Bibou le forum
Vous souhaitez réagir à ce message ? Créez un compte en quelques clics ou connectez-vous pour continuer.

Bibou Le Forum
Portail sur la sécurité
 
PortailAccueilDernières imagesRechercherS'enregistrerConnexion
Le Deal du moment : -28%
Précommande : Smartphone Google Pixel 8a 5G ...
Voir le deal
389 €

 

 [Fermé] FAKE Cookies messagerie Voila

Aller en bas 
3 participants
AuteurMessage
picmin
Bibou
Bibou



Masculin
Nombre de messages : 17
Age : 59
Localisation : GRENOBLE
Date d'inscription : 26/06/2011

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeMer 29 Juin 2011 - 13:16

bonjour

je n'arrive plus à accéder a la messagerie VOILA, il met met en rouge un message d'erreur FAKE Cookies messagerie Voila, cela peut il venir de mon ordinateur ou plutôt de leur serveur

merci

voila le rapport HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:55, on 29/06/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20861)
Boot mode: Normal

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
I:\WINDOWS\Explorer.EXE
I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
I:\Program Files\IDT\WDM\sttray.exe
I:\Program Files\Avira\AntiVir Desktop\avgnt.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Documents and Settings\Administrateur\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
I:\WINDOWS\system32\spoolsv.exe
i:\program files\idt\xpv_5902_012208\wdm\STacSV.exe
I:\Program Files\Avira\AntiVir Desktop\sched.exe
I:\Program Files\Avira\AntiVir Desktop\avguard.exe
I:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
I:\Program Files\Avira\AntiVir Desktop\avshadow.exe
I:\Program Files\Bonjour\mDNSResponder.exe
I:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
I:\Program Files\Java\jre6\bin\jqs.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\StkASv2K.exe
I:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\Program Files\Mozilla Firefox\plugin-container.exe
I:\Documents and Settings\Administrateur\Mes documents\Téléchargements\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - I:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - J:\UTILITAIRE\solid converter\SCPDF\ExploreExtPDF.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - I:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - I:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - I:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - J:\UTILITAIRE\solid converter\SCPDF\ExploreExtPDF.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - I:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [StartCCC] "I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [avgnt] "I:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "I:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON SX210 Series] I:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFDE.EXE /FU "I:\WINDOWS\TEMP\E_S70.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Google Update] "I:\Documents and Settings\Administrateur\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O8 - Extra context menu item: Barre RoboForm - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Download with Rapget - I:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.547\RapGet www.tripper.fr by tof 59\rapget.htm
O8 - Extra context menu item: Enregistrer le formulaire - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Free YouTube to MP3 Converter - I:\Documents and Settings\Administrateur\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Personnaliser le menu - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - I:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - I:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - I:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://I:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr
O15 - Trusted Zone: http://www.everestpoker.com
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} (CamfrogWEB Advanced Unicode Control) - http://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - I:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - I:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - I:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - I:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - I:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - I:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - I:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - I:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - i:\program files\idt\xpv_5902_012208\wdm\STacSV.exe
O23 - Service: Syntek STK1160 Service (StkASSrv) - Syntek America Inc. - I:\WINDOWS\System32\StkASv2K.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - I:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 9913 bytes
Revenir en haut Aller en bas
ouzopower
Moderateurs (trices)
Moderateurs (trices)
ouzopower


Masculin
Nombre de messages : 4422
Age : 61
Localisation : au fond du verre
Humeur : de soif !
Date d'inscription : 30/03/2008

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeMer 29 Juin 2011 - 16:03

Bonjour
le rapport hijackthis ne suffit pas pour établir un nettoyage complet.
Merci de poster un rapport OTL ou ZHPDiag afin qu'un helper puisse te prendre en charge

http://www.bibou0007.com/t2887-procedure-a-suivre-avant-de-poster
Revenir en haut Aller en bas
picmin
Bibou
Bibou



Masculin
Nombre de messages : 17
Age : 59
Localisation : GRENOBLE
Date d'inscription : 26/06/2011

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeMer 29 Juin 2011 - 17:13

puis les fichiers OTL

OTL Extras logfile created on: 29/06/2011 17:09:43 - Run 1
OTL by OldTimer - Version 3.2.24.2 Folder = I:\Documents and Settings\Administrateur\Mes documents\Téléchargements
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

3,00 Gb Total Physical Memory | 2,39 Gb Available Physical Memory | 79,69% Memory free
4,84 Gb Paging File | 4,26 Gb Available in Paging File | 87,99% Paging File free
Paging file location(s): I:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = I: | %SystemRoot% = I:\WINDOWS | %ProgramFiles% = I:\Program Files
Drive H: | 246,52 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive I: | 111,67 Gb Total Space | 8,06 Gb Free Space | 7,22% Space Free | Partition Type: NTFS
Drive J: | 354,09 Gb Total Space | 15,25 Gb Free Space | 4,31% Space Free | Partition Type: NTFS

Computer Name: A8F02614C8F340C | User Name: Administrateur | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.inf [@ = inffile] -- I:\WINDOWS\System32\NOTEPAD.EXE ()
.ini [@ = inifile] -- I:\WINDOWS\System32\NOTEPAD.EXE ()
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
.txt [@ = txtfile] -- I:\WINDOWS\System32\NOTEPAD.EXE ()

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- I:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 ()
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 ()
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 ()
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 ()
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 ()
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 ()
inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 ()
inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 ()
inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 ()
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 ()
jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 ()
jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 ()
jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 ()
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 ()
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 ()
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 ()
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 ()
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" ()
vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 ()
vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 ()
vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 ()
vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 ()
wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 ()
wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 ()
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "I:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "I:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "I:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "I:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "I:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"I:\Program Files\MSN Messenger\livecall.exe" = I:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"J:\jeux\PRINCE OF PERSIA\PrinceOfPersia_Launcher.exe" = J:\jeux\PRINCE OF PERSIA\PrinceOfPersia_Launcher.exe:*:Enabled:Prince of Persia Update -- (Ubisoft)
"I:\Program Files\Moovida\moovida.exe" = I:\Program Files\Moovida\moovida.exe:*:Enabled:Moovida Media Center -- ()
"I:\Program Files\Java\jre6\bin\java.exe" = I:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"J:\DOSSIER GUILLAUME\JEUX\steam.exe" = J:\DOSSIER GUILLAUME\JEUX\steam.exe:*:Enabled:Steam -- (Valve Corporation)
"I:\Program Files\Sports Interactive\Football Manager 2010\fm.exe" = I:\Program Files\Sports Interactive\Football Manager 2010\fm.exe:*:Enabled:Football Manager 2010 -- (Sports Interactive)
"I:\Program Files\Java\jre6\bin\javaw.exe" = I:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"I:\Program Files\Google\Google Earth\client\googleearth.exe" = I:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
"I:\Program Files\Sports Interactive\Football Manager 2011 Russian\fm.exe" = I:\Program Files\Sports Interactive\Football Manager 2011 Russian\fm.exe:*:Enabled:Football Manager 2011 -- (Sports Interactive)
"I:\Program Files\Java\jre6\launch4j-tmp\frd.exe" = I:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"I:\WINDOWS\system32\dplaysvr.exe" = I:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\half-life 2 deathmatch\hl2.exe" = J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2
"I:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe" = I:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS -- (France Telecom SA)
"J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\day of defeat source\hl2.exe" = J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\day of defeat source\hl2.exe:*:Enabled:Day of Defeat: Source
"J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\counterstrike source beta\hl2.exe" = J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\counterstrike source beta\hl2.exe:*:Enabled:Counter-Strike: Source Beta -- ()
"J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\counter-strike source\hl2.exe" = J:\DOSSIER GUILLAUME\JEUX\SteamApps\nantais380\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0525B2F9-CF32-31FB-2521-C5CD713EF94B}" = Catalyst Control Center Localization Czech
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{09766D45-F48F-2050-C720-EC039E72257C}" = CCC Help Spanish
"{09E7DBAC-713D-D170-C693-51824043B98E}" = CCC Help Norwegian
"{0BD83598-C2EF-3343-847B-7D2E84599128}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA
"{0E997922-CD3B-45F7-AA40-9F542F6FA161}_is1" = Photoshop CS3
"{133742BA-6F46-4D3E-85AF-78631D9AD8B8}" = Installation Windows Live
"{14592A8E-4DA6-4338-A9D5-E16449647EC3}" = Championship Manager L'Entraîneur 2010 (Données Patch de septembre)
"{1B30DF52-232D-3E72-2090-8BF1A74252F5}" = CCC Help Russian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live
"{21DC3202-0FD2-FC83-7605-F4CDBBBC6B2D}" = CCC Help Korean
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 24
"{2B6A6960-7023-EF3F-C7DC-F8BF7FCEC636}" = CCC Help Chinese Standard
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{2F6BB945-6B61-66C3-29D6-8A2CCDCF81A1}" = CCC Help Hungarian
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java(TM) SE Development Kit 6 Update 14
"{37E871A8-A441-FD0D-9824-3FC102EC83A9}" = CCC Help Portuguese
"{389A87A0-A2A8-4E05-87B7-074D8B1AEAB2}" = MP Manager
"{3CDF9C0F-6C77-4307-80A6-0A9D47C174D8}_is1" = Call of Duty Modern Warfare 2
"{3E31821C-7917-367E-938E-E65FC413EA31}" = Microsoft .NET Framework 3.5 Language Pack SP1 - fra
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{40CB06A4-FE29-240B-9B66-AF6BBDDBAA52}" = CCC Help Polish
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{445B183D-F4F1-45C8-B9DB-F11355CA657B}" = Windows Live Messenger
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A9B719C-604D-78AC-D24B-9F2093EC240E}" = CCC Help Czech
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{530927C2-7197-EADF-0598-6775CA4821DC}" = Catalyst Control Center Graphics Full Existing
"{57BAF854-3996-4F73-B097-4FE28106CB94}" = Concours-Fonction-Publique
"{5C2FE307-9893-430B-DEB8-FE98C7C932A3}" = Catalyst Control Center Localization Russian
"{5CA7899B-FFEC-4254-A05B-448420831F37}" = L'Entraîneur 2010
"{5DA6F06A-B389-407B-BF8C-1548767914D8}" = ATI Problem Report Wizard
"{5FB5B4A3-451F-E5DE-FAB6-9A4C2D0BA523}" = Catalyst Control Center Graphics Light
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AA0E439-FCF5-F7D6-C9D1-42CFB6F0FBD3}" = ccc-utility
"{6B3DF13C-D665-B9BA-81AC-DBE64626389C}" = CCC Help Japanese
"{706EA4A8-97B5-4C29-A0F3-0B38C666F0C4}" = QuarkXPress
"{719F7A64-A0EB-CC17-7BEA-912B12F8B5DA}" = CCC Help Dutch
"{72AD53CC-CCC0-3757-8480-9EE176866A7C}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA
"{748EC7BB-2C18-ED75-35CF-1FB70722E998}" = Catalyst Control Center Localization Greek
"{75ADEFA2-D4FF-4B37-9E93-4306E6AC176B}_is1" = ImgBurn 2.3.2.0 Fr
"{795BE19F-98EA-64ED-EBC6-F02C3293DE67}" = Catalyst Control Center Localization Finnish
"{7C11154F-3539-4CB5-979D-EF7913473E53}" = Prince of Persia
"{8155CC45-FCDB-6087-7B52-F8F94C8DEBC9}" = Catalyst Control Center Localization Thai
"{81E74A3D-22E6-04ED-94D8-92672C0722A8}" = CCC Help English
"{82154114-943B-4A6F-9B20-073C9573E93E}" = Quark Update
"{8269BAFA-897C-9D2C-8F19-547E1C6511D5}" = Catalyst Control Center Localization Spanish
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8404B862-6FE5-EFAB-F4FA-9AD921C37542}" = CCC Help Greek
"{85CC6638-C827-40E8-94C7-110A77E7812B}" = Adobe Illustrator CS Tryout
"{8674A5F6-3FD2-3ADE-1CFB-8DC208D25068}" = Catalyst Control Center Localization Italian
"{86BF3A26-BB1C-C5F6-1F58-6A9F5F66BEA6}" = Catalyst Control Center Localization Chinese Standard
"{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}" = Epson Easy Photo Print 2
"{8937FCB2-2FC6-4FC3-9FB5-DE2C92DB9C38}" = Microsoft .NET Framework 2.0 Language Pack - DEU
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A271484-6C3D-C790-FB7F-6F591C32D43F}" = Catalyst Control Center Localization Danish
"{8CE9CAAA-11BE-6011-B368-98B08BE9149F}" = Catalyst Control Center Localization Turkish
"{8F8D9297-FDD2-405A-97E7-E52C7B2F97B3}" = Ulead VideoStudio SE DVD
"{8F9065A6-4597-143C-DE8F-4899B47139D2}" = Catalyst Control Center Localization German
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1
"{95120000-00AF-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (French)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95F739DF-055F-5F78-BB25-390D3ED79B15}" = CCC Help German
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A394342-4A68-4EBA-85A6-55B559F4E700}" = Microsoft .NET Framework 1.1 French Language Pack
"{9AF609CB-7D53-C467-4AD8-F308F6517E1D}" = CCC Help Danish
"{9BC76CCE-A9EC-4A3A-9B51-D823805E1D1F}" = SolidConverterPDF
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2F166A0-F031-4E27-A057-C69733219435}_is1" = Mythos
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4A82C43-839A-B320-817F-E049E9AB88E3}" = Catalyst Control Center Localization Hungarian
"{A5AD9E34-0418-C38C-B45F-1299958F71DF}" = Catalyst Control Center Localization Swedish
"{A6151E89-9A29-46A9-89BF-F3E2317CAF78}" = Catalyst Control Center Localization Japanese
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9C9F63F-0935-1935-BEB3-5A22D18407AE}" = Catalyst Control Center Localization Polish
"{AC76BA86-7AD7-1036-7B44-A94000000001}" = Adobe Reader 9.4.5 - Français
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AF32785D-2647-8B8E-CEAB-C55C72399B82}" = CCC Help Italian
"{B2DA8661-FBEA-137C-0EDD-B6F79304F66E}" = ccc-core-static
"{B3B487E7-6171-4376-9074-B28082CEB504}" = Windows Live Call
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5AA33D0-8F0F-7D57-BAB3-89263A7F30D3}" = Catalyst Control Center Localization Chinese Traditional
"{B9AE2EE9-320A-C03D-A4FD-5F5AD5A6288D}" = Catalyst Control Center Graphics Previews Common
"{BB1343D0-D43A-ECF3-43D8-CCA7340711A1}" = Catalyst Control Center Localization French
"{BB50677E-16CD-7F20-DA32-7D6421E4F625}" = Catalyst Control Center Core Implementation
"{C021EA24-9C8B-7CD0-11DF-1440F8A36353}" = Catalyst Control Center Localization Norwegian
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C736B441-F731-92B9-44AE-104537F0DAE8}" = CCC Help Chinese Traditional
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF709F83-938F-41AE-8C7F-90A0A0C89CCF}" = Skins
"{D374F8CD-E0F3-4810-A48F-3C96E86AF6B4}" = Code de la Route Pratic
"{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}" = Black & White® 2
"{DA356B21-A3D1-EF40-E284-FE260681DF0C}" = Catalyst Control Center Localization Korean
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}" = Assistant de connexion Windows Live
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Codeur Windows Media Série 9
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E4AF5565-E6B8-78A5-246F-F5024A2D5386}" = Catalyst Control Center Localization Portuguese
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E81B505A-CEDE-4842-42A1-55E4330D6ED8}" = Catalyst Control Center Graphics Full New
"{EBAB55B3-EC6B-B02D-B105-3ACB70B8F896}" = Catalyst Control Center Localization Dutch
"{EC168ED9-3B78-2A2C-8F23-54211C2C7676}" = CCC Help French
"{EF8D87FC-E186-EBBE-7A29-9B1D67F2EFA7}" = Catalyst Control Center HydraVision Full
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0F6E30A-3CCB-3112-BFD1-487C3596513C}" = ccc-core-preinstall
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFE9798B-3AFA-BC35-3441-85C201E503C8}" = CCC Help Finnish
"{ORAHSS}.UninstallSuite" = Orange - Logiciels Internet
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Ad-Remover" = Ad-Remover par C_XX
"All ATI Software" = ATI - Utilitaire de désinstallation du logiciel
"ASIO4ALL" = ASIO4ALL
"ATI Display Driver" = ATI Display Driver
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Avidemux 2.5" = Avidemux 2.5
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Bink and Smacker" = Bink and Smacker
"CCleaner" = CCleaner (remove only)
"CFWebAdvancedU" = CamfrogWEB Advanced ActiveX Plugin (remove only)
"CFWebAdvancedU_BOBTV.FR" = CamfrogWEB Advanced ActiveX Plugin (www.bobtv.fr)
"CloneCD" = CloneCD
"D-Link VGA Webcam" = D-Link VGA Webcam
"DVD Decrypter" = DVD Decrypter (Remove Only)
"EPSON Scanner" = EPSON Scan
"Epson Stylus SX210_SX410_TX210_TX410 Guide d'utilisation" = Epson Stylus SX210_SX410_TX210_TX410 Manuel
"EPSON SX210 Series" = EPSON SX210 Series Printer Uninstall
"Everest Poker.fr" = Everest Poker.fr (Remove Only)
"File Splitter and Joiner_is1" = File Splitter and Joiner (FFSJ v3.3)
"FL Studio 9" = FL Studio 9
"Football Manager 2010" = Football Manager 2010
"Football Manager 2011 Russian" = Football Manager 2011 Russian
"FormatFactory" = FormatFactory 2.10
"FormatFactory (¸ñʽ¹¤³§)" = FormatFactory (¸ñʽ¹¤³§) V1.70 ¶à¹úÓïÑÔ°æ
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.8
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.37.426
"Glary Utilities_is1" = Glary Utilities 2.34.0.1190
"Graffiti Studio 2.0_is1" = Graffiti Studio 2.0
"Hardcore" = Hardcore
"HijackThis" = HijackThis 2.0.2
"IL Download Manager" = IL Download Manager
"Internet Speed Booster_is1" = Internet Speed Booster 1.1.0.1
"JDownloader" = JDownloader
"LastFM_is1" = Last.fm 1.5.4.24567
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200
"Microsoft .NET Framework 2.0 Language Pack - DEU" = Microsoft .NET Framework 2.0 Language Pack - DEU
"Microsoft .NET Framework 3.5 Language Pack SP1 - fra" = Module linguistique Microsoft .NET Framework 3.5 SP1- fra
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Monopoly Deluxe 3D" = Monopoly Deluxe 3D
"Moovida" = Moovida
"Mozilla Firefox 5.0 (x86 fr)" = Mozilla Firefox 5.0 (x86 fr)
"Mp3tag" = Mp3tag v2.46a
"Mumble" = Mumble and Murmur
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"Office8.0" = Microsoft Office 97 Professional
"PDF-to-Word 2.5 Demo" = PDF-to-Word 2.5 Demo
"PoiZone" = PoiZone
"Sawer" = Sawer
"Shockwave" = Shockwave
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"Steam App 240" = Counter-Strike: Source
"Steam App 260" = Counter-Strike: Source Beta
"Steam App 300" = Day of Defeat: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Toxic Biohazard" = Toxic Biohazard
"Uninstall_is1" = Uninstall 1.0.0.1
"Unlocker" = Unlocker 1.8.7
"VLC media player" = VLC media player 1.0.5
"Winamp" = Winamp
"Windows Media Encoder 9" = Codeur Windows Media Série 9
"WinLiveSuite_Wave3" = Installation Windows Live
"WinRAR archiver" = Archiveur WinRAR
"WOLAPI" = Composants Internet Partagés de Westwood
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"5f48e2ab41c5d005" = RapidShare Manager
"AI RoboForm" = RoboForm 7-3-2
"Google Chrome" = Google Chrome
"PhotoFiltre" = PhotoFiltre

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 28/06/2011 01:15:11 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

Error - 28/06/2011 03:40:10 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

Error - 28/06/2011 07:02:05 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

Error - 28/06/2011 07:02:20 | Computer Name = A8F02614C8F340C | Source = ESENT | ID = 490
Description = svchost (1504) Une tentative d'ouverture du fichier "I:\WINDOWS\system32\CatRoot2\edb.log"
pour accès en lecture/écriture a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).

Error - 28/06/2011 12:46:03 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

Error - 28/06/2011 13:27:47 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

Error - 28/06/2011 13:29:46 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

Error - 28/06/2011 14:45:42 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

Error - 29/06/2011 04:10:13 | Computer Name = A8F02614C8F340C | Source = ESENT | ID = 490
Description = svchost (1520) Une tentative d'ouverture du fichier "I:\WINDOWS\system32\CatRoot2\edb.log"
pour accès en lecture/écriture a échoué en indiquant l'erreur système 32 (0x00000020)
: "Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un
autre processus. ". L'opération d'ouverture de fichier échouera en indiquant l'erreur
-1032 (0xfffffbf8).

Error - 29/06/2011 08:11:42 | Computer Name = A8F02614C8F340C | Source = PerfNet | ID = 2004
Description = Impossible d'ouvrir le Service serveur. Les données de performance
du serveur ne seront pas renvoyées. Le code d'erreur renvoyé est la donnée DWORD
0.

[ System Events ]
Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7034
Description = Le service Service Bonjour s'est terminé de façon inattendue pour
la 1ème fois.

Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7034
Description = Le service France Telecom Routing Table Service s'est terminé de façon
inattendue pour la 1ème fois.

Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7034
Description = Le service Java Quick Starter s'est terminé de façon inattendue pour
la 1ème fois.

Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7034
Description = Le service Syntek STK1160 Service s'est terminé de façon inattendue
pour la 1ème fois.

Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7034
Description = Le service Ulead Burning Helper s'est terminé de façon inattendue
pour la 1ème fois.

Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7034
Description = Le service Service de la passerelle de la couche Application s'est
terminé de façon inattendue pour la 1ème fois.

Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7031
Description = Le service Apple Mobile Device s'est terminé de manière inattendue.
Ceci s'est produit 1 fois. L'action corrective suivante va être effectuée dans
60000 millisecondes : Redémarrer le service.

Error - 29/06/2011 08:06:28 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7031
Description = Le service Lavasoft Ad-Aware Service s'est terminé de manière inattendue.
Ceci s'est produit 1 fois. L'action corrective suivante va être effectuée dans
5000 millisecondes : Redémarrer le service.

Error - 29/06/2011 08:11:49 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7000
Description = Le service helpsvc n'a pas pu démarrer en raison de l'erreur : %%2

Error - 29/06/2011 08:11:49 | Computer Name = A8F02614C8F340C | Source = Service Control Manager | ID = 7023
Description = Le service Mises à jour automatiques s'est arrêté avec l'erreur :
%%126

[ TuneUp Events ]
Error - 03/05/2010 12:37:59 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 03/05/2010 12:38:39 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 03/05/2010 12:38:54 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 03/05/2010 12:38:59 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 03/05/2010 12:39:14 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 10/05/2010 10:07:43 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 28/05/2010 11:50:28 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 29/05/2010 04:12:27 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 07/06/2010 11:34:15 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 18/06/2010 01:44:13 | Computer Name = A8F02614C8F340C | Source = TuneUp Program Statistics | ID = 131840
Description =


< End of report >
Revenir en haut Aller en bas
picmin
Bibou
Bibou



Masculin
Nombre de messages : 17
Age : 59
Localisation : GRENOBLE
Date d'inscription : 26/06/2011

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeMer 29 Juin 2011 - 17:16

le 2°

TLOTL logfile created on: 29/06/2011 17:09:43 - Run 1
OTL by OldTimer - Version 3.2.24.2 Folder = I:\Documents and Settings\Administrateur\Mes documents\Téléchargements
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

3,00 Gb Total Physical Memory | 2,39 Gb Available Physical Memory | 79,69% Memory free
4,84 Gb Paging File | 4,26 Gb Available in Paging File | 87,99% Paging File free
Paging file location(s): I:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = I: | %SystemRoot% = I:\WINDOWS | %ProgramFiles% = I:\Program Files
Drive H: | 246,52 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive I: | 111,67 Gb Total Space | 8,06 Gb Free Space | 7,22% Space Free | Partition Type: NTFS
Drive J: | 354,09 Gb Total Space | 15,25 Gb Free Space | 4,31% Space Free | Partition Type: NTFS

Computer Name: A8F02614C8F340C | User Name: Administrateur | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/29 17:08:59 | 000,579,584 | ---- | M] (OldTimer Tools) -- I:\Documents and Settings\Administrateur\Mes documents\Téléchargements\OTL.exe
PRC - [2011/06/22 18:04:02 | 000,924,632 | ---- | M] (Mozilla Corporation) -- I:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/05/11 15:42:22 | 000,136,360 | ---- | M] (Avira GmbH) -- I:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/04/03 11:05:48 | 000,269,480 | ---- | M] (Avira GmbH) -- I:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/08/17 14:38:55 | 000,281,768 | ---- | M] (Avira GmbH) -- I:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- I:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/01/14 23:11:14 | 000,076,968 | ---- | M] (Avira GmbH) -- I:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009/02/19 14:36:24 | 000,611,664 | ---- | M] (Lavasoft) -- I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008/08/24 01:53:00 | 002,011,136 | ---- | M] (Microsoft Corporation) -- I:\WINDOWS\explorer.exe
PRC - [2008/07/21 04:55:00 | 000,442,433 | ---- | M] (IDT, Inc.) -- I:\Program Files\IDT\WDM\sttray.exe
PRC - [2008/07/21 04:55:00 | 000,221,239 | ---- | M] (IDT, Inc.) -- i:\Program Files\IDT\XPV_5902_012208\WDM\stacsv.exe
PRC - [2007/12/11 21:19:44 | 000,065,536 | ---- | M] (France Telecom SA) -- I:\Program Files\Fichiers communs\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
PRC - [2006/09/28 11:20:00 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- I:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2006/05/23 23:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) -- I:\WINDOWS\system32\StkASv2K.exe


========== Modules (SafeList) ==========

MOD - [2011/06/29 17:08:59 | 000,579,584 | ---- | M] (OldTimer Tools) -- I:\Documents and Settings\Administrateur\Mes documents\Téléchargements\OTL.exe
MOD - [2008/05/03 00:57:00 | 001,054,208 | R--- | M] (Microsoft Corporation) -- I:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (wuauserv)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (ERSvc)
SRV - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- I:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/05/11 15:42:22 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- I:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/04/03 11:05:48 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- I:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/08/13 12:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- I:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/02/19 14:36:24 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2008/07/21 04:55:00 | 000,221,239 | ---- | M] (IDT, Inc.) [Auto | Running] -- i:\Program Files\IDT\XPV_5902_012208\WDM\stacsv.exe -- (STacSV)
SRV - [2007/12/11 21:19:44 | 000,065,536 | ---- | M] (France Telecom SA) [Auto | Running] -- I:\Program Files\Fichiers communs\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe -- (FTRTSVC)
SRV - [2006/09/28 11:20:00 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- I:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2006/05/23 23:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) [Auto | Running] -- I:\WINDOWS\system32\StkASv2K.exe -- (StkASSrv)
SRV - [2004/03/18 17:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- I:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - [2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- I:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- I:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/04/03 11:05:48 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- I:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2010/12/13 15:03:16 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- I:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/08/05 10:06:24 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- I:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/06/17 16:28:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- I:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 16:27:52 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- I:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008/09/11 05:08:10 | 003,331,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- I:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2008/08/24 01:53:00 | 000,210,224 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- I:\WINDOWS\System32\drivers\Si3531.sys -- (Si3531)
DRV - [2008/08/24 01:53:00 | 000,208,688 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- I:\WINDOWS\System32\drivers\Si3132r5.sys -- (Si3132r5)
DRV - [2008/08/24 01:53:00 | 000,202,032 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- I:\WINDOWS\System32\drivers\Si3114r5.sys -- (Si3114r5)
DRV - [2008/08/24 01:53:00 | 000,076,208 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- I:\WINDOWS\System32\drivers\si3124.sys -- (Si3124)
DRV - [2008/08/24 01:53:00 | 000,074,672 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- I:\WINDOWS\System32\drivers\si3132.sys -- (Si3132)
DRV - [2008/08/24 01:53:00 | 000,069,296 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- I:\WINDOWS\System32\drivers\si3112.sys -- (Si3112)
DRV - [2008/07/21 04:55:00 | 001,292,888 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- I:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2008/07/02 21:38:14 | 000,089,600 | R--- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- I:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2008/05/03 00:57:38 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- I:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2008/05/03 00:57:00 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- I:\WINDOWS\system32\drivers\AtiHdAud.sys -- (HdAudAddService)
DRV - [2007/12/19 19:53:00 | 000,037,376 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- I:\WINDOWS\system32\drivers\l151x86.sys -- (AtcL001)
DRV - [2007/10/12 03:40:12 | 000,009,096 | R--- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- I:\WINDOWS\system32\DRIVERS\amdide.sys -- (amdide)
DRV - [2007/02/16 02:57:04 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- I:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2006/11/15 17:32:44 | 000,242,139 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- I:\WINDOWS\system32\drivers\StkAMini.sys -- (StkAMini)
DRV - [2006/06/27 18:27:18 | 000,004,772 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- I:\WINDOWS\system32\drivers\StkScan.sys -- (StkScan)
DRV - [2006/03/01 19:53:54 | 000,032,128 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- I:\WINDOWS\system32\pcandis5.sys -- (PCANDIS5)
DRV - [2004/03/02 18:37:50 | 000,125,184 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- I:\WINDOWS\system32\DRIVERS\imagesrv.sys -- (imagesrv)
DRV - [2004/03/02 18:37:48 | 000,005,504 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- I:\WINDOWS\System32\Drivers\imagedrv.sys -- (imagedrv)
DRV - [2003/10/15 17:52:50 | 000,174,530 | R--- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] -- I:\WINDOWS\system32\drivers\ov519vid.sys -- (ovt519)
DRV - [2003/09/23 11:38:34 | 000,034,688 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- I:\WINDOWS\system32\pcampr5.sys -- (PCAMPR5)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
IE - HKCU\..\URLSearchHook: {08C06D61-F1F3-4799-86F8-BE1A89362C85} - I:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.fr/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: alldebrid@alldebrid.com:1.5
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: illimitux@illimitux.net:4.0
FF - prefs.js..extensions.enabledItems: megadebridplugin@mega-debrid.eu:0.3
FF - prefs.js..extensions.enabledItems: plugin@debrideurmegaupload.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: fireform@mozilla.org:0.7.4


FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: I:\Program Files\Mozilla Firefox\components [2011/06/22 18:04:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: I:\Program Files\Mozilla Firefox\plugins [2011/06/22 19:34:26 | 000,000,000 | ---D | M]

[2009/05/21 08:52:29 | 000,000,000 | ---D | M] (No name found) -- I:\Documents and Settings\Administrateur\Application Data\Mozilla\Extensions
[2011/05/23 19:51:18 | 000,000,000 | ---D | M] (No name found) -- I:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\lkafy1na.default\extensions
[2009/12/13 10:32:44 | 000,001,786 | ---- | M] () -- I:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\lkafy1na.default\searchplugins\google-language-fr.xml
[2009/04/23 19:42:39 | 000,001,620 | ---- | M] () -- I:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\lkafy1na.default\searchplugins\mozilla-add-ons.xml
[2009/09/30 16:33:53 | 000,003,721 | ---- | M] () -- I:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\lkafy1na.default\searchplugins\Searcheo.xml
[2009/04/29 17:41:52 | 000,003,705 | ---- | M] () -- I:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\lkafy1na.default\searchplugins\YouGoo.xml
[2011/05/14 18:51:47 | 000,000,000 | ---D | M] (No name found) -- I:\Program Files\Mozilla Firefox\extensions
[2010/04/28 13:28:44 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/04 19:28:00 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/04 21:12:26 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/21 22:16:38 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/19 10:34:18 | 000,000,000 | ---D | M] (Java Console) -- I:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- I:\DOCUMENTS AND SETTINGS\ADMINISTRATEUR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\LKAFY1NA.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- I:\DOCUMENTS AND SETTINGS\ADMINISTRATEUR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\LKAFY1NA.DEFAULT\EXTENSIONS\FIREFORM@MOZILLA.ORG.XPI
[2009/05/29 19:23:44 | 000,000,000 | ---D | M] (Java Quick Starter) -- I:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/22 18:04:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- I:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- I:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/04/23 15:39:26 | 000,001,516 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2011/03/22 17:46:08 | 000,002,428 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/04/23 15:39:26 | 000,002,252 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/04/23 15:39:26 | 000,001,822 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2011/04/23 15:39:26 | 000,001,154 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2009/04/24 18:40:58 | 000,000,748 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\MediaDICO-fr.xml
[2011/04/23 15:39:26 | 000,001,426 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2011/04/23 15:39:26 | 000,000,956 | ---- | M] () -- I:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: ([2010/12/24 13:19:09 | 000,000,226 | ---- | M]) - I:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 static3.cdn.ubi.com
O1 - Hosts: 127.0.0.1 Ubisoft-orbit.s3.amazonaws.com
O1 - Hosts: 127.0.0.1 onlineconfigservice.ubi.com
O1 - Hosts: 127.0.0.1 orbitservice.ubi.com
O1 - Hosts: 127.0.0.1 Ubisoft orbite-savegames.s3.amazonaws.com
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Solid Converter PDF) - {259F616C-A300-44F5-B04A-ED001A26C85C} - J:\UTILITAIRE\solid converter\SCPDF\ExploreExtPDF.dll (VoyagerSoft, LLC)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - I:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - I:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Solid Converter PDF) - {259F616C-A300-44F5-B04A-ED001A26C85C} - J:\UTILITAIRE\solid converter\SCPDF\ExploreExtPDF.dll (VoyagerSoft, LLC)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - I:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - I:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {00000002-D378-01FA-8B20-3A7700000000} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {00000002-F180-01FA-8B20-3A771E000000} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - I:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe ARM] I:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] I:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [StartCCC] I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] I:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [EPSON SX210 Series] I:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFDE.EXE (SEIKO EPSON CORPORATION)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Barre RoboForm - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Enregistrer le formulaire - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - I:\Documents and Settings\Administrateur\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Personnaliser le menu - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Remplir le formulaire - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - Reg Error: Value error. File not found
O9 - Extra Button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - Reg Error: Value error. File not found
O9 - Extra Button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - I:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - I:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: everestpoker.com ([www] http in Sites de confiance)
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe (CamfrogWEB Advanced Unicode Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} http://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe (CamfrogWEB Advanced Unicode Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\copernicagent {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - Reg Error: Key error. File not found
O18 - Protocol\Handler\copernicagentcache {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - I:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - I:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: I:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: I:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/20 06:37:34 | 000,000,029 | R--- | M] () - H:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{6ded0c83-ee39-11dd-8ca6-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{6ded0c83-ee39-11dd-8ca6-806d6172696f}\Shell\AutoRun\command - "" = H:\EPSetup.exe -- [2009/06/03 16:01:00 | 000,059,304 | R--- | M] (Seiko Epson Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - I:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/29 14:05:04 | 000,000,000 | ---D | C] -- I:\Program Files\Ad-Remover
[2011/06/29 13:42:40 | 000,000,000 | RH-D | C] -- I:\Documents and Settings\Administrateur\Recent
[2011/06/26 15:48:17 | 000,000,000 | ---D | C] -- I:\_OTM
[2011/06/26 11:14:10 | 000,000,000 | ---D | C] -- I:\Ad-Remover
[2011/06/18 11:29:30 | 000,000,000 | ---D | C] -- I:\Documents and Settings\All Users\Menu Démarrer\Programmes\Google Earth
[2011/06/13 21:52:47 | 000,000,000 | ---D | C] -- I:\Documents and Settings\Administrateur\Bureau\Alkpote-Lempereur-FR-2008-VBR-www.FRap.ru
[2011/06/13 21:52:39 | 000,000,000 | ---D | C] -- I:\Documents and Settings\Administrateur\Bureau\Booba - Temps Mort
[2011/06/06 19:29:51 | 000,000,000 | ---D | C] -- I:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\RoboForm
[2011/06/03 17:10:40 | 000,000,000 | ---D | C] -- I:\Documents and Settings\All Users\Application Data\Webroot
[2011/06/03 17:10:38 | 000,000,000 | ---D | C] -- I:\Documents and Settings\Administrateur\Local Settings\Application Data\PackageAware
[2011/05/31 19:37:12 | 000,000,000 | ---D | C] -- I:\Documents and Settings\All Users\Menu Démarrer\Programmes\Glary Utilities
[2011/05/31 19:37:08 | 000,000,000 | ---D | C] -- I:\Program Files\Glary Utilities
[2004/06/22 12:16:30 | 000,022,608 | ---- | C] (Microsoft Corporation) -- I:\Program Files\usbprint.sys
[2004/06/22 12:16:30 | 000,012,288 | ---- | C] (Microsoft Corporation) -- I:\Program Files\usbmon.dll
[2004/06/22 12:16:28 | 000,442,425 | ---- | C] (Hewlett-Packard) -- I:\Program Files\hpzjpp01.dll
[2004/06/22 12:16:28 | 000,290,873 | ---- | C] (Hewlett-Packard) -- I:\Program Files\hpzjut01.dll
[2004/06/22 12:16:28 | 000,254,005 | ---- | C] (Microsoft Corporation) -- I:\Program Files\msvcrt.dll
[2004/06/22 12:16:28 | 000,200,704 | ---- | C] (HP) -- I:\Program Files\hpzpnp10.dll
[2004/06/22 12:16:28 | 000,176,128 | ---- | C] (HP) -- I:\Program Files\hpzscr10.dll
[2004/06/22 12:16:28 | 000,070,656 | ---- | C] (Microsoft Corporation) -- I:\Program Files\msvcirt.dll
[2004/06/22 12:16:28 | 000,049,212 | ---- | C] (Hewlett-Packard) -- I:\Program Files\hpzjvp01.dll
[2004/06/22 12:16:28 | 000,028,722 | ---- | C] (Hewlett-Packard) -- I:\Program Files\hpzjlog.dll
[2004/06/22 12:16:28 | 000,026,768 | ---- | C] (Microsoft Corporation) -- I:\Program Files\usbhub.sys
[2004/06/22 12:16:26 | 000,270,336 | ---- | C] (Hewlett-Packard Co.) -- I:\Program Files\hpzc3212.dll
[1 I:\Documents and Settings\Administrateur\*.tmp files -> I:\Documents and Settings\Administrateur\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/29 17:01:00 | 000,001,184 | ---- | M] () -- I:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1644491937-682003330-500UA.job
[2011/06/29 16:27:00 | 000,001,072 | ---- | M] () -- I:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/29 15:27:00 | 000,001,068 | ---- | M] () -- I:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/29 14:11:35 | 000,000,330 | ---- | M] () -- I:\WINDOWS\tasks\GlaryInitialize.job
[2011/06/29 14:10:44 | 000,054,376 | ---- | M] () -- I:\WINDOWS\System32\ativvaxx.cap
[2011/06/29 14:10:44 | 000,002,048 | --S- | M] () -- I:\WINDOWS\bootstat.dat
[2011/06/29 14:05:05 | 000,001,554 | ---- | M] () -- I:\Documents and Settings\Administrateur\Bureau\AD-R.lnk
[2011/06/26 16:02:06 | 000,000,374 | ---- | M] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110626_160159.reg
[2011/06/26 15:46:59 | 000,002,262 | ---- | M] () -- I:\Documents and Settings\Administrateur\main.vbe
[2011/06/26 15:40:20 | 000,000,004 | ---- | M] () -- I:\Documents and Settings\Administrateur\binternet_26_06_2011
[2011/06/26 15:40:20 | 000,000,003 | ---- | M] () -- I:\Documents and Settings\Administrateur\vers
[2011/06/26 11:37:58 | 000,001,504 | ---- | M] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110626_113755.reg
[2011/06/26 11:35:25 | 000,165,120 | ---- | M] () -- I:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/26 11:20:17 | 000,000,126 | ---- | M] () -- I:\Documents and Settings\Administrateur\parm.fr
[2011/06/26 10:38:53 | 000,000,206 | ---- | M] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110626_103851.reg
[2011/06/26 10:09:00 | 000,001,132 | ---- | M] () -- I:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1644491937-682003330-500Core1cc25b2aef20aea.job
[2011/06/25 19:02:44 | 000,004,290 | ---- | M] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110625_190241.reg
[2011/06/24 16:50:12 | 000,000,665 | ---- | M] () -- I:\Documents and Settings\All Users\Bureau\EPSON Scan.lnk
[2011/06/23 13:20:50 | 000,000,000 | ---- | M] () -- I:\Documents and Settings\Administrateur\tmp1.16
[2011/06/22 19:34:03 | 003,314,425 | ---- | M] () -- I:\Documents and Settings\Administrateur\Bureau\recettes_cocktails.pdf
[2011/06/18 11:29:30 | 000,001,915 | ---- | M] () -- I:\Documents and Settings\All Users\Bureau\Google Earth.lnk
[2011/06/15 07:48:03 | 000,002,351 | ---- | M] () -- I:\Documents and Settings\Administrateur\Bureau\Google Chrome.lnk
[2011/06/14 15:31:21 | 000,006,537 | ---- | M] () -- I:\Documents and Settings\Administrateur\Bureau\http___www.deposezvosjeux.com_wp-content_themes_reglements_pdf_create_pdf.pdf
[2011/06/10 13:32:43 | 000,002,206 | ---- | M] () -- I:\WINDOWS\System32\wpa.dbl
[2011/06/03 16:56:53 | 000,001,548 | ---- | M] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110603_165650.reg
[2011/05/31 19:37:12 | 000,000,741 | ---- | M] () -- I:\Documents and Settings\Administrateur\Bureau\Glary Utilities.lnk
[2011/05/30 20:13:46 | 005,669,220 | ---- | M] () -- I:\Documents and Settings\Administrateur\Bureau\hps_Mise en page 1.pdf
[1 I:\Documents and Settings\Administrateur\*.tmp files -> I:\Documents and Settings\Administrateur\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/29 14:05:05 | 000,001,554 | ---- | C] () -- I:\Documents and Settings\Administrateur\Bureau\AD-R.lnk
[2011/06/26 16:02:01 | 000,000,374 | ---- | C] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110626_160159.reg
[2011/06/26 11:37:56 | 000,001,504 | ---- | C] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110626_113755.reg
[2011/06/26 11:29:22 | 000,000,004 | ---- | C] () -- I:\Documents and Settings\Administrateur\binternet_26_06_2011
[2011/06/26 11:29:22 | 000,000,003 | ---- | C] () -- I:\Documents and Settings\Administrateur\vers
[2011/06/26 10:38:52 | 000,000,206 | ---- | C] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110626_103851.reg
[2011/06/25 19:02:42 | 000,004,290 | ---- | C] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110625_190241.reg
[2011/06/24 16:50:12 | 000,000,665 | ---- | C] () -- I:\Documents and Settings\All Users\Bureau\EPSON Scan.lnk
[2011/06/23 20:37:36 | 000,002,262 | ---- | C] () -- I:\Documents and Settings\Administrateur\main.vbe
[2011/06/23 13:20:58 | 000,000,126 | ---- | C] () -- I:\Documents and Settings\Administrateur\parm.fr
[2011/06/23 13:20:50 | 000,000,000 | ---- | C] () -- I:\Documents and Settings\Administrateur\tmp1.16
[2011/06/22 19:33:50 | 003,314,425 | ---- | C] () -- I:\Documents and Settings\Administrateur\Bureau\recettes_cocktails.pdf
[2011/06/18 11:29:30 | 000,001,915 | ---- | C] () -- I:\Documents and Settings\All Users\Bureau\Google Earth.lnk
[2011/06/14 15:31:21 | 000,006,537 | ---- | C] () -- I:\Documents and Settings\Administrateur\Bureau\http___www.deposezvosjeux.com_wp-content_themes_reglements_pdf_create_pdf.pdf
[2011/06/08 10:04:25 | 000,001,132 | ---- | C] () -- I:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1644491937-682003330-500Core1cc25b2aef20aea.job
[2011/06/03 16:56:51 | 000,001,548 | ---- | C] () -- I:\Documents and Settings\Administrateur\Mes documents\cc_20110603_165650.reg
[2011/05/31 19:37:13 | 000,000,330 | ---- | C] () -- I:\WINDOWS\tasks\GlaryInitialize.job
[2011/05/31 19:37:12 | 000,000,741 | ---- | C] () -- I:\Documents and Settings\Administrateur\Bureau\Glary Utilities.lnk
[2011/05/30 20:13:36 | 005,669,220 | ---- | C] () -- I:\Documents and Settings\Administrateur\Bureau\hps_Mise en page 1.pdf
[2011/02/04 15:31:45 | 000,109,967 | ---- | C] () -- I:\WINDOWS\CopernicAgentUninstall.exe
[2010/12/03 17:04:32 | 000,056,832 | ---- | C] () -- I:\WINDOWS\System32\iyvu9_32.dll
[2010/11/13 19:36:55 | 000,057,344 | ---- | C] () -- I:\Documents and Settings\Administrateur\Application Data\chrtmp
[2010/08/27 18:20:58 | 000,111,932 | ---- | C] () -- I:\WINDOWS\System32\EPPICPrinterDB.dat
[2010/08/27 18:20:58 | 000,031,053 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern131.dat
[2010/08/27 18:20:58 | 000,027,417 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern121.dat
[2010/08/27 18:20:58 | 000,026,154 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern1.dat
[2010/08/27 18:20:58 | 000,024,903 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern3.dat
[2010/08/27 18:20:58 | 000,021,390 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern5.dat
[2010/08/27 18:20:58 | 000,020,148 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern2.dat
[2010/08/27 18:20:58 | 000,011,811 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern4.dat
[2010/08/27 18:20:58 | 000,004,943 | ---- | C] () -- I:\WINDOWS\System32\EPPICPattern6.dat
[2010/08/27 18:20:58 | 000,001,146 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_DU.dat
[2010/08/27 18:20:58 | 000,001,139 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010/08/27 18:20:58 | 000,001,139 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010/08/27 18:20:58 | 000,001,136 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010/08/27 18:20:58 | 000,001,129 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010/08/27 18:20:58 | 000,001,129 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010/08/27 18:20:58 | 000,001,120 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_IT.dat
[2010/08/27 18:20:58 | 000,001,107 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_GE.dat
[2010/08/27 18:20:58 | 000,001,104 | ---- | C] () -- I:\WINDOWS\System32\EPPICPresetData_EN.dat
[2010/08/27 18:20:58 | 000,000,097 | ---- | C] () -- I:\WINDOWS\System32\PICSDK.ini
[2010/06/11 12:47:01 | 001,537,024 | ---- | C] () -- I:\Documents and Settings\Administrateur\Application Data\questdb.v12
[2010/06/11 12:47:01 | 000,011,264 | ---- | C] () -- I:\Documents and Settings\Administrateur\Application Data\CDRusersDB.v12
[2010/03/06 11:07:50 | 000,073,728 | ---- | C] () -- I:\WINDOWS\unacev2.dll
[2009/12/05 20:06:31 | 000,027,648 | ---- | C] () -- I:\WINDOWS\System32\AVSredirect.dll
[2009/10/27 20:11:08 | 000,000,038 | ---- | C] () -- I:\WINDOWS\AviSplitter.INI
[2009/10/05 20:04:38 | 001,051,968 | ---- | C] () -- I:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/06/28 18:40:22 | 000,000,041 | -HS- | C] () -- I:\Documents and Settings\All Users\Application Data\.zreglib
[2009/06/11 14:06:01 | 000,000,978 | ---- | C] () -- I:\WINDOWS\eReg.dat
[2009/04/12 12:53:26 | 000,005,963 | ---- | C] () -- I:\WINDOWS\wininit.ini
[2009/03/23 10:27:32 | 000,747,566 | ---- | C] () -- I:\WINDOWS\System32\abgx360.exe
[2009/02/14 17:27:27 | 000,016,384 | ---- | C] () -- I:\WINDOWS\System32\FileOps.exe
[2009/02/10 18:24:20 | 000,000,000 | ---- | C] () -- I:\WINDOWS\WD.INI
[2009/02/09 20:17:01 | 000,000,116 | ---- | C] () -- I:\WINDOWS\ConverterCore.INI
[2009/02/03 19:21:51 | 000,794,906 | ---- | C] () -- I:\WINDOWS\unins000.exe
[2009/02/03 19:21:51 | 000,004,213 | ---- | C] () -- I:\WINDOWS\unins000.dat
[2009/02/01 17:54:21 | 000,200,704 | R--- | C] () -- I:\WINDOWS\sel3110.exe
[2009/02/01 17:54:21 | 000,040,960 | R--- | C] () -- I:\WINDOWS\CleanDev.exe
[2009/02/01 17:54:21 | 000,032,528 | R--- | C] () -- I:\WINDOWS\amcap.exe
[2009/01/31 19:30:27 | 000,000,214 | ---- | C] () -- I:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/01/31 19:25:03 | 000,000,116 | ---- | C] () -- I:\WINDOWS\NeroDigital.ini
[2009/01/31 16:29:08 | 000,000,137 | ---- | C] () -- I:\Documents and Settings\Administrateur\Local Settings\Application Data\fusioncache.dat
[2009/01/31 13:04:24 | 000,026,112 | ---- | C] () -- I:\Documents and Settings\Administrateur\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/29 21:23:17 | 000,004,205 | ---- | C] () -- I:\WINDOWS\ODBCINST.INI
[2009/01/29 21:23:11 | 000,970,752 | ---- | C] () -- I:\WINDOWS\notepad.exe
[2009/01/29 21:22:30 | 000,165,120 | ---- | C] () -- I:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/29 21:19:42 | 000,049,152 | R--- | C] () -- I:\WINDOWS\System32\ChCfg.exe
[2009/01/29 21:06:49 | 000,000,000 | ---- | C] () -- I:\WINDOWS\nsreg.dat
[2009/01/29 20:52:29 | 000,000,000 | ---- | C] () -- I:\WINDOWS\ativpsrm.bin
[2009/01/29 20:49:12 | 000,000,552 | ---- | C] () -- I:\WINDOWS\System32\d3d8caps.dat
[2009/01/29 20:48:59 | 000,354,816 | ---- | C] () -- I:\WINDOWS\System32\psisdecd.dll
[2009/01/29 20:48:23 | 000,593,920 | ---- | C] () -- I:\WINDOWS\System32\ati2sgag.exe
[2009/01/29 20:48:16 | 000,887,724 | R--- | C] () -- I:\WINDOWS\System32\ativva6x.dat
[2009/01/29 20:48:15 | 003,107,788 | R--- | C] () -- I:\WINDOWS\System32\ativva5x.dat
[2009/01/29 20:48:14 | 003,107,788 | R--- | C] () -- I:\WINDOWS\System32\ativvaxx.dat
[2009/01/29 20:48:14 | 000,176,216 | R--- | C] () -- I:\WINDOWS\System32\atiicdxx.dat
[2009/01/29 20:40:02 | 000,002,048 | --S- | C] () -- I:\WINDOWS\bootstat.dat
[2009/01/29 20:32:49 | 000,006,550 | ---- | C] () -- I:\WINDOWS\jautoexp.dat
[2009/01/29 20:28:03 | 000,021,892 | ---- | C] () -- I:\WINDOWS\System32\emptyregdb.dat
[2008/10/28 17:40:48 | 000,173,552 | ---- | C] () -- I:\WINDOWS\System32\xlive.dll.cat
[2008/08/24 01:53:00 | 013,107,200 | ---- | C] () -- I:\WINDOWS\System32\oembios.bin
[2008/08/24 01:53:00 | 001,274,222 | ---- | C] () -- I:\WINDOWS\System32\zipfldr.exe
[2008/08/24 01:53:00 | 000,970,752 | ---- | C] () -- I:\WINDOWS\System32\notepad.exe
[2008/08/24 01:53:00 | 000,676,224 | ---- | C] () -- I:\WINDOWS\System32\OGACheckControl.DLL
[2008/08/24 01:53:00 | 000,673,088 | ---- | C] () -- I:\WINDOWS\System32\mlang.dat
[2008/08/24 01:53:00 | 000,507,458 | ---- | C] () -- I:\WINDOWS\System32\perfh00C.dat
[2008/08/24 01:53:00 | 000,438,614 | ---- | C] () -- I:\WINDOWS\System32\perfh009.dat
[2008/08/24 01:53:00 | 000,322,810 | ---- | C] () -- I:\WINDOWS\System32\perfi00C.dat
[2008/08/24 01:53:00 | 000,272,128 | ---- | C] () -- I:\WINDOWS\System32\perfi009.dat
[2008/08/24 01:53:00 | 000,218,003 | ---- | C] () -- I:\WINDOWS\System32\dssec.dat
[2008/08/24 01:53:00 | 000,082,830 | ---- | C] () -- I:\WINDOWS\System32\perfc00C.dat
[2008/08/24 01:53:00 | 000,069,790 | ---- | C] () -- I:\WINDOWS\System32\perfc009.dat
[2008/08/24 01:53:00 | 000,053,248 | ---- | C] () -- I:\WINDOWS\System32\memtest.exe
[2008/08/24 01:53:00 | 000,046,258 | ---- | C] () -- I:\WINDOWS\System32\mib.bin
[2008/08/24 01:53:00 | 000,034,108 | ---- | C] () -- I:\WINDOWS\System32\perfd00C.dat
[2008/08/24 01:53:00 | 000,028,626 | ---- | C] () -- I:\WINDOWS\System32\perfd009.dat
[2008/08/24 01:53:00 | 000,004,569 | ---- | C] () -- I:\WINDOWS\System32\secupd.dat
[2008/08/24 01:53:00 | 000,004,463 | ---- | C] () -- I:\WINDOWS\System32\oembios.dat
[2008/08/24 01:53:00 | 000,001,804 | ---- | C] () -- I:\WINDOWS\System32\Dcache.bin
[2008/07/30 19:00:50 | 000,090,112 | ---- | C] () -- I:\WINDOWS\System32\atibrtmon.exe
[2008/05/16 12:58:04 | 000,012,632 | ---- | C] () -- I:\WINDOWS\System32\lsdelete.exe
[2007/08/21 23:51:16 | 000,081,920 | ---- | C] () -- I:\WINDOWS\System32\ATIODE.exe
[2007/08/21 21:36:12 | 000,040,960 | ---- | C] () -- I:\WINDOWS\System32\ATIODCLI.exe
[2004/06/22 12:16:28 | 000,052,349 | ---- | C] () -- I:\Program Files\hpzius13.cat
[2004/06/22 12:16:28 | 000,052,349 | ---- | C] () -- I:\Program Files\HPZius12.cat
[2004/06/22 12:16:28 | 000,051,467 | ---- | C] () -- I:\Program Files\hpzist13.cat
[2004/06/22 12:16:28 | 000,020,168 | ---- | C] () -- I:\Program Files\hpzius12.inf
[2004/06/22 12:16:28 | 000,014,815 | ---- | C] () -- I:\Program Files\hpzius13.inf
[2004/06/22 12:16:28 | 000,004,132 | ---- | C] () -- I:\Program Files\hpzist13.inf
[2004/06/22 12:16:28 | 000,000,399 | ---- | C] () -- I:\Program Files\hpzprl01.dat
[2004/06/22 12:16:28 | 000,000,267 | ---- | C] () -- I:\Program Files\Readme.html
[2004/06/22 12:16:28 | 000,000,205 | ---- | C] () -- I:\Program Files\hpzprl02.dat
[2004/06/22 12:16:26 | 000,447,400 | ---- | C] () -- I:\Program Files\hpoprn08.cat
[2004/06/22 12:16:26 | 000,137,124 | ---- | C] () -- I:\Program Files\hpoprn08.inf
[2004/06/22 12:16:26 | 000,094,438 | ---- | C] () -- I:\Program Files\hposcu08.inf
[2004/06/22 12:16:26 | 000,066,431 | ---- | C] () -- I:\Program Files\hpoprl04.dat
[2004/06/22 12:16:26 | 000,065,420 | ---- | C] () -- I:\Program Files\hpoprl05.dat
[2004/06/22 12:16:26 | 000,053,670 | ---- | C] () -- I:\Program Files\hposcu08.cat
[2004/06/22 12:16:26 | 000,051,467 | ---- | C] () -- I:\Program Files\hpzist12.cat
[2004/06/22 12:16:26 | 000,051,467 | ---- | C] () -- I:\Program Files\hpzipr13.cat
[2004/06/22 12:16:26 | 000,051,467 | ---- | C] () -- I:\Program Files\HPZipr12.cat
[2004/06/22 12:16:26 | 000,051,467 | ---- | C] () -- I:\Program Files\hpzid413.cat
[2004/06/22 12:16:26 | 000,051,467 | ---- | C] () -- I:\Program Files\HPZid412.cat
[2004/06/22 12:16:26 | 000,051,026 | ---- | C] () -- I:\Program Files\HPOunp08.cat
[2004/06/22 12:16:26 | 000,050,615 | ---- | C] () -- I:\Program Files\hpzid412.inf
[2004/06/22 12:16:26 | 000,022,636 | ---- | C] () -- I:\Program Files\hpzid413.inf
[2004/06/22 12:16:26 | 000,019,578 | ---- | C] () -- I:\Program Files\hpoprl03.dat
[2004/06/22 12:16:26 | 000,017,176 | ---- | C] () -- I:\Program Files\hpomdl04.dat
[2004/06/22 12:16:26 | 000,014,845 | ---- | C] () -- I:\Program Files\hpoapd01.dat
[2004/06/22 12:16:26 | 000,012,922 | ---- | C] () -- I:\Program Files\hpzipr12.inf
[2004/06/22 12:16:26 | 000,009,777 | ---- | C] () -- I:\Program Files\hpzipr13.inf
[2004/06/22 12:16:26 | 000,009,773 | ---- | C] () -- I:\Program Files\hpousc08.inf
[2004/06/22 12:16:26 | 000,007,579 | ---- | C] () -- I:\Program Files\hpound08.inf
[2004/06/22 12:16:26 | 000,006,704 | ---- | C] () -- I:\Program Files\hpounp08.inf
[2004/06/22 12:16:26 | 000,005,538 | ---- | C] () -- I:\Program Files\hpzist12.inf
[2004/06/22 12:16:26 | 000,004,779 | ---- | C] () -- I:\Program Files\hpoglu08.inf
[2004/06/22 12:16:26 | 000,004,768 | ---- | C] () -- I:\Program Files\hpoprl01.dat
[2004/06/22 12:16:26 | 000,004,144 | ---- | C] () -- I:\Program Files\hpousb08.inf
[2004/06/22 12:16:26 | 000,004,014 | ---- | C] () -- I:\Program Files\hpoprl08.dat
[2004/06/22 12:16:26 | 000,003,448 | ---- | C] () -- I:\Program Files\hpohub08.inf
[2004/06/22 12:16:26 | 000,002,542 | ---- | C] () -- I:\Program Files\hpoprl02.dat
[2004/06/22 12:16:26 | 000,001,980 | ---- | C] () -- I:\Program Files\hpoprl07.dat
[2004/06/22 12:16:26 | 000,000,314 | ---- | C] () -- I:\Program Files\hpqprl01.dat
[2004/06/22 12:16:26 | 000,000,065 | ---- | C] () -- I:\Program Files\dxprl.dat
[1996/12/17 01:00:00 | 000,022,016 | ---- | C] () -- I:\WINDOWS\System32\DOCOBJ.DLL
[1996/12/17 01:00:00 | 000,012,288 | ---- | C] () -- I:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2010/08/28 16:27:20 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Audacity
[2009/10/31 22:30:40 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\avidemux
[2011/02/04 15:11:28 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\CamfrogWEB
[2009/02/01 20:13:44 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Carnival Software
[2011/02/04 15:31:51 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Copernic
[2010/04/14 13:32:33 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\DAEMON Tools Lite
[2011/05/04 14:08:01 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\DVDVideoSoftIEHelpers
[2010/12/12 12:02:00 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\EPSON
[2009/02/03 19:25:14 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\FFSJ
[2011/02/04 15:44:03 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\GetRightToGo
[2011/02/04 15:51:49 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\GlarySoft
[2009/02/09 16:13:36 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Icone
[2010/05/19 17:06:03 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Icones
[2009/09/03 22:07:37 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\ImgBurn
[2009/05/20 19:59:00 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\LimeWire
[2009/09/09 20:22:36 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\MP-Manager
[2010/06/20 15:49:51 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Mp3tag
[2010/09/11 15:26:09 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Mumble
[2010/02/02 13:56:13 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\PhotoFiltre
[2009/04/28 20:37:15 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\PokerAcademy2
[2011/04/12 15:04:48 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Python-Eggs
[2011/03/07 16:31:41 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Quark
[2011/06/28 20:06:31 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\SolidDocuments
[2010/11/07 13:13:04 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Sports Interactive
[2009/10/22 21:07:20 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\SystemRequirementsLab
[2009/02/14 17:21:42 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Thinstall
[2010/11/12 19:40:18 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\TuneUp Software
[2011/01/16 10:22:59 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Ubisoft
[2010/05/12 17:47:04 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\Ulead Systems
[2010/12/21 13:56:25 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\ValuSoft
[2010/11/13 18:17:37 | 000,000,000 | ---D | M] -- I:\Documents and Settings\Administrateur\Application Data\VitySoft
[2011/02/27 10:52:42 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Atoowin
[2010/08/05 10:05:53 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/05/09 10:57:35 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Electronic Arts
[2010/08/27 18:25:36 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\EPSON
[2009/10/29 12:00:54 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Last.fm
[2010/02/17 21:58:11 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Micro Application
[2011/03/09 11:04:40 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Quark
[2009/02/07 13:06:57 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\RoboForm
[2010/02/18 14:07:49 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\SlySoft
[2009/02/03 20:38:25 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Sports Interactive
[2010/11/12 19:41:16 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/01/16 10:22:59 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Ubisoft
[2010/08/27 18:22:52 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\UDL
[2010/05/12 17:43:29 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/11/12 19:39:42 | 000,000,000 | -HSD | M] -- I:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2010/10/26 15:46:21 | 000,000,000 | ---D | M] -- I:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/29 18:54:42 | 000,000,000 | -HSD | M] -- I:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010/06/18 11:43:26 | 000,000,000 | -HSD | M] -- I:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2011/06/29 14:11:35 | 000,000,330 | ---- | M] () -- I:\WINDOWS\Tasks\GlaryInitialize.job
[2011/03/07 16:31:12 | 000,000,352 | ---- | M] () -- I:\WINDOWS\Tasks\Quark Updater.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 24 bytes -> I:\WINDOWS:37AA49007517554B

< End of report >
Revenir en haut Aller en bas
ouzopower
Moderateurs (trices)
Moderateurs (trices)
ouzopower


Masculin
Nombre de messages : 4422
Age : 61
Localisation : au fond du verre
Humeur : de soif !
Date d'inscription : 30/03/2008

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeMer 29 Juin 2011 - 19:45

bonsoir picmin
ce serait plus cool et plus esthétique d' heberger les rapports stp

http://www.bibou0007.com/t4875-pratique-hebergez-vos-rapports-sur-ci-joint

merci Wink
Revenir en haut Aller en bas
GrosBébé
Moderateurs (trices)
Moderateurs (trices)
GrosBébé


Masculin
Nombre de messages : 6878
Age : 43
Localisation : devant le pc
Date d'inscription : 18/12/2007

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeSam 2 Juil 2011 - 16:13

Bonjour à tous Smile

Picmin, es tu aidé sur un autre forum ?
Revenir en haut Aller en bas
GrosBébé
Moderateurs (trices)
Moderateurs (trices)
GrosBébé


Masculin
Nombre de messages : 6878
Age : 43
Localisation : devant le pc
Date d'inscription : 18/12/2007

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeMar 5 Juil 2011 - 23:45

Re


Toujours avec nous ?
Revenir en haut Aller en bas
GrosBébé
Moderateurs (trices)
Moderateurs (trices)
GrosBébé


Masculin
Nombre de messages : 6878
Age : 43
Localisation : devant le pc
Date d'inscription : 18/12/2007

[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitimeVen 8 Juil 2011 - 10:13

Sujet fermé en raison de l'inactivité. Si vous souhaitez réouvrir ce sujet, faites en la demande à un membre de l'équipe, par MP, en indiquant la raison et le lien vers ce sujet. Cela ne s'applique qu'à Picmin Pour les autres, créez votre propre sujet svp.
Revenir en haut Aller en bas
Contenu sponsorisé





[Fermé] FAKE Cookies messagerie Voila Empty
MessageSujet: Re: [Fermé] FAKE Cookies messagerie Voila   [Fermé] FAKE Cookies messagerie Voila Icon_minitime

Revenir en haut Aller en bas
 
[Fermé] FAKE Cookies messagerie Voila
Revenir en haut 
Page 1 sur 1

Permission de ce forum:Vous ne pouvez pas répondre aux sujets dans ce forum
Bibou le forum :: 
La sécurité
 :: Aide à la désinfection :: Sujets résolus ou anciens
-
Sauter vers: