Deckard's System Scanner v20071014.68
Run by Matthias on 2008-09-20 15:31:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-09-20 13:31:39 UTC - RP1 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Matthias.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:33:44, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Xion\Xion.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Matthias\Mes documents\Téléchargements\dss\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Matthias.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://global.acer.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.10\RivaTuner.exe" /S
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia....ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\RpcAgentSrv.exe
--
End of file - 5453 bytes
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,23
.inf - inffile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.reg - regfile - shell\open\command - regedit.exe "%1" %*
.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 giveio - c:\windows\system32\giveio.sys
R0 speedfan - c:\windows\system32\speedfan.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
R1 cpuidlep (CpuIdle Pro System Driver) - c:\windows\system32\drivers\cpuidlep.sys
R1 SysTool (SysTool Overclocking Utility) - c:\windows\system32\drivers\systool.sys <Not Verified; ; Low-Level Driver>
R2 nxsIO32 (NextSensor Kernel I/O Driver) - c:\windows\system32\drivers\nxsio32.sys
R3 NTIDrvr (Upper Class Filter Driver) - c:\windows\system32\drivers\ntidrvr.sys <Not Verified; NewTech Infosystems, Inc.; >
R3 RivaTuner32 - c:\program files\rivatuner v2.10\rivatuner32.sys
S0 NVStrap - c:\windows\system32\drivers\nvstrap.sys
S1 avipbb - c:\windows\system32\drivers\avipbb.sys (file missing)
S3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
S3 NETw4x32 (Pilote de carte Intel(R) Wireless WiFi Link pour Windows XP 32 bits) - c:\windows\system32\drivers\netw4x32.sys (file missing)
S3 Point32 (Microsoft IntelliPoint Filter Driver) - c:\windows\system32\drivers\point32.sys (file missing)
S3 TSP - c:\windows\system32\drivers\klif.sys (file missing)
S4 s24trans (Transport RLAN) - c:\windows\system32\drivers\s24trans.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S3 FLEXnet Licensing Service - "c:\program files\fichiers communs\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Description: Agere Systems HDA Modem
Device ID: HDAUDIO\FUNC_02&VEN_11C1&DEV_3026&SUBSYS_10250100&REV_1006\4&25289786&0&0101
Manufacturer: Agere
Name: Agere Systems HDA Modem
PNP Device ID: HDAUDIO\FUNC_02&VEN_11C1&DEV_3026&SUBSYS_10250100&REV_1006\4&25289786&0&0101
Service: Modem
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_01071025&REV_01\4&192AC53F&0&00E0
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_01071025&REV_01\4&192AC53F&0&00E0
Service: RTL8023xp
-- Scheduled Tasks -------------------------------------------------------------
2008-09-20 15:19:00 318 --a------ C:\WINDOWS\Tasks\GlaryInitialize.job
2008-09-15 22:44:00 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-08-20 and 2008-09-20 -----------------------------
2008-09-20 15:33:11 0 d-------- C:\Program Files\Trend Micro
2008-09-20 09:17:37 0 d--hs---- C:\Documents and Settings\Matthias\Recent
2008-09-19 18:40:32 0 d--h----- C:\$AVG8.VAULT$
2008-09-19 18:04:22 0 d-------- C:\Program Files\ZNsoft Corporation
2008-09-17 22:23:16 3065 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2008-09-17 22:21:32 3625 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2008-09-17 22:19:14 0 d-------- C:\Documents and Settings\Matthias\Application Data\AccurateRip
2008-09-17 22:19:12 13783 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2008-09-17 22:19:08 0 d-------- C:\Program Files\Illustrate
2008-09-17 16:10:51 0 d-------- C:\Program Files\Windows Live Safety Center
2008-09-17 16:02:45 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-17 16:02:42 0 d-------- C:\Program Files\AVG
2008-09-17 16:02:42 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-17 15:42:39 0 d-------- C:\Documents and Settings\Matthias\Tracing
2008-09-17 15:40:49 0 d-------- C:\Program Files\Microsoft
2008-09-17 15:30:49 0 d-------- C:\Program Files\Fichiers communs\Windows Live
2008-09-17 15:24:28 0 d-------- C:\Program Files\TrustPort
2008-09-17 15:24:17 0 d-------- C:\Program Files\Fichiers communs\TrustPort
2008-09-16 18:20:59 0 d-------- C:\Documents and Settings\Matthias\Application Data\F-Secure
2008-09-16 18:11:16 0 d-------- C:\Program Files\F-Secure Internet Security
2008-09-16 18:10:52 0 d-------- C:\Documents and Settings\All Users\Application Data\fssg
2008-09-16 18:10:01 0 d-------- C:\Documents and Settings\All Users\Application Data\f-secure
2008-09-16 15:24:25 0 d-------- C:\Documents and Settings\Matthias\Application Data\CVitae
2008-09-16 15:24:08 0 d-------- C:\Program Files\CVitae
2008-09-16 15:04:59 0 d-------- C:\Games
2008-09-16 10:50:56 0 d-------- C:\Program Files\EAGLE-4.15
2008-09-16 10:50:35 299520 --a------ C:\WINDOWS\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2008-09-16 10:50:10 0 d-------- C:\Documents and Settings\Matthias\WINDOWS
2008-09-16 08:20:08 0 d-------- C:\Program Files\Notepad++
2008-09-16 08:20:08 0 d-------- C:\Documents and Settings\Matthias\Application Data\Notepad++
2008-09-16 08:17:16 0 d-------- C:\MinGWStudio
2008-09-15 22:49:16 0 d-------- C:\Program Files\Kaspersky Lab
2008-09-15 22:43:04 0 d-------- C:\Program Files\iPod
2008-09-15 22:43:03 0 d-------- C:\Program Files\iTunes
2008-09-15 22:43:03 0 d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-15 22:42:00 0 d-------- C:\Program Files\QuickTime
2008-09-15 22:38:12 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-15 22:34:00 0 d-------- C:\Documents and Settings\Matthias\Application Data\Desktopicon
2008-09-15 22:26:51 0 d-------- C:\Documents and Settings\Matthias\Application Data\vlc
2008-09-15 22:24:34 0 d-------- C:\Program Files\Safari
2008-09-15 20:28:04 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-09-15 19:23:23 0 d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-09-15 18:59:04 0 d-------- C:\Documents and Settings\Matthias\Application Data\CadSoft
2008-09-14 21:37:33 1101824 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-09-14 21:37:33 1724416 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-09-14 21:37:33 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-09-14 21:37:33 1499136 --a------ C:\WINDOWS\system32\nview.dll
2008-09-14 21:35:07 0 d-------- C:\WINDOWS\nview
2008-09-14 21:32:39 286720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2008-09-14 21:07:24 0 d-------- C:\Program Files\AquaMark3
2008-09-14 20:17:32 0 d-------- C:\Documents and Settings\Matthias\Application Data\Ubisoft
2008-09-14 20:17:32 0 d-------- C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-09-10 16:48:25 0 d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-10 16:23:58 0 d-------- C:\Program Files\Fichiers communs\Macrovision Shared
2008-09-09 17:16:09 0 d-------- C:\Documents and Settings\LocalService\Application Data\Real
2008-09-08 18:56:54 0 d-------- C:\Program Files\Paint.NET
2008-09-08 00:16:40 0 d-------- C:\Documents and Settings\Matthias\dwhelper
2008-09-07 23:49:38 0 d-------- C:\Documents and Settings\Matthias\Application Data\GlarySoft
2008-09-07 23:47:41 0 d-------- C:\Program Files\Glary Utilities
2008-09-07 10:40:05 21840 --a------ C:\WINDOWS\system32\SIntfNT.dll
2008-09-07 10:40:05 17212 --a------ C:\WINDOWS\system32\SIntf32.dll
2008-09-07 10:40:05 12067 --a------ C:\WINDOWS\system32\SIntf16.dll
2008-09-07 10:23:04 26469 --a------ C:\WINDOWS\DIIUnin.dat
2008-09-07 10:22:59 2829 --a------ C:\WINDOWS\DIIUnin.pif
2008-09-07 10:22:58 102400 --a------ C:\WINDOWS\DIIUnin.exe <Not Verified; Blizzard Entertainment; Désinstallation de Diablo II>
2008-09-06 23:45:43 0 d-------- C:\Program Files\CCleaner
2008-09-06 23:27:22 0 d-------- C:\WINDOWS\pss
2008-09-06 21:13:26 0 d-------- C:\Program Files\SiSoftware
2008-09-06 19:30:42 0 d-------- C:\Program Files\Zuma Deluxe
2008-09-06 17:08:27 10 --a------ C:\WINDOWS\popcinfo.dat
2008-09-06 13:27:44 319488 --a------ C:\WINDOWS\system32\AegisI5Installer.exe <Not Verified; ; AegisInstall Application>
2008-09-03 22:29:50 0 d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-09-03 22:29:48 0 d-------- C:\Program Files\DVD Shrink
2008-09-01 18:07:14 0 d-------- C:\Program Files\RivaTuner v2.10
2008-08-31 14:38:02 0 d-------- C:\Program Files\Microsoft Bootvis
2008-08-29 09:53:50 61440 --a------ C:\WINDOWS\system32\dnssd.dll <Not Verified; Apple Inc.; Bonjour>
2008-08-23 20:24:31 0 d-------- C:\Documents and Settings\Matthias\Application Data\dvdcss
2008-08-22 11:15:49 0 d--hs---- C:\Diskeeper
2008-08-20 17:46:03 0 d-------- C:\Program Files\Paragon Software
-- Find3M Report ---------------------------------------------------------------
2008-09-17 21:48:48 0 d-------- C:\Documents and Settings\Matthias\Application Data\uTorrent
2008-09-17 15:40:01 0 d-------- C:\Program Files\Windows Live
2008-09-17 15:30:49 0 d-------- C:\Program Files\Fichiers communs
2008-09-17 15:13:37 509314 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-09-17 15:13:37 85568 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-09-15 22:47:02 0 d-------- C:\Program Files\Apple Software Update
2008-09-15 22:42:33 0 d-------- C:\Program Files\Bonjour
2008-09-15 22:42:02 0 d-------- C:\Program Files\Fichiers communs\Apple
2008-09-15 22:28:18 0 d-------- C:\Documents and Settings\Matthias\Application Data\Apple Computer
2008-09-11 21:54:57 0 d-------- C:\Documents and Settings\Matthias\Application Data\Adobe
2008-09-11 21:33:09 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-10 16:34:07 0 d-------- C:\Program Files\Fichiers communs\Adobe
2008-09-08 19:04:23 2287104 --a------ C:\WINDOWS\system32\TUKernel.exe <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-09-08 00:10:46 0 d-------- C:\Program Files\Messenger Plus! Live
2008-09-08 00:10:46 0 d-------- C:\Program Files\eMule
2008-09-06 19:21:29 0 d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-01 18:14:11 0 d-------- C:\Program Files\Messenger
2008-09-01 18:11:12 0 d-------- C:\Program Files\Microsoft Silverlight
2008-08-31 19:21:36 0 d-------- C:\Documents and Settings\Matthias\Application Data\skypePM
2008-08-20 17:46:03 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-19 20:38:40 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-08-19 20:38:36 0 d-------- C:\Documents and Settings\Matthias\Application Data\Real
2008-08-19 20:22:39 0 d-------- C:\Documents and Settings\Matthias\Application Data\Media Player Classic
2008-08-16 11:13:54 0 d-------- C:\Documents and Settings\Matthias\Application Data\InstallShield
2008-08-14 21:20:45 2560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-08-14 19:44:38 0 d-------- C:\Program Files\Movie Maker
2008-08-14 19:42:49 5300 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-08-14 19:42:48 72066 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-08-13 20:16:02 45056 --a------ C:\WINDOWS\system32\sstunst3.exe <Not Verified; Stardust Software; Stardust Screen Saver Toolkit 2004>
2008-08-11 11:50:21 4096 --a------ C:\WINDOWS\d3dx.dat
2008-08-11 11:28:07 6656 --a------ C:\WINDOWS\system32\lpcio.dll
2008-08-10 22:12:18 0 d-------- C:\Documents and Settings\Matthias\Application Data\Ashampoo
2008-08-10 22:10:48 0 d-------- C:\Program Files\Ashampoo
2008-08-10 21:38:02 0 d-------- C:\Program Files\MSBuild
2008-08-10 21:34:04 0 d-------- C:\Program Files\Reference Assemblies
2008-08-06 10:26:18 0 d-------- C:\Program Files\DAEMON Tools Lite
2008-08-06 10:22:35 0 d-------- C:\Documents and Settings\Matthias\Application Data\DAEMON Tools
2008-08-06 10:20:56 0 d-------- C:\Documents and Settings\Matthias\Application Data\Sun
2008-08-06 02:27:34 0 d-------- C:\Program Files\Java
2008-08-06 02:22:09 0 d-------- C:\Program Files\Fichiers communs\Java
2008-08-05 23:08:08 0 d-------- C:\Program Files\Sony Ericsson
2008-08-05 11:08:41 0 d-------- C:\Documents and Settings\Matthias\Application Data\Sony
2008-08-05 11:05:39 0 d-------- C:\Program Files\Fichiers communs\Sony Shared
2008-08-05 11:05:13 0 d-------- C:\Program Files\Sony
2008-08-05 11:03:56 0 d-------- C:\Program Files\Sony Setup
2008-08-05 09:31:02 0 d-------- C:\Program Files\TuneUp Utilities 2008
2008-07-27 03:39:53 0 d-------- C:\Documents and Settings\Matthias\Application Data\teamspeak2
2008-07-24 17:38:04 0 d-------- C:\Program Files\Teamspeak2_RC2
2008-07-15 23:14:16 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-10 23:14:31 18551 --a------ C:\WINDOWS\War3Unin.dat
2008-07-10 23:09:03 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-07-10 23:09:02 126976 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-07-10 22:20:30 262144 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-07-10 22:20:30 86016 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library>
2008-07-09 01:20:16 219648 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
11/06/2008 22:33 75128 --a------ C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
02/09/2008 21:02 75272 --a------ C:\Program Files\Windows Live\Messenger\wlchtc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.10\RivaTuner.exe" [16/09/2008 19:15]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [17/09/2008 16:30]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [24/08/2008 02:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"=00000000
"NoTrayItemsDisplay"=0 (0x0)
"NoLowDiskSpaceChecks"=1 (0x1)
"ClearRecentDocsOnExit"=1 (0x1)
"NoSMBalloonTip"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"speedfan"=C:\Monitoring\SpeedFan\speedfan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RTHDCPL"=RTHDCPL.EXE
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"AzMixerSel"=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
"Alcmtr"=ALCMTR.EXE
"AGRSMMSG"=AGRSMMSG.exe
"preload"=C:\Windows\RUNXMLPL.exe
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bfeeda4-777c-11dd-9a71-001302263d52}]
AutoRun\command- H:\ClickMe.exe
-- Hosts -----------------------------------------------------------------------
127.0.0.1 localhost
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
www.032439.com
9227 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-09-20 15:34:35 ------------