:Otl
PRC - [2008/01/28 11:43:32 | 000,810,320 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No CLSID value found.
O3 - HKU\S-1-5-21-1736310375-3831867402-2168805588-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast5] File not found
O4 - HKU\S-1-5-21-1736310375-3831867402-2168805588-1000\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\ReadMe.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
IE - HKU\S-1-5-21-1736310375-3831867402-2168805588-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.bearshare.com/ FF - prefs.js..keyword.URL: "http://search.bearshare.com/web?src=ffb&systemid=2&q="
[2009/03/08 21:25:38 | 000,000,000 | ---D | M] -- C:\Users\sandrine\AppData\Roaming\EoRezo
[2009/03/08 21:25:38 | 000,000,000 | ---D | M] -- C:\Users\sandrine\AppData\Roaming\EoRezo
[2011/05/02 19:27:23 | 000,125,636 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2007/11/27 11:45:38 | 000,125,636 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2011/05/02 19:27:23 | 000,103,194 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 12:33:01 | 000,103,194 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2007/11/27 11:45:38 | 000,037,390 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2006/11/02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2011/05/02 19:27:23 | 000,673,938 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2007/11/27 11:45:38 | 000,673,938 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2011/05/02 19:27:23 | 000,591,320 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 12:33:01 | 000,591,320 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2007/11/27 11:45:38 | 000,340,236 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2006/11/02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
:Commands
[emptytemp]
[emptyflash]
[resethosts]
[reboot]