+- 160 virus qui bloke
Résolu
camarchecommeca
Messages postés
170
Statut
Membre
-
tapion76 Messages postés 4857 Statut Membre -
tapion76 Messages postés 4857 Statut Membre -
Bien,je voudrais un logiciel qui supprime tout les virus/ malware ...... payant ou non-payant ya pas dinportance je l'acheterais meme si sa coute 200€merci de votre reponse au plus je suis en mode sans-echec prise cresau
A voir également:
- +- 160 virus qui bloke
- Virus mcafee - Accueil - Piratage
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
- Ordinateur bloqué virus - Accueil - Arnaque
21 réponses
Bonjour,
--> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
--> Double-clique sur RSIT.exe afin de lancer le programme.
(Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
--> Clique sur Continue à l'écran Disclaimer.
--> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
--> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : les rapports sont sauvegardés dans le dossier C:\rsit.
--> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
--> Double-clique sur RSIT.exe afin de lancer le programme.
(Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
--> Clique sur Continue à l'écran Disclaimer.
--> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
--> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : les rapports sont sauvegardés dans le dossier C:\rsit.
/!\ Désactive tes protections résidentes (Antivirus, etc...) /!\
--> Télécharge ComboFix (de sUBs) sur ton Bureau.
--> Double-clique sur ComboFix.exe (le .exe n'est pas forcément visible) afin de le lancer.
--> Il va te demander d'installer la console de récupération : accepte.
--> Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.
Pour t'aider : Un guide et un tutoriel sur l'utilisation de ComboFix
--> Télécharge ComboFix (de sUBs) sur ton Bureau.
--> Double-clique sur ComboFix.exe (le .exe n'est pas forcément visible) afin de le lancer.
--> Il va te demander d'installer la console de récupération : accepte.
--> Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.
Pour t'aider : Un guide et un tutoriel sur l'utilisation de ComboFix
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
info.txt logfile of random's system information tool 1.06 2009-05-04 18:15:01
======Uninstall list======
-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
DivX Codec-->D:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->D:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->D:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->D:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
HijackThis 2.0.2-->"D:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Installation Windows Live-->D:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Lecteur Windows Media 11-->"D:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Malwarebytes' Anti-Malware-->"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0-->D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"D:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word 2007-->"D:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall WORD /dll OSETUP.DLL
Microsoft Office Word 2007-->MsiExec.exe /X{90120000-001B-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"D:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PC Camera-->D:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{02BD1C19-5946-4420-BAE3-F742686B3D43} /l1036
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Windows Imaging Component-->"D:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format 11 runtime-->"D:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"D:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"D:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 2-->D:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinRAR archiver-->D:\Program Files\WinRAR\uninstall.exe
Yahoo! Toolbar-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
=====HijackThis Backups=====
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030d464-4c02-4abf-8ecc-5164760863c6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-05-04]
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll [2009-05-04]
O9 - Extra button: Ajout Direct - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k [2009-05-04]
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe [2009-05-04]
O4 - HKLM\..\Run: [APVXDWIN] "D:\Program Files\Panda Security\Panda Internet Security 2009\APVXDWIN.EXE" /s [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = [2009-05-04]
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) [2009-05-04]
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\uni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [2009-05-04]
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') [2009-05-04]
O2 - BHO: Search Helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - D:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-05-04]
O2 - BHO: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file) [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = [2009-05-04]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx [2009-05-04]
O4 - HKLM\..\RunOnce: [InstallShieldSetup] D:\PROGRA~1\INSTAL~1\{7926E~1\SETUP.exe -rebootD:\PROGRA~1\INSTAL~1\{7926E~1\reboot.ini -l0x40c [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl [2009-05-04]
O4 - HKLM\..\Run: [SCANINICIO] "D:\Program Files\Panda Security\Panda Internet Security 2009\Inicio.exe" [2009-05-04]
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') [2009-05-04]
O2 - BHO: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file) [2009-05-04]
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') [2009-05-04]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.be/?gws_rd=ssl [2009-05-04]
O2 - BHO: Windows Live Toolbar Helper - {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user') [2009-05-04]
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU) [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O20 - AppInit_DLLs: dxvars.dll, dxvars.dll, sysdiag.dll [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O9 - Extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - D:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL [2009-05-04]
O20 - Winlogon Notify: __c00a9d7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/... [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
======System event log======
Computer Name: XP-2YJUGV67T4OW
Event Code: 60054
Message: Le programme d'installation a correctement installé Windows version 2600.
Record Number: 5
Source Name: Setup
Time Written: 20090503111311.000000+120
Event Type: Informations
User:
Computer Name: XP-2YJUGV67T4OW
Event Code: 6011
Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers XP-2YJUGV67T4OW.
Record Number: 4
Source Name: EventLog
Time Written: 20090503110627.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6005
Message: Le service d'Enregistrement d'événement a démarré.
Record Number: 3
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Multiprocessor Free.
Record Number: 2
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 2
Message: Pendant la validation de \Device\Serial0 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée.
Record Number: 1
Source Name: Serial
Time Written: 20090503120313.000000+120
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"SAFEBOOT_OPTION"=NETWORK
-----------------EOF-----------------
======Uninstall list======
-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
DivX Codec-->D:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->D:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->D:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->D:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
HijackThis 2.0.2-->"D:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Installation Windows Live-->D:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Lecteur Windows Media 11-->"D:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Malwarebytes' Anti-Malware-->"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0-->D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"D:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word 2007-->"D:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall WORD /dll OSETUP.DLL
Microsoft Office Word 2007-->MsiExec.exe /X{90120000-001B-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"D:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PC Camera-->D:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{02BD1C19-5946-4420-BAE3-F742686B3D43} /l1036
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Windows Imaging Component-->"D:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format 11 runtime-->"D:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"D:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"D:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 2-->D:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinRAR archiver-->D:\Program Files\WinRAR\uninstall.exe
Yahoo! Toolbar-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
=====HijackThis Backups=====
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030d464-4c02-4abf-8ecc-5164760863c6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-05-04]
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll [2009-05-04]
O9 - Extra button: Ajout Direct - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k [2009-05-04]
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe [2009-05-04]
O4 - HKLM\..\Run: [APVXDWIN] "D:\Program Files\Panda Security\Panda Internet Security 2009\APVXDWIN.EXE" /s [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = [2009-05-04]
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) [2009-05-04]
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\uni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [2009-05-04]
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') [2009-05-04]
O2 - BHO: Search Helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - D:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-05-04]
O2 - BHO: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file) [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = [2009-05-04]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx [2009-05-04]
O4 - HKLM\..\RunOnce: [InstallShieldSetup] D:\PROGRA~1\INSTAL~1\{7926E~1\SETUP.exe -rebootD:\PROGRA~1\INSTAL~1\{7926E~1\reboot.ini -l0x40c [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl [2009-05-04]
O4 - HKLM\..\Run: [SCANINICIO] "D:\Program Files\Panda Security\Panda Internet Security 2009\Inicio.exe" [2009-05-04]
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') [2009-05-04]
O2 - BHO: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file) [2009-05-04]
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') [2009-05-04]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.be/?gws_rd=ssl [2009-05-04]
O2 - BHO: Windows Live Toolbar Helper - {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user') [2009-05-04]
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU) [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O20 - AppInit_DLLs: dxvars.dll, dxvars.dll, sysdiag.dll [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O9 - Extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - D:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL [2009-05-04]
O20 - Winlogon Notify: __c00a9d7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/... [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
======System event log======
Computer Name: XP-2YJUGV67T4OW
Event Code: 60054
Message: Le programme d'installation a correctement installé Windows version 2600.
Record Number: 5
Source Name: Setup
Time Written: 20090503111311.000000+120
Event Type: Informations
User:
Computer Name: XP-2YJUGV67T4OW
Event Code: 6011
Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers XP-2YJUGV67T4OW.
Record Number: 4
Source Name: EventLog
Time Written: 20090503110627.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6005
Message: Le service d'Enregistrement d'événement a démarré.
Record Number: 3
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Multiprocessor Free.
Record Number: 2
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 2
Message: Pendant la validation de \Device\Serial0 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée.
Record Number: 1
Source Name: Serial
Time Written: 20090503120313.000000+120
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"SAFEBOOT_OPTION"=NETWORK
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by uni at 2009-05-04 18:14:50
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 56 GB (91%) free of 61 GB
Total RAM: 503 MB (35% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:14:58, on 04/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
D:\Documents and Settings\uni\Mes documents\Downloads\RSIT.exe
D:\Program Files\Trend Micro\HijackThis\uni.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\
Run by uni at 2009-05-04 18:14:50
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 56 GB (91%) free of 61 GB
Total RAM: 503 MB (35% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:14:58, on 04/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
D:\Documents and Settings\uni\Mes documents\Downloads\RSIT.exe
D:\Program Files\Trend Micro\HijackThis\uni.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\
info.txt logfile of random's system information tool 1.06 2009-05-04 18:15:01
======Uninstall list======
-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
DivX Codec-->D:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->D:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->D:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->D:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
HijackThis 2.0.2-->"D:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Installation Windows Live-->D:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Lecteur Windows Media 11-->"D:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Malwarebytes' Anti-Malware-->"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0-->D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"D:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word 2007-->"D:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall WORD /dll OSETUP.DLL
Microsoft Office Word 2007-->MsiExec.exe /X{90120000-001B-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"D:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PC Camera-->D:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{02BD1C19-5946-4420-BAE3-F742686B3D43} /l1036
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Windows Imaging Component-->"D:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format 11 runtime-->"D:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"D:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"D:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 2-->D:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinRAR archiver-->D:\Program Files\WinRAR\uninstall.exe
Yahoo! Toolbar-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
=====HijackThis Backups=====
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030d464-4c02-4abf-8ecc-5164760863c6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-05-04]
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll [2009-05-04]
O9 - Extra button: Ajout Direct - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k [2009-05-04]
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe [2009-05-04]
O4 - HKLM\..\Run: [APVXDWIN] "D:\Program Files\Panda Security\Panda Internet Security 2009\APVXDWIN.EXE" /s [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = [2009-05-04]
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) [2009-05-04]
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\uni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [2009-05-04]
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') [2009-05-04]
O2 - BHO: Search Helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - D:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-05-04]
O2 - BHO: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file) [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = [2009-05-04]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx [2009-05-04]
O4 - HKLM\..\RunOnce: [InstallShieldSetup] D:\PROGRA~1\INSTAL~1\{7926E~1\SETUP.exe -rebootD:\PROGRA~1\INSTAL~1\{7926E~1\reboot.ini -l0x40c [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl [2009-05-04]
O4 - HKLM\..\Run: [SCANINICIO] "D:\Program Files\Panda Security\Panda Internet Security 2009\Inicio.exe" [2009-05-04]
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') [2009-05-04]
O2 - BHO: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file) [2009-05-04]
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') [2009-05-04]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.be/?gws_rd=ssl [2009-05-04]
O2 - BHO: Windows Live Toolbar Helper - {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user') [2009-05-04]
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU) [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O20 - AppInit_DLLs: dxvars.dll, dxvars.dll, sysdiag.dll [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O9 - Extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - D:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL [2009-05-04]
O20 - Winlogon Notify: __c00a9d7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/... [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
======System event log======
Computer Name: XP-2YJUGV67T4OW
Event Code: 60054
Message: Le programme d'installation a correctement installé Windows version 2600.
Record Number: 5
Source Name: Setup
Time Written: 20090503111311.000000+120
Event Type: Informations
User:
Computer Name: XP-2YJUGV67T4OW
Event Code: 6011
Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers XP-2YJUGV67T4OW.
Record Number: 4
Source Name: EventLog
Time Written: 20090503110627.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6005
Message: Le service d'Enregistrement d'événement a démarré.
Record Number: 3
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Multiprocessor Free.
Record Number: 2
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 2
Message: Pendant la validation de \Device\Serial0 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée.
Record Number: 1
Source Name: Serial
Time Written: 20090503120313.000000+120
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"SAFEBOOT_OPTION"=NETWORK
-----------------EOF-----------------
======Uninstall list======
-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
CCleaner (remove only)-->"D:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
DivX Codec-->D:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->D:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->D:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->D:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
HijackThis 2.0.2-->"D:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Installation Windows Live-->D:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
Lecteur Windows Media 11-->"D:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Malwarebytes' Anti-Malware-->"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0-->D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"D:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word 2007-->"D:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall WORD /dll OSETUP.DLL
Microsoft Office Word 2007-->MsiExec.exe /X{90120000-001B-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"D:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PC Camera-->D:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{02BD1C19-5946-4420-BAE3-F742686B3D43} /l1036
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Windows Imaging Component-->"D:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
Windows Media Format 11 runtime-->"D:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"D:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"D:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 2-->D:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinRAR archiver-->D:\Program Files\WinRAR\uninstall.exe
Yahoo! Toolbar-->D:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
=====HijackThis Backups=====
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030d464-4c02-4abf-8ecc-5164760863c6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-05-04]
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll [2009-05-04]
O9 - Extra button: Ajout Direct - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k [2009-05-04]
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe [2009-05-04]
O4 - HKLM\..\Run: [APVXDWIN] "D:\Program Files\Panda Security\Panda Internet Security 2009\APVXDWIN.EXE" /s [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = [2009-05-04]
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) [2009-05-04]
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\uni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [2009-05-04]
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') [2009-05-04]
O2 - BHO: Search Helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - D:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-05-04]
O2 - BHO: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file) [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = [2009-05-04]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx [2009-05-04]
O4 - HKLM\..\RunOnce: [InstallShieldSetup] D:\PROGRA~1\INSTAL~1\{7926E~1\SETUP.exe -rebootD:\PROGRA~1\INSTAL~1\{7926E~1\reboot.ini -l0x40c [2009-05-04]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl [2009-05-04]
O4 - HKLM\..\Run: [SCANINICIO] "D:\Program Files\Panda Security\Panda Internet Security 2009\Inicio.exe" [2009-05-04]
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') [2009-05-04]
O2 - BHO: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file) [2009-05-04]
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') [2009-05-04]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.be/?gws_rd=ssl [2009-05-04]
O2 - BHO: Windows Live Toolbar Helper - {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - D:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-05-04]
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user') [2009-05-04]
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [2009-05-04]
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU) [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O20 - AppInit_DLLs: dxvars.dll, dxvars.dll, sysdiag.dll [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [2009-05-04]
O9 - Extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - D:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL [2009-05-04]
O20 - Winlogon Notify: __c00a9d7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/... [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O23 - Service: Panda Function Service (pavfnsvr) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe [2009-05-04]
O23 - Service: Panda anti-virus service (pavsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe [2009-05-04]
O23 - Service: Panda Host Service (pshost) - Panda Software International - d:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE [2009-05-04]
O23 - Service: Panda PSK service (psksvcretail) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Panda Process Protection Service (pavprsrv) - Panda Security, S.L. - D:\Program Files\Fichiers communs\Panda Security\PavShld\pavprsrv.exe [2009-05-04]
O23 - Service: Panda Software Controller (panda software controller) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe [2009-05-04]
O23 - Service: Panda TPSrv (tpsrv) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe [2009-05-04]
O23 - Service: Panda IManager Service (psimsvc) - Panda Security S.L. - D:\Program Files\Panda Security\Panda Internet Security 2009\psimsvc.exe [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\ [2009-05-04]
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat [2009-05-04]
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\ [2009-05-04]
======System event log======
Computer Name: XP-2YJUGV67T4OW
Event Code: 60054
Message: Le programme d'installation a correctement installé Windows version 2600.
Record Number: 5
Source Name: Setup
Time Written: 20090503111311.000000+120
Event Type: Informations
User:
Computer Name: XP-2YJUGV67T4OW
Event Code: 6011
Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers XP-2YJUGV67T4OW.
Record Number: 4
Source Name: EventLog
Time Written: 20090503110627.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6005
Message: Le service d'Enregistrement d'événement a démarré.
Record Number: 3
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Multiprocessor Free.
Record Number: 2
Source Name: EventLog
Time Written: 20090503120255.000000+120
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 2
Message: Pendant la validation de \Device\Serial0 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée.
Record Number: 1
Source Name: Serial
Time Written: 20090503120313.000000+120
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"SAFEBOOT_OPTION"=NETWORK
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by uni at 2009-05-04 18:14:50
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 56 GB (91%) free of 61 GB
Total RAM: 503 MB (35% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:14:58, on 04/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
D:\Documents and Settings\uni\Mes documents\Downloads\RSIT.exe
D:\Program Files\Trend Micro\HijackThis\uni.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\
Run by uni at 2009-05-04 18:14:50
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 56 GB (91%) free of 61 GB
Total RAM: 503 MB (35% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:14:58, on 04/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\uni\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
D:\Documents and Settings\uni\Mes documents\Downloads\RSIT.exe
D:\Program Files\Trend Micro\HijackThis\uni.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: __c00A9D7 - D:\WINDOWS\system32\__c00A9D7.dat
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - D:\WINDOWS\
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - D:\WINDOWS\