Ahnrpta virus rapport d'erreurs
Bangs
-
V-X -
V-X -
Bonjour, j'ai suivi le tuto concernant le virus et comme demandé je poste les différents rapports, je remercie d'avance tous ceux qui pourront ou voudront m'aider...
log.txt :
Logfile of random's system information tool 1.05 (written by random/random)
Run by Admin at 2009-01-19 02:30:16
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 46 GB (44%) free of 103 GB
Total RAM: 1023 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:30:26, on 19/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\SFR\Kit\WiFi\9wifi.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\SFR\Media Center\httpd\httpd.exe
C:\Program Files\SFR\Media Center\httpd\httpd.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\AhnRpta.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Bureau\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\cbXRHwtU.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9F77605E-AC80-437E-BC51-EEE4D2810A28} - C:\WINDOWS\system32\awtSMDTm.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Autoconfigurateur WiFi SFR] "C:\Program Files\SFR\Kit\WiFi\9wifi.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
O4 - HKCU\..\Run: [ertyuop] C:\WINDOWS\system32\rttrwq.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O20 - Winlogon Notify: cbXRHwtU - C:\WINDOWS\SYSTEM32\cbXRHwtU.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5352 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\xxiefvzp.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
C:\WINDOWS\system32\cbXRHwtU.dll [2009-01-18 36352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9F77605E-AC80-437E-BC51-EEE4D2810A28}]
C:\WINDOWS\system32\awtSMDTm.dll [2009-01-18 315904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-06-28 8466432]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-06-28 81920]
"nForce Tray Options"=sstray.exe /r []
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"Autoconfigurateur WiFi SFR"=C:\Program Files\SFR\Kit\WiFi\9wifi.exe [2008-09-01 287984]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2006-04-21 94208]
"RocketDock"=C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
"kava"=C:\WINDOWS\system32\kavo.exe [2009-01-11 110134]
"kamsoft"=C:\WINDOWS\system32\kamsoft.exe [2008-12-08 107045]
"vamsoft"=C:\WINDOWS\system32\vamsoft.exe [2009-01-11 109418]
"Neuf Media Center"=C:\Program Files\SFR\Media Center\MediaCenter.exe [2008-10-10 726336]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"cdoosoft"=C:\WINDOWS\system32\olhrwef.exe [2009-01-19 107501]
"ertyuop"=C:\WINDOWS\system32\rttrwq.exe [2009-01-16 105003]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
C:\Documents and Settings\Admin\Menu Démarrer\Programmes\Démarrage
DeskPins.lnk - C:\Program Files\DeskPins\DeskPins.exe
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbXRHwtU]
C:\WINDOWS\system32\cbXRHwtU.dll [2009-01-18 36352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C5F43BEF-CE2F-46D8-AFE6-A647BACD1F09}"=C:\WINDOWS\system32\Bitkv0.dll [2005-07-26 69632]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=C:\WINDOWS\system32\cbXRHwtU.dll [2009-01-18 36352]
"{BB4C402F-882A-4526-8C08-51278EA437C1}"=C:\WINDOWS\system32\afmain0.dll [2005-07-26 78848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\awtSMDTm
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMHelp"=1
"MemCheckBoxInRunDlg"=1
"NoSMBalloonTip"=1
"NoDesktopCleanupWizard"=1
"NoWelcomeScreen"=1
"NoAutoUpdate"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\SFR\Media Center\httpd\httpd.exe"="C:\Program Files\SFR\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.0/255.255.255.0:Enabled:Serveur de partage Media Center (Player SFR)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10e73e6e-0e4d-11dd-8aa2-000c6e30121d}]
shell\AutoRun\command - H:\nm3osq.bat
shell\open\command - H:\nm3osq.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c47-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - F:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c4a-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - D:\j60osk9.cmd
shell\open\command - D:\j60osk9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c4b-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - E:\j60osk9.cmd
shell\open\command - E:\j60osk9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c4d-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - C:\j60osk9.cmd
shell\open\command - C:\j60osk9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae9c2ac8-d509-11dd-8aea-001167664876}]
shell\AutoRun\command - H:\iqe68o.bat
shell\explore\command - H:\iqe68o.bat
shell\open\command - H:\iqe68o.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd66714d-e011-11dd-8aed-001167664876}]
shell\AutoRun\command - H:\x2tpc.cmd
shell\open\command - H:\x2tpc.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8052d25-03b8-11dd-8a9e-000c6e30121d}]
shell\AutoRun\command - H:\m9ma.exe
shell\explore\command - H:\m9ma.exe
shell\open\command - H:\m9ma.exe
======List of files/folders created in the last 3 months======
2009-01-19 02:30:17 ----D---- C:\Program Files\trend micro
2009-01-19 02:30:16 ----D---- C:\rsit
2009-01-19 02:27:09 ----RSH---- C:\WINDOWS\system32\nmdfgds1.dll
2009-01-19 02:26:34 ----A---- C:\WINDOWS\AhnRpta.exe
2009-01-18 20:03:12 ----A---- C:\WINDOWS\system32\a7ce8381-.txt
2009-01-18 20:02:56 ----ASH---- C:\WINDOWS\system32\mTDMStwa.ini2
2009-01-18 20:02:56 ----ASH---- C:\WINDOWS\system32\mTDMStwa.ini
2009-01-18 20:02:53 ----N---- C:\WINDOWS\system32\awtSMDTm.dll
2009-01-18 19:57:55 ----D---- C:\Documents and Settings\All Users\Application Data\Babylon
2009-01-18 19:57:55 ----D---- C:\Documents and Settings\Admin\Application Data\Babylon
2009-01-18 19:57:52 ----A---- C:\WINDOWS\system32\cbXpmMGY.dll
2009-01-18 19:57:50 ----A---- C:\WINDOWS\system32\cbXRHwtU.dll
2009-01-17 17:39:25 ----RSH---- C:\j60osk9.cmd
2009-01-16 21:33:21 ----RSH---- C:\il0byu3h.com
2009-01-16 21:32:55 ----RSH---- C:\WINDOWS\system32\rttrwq.exe
2009-01-16 21:32:55 ----RSH---- C:\WINDOWS\system32\mkfght0.dll
2009-01-16 09:06:57 ----RSH---- C:\x2csvg.exe
2009-01-16 09:06:30 ----RSH---- C:\WINDOWS\system32\olhrwef.exe
2009-01-16 09:06:30 ----N---- C:\WINDOWS\system32\nmdfgds0.dll
2009-01-15 01:42:52 ----D---- C:\Documents and Settings\Admin\Application Data\vlc
2009-01-15 01:34:12 ----D---- C:\WINDOWS\RegisteredPackages
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\px.dll
2009-01-15 01:33:14 ----D---- C:\Program Files\Winamp
2009-01-15 01:33:14 ----D---- C:\Documents and Settings\Admin\Application Data\Winamp
2009-01-13 21:22:21 ----SD---- C:\y - PSP_GAMES
2009-01-12 21:08:25 ----A---- C:\WINDOWS\system32\muweb.dll
2009-01-12 21:08:25 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-01-12 21:08:25 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-01-12 01:27:56 ----D---- C:\WINDOWS\SxsCaPendDel
2009-01-12 01:27:53 ----SHD---- C:\Config.Msi
2009-01-12 01:18:47 ----D---- C:\Program Files\Windows Live SkyDrive
2009-01-12 01:12:37 ----D---- C:\Program Files\Fichiers communs\Windows Live
2009-01-12 01:02:03 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-01-12 01:01:06 ----SHDC---- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2009-01-12 01:00:41 ----D---- C:\Documents and Settings\All Users\Application Data\WLInstaller
2009-01-12 00:56:34 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-01-11 17:51:05 ----RSH---- C:\WINDOWS\system32\ciuytr1.dll
2009-01-11 17:43:22 ----RSH---- C:\x2tpc.cmd
2009-01-11 17:42:56 ----RSH---- C:\WINDOWS\system32\ciuytr0.dll
2009-01-11 17:35:10 ----RSH---- C:\nm3osq.bat
2009-01-04 00:53:44 ----RSH---- C:\i6a0.bat
2009-01-03 00:09:38 ----D---- C:\WINDOWS\system32\NtmsData
2009-01-02 22:28:47 ----D---- C:\Program Files\EuroPoker Tournament Director's Poker Clock
2008-12-30 11:17:06 ----D---- C:\Program Files\SFR
2008-12-27 02:46:10 ----RSH---- C:\iqe68o.bat
2008-12-19 07:49:27 ----RSH---- C:\iky.bat
2008-12-16 11:33:33 ----RASH---- C:\bjj3iccf.com
2008-12-16 09:04:14 ----RSH---- C:\p1y2.cmd
2008-12-13 06:49:08 ----RSH---- C:\h3.bat
2008-12-10 08:33:17 ----RSH---- C:\6fnlpetp.exe
2008-12-10 08:32:51 ----RSH---- C:\WINDOWS\system32\vbsdfe0.dll
2008-12-09 15:29:35 ----RSH---- C:\86m2.cmd
2008-12-09 15:29:34 ----RSH---- C:\3rl3lqbq.bat
2008-12-09 15:29:08 ----RSH---- C:\WINDOWS\system32\vbsdfe1.dll
2008-12-09 15:28:58 ----RSH---- C:\WINDOWS\system32\vamsoft.exe
2008-12-08 17:23:18 ----RSH---- C:\m9ma.exe
2008-12-05 06:37:19 ----RSH---- C:\2u.com
2008-12-03 18:33:03 ----RSH---- C:\rcukd.cmd
2008-12-03 07:29:43 ----RSH---- C:\ncyrf.bat
2008-11-30 21:19:47 ----RSH---- C:\eeqt.exe
2008-11-30 17:12:54 ----D---- C:\Program Files\TVAnts
2008-11-30 11:04:04 ----RSH---- C:\e.cmd
2008-11-29 15:57:19 ----RSH---- C:\i.bat
2008-11-28 06:54:10 ----RSH---- C:\o1.com
2008-11-27 22:07:58 ----RSH---- C:\gwmt83.bat
2008-11-27 05:29:27 ----RSH---- C:\m2nl.bat
2008-11-25 06:18:03 ----RSH---- C:\ij.bat
2008-11-21 19:06:09 ----RSH---- C:\0o.com
2008-11-18 10:40:10 ----RSH---- C:\abk.bat
2008-11-17 06:45:27 ----RSH---- C:\yannh.cmd
2008-11-15 10:27:19 ----D---- C:\Program Files\IKEA HomePlanner
2008-11-15 10:27:01 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-11-15 01:09:55 ----RSH---- C:\wycgb8.cmd
2008-11-14 16:50:21 ----RSH---- C:\0w.com
2008-11-12 19:20:40 ----RSH---- C:\6d9owdry.cmd
2008-11-11 13:47:32 ----RSH---- C:\lky.exe
2008-11-10 15:41:26 ----RSH---- C:\WINDOWS\system32\gasretyw1.dll
2008-11-10 15:28:24 ----D---- C:\Documents and Settings\All Users\Application Data\Planit Fusion Live But
2008-11-10 15:28:24 ----D---- C:\Documents and Settings\Admin\Application Data\Planit International
2008-11-10 15:27:28 ----D---- C:\Program Files\InstallShield Installation Information
2008-11-10 15:27:25 ----D---- C:\Program Files\iDeal Designer
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\TLBINF32.dll
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\MSDBRPT.DLL
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\MSCmCFR.dll
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\CmDlgFR.dll
2008-11-10 13:45:14 ----D---- C:\Program Files\Cuisines Stock 3D
2008-11-09 16:37:19 ----RSH---- C:\whi.com
2008-11-09 16:36:52 ----RSH---- C:\WINDOWS\system32\kamsoft.exe
2008-11-09 16:36:52 ----RSH---- C:\WINDOWS\system32\gasretyw0.dll
2008-11-07 09:24:41 ----RSH---- C:\sq.com
2008-11-06 20:21:29 ----RSH---- C:\r8wb.bat
2008-11-05 07:24:52 ----RSH---- C:\nq0cq.cmd
2008-11-03 16:15:30 ----RSH---- C:\yjkjfuo.cmd
2008-10-30 23:18:37 ----RSH---- C:\obehha.com
2008-10-28 12:11:18 ----D---- C:\Documents and Settings\Admin\Application Data\Google
2008-10-28 12:10:59 ----D---- C:\Program Files\Google
2008-10-24 05:45:52 ----RSH---- C:\xih9.cmd
2008-10-22 07:35:21 ----RSH---- C:\xlk9.com
2008-10-21 13:49:20 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-10-21 13:45:58 ----D---- C:\Program Files\IVT Corporation
======List of files/folders modified in the last 3 months======
2009-01-19 02:30:17 ----RD---- C:\Program Files
2009-01-19 02:27:30 ----D---- C:\Program Files\Mozilla Firefox
2009-01-19 02:27:09 ----D---- C:\WINDOWS\system32
2009-01-19 02:27:08 ----D---- C:\WINDOWS\system32\drivers
2009-01-19 02:26:34 ----D---- C:\WINDOWS
2009-01-19 02:18:19 ----RSH---- C:\WINDOWS\system32\kavo0.dll
2009-01-19 02:16:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-19 02:13:56 ----D---- C:\Program Files\eMule
2009-01-18 21:34:51 ----D---- C:\WINDOWS\Prefetch
2009-01-18 20:50:29 ----D---- C:\WINDOWS\Temp
2009-01-18 19:57:54 ----SD---- C:\WINDOWS\Tasks
2009-01-18 19:17:58 ----D---- C:\Program Files\PKR
2009-01-18 02:12:25 ----A---- C:\WINDOWS\NeroDigital.ini
2009-01-18 02:09:56 ----D---- C:\Documents and Settings\Admin\Application Data\uTorrent
2009-01-16 21:20:46 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-15 01:42:00 ----D---- C:\Program Files\VideoLAN
2009-01-15 01:34:34 ----HD---- C:\WINDOWS\inf
2009-01-15 01:34:34 ----D---- C:\Program Files\Windows Media Player
2009-01-15 01:34:32 ----D---- C:\WINDOWS\security
2009-01-13 00:56:00 ----D---- C:\Documents and Settings\Admin\Application Data\Real
2009-01-12 02:05:12 ----SHD---- C:\WINDOWS\Installer
2009-01-12 02:05:03 ----D---- C:\WINDOWS\WinSxS
2009-01-12 02:05:02 ----D---- C:\WINDOWS\pchealth
2009-01-12 02:02:28 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-01-12 02:01:52 ----D---- C:\Program Files\Windows Live
2009-01-12 01:19:33 ----D---- C:\Program Files\MSN Messenger
2009-01-12 01:18:52 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-12 01:18:29 ----RSD---- C:\WINDOWS\Fonts
2009-01-12 01:12:37 ----D---- C:\Program Files\Fichiers communs
2009-01-12 01:10:07 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-12 01:02:03 ----D---- C:\WINDOWS\Debug
2009-01-12 01:01:47 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-12 00:56:53 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-12 00:56:41 ----D---- C:\WINDOWS\Help
2009-01-11 17:34:44 ----RSH---- C:\WINDOWS\system32\kavo1.dll
2009-01-11 17:34:43 ----RSH---- C:\WINDOWS\system32\kavo.exe
2008-11-09 06:34:19 ----RSH---- C:\WINDOWS\system32\ckvo0.dll
2008-11-09 06:34:18 ----RSH---- C:\WINDOWS\system32\ckvo.exe
2008-11-08 12:29:52 ----RSH---- C:\WINDOWS\system32\ckvo1.dll
2008-10-30 23:21:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-21 17:32:18 ----RSH---- C:\2fiji.com
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2005-10-12 41600]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2005-10-12 60800]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-02 9600]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2005-07-26 12288]
R3 ms_mpu401;Pilote UART MIDI MPU-401 Microsoft; C:\WINDOWS\system32\drivers\msmpu401.sys [2005-07-26 2944]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2005-10-12 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-06-28 6807328]
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2002-12-05 13056]
R3 NVENET;NVIDIA nForce MCP Networking Adapter Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2002-09-23 80896]
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2002-12-05 241664]
R3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2005-11-19 20096]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-02 5888]
R3 rtl8185;Realtek RTL8185 54M Wireless LAN Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys [2007-11-21 308096]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2005-07-26 26496]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-09 36496]
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 hidgame;Activateur de port HID à manette de jeu Microsoft; C:\WINDOWS\system32\DRIVERS\hidgame.sys [2005-07-26 8576]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Pilote de filtre de restauration système; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-19 73600]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-06-28 155716]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
Info.txt : info.txt logfile of random's system information tool 1.05 2009-01-19 02:30:28
======Uninstall list======
"Cuisines Stock 3D"-->C:\PROGRA~1\CUISIN~1\UNWISE.EXE C:\PROGRA~1\CUISIN~1\INSTALL.LOG
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{D6E592B3-67DA-4BBB-9783-E1838FB253A2}
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Bluesoleil2.6.0.8 Release 070517-->MsiExec.exe /X{438BB9B4-65FE-4626-91D9-A8F57B18001D}
DeskPins (remove only)-->"C:\Program Files\DeskPins\uninstall.exe"
eMule-->"C:\Program Files\eMule\Uninstall.exe"
EuroPoker Tournament Director's Poker Clock-->C:\Program Files\EuroPoker Tournament Director's Poker Clock\EuroPoker Tournament Director's Poker Clock.exe /UNINSTALL "C:\WINDOWS\system32\EuroPoker Tournament Director's Poker Clock.log"
ffdshow [rev 1703] [2007-12-15]-->"C:\Program Files\ffdshow\unins000.exe"
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
iDeal Designer-->"C:\Program Files\InstallShield Installation Information\{8E45E95F-18DB-47B0-857C-EBE7F40F1161}\setup.exe" -runfromtemp -l0x040c -removeonly
iDeal Designer-->MsiExec.exe /X{8E45E95F-18DB-47B0-857C-EBE7F40F1161}
IKEA Home Planner-->MsiExec.exe /I{E7310F2E-C551-4FAB-BA07-EAC2E158B1BB}
Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Lame ACM MP3 Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Mise à jour de sécurité pour Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Nero 7 Ultra Edition-->MsiExec.exe /I{70AB1576-7883-2313-C650-7A71270B1036}
NVIDIA Drivers-->C:\WINDOWS\system32\nvuide.exe UninstallGUI
NVIDIA nForce Utilities-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_SSUtilsNT 132 C:\WINDOWS\INF\nvautlml.inf
OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
Pilotes NVIDIA nForce pour Windows 2000/XP-->rundll32.exe C:\WINDOWS\system32\NVNFINST.DLL,NvUninstallCrush
PKR-->"C:\Program Files\PKR\uninstall-pkr.exe"
PSP Video Converter 3-->C:\Program Files\ImTOO\PSP Video Converter 3\Uninstall.exe
QuickTime Alternative 1.78-->"C:\Program Files\QuickTime Alternative\unins000.exe"
Real Alternative 1.51 Lite-->"C:\Program Files\Real Alternative\unins000.exe"
Ri4m v5-->C:\Program Files\Ripp-it_AM\Ri4m_Uninstal.exe
Ripp-It Codec Pack v 4.2.6-->C:\Program Files\Ripp-It Codec Pack\uninst.exe
SC Ver 2.68-->"C:\Program Files\SuperCard\unins000.exe"
SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
SFR - Media Center-->C:\Program Files\SFR\Media Center\uninstall.exe
TVAnts 1.0-->C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG
VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
System event log
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2700
Source Name: Cdrom
Time Written: 20081226114123.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2699
Source Name: Cdrom
Time Written: 20081226114115.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2698
Source Name: Cdrom
Time Written: 20081226114107.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2697
Source Name: Cdrom
Time Written: 20081226114059.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2696
Source Name: Cdrom
Time Written: 20081226114052.000000+060
Event Type: erreur
User:
Application event log
Computer Name: XPSP2-60829E550
Event Code: 100
Message: msnmsgr (2924) Le moteur de base de données 5.01.2600.2180 est démarré.
Record Number: 4416
Source Name: ESENT
Time Written: 20081112102547.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 101
Message: msnmsgr (2924) Le moteur de base de données est arrêté.
Record Number: 4415
Source Name: ESENT
Time Written: 20081112102506.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 103
Message: msnmsgr (2924) \\.\C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Messenger\bangala_971@hotmail.com\SharingMetadata\Working\database_44AC_ED5A_ACED_4750\dfsr.db: Le moteur de base de données a arrêté une instance (0).
Record Number: 4414
Source Name: ESENT
Time Written: 20081112102506.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 704
Message: msnmsgr (2924) La défragmentation en ligne de la base de données '\\.\C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Messenger\bangala_971@hotmail.com\SharingMetadata\Working\database_44AC_ED5A_ACED_4750\dfsr.db' a été interrompue et arrêtée. La prochaine fois qu'une défragmentation en ligne sera effectuée dans cette base de données, elle reprendra à l'endroit où elle a été interrompue.
Record Number: 4413
Source Name: ESENT
Time Written: 20081112102505.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 701
Message: msnmsgr (2924) La défragmentation en ligne a terminé un passage complet dans la base de données '\\.\C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Messenger\bangala_971@hotmail.com\SharingMetadata\Working\database_44AC_ED5A_ACED_4750\dfsr.db'.
Record Number: 4412
Source Name: ESENT
Time Written: 20081112095756.000000+060
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Samsung\Samsung PC Studio 3\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0a00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
log.txt :
Logfile of random's system information tool 1.05 (written by random/random)
Run by Admin at 2009-01-19 02:30:16
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 46 GB (44%) free of 103 GB
Total RAM: 1023 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:30:26, on 19/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\SFR\Kit\WiFi\9wifi.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\SFR\Media Center\httpd\httpd.exe
C:\Program Files\SFR\Media Center\httpd\httpd.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\AhnRpta.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Bureau\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\cbXRHwtU.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9F77605E-AC80-437E-BC51-EEE4D2810A28} - C:\WINDOWS\system32\awtSMDTm.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Autoconfigurateur WiFi SFR] "C:\Program Files\SFR\Kit\WiFi\9wifi.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
O4 - HKCU\..\Run: [ertyuop] C:\WINDOWS\system32\rttrwq.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O20 - Winlogon Notify: cbXRHwtU - C:\WINDOWS\SYSTEM32\cbXRHwtU.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5352 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\xxiefvzp.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
C:\WINDOWS\system32\cbXRHwtU.dll [2009-01-18 36352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9F77605E-AC80-437E-BC51-EEE4D2810A28}]
C:\WINDOWS\system32\awtSMDTm.dll [2009-01-18 315904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-06-28 8466432]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-06-28 81920]
"nForce Tray Options"=sstray.exe /r []
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"Autoconfigurateur WiFi SFR"=C:\Program Files\SFR\Kit\WiFi\9wifi.exe [2008-09-01 287984]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2006-04-21 94208]
"RocketDock"=C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
"kava"=C:\WINDOWS\system32\kavo.exe [2009-01-11 110134]
"kamsoft"=C:\WINDOWS\system32\kamsoft.exe [2008-12-08 107045]
"vamsoft"=C:\WINDOWS\system32\vamsoft.exe [2009-01-11 109418]
"Neuf Media Center"=C:\Program Files\SFR\Media Center\MediaCenter.exe [2008-10-10 726336]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"cdoosoft"=C:\WINDOWS\system32\olhrwef.exe [2009-01-19 107501]
"ertyuop"=C:\WINDOWS\system32\rttrwq.exe [2009-01-16 105003]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
C:\Documents and Settings\Admin\Menu Démarrer\Programmes\Démarrage
DeskPins.lnk - C:\Program Files\DeskPins\DeskPins.exe
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbXRHwtU]
C:\WINDOWS\system32\cbXRHwtU.dll [2009-01-18 36352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C5F43BEF-CE2F-46D8-AFE6-A647BACD1F09}"=C:\WINDOWS\system32\Bitkv0.dll [2005-07-26 69632]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=C:\WINDOWS\system32\cbXRHwtU.dll [2009-01-18 36352]
"{BB4C402F-882A-4526-8C08-51278EA437C1}"=C:\WINDOWS\system32\afmain0.dll [2005-07-26 78848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\awtSMDTm
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMHelp"=1
"MemCheckBoxInRunDlg"=1
"NoSMBalloonTip"=1
"NoDesktopCleanupWizard"=1
"NoWelcomeScreen"=1
"NoAutoUpdate"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\SFR\Media Center\httpd\httpd.exe"="C:\Program Files\SFR\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.0/255.255.255.0:Enabled:Serveur de partage Media Center (Player SFR)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10e73e6e-0e4d-11dd-8aa2-000c6e30121d}]
shell\AutoRun\command - H:\nm3osq.bat
shell\open\command - H:\nm3osq.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c47-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - F:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c4a-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - D:\j60osk9.cmd
shell\open\command - D:\j60osk9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c4b-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - E:\j60osk9.cmd
shell\open\command - E:\j60osk9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16c95c4d-0319-11dd-a43c-806d6172696f}]
shell\AutoRun\command - C:\j60osk9.cmd
shell\open\command - C:\j60osk9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae9c2ac8-d509-11dd-8aea-001167664876}]
shell\AutoRun\command - H:\iqe68o.bat
shell\explore\command - H:\iqe68o.bat
shell\open\command - H:\iqe68o.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd66714d-e011-11dd-8aed-001167664876}]
shell\AutoRun\command - H:\x2tpc.cmd
shell\open\command - H:\x2tpc.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8052d25-03b8-11dd-8a9e-000c6e30121d}]
shell\AutoRun\command - H:\m9ma.exe
shell\explore\command - H:\m9ma.exe
shell\open\command - H:\m9ma.exe
======List of files/folders created in the last 3 months======
2009-01-19 02:30:17 ----D---- C:\Program Files\trend micro
2009-01-19 02:30:16 ----D---- C:\rsit
2009-01-19 02:27:09 ----RSH---- C:\WINDOWS\system32\nmdfgds1.dll
2009-01-19 02:26:34 ----A---- C:\WINDOWS\AhnRpta.exe
2009-01-18 20:03:12 ----A---- C:\WINDOWS\system32\a7ce8381-.txt
2009-01-18 20:02:56 ----ASH---- C:\WINDOWS\system32\mTDMStwa.ini2
2009-01-18 20:02:56 ----ASH---- C:\WINDOWS\system32\mTDMStwa.ini
2009-01-18 20:02:53 ----N---- C:\WINDOWS\system32\awtSMDTm.dll
2009-01-18 19:57:55 ----D---- C:\Documents and Settings\All Users\Application Data\Babylon
2009-01-18 19:57:55 ----D---- C:\Documents and Settings\Admin\Application Data\Babylon
2009-01-18 19:57:52 ----A---- C:\WINDOWS\system32\cbXpmMGY.dll
2009-01-18 19:57:50 ----A---- C:\WINDOWS\system32\cbXRHwtU.dll
2009-01-17 17:39:25 ----RSH---- C:\j60osk9.cmd
2009-01-16 21:33:21 ----RSH---- C:\il0byu3h.com
2009-01-16 21:32:55 ----RSH---- C:\WINDOWS\system32\rttrwq.exe
2009-01-16 21:32:55 ----RSH---- C:\WINDOWS\system32\mkfght0.dll
2009-01-16 09:06:57 ----RSH---- C:\x2csvg.exe
2009-01-16 09:06:30 ----RSH---- C:\WINDOWS\system32\olhrwef.exe
2009-01-16 09:06:30 ----N---- C:\WINDOWS\system32\nmdfgds0.dll
2009-01-15 01:42:52 ----D---- C:\Documents and Settings\Admin\Application Data\vlc
2009-01-15 01:34:12 ----D---- C:\WINDOWS\RegisteredPackages
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-01-15 01:33:16 ----N---- C:\WINDOWS\system32\px.dll
2009-01-15 01:33:14 ----D---- C:\Program Files\Winamp
2009-01-15 01:33:14 ----D---- C:\Documents and Settings\Admin\Application Data\Winamp
2009-01-13 21:22:21 ----SD---- C:\y - PSP_GAMES
2009-01-12 21:08:25 ----A---- C:\WINDOWS\system32\muweb.dll
2009-01-12 21:08:25 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-01-12 21:08:25 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-01-12 01:27:56 ----D---- C:\WINDOWS\SxsCaPendDel
2009-01-12 01:27:53 ----SHD---- C:\Config.Msi
2009-01-12 01:18:47 ----D---- C:\Program Files\Windows Live SkyDrive
2009-01-12 01:12:37 ----D---- C:\Program Files\Fichiers communs\Windows Live
2009-01-12 01:02:03 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-01-12 01:01:06 ----SHDC---- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2009-01-12 01:00:41 ----D---- C:\Documents and Settings\All Users\Application Data\WLInstaller
2009-01-12 00:56:34 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-01-11 17:51:05 ----RSH---- C:\WINDOWS\system32\ciuytr1.dll
2009-01-11 17:43:22 ----RSH---- C:\x2tpc.cmd
2009-01-11 17:42:56 ----RSH---- C:\WINDOWS\system32\ciuytr0.dll
2009-01-11 17:35:10 ----RSH---- C:\nm3osq.bat
2009-01-04 00:53:44 ----RSH---- C:\i6a0.bat
2009-01-03 00:09:38 ----D---- C:\WINDOWS\system32\NtmsData
2009-01-02 22:28:47 ----D---- C:\Program Files\EuroPoker Tournament Director's Poker Clock
2008-12-30 11:17:06 ----D---- C:\Program Files\SFR
2008-12-27 02:46:10 ----RSH---- C:\iqe68o.bat
2008-12-19 07:49:27 ----RSH---- C:\iky.bat
2008-12-16 11:33:33 ----RASH---- C:\bjj3iccf.com
2008-12-16 09:04:14 ----RSH---- C:\p1y2.cmd
2008-12-13 06:49:08 ----RSH---- C:\h3.bat
2008-12-10 08:33:17 ----RSH---- C:\6fnlpetp.exe
2008-12-10 08:32:51 ----RSH---- C:\WINDOWS\system32\vbsdfe0.dll
2008-12-09 15:29:35 ----RSH---- C:\86m2.cmd
2008-12-09 15:29:34 ----RSH---- C:\3rl3lqbq.bat
2008-12-09 15:29:08 ----RSH---- C:\WINDOWS\system32\vbsdfe1.dll
2008-12-09 15:28:58 ----RSH---- C:\WINDOWS\system32\vamsoft.exe
2008-12-08 17:23:18 ----RSH---- C:\m9ma.exe
2008-12-05 06:37:19 ----RSH---- C:\2u.com
2008-12-03 18:33:03 ----RSH---- C:\rcukd.cmd
2008-12-03 07:29:43 ----RSH---- C:\ncyrf.bat
2008-11-30 21:19:47 ----RSH---- C:\eeqt.exe
2008-11-30 17:12:54 ----D---- C:\Program Files\TVAnts
2008-11-30 11:04:04 ----RSH---- C:\e.cmd
2008-11-29 15:57:19 ----RSH---- C:\i.bat
2008-11-28 06:54:10 ----RSH---- C:\o1.com
2008-11-27 22:07:58 ----RSH---- C:\gwmt83.bat
2008-11-27 05:29:27 ----RSH---- C:\m2nl.bat
2008-11-25 06:18:03 ----RSH---- C:\ij.bat
2008-11-21 19:06:09 ----RSH---- C:\0o.com
2008-11-18 10:40:10 ----RSH---- C:\abk.bat
2008-11-17 06:45:27 ----RSH---- C:\yannh.cmd
2008-11-15 10:27:19 ----D---- C:\Program Files\IKEA HomePlanner
2008-11-15 10:27:01 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-11-15 01:09:55 ----RSH---- C:\wycgb8.cmd
2008-11-14 16:50:21 ----RSH---- C:\0w.com
2008-11-12 19:20:40 ----RSH---- C:\6d9owdry.cmd
2008-11-11 13:47:32 ----RSH---- C:\lky.exe
2008-11-10 15:41:26 ----RSH---- C:\WINDOWS\system32\gasretyw1.dll
2008-11-10 15:28:24 ----D---- C:\Documents and Settings\All Users\Application Data\Planit Fusion Live But
2008-11-10 15:28:24 ----D---- C:\Documents and Settings\Admin\Application Data\Planit International
2008-11-10 15:27:28 ----D---- C:\Program Files\InstallShield Installation Information
2008-11-10 15:27:25 ----D---- C:\Program Files\iDeal Designer
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\TLBINF32.dll
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\MSDBRPT.DLL
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\MSCmCFR.dll
2008-11-10 13:45:16 ----A---- C:\WINDOWS\system32\CmDlgFR.dll
2008-11-10 13:45:14 ----D---- C:\Program Files\Cuisines Stock 3D
2008-11-09 16:37:19 ----RSH---- C:\whi.com
2008-11-09 16:36:52 ----RSH---- C:\WINDOWS\system32\kamsoft.exe
2008-11-09 16:36:52 ----RSH---- C:\WINDOWS\system32\gasretyw0.dll
2008-11-07 09:24:41 ----RSH---- C:\sq.com
2008-11-06 20:21:29 ----RSH---- C:\r8wb.bat
2008-11-05 07:24:52 ----RSH---- C:\nq0cq.cmd
2008-11-03 16:15:30 ----RSH---- C:\yjkjfuo.cmd
2008-10-30 23:18:37 ----RSH---- C:\obehha.com
2008-10-28 12:11:18 ----D---- C:\Documents and Settings\Admin\Application Data\Google
2008-10-28 12:10:59 ----D---- C:\Program Files\Google
2008-10-24 05:45:52 ----RSH---- C:\xih9.cmd
2008-10-22 07:35:21 ----RSH---- C:\xlk9.com
2008-10-21 13:49:20 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-10-21 13:45:58 ----D---- C:\Program Files\IVT Corporation
======List of files/folders modified in the last 3 months======
2009-01-19 02:30:17 ----RD---- C:\Program Files
2009-01-19 02:27:30 ----D---- C:\Program Files\Mozilla Firefox
2009-01-19 02:27:09 ----D---- C:\WINDOWS\system32
2009-01-19 02:27:08 ----D---- C:\WINDOWS\system32\drivers
2009-01-19 02:26:34 ----D---- C:\WINDOWS
2009-01-19 02:18:19 ----RSH---- C:\WINDOWS\system32\kavo0.dll
2009-01-19 02:16:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-19 02:13:56 ----D---- C:\Program Files\eMule
2009-01-18 21:34:51 ----D---- C:\WINDOWS\Prefetch
2009-01-18 20:50:29 ----D---- C:\WINDOWS\Temp
2009-01-18 19:57:54 ----SD---- C:\WINDOWS\Tasks
2009-01-18 19:17:58 ----D---- C:\Program Files\PKR
2009-01-18 02:12:25 ----A---- C:\WINDOWS\NeroDigital.ini
2009-01-18 02:09:56 ----D---- C:\Documents and Settings\Admin\Application Data\uTorrent
2009-01-16 21:20:46 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-15 01:42:00 ----D---- C:\Program Files\VideoLAN
2009-01-15 01:34:34 ----HD---- C:\WINDOWS\inf
2009-01-15 01:34:34 ----D---- C:\Program Files\Windows Media Player
2009-01-15 01:34:32 ----D---- C:\WINDOWS\security
2009-01-13 00:56:00 ----D---- C:\Documents and Settings\Admin\Application Data\Real
2009-01-12 02:05:12 ----SHD---- C:\WINDOWS\Installer
2009-01-12 02:05:03 ----D---- C:\WINDOWS\WinSxS
2009-01-12 02:05:02 ----D---- C:\WINDOWS\pchealth
2009-01-12 02:02:28 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-01-12 02:01:52 ----D---- C:\Program Files\Windows Live
2009-01-12 01:19:33 ----D---- C:\Program Files\MSN Messenger
2009-01-12 01:18:52 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-12 01:18:29 ----RSD---- C:\WINDOWS\Fonts
2009-01-12 01:12:37 ----D---- C:\Program Files\Fichiers communs
2009-01-12 01:10:07 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-12 01:02:03 ----D---- C:\WINDOWS\Debug
2009-01-12 01:01:47 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-12 00:56:53 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-12 00:56:41 ----D---- C:\WINDOWS\Help
2009-01-11 17:34:44 ----RSH---- C:\WINDOWS\system32\kavo1.dll
2009-01-11 17:34:43 ----RSH---- C:\WINDOWS\system32\kavo.exe
2008-11-09 06:34:19 ----RSH---- C:\WINDOWS\system32\ckvo0.dll
2008-11-09 06:34:18 ----RSH---- C:\WINDOWS\system32\ckvo.exe
2008-11-08 12:29:52 ----RSH---- C:\WINDOWS\system32\ckvo1.dll
2008-10-30 23:21:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-21 17:32:18 ----RSH---- C:\2fiji.com
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2005-10-12 41600]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2005-10-12 60800]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-02 9600]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2005-07-26 12288]
R3 ms_mpu401;Pilote UART MIDI MPU-401 Microsoft; C:\WINDOWS\system32\drivers\msmpu401.sys [2005-07-26 2944]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2005-10-12 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-06-28 6807328]
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2002-12-05 13056]
R3 NVENET;NVIDIA nForce MCP Networking Adapter Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2002-09-23 80896]
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2002-12-05 241664]
R3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2005-11-19 20096]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-02 5888]
R3 rtl8185;Realtek RTL8185 54M Wireless LAN Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys [2007-11-21 308096]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2005-07-26 26496]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-09 36496]
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 hidgame;Activateur de port HID à manette de jeu Microsoft; C:\WINDOWS\system32\DRIVERS\hidgame.sys [2005-07-26 8576]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Pilote de filtre de restauration système; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-19 73600]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-06-28 155716]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
Info.txt : info.txt logfile of random's system information tool 1.05 2009-01-19 02:30:28
======Uninstall list======
"Cuisines Stock 3D"-->C:\PROGRA~1\CUISIN~1\UNWISE.EXE C:\PROGRA~1\CUISIN~1\INSTALL.LOG
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{D6E592B3-67DA-4BBB-9783-E1838FB253A2}
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Bluesoleil2.6.0.8 Release 070517-->MsiExec.exe /X{438BB9B4-65FE-4626-91D9-A8F57B18001D}
DeskPins (remove only)-->"C:\Program Files\DeskPins\uninstall.exe"
eMule-->"C:\Program Files\eMule\Uninstall.exe"
EuroPoker Tournament Director's Poker Clock-->C:\Program Files\EuroPoker Tournament Director's Poker Clock\EuroPoker Tournament Director's Poker Clock.exe /UNINSTALL "C:\WINDOWS\system32\EuroPoker Tournament Director's Poker Clock.log"
ffdshow [rev 1703] [2007-12-15]-->"C:\Program Files\ffdshow\unins000.exe"
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
iDeal Designer-->"C:\Program Files\InstallShield Installation Information\{8E45E95F-18DB-47B0-857C-EBE7F40F1161}\setup.exe" -runfromtemp -l0x040c -removeonly
iDeal Designer-->MsiExec.exe /X{8E45E95F-18DB-47B0-857C-EBE7F40F1161}
IKEA Home Planner-->MsiExec.exe /I{E7310F2E-C551-4FAB-BA07-EAC2E158B1BB}
Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Lame ACM MP3 Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Mise à jour de sécurité pour Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Nero 7 Ultra Edition-->MsiExec.exe /I{70AB1576-7883-2313-C650-7A71270B1036}
NVIDIA Drivers-->C:\WINDOWS\system32\nvuide.exe UninstallGUI
NVIDIA nForce Utilities-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_SSUtilsNT 132 C:\WINDOWS\INF\nvautlml.inf
OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
Pilotes NVIDIA nForce pour Windows 2000/XP-->rundll32.exe C:\WINDOWS\system32\NVNFINST.DLL,NvUninstallCrush
PKR-->"C:\Program Files\PKR\uninstall-pkr.exe"
PSP Video Converter 3-->C:\Program Files\ImTOO\PSP Video Converter 3\Uninstall.exe
QuickTime Alternative 1.78-->"C:\Program Files\QuickTime Alternative\unins000.exe"
Real Alternative 1.51 Lite-->"C:\Program Files\Real Alternative\unins000.exe"
Ri4m v5-->C:\Program Files\Ripp-it_AM\Ri4m_Uninstal.exe
Ripp-It Codec Pack v 4.2.6-->C:\Program Files\Ripp-It Codec Pack\uninst.exe
SC Ver 2.68-->"C:\Program Files\SuperCard\unins000.exe"
SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
SFR - Media Center-->C:\Program Files\SFR\Media Center\uninstall.exe
TVAnts 1.0-->C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG
VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
System event log
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2700
Source Name: Cdrom
Time Written: 20081226114123.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2699
Source Name: Cdrom
Time Written: 20081226114115.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2698
Source Name: Cdrom
Time Written: 20081226114107.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2697
Source Name: Cdrom
Time Written: 20081226114059.000000+060
Event Type: erreur
User:
Computer Name: XPSP2-60829E550
Event Code: 7
Message: Le périphérique \Device\CdRom1 comporte un bloc défectueux.
Record Number: 2696
Source Name: Cdrom
Time Written: 20081226114052.000000+060
Event Type: erreur
User:
Application event log
Computer Name: XPSP2-60829E550
Event Code: 100
Message: msnmsgr (2924) Le moteur de base de données 5.01.2600.2180 est démarré.
Record Number: 4416
Source Name: ESENT
Time Written: 20081112102547.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 101
Message: msnmsgr (2924) Le moteur de base de données est arrêté.
Record Number: 4415
Source Name: ESENT
Time Written: 20081112102506.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 103
Message: msnmsgr (2924) \\.\C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Messenger\bangala_971@hotmail.com\SharingMetadata\Working\database_44AC_ED5A_ACED_4750\dfsr.db: Le moteur de base de données a arrêté une instance (0).
Record Number: 4414
Source Name: ESENT
Time Written: 20081112102506.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 704
Message: msnmsgr (2924) La défragmentation en ligne de la base de données '\\.\C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Messenger\bangala_971@hotmail.com\SharingMetadata\Working\database_44AC_ED5A_ACED_4750\dfsr.db' a été interrompue et arrêtée. La prochaine fois qu'une défragmentation en ligne sera effectuée dans cette base de données, elle reprendra à l'endroit où elle a été interrompue.
Record Number: 4413
Source Name: ESENT
Time Written: 20081112102505.000000+060
Event Type: Informations
User:
Computer Name: XPSP2-60829E550
Event Code: 701
Message: msnmsgr (2924) La défragmentation en ligne a terminé un passage complet dans la base de données '\\.\C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Messenger\bangala_971@hotmail.com\SharingMetadata\Working\database_44AC_ED5A_ACED_4750\dfsr.db'.
Record Number: 4412
Source Name: ESENT
Time Written: 20081112095756.000000+060
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Samsung\Samsung PC Studio 3\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0a00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
Configuration: Windows XP Firefox 3.0.5
A voir également:
- Ahnrpta virus rapport d'erreurs
- Plan rapport de stage - Guide
- Virus mcafee - Accueil - Piratage
- Rapport erreur windows - Guide
- Comment détruire un virus informatique - Guide
- Un exemple de rapport de travail ✓ - Forum Word
1 réponse
Salut,
▶ Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
▶ Lance l'installation avec les paramètres par défaut.
▶ Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double-clique sur le raccourci UsbFix sur ton Bureau.
▶ Choisit l'option 1
▶ Le PC va redémarrer.
▶ Après redémarrage, poste le rapport UsbFix.txt
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
▶ Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
▶ Lance l'installation avec les paramètres par défaut.
▶ Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double-clique sur le raccourci UsbFix sur ton Bureau.
▶ Choisit l'option 1
▶ Le PC va redémarrer.
▶ Après redémarrage, poste le rapport UsbFix.txt
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.