re
======Scheduled tasks folder======
C:\\WINDOWS\\tasks\\Maintenance en 1 clic.job
======Registry dump======
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\\Program Files\\Fichiers communs\\Adobe\\Acrobat\\ActiveX\\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\\Program Files\\Real\\RealPlayer\\rpbrowserrecordplugin.dll [2007-12-11 370296]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll [2008-01-28 1554256]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\\Program Files\\Java\\jre6\\bin\\ssv.dll [2008-12-03 320920]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\\Program Files\\Java\\jre6\\bin\\jp2ssv.dll [2008-12-03 34816]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\\Program Files\\Java\\jre6\\lib\\deploy\\jqs\\ie\\jqs_plugin.dll [2008-12-03 73728]
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
"avast!"=C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe [2008-11-26 81000]
"SunJavaUpdateSched"=C:\\Program Files\\Java\\jre6\\bin\\jusched.exe [2008-12-03 136600]
"QuickTime Task"=C:\\Program Files\\QuickTime\\qttask.exe [2008-09-06 413696]
"WinampAgent"=C:\\Program Files\\Winamp\\winampa.exe [2008-08-03 36352]
"Adobe Reader Speed Launcher"=C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe [2008-10-15 39792]
"MSConfig"=C:\\WINDOWS\\pchealth\\helpctr\\Binaries\\MSCONFIG.EXE [2008-04-13 172544]
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
"ctfmon.exe"=C:\\WINDOWS\\system32\\ctfmon.exe [2008-04-13 15360]
"WeatherEye"=C:\\Program Files\\MétéoMédia\\MétéoÉclair\\WeatherEye.exe [2009-01-16 4519832]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\Adobe Photo Downloader]
C:\\Program Files\\Adobe\\Photoshop Album Edition Découverte\\3.0\\Apps\\apdproxy.exe [2005-06-23 57344]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\Adobe Reader Speed Launcher]
C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\Ceedo AutoDetect]
C:\\DOCUME~1\\user\\LOCALS~1\\Temp\\AutoDetect.exe [2007-11-15 374288]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\ctfmon.exe]
C:\\WINDOWS\\system32\\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\PinnacleDriverCheck]
C:\\WINDOWS\\system32\\PSDrvCheck.exe [2004-03-10 406016]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\QuickTime Task]
C:\\Program Files\\QuickTime\\qttask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\SpybotSD TeaTimer]
C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\SunJavaUpdateSched]
C:\\Program Files\\Java\\jre6\\bin\\jusched.exe [2008-12-03 136600]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\type32]
C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe [2004-06-03 172032]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\VTTimer]
C:\\WINDOWS\\system32\\VTTimer.exe [2003-05-07 36864]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupreg\\WinampAgent]
C:\\Program Files\\Winamp\\winampa.exe [2008-08-03 36352]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupfolder\\C:^Documents and Settings^user^Menu Démarrer^Programmes^Démarrage^ADeck.lnk]
C:\\PROGRA~1\\VIAudioi\\SBADeck\\ADeck.exe [2004-05-10 7917056]
[HKEY_LOCAL_MACHINE\\software\\microsoft\\shared tools\\msconfig\\startupfolder\\C:^Documents and Settings^user^Menu Démarrer^Programmes^Démarrage^Webshots.lnk]
C:\\PROGRA~1\\Webshots\\Launcher.exe [2009-01-10 157000]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Notify\\WgaLogon]
C:\\WINDOWS\\system32\\WgaLogon.dll [2008-09-05 267304]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\\WINDOWS\\system32\\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\\WINDOWS\\system32\\upnpui.dll [2008-04-13 240128]
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\control\\securityproviders]
"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\aawservice]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\aawservice]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\nm]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\nm.sys]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\UploadMgr]
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\explorer]
"NoDriveAutoRun"=FFFFFFFF
"NoDriveTypeAutoRun"=36
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\services\\sharedaccess\\parameters\\firewallpolicy\\standardprofile\\authorizedapplications\\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Disabled:Microsoft Management Console"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\\Program Files\\Photo Story 3 for Windows\\PhotoStory3.exe"="C:\\Program Files\\Photo Story 3 for Windows\\PhotoStory3.exe:*:Enabled:Photo Story 3 for Windows"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Deer Hunter 3\\Deer Hunter 3.exe"="C:\\Program Files\\Deer Hunter 3\\Deer Hunter 3.exe:*:Enabled:Deer Hunter 3"
"C:\\Documents and Settings\\user\\Mes documents\\StubInstaller.exe"="C:\\Documents and Settings\\user\\Mes documents\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\services\\sharedaccess\\parameters\\firewallpolicy\\domainprofile\\authorizedapplications\\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_CURRENT_USER\\software\\microsoft\\windows\\currentversion\\explorer\\mountpoints2\\{42a81d3f-81c6-11dc-9b8b-00138f240de8}]
shell\\AutoRun\\command - K:\\Autorun.exe /run
shell\\Shell00\\command - K:\\Autorun.exe /run
shell\\Shell01\\command - K:\\Autorun.exe /action
shell\\Shell02\\command - K:\\Autorun.exe /uninstall
======List of files/folders created in the last 1 months======
2009-01-24 11:37:10 ----D---- C:\\rsit
2009-01-23 01:09:05 ----N---- C:\\WINDOWS\\system32\\difxapi.dll
2009-01-23 01:09:05 ----D---- C:\\Program Files\\VIA
2009-01-23 01:04:18 ----AD---- C:\\Program Files\\Vinyl_V700b
2009-01-16 14:51:17 ----D---- C:\\Documents and Settings\\user\\Application Data\\Obsidium
2009-01-16 14:51:12 ----D---- C:\\Program Files\\AudioComparer
2009-01-14 01:22:42 ----HDC---- C:\\WINDOWS\\$NtUninstallKB958687$
2009-01-10 23:45:51 ----D---- C:\\Program Files\\Diettes et tics
2009-01-10 14:00:25 ----D---- C:\\Documents and Settings\\user\\Application Data\\agi
2009-01-10 14:00:24 ----D---- C:\\Documents and Settings\\All Users\\Application Data\\agi
2009-01-10 13:59:56 ----D---- C:\\Program Files\\AGI
2009-01-10 00:57:19 ----D---- C:\\Documents and Settings\\user\\Application Data\\ESTSoft
======List of files/folders modified in the last 1 months======
2009-01-24 11:37:20 ----D---- C:\\WINDOWS\\Prefetch
2009-01-24 11:05:52 ----D---- C:\\WINDOWS\\Temp
2009-01-24 11:05:16 ----RASH---- C:\\boot.ini
2009-01-24 11:05:16 ----A---- C:\\WINDOWS\\win.ini
2009-01-24 11:05:16 ----A---- C:\\WINDOWS\\system.ini
2009-01-24 00:58:22 ----A---- C:\\WINDOWS\\SchedLgU.Txt
2009-01-23 15:40:49 ----D---- C:\\WINDOWS\\system32\\CatRoot2
2009-01-23 15:39:09 ----D---- C:\\WINDOWS\\pss
2009-01-23 14:38:21 ----SHD---- C:\\WINDOWS\\Installer
2009-01-23 06:38:42 ----D---- C:\\WINDOWS
2009-01-23 01:10:34 ----HD---- C:\\Program Files\\InstallShield Installation Information
2009-01-23 01:10:06 ----D---- C:\\Config.Msi
2009-01-23 01:09:55 ----RSHDC---- C:\\WINDOWS\\system32\\dllcache
2009-01-23 01:09:50 ----D---- C:\\WINDOWS\\system32\\drivers
2009-01-23 01:09:50 ----D---- C:\\WINDOWS\\system32
2009-01-23 01:09:45 ----HD---- C:\\WINDOWS\\inf
2009-01-23 01:09:44 ----D---- C:\\WINDOWS\\system32\\ReinstallBackups
2009-01-23 01:09:05 ----D---- C:\\Program Files
2009-01-22 23:15:27 ----A---- C:\\WINDOWS\\LEXSTAT.INI
2009-01-22 14:41:04 ----D---- C:\\WINDOWS\\Debug
2009-01-21 16:32:25 ----D---- C:\\WINDOWS\\BDOSCAN8
2009-01-21 08:25:57 ----D---- C:\\Program Files\\Panda Security
2009-01-21 08:21:37 ----SD---- C:\\WINDOWS\\Downloaded Program Files
2009-01-20 20:24:36 ----D---- C:\\Documents and Settings\\All Users\\Application Data\\Adobe
2009-01-20 20:24:27 ----D---- C:\\Program Files\\Fichiers communs\\Adobe
2009-01-20 20:24:27 ----D---- C:\\Program Files\\Adobe
2009-01-20 17:47:02 ----A---- C:\\WINDOWS\\NeroDigital.ini
2009-01-20 16:57:52 ----D---- C:\\Program Files\\totalcmd
2009-01-20 14:38:44 ----D---- C:\\WINDOWS\\Minidump
2009-01-20 14:28:31 ----A---- C:\\WINDOWS\\wincmd.ini
2009-01-19 17:57:58 ----D---- C:\\Documents and Settings\\user\\Application Data\\IconTweaker
2009-01-19 17:57:58 ----D---- C:\\Documents and Settings\\All Users\\Application Data\\IconTweaker
2009-01-19 17:33:07 ----D---- C:\\Program Files\\Bonjour
2009-01-18 12:26:29 ----D---- C:\\Program Files\\Winamp
2009-01-16 14:42:58 ----D---- C:\\Program Files\\Fichiers communs
2009-01-15 01:41:33 ----D---- C:\\Documents and Settings\\All Users\\Application Data\\Microsoft Help
2009-01-14 01:22:17 ----HD---- C:\\WINDOWS\\$hf_mig$
2009-01-11 11:18:05 ----D---- C:\\Program Files\\Webshots
2009-01-10 14:00:09 ----A---- C:\\WINDOWS\\system32\\pywintypes25.dll
2009-01-10 14:00:09 ----A---- C:\\WINDOWS\\system32\\pythoncom25.dll
2009-01-10 14:00:09 ----A---- C:\\WINDOWS\\system32\\python25.dll
2009-01-09 17:35:30 ----A---- C:\\WINDOWS\\system32\\MRT.exe
2009-01-06 14:55:17 ----D---- C:\\WINDOWS\\Help
======
_________________
L'essentiel est invisible pour les yeux
