-02-23 20:25:46 | 000,002,491 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2012-02-23 20:24:29 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012-02-20 21:19:56 | 000,002,246 | ---- | M] () -- C:\Users\Serge\Desktop\Aaron Crane Paintings Come Alive.lnk
[2012-02-20 18:43:59 | 001,556,228 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012-02-19 19:02:30 | 000,002,368 | ---- | M] () -- C:\Users\Serge\Desktop\Amulet of Time - Shadow of la Rochelle.lnk
[2012-02-19 14:25:54 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\mIRC.lnk
[2012-02-18 21:30:18 | 000,002,482 | ---- | M] () -- C:\Users\Serge\Desktop\Maestro 2- Notes of Life.lnk
[2012-02-16 21:23:25 | 578,189,269 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012-02-16 21:22:04 | 000,466,456 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2012-02-16 21:22:04 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2012-02-16 21:22:04 | 000,122,904 | ---- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll
[2012-02-16 21:22:04 | 000,109,080 | ---- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll
[2012-02-16 21:21:25 | 000,002,088 | ---- | M] () -- C:\Users\Public\Desktop\Play Malice - Two Sisters Survey.lnk
[2012-02-14 22:49:34 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2012-02-11 12:48:45 | 000,001,137 | ---- | M] () -- C:\Users\Serge\Desktop\BID Queue Manager.lnk
[2012-02-11 12:48:45 | 000,001,071 | ---- | M] () -- C:\Users\Serge\Desktop\Bulk Image Downloader.lnk
[2012-02-11 12:25:41 | 102,933,364 | ---- | M] () -- C:\Users\Serge\Documents\Nicki Minaj - Super Bass_(1080p).mp4
[2012-02-11 12:23:32 | 000,001,157 | ---- | M] () -- C:\Users\Serge\Desktop\Youtube Downloader HD.lnk
[2012-02-11 11:55:10 | 000,061,437 | ---- | M] () -- C:\Users\Serge\Documents\CADM.jpg
[2012-02-11 11:55:09 | 000,063,940 | ---- | M] () -- C:\Users\Serge\Documents\BACC.jpg
[2012-02-11 11:47:20 | 000,116,281 | ---- | M] () -- C:\Users\Serge\Documents\Diplômes.pdf
[2012-02-11 11:46:30 | 000,054,217 | ---- | M] () -- C:\Users\Serge\Documents\Sans titre1.pdf
[2012-02-11 11:46:24 | 000,063,511 | ---- | M] () -- C:\Users\Serge\Documents\Sans titre.pdf
[2012-02-11 01:05:25 | 000,002,192 | ---- | M] () -- C:\Users\Public\Desktop\CyberLink PowerDVD 11.lnk
[2012-02-11 00:58:03 | 000,002,026 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012-02-10 21:53:10 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\BitTorrent.lnk
[2012-02-04 15:25:12 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_lgandadb_01005.Wdf
[2012-02-03 22:16:17 | 000,000,892 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2012-02-03 13:57:37 | 000,002,092 | ---- | M] () -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012-02-03 13:57:37 | 000,002,068 | ---- | M] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012-02-03 11:25:09 | 000,042,095 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2012-02-03 11:18:01 | 000,042,095 | ---- | M] () -- C:\ProgramData\nvModes.001
========== Files Created - No Company Name ========== [2012-03-03 11:40:40 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012-03-03 11:40:40 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012-03-03 11:40:40 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012-03-03 11:40:40 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012-03-03 11:40:40 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012-03-01 18:29:57 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2012-03-01 18:29:57 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2012-02-28 17:42:13 | 000,001,200 | ---- | C] () -- C:\Users\Public\Desktop\Deal Or No Deal.lnk
[2012-02-27 19:04:28 | 000,345,600 | ---- | C] () -- C:\Users\Serge\Desktop\impot.exe
[2012-02-27 18:15:14 | 000,002,975 | ---- | C] () -- C:\Users\Serge\Desktop\HiJackThis.lnk
[2012-02-27 17:20:45 | 000,001,907 | ---- | C] () -- C:\Users\Public\Desktop\ImpôtRapide 2008.lnk
[2012-02-27 17:18:38 | 000,001,055 | ---- | C] () -- C:\Users\Public\Desktop\ImpôtRapide 2009.lnk
[2012-02-27 17:16:06 | 000,001,907 | ---- | C] () -- C:\Users\Public\Desktop\ImpôtRapide 2010.lnk
[2012-02-27 16:29:15 | 000,050,575 | ---- | C] () -- C:\Users\Serge\Documents\billets madonna.pdf
[2012-02-27 10:59:54 | 000,004,782 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\VT20111023.022
[2012-02-27 10:56:28 | 002,125,276 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\Cat.DB
[2012-02-27 10:56:24 | 000,007,488 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012-02-27 10:56:24 | 000,000,855 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012-02-27 10:56:15 | 000,002,588 | ---- | C] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012-02-27 10:55:54 | 000,007,496 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS64.cat
[2012-02-27 10:55:54 | 000,007,468 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.cat
[2012-02-27 10:55:54 | 000,007,462 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.cat
[2012-02-27 10:55:54 | 000,007,460 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA64.cat
[2012-02-27 10:55:54 | 000,007,458 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\symnet64.cat
[2012-02-27 10:55:54 | 000,007,458 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.cat
[2012-02-27 10:55:54 | 000,007,450 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\iron.cat
[2012-02-27 10:55:54 | 000,004,782 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymVTcer.dat
[2012-02-27 10:55:54 | 000,003,434 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA.inf
[2012-02-27 10:55:54 | 000,002,852 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS.inf
[2012-02-27 10:55:54 | 000,001,441 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\SymNet.inf
[2012-02-27 10:55:54 | 000,001,438 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.inf
[2012-02-27 10:55:54 | 000,001,420 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.inf
[2012-02-27 10:55:54 | 000,000,853 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.inf
[2012-02-27 10:55:54 | 000,000,772 | R--- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\Iron.inf
[2012-02-27 10:55:54 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NISx64\1305000.091\isolate.ini
[2012-02-27 10:50:52 | 000,001,298 | ---- | C] () -- C:\Users\Serge\Desktop\Fichiers d’installation Norton.lnk
[2012-02-26 13:22:27 | 000,001,338 | ---- | C] () -- C:\Users\Public\Desktop\New Yankee in King Arthurs Court.lnk
[2012-02-25 22:01:36 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2012-02-25 22:01:02 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2012-02-25 22:00:23 | 000,002,486 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012-02-23 20:25:46 | 000,002,515 | ---- | C] () -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2012-02-23 20:25:46 | 000,002,503 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2012-02-23 20:25:46 | 000,002,491 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
[2012-02-23 20:24:29 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012-02-20 21:19:56 | 000,002,246 | ---- | C] () -- C:\Users\Serge\Desktop\Aaron Crane Paintings Come Alive.lnk
[2012-02-19 19:02:30 | 000,002,368 | ---- | C] () -- C:\Users\Serge\Desktop\Amulet of Time - Shadow of la Rochelle.lnk
[2012-02-19 14:25:54 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\mIRC.lnk
[2012-02-18 21:30:18 | 000,002,482 | ---- | C] () -- C:\Users\Serge\Desktop\Maestro 2- Notes of Life.lnk
[2012-02-16 21:23:25 | 578,189,269 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012-02-16 21:21:25 | 000,002,088 | ---- | C] () -- C:\Users\Public\Desktop\Play Malice - Two Sisters Survey.lnk
[2012-02-16 21:11:30 | 000,001,931 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Manager.lnk
[2012-02-16 21:11:30 | 000,001,248 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\More Great Games.lnk
[2012-02-14 22:49:34 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2012-02-11 12:36:14 | 000,001,137 | ---- | C] () -- C:\Users\Serge\Desktop\BID Queue Manager.lnk
[2012-02-11 12:36:14 | 000,001,071 | ---- | C] () -- C:\Users\Serge\Desktop\Bulk Image Downloader.lnk
[2012-02-11 12:23:45 | 102,933,364 | ---- | C] () -- C:\Users\Serge\Documents\Nicki Minaj - Super Bass_(1080p).mp4
[2012-02-11 12:20:55 | 000,001,157 | ---- | C] () -- C:\Users\Serge\Desktop\Youtube Downloader HD.lnk
[2012-02-11 11:55:10 | 000,061,437 | ---- | C] () -- C:\Users\Serge\Documents\CADM.jpg
[2012-02-11 11:55:09 | 000,063,940 | ---- | C] () -- C:\Users\Serge\Documents\BACC.jpg
[2012-02-11 11:47:20 | 000,116,281 | ---- | C] () -- C:\Users\Serge\Documents\Diplômes.pdf
[2012-02-11 11:46:30 | 000,054,217 | ---- | C] () -- C:\Users\Serge\Documents\Sans titre1.pdf
[2012-02-11 11:46:24 | 000,063,511 | ---- | C] () -- C:\Users\Serge\Documents\Sans titre.pdf
[2012-02-11 11:40:58 | 000,142,128 | ---- | C] () -- C:\Windows\wiainst64.exe
[2012-02-11 01:05:25 | 000,002,192 | ---- | C] () -- C:\Users\Public\Desktop\CyberLink PowerDVD 11.lnk
[2012-02-11 00:58:03 | 000,002,026 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2012-02-11 00:58:02 | 000,002,465 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2012-02-11 00:58:02 | 000,002,453 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
[2012-02-11 00:23:41 | 000,000,928 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1365876331-3669831383-1828126602-1001UA.job
[2012-02-11 00:23:40 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1365876331-3669831383-1828126602-1001Core.job
[2012-02-10 21:53:10 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\BitTorrent.lnk
[2012-02-04 15:25:12 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_lgandadb_01005.Wdf
[2012-02-04 09:46:24 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\CommonDL.dll
[2012-02-04 09:46:24 | 000,002,413 | ---- | C] () -- C:\Windows\SysWow64\lgAxconfig.ini
[2012-02-03 22:15:55 | 000,000,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2012-02-03 13:57:37 | 000,002,092 | ---- | C] () -- C:\Users\Serge\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012-02-03 13:57:37 | 000,002,080 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2012-02-03 13:57:37 | 000,002,068 | ---- | C] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012-02-03 11:58:04 | 000,007,384 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2012-02-03 11:58:03 | 000,061,440 | ---- | C] () -- C:\Windows\SysWow64\nvvcompiler.dll
[2012-02-03 11:05:38 | 000,042,095 | ---- | C] () -- C:\ProgramData\nvModes.001
[2012-02-03 11:05:37 | 000,042,095 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2012-01-31 08:42:08 | 000,080,384 | ---- | C] () -- C:\Windows\smgrinst.exe
[2012-01-31 08:42:02 | 000,113,768 | ---- | C] () -- C:\Windows\Wiainst.exe
[2012-01-31 08:40:26 | 000,482,408 | ---- | C] () -- C:\Windows\ssndii.exe
[2012-01-26 19:53:29 | 000,000,120 | ---- | C] () -- C:\Windows\inst20.dat
[2012-01-26 19:53:29 | 000,000,034 | ---- | C] () -- C:\Windows\instusers20.dat
[2012-01-24 18:12:23 | 000,735,230 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012-01-24 16:55:59 | 000,073,220 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2012-01-24 16:55:59 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2012-01-24 16:55:59 | 000,029,114 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2012-01-24 16:55:59 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2012-01-24 16:55:59 | 000,021,021 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2012-01-24 16:55:59 | 000,015,670 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2012-01-24 16:55:59 | 000,013,280 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2012-01-24 16:55:59 | 000,010,673 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2012-01-24 16:55:59 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2012-01-24 16:55:59 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2012-01-24 16:55:59 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2012-01-24 16:55:59 | 000,001,137 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2012-01-24 16:55:59 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2012-01-24 16:55:59 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2012-01-24 16:55:59 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2012-01-24 16:55:59 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2012-01-23 23:55:03 | 000,196,608 | ---- | C] () -- C:\Windows\SysWow64\KBDDGR1.DLL
[2012-01-11 16:07:44 | 000,118,784 | ---- | C] () -- C:\Windows\SysWow64\formodpar.exe
[2011-05-16 12:31:44 | 000,008,592 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
========== Alternate Data Streams ========== @Alternate Data Stream - 181 bytes -> C:\ProgramData\TEMP:D9C49B45
@Alternate Data Stream - 180 bytes -> C:\ProgramData\TEMP:4CD3F344
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:728B799F
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E3D8C69A
< End of report >