Virus qui empèche installation antivirus

Résolu/Fermé
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 - 9 avril 2009 à 13:36
 Utilisateur anonyme - 9 avril 2009 à 16:26
Bonjour,
Je me permets de créer ce sujet car je suis infecté par un virus que je ne parviens pas à supprimer.

- Système : windows vista familial basic

- Symptomes : j'ai exécuté un fichier malveillant qui a désinstallé mon antivirus (Avast) et qui s'oppose à toute réinstallation d'antivirus.

J'ai suivi la procédure décrite et voici les rapports :
Merci

- Rapport log.txt :

Logfile of random's system information tool 1.06 (written by random/random)
Run by janfi at 2009-04-09 12:41:25
Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
System drive C: has 186 GB (64%) free of 293 GB
Total RAM: 2686 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:41:39, on 09/04/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe
C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe
C:\Program Files\CyberLink\PlayMovie\PMVService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\conime.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\janfi\Desktop\RSIT.exe
C:\Program Files\trend micro\janfi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.com/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe" /preinstalled
O4 - HKLM\..\Run: [PCMAgent] "C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\CyberLink\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [GridinSoft Trojan Killer] "C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe" 0
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [GridinSoft Trojan Killer] "C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe" 0 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GridinSoft Trojan Killer] "C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe" 0 (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/fr-be/wlscctrl2.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.807.15159 (GoogleDesktopManager-071508-051939) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1c9a32f14f91916) (gupdate1c9a32f14f91916) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
End of file - 9092 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Extension de garantie-janfi.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachine.job
C:\Windows\tasks\Recovery DVD Creator-janfi.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-25 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\Google\Google_BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-08 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2009-04-09 1008184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-03-01 857648]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-08-17 4702208]
"Skytel"=C:\Windows\Skytel.exe [2007-08-03 1826816]
"CarboniteSetupLite"=C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe [2008-04-07 306112]
"PCMAgent"=C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe [2008-03-21 143360]
"CLMLServer"=C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe [2008-04-12 196608]
"PlayMovie"=C:\Program Files\CyberLink\PlayMovie\PMVService.exe [2008-03-31 172032]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-11-25 24064]
"toolbar_eula_launcher"=C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe [2007-02-20 28672]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-04-09 81000]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-04-08 148888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-11-25 68856]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-03-18 251240]
"GridinSoft Trojan Killer"=C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe [2009-04-08 3665920]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2009-04-09 12:41:26 ----D---- C:\Program Files\trend micro
2009-04-09 12:41:25 ----D---- C:\rsit
2009-04-09 08:42:28 ----D---- C:\ProgramData\avg8
2009-04-08 18:18:02 ----D---- C:\Program Files\GridinSoft Trojan Killer
2009-04-08 18:03:14 ----A---- C:\Windows\ntbtlog.txt
2009-04-08 16:37:01 ----D---- C:\Program Files\DrWeb
2009-04-08 15:49:34 ----D---- C:\Program Files\Panda Security
2009-04-08 15:27:05 ----D---- C:\Program Files\Windows Live Safety Center
2009-04-08 15:12:49 ----A---- C:\InfoSat.txt
2009-04-08 14:50:31 ----D---- C:\Windows\system32\Kaspersky Lab
2009-04-08 14:16:44 ----D---- C:\Windows\Sun
2009-04-08 14:15:39 ----A---- C:\Windows\system32\javaws.exe
2009-04-08 14:15:39 ----A---- C:\Windows\system32\javaw.exe
2009-04-08 14:15:39 ----A---- C:\Windows\system32\java.exe
2009-04-08 14:15:39 ----A---- C:\Windows\system32\deploytk.dll
2009-04-08 14:14:45 ----D---- C:\Program Files\Java
2009-04-08 14:05:42 ----D---- C:\Windows\avxoscan
2009-04-08 13:46:44 ----HD---- C:\Users\janfi\AppData\Roaming\m
2009-04-08 13:28:51 ----A---- C:\Windows\system32\aswBoot.exe
2009-04-08 13:26:54 ----D---- C:\Windows\Minidump
2009-04-08 11:36:51 ----HD---- C:\Users\janfi\AppData\Roaming\drivers
2009-04-08 08:49:36 ----D---- C:\Program Files\PhotoFiltre
2009-03-28 14:25:09 ----D---- C:\Program Files\eMule
2009-03-26 16:52:06 ----A---- C:\Windows\system32\x264vfw.dll
2009-03-26 16:52:06 ----A---- C:\Windows\system32\WMV9VCM.dll
2009-03-26 16:52:05 ----A---- C:\Windows\system32\xvidvfw.dll
2009-03-26 16:52:05 ----A---- C:\Windows\system32\xvidcore.dll
2009-03-26 16:52:05 ----A---- C:\Windows\system32\ssldivx.dll
2009-03-26 16:52:04 ----A---- C:\Windows\system32\qt-dx331.dll
2009-03-26 16:52:04 ----A---- C:\Windows\system32\libdivx.dll
2009-03-26 16:52:04 ----A---- C:\Windows\system32\dtu100.dll
2009-03-26 16:52:04 ----A---- C:\Windows\system32\dpl100.dll
2009-03-26 16:52:04 ----A---- C:\Windows\system32\divx.dll
2009-03-26 16:52:03 ----A---- C:\Windows\system32\ff_vfw.dll.manifest
2009-03-26 16:52:03 ----A---- C:\Windows\system32\ff_vfw.dll
2009-03-26 16:52:01 ----D---- C:\Program Files\K-Lite Codec Pack
2009-03-22 19:23:15 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-03-22 19:23:15 ----A---- C:\Windows\system32\infocardapi.dll
2009-03-22 19:23:13 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-03-22 19:23:13 ----A---- C:\Windows\system32\icardres.dll
2009-03-22 19:23:13 ----A---- C:\Windows\system32\icardagt.exe
2009-03-22 19:23:10 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-03-22 19:23:07 ----A---- C:\Windows\system32\PresentationHost.exe
2009-03-22 19:16:28 ----A---- C:\Windows\system32\dfshim.dll
2009-03-22 19:16:21 ----A---- C:\Windows\system32\mscoree.dll
2009-03-22 19:16:19 ----A---- C:\Windows\system32\netfxperf.dll
2009-03-22 19:16:07 ----A---- C:\Windows\system32\mscorier.dll
2009-03-22 19:16:00 ----A---- C:\Windows\system32\mscories.dll
2009-03-19 18:59:11 ----D---- C:\Users\janfi\AppData\Roaming\TomTom
2009-03-19 18:58:56 ----D---- C:\Program Files\TomTom International B.V
2009-03-19 18:58:37 ----D---- C:\Program Files\TomTom HOME 2
2009-03-18 09:00:08 ----D---- C:\ProgramData\FLEXnet
2009-03-16 18:44:44 ----D---- C:\Program Files\TomTom HOME
2009-03-16 16:27:14 ----D---- C:\Users\janfi\AppData\Roaming\WinRAR
2009-03-16 16:26:58 ----D---- C:\Program Files\WinRAR
2009-03-12 18:23:00 ----D---- C:\ProgramData\Google Updater
2009-03-12 16:26:10 ----D---- C:\ProgramData\HP Product Assistant
2009-03-11 19:56:00 ----D---- C:\ProgramData\eMule
2009-03-11 14:42:32 ----A---- C:\Windows\system32\wmp.dll
2009-03-11 14:42:30 ----A---- C:\Windows\system32\spwmp.dll
2009-03-11 14:42:28 ----A---- C:\Windows\system32\wmploc.DLL
2009-03-11 14:42:28 ----A---- C:\Windows\system32\dxmasf.dll
2009-03-11 14:40:32 ----A---- C:\Windows\system32\schannel.dll
2009-03-11 14:40:25 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-03-11 14:40:25 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-03-11 09:54:09 ----D---- C:\Program Files\Common Files\HP
2009-03-11 09:51:49 ----D---- C:\ProgramData\Hewlett-Packard
2009-03-11 09:46:38 ----A---- C:\Windows\system32\hpz3l4v2.dll
2009-03-11 09:46:37 ----A---- C:\Windows\system32\HPJIPX1U.DLL
2009-03-11 09:46:37 ----A---- C:\Windows\system32\HPJCMN2U.DLL
2009-03-11 09:46:37 ----A---- C:\Windows\system32\HPBPROPS.DLL
2009-03-11 09:46:36 ----A---- C:\Windows\system32\HPBPRO.DLL
2009-03-11 09:46:36 ----A---- C:\Windows\system32\HPBOIDPS.DLL
2009-03-11 09:46:36 ----A---- C:\Windows\system32\HPBOID.DLL
2009-03-11 09:46:36 ----A---- C:\Windows\system32\HPBNRAC2.DLL
2009-03-11 09:46:36 ----A---- C:\Windows\system32\HPBMINI.DLL
2009-03-11 09:46:36 ----A---- C:\Windows\system32\HPBMIAPI.DLL
2009-03-11 09:46:18 ----HD---- C:\Config.Msi
2009-03-11 09:44:43 ----A---- C:\Windows\system32\hpzids01.dll
2009-03-11 09:44:42 ----A---- C:\Windows\system32\hpowiav1.dll
2009-03-11 09:44:42 ----A---- C:\Windows\system32\hpovst01.dll
2009-03-11 09:44:42 ----A---- C:\Windows\system32\hpotiop1.dll
2009-03-11 08:15:22 ----A---- C:\Windows\system32\msshooks.dll
2009-03-11 08:15:21 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-03-11 08:15:21 ----A---- C:\Windows\system32\propdefs.dll
2009-03-11 08:15:21 ----A---- C:\Windows\system32\msstrc.dll
2009-03-11 08:15:21 ----A---- C:\Windows\system32\mssitlb.dll
2009-03-11 08:15:21 ----A---- C:\Windows\system32\msshsq.dll
2009-03-11 08:15:21 ----A---- C:\Windows\system32\msscb.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\xmlfilter.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\wsepno.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\thawbrkr.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\srchadmin.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\rtffilt.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\propsys.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\offfilt.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\nlhtml.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\mssprxy.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\msscntrs.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\mimefilt.dll
2009-03-11 08:15:20 ----A---- C:\Windows\system32\korwbrkr.dll
2009-03-11 08:15:19 ----A---- C:\Windows\system32\tquery.dll
2009-03-11 08:15:19 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-03-11 08:15:19 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-03-11 08:15:19 ----A---- C:\Windows\system32\mssvp.dll
2009-03-11 08:15:19 ----A---- C:\Windows\system32\mssrch.dll
2009-03-11 08:15:19 ----A---- C:\Windows\system32\mssphtb.dll
2009-03-11 08:15:19 ----A---- C:\Windows\system32\mssph.dll
2009-03-11 08:15:19 ----A---- C:\Windows\system32\chtbrkr.dll
2009-03-11 08:15:19 ----A---- C:\Windows\system32\chsbrkr.dll
2009-03-11 08:14:42 ----A---- C:\Windows\system32\tzres.dll
2009-03-10 17:17:02 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-03-10 17:16:56 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-03-10 17:16:26 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-03-10 17:13:14 ----A---- C:\Windows\system32\inetcomm.dll
2009-03-10 17:13:06 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-03-10 17:12:59 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-03-10 17:12:48 ----A---- C:\Windows\system32\mshtml.dll
2009-03-10 17:12:47 ----A---- C:\Windows\system32\urlmon.dll
2009-03-10 17:12:47 ----A---- C:\Windows\system32\ieframe.dll
2009-03-10 17:12:46 ----A---- C:\Windows\system32\wininet.dll
2009-03-10 17:12:46 ----A---- C:\Windows\system32\mstime.dll
2009-03-10 17:12:46 ----A---- C:\Windows\system32\msfeeds.dll
2009-03-10 17:12:46 ----A---- C:\Windows\system32\jsproxy.dll
2009-03-10 17:12:46 ----A---- C:\Windows\system32\iertutil.dll
2009-03-10 17:11:40 ----A---- C:\Windows\system32\rpcrt4.dll
2009-03-10 17:11:39 ----A---- C:\Windows\system32\pacerprf.dll
2009-03-10 17:11:32 ----A---- C:\Windows\system32\es.dll
2009-03-10 17:11:31 ----A---- C:\Windows\system32\gdi32.dll
2009-03-10 17:11:20 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-03-10 17:11:20 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-03-10 17:09:05 ----A---- C:\Windows\system32\wmpeffects.dll
2009-03-10 17:09:04 ----A---- C:\Windows\system32\netapi32.dll
2009-03-10 17:08:57 ----A---- C:\Windows\system32\msxml3.dll
2009-03-10 17:08:51 ----A---- C:\Windows\system32\shell32.dll
2009-03-10 17:07:46 ----A---- C:\Windows\explorer.exe
2009-03-10 17:07:33 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-03-10 17:07:32 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-03-10 17:07:32 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-03-10 17:07:30 ----A---- C:\Windows\system32\wersvc.dll
2009-03-10 17:07:30 ----A---- C:\Windows\system32\Faultrep.dll
2009-03-10 17:07:29 ----A---- C:\Windows\system32\win32spl.dll
2009-03-10 17:07:26 ----A---- C:\Windows\system32\emdmgmt.dll
2009-03-10 17:07:26 ----A---- C:\Windows\system32\dataclen.dll
2009-03-10 17:07:26 ----A---- C:\Windows\system32\cdd.dll
2009-03-10 17:06:18 ----A---- C:\Windows\system32\mf.dll
2009-03-10 17:06:17 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-03-10 17:06:17 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-03-10 17:06:17 ----A---- C:\Windows\system32\logagent.exe
2009-03-10 17:03:11 ----A---- C:\Windows\system32\wshext.dll
2009-03-10 17:03:11 ----A---- C:\Windows\system32\wscript.exe
2009-03-10 17:03:11 ----A---- C:\Windows\system32\vbscript.dll
2009-03-10 17:03:11 ----A---- C:\Windows\system32\scrrun.dll
2009-03-10 17:03:11 ----A---- C:\Windows\system32\scrobj.dll
2009-03-10 17:03:11 ----A---- C:\Windows\system32\jscript.dll
2009-03-10 17:03:11 ----A---- C:\Windows\system32\cscript.exe
2009-03-10 17:03:08 ----A---- C:\Windows\system32\connect.dll
2009-03-10 17:03:06 ----A---- C:\Windows\system32\quartz.dll
2009-03-10 17:00:06 ----D---- C:\Program Files\Microsoft Visual Studio
2009-03-10 16:54:38 ----A---- C:\Windows\system32\msxml6.dll
2009-03-10 16:45:14 ----A---- C:\Windows\system32\wups2.dll
2009-03-10 16:45:14 ----A---- C:\Windows\system32\wucltux.dll
2009-03-10 16:45:14 ----A---- C:\Windows\system32\wuaueng.dll
2009-03-10 16:45:14 ----A---- C:\Windows\system32\wuauclt.exe
2009-03-10 16:44:37 ----A---- C:\Windows\system32\wups.dll
2009-03-10 16:44:37 ----A---- C:\Windows\system32\wudriver.dll
2009-03-10 16:44:37 ----A---- C:\Windows\system32\wuapi.dll
2009-03-10 16:44:28 ----A---- C:\Windows\system32\wuwebv.dll
2009-03-10 16:44:28 ----A---- C:\Windows\system32\wuapp.exe

======List of files/folders modified in the last 1 months======

2009-04-09 12:41:26 ----RD---- C:\Program Files
2009-04-09 12:41:22 ----D---- C:\Windows\Temp
2009-04-09 12:38:07 ----D---- C:\Windows\inf
2009-04-09 12:38:07 ----AD---- C:\Windows\System32
2009-04-09 12:38:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-04-09 12:36:41 ----D---- C:\Windows\prefetch
2009-04-09 10:31:20 ----D---- C:\Windows\Tasks
2009-04-09 10:02:47 ----SHD---- C:\Windows\Installer
2009-04-09 10:02:43 ----D---- C:\Users\janfi\AppData\Roaming\Adobe
2009-04-09 10:02:42 ----D---- C:\Program Files\Adobe
2009-04-09 09:58:33 ----D---- C:\Program Files\Common Files\Adobe
2009-04-09 09:50:44 ----HD---- C:\Windows\system32\drivers
2009-04-09 09:46:01 ----SHD---- C:\System Volume Information
2009-04-09 09:45:20 ----D---- C:\ProgramData\Google
2009-04-09 09:45:20 ----D---- C:\Program Files\Google
2009-04-09 08:42:28 ----HD---- C:\ProgramData
2009-04-09 08:41:10 ----D---- C:\Windows
2009-04-09 08:13:24 ----D---- C:\Windows\system32\Tasks
2009-04-09 08:08:23 ----D---- C:\Program Files\Common Files
2009-04-09 07:35:32 ----SD---- C:\Windows\Downloaded Program Files
2009-04-08 20:06:33 ----D---- C:\Program Files\Packard Bell
2009-04-08 15:39:25 ----D---- C:\Program Files\Mozilla Firefox
2009-04-08 12:34:17 ----D---- C:\Windows\system32\catroot2
2009-04-08 12:21:55 ----D---- C:\Windows\Logs
2009-03-31 14:26:18 ----SD---- C:\Users\janfi\AppData\Roaming\Microsoft
2009-03-23 22:48:07 ----D---- C:\Windows\system32\WDI
2009-03-22 20:00:02 ----D---- C:\Windows\rescache
2009-03-22 19:52:44 ----D---- C:\Windows\Microsoft.NET
2009-03-22 19:52:39 ----RSD---- C:\Windows\assembly
2009-03-22 19:42:35 ----D---- C:\Windows\system32\fr-FR
2009-03-22 19:42:34 ----D---- C:\Windows\system32\XPSViewer
2009-03-22 19:42:34 ----D---- C:\Windows\system32\en-US
2009-03-22 19:42:33 ----D---- C:\Windows\system32\wbem
2009-03-22 19:33:43 ----D---- C:\Windows\winsxs
2009-03-22 19:33:32 ----D---- C:\Windows\system32\catroot
2009-03-20 07:58:11 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-17 08:30:43 ----D---- C:\ProgramData\Adobe
2009-03-11 20:16:19 ----D---- C:\Program Files\Windows Media Player
2009-03-11 20:16:18 ----D---- C:\Program Files\Windows Mail
2009-03-11 20:16:14 ----A---- C:\Windows\DUMP33cc.tmp
2009-03-11 14:48:01 ----D---- C:\ProgramData\HP
2009-03-11 14:46:01 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-03-11 14:43:48 ----D---- C:\ProgramData\Symantec
2009-03-11 10:00:30 ----A---- C:\Windows\win.ini
2009-03-11 09:59:46 ----D---- C:\Program Files\HP
2009-03-11 09:55:18 ----D---- C:\Windows\twain_32
2009-03-11 08:55:02 ----D---- C:\Windows\WindowsMobile
2009-03-11 08:25:29 ----D---- C:\Windows\PolicyDefinitions
2009-03-11 08:25:29 ----D---- C:\Windows\AppPatch
2009-03-10 17:02:07 ----D---- C:\ProgramData\Microsoft Help
2009-03-10 17:00:36 ----D---- C:\Program Files\Common Files\microsoft shared
2009-03-10 17:00:32 ----D---- C:\Program Files\MSBuild
2009-03-10 16:59:50 ----D---- C:\Windows\SHELLNEW
2009-03-10 16:58:17 ----RSD---- C:\Windows\Fonts
2009-03-10 16:52:09 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-03-10 16:51:36 ----D---- C:\Program Files\Common Files\System
2009-03-10 16:35:32 ----D---- C:\Windows\system32\config
2009-03-10 16:33:53 ----RSD---- C:\Windows\Media
2009-03-10 16:33:53 ----D---- C:\Windows\system32\migration
2009-03-10 16:33:53 ----D---- C:\Program Files\Internet Explorer
2009-03-10 16:33:42 ----D---- C:\Windows\system32\spool
2009-03-10 16:33:42 ----D---- C:\Windows\system32\Msdtc
2009-03-10 16:33:42 ----D---- C:\Windows\system32\CodeIntegrity
2009-03-10 16:33:40 ----D---- C:\Program Files\Microsoft Works
2009-03-10 16:33:09 ----D---- C:\Windows\registration
2009-03-10 16:33:04 ----RHD---- C:\MSOCache
2009-03-10 14:46:43 ----D---- C:\Windows\system32\NDF
2009-03-10 14:35:00 ----D---- C:\Windows\Debug
2009-03-10 09:23:21 ----D---- C:\Users\janfi\AppData\Roaming\HP

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 sK9Ou0s;sK9Ou0s; \??\C:\Users\janfi\AppData\Roaming\drivers\srosa2.sys [2009-04-09 7168]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\CyberLink\PlayMovie\000.fcl [2008-03-31 41456]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-02-05 51792]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-07-30 743424]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-05-24 2609152]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
R3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
R3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-08-22 1950552]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2007-01-23 50176]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-03-01 182456]
R3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
R4 AvgRkx86;avgrkx86.sys; C:\Windows\System32\Drivers\avgrkx86.sys []
R4 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys []
R4 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys []
S1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys []
S2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys []
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 usb_rndisx;Carte RNDIS USB; C:\Windows\system32\DRIVERS\usb8023x.sys [2008-01-21 15872]
S3 WINUSB;Pilote WinUsb; C:\Windows\system32\DRIVERS\WinUSB.SYS [2008-01-21 31616]
S4 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys []
S4 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-02-05 94208]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-05-24 602112]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-03-18 92008]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 gupdate1c9a32f14f91916;Service Google Update (gupdate1c9a32f14f91916); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-03-12 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-25 183280]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-11-25 647680]
S3 GoogleDesktopManager-071508-051939;Google Desktop Manager 5.7.807.15159; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-11-25 24064]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-01-14 447784]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-04-09 18752]
S4 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-04-09 138680]
S4 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-04-09 254040]
S4 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-04-09 352920]

-----------------EOF-----------------
- Rapport infos.txt :

info.txt logfile of random's system information tool 1.06 2009-04-09 12:41:42

======Uninstall list======

-->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
-->C:\Windows\UNNeroShowTime.exe /UNINSTALL
-->C:\Windows\UNNeroVision.exe /UNINSTALL
-->C:\Windows\UNRecode.exe /UNINSTALL
-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1DE7171-017D-4E08-ABC5-92EBCCB40F4D}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\Setup.exe" -uninstall
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}
Adobe Reader 8.1.4 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
Adobe Reader 8-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *AdobeReader*
Adobe Shockwave Player-->C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log
ADSL Neuf-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *NEUF_FR*
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
ATK Hotkey-->C:\Program Files\InstallShield Installation Information\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}\setup.exe -runfromtemp -l0x040c -removeonly
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Browser Address Error Redirector-->regsvr32 /u /s "C:\Program Files\Google\Google_BAE\BAE.dll"
Carbonite-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Carbonite*
CyberLink PowerCinema-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
CyberLink PowerCinema-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
eMule-->"C:\Program Files\eMule\Uninstall.exe"
Gestionnaire pour appareils Windows Mobile-->MsiExec.exe /X{904CCF62-818D-4675-BC76-D37EB399F917}
Google BAE-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GoogleBAE*
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
GoogleDesktop-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GoogleDesktop_XX*
HDReg France-->MsiExec.exe /I{0ED40D2A-7131-4FE7-941E-5C329336F712}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
Infocentre Rev. 2.0.0.1-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Infocentre*
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Kaspersky On-line Scanner-->C:\Windows\system32\KASPER~1\KASPER~2\kavuninstall.exe
K-Lite Codec Pack 2.77 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Metaboli-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *METABOLI*
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works 9 SE-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *works9se*
Microsoft Works-->MsiExec.exe /I{0214A441-A4AB-43A8-8DEF-2F73C5364673}
Microsoft® Office Trial 2007-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *OFF2k7_FR*
Mise à jour du pilote du Gestionnaire pour appareils Windows Mobile-->MsiExec.exe /X{E7044E25-3038-4A76-9064-344AC038043E}
Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Nero 8 Essentials-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Nero8*
Nero 8 Essentials-->MsiExec.exe /X{980B9958-1239-4FC5-8C88-AC5650321036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Norton Internet Security-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *NIS2008_FR*
Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Packard Bell ImageWriter-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *ImageWriter*
Packard Bell LCD Test-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *LCDTest*
Packard Bell Updator-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Updator*
Panda ActiveScan 2.0-->C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
Power Cinema 6-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *PowerCinema6*
Protégez vos données-->"C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe" /preinstalled /uninstall
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
SeaTools for Windows-->MsiExec.exe /I{98613C99-1399-416C-A07C-1EE1C585D872}
Skype 3.6.2.248-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *SKYPE*
Skype™ 3.6-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
TomTom HOME 2.6.1.1549-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
TomTom HOME Visual Studio Merge Modules-->MsiExec.exe /I{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}
Trojan Killer 2.0-->"C:\Program Files\GridinSoft Trojan Killer\unins000.exe"
Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
USB 2.0 VGA UVC WebCam-->C:\Windows\Uninstvga.bat
VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}

======Security center information======

AS: Windows Defender

======System event log======

Computer Name: PC-de-janfi1
Event Code: 7000
Message: Le service aswFsBlk n'a pas pu démarrer en raison de l'erreur :
Le fichier spécifié est introuvable.
Record Number: 41691
Source Name: Service Control Manager
Time Written: 20090409062446.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 7026
Message: Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se charger :
aswSP
pavboot
Record Number: 41762
Source Name: Service Control Manager
Time Written: 20090409062446.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 7000
Message: Le service AVG8 WatchDog n'a pas pu démarrer en raison de l'erreur :
AVG8 WatchDog n'est pas une application Win32 valide.
Record Number: 41788
Source Name: Service Control Manager
Time Written: 20090409064305.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 12
Message: Le périphérique 'Énumérateur de périphérique logiciel Plug-and-Play' (Root\SYSTEM\0000) a disparu du système sans que sa suppression ait tout d'abord été préparée.
Record Number: 41790
Source Name: PlugPlayManager
Time Written: 20090409064352.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 12
Message: Le périphérique 'Pilote BIOS de gestion de systèmes Microsoft' (Root\SYSTEM\0002) a disparu du système sans que sa suppression ait tout d'abord été préparée.
Record Number: 41791
Source Name: PlugPlayManager
Time Written: 20090409064352.000000-000
Event Type: Erreur
User:

=====Application event log=====

Computer Name: PC-de-janfi1
Event Code: 8205
Message: Le point de restauration sélectionné a été endommagé ou supprimé pendant la restauration (Point de contrôle planifié).
Record Number: 6187
Source Name: System Restore
Time Written: 20090409062140.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 10
Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
Record Number: 6215
Source Name: Microsoft-Windows-WMI
Time Written: 20090409062446.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 1000
Message: Application défaillante WINWORD.EXE, version 12.0.6211.1000, horodatage 0x46d4a7df, module défaillant hpz3r4v2.dll, version 61.63.249.0, horodatage 0x45c2d639, code d’exception 0xc0000005, décalage d’erreur 0x00046078, ID du processus 0x16f4, heure de début de l’application 0x01c9b8dfe58824ff.
Record Number: 6225
Source Name: Application Error
Time Written: 20090409065349.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 3013
Message: Impossible de mettre à jour l'entrée <C:\USERS\JANFI\DOCUMENTS\~$PPORT ERREUR AVG.DOC> dans la configuration de hachage.

Contexte : Application , Catalogue SystemIndex

Détails :
Un périphérique attaché au système ne fonctionne pas correctement. (0x8007001f)

Record Number: 6238
Source Name: Microsoft-Windows-Search
Time Written: 20090409080539.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-janfi1
Event Code: 3036
Message: La source de contenu <mapi://{s-1-5-21-3054677212-4227261473-3906063122-1000}/> est inaccessible.

Contexte : Application , Catalogue SystemIndex

Détails :
Une erreur s'est produite sur le serveur. Vérifiez que le serveur est disponible. (0x80041206)

Record Number: 6239
Source Name: Microsoft-Windows-Search
Time Written: 20090409081157.000000-000
Event Type: Avertissement
User:

=====Security event log=====

Computer Name: PC-de-janfi1
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 6378
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090409104138.354141-000
Event Type: Échec de l'audit
User:

Computer Name: PC-de-janfi1
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 6379
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090409104138.385341-000
Event Type: Échec de l'audit
User:

Computer Name: PC-de-janfi1
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 6380
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090409104138.416541-000
Event Type: Échec de l'audit
User:

Computer Name: PC-de-janfi1
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 6381
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090409104138.447741-000
Event Type: Échec de l'audit
User:

Computer Name: PC-de-janfi1
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 6382
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090409104138.478941-000
Event Type: Échec de l'audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=6802
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
A voir également:

19 réponses

toptitbal Messages postés 25709 Date d'inscription samedi 8 juillet 2006 Statut Contributeur sécurité Dernière intervention 4 mars 2010 2 229
9 avril 2009 à 13:38
Bonjour

Télécharge FindyKill de Chiquitine29 :

http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

->Enregistre-le sur ton bureau et pas ailleurs !

!! Déconnecte toi et ferme toutes les applications en cours !!

( Si ton anti-virus s'affolle au moment de l'enregistrement ou de l'utilisation de l'outil , ignore l'alerte ...)

-> Clique sur "FindyKill.exe" pour lancer l'installe de l'outil . Ne touche surtout pas aux paramètres d'installation.

Tuto : https://www.malekal.com/tutorial-findykill/



--> Double-clique sur le raccourci " FindyKill " qui est sur ton bureau .

-->choisis l'option 1 ( recherche ). Puis laisse travailler l'outil sans rien toucher ...

Une fois terminé, poste le rapport FindyKill.txt qui est généré ...

( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

PS : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

1
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 14:07
Merci pour votre réponse.
J'ai installé FindyKill sur mon bureau.
Je l'ai lancé l'exécution mais il me met "accès refusé" après avoir sélectionné l'option 1 puis referme automatiquement l'application. Donc pas de rapport.
1
Utilisateur anonyme
9 avril 2009 à 14:20
! Déconnecte toi et ferme toutes application en cours ( navigateur compris ) .

* Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

* Relance "FindyKill" (clic droit sur le raccourci ...) : au menu principal choisis l'option " F " pour français et tape sur [entrée] .

* Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

* Le pc va redémarrer automatiquement ...

--> le programme va travailler , ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

* Poste le rapport qui apparait à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )

/!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

Aides en images ( Suppression ) : http://pagesperso-orange.fr/FindyKill.Ad.Remover/fyk_nettoyage.html
1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
9 avril 2009 à 13:40
je laisse la main :)
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
9 avril 2009 à 13:43
C:\Users\janfi\AppData\Roaming\m
C:\Users\janfi\AppData\Roaming\drivers

>>>bagle.
0
Utilisateur anonyme
9 avril 2009 à 14:08
fais un clic droit sur le raccourci findykill sur ton bureau et choisi executer en tant qu administrateur
0
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 14:16
Voici le rapport

############################## [ FindyKill V4.722 ]

# User : janfi (Administrateurs) # PC-DE-JANFI1
# Update on 04/04/09 by Chiquitine29
# Start at: 14:11:02 | 09/04/2009
# Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

# AMD Turion(tm) 64 X2 Mobile Technology TL-62
# Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
# Internet Explorer 7.0.6001.18000
# Windows Firewall Status : Disabled

# C:\ # Disque fixe local # 286,09 Go (181,9 Go free) [HDD] # NTFS
# D:\ # Disque CD-ROM
# F:\ # Disque amovible

############################## [ Processus actifs ]

C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe
C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe
C:\Program Files\CyberLink\PlayMovie\PMVService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Users\janfi\AppData\Roaming\drivers\winupgro.exe
C:\Windows\System32\wintems.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\system32\svchost.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\janfi\AppData\Roaming\m\flec006.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe

################## [ Processus infectieux stoppés ]

"C:\Users\janfi\AppData\Roaming\drivers\winupgro.exe" (3592)
"C:\Windows\System32\wintems.exe" (3608)
"C:\Users\janfi\AppData\Roaming\m\flec006.exe" (3240)

################## [ C:\Windows # C:\Windows\Prefetch ]


################## [ C:\Windows\System32... ]

Found ! C:\Windows\system32\mdelk.exe
Found ! C:\Windows\system32\wintems.exe

################## [ C:\Users\janfi\AppData\Roaming ]

Found ! "C:\Users\janfi\AppData\Roaming\m\shared"
Found ! "C:\Users\janfi\AppData\Roaming\m\flec006.exe"
Found ! "C:\Users\janfi\AppData\Roaming\m\list.oct"
Found ! "C:\Users\janfi\AppData\Roaming\m\data.oct"
Found ! "C:\Users\janfi\AppData\Roaming\m\srvlist.oct"
Found ! "C:\Users\janfi\AppData\Roaming\m"
Found ! "C:\Users\janfi\AppData\Roaming\drivers"
Found ! "C:\Users\janfi\AppData\Roaming\drivers\srosa2.sys"
Found ! "C:\Users\janfi\AppData\Roaming\drivers\wfsintwq.sys"
Found ! "C:\Users\janfi\AppData\Roaming\drivers\winupgro.exe"
Found ! "C:\Users\janfi\AppData\Roaming\drivers\downld"

################## [ C:\Users\janfi...\Temp Files... ]

Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[2].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[3].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[4].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_2[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_2[2].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_2[3].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[2].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[3].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[4].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[5].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_6[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_6[2].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[2].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[3].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[4].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[5].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[6].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[7].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\b64_3[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\b64_6[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\file[1].txt
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\ftpps[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\2ZTE0PNI\ftpps[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\5J8J0FR2\b64_3[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\5J8J0FR2\ftpps[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\E9MRZI71\ftpps[1].jpg
Found ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\E9MRZI71\ftpps[2].jpg

################## [ Registre / Clés infectieuses ]

Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\Local AppWizard-Generated Applications\flec006
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\Local AppWizard-Generated Applications\run
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\Local AppWizard-Generated Applications\winupgro
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\bisoft
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\DateTime4
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\FirtR
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\MuleAppData
Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\flec006
Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\run
Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! HKEY_CURRENT_USER\Software\bisoft
Found ! HKEY_CURRENT_USER\Software\DateTime4
Found ! HKEY_CURRENT_USER\Software\FirtR
Found ! HKEY_CURRENT_USER\Software\MuleAppData
Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
Found ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

# (!) HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
# (!) HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1

################## [ Recherche dans supports amovibles]

# Recherche fichiers connus :

Found ! "C:\InfoSat.txt"

################## [ Registre / Mountpoint2 ]

# -> Not found !

################## [ ! Fin du rapport # FindyKill V4.722 ! ]
0
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 14:56
J'ai suivi les instructions.
Voici le rapport :

############################## [ FindyKill V4.722 ]

# User : janfi (Administrateurs) # PC-DE-JANFI1
# Update on 04/04/09 by Chiquitine29
# Start at: 14:34:47 | 09/04/2009
# Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

# AMD Turion(tm) 64 X2 Mobile Technology TL-62
# Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
# Internet Explorer 7.0.6001.18000
# Windows Firewall Status : Disabled

# C:\ # Disque fixe local # 286,09 Go (181,8 Go free) [HDD] # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque fixe local # 37,31 Go (5,21 Go free) # NTFS
# F:\ # Disque amovible
# G:\ # Disque amovible # 1,87 Go (357,41 Mo free) [Lexar] # FAT

############################## [ Active Processes ]

C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

################## [ C:\Windows # C:\Windows\Prefetch ]


################## [ C:\Windows\System32... ]

Deleted ! C:\Windows\system32\mdelk.exe
Deleted ! C:\Windows\system32\wintems.exe

################## [ C:\Users\...\AppData\Roaming ]

Deleted ! "C:\Users\janfi\AppData\Roaming\m\flec006.exe"
Deleted ! "C:\Users\janfi\AppData\Roaming\m\list.oct"
Deleted ! "C:\Users\janfi\AppData\Roaming\m\data.oct"
Deleted ! "C:\Users\janfi\AppData\Roaming\m\srvlist.oct"
Deleted ! "C:\Users\janfi\AppData\Roaming\drivers\srosa2.sys"
Deleted ! "C:\Users\janfi\AppData\Roaming\drivers\wfsintwq.sys"
Deleted ! "C:\Users\janfi\AppData\Roaming\drivers\winupgro.exe"
Deleted ! "C:\Users\janfi\AppData\Roaming\m\shared"
Deleted ! "C:\Users\janfi\AppData\Roaming\m"
Deleted ! "C:\Users\janfi\AppData\Roaming\drivers\downld"
Deleted ! "C:\Users\janfi\AppData\Roaming\drivers"

################## [ Cleaning .. Temp Files... ]

Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[2].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[3].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_1[4].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_2[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_2[2].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_2[3].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[2].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[3].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[4].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_3[5].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_6[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\b64_6[2].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[2].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[3].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[4].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[5].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[6].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\016HTS6S\ftpps[7].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\b64_3[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\b64_6[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\file[1].txt
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\257SMHYZ\ftpps[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\2ZTE0PNI\ftpps[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\5J8J0FR2\b64_3[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\5J8J0FR2\ftpps[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\E9MRZI71\ftpps[1].jpg
Deleted ! C:\Users\janfi\Local Settings\Temporary Internet Files\Content.IE5\E9MRZI71\ftpps[2].jpg

################## [ Registry / Infected keys ]

Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Deleted ! HKEY_CURRENT_USER\Software\bisoft
Deleted ! HKEY_CURRENT_USER\Software\DateTime4
Deleted ! HKEY_CURRENT_USER\Software\FirtR
Deleted ! HKEY_CURRENT_USER\Software\MuleAppData
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\flec006
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\run
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! HKEY_USERS\S-1-5-21-3054677212-4227261473-3906063122-1000\Software\MuleAppData
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

################## [ Cleaning Removable drives ]

# Deleting Files :

Deleted ! "C:\InfoSat.txt"

################## [ Registry / Mountpoint2 ]

# -> Not found !

################## [ States / Restarting of services ]

# Services : [ Auto=2 / Request=3 / Disable=4 ]

# Ndisuio -> # Type of startup =3
# EapHost -> # Type of startup =2
# Wlansvc -> # Type of startup =2
# SharedAccess -> # Type of startup =2
# wuauserv -> # Type of startup =2
# wscsvc -> # Type of startup =2
# WinDefend -> # Type of startup =2
# -> UAC is Enable.

################## [ Searching Other Infections ]

# Références de comparaison Bagle MD5 :

File ... : C:\Users\janfi\AppData\Roaming\drivers\winupgro.exe
CRC32 .. : b6638d0b
MD5 .... : 3b0299d2ed3587a62bd15341de6396ef

Deleted ! : C:\$Recycle.Bin\S-1-5-21-3054677212-4227261473-3906063122-1000\$R4OWV7G.zip
Contain run.exe [864256] with Bagle CRC32 : B6638D0B


################## [ Corrupted files # Re-Installation required ]

C:\Program Files\Alwil Software\Avast4\ashAvast.exe
C:\Program Files\Alwil Software\Avast4\ashChest.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashLogV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
C:\Program Files\Alwil Software\Avast4\ashQuick.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
C:\Program Files\Alwil Software\Avast4\ashUpd.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\sched.exe
C:\Program Files\Alwil Software\Avast4\VisthLic.exe
C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
C:\Program Files\CyberLink\PlayMovie\TaskScheduler.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\TaskScheduler.exe
C:\Program Files\CyberLink\PowerCinema\TaskScheduler.exe
C:\Program Files\Mozilla Firefox\uninstall\helper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\avxoscan\upgrepl.exe
C:\Windows\winsxs\x86_security-malware-windows-defender_31bf3856ad364e35_6.0.6001.18000_none_57bcb0ca582f18c5\MSASCui.exe

################## [ ! End of Report # FindyKill V4.722 ! ]
0
Utilisateur anonyme
9 avril 2009 à 14:58
désinstal Avast et avg :

Pour désinstaller Avast telecharge cet outil

https://www.avast.com/fr-fr/uninstall-utility


Instal antivir à la place :

Telecharge et instales l'antivirus Antivir Personal Edition Classic :

->Antivir le telecharger

-> http://www.commentcamarche.net/telecharger/telecharger 55 antivir

tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/
tuto : http://www.swl1f.net/viewtopic.php?f=14&t=59


Telecharge malwarebytes
https://www.malwarebytes.com/

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examen Rapide".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.

PS : les rapport sont aussi rangé dans l onglet rapport/log

0
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 15:25
Voici le rapport :

Malwarebytes' Anti-Malware 1.36
Version de la base de données: 1958
Windows 6.0.6001 Service Pack 1

09/04/2009 15:23:53
mbam-log-2009-04-09 (15-23-53).txt

Type de recherche: Examen rapide
Eléments examinés: 62408
Temps écoulé: 3 minute(s), 0 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/uninst.bat (Trojan.Agent) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\Downloaded Program Files\uninst.bat (Trojan.Agent) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Windows\Downloaded Program Files\uninst.bat (Trojan.Agent) -> Quarantined and deleted successfully.
0
Utilisateur anonyme
9 avril 2009 à 15:29
Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt
0
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 15:35
Logfile of random's system information tool 1.06 (written by random/random)
Run by janfi at 2009-04-09 15:34:24
Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
System drive C: has 186 GB (63%) free of 293 GB
Total RAM: 2686 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:34:34, on 09/04/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe
C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe
C:\Program Files\CyberLink\PlayMovie\PMVService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\janfi\Desktop\RSIT(2).exe
C:\Program Files\trend micro\janfi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.com/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe" /preinstalled
O4 - HKLM\..\Run: [PCMAgent] "C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\CyberLink\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [GridinSoft Trojan Killer] "C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe" 0
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [GridinSoft Trojan Killer] "C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe" 0 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GridinSoft Trojan Killer] "C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe" 0 (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/fr-be/wlscctrl2.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1239192829791&h=db62104727a0d9355e62b9c2ddef6fcf/&filename=jinstall-6u13-windows-i586-jc.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.807.15159 (GoogleDesktopManager-071508-051939) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1c9a32f14f91916) (gupdate1c9a32f14f91916) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
0
Utilisateur anonyme
9 avril 2009 à 15:42
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :



:processes
explorer.exe


:files
C:\Program Files\GridinSoft Trojan Killer
C:\Program Files\Common Files\Symantec Shared
C:\ProgramData\Symantec
C:\Windows\system32\Kaspersky Lab
C:\ProgramData\avg8
C:\Program Files\Panda Security
C:\Program Files\AVG
C:\PROGRA~1\AVG


:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GridinSoft Trojan Killer"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]

:commands
[emptytemp]
[reboot]





---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\ Le nom du rapport correspond au moment de sa création : date_heure.log
0
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 15:55
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
Folder move failed. C:\Program Files\GridinSoft Trojan Killer\updates scheduled to be moved on reboot.
Folder move failed. C:\Program Files\GridinSoft Trojan Killer\logs scheduled to be moved on reboot.
Folder move failed. C:\Program Files\GridinSoft Trojan Killer scheduled to be moved on reboot.
Folder move failed. C:\Program Files\Common Files\Symantec Shared\CCPD-LC scheduled to be moved on reboot.
Folder move failed. C:\Program Files\Common Files\Symantec Shared scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\LiveUpdate\LuRegManifests\Static scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\LiveUpdate\LuRegManifests scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\LiveUpdate scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\Definitions\VirusDefs\20080122.037 scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\Definitions\VirusDefs scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20071204.002 scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\Definitions\SymcData scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec\Definitions scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\Symantec scheduled to be moved on reboot.
Folder move failed. C:\Windows\system32\Kaspersky Lab\Kaspersky Online Scanner scheduled to be moved on reboot.
Folder move failed. C:\Windows\system32\Kaspersky Lab scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\avg8\Log scheduled to be moved on reboot.
Folder move failed. C:\ProgramData\avg8 scheduled to be moved on reboot.
Folder move failed. C:\Program Files\Panda Security scheduled to be moved on reboot.
File/Folder C:\Program Files\AVG not found.
File/Folder C:\PROGRA~1\AVG not found.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GridinSoft Trojan Killer deleted successfully.
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\\ .
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}\\ .
========== COMMANDS ==========
File delete failed. C:\Users\janfi\AppData\Local\Temp\etilqs_1m7uO8TxAKeLDtNLlBEq scheduled to be deleted on reboot.
File delete failed. C:\Users\janfi\AppData\Local\Temp\~DF223D.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\janfi\AppData\Local\Temp\~DF488A.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Windows Temp folder emptied.
File delete failed. C:\Users\janfi\AppData\Local\Mozilla\Firefox\Profiles\lfzewh8i.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Users\janfi\AppData\Local\Mozilla\Firefox\Profiles\lfzewh8i.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Users\janfi\AppData\Local\Mozilla\Firefox\Profiles\lfzewh8i.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Users\janfi\AppData\Local\Mozilla\Firefox\Profiles\lfzewh8i.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Users\janfi\AppData\Local\Mozilla\Firefox\Profiles\lfzewh8i.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Users\janfi\AppData\Local\Mozilla\Firefox\Profiles\lfzewh8i.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04092009_154724
0
Utilisateur anonyme
9 avril 2009 à 15:59
Désactive et reactive ta restauration


* pour supprimer les outils/fix utilisés :

Télécharge ToolsCleaner sur ton bureau.
-->
http://pc-system.fr/
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

# Fais un clic droit sur toolcleaner
# Choisi executer en tant qu administrateur
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
0
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 16:15
[ Rapport ToolsCleaner version 2.3.4 (par A.Rothstein & dj QUIOU) ]

--> Recherche:

C:\FindyKill.txt: trouvé !
C:\_OtMoveIt: trouvé !
C:\FindyKill: trouvé !
C:\Rsit: trouvé !
C:\Program Files\trend micro\HijackThis.exe: trouvé !
C:\Program Files\trend micro\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\FindyKill: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FindyKill: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\FindyKill: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\FindyKill: trouvé !
C:\Users\janfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\FindyKill: trouvé !
C:\Users\janfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FindyKill: trouvé !
C:\Users\janfi\Desktop\OTMoveIt3.exe: trouvé !
C:\Users\janfi\Desktop\Rsit.exe: trouvé !
C:\Users\janfi\Downloads\OTMoveIt3.exe: trouvé !
C:\Users\janfi\Downloads\Rsit.exe: trouvé !

---------------------------------
--> Suppression:

C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\FindyKill.txt: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\Users\janfi\Desktop\OTMoveIt3.exe: supprimé !
C:\Users\janfi\Desktop\Rsit.exe: supprimé !
C:\Users\janfi\Downloads\OTMoveIt3.exe: supprimé !
C:\Users\janfi\Downloads\Rsit.exe: supprimé !
C:\_OtMoveIt: supprimé !
C:\FindyKill: supprimé !
C:\Rsit: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\FindyKill: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FindyKill: supprimé !
C:\Users\janfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes\FindyKill: ERREUR DE SUPPRESSION !!
C:\Users\janfi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FindyKill: supprimé !
0
Utilisateur anonyme
9 avril 2009 à 16:22
si tu n as pas d autres soucis change le statut du sujet en resolu stp

http://www.commentcamarche.net/faq/sujet 11365 marquer un fil de discussion comme etant resolu
0
valcros Messages postés 11 Date d'inscription jeudi 9 avril 2009 Statut Membre Dernière intervention 9 avril 2009 1
9 avril 2009 à 16:25
Tout semble fonctionner parfaitement désormais. Je te remercie de m'avoir aidé et consacré du temps.
0
Utilisateur anonyme
9 avril 2009 à 16:26
De rien,

Bonne apres midi
0