OTL logfile created on: 25/01/2011 22:06:42 - Run 2 OTL by OldTimer - Version 3.2.20.4 Folder = C:\Users\Ilona\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18999) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 75,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 141,59 Gb Total Space | 24,64 Gb Free Space | 17,40% Space Free | Partition Type: NTFS Drive F: | 562,85 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive G: | 5,95 Gb Total Space | 0,75 Gb Free Space | 12,53% Space Free | Partition Type: NTFS Drive R: | 914,26 Gb Total Space | 765,92 Gb Free Space | 83,77% Space Free | Partition Type: NTFS Drive S: | 914,26 Gb Total Space | 765,92 Gb Free Space | 83,77% Space Free | Partition Type: NTFS Computer Name: ILONA-ET-PIERRE | User Name: Ilona | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011/01/23 19:04:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ilona\Desktop\OTL.exe PRC - [2010/03/04 09:06:06 | 000,038,240 | ---- | M] (Mindjet) -- C:\Program Files\Mindjet\MindManager 8\MmReminderService.exe PRC - [2009/12/03 23:49:40 | 000,099,896 | ---- | M] (HP) -- C:\Windows\System32\HPSIsvc.exe PRC - [2009/11/23 12:31:42 | 000,964,664 | ---- | M] (Seagate) -- C:\Program Files\Seagate\BlackArmorBackup\TimounterMonitor.exe PRC - [2009/11/23 12:30:40 | 000,376,520 | ---- | M] (Seagate) -- C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe PRC - [2009/11/23 12:30:38 | 000,618,216 | ---- | M] (Seagate) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe PRC - [2009/11/23 12:26:46 | 004,383,984 | ---- | M] (Seagate) -- C:\Program Files\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe PRC - [2009/08/23 09:56:38 | 000,386,872 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe PRC - [2009/07/17 10:10:18 | 001,033,480 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe PRC - [2009/07/17 10:10:18 | 000,066,824 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe PRC - [2009/07/17 10:10:16 | 000,931,080 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009/04/11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2009/02/20 20:41:03 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2008/04/15 16:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe PRC - [2008/04/15 16:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe PRC - [2008/01/14 18:26:18 | 004,874,240 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2007/11/02 19:19:39 | 000,033,792 | ---- | M] (EasyBits Software Corp.) -- C:\Windows\System32\ezntsvc.exe PRC - [2007/10/26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe PRC - [2007/09/15 02:29:10 | 000,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPStart.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2011/01/23 19:04:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ilona\Desktop\OTL.exe MOD - [2010/08/31 16:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll MOD - [2010/03/04 09:05:14 | 000,107,856 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mindjet\MindManager 8\msscript.ocx [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2010/03/18 12:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400) SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/12/03 23:49:40 | 000,099,896 | ---- | M] (HP) [Auto | Running] -- C:\Windows\System32\HPSIsvc.exe -- (HPSIService) SRV - [2009/11/23 12:30:38 | 000,618,216 | ---- | M] (Seagate) [Auto | Running] -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (SgtSch2Svc) SRV - [2009/09/25 02:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache) SRV - [2009/07/17 10:10:18 | 001,033,480 | ---- | M] (Raxco Software, Inc.) [On_Demand | Running] -- C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe -- (PDEngine) SRV - [2009/07/17 10:10:16 | 000,931,080 | ---- | M] (Raxco Software, Inc.) [Auto | Running] -- C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe -- (PDAgent) SRV - [2008/04/15 16:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON) Intel(R) SRV - [2008/01/19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2007/12/30 22:47:17 | 000,306,432 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag) SRV - [2007/12/20 10:41:56 | 000,029,440 | ---- | M] (TuneUp Software GmbH) [Disabled | Stopped] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp) SRV - [2007/11/02 19:19:39 | 000,033,792 | ---- | M] (EasyBits Software Corp.) [Auto | Running] -- C:\Windows\System32\ezntsvc.exe -- (ezntsvc) SRV - [2007/10/26 14:28:06 | 001,524,512 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND) SRV - [2007/04/23 17:11:44 | 000,106,593 | ---- | M] () [Auto | Stopped] -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe -- (CLSched) CyberLink Task Scheduler (CTS) SRV - [2007/04/23 17:11:42 | 000,262,243 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) CyberLink Background Capture Service (CBCS) SRV - [2007/01/09 13:55:34 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb) SRV - [2005/11/14 00:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011/01/06 20:34:04 | 000,971,552 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\tdrpm174.sys -- (tdrpman174) Acronis Try&Decide and Restore Points filter (build 174) DRV - [2011/01/06 20:34:02 | 000,568,384 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\timntr.sys -- (timounter) DRV - [2011/01/06 20:33:50 | 000,134,272 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\snman380.sys -- (snapman380) Acronis Snapshots Manager (Build 380) DRV - [2009/12/04 00:05:26 | 000,017,408 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mvusbews.sys -- (mvusbews) DRV - [2009/10/03 05:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009/06/08 09:00:56 | 000,071,696 | ---- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\DefragFs.sys -- (DefragFS) DRV - [2009/05/29 06:41:27 | 004,233,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel(R) DRV - [2009/05/05 11:15:58 | 001,095,808 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) DRV - [2009/04/11 05:42:54 | 000,073,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) Pilote USB audio (WDM) DRV - [2008/04/15 16:53:44 | 000,312,344 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor) DRV - [2008/03/28 01:06:00 | 000,199,472 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP) DRV - [2008/01/15 02:19:04 | 002,047,576 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2007/11/03 11:21:02 | 000,068,096 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive) DRV - [2007/10/26 14:27:00 | 000,306,300 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2007/06/21 11:51:28 | 002,222,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Pilote de carte Intel(R) DRV - [2007/03/05 22:28:00 | 000,076,288 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2007/02/24 15:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007/01/31 13:45:06 | 000,127,376 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE) DRV - [2007/01/23 18:03:28 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007/01/23 17:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) DRV - [2007/01/18 16:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA) DRV - [2006/11/30 09:24:58 | 000,008,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] -- C:\Windows\System32\drivers\eabfiltr.sys -- (eabfiltr) DRV - [2006/11/02 10:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300) DRV - [2006/11/02 10:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx) DRV - [2006/11/02 10:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor) DRV - [2006/11/02 10:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci) DRV - [2006/11/02 10:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci) DRV - [2006/11/02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV) DRV - [2006/11/02 10:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320) DRV - [2006/11/02 10:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2) DRV - [2006/11/02 10:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid) DRV - [2006/11/02 10:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx) DRV - [2006/11/02 10:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata) DRV - [2006/11/02 10:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m) DRV - [2006/11/02 10:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid) DRV - [2006/11/02 10:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960) DRV - [2006/11/02 10:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp) DRV - [2006/11/02 10:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4) DRV - [2006/11/02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor) DRV - [2006/11/02 10:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx) DRV - [2006/11/02 10:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas) DRV - [2006/11/02 10:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI) DRV - [2006/11/02 10:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2) DRV - [2006/11/02 10:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs) DRV - [2006/11/02 10:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc) DRV - [2006/11/02 10:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid) DRV - [2006/11/02 10:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi) DRV - [2006/11/02 10:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS) DRV - [2006/11/02 10:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx) DRV - [2006/11/02 10:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC) DRV - [2006/11/02 10:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3) DRV - [2006/11/02 10:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x) DRV - [2006/11/02 10:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi) DRV - [2006/11/02 10:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas) DRV - [2006/11/02 10:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide) DRV - [2006/11/02 10:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide) DRV - [2006/11/02 10:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide) DRV - [2006/11/02 09:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM) DRV - [2006/11/02 09:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer) DRV - [2006/11/02 09:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp) DRV - [2006/11/02 09:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo) DRV - [2006/11/02 09:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm) DRV - [2006/11/02 09:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm) DRV - [2006/11/02 08:41:50 | 000,987,648 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTDPV3.SYS -- (HSF_DPV) DRV - [2006/11/02 08:41:49 | 000,200,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTAZL3.SYS -- (HSFHWAZL) DRV - [2006/11/02 08:41:48 | 000,654,336 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTCNXT3.SYS -- (winachsf) DRV - [2006/11/02 08:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi) DRV - [2006/11/02 08:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R) DRV - [2006/11/02 08:30:53 | 000,464,384 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BCMWL6.SYS -- (BCM43XV) DRV - [2006/10/19 03:10:57 | 001,380,864 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\igdkmd32.sys -- (ialm) DRV - [2006/10/18 00:09:54 | 000,073,344 | ---- | M] (Ricoh) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\R5U870FLx86.sys -- (R5U870FLx86) DRV - [2006/10/18 00:09:14 | 000,043,904 | ---- | M] (Ricoh) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\R5U870FUx86.sys -- (R5U870FUx86) DRV - [2006/06/28 08:54:00 | 000,009,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBttn.sys -- (HBtnKey) DRV - [2005/08/17 07:46:26 | 000,093,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm) DRV - [2005/08/17 07:46:20 | 000,008,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl) DRV - [2005/08/17 07:45:00 | 000,058,352 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM) DRV - [2003/02/11 13:25:14 | 000,009,216 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pelusblf.sys -- (pelusblf) DRV - [2003/01/10 13:55:32 | 000,016,384 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PELMOUSE.SYS -- (pelmouse) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60265 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60265 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2542115 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultthis.engineName: "Softonic_France Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2542115&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT2542115&SearchSource=13" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2 FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4 FF - prefs.js..extensions.enabledItems: {4daac69c-cba7-45e2-9bc8-1044483d3352}:2.7.2.0 FF - prefs.js..network.proxy.no_proxies_on: "*.local" FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/01/13 19:01:20 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/14 16:46:26 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/14 16:46:26 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/12/13 18:58:26 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/03/28 19:40:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ilona\AppData\Roaming\mozilla\Extensions [2010/03/28 19:40:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ilona\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011/01/23 09:32:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ilona\AppData\Roaming\mozilla\Firefox\Profiles\or4br567.default\extensions [2010/04/30 07:26:33 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Ilona\AppData\Roaming\mozilla\Firefox\Profiles\or4br567.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010/09/05 10:34:00 | 000,000,000 | ---D | M] (Softonic_France Toolbar) -- C:\Users\Ilona\AppData\Roaming\mozilla\Firefox\Profiles\or4br567.default\extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352} [2010/09/05 10:34:00 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Ilona\AppData\Roaming\mozilla\Firefox\Profiles\or4br567.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/08/09 16:10:30 | 000,000,000 | ---D | M] (Tweak Network) -- C:\Users\Ilona\AppData\Roaming\mozilla\Firefox\Profiles\or4br567.default\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA} [2010/03/16 17:11:42 | 000,000,933 | ---- | M] () -- C:\Users\Ilona\AppData\Roaming\Mozilla\Firefox\Profiles\or4br567.default\searchplugins\conduit.xml [2011/01/23 09:32:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions [2009/08/23 11:07:13 | 000,000,000 | ---D | M] (Free Download Manager plugin) -- C:\PROGRAM FILES\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSION [2010/10/30 10:14:03 | 000,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml [2010/10/30 10:14:03 | 000,001,822 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml [2010/10/30 10:14:03 | 000,000,757 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml [2010/10/30 10:14:03 | 000,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml [2010/10/30 10:14:03 | 000,000,956 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml O1 HOSTS File: ([2011/01/25 21:54:41 | 000,000,772 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost ::1 localhost O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet) O2 - BHO: (BHO Barre de Confiance) - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\Barre de Confiance\TAPBar.dll (Euro-Information) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.) O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll () O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Barre de confiance) - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\Barre de Confiance\TAPBar.dll (Euro-Information) O3 - HKLM\..\Toolbar: (I.R.I.S. Desktop Search) - {577EBCA9-8ED3-45FC-A514-55B3817D4BCF} - C:\Program Files\IRIS Desktop Search\IRISDesktopSearchIntegration910.dll (Copernic Technologies Inc.) O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\BlackArmorBackup\TimounterMonitor.exe (Seagate) O4 - HKLM..\Run: [BlackArmorBackupMonitor.exe] C:\Program Files\Seagate\BlackArmorBackup\BlackArmorBackupMonitor.exe (Seagate) O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) O4 - HKLM..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 8\MMReminderService.exe (Mindjet) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\WINDOWS\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Service Scheduler2 Seagate] C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate) O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.) O4 - HKCU..\Run: [I.R.I.S. Desktop Search] C:\Program Files\IRIS Desktop Search\IRISDesktopSearch.exe (Copernic Technologies Inc.) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0 O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm () O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm () O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm () O9 - Extra Button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Envoyer à Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\ezShellStart.exe) - C:\Windows\System32\ezShellStart.exe (EasyBits Software Corp.) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img23.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img23.jpg O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\System32\ezUPBHook.dll (EasyBits Software Corp.) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [1997/10/13 16:42:04 | 000,124,416 | R--- | M] () - F:\AUTORUN.EXE -- [ CDFS ] O32 - AutoRun File - [1997/09/18 13:14:44 | 000,000,045 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ] O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - G:\AUTOMODE -- [ NTFS ] O33 - MountPoints2\{55d7b531-2c7a-11df-8c21-001b2467356a}\Shell - "" = AutoRun O33 - MountPoints2\{55d7b531-2c7a-11df-8c21-001b2467356a}\Shell\AutoRun\command - "" = "J:\WD SmartWare.exe" autoplay=true O33 - MountPoints2\{920d5a3b-54cd-11dc-954a-001b2467356a}\Shell\AutoRun\command - "" = I:\USBNB.exe O33 - MountPoints2\{b347b361-b2d7-11dc-9eef-001b2467356a}\Shell - "" = AutoRun O33 - MountPoints2\{b347b361-b2d7-11dc-9eef-001b2467356a}\Shell\AutoRun\command - "" = F:\AUTORUN.EXE -- [1997/10/13 16:42:04 | 000,124,416 | R--- | M] () O33 - MountPoints2\{f672fec2-b8c4-11df-89af-fde05864149b}\Shell - "" = AutoRun O33 - MountPoints2\{f672fec2-b8c4-11df-89af-fde05864149b}\Shell\AutoRun\command - "" = G:\SISetup.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011/01/23 19:04:29 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ilona\Desktop\OTL.exe [2011/01/19 22:30:21 | 000,000,000 | ---D | C] -- C:\Users\Ilona\AppData\Roaming\Malwarebytes [2011/01/19 22:30:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011/01/19 22:30:14 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011/01/19 22:30:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/01/19 22:30:10 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011/01/19 22:30:09 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011/01/19 22:28:32 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Ilona\Desktop\mbam-setup-1.50.1.1100.exe [2011/01/14 19:34:29 | 000,000,000 | ---D | C] -- C:\Users\Ilona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome [2011/01/13 06:47:56 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll [2011/01/13 06:47:50 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe [2011/01/06 21:22:34 | 000,000,000 | ---D | C] -- C:\Users\Ilona\AppData\Roaming\Seagate [2011/01/06 20:44:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Seagate [2011/01/06 20:34:04 | 000,971,552 | ---- | C] (Acronis) -- C:\Windows\System32\drivers\tdrpm174.sys [2011/01/06 20:34:02 | 000,568,384 | ---- | C] (Acronis) -- C:\Windows\System32\drivers\timntr.sys [2011/01/06 20:33:50 | 000,134,272 | ---- | C] (Acronis) -- C:\Windows\System32\drivers\snman380.sys [2011/01/06 20:33:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Seagate [2011/01/06 20:32:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Maxtor [2011/01/06 20:29:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate [2011/01/06 20:29:18 | 000,000,000 | ---D | C] -- C:\Program Files\Seagate [2011/01/06 20:21:58 | 000,000,000 | ---D | C] -- C:\Users\Ilona\AppData\Roaming\Leadertech [2010/12/31 19:01:33 | 000,000,000 | ---D | C] -- C:\Users\Ilona\AppData\Roaming\AirDownloaderMain.447DBE4B8352E60C6628BA362FFE0160304ED2DC.1 [2010/12/31 19:01:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\musicMe [2010/12/31 19:01:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR [2010/12/31 19:01:21 | 000,000,000 | ---D | C] -- C:\Program Files\musicMe [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011/01/25 21:54:41 | 000,000,772 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts [2011/01/25 21:38:04 | 000,001,076 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2446411076-420533422-722245841-1000UA.job [2011/01/25 21:28:00 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/01/25 21:24:06 | 000,403,676 | ---- | M] () -- C:\ProgramData\nvModes.001 [2011/01/25 21:23:48 | 000,403,676 | ---- | M] () -- C:\ProgramData\nvModes.dat [2011/01/25 21:23:48 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/01/25 21:23:46 | 000,000,562 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics [2011/01/25 21:23:41 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011/01/25 21:23:39 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011/01/25 21:23:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011/01/23 23:23:48 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2011/01/23 19:38:00 | 000,001,024 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2446411076-420533422-722245841-1000Core.job [2011/01/23 19:04:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ilona\Desktop\OTL.exe [2011/01/23 18:23:13 | 000,002,401 | ---- | M] () -- C:\Users\Ilona\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk [2011/01/23 18:17:20 | 000,681,798 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2011/01/23 18:17:20 | 000,598,900 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011/01/23 18:17:20 | 000,127,504 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2011/01/23 18:17:20 | 000,104,914 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011/01/19 22:30:15 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/01/19 22:28:59 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Ilona\Desktop\mbam-setup-1.50.1.1100.exe [2011/01/18 07:47:17 | 000,002,619 | ---- | M] () -- C:\Users\Public\Desktop\BlackArmor Discovery.lnk [2011/01/17 13:26:06 | 005,193,728 | ---- | M] () -- C:\Users\Ilona\Documents\Analyse Matériaux.accdb [2011/01/16 18:23:17 | 000,484,641 | ---- | M] () -- C:\Users\Ilona\Desktop\Galettes.pdf [2011/01/16 18:22:25 | 000,484,641 | ---- | M] () -- C:\Users\Ilona\Documents\Galettes.pdf [2011/01/14 19:34:36 | 000,002,049 | ---- | M] () -- C:\Users\Ilona\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2011/01/06 20:34:04 | 000,971,552 | ---- | M] (Acronis) -- C:\Windows\System32\drivers\tdrpm174.sys [2011/01/06 20:34:02 | 000,568,384 | ---- | M] (Acronis) -- C:\Windows\System32\drivers\timntr.sys [2011/01/06 20:33:50 | 000,134,272 | ---- | M] (Acronis) -- C:\Windows\System32\drivers\snman380.sys [2011/01/06 20:33:41 | 000,001,020 | ---- | M] () -- C:\Users\Public\Desktop\BlackArmor Backup.lnk [2010/12/31 19:01:29 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\musicMeDownloader.lnk [2010/12/28 16:55:03 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011/01/19 22:30:15 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/01/16 18:23:15 | 000,484,641 | ---- | C] () -- C:\Users\Ilona\Desktop\Galettes.pdf [2011/01/16 18:20:45 | 000,484,641 | ---- | C] () -- C:\Users\Ilona\Documents\Galettes.pdf [2011/01/14 19:34:36 | 000,002,049 | ---- | C] () -- C:\Users\Ilona\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2011/01/14 19:33:18 | 000,001,076 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2446411076-420533422-722245841-1000UA.job [2011/01/14 19:33:15 | 000,001,024 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2446411076-420533422-722245841-1000Core.job [2011/01/06 20:33:41 | 000,001,020 | ---- | C] () -- C:\Users\Public\Desktop\BlackArmor Backup.lnk [2011/01/06 20:29:28 | 000,002,619 | ---- | C] () -- C:\Users\Public\Desktop\BlackArmor Discovery.lnk [2010/12/31 19:01:29 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\musicMeDownloader.lnk [2010/09/05 10:51:33 | 000,000,144 | ---- | C] () -- C:\Windows\Readiris.ini [2010/09/05 10:27:56 | 000,163,840 | ---- | C] () -- C:\Windows\System32\HPM1210LM.DLL [2010/09/05 10:24:17 | 000,284,160 | ---- | C] () -- C:\Windows\System32\mvhlewsi.dll [2010/09/05 10:24:15 | 000,167,936 | ---- | C] () -- C:\Windows\System32\m1130wia.dll [2010/09/05 10:24:15 | 000,081,920 | ---- | C] () -- C:\Windows\System32\mvusbews.dll [2010/09/05 10:24:14 | 000,053,248 | ---- | C] () -- C:\Windows\System32\HPM1210SMs.dll [2010/06/07 08:09:43 | 000,017,920 | ---- | C] () -- C:\Windows\System32\IMPLODE.DLL [2010/06/07 08:09:43 | 000,000,400 | ---- | C] () -- C:\Windows\SloOrt.ini [2009/08/17 15:23:20 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2009/08/12 15:28:30 | 000,053,478 | ---- | C] () -- C:\Windows\mvtcpui.ini [2009/08/08 18:56:30 | 000,403,676 | ---- | C] () -- C:\ProgramData\nvModes.dat [2009/08/08 18:56:30 | 000,403,676 | ---- | C] () -- C:\ProgramData\nvModes.001 [2009/08/08 18:14:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll [2009/05/29 15:52:26 | 000,204,800 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2009/05/29 15:47:06 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2008/12/29 22:13:23 | 000,024,206 | ---- | C] () -- C:\Users\Ilona\AppData\Roaming\UserTile.png [2008/10/07 08:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll [2008/10/07 08:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll [2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll [2008/08/26 17:17:06 | 000,003,654 | ---- | C] () -- C:\Windows\System32\drivers\Sonyhcp.dll [2008/04/05 17:22:30 | 000,000,000 | ---- | C] () -- C:\Windows\Irremote.ini [2008/03/28 22:51:00 | 000,000,000 | ---- | C] () -- C:\Users\Ilona\AppData\Local\FnF4.txt [2008/01/13 20:03:36 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini [2008/01/02 00:08:32 | 000,001,356 | ---- | C] () -- C:\Users\Ilona\AppData\Local\d3d9caps.dat [2007/12/31 13:14:07 | 000,000,198 | ---- | C] () -- C:\Windows\Wininit.ini [2007/12/31 08:47:57 | 000,009,728 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll [2007/12/30 22:38:24 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2007/12/30 22:23:06 | 000,024,576 | ---- | C] () -- C:\Windows\System32\FSRremoC.DLL [2007/12/04 20:59:08 | 000,000,033 | ---- | C] () -- C:\Windows\PR1.INI [2007/10/29 19:10:04 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html [2007/10/26 14:28:18 | 000,197,408 | ---- | C] () -- C:\Windows\System32\vpnapi.dll [2007/09/17 21:46:42 | 000,121,344 | ---- | C] () -- C:\Users\Ilona\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007/08/27 22:42:50 | 000,146,213 | ---- | C] () -- C:\Users\Ilona\AppData\Roaming\nvModes.001 [2007/08/27 22:42:31 | 000,146,213 | ---- | C] () -- C:\Users\Ilona\AppData\Roaming\nvModes.dat [2007/08/27 22:13:53 | 000,000,574 | ---- | C] () -- C:\Users\Ilona\AppData\Roaming\wklnhst.dat [2007/08/27 19:23:52 | 000,000,000 | ---- | C] () -- C:\Users\Ilona\AppData\Local\QSwitch.txt [2007/08/27 19:23:52 | 000,000,000 | ---- | C] () -- C:\Users\Ilona\AppData\Local\DSwitch.txt [2007/08/27 19:23:52 | 000,000,000 | ---- | C] () -- C:\Users\Ilona\AppData\Local\AtStart.txt [2007/06/25 22:03:19 | 000,001,111 | ---- | C] () -- C:\ProgramData\hpzinstall.log [2007/02/27 21:43:02 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini [2007/02/05 19:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI [2006/12/13 22:01:36 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll [2006/12/13 22:01:36 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll [2006/11/02 13:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 11:25:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll [2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/03/10 01:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2005/05/07 13:06:00 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll [color=#E56717]========== LOP Check ==========[/color] [2010/12/31 19:01:33 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\AirDownloaderMain.447DBE4B8352E60C6628BA362FFE0160304ED2DC.1 [2009/10/19 19:47:19 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\ArchiFacile [2007/12/31 09:39:01 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Azureus [2007/12/25 12:18:03 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\FarStone [2010/09/05 18:50:34 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\FileZilla [2011/01/11 22:44:19 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Free Download Manager [2010/06/19 15:56:49 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Guitar Pro 6 [2011/01/06 20:21:58 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Leadertech [2007/08/28 19:16:59 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\MusicIP [2009/08/22 23:41:31 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Opera [2007/08/27 22:01:20 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\OTi [2008/12/29 22:13:22 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\PeerNetworking [2011/01/06 21:25:30 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Seagate [2010/03/28 18:54:16 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\SmartDraw [2007/08/27 22:13:55 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Template [2010/03/28 19:40:17 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Thunderbird [2007/12/30 22:47:23 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\TuneUp Software [2010/09/05 18:20:42 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Uniblue [2009/08/23 09:58:44 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\VistaCodecs [2009/08/10 21:39:08 | 000,000,000 | ---D | M] -- C:\Users\Ilona\AppData\Roaming\Yamicsoft [2010/12/10 17:29:24 | 000,000,376 | ---- | M] () -- C:\Windows\Tasks\1-Click Maintenance.job [2011/01/23 23:23:50 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2010/12/20 08:37:49 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{C7B79D89-6AEF-41EB-A899-383A487A1BB3}.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< :OTL >[/color] [color=#A23BEC]< IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = "http://dnl.crawler.com/support/sa_customize.aspx?TbId=60265" >[/color] [color=#A23BEC]< IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = "http://www.crawler.com/search/ie.aspx?tb_id=60265" >[/color] [color=#A23BEC]< IE - HKU\S-1-5-21-2446411076-420533422-722245841-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = "http://search.conduit.com?SearchSource=10&ctid=CT2542115" >[/color] [color=#A23BEC]< FF - prefs.js..browser.search.defaultthis.engineName: "Softonic_France Customized Web Search" >[/color] [color=#A23BEC]< FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2542115&SearchSource=3&q={searchTerms}" >[/color] [color=#A23BEC]< FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT2542115&SearchSource=13" >[/color] [color=#A23BEC]< FF - prefs.js..extensions.enabledItems: {4daac69c-cba7-45e2-9bc8-1044483d3352}:2.7.2.0 >[/color] [color=#A23BEC]< [2010/09/05 10:34:00 | 000,000,000 | ---D | M] (Softonic_France Toolbar) >[/color] Invalid Switch: 05 10:34:00 | 000,000,000 | ---D | M] (Softonic_France Toolbar) [color=#A23BEC]< -- >[/color] [color=#A23BEC]< C:\Users\Ilona\AppData\Roaming\mozilla\Firefox\Profiles\or4br567.default\extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352} >[/color] [color=#A23BEC]< [2010/03/16 17:11:42 | 000,000,933 | ---- | M] () -- C:\Users\Ilona\AppData\Roaming\Mozilla\Firefox\Profiles\or4br567.default\searchplugins\conduit.xml >[/color] Invalid Switch: 16 17:11:42 | 000,000,933 | ---- | M] () -- C:\Users\Ilona\AppData\Roaming\Mozilla\Firefox\Profiles\or4br567.default\searchplugins\conduit.xml [color=#A23BEC]< O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. >[/color] [color=#A23BEC]< >[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C321E34 < End of report >