Trop de pub quand j'ouvre internet

mlle-agnes -  
mlle-agnes Messages postés 33 Statut Membre -
Bonjour,
Depuis quelques temps, un flot de pub s'affiche lorsque je suis sur internet (mozilla/internet explorer) , je n'en peux plus ! De plus, mon ordinateur rame de plus en plus. J'ai telechargé avast et adaware mais ren n'y fait !
Je vous remercie de votre aide =) !
A voir également:

72 réponses

loloetseb Messages postés 5684 Statut Membre 174
 
Salut VX,

Je vois pas pourquoi tu es si agressif,je lui faire faire findy kill pour supprimer un mountpoint.Ensuite SAS ne se lance pas donc je lui fais faire MBAM à la place.Les lignes fixées et le script fait est justifié.Je ferais navipromo par la suite.
2
loloetseb Messages postés 5684 Statut Membre 174
 
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

-> http://images.malwareremoval.com/random/RSIT.exe

! Déconnecte toi et ferme toutes tes applications en cours !

Double-clique sur " RSIT.exe " pour le lancer .

-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

* Devant l'option "List files/folders created ..." , tu choisis : 2 months

* clique ensuite sur " Continue " pour lancer l'analyse ...

-> laisse faire le scan et ne touche pas au PC ...

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

Important : poste un rapport, puis l'autre dans la réponse suivante
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
1
07061977
 
voila je poste mon log info


Logfile of random's system information tool 1.06 (written by random/random)
Run by Raphael at 2009-04-20 22:40:10
Microsoft® Windows Vista™ Home Premium
System drive C: has 86 GB (59%) free of 146 GB
Total RAM: 2045 MB (69% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\HPCeeScheduleForRaphael.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL [2009-02-27 107896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0\bin\ssv.dll [2006-12-29 501384]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2009-03-19 1006264]
"WAWifiMessage"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [2006-10-18 317152]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2006-10-18 472800]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-11-15 815104]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-01-05 413696]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2006-12-07 90191]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2006-12-07 7766016]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2006-12-07 81920]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-03-26 177472]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"=C:\Windows\SMINST\launcher.exe [2006-11-08 44128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2006-11-28 46704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2006-11-22 1474560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2006-11-06 159744]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
C:\Program Files\HP\QuickPlay\QPService.exe [2006-11-24 167936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0\bin\jusched.exe [2006-12-29 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-11-15 815104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2006-10-23 40048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2006-10-23 734872]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Connections.lnk - C:\Program Files\HP Connections\6811507\Program\HP Connections.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\System32\compstui32.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f07efd02-127c-11de-b349-001636e20c70}]
shell\AutoRun\command - F:\o1.com
shell\explore\command - F:\o1.com
shell\open\command - F:\o1.com


======List of files/folders created in the last 2 months======

2009-04-20 22:40:10 ----D---- C:\rsit
2009-04-20 22:40:10 ----D---- C:\Program Files\trend micro
2009-04-18 23:52:35 ----D---- C:\Users\Raphael\AppData\Roaming\WildTangent
2009-04-18 21:07:29 ----A---- C:\Windows\system32\compstui32.dll
2009-04-18 21:07:28 ----A---- C:\Windows\system32\omayb4Fy52mLOkc.vbs
2009-04-18 19:40:27 ----A---- C:\Windows\system32\GEARAspi.dll
2009-04-18 19:39:58 ----D---- C:\Program Files\iPod
2009-04-18 19:39:53 ----D---- C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-18 19:39:53 ----D---- C:\Program Files\iTunes
2009-04-16 17:01:42 ----A---- C:\Windows\system32\winhttp.dll
2009-04-16 17:01:35 ----A---- C:\Windows\system32\msdtcprx.dll
2009-04-16 17:01:34 ----A---- C:\Windows\system32\xolehlp.dll
2009-04-16 17:01:10 ----A---- C:\Windows\system32\rpcss.dll
2009-04-16 17:01:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-04-16 17:01:06 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-04-16 17:01:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-04-16 17:01:05 ----A---- C:\Windows\system32\sdohlp.dll
2009-04-16 17:01:05 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-04-16 17:01:05 ----A---- C:\Windows\system32\iasrecst.dll
2009-04-16 17:01:05 ----A---- C:\Windows\system32\iasdatastore.dll
2009-04-16 17:01:05 ----A---- C:\Windows\system32\iasads.dll
2009-04-16 17:00:49 ----A---- C:\Windows\system32\secur32.dll
2009-04-16 17:00:49 ----A---- C:\Windows\system32\lsasrv.dll
2009-04-16 17:00:49 ----A---- C:\Windows\system32\kernel32.dll
2009-04-16 17:00:48 ----A---- C:\Windows\system32\lsass.exe
2009-04-16 17:00:48 ----A---- C:\Windows\system32\apilogen.dll
2009-04-16 17:00:48 ----A---- C:\Windows\system32\amxread.dll
2009-04-16 17:00:26 ----A---- C:\Windows\system32\mshtml.dll
2009-04-16 17:00:23 ----A---- C:\Windows\system32\ieframe.dll
2009-04-16 17:00:22 ----A---- C:\Windows\system32\wininet.dll
2009-04-16 17:00:21 ----A---- C:\Windows\system32\mstime.dll
2009-04-16 17:00:20 ----A---- C:\Windows\system32\urlmon.dll
2009-04-16 17:00:19 ----A---- C:\Windows\system32\ieapfltr.dll
2009-04-16 17:00:19 ----A---- C:\Windows\system32\ie4uinit.exe
2009-04-16 17:00:18 ----A---- C:\Windows\system32\mshtmled.dll
2009-04-16 17:00:18 ----A---- C:\Windows\system32\iertutil.dll
2009-04-16 17:00:18 ----A---- C:\Windows\system32\iedkcs32.dll
2009-04-16 17:00:18 ----A---- C:\Windows\system32\icardie.dll
2009-04-16 17:00:18 ----A---- C:\Windows\system32\dxtmsft.dll
2009-04-16 17:00:17 ----A---- C:\Windows\system32\pngfilt.dll
2009-04-16 17:00:17 ----A---- C:\Windows\system32\occache.dll
2009-04-16 17:00:17 ----A---- C:\Windows\system32\msfeeds.dll
2009-04-16 17:00:17 ----A---- C:\Windows\system32\jsproxy.dll
2009-04-16 17:00:17 ----A---- C:\Windows\system32\ieaksie.dll
2009-04-16 17:00:17 ----A---- C:\Windows\system32\dxtrans.dll
2009-04-16 17:00:17 ----A---- C:\Windows\system32\advpack.dll
2009-04-16 17:00:16 ----A---- C:\Windows\system32\ieUnatt.exe
2009-04-16 17:00:16 ----A---- C:\Windows\system32\ieui.dll
2009-04-16 17:00:16 ----A---- C:\Windows\system32\iesetup.dll
2009-04-16 17:00:16 ----A---- C:\Windows\system32\iernonce.dll
2009-04-16 17:00:16 ----A---- C:\Windows\system32\ieencode.dll
2009-04-16 17:00:16 ----A---- C:\Windows\system32\admparse.dll
2009-04-16 17:00:14 ----A---- C:\Windows\system32\mshtmler.dll
2009-04-16 17:00:14 ----A---- C:\Windows\system32\ieakui.dll
2009-04-02 00:45:22 ----A---- C:\Windows\system32\hpz3l4v2.dll
2009-03-30 02:51:49 ----D---- C:\Symlogs
2009-03-29 23:19:39 ----D---- C:\Program Files\MSN
2009-03-25 17:19:18 ----D---- C:\Users\Raphael\AppData\Roaming\CyberLink
2009-03-21 19:14:45 ----A---- C:\Windows\system32\icardagt.exe
2009-03-21 19:14:44 ----A---- C:\Windows\system32\infocardapi.dll
2009-03-21 19:14:44 ----A---- C:\Windows\system32\icardres.dll
2009-03-21 19:14:36 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-03-21 19:14:34 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-03-21 19:14:34 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-03-21 19:14:34 ----A---- C:\Windows\system32\PresentationHost.exe
2009-03-21 18:44:19 ----A---- C:\Windows\system32\netfxperf.dll
2009-03-21 18:44:19 ----A---- C:\Windows\system32\dfshim.dll
2009-03-21 18:44:16 ----A---- C:\Windows\system32\mscorier.dll
2009-03-21 18:44:16 ----A---- C:\Windows\system32\mscoree.dll
2009-03-21 18:44:15 ----A---- C:\Windows\system32\mscories.dll
2009-03-21 13:39:28 ----A---- C:\Windows\system32\es.dll
2009-03-19 02:35:14 ----D---- C:\Users\Raphael\AppData\Roaming\Apple Computer
2009-03-19 02:34:35 ----DC---- C:\Windows\system32\DRVSTORE
2009-03-19 02:33:44 ----D---- C:\ProgramData\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-19 02:32:54 ----D---- C:\Program Files\Bonjour
2009-03-19 02:31:38 ----D---- C:\Program Files\QuickTime
2009-03-19 02:31:35 ----D---- C:\ProgramData\Apple Computer
2009-03-19 02:30:47 ----D---- C:\Program Files\Apple Software Update
2009-03-19 02:29:41 ----D---- C:\Program Files\Common Files\Apple
2009-03-19 02:29:37 ----D---- C:\ProgramData\Apple
2009-03-19 02:10:25 ----D---- C:\Users\Raphael\AppData\Roaming\Mozilla
2009-03-19 02:09:59 ----D---- C:\Users\Raphael\AppData\Roaming\LimeWire
2009-03-19 02:08:38 ----D---- C:\Program Files\LimeWire
2009-03-19 01:30:55 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2009-03-19 01:30:54 ----A---- C:\Windows\system32\winipsec.dll
2009-03-19 01:30:54 ----A---- C:\Windows\system32\polstore.dll
2009-03-19 01:30:54 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-03-19 01:29:10 ----A---- C:\Windows\system32\riched32.dll
2009-03-19 01:29:10 ----A---- C:\Windows\system32\riched20.dll
2009-03-19 01:29:07 ----A---- C:\Windows\system32\rasser.dll
2009-03-19 01:29:06 ----A---- C:\Windows\system32\rasmxs.dll
2009-03-19 01:29:06 ----A---- C:\Windows\system32\rasdiag.dll
2009-03-19 01:29:06 ----A---- C:\Windows\system32\rascfg.dll
2009-03-19 01:29:05 ----A---- C:\Windows\system32\netcfgx.dll
2009-03-19 01:29:05 ----A---- C:\Windows\system32\msftedit.dll
2009-03-19 01:29:04 ----A---- C:\Windows\system32\ipnathlp.dll
2009-03-19 01:29:04 ----A---- C:\Windows\system32\icsunattend.exe
2009-03-19 01:29:02 ----A---- C:\Windows\system32\wshqos.dll
2009-03-19 01:29:02 ----A---- C:\Windows\system32\traffic.dll
2009-03-19 01:29:02 ----A---- C:\Windows\system32\pacerprf.dll
2009-03-19 01:29:01 ----A---- C:\Windows\system32\localspl.dll
2009-03-19 01:29:01 ----A---- C:\Windows\system32\dps.dll
2009-03-19 01:29:01 ----A---- C:\Windows\system32\cdd.dll
2009-03-19 01:27:25 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-03-19 01:27:24 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-03-19 01:27:24 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-03-19 01:25:36 ----A---- C:\Windows\system32\msoert2.dll
2009-03-19 01:25:36 ----A---- C:\Windows\system32\msoeacct.dll
2009-03-19 01:25:36 ----A---- C:\Windows\system32\ACCTRES.dll
2009-03-19 01:23:50 ----A---- C:\Windows\system32\wtsapi32.dll
2009-03-19 01:23:46 ----A---- C:\Windows\system32\sysmain.dll
2009-03-19 01:23:44 ----A---- C:\Windows\system32\wlanmsm.dll
2009-03-19 01:23:44 ----A---- C:\Windows\system32\wlanhlp.dll
2009-03-19 01:23:44 ----A---- C:\Windows\system32\wlanapi.dll
2009-03-19 01:23:43 ----A---- C:\Windows\system32\wlansvc.dll
2009-03-19 01:23:43 ----A---- C:\Windows\system32\wlansec.dll
2009-03-19 01:23:43 ----A---- C:\Windows\system32\gatherWirelessInfo.vbs
2009-03-19 01:22:12 ----A---- C:\Windows\system32\WebClnt.dll
2009-03-19 01:17:09 ----A---- C:\Windows\system32\winsrv.dll
2009-03-19 01:17:09 ----A---- C:\Windows\system32\csrsrv.dll
2009-03-19 01:11:38 ----A---- C:\Windows\system32\gdi32.dll
2009-03-19 01:08:22 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-03-19 01:07:18 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-03-19 01:07:13 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-03-19 01:07:13 ----A---- C:\Windows\system32\gameux.dll
2009-03-19 01:05:56 ----A---- C:\Windows\system32\wmpeffects.dll
2009-03-19 01:04:50 ----A---- C:\Windows\system32\msxml3.dll
2009-03-19 01:04:49 ----A---- C:\Windows\system32\msxml3r.dll
2009-03-19 01:03:43 ----A---- C:\Windows\system32\wmdrmsdk.dll
2009-03-19 01:03:43 ----A---- C:\Windows\system32\drmv2clt.dll
2009-03-19 01:03:43 ----A---- C:\Windows\system32\drmmgrtn.dll
2009-03-19 01:03:43 ----A---- C:\Windows\system32\blackbox.dll
2009-03-19 01:03:42 ----A---- C:\Windows\system32\msscp.dll
2009-03-19 01:03:42 ----A---- C:\Windows\system32\msnetobj.dll
2009-03-19 01:02:33 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2009-03-19 01:01:26 ----A---- C:\Windows\system32\FirewallAPI.dll
2009-03-19 01:01:25 ----A---- C:\Windows\system32\MPSSVC.dll
2009-03-19 01:01:25 ----A---- C:\Windows\system32\icfupgd.dll
2009-03-19 01:01:24 ----A---- C:\Windows\system32\wfapigp.dll
2009-03-19 01:01:24 ----A---- C:\Windows\system32\cmifw.dll
2009-03-19 01:01:23 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-03-19 01:00:21 ----A---- C:\Windows\system32\netapi32.dll
2009-03-19 00:59:05 ----A---- C:\Windows\system32\tzres.dll
2009-03-19 00:56:49 ----A---- C:\Windows\system32\mcmde.dll
2009-03-19 00:56:48 ----A---- C:\Windows\system32\EncDec.dll
2009-03-19 00:56:47 ----A---- C:\Windows\system32\psisdecd.dll
2009-03-19 00:55:20 ----A---- C:\Windows\system32\wmploc.DLL
2009-03-19 00:55:19 ----A---- C:\Windows\system32\wmp.dll
2009-03-19 00:55:18 ----A---- C:\Windows\system32\spwmp.dll
2009-03-19 00:55:17 ----A---- C:\Windows\system32\dxmasf.dll
2009-03-19 00:52:42 ----A---- C:\Windows\system32\shell32.dll
2009-03-19 00:48:43 ----A---- C:\Windows\system32\DWWIN.EXE
2009-03-19 00:48:00 ----A---- C:\Windows\explorer.exe
2009-03-19 00:46:16 ----A---- C:\Windows\system32\hcrstco.dll
2009-03-19 00:46:16 ----A---- C:\Windows\system32\hccoin.dll
2009-03-19 00:44:45 ----A---- C:\Windows\system32\tcpipcfg.dll
2009-03-19 00:44:45 ----A---- C:\Windows\system32\netiougc.exe
2009-03-19 00:44:45 ----A---- C:\Windows\system32\netcfg.exe
2009-03-19 00:43:57 ----A---- C:\Windows\system32\NlsLexicons0046.dll
2009-03-19 00:43:57 ----A---- C:\Windows\system32\NlsLexicons0045.dll
2009-03-19 00:43:56 ----A---- C:\Windows\system32\NlsLexicons0049.dll
2009-03-19 00:43:56 ----A---- C:\Windows\system32\NlsLexicons0047.dll
2009-03-19 00:43:55 ----A---- C:\Windows\system32\NlsLexicons0039.dll
2009-03-19 00:43:55 ----A---- C:\Windows\system32\NlsLexicons0020.dll
2009-03-19 00:43:54 ----A---- C:\Windows\system32\NlsLexicons0022.dll
2009-03-19 00:43:54 ----A---- C:\Windows\system32\NlsLexicons0021.dll
2009-03-19 00:43:53 ----A---- C:\Windows\system32\NlsLexicons0024.dll
2009-03-19 00:43:52 ----A---- C:\Windows\system32\NlsLexicons0027.dll
2009-03-19 00:43:52 ----A---- C:\Windows\system32\NlsLexicons0026.dll
2009-03-19 00:43:51 ----A---- C:\Windows\system32\NlsLexicons0011.dll
2009-03-19 00:43:51 ----A---- C:\Windows\system32\NlsLexicons0010.dll
2009-03-19 00:43:50 ----A---- C:\Windows\system32\NlsLexicons0013.dll
2009-03-19 00:43:49 ----A---- C:\Windows\system32\NlsLexicons0018.dll
2009-03-19 00:43:48 ----A---- C:\Windows\system32\NlsLexicons0019.dll
2009-03-19 00:43:47 ----A---- C:\Windows\system32\NlsLexicons0003.dll
2009-03-19 00:43:47 ----A---- C:\Windows\system32\NlsLexicons0002.dll
2009-03-19 00:43:47 ----A---- C:\Windows\system32\NlsLexicons0001.dll
2009-03-19 00:43:45 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-03-19 00:43:45 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-03-19 00:43:44 ----A---- C:\Windows\system32\NlsLexicons004b.dll
2009-03-19 00:43:44 ----A---- C:\Windows\system32\NlsLexicons004a.dll
2009-03-19 00:43:43 ----A---- C:\Windows\system32\NlsLexicons004e.dll
2009-03-19 00:43:43 ----A---- C:\Windows\system32\NlsLexicons004c.dll
2009-03-19 00:43:43 ----A---- C:\Windows\system32\NlsLexicons003e.dll
2009-03-19 00:43:42 ----A---- C:\Windows\system32\NlsLexicons002a.dll
2009-03-19 00:43:42 ----A---- C:\Windows\system32\NlsLexicons001a.dll
2009-03-19 00:43:40 ----A---- C:\Windows\system32\NlsLexicons001d.dll
2009-03-19 00:43:40 ----A---- C:\Windows\system32\NlsLexicons001b.dll
2009-03-19 00:43:38 ----A---- C:\Windows\system32\NlsLexicons000c.dll
2009-03-19 00:43:38 ----A---- C:\Windows\system32\NlsLexicons000a.dll
2009-03-19 00:43:37 ----A---- C:\Windows\system32\NlsLexicons000f.dll
2009-03-19 00:43:37 ----A---- C:\Windows\system32\NlsLexicons000d.dll
2009-03-19 00:43:36 ----A---- C:\Windows\system32\NlsLexicons0414.dll
2009-03-19 00:43:35 ----A---- C:\Windows\system32\NlsLexicons0416.dll
2009-03-19 00:43:34 ----A---- C:\Windows\system32\NlsLexicons081a.dll
2009-03-19 00:43:34 ----A---- C:\Windows\system32\NlsLexicons0816.dll
2009-03-19 00:43:33 ----A---- C:\Windows\system32\NlsModels0011.dll
2009-03-19 00:43:33 ----A---- C:\Windows\system32\NlsData0045.dll
2009-03-19 00:43:32 ----A---- C:\Windows\system32\NlsData0049.dll
2009-03-19 00:43:32 ----A---- C:\Windows\system32\NlsData0047.dll
2009-03-19 00:43:32 ----A---- C:\Windows\system32\NlsData0046.dll
2009-03-19 00:43:31 ----A---- C:\Windows\system32\NlsData0039.dll
2009-03-19 00:43:31 ----A---- C:\Windows\system32\NlsData0021.dll
2009-03-19 00:43:31 ----A---- C:\Windows\system32\NlsData0020.dll
2009-03-19 00:43:30 ----A---- C:\Windows\system32\NlsData0026.dll
2009-03-19 00:43:30 ----A---- C:\Windows\system32\NlsData0024.dll
2009-03-19 00:43:30 ----A---- C:\Windows\system32\NlsData0022.dll
2009-03-19 00:43:29 ----A---- C:\Windows\system32\NlsData0027.dll
2009-03-19 00:43:28 ----A---- C:\Windows\system32\NlsData0010.dll
2009-03-19 00:43:27 ----A---- C:\Windows\system32\NlsData0018.dll
2009-03-19 00:43:27 ----A---- C:\Windows\system32\NlsData0013.dll
2009-03-19 00:43:27 ----A---- C:\Windows\system32\NlsData0011.dll
2009-03-19 00:43:26 ----A---- C:\Windows\system32\NlsData0019.dll
2009-03-19 00:43:26 ----A---- C:\Windows\system32\NlsData0001.dll
2009-03-19 00:43:26 ----A---- C:\Windows\system32\NlsData0000.dll
2009-03-19 00:43:25 ----A---- C:\Windows\system32\NlsData0003.dll
2009-03-19 00:43:25 ----A---- C:\Windows\system32\NlsData0002.dll
2009-03-19 00:43:24 ----A---- C:\Windows\system32\NlsData0009.dll
2009-03-19 00:43:24 ----A---- C:\Windows\system32\NlsData0007.dll
2009-03-19 00:43:23 ----A---- C:\Windows\system32\NlsData004b.dll
2009-03-19 00:43:23 ----A---- C:\Windows\system32\NlsData004a.dll
2009-03-19 00:43:22 ----A---- C:\Windows\system32\NlsData004e.dll
2009-03-19 00:43:22 ----A---- C:\Windows\system32\NlsData004c.dll
2009-03-19 00:43:22 ----A---- C:\Windows\system32\NlsData003e.dll
2009-03-19 00:43:21 ----A---- C:\Windows\system32\NlsData002a.dll
2009-03-19 00:43:21 ----A---- C:\Windows\system32\NlsData001b.dll
2009-03-19 00:43:21 ----A---- C:\Windows\system32\NlsData001a.dll
2009-03-19 00:43:20 ----A---- C:\Windows\system32\NlsData001d.dll
2009-03-19 00:43:19 ----A---- C:\Windows\system32\NlsData000a.dll
2009-03-19 00:43:18 ----A---- C:\Windows\system32\NlsData000d.dll
2009-03-19 00:43:18 ----A---- C:\Windows\system32\NlsData000c.dll
2009-03-19 00:43:17 ----A---- C:\Windows\system32\NlsData0414.dll
2009-03-19 00:43:17 ----A---- C:\Windows\system32\NlsData000f.dll
2009-03-19 00:43:16 ----A---- C:\Windows\system32\NlsData0416.dll
2009-03-19 00:43:16 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-03-19 00:43:15 ----A---- C:\Windows\system32\NlsLexicons0c1a.dll
2009-03-19 00:43:15 ----A---- C:\Windows\system32\NlsData081a.dll
2009-03-19 00:43:15 ----A---- C:\Windows\system32\NlsData0816.dll
2009-03-19 00:43:14 ----A---- C:\Windows\system32\NlsData0c1a.dll
2009-03-19 00:38:03 ----A---- C:\Windows\system32\setupapi.dll
2009-03-19 00:37:08 ----A---- C:\Windows\system32\srcore.dll
2009-03-19 00:37:08 ----A---- C:\Windows\system32\srclient.dll
2009-03-19 00:37:08 ----A---- C:\Windows\system32\rstrui.exe
2009-03-19 00:37:07 ----A---- C:\Windows\system32\wpd_ci.dll
2009-03-19 00:37:07 ----A---- C:\Windows\system32\srdelayed.exe
2009-03-19 00:37:07 ----A---- C:\Windows\system32\kd1394.dll
2009-03-19 00:37:06 ----A---- C:\Windows\system32\winresume.exe
2009-03-19 00:37:06 ----A---- C:\Windows\system32\winload.exe
2009-03-19 00:37:05 ----A---- C:\Windows\system32\ci.dll
2009-03-19 00:37:05 ----A---- C:\Windows\system32\cfgmgr32.dll
2009-03-19 00:37:04 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-03-19 00:37:04 ----A---- C:\Windows\system32\drvinst.exe
2009-03-19 00:37:03 ----A---- C:\Windows\system32\kbd106n.dll
2009-03-19 00:37:03 ----A---- C:\Windows\system32\dpx.dll
2009-03-19 00:37:02 ----A---- C:\Windows\system32\oleaut32.dll
2009-03-19 00:37:02 ----A---- C:\Windows\system32\nshhttp.dll
2009-03-19 00:37:01 ----A---- C:\Windows\system32\unlodctr.exe
2009-03-19 00:37:01 ----A---- C:\Windows\system32\prflbmsg.dll
2009-03-19 00:37:01 ----A---- C:\Windows\system32\lodctr.exe
2009-03-19 00:37:01 ----A---- C:\Windows\system32\loadperf.dll
2009-03-19 00:37:00 ----A---- C:\Windows\system32\schedsvc.dll
2009-03-19 00:36:58 ----A---- C:\Windows\system32\f3ahvoas.dll
2009-03-19 00:36:58 ----A---- C:\Windows\system32\dispci.dll
2009-03-19 00:36:58 ----A---- C:\Windows\system32\batt.dll
2009-03-19 00:32:46 ----A---- C:\Windows\system32\LAPRXY.DLL
2009-03-19 00:32:45 ----A---- C:\Windows\system32\WMASF.DLL
2009-03-19 00:32:45 ----A---- C:\Windows\system32\asferror.dll
2009-03-19 00:32:02 ----A---- C:\Windows\system32\SLC.dll
2009-03-19 00:32:02 ----A---- C:\Windows\system32\mcbuilder.exe
2009-03-19 00:32:01 ----A---- C:\Windows\system32\slwmi.dll
2009-03-19 00:31:58 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-03-19 00:31:57 ----A---- C:\Windows\system32\SLUI.exe
2009-03-19 00:31:56 ----A---- C:\Windows\system32\SLUINotify.dll
2009-03-19 00:31:56 ----A---- C:\Windows\system32\SLLUA.exe
2009-03-19 00:31:54 ----A---- C:\Windows\system32\SLsvc.exe
2009-03-19 00:31:54 ----A---- C:\Windows\system32\slcinst.dll
2009-03-19 00:30:44 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-03-19 00:30:44 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-03-19 00:30:42 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-03-19 00:27:27 ----A---- C:\Windows\system32\ntprint.exe
2009-03-19 00:27:27 ----A---- C:\Windows\system32\ntprint.dll
2009-03-19 00:27:25 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-03-19 00:27:25 ----A---- C:\Windows\system32\dhcpcsvc.dll
2009-03-19 00:27:25 ----A---- C:\Windows\system32\dhcpcmonitor.dll
2009-03-19 00:27:24 ----A---- C:\Windows\system32\authui.dll
2009-03-19 00:27:21 ----A---- C:\Windows\system32\msvfw32.dll
2009-03-19 00:27:21 ----A---- C:\Windows\system32\mciavi32.dll
2009-03-19 00:27:21 ----A---- C:\Windows\system32\avifil32.dll
2009-03-19 00:27:21 ----A---- C:\Windows\system32\avicap32.dll
2009-03-19 00:27:20 ----A---- C:\Windows\system32\msvidc32.dll
2009-03-19 00:27:20 ----A---- C:\Windows\system32\msrle32.dll
2009-03-19 00:27:19 ----A---- C:\Windows\system32\sendmail.dll
2009-03-19 00:26:30 ----A---- C:\Windows\system32\win32spl.dll
2009-03-19 00:26:30 ----A---- C:\Windows\system32\printcom.dll
2009-03-19 00:26:01 ----A---- C:\Windows\system32\wshrm.dll
2009-03-19 00:25:31 ----A---- C:\Windows\system32\sbunattend.exe
2009-03-19 00:24:14 ----A---- C:\Windows\system32\dnsrslvr.dll
2009-03-19 00:24:14 ----A---- C:\Windows\system32\dnscacheugc.exe
2009-03-19 00:24:14 ----A---- C:\Windows\system32\dnsapi.dll
2009-03-19 00:23:36 ----A---- C:\Windows\system32\schannel.dll
2009-03-19 00:23:05 ----A---- C:\Windows\system32\mfps.dll
2009-03-19 00:23:05 ----A---- C:\Windows\system32\mf.dll
2009-03-19 00:23:04 ----A---- C:\Windows\system32\rrinstaller.exe
2009-03-19 00:23:04 ----A---- C:\Windows\system32\mfpmp.exe
2009-03-19 00:23:04 ----A---- C:\Windows\system32\mferror.dll
2009-03-19 00:23:02 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-03-19 00:23:02 ----A---- C:\Windows\system32\logagent.exe
2009-03-19 00:22:59 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-03-19 00:22:09 ----A---- C:\Windows\system32\rpcrt4.dll
2009-03-19 00:21:35 ----A---- C:\Windows\system32\INETRES.dll
2009-03-19 00:21:35 ----A---- C:\Windows\system32\inetcomm.dll
2009-03-19 00:21:06 ----A---- C:\Windows\system32\connect.dll
2009-03-19 00:20:34 ----A---- C:\Windows\system32\wmi.dll
2009-03-19 00:20:33 ----A---- C:\Windows\system32\imagehlp.dll
2009-03-19 00:20:10 ----A---- C:\Windows\system32\quartz.dll
2009-03-19 00:19:24 ----A---- C:\Windows\system32\crypt32.dll
2009-03-19 00:19:00 ----D---- C:\Program Files\MSXML 4.0
2009-03-19 00:18:04 ----A---- C:\Windows\system32\user32.dll
2009-03-19 00:17:49 ----A---- C:\Windows\system32\msxml6r.dll
2009-03-19 00:17:49 ----A---- C:\Windows\system32\msxml6.dll
2009-03-19 00:16:34 ----A---- C:\Windows\system32\qmgr.dll
2009-03-19 00:05:47 ----D---- C:\Users\Raphael\AppData\Roaming\Roxio
2009-03-18 23:21:39 ----D---- C:\Program Files\SAGEM
2009-03-16 23:34:31 ----A---- C:\Windows\ODBC.INI
2009-03-16 23:34:09 ----A---- C:\Windows\system32\mdimon.dll
2009-03-16 23:28:01 ----D---- C:\Program Files\Common Files\DESIGNER
2009-03-16 23:27:12 ----D---- C:\Program Files\Microsoft Visual Studio
2009-03-16 23:24:19 ----D---- C:\Windows\PCHEALTH
2009-03-16 23:24:19 ----D---- C:\Program Files\Microsoft.NET
2009-03-16 23:20:52 ----RHD---- C:\MSOCache
2009-03-16 22:11:35 ----D---- C:\Users\Raphael\AppData\Roaming\Macromedia
2009-03-16 22:09:38 ----RD---- C:\Program Files\Norton Support
2009-03-16 21:59:43 ----A---- C:\Windows\system32\wups2.dll
2009-03-16 21:59:43 ----A---- C:\Windows\system32\wucltux.dll
2009-03-16 21:59:43 ----A---- C:\Windows\system32\wuaueng.dll
2009-03-16 21:59:43 ----A---- C:\Windows\system32\wuauclt.exe
2009-03-16 21:59:24 ----A---- C:\Windows\system32\wups.dll
2009-03-16 21:59:24 ----A---- C:\Windows\system32\wudriver.dll
2009-03-16 21:59:23 ----A---- C:\Windows\system32\wuapi.dll
2009-03-16 21:59:11 ----A---- C:\Windows\system32\wuwebv.dll
2009-03-16 21:59:11 ----A---- C:\Windows\system32\wuapp.exe
2009-03-16 21:54:07 ----D---- C:\Program Files\Symantec
2009-03-16 21:53:45 ----D---- C:\ProgramData\Norton
2009-03-16 21:53:45 ----D---- C:\Program Files\Norton AntiVirus
2009-03-16 21:52:23 ----D---- C:\ProgramData\NortonInstaller
2009-03-16 21:52:23 ----D---- C:\Program Files\NortonInstaller
2009-03-16 06:52:08 ----D---- C:\Windows\SoftwareDistribution
2009-03-16 06:50:48 ----SHD---- C:\System Volume Information
2009-03-16 06:47:16 ----D---- C:\Windows\Prefetch
2009-03-15 23:46:39 ----D---- C:\Windows\pss
2009-03-15 23:37:44 ----D---- C:\Users\Raphael\AppData\Roaming\HP
2009-03-15 23:37:44 ----D---- C:\ProgramData\HP
2009-03-15 23:09:32 ----D---- C:\Users\Raphael\AppData\Roaming\Adobe
2009-03-15 23:09:02 ----D---- C:\Users\Raphael\AppData\Roaming\Identities
2009-03-15 23:05:47 ----D---- C:\Users\Raphael\AppData\Roaming\Hewlett-Packard
2009-03-15 23:03:35 ----SD---- C:\Users\Raphael\AppData\Roaming\Microsoft
2009-03-15 23:03:35 ----D---- C:\Users\Raphael\AppData\Roaming\Media Center Programs
2009-03-15 23:00:17 ----SHD---- C:\ProgramData\Templates
2009-03-15 23:00:17 ----SHD---- C:\ProgramData\Start Menu
2009-03-15 23:00:17 ----SHD---- C:\ProgramData\Favorites
2009-03-15 23:00:17 ----SHD---- C:\ProgramData\Documents
2009-03-15 23:00:17 ----SHD---- C:\ProgramData\Desktop
2009-03-15 23:00:17 ----SHD---- C:\ProgramData\Application Data
2009-03-15 23:00:17 ----SHD---- C:\Documents and Settings
2009-03-05 23:59:00 ----A---- C:\Windows\system32\usbaaplrc.dll

======List of files/folders modified in the last 2 months======

2009-04-20 22:40:10 ----RD---- C:\Program Files
2009-04-20 22:40:00 ----D---- C:\Windows\Temp
2009-04-20 22:39:55 ----D---- C:\Windows\System32
2009-04-20 22:39:55 ----D---- C:\Windows\inf
2009-04-20 22:39:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-04-20 20:44:29 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2009-04-20 20:41:14 ----SD---- C:\ProgramData\Microsoft
2009-04-18 23:55:12 ----D---- C:\ProgramData\WildTangent
2009-04-18 23:47:33 ----SHD---- C:\Windows\Installer
2009-04-18 21:39:09 ----D---- C:\ProgramData\Roxio
2009-04-18 19:40:28 ----D---- C:\Windows\system32\catroot
2009-04-18 19:40:27 ----D---- C:\Windows\system32\drivers
2009-04-18 19:39:53 ----HD---- C:\ProgramData
2009-04-18 03:06:10 ----D---- C:\Windows\system32\manifeststore
2009-04-18 03:06:10 ----D---- C:\Windows\AppPatch
2009-04-18 03:01:04 ----D---- C:\Windows\winsxs
2009-04-18 03:00:41 ----D---- C:\Windows\system32\WDI
2009-04-17 09:15:33 ----D---- C:\Windows\system32\catroot2
2009-04-17 03:17:01 ----D---- C:\Windows\system32\wbem
2009-04-17 03:17:01 ----D---- C:\Program Files\Windows Mail
2009-04-17 03:17:00 ----D---- C:\Windows\system32\migration
2009-04-17 03:17:00 ----D---- C:\Program Files\Internet Explorer
2009-04-06 14:57:24 ----A---- C:\Windows\system32\mrt.exe
2009-04-03 19:03:50 ----D---- C:\WINDOWS
2009-04-02 00:46:23 ----D---- C:\ProgramData\Hewlett-Packard
2009-03-30 02:48:24 ----D---- C:\ProgramData\Symantec
2009-03-29 23:53:47 ----D---- C:\Windows\system32\restore
2009-03-29 23:38:20 ----D---- C:\Windows\Microsoft.NET
2009-03-29 23:37:23 ----RSD---- C:\Windows\assembly
2009-03-29 23:30:40 ----SHD---- C:\boot
2009-03-29 23:28:58 ----ASH---- C:\Program Files\desktop.ini
2009-03-29 23:20:27 ----D---- C:\Program Files\Windows Sidebar
2009-03-29 23:20:27 ----D---- C:\Program Files\Windows Calendar
2009-03-29 23:20:27 ----D---- C:\Program Files\Movie Maker
2009-03-29 23:20:26 ----D---- C:\Program Files\Windows Photo Gallery
2009-03-29 23:20:26 ----D---- C:\Program Files\Windows Media Player
2009-03-29 23:20:26 ----D---- C:\Program Files\Windows Journal
2009-03-29 23:20:26 ----D---- C:\Program Files\Windows Collaboration
2009-03-29 23:20:25 ----D---- C:\Windows\servicing
2009-03-29 23:20:25 ----D---- C:\Windows\ehome
2009-03-29 23:20:25 ----D---- C:\Program Files\Windows Defender
2009-03-29 23:20:25 ----D---- C:\Program Files\Common Files\System
2009-03-29 23:20:24 ----D---- C:\Windows\MSAgent
2009-03-29 23:20:23 ----D---- C:\Windows\system32\ko-KR
2009-03-29 23:20:23 ----D---- C:\Windows\system32\da-DK
2009-03-29 23:20:23 ----D---- C:\Windows\system32\com
2009-03-29 23:20:23 ----D---- C:\Windows\PolicyDefinitions
2009-03-29 23:20:23 ----D---- C:\Windows\L2Schemas
2009-03-29 23:20:23 ----D---- C:\Windows\IME
2009-03-29 23:20:23 ----D---- C:\Windows\DigitalLocker
2009-03-29 23:20:22 ----D---- C:\Windows\system32\en-US
2009-03-29 23:20:19 ----D---- C:\Windows\system32\sysprep
2009-03-29 23:20:19 ----D---- C:\Windows\system32\oobe
2009-03-29 23:20:19 ----D---- C:\Windows\system32\it-IT
2009-03-29 23:20:19 ----D---- C:\Windows\system32\el-GR
2009-03-29 23:20:19 ----D---- C:\Windows\system32\de-DE
2009-03-29 23:20:16 ----D---- C:\Windows\system32\sv-SE
2009-03-29 23:20:16 ----D---- C:\Windows\system32\SLUI
2009-03-29 23:20:16 ----D---- C:\Windows\system32\setup
2009-03-29 23:20:16 ----D---- C:\Windows\system32\ru-RU
2009-03-29 23:20:16 ----D---- C:\Windows\system32\pt-PT
2009-03-29 23:20:16 ----D---- C:\Windows\system32\ias
2009-03-29 23:20:16 ----D---- C:\Windows\system32\hu-HU
2009-03-29 23:20:16 ----D---- C:\Windows\system32\he-IL
2009-03-29 23:20:16 ----D---- C:\Windows\system32\fr-FR
2009-03-29 23:20:16 ----D---- C:\Windows\system32\fi-FI
2009-03-29 23:20:16 ----D---- C:\Windows\system32\cs-CZ
2009-03-29 23:20:16 ----D---- C:\Windows\system32\AdvancedInstallers
2009-03-29 23:20:14 ----D---- C:\Windows\system32\zh-TW
2009-03-29 23:20:14 ----D---- C:\Windows\system32\zh-CN
2009-03-29 23:20:14 ----D---- C:\Windows\system32\ro-RO
2009-03-29 23:20:14 ----D---- C:\Windows\system32\pl-PL
2009-03-29 23:20:14 ----D---- C:\Windows\system32\ja-JP
2009-03-29 23:20:14 ----D---- C:\Windows\system32\es-ES
2009-03-29 23:20:14 ----D---- C:\Windows\system32\en
2009-03-29 23:20:12 ----D---- C:\Windows\system32\tr-TR
2009-03-29 23:20:11 ----D---- C:\Windows\system32\nl-NL
2009-03-29 23:20:11 ----D---- C:\Windows\system32\nb-NO
2009-03-29 23:20:11 ----D---- C:\Windows\system32\ar-SA
2009-03-29 23:20:09 ----D---- C:\Windows\system32\pt-BR
2009-03-29 23:20:09 ----D---- C:\Windows\system32\migwiz
2009-03-29 23:19:49 ----RSD---- C:\Windows\Fonts
2009-03-29 23:19:38 ----D---- C:\Windows\system32\Boot
2009-03-29 22:55:04 ----A---- C:\Windows\system32\ifxcardm.dll
2009-03-29 22:54:59 ----A---- C:\Windows\system32\axaltocm.dll
2009-03-29 22:41:53 ----D---- C:\Windows\Logs
2009-03-29 21:06:16 ----D---- C:\Windows\rescache
2009-03-29 20:43:35 ----D---- C:\Windows\Boot
2009-03-21 21:18:27 ----D---- C:\Windows\system32\XPSViewer
2009-03-21 19:18:32 ----D---- C:\Windows\Debug
2009-03-19 02:29:41 ----D---- C:\Program Files\Common Files
2009-03-19 02:01:17 ----D---- C:\Windows\Tasks
2009-03-19 02:01:17 ----D---- C:\Windows\system32\Tasks
2009-03-19 01:59:58 ----D---- C:\Program Files\Yahoo!
2009-03-19 01:35:49 ----D---- C:\Windows\system32\ras
2009-03-19 01:35:49 ----D---- C:\Windows\system32\icsxml
2009-03-19 00:05:49 ----D---- C:\ProgramData\Sonic
2009-03-18 23:22:02 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-17 22:24:09 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-03-16 23:32:38 ----A---- C:\Windows\win.ini
2009-03-16 23:30:08 ----D---- C:\Program Files\Common Files\microsoft shared
2009-03-16 23:29:47 ----D---- C:\Windows\ShellNew
2009-03-16 23:28:10 ----D---- C:\Program Files\Microsoft Office
2009-03-16 23:25:48 ----D---- C:\Windows\Help
2009-03-16 23:21:51 ----D---- C:\Windows\system
2009-03-16 22:11:27 ----SD---- C:\Windows\Downloaded Program Files
2009-03-16 06:55:00 ----D---- C:\Windows\panther
2009-03-16 06:52:07 ----D---- C:\ProgramData\CyberLink
2009-03-16 06:46:11 ----D---- C:\Windows\SMINST
2009-03-15 23:13:58 ----D---- C:\ProgramData\Microsoft Help
2009-03-15 23:13:48 ----D---- C:\Program Files\Microsoft Works
2009-03-15 23:09:14 ----SHD---- C:\$RECYCLE.BIN
2009-03-15 23:08:52 ----HD---- C:\System.sav
2009-03-15 23:08:52 ----D---- C:\SwSetup
2009-03-15 23:03:35 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 BHDrvx86;Symantec Heuristics Driver; C:\Windows\System32\Drivers\NAV\1005000.086\BHDrvx86.sys [2009-02-27 258608]
R1 ccHP;Symantec Hash Provider; C:\Windows\System32\Drivers\NAV\1005000.086\ccHPx86.sys [2009-03-25 482352]
R1 eabfiltr;eabfiltr; C:\Windows\system32\DRIVERS\eabfiltr.sys [2006-06-28 8192]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2009-03-10 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090414.001\IDSvix86.sys [2009-02-06 292912]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); \??\C:\Windows\system32\drivers\NAV\1005000.086\SRTSPX.SYS [2009-02-27 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2009-02-27 25136]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\Windows\System32\Drivers\NAV\1005000.086\SYMTDI.SYS [2009-02-27 217392]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2006-11-16 32256]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2006-11-16 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-16 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 8192]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-03-19 14208]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2006-11-02 200704]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-10 101936]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2006-11-19 145920]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-10-18 986624]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2006-10-18 206848]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090420.002\NAVENG.SYS [2009-04-18 89104]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090420.002\NAVEX15.SYS [2009-04-18 876144]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-09 1786880]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2006-12-07 4456416]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-03-19 82432]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NAV\1005000.086\SRTSP.SYS [2009-02-27 307760]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2009-03-25 124464]
R3 SYMFW;Symantec Network Filter Driver; C:\Windows\System32\Drivers\NAV\1005000.086\SYMFW.SYS [2009-02-27 89776]
R3 SYMNDISV;Symantec Network Filter Driver; C:\Windows\System32\Drivers\NAV\1005000.086\SYMNDISV.SYS [2009-02-27 39984]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2006-11-15 179256]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 132352]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-10-18 659968]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-03-19 11264]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2006-11-02 19456]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2006-11-02 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2006-11-02 220160]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2006-11-02 29184]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 E100B;Intel(R) PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-11-02 163328]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2006-11-02 49664]
S3 SYMDNS;SYMDNS; \??\C:\Windows\system32\drivers\NAV\1000000.07D\SYMDNS.SYS []
S3 SYMREDRV;SYMREDRV; \??\C:\Windows\system32\drivers\NAV\1000000.07D\SYMREDRV.SYS []
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-03-05 36864]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-06 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Norton AntiVirus;Norton AntiVirus; C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [2009-02-27 115560]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-08-04 386560]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
S2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [2006-11-24 118877]
S2 CLTNetCnService;Symantec Lic NetConnect service; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S3 AddFiltr;AddFiltr; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe [2006-06-26 126976]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2006-11-06 887544]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-11-01 73728]
S4 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [2006-11-24 270431]
S4 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2006-11-28 63080]
S4 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]

-----------------EOF-----------------
0
07061977
 
et voila mon info log

info.txt logfile of random's system information tool 1.06 2009-04-20 22:40:15

======Uninstall list======

-->"C:\Program Files\HP Games\Ancient Sudoku\Uninstall.exe"
-->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Big Kahuna Reef\Uninstall.exe"
-->"C:\Program Files\HP Games\Blackhawk Striker 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
-->"C:\Program Files\HP Games\Boggle Supreme\Uninstall.exe"
-->"C:\Program Files\HP Games\Bookworm Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
-->"C:\Program Files\HP Games\Family Feud\Uninstall.exe"
-->"C:\Program Files\HP Games\FATE\Uninstall.exe"
-->"C:\Program Files\HP Games\Final Drive Nitro\Uninstall.exe"
-->"C:\Program Files\HP Games\Flip Words\Uninstall.exe"
-->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Lemonade Tycoon 2\Uninstall.exe"
-->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
-->"C:\Program Files\HP Games\Otto\Uninstall.exe"
-->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
-->"C:\Program Files\HP Games\Poker Superstars 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Tubing\Uninstall.exe"
-->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
-->"C:\Program Files\HP Games\SCRABBLE\Uninstall.exe"
-->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
-->"C:\Program Files\HP Games\The Apprentice\Uninstall.exe"
-->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
-->"C:\Program Files\HP Games\Word Symphony\Uninstall.exe"
-->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
Apple Mobile Device Support-->MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ASL_HS_Installer32-->MsiExec.exe /I{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HUFSetup.EXE -U -IwisR30B7.inf
DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Hewlett-Packard Asset Agent-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{21E62565-8639-457C-B64C-A3FF0A8B4D80}\setup.exe -runfromtemp -l0x0409
HP Connections (remove only)-->C:\Windows\HPCPCUninstall-6811507\HPBWSetup.exe -appid 6811507 -uninstall
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
HP Easy Setup - Core-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}\setup.exe" -l0x9
HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
HP Help and Support-->MsiExec.exe /I{E4DDBA93-769B-49D8-BA33-8814E45ED0C1}
HP Pavilion Webcam Driver for Vista v061.001.00005-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CA81D12-9EC2-4082-972B-43ECA63F41F2}\setup.exe" -l0x9 -removeonly
HP Quick Launch Buttons 6.10 B9-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x9 uninst
HP QuickPlay 3.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
HP Total Care Advisor-->MsiExec.exe /X{A12A3DED-CCDA-4F29-A1BA-00F0C6521CD5}
HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HP User Guide 0049-->MsiExec.exe /I{3E3A110A-7FAE-4DC0-8E39-BAFFE89724B6}
HP Wireless Assistant-->MsiExec.exe /I{02F33FB0-F7D5-4C0A-B4AD-8CE5CE230BBE}
HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
LimeWire 5.1.2-->"C:\Program Files\LimeWire\uninstall.exe"
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
MobileMe Control Panel-->MsiExec.exe /I{44A91B04-3D0C-47F9-B644-7F682869AFF3}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
muvee autoProducer 5.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{99C5770C-1C90-42E7-9B74-D47CFAF14621}\setup.exe" -l0x9
My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
Norton AntiVirus-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\InstStub.exe /X
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
Roxio Creator Audio-->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator Basic v9-->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Copy-->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data-->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator EasyArchive-->MsiExec.exe /I{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
Roxio Creator Tools-->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio Express Labeler 3-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio MyDVD Basic v9-->MsiExec.exe /I{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}
Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5045&SUBSYS_103C30B7\HXFSETUP.EXE -U -Iwis30B7z.inf
Sonic Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall

======Security center information======

AV: Norton AntiVirus
AS: Windows Defender
AS: Norton AntiVirus

======System event log======

Computer Name: Raphael-PC
Event Code: 7000
Message: The Parallel port driver service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38663
Source Name: Service Control Manager
Time Written: 20090420203611.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 7001
Message: The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38666
Source Name: Service Control Manager
Time Written: 20090420203611.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 4001
Message: WLAN AutoConfig service has successfully stopped.

Record Number: 38752
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20090420223055.507800-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Raphael-PC
Event Code: 7000
Message: The Parallel port driver service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38799
Source Name: Service Control Manager
Time Written: 20090420223326.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 7001
Message: The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38803
Source Name: Service Control Manager
Time Written: 20090420223326.000000-000
Event Type: Error
User:

=====Application event log=====

Computer Name: Raphael-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-1098392157-4093108927-2693896540-1000_Classes:
Process 1688 (\Device\HarddiskVolume1\WINDOWS\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-1098392157-4093108927-2693896540-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

Record Number: 1929
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090419021916.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Raphael-PC
Event Code: 1002
Message: The program iexplore.exe version 7.0.6000.16830 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel. Process ID: 924 Start Time: 01c9c0f56ba90a5a Termination Time: 53
Record Number: 1956
Source Name: Application Hang
Time Written: 20090419143143.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 4104
Message: File backup failed. The error is: There is not enough space to save the backup files. Free up disk space or change your backup settings. (0x81000005).
Record Number: 1987
Source Name: Windows Backup
Time Written: 20090419190342.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 3100
Message: Unable to initialize the filter host process. Terminating.

Details:
This operation returned because the timeout period expired. (0x800705b4)

Record Number: 2073
Source Name: Microsoft-Windows-Search
Time Written: 20090420192526.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 4356
Message: The COM+ Event System failed to create an instance of the subscriber {28778B62-8481-400D-8E8A-A4C81ED3F65C}. StandardCreateInstance returned HRESULT 80080005.
Record Number: 2093
Source Name: Microsoft-Windows-EventSystem
Time Written: 20090420201723.000000-000
Event Type: Warning
User:

=====Security event log=====

Computer Name: Raphael-PC
Event Code: 5032
Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.

Error Code: 2
Record Number: 7565
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420223748.081810-000
Event Type: Audit Failure
User:

Computer Name: Raphael-PC
Event Code: 5032
Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.

Error Code: 2
Record Number: 7566
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420223748.097410-000
Event Type: Audit Failure
User:

Computer Name: Raphael-PC
Event Code: 4648
Message: A logon was attempted using explicit credentials.

Subject:
Security ID: S-1-5-18
Account Name: RAPHAEL-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server:
Target Server Name: localhost
Additional Information: localhost

Process Information:
Process ID: 0x27c
Process Name: C:\WINDOWS\System32\services.exe

Network Information:
Network Address: -
Port: -

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 7567
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420224101.399210-000
Event Type: Audit Success
User:

Computer Name: Raphael-PC
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: RAPHAEL-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x27c
Process Name: C:\WINDOWS\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 7568
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420224101.399210-000
Event Type: Audit Success
User:

Computer Name: Raphael-PC
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7

Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 7569
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420224101.399210-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"PLATFORM"=MCD
"PCBRAND"=Pavilion
"OnlineServices"=Online Services
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip

-----------------EOF-----------------
0
07061977
 
et voila mon info log

info.txt logfile of random's system information tool 1.06 2009-04-20 22:40:15

======Uninstall list======

-->"C:\Program Files\HP Games\Ancient Sudoku\Uninstall.exe"
-->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Big Kahuna Reef\Uninstall.exe"
-->"C:\Program Files\HP Games\Blackhawk Striker 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
-->"C:\Program Files\HP Games\Boggle Supreme\Uninstall.exe"
-->"C:\Program Files\HP Games\Bookworm Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
-->"C:\Program Files\HP Games\Family Feud\Uninstall.exe"
-->"C:\Program Files\HP Games\FATE\Uninstall.exe"
-->"C:\Program Files\HP Games\Final Drive Nitro\Uninstall.exe"
-->"C:\Program Files\HP Games\Flip Words\Uninstall.exe"
-->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Lemonade Tycoon 2\Uninstall.exe"
-->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
-->"C:\Program Files\HP Games\Otto\Uninstall.exe"
-->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
-->"C:\Program Files\HP Games\Poker Superstars 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Tubing\Uninstall.exe"
-->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
-->"C:\Program Files\HP Games\SCRABBLE\Uninstall.exe"
-->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
-->"C:\Program Files\HP Games\The Apprentice\Uninstall.exe"
-->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
-->"C:\Program Files\HP Games\Word Symphony\Uninstall.exe"
-->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
Apple Mobile Device Support-->MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ASL_HS_Installer32-->MsiExec.exe /I{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HUFSetup.EXE -U -IwisR30B7.inf
DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Hewlett-Packard Asset Agent-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{21E62565-8639-457C-B64C-A3FF0A8B4D80}\setup.exe -runfromtemp -l0x0409
HP Connections (remove only)-->C:\Windows\HPCPCUninstall-6811507\HPBWSetup.exe -appid 6811507 -uninstall
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
HP Easy Setup - Core-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}\setup.exe" -l0x9
HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
HP Help and Support-->MsiExec.exe /I{E4DDBA93-769B-49D8-BA33-8814E45ED0C1}
HP Pavilion Webcam Driver for Vista v061.001.00005-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CA81D12-9EC2-4082-972B-43ECA63F41F2}\setup.exe" -l0x9 -removeonly
HP Quick Launch Buttons 6.10 B9-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x9 uninst
HP QuickPlay 3.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
HP Total Care Advisor-->MsiExec.exe /X{A12A3DED-CCDA-4F29-A1BA-00F0C6521CD5}
HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HP User Guide 0049-->MsiExec.exe /I{3E3A110A-7FAE-4DC0-8E39-BAFFE89724B6}
HP Wireless Assistant-->MsiExec.exe /I{02F33FB0-F7D5-4C0A-B4AD-8CE5CE230BBE}
HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
LimeWire 5.1.2-->"C:\Program Files\LimeWire\uninstall.exe"
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
MobileMe Control Panel-->MsiExec.exe /I{44A91B04-3D0C-47F9-B644-7F682869AFF3}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
muvee autoProducer 5.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{99C5770C-1C90-42E7-9B74-D47CFAF14621}\setup.exe" -l0x9
My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
Norton AntiVirus-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.5.0.134\InstStub.exe /X
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
Roxio Creator Audio-->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator Basic v9-->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Copy-->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data-->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator EasyArchive-->MsiExec.exe /I{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
Roxio Creator Tools-->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio Express Labeler 3-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio MyDVD Basic v9-->MsiExec.exe /I{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}
Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5045&SUBSYS_103C30B7\HXFSETUP.EXE -U -Iwis30B7z.inf
Sonic Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall

======Security center information======

AV: Norton AntiVirus
AS: Windows Defender
AS: Norton AntiVirus

======System event log======

Computer Name: Raphael-PC
Event Code: 7000
Message: The Parallel port driver service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38663
Source Name: Service Control Manager
Time Written: 20090420203611.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 7001
Message: The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38666
Source Name: Service Control Manager
Time Written: 20090420203611.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 4001
Message: WLAN AutoConfig service has successfully stopped.

Record Number: 38752
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20090420223055.507800-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Raphael-PC
Event Code: 7000
Message: The Parallel port driver service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38799
Source Name: Service Control Manager
Time Written: 20090420223326.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 7001
Message: The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 38803
Source Name: Service Control Manager
Time Written: 20090420223326.000000-000
Event Type: Error
User:

=====Application event log=====

Computer Name: Raphael-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-1098392157-4093108927-2693896540-1000_Classes:
Process 1688 (\Device\HarddiskVolume1\WINDOWS\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-1098392157-4093108927-2693896540-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

Record Number: 1929
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090419021916.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Raphael-PC
Event Code: 1002
Message: The program iexplore.exe version 7.0.6000.16830 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel. Process ID: 924 Start Time: 01c9c0f56ba90a5a Termination Time: 53
Record Number: 1956
Source Name: Application Hang
Time Written: 20090419143143.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 4104
Message: File backup failed. The error is: There is not enough space to save the backup files. Free up disk space or change your backup settings. (0x81000005).
Record Number: 1987
Source Name: Windows Backup
Time Written: 20090419190342.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 3100
Message: Unable to initialize the filter host process. Terminating.

Details:
This operation returned because the timeout period expired. (0x800705b4)

Record Number: 2073
Source Name: Microsoft-Windows-Search
Time Written: 20090420192526.000000-000
Event Type: Error
User:

Computer Name: Raphael-PC
Event Code: 4356
Message: The COM+ Event System failed to create an instance of the subscriber {28778B62-8481-400D-8E8A-A4C81ED3F65C}. StandardCreateInstance returned HRESULT 80080005.
Record Number: 2093
Source Name: Microsoft-Windows-EventSystem
Time Written: 20090420201723.000000-000
Event Type: Warning
User:

=====Security event log=====

Computer Name: Raphael-PC
Event Code: 5032
Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.

Error Code: 2
Record Number: 7565
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420223748.081810-000
Event Type: Audit Failure
User:

Computer Name: Raphael-PC
Event Code: 5032
Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.

Error Code: 2
Record Number: 7566
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420223748.097410-000
Event Type: Audit Failure
User:

Computer Name: Raphael-PC
Event Code: 4648
Message: A logon was attempted using explicit credentials.

Subject:
Security ID: S-1-5-18
Account Name: RAPHAEL-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server:
Target Server Name: localhost
Additional Information: localhost

Process Information:
Process ID: 0x27c
Process Name: C:\WINDOWS\System32\services.exe

Network Information:
Network Address: -
Port: -

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 7567
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420224101.399210-000
Event Type: Audit Success
User:

Computer Name: Raphael-PC
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: RAPHAEL-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x27c
Process Name: C:\WINDOWS\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 7568
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420224101.399210-000
Event Type: Audit Success
User:

Computer Name: Raphael-PC
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7

Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 7569
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090420224101.399210-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"PLATFORM"=MCD
"PCBRAND"=Pavilion
"OnlineServices"=Online Services
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip

-----------------EOF-----------------
0
Utilisateur anonyme
 
Bonsoir a vous deux,

Euhhhh, tu vas tous les faires ??????

Plusieurs infections et pas un outils de donner valable si je puis dire.........

bonne continuation...
1
Utilisateur anonyme
 
---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :



:processes
explorer.exe

:files
C:\32788R22FWJFW
C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
C:\WINDOWS\system32\cmd.execf

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-
"iTunesHelper"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=-
"NoResolveTrack"=-
"NoSMConfigurePrograms"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideRunAsVerb"=-
"NoActiveDesktop"=-
"NoInstrumentation"=-
"NoResolveTrack"=-
"NoSetActiveDesktop"=-
"NoStartMenuMFUprogramsList"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Disabled:Bonjour"
"C:\Program Files\Bonjour\mDNSResponder.exe"=-

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]



---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
1

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
harno Messages postés 512 Statut Membre 32
 
Bonjour,

Dans Mozilla/Firefox/Outils, tu cliques sur "Modules complémentaires", puis "Obtenir des extensions. Tu recherches "Adblock plus", puis tu cliques sur "Ajouter à Firefox". Après tu choisis les listes de blocage que tu veux, les mises à jour seront automatiques. Je n'ai pas en tête celles que j'ai choisies mais je repasserai dans quelques minutes.

Après cela, les pubs, toutes les pubs, ne seront plus qu'un mauvais souvenir
0
harno Messages postés 512 Statut Membre 32
 
Tu peux prendre les filtres suivants:

1.- Rick752's EasyElement USA (general element hiding)
2.- Rick752's EasyPrivacy (blocks tracking)
3.- Liste FR
4.- Cédrics Liste

Personnellement, comme je vais souvent sur les sites allemands, j'ai ajouté:
5.- Ares' ABP Liste (DE)
6.- Filter von Dr.Evil (Deutschland)
0
mlle-agnes > harno Messages postés 512 Statut Membre
 
Justement j'ai déjà essayé et ca ne marche pas :( ! Je crois bien que je suis bien infectée !
0
harno Messages postés 512 Statut Membre 32 > mlle-agnes
 
Tu veux dire que les filtres que je t'ai donnés ne marchent pas ? Impossible ! Tu as du faire une erreur. Je n'ai pas le droit de donner de sites ici, mais certains contiennent 20/30 pubs sur la même page. Avec Adblock plus, je n'en ai pas un seul. Que ton PC soit toujours lent, je veux bien le croire, mais les pubs, tu ne dois plus en avoir.

En cliquant sur "Modules complémentaires" tu dois pouvoir lire "ABP Adblock Plus 1.0.1, et tout à droite de la ligne d'adresse de Firefox, également un icône ABP en rouge. Sinon, Adblock Plus n'est pas installé.

D'autre part, Ad-Aware et Spybot ne sont pas si daubes que cela. Si tu as des spywares, ils te le diront.
0
loloetseb Messages postés 5684 Statut Membre 174
 
Avast et ad aware sont deux daube,postes moi le rsit on va faire la procedure adequate
0
mlle-agnes
 
Tout d'abord je vous remercie de votre rapidité ! Voici le 1er rapport :

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrateur at 2009-03-22 00:55:35
Microsoft Windows XP Professionnel Service Pack 3, v.5657
System drive C: has 129 GB (84%) free of 153 GB
Total RAM: 2038 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:55:37, on 22/03/2009
Platform: Windows XP SP3, v.5657 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Taskix\Taskix32.exe
C:\Program Files\VirtuaWin\VirtuaWin.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\program files\orange\media player\Media Player.exe
C:\documents and settings\administrateur\local settings\application data\mecwqce.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Administrateur\Bureau\Firefox\RSIT.exe
C:\Documents and Settings\Administrateur\Bureau\Firefox\Administrateur.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/toolbar/ie8/sidebar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/toolbar/ie8/sidebar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: mysidesearch search enhancer - {FF35AC04-87CD-63AB-90A6-CF51C69EDE69} - C:\WINDOWS\system32\jaynkjnrprduk.dll
O4 - HKLM\..\Run: [Taskix] C:\Program Files\Taskix\Taskix32.exe start
O4 - HKLM\..\Run: [VirtuaWin] C:\Program Files\VirtuaWin\VirtuaWin.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray
O4 - HKCU\..\Run: [mecwqce] "c:\documents and settings\administrateur\local settings\application data\mecwqce.exe" mecwqce
O4 - HKUS\S-1-5-19\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OrangePlayer] c:\program files\orange\media player\Media Player.exe /systray (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\console32.dll
O20 - Winlogon Notify: a8f95583560 - C:\WINDOWS\System32\console32.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
0
mlle-agnes
 
et le deuxième !

nfo.txt logfile of random's system information tool 1.06 2009-03-22 00:55:23

======Uninstall list======

-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E47302B-8081-46D3-9FEA-BEB2E5F5C3EC}\setup.exe" -l0x40c anything
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00BA-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
7-Zip 4.60 beta-->"C:\Program Files\7-Zip\Uninstall.exe"
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
Canon MP140 series-->"C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series /L0x000c
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HXFSETUP.EXE -U -IDW1Ven5a.inf
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
FastStone-->"C:\Program Files\FastStone Capture\Désinstaller.exe"
Favorit-->"c:\documents and settings\administrateur\local settings\application data\mecwqce.exe" -uninstall
FrostWire 4.17.2-->C:\Program Files\FrostWire\Uninstall.exe
Gestionnaire Internet-->C:\PROGRA~1\Wanadoo\uninstall.exe
HijackThis 2.0.2-->"C:\Documents and Settings\Administrateur\Bureau\Firefox\HijackThis.exe" /uninstall
Intel PROSet Wireless-->Intel PROSet Wireless
Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe" -l0x40c
Media Player-->"C:\Program Files\Orange\Media Player\uninstall.exe"
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Groove MUI (French) 2007-->MsiExec.exe /X{90120000-00BA-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
Mozilla Firefox (3.0.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Navigateur Orange-->C:\PROGRA~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl
Navilog1 3.7.6-->"C:\Program Files\Navilog1\unins000.exe"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Norton AntiVirus-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\2454B0AB\16.2.0.7\InstStub.exe /X
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Search Assistant Mysidesearch-->C:\WINDOWS\system32\jaynkjnrprduk.dll-uninst.exe
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Snappyads Games Collection-->C:\Program Files\Snappyads Games Collection\uninstall.exe
Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_5045&SUBSYS_152D0755\HXFSETUP.EXE -U -IDW1Venpm.inf
Sumatra PDF Reader-->"C:\Program Files\SumatraPDF\Désinstaller.exe"
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Taskix-->"C:\Program Files\Taskix\Désinstaller.exe"
Unity Web Player-->C:\Program Files\Unity\WebPlayer\Uninstall.exe
Unlocker 1.8.7-->C:\Program Files\Unlocker\uninst.exe
Update for Outlook 2007 Junk Email Filter (kb943597)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A751F0DB-8476-4207-956E-20AEBBA4B1DA}
uTorrent-->"C:\Program Files\uTorrent\Désinstaller.exe"
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
VirtuaWin-->"C:\Program Files\VirtuaWin\Désinstaller.exe"
VLC media player 0.9.6-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Trust Anti-Pub-->"C:\WINDOWS\System32\Drivers\Etc\UnHosts.exe"
Windows Trust Core Codecs-->"C:\WINDOWS\System32\UnWTCC.exe"
Windows Trust Installer-->"C:\Program Files\WTInstaller\Désinstaller.exe"
WinRAR-->"C:\Program Files\WinRAR\uninstall.exe"
XtremSplit-->"C:\Program Files\XtremSplit\Désinstaller.exe"

======Hosts File======

127.0.0.1 localhost
127.0.0.1 mpa.one.microsoft.com
127.0.0.1 rad.msn.com
127.0.0.1 rad.live.com
127.0.0.1 ads1.msn.com
127.0.0.1 adfarm.mediaplex.com
127.0.0.1 101com.com
127.0.0.1 101order.com
127.0.0.1 103bees.com
127.0.0.1 1100i.com

Securitycenter WMI appears to be broken

======System event log======

Computer Name: 16966EE0DE5E49B
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Service Messenger Sharing Folders USN Journal Reader.

Record Number: 1489
Source Name: Service Control Manager
Time Written: 20090201225553.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: 16966EE0DE5E49B
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{AA60CD17-2664-4468-B5A3-D8FBFD205C40} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.

Record Number: 1488
Source Name: Tcpip
Time Written: 20090201225536.000000+060
Event Type: Informations
User:

Computer Name: 16966EE0DE5E49B
Event Code: 4202
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{AA60CD17-2664-4468-B5A3-D8FBFD205C40} était déconnectée du réseau,
et la configuration réseau de la carte a été abandonnée. Si la carte
réseau n'était pas déconnectée, ceci peut indiquer un disfonctionnement.
Contactez le fabricant pour des pilotes mis à jour.

Record Number: 1487
Source Name: Tcpip
Time Written: 20090201225531.000000+060
Event Type: Informations
User:

Computer Name: 16966EE0DE5E49B
Event Code: 2505
Message: Le serveur n'a pas pu se lier au transport \Device\NetBT_Tcpip_{AA60CD17-2664-4468-B5A3-D8FBFD205C40} car un autre ordinateur du réseau porte le même nom. Le serveur n'a pas pu démarrer.

Record Number: 1486
Source Name: Server
Time Written: 20090201225455.000000+060
Event Type: erreur
User:

Computer Name: 16966EE0DE5E49B
Event Code: 7036
Message: Le service HTTP SSL est entré dans l'état : en cours d'exécution.

Record Number: 1485
Source Name: Service Control Manager
Time Written: 20090201225449.000000+060
Event Type: Informations
User:

=====Application event log=====

Computer Name: 16966EE0DE5E49B
Event Code: 1
Message:
Record Number: 672
Source Name: Bonjour Service
Time Written: 20090207012722.000000+060
Event Type: Informations
User:

Computer Name: 16966EE0DE5E49B
Event Code: 101
Message: MsnMsgr (2748) Le moteur de base de données est arrêté.

Record Number: 671
Source Name: ESENT
Time Written: 20090201225856.000000+060
Event Type: Informations
User:

Computer Name: 16966EE0DE5E49B
Event Code: 103
Message: MsnMsgr (2748) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\sapiklamoutarde2dijon@hotmail.com\SharingMetadata\Working\database_CAA8_F96A_A8F9_5583\dfsr.db: Le moteur de base de données a arrêté une instance (0).

Record Number: 670
Source Name: ESENT
Time Written: 20090201225856.000000+060
Event Type: Informations
User:

Computer Name: 16966EE0DE5E49B
Event Code: 302
Message: MsnMsgr (2748) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\sapiklamoutarde2dijon@hotmail.com\SharingMetadata\Working\database_CAA8_F96A_A8F9_5583\dfsr.db: Le moteur de base de données a exécuté la procédure de récupération avec succès.

Record Number: 669
Source Name: ESENT
Time Written: 20090201225557.000000+060
Event Type: Informations
User:

Computer Name: 16966EE0DE5E49B
Event Code: 301
Message: MsnMsgr (2748) \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\sapiklamoutarde2dijon@hotmail.com\SharingMetadata\Working\database_CAA8_F96A_A8F9_5583\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\sapiklamoutarde2dijon@hotmail.com\SharingMetadata\Working\database_CAA8_F96A_A8F9_5583\fsr.log.

Record Number: 668
Source Name: ESENT
Time Written: 20090201225556.000000+060
Event Type: Informations
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"SysDir"=C:\WINDOWS\system32
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------
0
harno Messages postés 512 Statut Membre 32
 
mlle-agnes, tu sembles confondre spywares sur ton PC et pubs dans le navigateur.

Un anti-spyware va te protéger éventuellement de l'arrivée d'un fichier espion et pourra t'aider à t'en débarrasser, mais il ne te protègera jamais des pubs intempestives. Seul un outil comme Adblock plus (v1.0.1 actuellement) en sera capable.
0
mlle-agnes Messages postés 33 Statut Membre
 
Je pensais que certaines de ces pubs étaient des spywares ! Merci de m'avoir éclairé !
0
loloetseb Messages postés 5684 Statut Membre 174
 
Bon tu es tres infecté,je vais te donner une procedure a suivre
0
loloetseb Messages postés 5684 Statut Membre 174
 
Lances hijack this "do a scan only",puis coches les cases ci dessous et cliques sur fix

O2 - BHO: mysidesearch search enhancer - {FF35AC04-87CD-63AB-90A6-CF51C69EDE69} - C:\WINDOWS\system32\jaynkjnrprduk.dll
O4 - HKCU\..\Run: [mecwqce] "c:\documents and settings\administrateur\local settings\application data\mecwqce.exe" mecwqce

Ensuite

---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :

:processes
explorer.exe

:files
c:\documents and settings\administrateur\local settings\application data\mecwqce.exe
c:\windows\system32\jaynkjnrprduk.dll
c:\windows\system32\diskcopy32.dll
c:\windows\system32\dciman3232.dll
c:\windows\system32\comdlg3232.dll
c:\windows\system32\jaynkjnrprduk.dll-uninst.exe
c:\program files\snappyads games collection\uninstall.exe

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF35AC04-87CD-63AB-90A6-CF51C69EDE69}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF35AC04-87CD-63AB-90A6-CF51C69EDE69}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"mecwqce"=-

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]

---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
mlle-agnes Messages postés 33 Statut Membre
 
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
c:\documents and settings\administrateur\local settings\application data\mecwqce.exe moved successfully.
c:\windows\system32\jaynkjnrprduk.dll unregistered successfully.
c:\windows\system32\jaynkjnrprduk.dll moved successfully.
LoadLibrary failed for c:\windows\system32\diskcopy32.dll
c:\windows\system32\diskcopy32.dll NOT unregistered.
c:\windows\system32\diskcopy32.dll moved successfully.
LoadLibrary failed for c:\windows\system32\dciman3232.dll
c:\windows\system32\dciman3232.dll NOT unregistered.
c:\windows\system32\dciman3232.dll moved successfully.
LoadLibrary failed for c:\windows\system32\comdlg3232.dll
c:\windows\system32\comdlg3232.dll NOT unregistered.
c:\windows\system32\comdlg3232.dll moved successfully.
c:\windows\system32\jaynkjnrprduk.dll-uninst.exe moved successfully.
c:\program files\snappyads games collection\uninstall.exe moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF35AC04-87CD-63AB-90A6-CF51C69EDE69}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF35AC04-87CD-63AB-90A6-CF51C69EDE69}\\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mecwqce deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsperfdata_Administrateur\4328 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_2ruPud8raQJWvKomyYQy scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE6DA.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\JETF03C.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_df8.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_e58.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03222009_012500

Files moved on Reboot...
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsperfdata_Administrateur\4328 not found!
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_2ruPud8raQJWvKomyYQy not found!
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFE6DA.tmp moved successfully.
File C:\WINDOWS\temp\JETF03C.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_df8.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_e58.dat moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\yetsnoya.default\urlclassifier3.sqlite moved successfully.
0
loloetseb Messages postés 5684 Statut Membre 174
 
Télécharge Superantispyware (SAS)

Choisis "enregistrer" et enregistre-le sur ton bureau.

Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

Créé une icône sur le bureau.

Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.

- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

Dans la colonne de gauche, coche C:\Fixed Drive.

Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

Pour recopier les informations sur le forum, fais ceci :

- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

- Copie son contenu dans ta réponse.

Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
0
mlle-agnes Messages postés 33 Statut Membre
 
J'ai télécharge SAS mais lorsque je double clique il ne veut pas se lancer....
0
loloetseb Messages postés 5684 Statut Membre 174
 
Télécharge MalwareByte's :
http://www.malwarebytes.org/mbam.php ou ici :
http://www.malwarebytes.org/mbam/program/mbam-setup.exe

* Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

* Potasse le tuto pour te familiariser avec le prg :
https://forum.pcastuces.com/sujet.asp?f=31&s=3
( cela dis, il est très simple d'utilisation ).

relance malwarebytes en suivant scrupuleusement ces consignes :

! Déconnecte toi et ferme toutes applications en cours !

* Lance Malwarebyte's .

Fais un examen dit "Complet" .

--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
0
mlle-agnes Messages postés 33 Statut Membre
 
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1883
Windows 5.1.2600 Service Pack 3, v.5657

22/03/2009 02:22:49
mbam-log-2009-03-22 (02-22-49).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 123042
Temps écoulé: 32 minute(s), 31 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 4
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 52

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\console32.dll (Trojan.Agent) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\a8f95583560 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: c:\windows\system32\console32.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: system32\console32.dll -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\_OTMoveIt\MovedFiles\03222009_012500\windows\system32\jaynkjnrprduk.dll-uninst.exe (Adware.MySideSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddeml32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dhcpsapi32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DHCPMON32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\d3dx10_3832.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cnvfat32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\camocx32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CATSRVUT32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CERTCLI32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CLBCATEX32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CLICONFG32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CNBJMON32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\COMADDIN32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\COMPATUI32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\COMPSTUI32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comuid32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CONSOLE32.DLL (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\corpol32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CRYPT3232.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\danim32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DBGHELP32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DDRAWEX32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DESKMON32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dimap32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dinput32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dmdlgs32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DMLOADER32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DMSCRIPT32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DivX32.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dbnetlib32.dll (Worm.P2P) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\d3dxof32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dgrpsetu32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cdfview32.dll (Worm.P2P) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dmdskres32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\csseqchk32.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cscdll32.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\67.crack.zip (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\67.crack.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\68.keygen.zip (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\68.keygen.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\69.serial.zip (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\69.serial.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\70.setup.zip (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\70.setup.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\72.music.mp3 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\72.music.mp3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\73.music.snd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\73.music.snd.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\74.music.au (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\74.music.au.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\75.music.wav (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\NetworkService32\75.music.wav.kwd (Worm.Archive) -> Quarantined and deleted successfully.
0
loloetseb Messages postés 5684 Statut Membre 174
 
1/
Telecharge maintenant FindyKill sur ton bureau :

http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

--> Lance l installation avec les parametres par default

--> Au menu principal,choisi l option 1 (Recherche)

--> Post le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

2/
Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

--> Fais clic droit sur le raccourci FindyKill sur ton bureau

--> Au menu principal,choisi l option 2 (Suppression)

/!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

/!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

-------> ensuite post le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
0
mlle-agnes Messages postés 33 Statut Membre
 
FindyKill ne peut s'ouvrir non plus, je desespère !
0
Utilisateur anonyme
 
Re,

^^
0
loloetseb Messages postés 5684 Statut Membre 174
 
Vx peux tu me dire ce quel fix est inutile sur ce topic?
0
Utilisateur anonyme
 
bonsoir V-X bien ?

Plusieurs infections et pas un outils de donner valable si je puis dire.= et OtMoveit ?(seul fix effectue d ailleurs)

Cordialement
0
loloetseb Messages postés 5684 Statut Membre 174
 
Tu peux faire la procedure findy kill.Comme tu peux voir sur le rapport malwarebytes ,tu as des cracks infectés donc je te conseille vivement de supprimer tes cracks sinon l'infection risque de se reinstaller
0
loloetseb Messages postés 5684 Statut Membre 174
 
Donc fais la procedure 1 et 2 findy kill du post 17

Ensuite:

1/
Télécharge Navilog1 depuis-ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.

Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

Au menu principal, Fais le choix 1 >> Recherche
Laisse toi guider et patiente.
Patiente jusqu'au message :
*** Analyse Termine le ..... *** >>>>> Le fix peut durer une dizaine de minutes ;)
Appuie sur une touche le bloc note va s'ouvrir.
Copie-colle le rapport ici.

2/Ton ordinateur est infecté par MagicControl/navipromo, qui s'installe via des programmes dits "gratuits", dont ceux-ci :

* go-astro
* GoRecord
* HotTVPlayer / HotTVPlayer & Paris Hilton
* Live-Player
* MailSkinner
* Messenger Skinner
* Instant Access
* InternetGameBox
* Officiale Emule (Version d'Emule modifiée)
* Sudoplanet
* Webmediaplayer

# Si tu as Spybot, désactive le TeaTimer de Spybot (tu le réactiveras après ta désinfection) :
Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer

# Relance Navilog en faisant un clic-droit sur le raccourci Navilog présent sur ton bureau et en choisissant "Exécuter en tant qu'administrateur"

Au menu principal, choisis 2 et valide.
Le fix va t'informer qu'il va alors redémarrer ton PC
Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuie sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.

Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***

Le bloc note va s'ouvrir, copie/colle ici le rapport, comme tu l’as fait pour l’autre.

Postes moi les rapports,je vais me coucher,je regarderais ca demain.Bonne fin de soirée
0
mlle-agnes Messages postés 33 Statut Membre
 
Search Navipromo version 3.7.6 commencé le 22/03/2009 à 3:02:20,23

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3, v.5657
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz )
BIOS : Ver 1.00PARTTBL
USER : Administrateur ( Administrator )
BOOT : Normal boot




C:\ (Local Disk) - NTFS - Total:149 Go (Free:125 Go)
D:\ (CD or DVD)


Recherche executé en mode normal


*** Recherche dossiers dans "C:\WINDOWS" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Administrateur\menudm~1\progra~1" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" *



*** Recherche fichiers ***



*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :


* Dans "C:\Documents and Settings\Administrateur\locals~1\applic~1" :

mecwqce.dat trouvé !
mecwqce_nav.dat trouvé !
mecwqce_navps.dat trouvé !

3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche autres dossiers et fichiers connus :



*** Analyse terminée le 22/03/2009 à 3:05:32,50 ***
0