:OTL
[2012/06/22 21:44:36 | 000,002,352 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll File not found
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\TmIEPlg32.dll File not found
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM\..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4 - HKLM\..\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd File not found
O4 - HKLM\..\Run: [] File not found
MsConfig:64bit - StartUpReg:
googletalk - hkey= - key= - C:\Users\Cécile\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
MsConfig:64bit - StartUpFolder: C:^Users^Cécile^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Alertes de surveillance de l'encre - HP Deskjet 3070 B611 series (réseau).lnk - C:\Windows\SysNative\RunDll32.exe - (Microsoft Corporation)
MsConfig:64bit - StartUpReg:
HP Deskjet 3070 B611 series (NET) - hkey= - key= - C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
[2012/09/03 13:03:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Software
[2012/09/02 23:58:26 | 000,000,000 | ---D | C] -- C:\Users\Cécile\AppData\Local\Software
[2012/09/02 23:58:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Software
[2012/08/23 11:38:52 | 000,000,000 | ---D | C] -- C:\Users\Cécile\AppData\Local\{5A42B4B8-5CDE-49F7-9F01-AF0C92C8B07B}
[2012/08/23 01:34:50 | 000,000,000 | -HSD | C] -- C:\found.001
[2012/08/22 12:11:11 | 000,000,000 | -HSD | C] -- C:\found.000
[2012/08/20 00:28:43 | 000,000,000 | ---D | C] -- C:\Users\Cécile\AppData\Local\{CEF9B328-0657-42BC-9A4C-72F515CEB183}
[2012/08/16 14:34:31 | 000,000,000 | ---D | C] -- C:\Users\Cécile\AppData\Local\{367A0435-EFE7-40FC-A1BF-6346167E79D4}
[2012/08/16 14:34:20 | 000,000,000 | ---D | C] -- C:\Users\Cécile\AppData\Local\{7506AEE4-DB96-4969-9E6F-E2770B56E083}
@Alternate Data Stream - 76 bytes -> C:\Users\Cécile\Desktop\L2-S1:Roxio EMC Stream
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:D20FFA63
:Commands
[emptytemp]