Mon clavier est blocké par un script

hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   -  
 gen-hackman -
Bonjour a tous j ai des touches de mon clavier qui sont blocké par un script que j arrive pas a trouver
j utilise avast Pro j ai lancer a plusieurs reprise un scan en mode ss échec mais rien il trouve rien ,moi j ai inspecté tout mes processus RIEN!!!! en plus ce foutu virus ou plus tôt dois-je dire script me bloque la touche + et comme je fait du c#&c++ je vous raconte pas le calvaire .... (ce n est pas une défaillance du clavier ni un problème de Driver c un script !)
Je c que la 1iere solution et d utiliser HiJackThis mais dois-je poster le rapport ...??
Si quelq1 a une meilleur solution que HiJackThis .....???
Configuration: Windows XP Pro-SP2

35 réponses

  • 1
  • 2
  1. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    Logfile of HijackThis v1.99.1
    Scan saved at 04:21:30, on 08/06/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\DjBenS\LOCALS~1\Temp\Rar$EX00.406\HijackThis.exe

    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
    0
  2. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    Je viens d installer un ad-Aware et rien il ne trouve rien lui non plus SVP aidez moi je suis en période de révision et sans l espace ni le + je perd un temps fous avec le clavier visuel !!!!!
    0
  3. gen-hackman
     
    salut tu as essayé un autre clavier ?
    0
  4. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    Merci déja pour ton intérêt :
    Oui. c pas le clavier le problème c ce foutu script que je trouve pas !!!
    1) j ai essayé un autre clavier
    2) j ai analiser par les meilleurs anti virus
    3) j ai formater (sof la partion d ou g mes données)
    4) j ai installer et analiser avec toute sorte de anti spy , malware ,.....
    5) j ai chercher manuellement dans tout les processus
    je suis désarmé ! :'(
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    si on me trouve une solution j offre l adobe CS4 !
    0
  7. gen-hackman
     
    LE CS4 tu peux le garder ce n'est pas interessant

    Passer de Avast à AntiVir :

    Télécharge Désinstalleur d'Avast!.

    redemarre en mode sans echec :

    Comment aller en Mode sans échec
    1) Redémarres ton ordi
    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
    3) Tu verras un écran avec options de démarrage apparaître
    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
    (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

    Désinstalle via Ajout/Suppression de Programmes (si présents) :

    * Avast!

    ensuite execute le desinstaller

    Ceci effacera la majorité des traces du produit Avast! d'Alwil Software.

    redemarre

    Télécharge Ccleaner sur ton Bureau. :

    * Clique sur "download the latest version"
    * Installe-le en laissant seulement les options suivantes cochées :

    - Ajouter un raccourci sur le Bureau
    - Contrôler automatiquement les mises à jour de CCleaner

    * Lance le Nettoyage
    * Clique sur Chercher des erreurs et sauvegarde si tu le souhaites.

    plus de precision sur la configuration de ccleaner te seront donnees plus tard

    tuto Comment utiliser CCleaner.
    ***************

    Télécharge Antivir en Francais ou Antivir en Francais sur ton Bureau.:

    * Double clique sur l'exécutable téléchargé pour lancer l'installation.
    * À la fin de l'installation, clique sur Finish.
    * Ouvre Antivir, assure-toi qu’il soit bien à jour !
    * Dans l'onglet Protection Locale, choisis Contrôler.
    * Active la recherche de rootkits via le + de Recherche de Rootkits, puis dans Sélection manuelle, coche tout (tes partitions de disque dur).
    * Clique sur la loupe du milieu pour lancer le scan en tant qu'Administrateur.
    * Poste moi le rapport généré : Pour cela, clique sur l'onglet Aperçu, puis choisis Rapports, tu trouveras son rapport..
    * Sélectionne le rapport et clique sur l'icône "Afficher le fichier de rapport du rapport sélectionné.

    Note : Pour une éradication des menaces plus efficace, lance le scan en mode sans échec.

    Pourquoi changer ? :Avast Vs Antivir

    Tuto Antivir: Comment installer et utiliser AntiVir.

    ***************************************
    Une fois AntiVir ouvert, clique sur "configuration" et coche la case " mode expert " :
    * mets toi sur "scanner"/"recherche" (à gauche) -> dans "fichiers", coche tous les fichiers et en dessous dans priorité scanner= élevé .
    coche aussi : autorisé l'arrêt , comme cela tu peux faire une pause pendant le scan si tu le desir.
    * toujours dans "recherche" -> " Autres réglages ", coche les cases suivantes :

    >secteur d'amorçage lecteurs de rech.

    >Contrôler secteurs d'amorçage maître

    >Suivre les liens symboliques

    >Rech.Rootkit au dém. de la recherche

    et décoche :

    ignorer les fichiers hors ligne

    * mets toi sur "scanner"/"recherche"/ "heuristique" -> Heuristique macrovirus= coché, et en dessous coche activer AHeAD et coche la case degré d'identification élévé ...

    ---> clique sur "OK" pour valider le réglage ...
    ****************************************
    0
  8. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    Merci pour votre soutien :J'ai suivi tes recommandations a la lettre pour le moment tout va mieux ça lague juste un peut.
    Le scan a pris 6heur pour ce faire Antivir a trouver 9menace potentiel tous dans la partition D rien dans le C: !!!!
    il a réparer les menaces j espère que ça va aller . Ce soir je v testé en coding Php :) et je vous tien au courant ;) si non voici le fichier log :

    *********************************************************************************

    Avira AntiVir Personal
    Date de création du fichier de rapport : mercredi 10 juin 2009 17:36

    La recherche porte sur 1461353 souches de virus.

    Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
    Numéro de série : 0000149996-ADJIE-0000001
    Plateforme : Windows XP
    Version de Windows : (Service Pack 3) [5.1.2600]
    Mode Boot : Démarré normalement
    Identifiant : DjBenS
    Nom de l'ordinateur : BENS-1BC494609F

    Informations de version :
    BUILD.DAT : 9.0.0.65 17959 Bytes 22/04/2009 12:06:00
    AVSCAN.EXE : 9.0.3.6 466689 Bytes 21/04/2009 12:20:54
    AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
    LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
    LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
    ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
    ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 19:33:26
    ANTIVIR2.VDF : 7.1.4.38 2692096 Bytes 29/05/2009 22:53:29
    ANTIVIR3.VDF : 7.1.4.77 306176 Bytes 09/06/2009 22:53:53
    Version du moteur : 8.2.0.183
    AEVDF.DLL : 8.1.1.1 106868 Bytes 09/06/2009 23:01:21
    AESCRIPT.DLL : 8.1.2.0 389497 Bytes 09/06/2009 23:01:17
    AESCN.DLL : 8.1.2.3 127347 Bytes 09/06/2009 23:01:06
    AERDL.DLL : 8.1.1.3 438645 Bytes 29/10/2008 17:24:41
    AEPACK.DLL : 8.1.3.18 401783 Bytes 09/06/2009 23:01:02
    AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 19:01:56
    AEHEUR.DLL : 8.1.0.129 1761655 Bytes 09/06/2009 23:00:28
    AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 19:01:56
    AEGEN.DLL : 8.1.1.45 348532 Bytes 09/06/2009 22:54:29
    AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 13:32:40
    AECORE.DLL : 8.1.6.12 180599 Bytes 09/06/2009 22:53:58
    AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
    AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
    AVPREF.DLL : 9.0.0.1 43777 Bytes 03/12/2008 10:39:26
    AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
    AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
    AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
    AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
    SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
    SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
    NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
    RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 17/02/2009 12:49:32
    RCTEXT.DLL : 9.0.37.0 88321 Bytes 15/04/2009 09:07:05

    Configuration pour la recherche actuelle :
    Nom de la tâche...............................: Sélection manuelle
    Fichier de configuration......................: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\PROFILES\folder.avp
    Documentation.................................: bas
    Action principale.............................: interactif
    Action secondaire.............................: ignorer
    Recherche sur les secteurs d'amorçage maître..: marche
    Recherche sur les secteurs d'amorçage.........: marche
    Secteurs d'amorçage...........................: C:, D:, E:,
    Recherche dans les programmes actifs..........: marche
    Recherche en cours sur l'enregistrement.......: marche
    Recherche de Rootkits.........................: marche
    Contrôle d'intégrité de fichiers système......: arrêt
    Fichier mode de recherche.....................: Tous les fichiers
    Recherche sur les archives....................: marche
    Limiter la profondeur de récursivité..........: 20
    Archive Smart Extensions......................: marche
    Heuristique de macrovirus.....................: marche
    Heuristique fichier...........................: élevé
    Catégories de dangers divergentes.............: +APPL,+GAME,+JOKE,+PCK,+SPR,

    Début de la recherche : mercredi 10 juin 2009 17:36

    La recherche d'objets cachés commence.
    '43267' objets ont été contrôlés, '0' objets cachés ont été trouvés.

    La recherche sur les processus démarrés commence :
    Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'wmiapsrv.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'sqlwriter.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'sqlservr.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'jqs.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'rapimgr.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'RocketDock.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'wcescomm.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'msnmsgr.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'ati2evxx.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'ati2evxx.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
    '31' processus ont été contrôlés avec '31' modules

    La recherche sur les secteurs d'amorçage maître commence :
    Secteur d'amorçage maître HD0
    [INFO] Aucun virus trouvé !

    La recherche sur les secteurs d'amorçage commence :
    Secteur d'amorçage 'C:\'
    [INFO] Aucun virus trouvé !
    Secteur d'amorçage 'D:\'
    [INFO] Aucun virus trouvé !

    La recherche sur les renvois aux fichiers exécutables (registre) commence :
    Le registre a été contrôlé ( '48' fichiers).

    La recherche sur les fichiers sélectionnés commence :

    Recherche débutant dans 'C:\'
    C:\pagefile.sys
    [AVERTISSEMENT] Impossible d'ouvrir le fichier !
    [REMARQUE] Ce fichier est un fichier système Windows.
    [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
    C:\WINDOWS\SoftwareDistribution\Download\fcb9a1aecafad7d0bb1ee89bf1633e2c\BIT9.tmp
    [0] Type d'archive: CAB (Microsoft)
    --> _sfx_0003._p
    [AVERTISSEMENT] Impossible d'écrire le fichier !
    --> _sfx_0007._p
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    Recherche débutant dans 'D:\'
    D:\Mes Logiciel\front page 03\Front Page 2003.part2.rar
    [0] Type d'archive: RAR
    --> Front Page 2003\SKU017.CAB
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    Recherche débutant dans 'E:\'
    Impossible d'ouvrir le chemin à contrôler E:\ !
    Erreur système [21]: Le périphérique n'est pas prêt.

    Fin de la recherche : mercredi 10 juin 2009 19:05
    Temps nécessaire: 1:29:22 Heure(s)

    La recherche a été effectuée intégralement

    12435 Les répertoires ont été contrôlés
    557375 Des fichiers ont été contrôlés
    0 Des virus ou programmes indésirables ont été trouvés
    0 Des fichiers ont été classés comme suspects
    0 Des fichiers ont été supprimés
    0 Des virus ou programmes indésirables ont été réparés
    0 Les fichiers ont été déplacés dans la quarantaine
    0 Les fichiers ont été renommés
    1 Impossible de contrôler des fichiers
    557374 Fichiers non infectés
    4529 Les archives ont été contrôlées
    6 Avertissements
    1 Consignes
    43267 Des objets ont été contrôlés lors du Rootkitscan
    0 Des objets cachés ont été trouvés
    0
  9. gen-hackman
     
    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
    0
  10. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    Donc Je rectifie rien ne c passer mon clavier ne fonctionne tj pas g tj l "espace" et le "?" et le "+" qui lague trop et ca dé que je fait du Clt+C donc au début du démarrage tout va bien et dé que je fait une copie ces touches ce plante et ne fonctionnes plus !
    /******************** Info.txt ***************************/
    info.txt logfile of random's system information tool 1.06 2009-06-10 22:08:02

    ======Uninstall list======

    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
    Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
    ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
    ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
    Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    Crystal Reports Basic for Visual Studio 2008-->MsiExec.exe /X{AA467959-A1D6-4F45-90CD-11DC57733F32}
    Crystal Reports Basic French Language Pack for Visual Studio 2008-->MsiExec.exe /X{2516845C-017F-4036-828B-3365FF640AB6}
    Fichiers de prise en charge de l'installation de Microsoft SQL Server (Français)-->MsiExec.exe /X{3380F354-C5F7-4E71-8F51-EEE6C3F06C62}
    High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
    Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
    K-Lite Mega Codec Pack 1.49-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
    Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
    Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{3F7924B9-D148-3141-87B1-68F36043A940}
    Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
    Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{511DF669-2930-30C0-8EB6-552887E29EC8}
    Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
    Microsoft .NET Framework 3.5 Language Pack - fra-->MsiExec.exe /I{5B76AEA2-D4E5-3B55-B965-ACC36AE0EAFC}
    Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
    Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
    Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
    Microsoft Device Emulator version 3.0 - FRA-->MsiExec.exe /X{A5774693-2D17-3E6C-9324-97B17C5AA1E9}
    Microsoft Document Explorer 2008 Language Pack - FRA-->MsiExec.exe /X{AACA7728-BE87-3D11-8A3F-773664BFCF1B}
    Microsoft Document Explorer 2008-->C:\Program Files\Fichiers communs\Microsoft Shared\Help 9\Microsoft Document Explorer 2008\install.exe
    Microsoft Document Explorer 2008-->MsiExec.exe /X{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}
    Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
    Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
    Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
    Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
    Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
    Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
    Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
    Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
    Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
    Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
    Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
    Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
    Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
    Microsoft Office Visual Web Developer 2007-->MsiExec.exe /X{90120000-0021-0000-0000-0000000FF1CE}
    Microsoft Office Visual Web Developer MUI (French) 2007-->MsiExec.exe /X{90120000-0021-040C-0000-0000000FF1CE}
    Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
    Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
    Microsoft SQL Server 2005 Tools Express Edition-->MsiExec.exe /I{3F59A7E0-BC01-4435-9E93-C7D7015C21DA}
    Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
    Microsoft SQL Server Compact 3.5 Design Tools FRA-->MsiExec.exe /X{043ECF7B-4724-4F7B-8A9D-BC22719E95F7}
    Microsoft SQL Server Compact 3.5 for Devices FRA-->MsiExec.exe /I{B4C6D770-DF2E-4731-8869-F89BA6670DDA}
    Microsoft SQL Server Compact 3.5 FRA-->MsiExec.exe /I{BE361597-42AC-4513-9BA6-FFAB310038FB}
    Microsoft SQL Server Database Publishing Wizard 1.2-->MsiExec.exe /X{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}
    Microsoft SQL Server Native Client-->MsiExec.exe /I{9C7E944F-4502-40B8-A0AB-66B2FA9EE829}
    Microsoft SQL Server VSS Writer-->MsiExec.exe /I{75FF1600-6330-43FA-9022-E0835BF20778}
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
    Microsoft Visual Studio 2005 Tools for Office Runtime Language Pack-->C:\Program Files\Fichiers communs\Microsoft Shared\VSTO\8.0\Microsoft Visual Studio 2005 Tools for Office Runtime Language Pack\install.exe
    Microsoft Visual Studio 2005 Tools for Office Runtime-->MsiExec.exe /X{388E4B09-3E71-4649-8921-F44A3A2954A7}
    Microsoft Visual Studio 2008 Professional Edition - Français-->c:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual Studio 2008 Professional Edition - FRA\setup.exe
    Microsoft Visual Studio Web Authoring Component-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall VISUALWEBDEVELOPER /dll OSETUP.DLL
    Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools-->MsiExec.exe /X{6E88CC59-832E-39AF-AE17-B9017DDB12C3}
    Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries-->MsiExec.exe /X{842FAF7C-50EF-4463-9B8F-6222E1384D7D}
    Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense-->MsiExec.exe /X{64c5b887-b5ee-42b8-8596-78905a6b5f1f}
    Microsoft Windows SDK for Visual Studio 2008 Tools-->MsiExec.exe /X{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}
    Microsoft Windows SDK for Visual Studio 2008 Win32 Tools-->MsiExec.exe /X{B268E9A1-04A9-40D0-9866-846BE2B74BA7}
    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
    Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
    Module linguistique Microsoft .NET Framework 3.5 - fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - fra\setup.exe
    Module linguistique Microsoft Document Explorer 2008 - FRA-->C:\Program Files\Fichiers communs\Microsoft Shared\Help 9\Microsoft Document Explorer 2008 Language Pack - FRA\install.exe
    Module linguistique Visual Studio Tools pour Office System 3.0 Runtime - FRA-->C:\Program Files\Fichiers communs\Microsoft Shared\VSTO\9.0\Visual Studio Tools for the Office system 3.0 Runtime Language Pack - FRA\install.exe
    Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
    Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
    Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
    RT61 Wireless LAN Card-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1AFBEFF9-48C2-44FE-92DE-DDAE815DB184}\Setup.exe" -l0x9
    VideoLAN VLC media player 0.8.6a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    Visual Studio 2005 Tools pour Office Second Edition Runtime-->c:\Program Files\Fichiers communs\Microsoft Shared\VSTO\8.0\Microsoft Visual Studio 2005 Tools for Office Runtime\install.exe
    Visual Studio Tools for the Office system 3.0 Runtime-->C:\Program Files\Fichiers communs\Microsoft Shared\VSTO\9.0\Visual Studio Tools for the Office system 3.0 Runtime\install.exe
    Visual Studio Tools for the Office system 3.0 Runtime-->MsiExec.exe /X{8FB53850-246A-3507-8ADE-0060093FFEA6}
    Winamp (remove only)-->"C:\Program Files\Winamp\UninstWA.exe"
    Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
    Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
    Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
    Windows Mobile 5.0 SDK R2 for Pocket PC-->MsiExec.exe /I{94576E4F-703B-4038-806B-CDE9479A33AF}
    Windows Mobile 5.0 SDK R2 for Smartphone-->MsiExec.exe /I{CCFA733C-2F56-4E8C-90B4-B38807400B7A}
    Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
    XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

    ======Security center information======

    AV: AntiVir Desktop

    ======System event log======

    Computer Name: BENS-1BC494609F
    Event Code: 15007
    Message: La réservation de l'espace de nom identifié par le préfixe d'URL http://*:2869/ a été correctement ajoutée.

    Record Number: 5
    Source Name: HTTP
    Time Written: 20090606010645.000000+120
    Event Type: Informations
    User:

    Computer Name: BENS-1BC494609F
    Event Code: 3260
    Message: Cet ordinateur a correctement été joint au workgroup 'WORKGROUP'.

    Record Number: 4
    Source Name: Workstation
    Time Written: 20090606010237.000000+120
    Event Type: Informations
    User:

    Computer Name: BENS-1BC494609F
    Event Code: 6011
    Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers BENS-1BC494609F.

    Record Number: 3
    Source Name: EventLog
    Time Written: 20090606005910.000000+120
    Event Type: Informations
    User:

    Computer Name: MACHINENAME
    Event Code: 6005
    Message: Le service d'Enregistrement d'événement a démarré.

    Record Number: 2
    Source Name: EventLog
    Time Written: 20090606021700.000000+120
    Event Type: Informations
    User:

    Computer Name: MACHINENAME
    Event Code: 6009
    Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.

    Record Number: 1
    Source Name: EventLog
    Time Written: 20090606021700.000000+120
    Event Type: Informations
    User:

    =====Application event log=====

    Computer Name: BENS-1BC494609F
    Event Code: 1000
    Message: Les compteurs de performances pour le service MSDTC (MSDTC) ont été chargés.
    Les données d'enregistrement contiennent les nouvelles valeurs d'index
    assignées à ce service.

    Record Number: 5
    Source Name: LoadPerf
    Time Written: 20090606010403.000000+120
    Event Type: Informations
    User:

    Computer Name: BENS-1BC494609F
    Event Code: 1000
    Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés.
    Les données d'enregistrement contiennent les nouvelles valeurs d'index
    assignées à ce service.

    Record Number: 4
    Source Name: LoadPerf
    Time Written: 20090606010359.000000+120
    Event Type: Informations
    User:

    Computer Name: BENS-1BC494609F
    Event Code: 1000
    Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés.
    Les données d'enregistrement contiennent les nouvelles valeurs d'index
    assignées à ce service.

    Record Number: 3
    Source Name: LoadPerf
    Time Written: 20090606005958.000000+120
    Event Type: Informations
    User:

    Computer Name: BENS-1BC494609F
    Event Code: 1000
    Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés.
    Les données d'enregistrement contiennent les nouvelles valeurs d'index
    assignées à ce service.

    Record Number: 2
    Source Name: LoadPerf
    Time Written: 20090606005924.000000+120
    Event Type: Informations
    User:

    Computer Name: BENS-1BC494609F
    Event Code: 1000
    Message: Les compteurs de performances pour le service RSVP (QoS RSVP) ont été chargés.
    Les données d'enregistrement contiennent les nouvelles valeurs d'index
    assignées à ce service.

    Record Number: 1
    Source Name: LoadPerf
    Time Written: 20090606005923.000000+120
    Event Type: Informations
    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\Microsoft SQL Server\90\Tools\binn\
    "windir"=%SystemRoot%
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=6
    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 12, GenuineIntel
    "PROCESSOR_REVISION"=0e0c
    "NUMBER_OF_PROCESSORS"=2
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "VS90COMNTOOLS"=c:\Program Files\Microsoft Visual Studio 9.0\Common7\Tools\

    -----------------EOF-----------------
    0
  11. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    /*********************** Log.txt *********************************/

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by DjBenS at 2009-06-10 22:07:58
    Microsoft Windows XP Professionnel Service Pack 3
    System drive C: has 15 GB (49%) free of 30 GB
    Total RAM: 894 MB (62% free)

    HijackThis download failed

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-08 35840]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-06-08 73728]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-06-08 148888]
    "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    ""= []
    "MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
    "H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "RocketDock"=C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]

    C:\Documents and Settings\DjBenS\Menu Démarrer\Programmes\Démarrage
    RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\WINDOWS\system32\Ati2evxx.dll [2007-05-15 110592]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    ======List of files/folders created in the last 2 months======

    2009-06-10 22:07:59 ----D---- C:\Program Files\trend micro
    2009-06-10 22:07:58 ----D---- C:\rsit
    2009-06-10 21:17:24 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2009-06-10 21:17:09 ----D---- C:\Program Files\Fichiers communs\Adobe
    2009-06-10 21:16:36 ----SHD---- C:\Config.Msi
    2009-06-10 20:26:32 ----D---- C:\Documents and Settings\DjBenS\Application Data\VitySoft
    2009-06-10 01:13:25 ----A---- C:\WINDOWS\ntbtlog.txt
    2009-06-10 00:39:20 ----D---- C:\Program Files\Avira
    2009-06-10 00:39:20 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
    2009-06-10 00:19:49 ----D---- C:\Program Files\CCleaner
    2009-06-09 04:30:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2009-06-09 04:30:35 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
    2009-06-09 01:28:40 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2009-06-08 22:11:36 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
    2009-06-08 19:35:57 ----A---- C:\WINDOWS\system32\wmpns.dll
    2009-06-08 19:35:12 ----D---- C:\WINDOWS\Prefetch
    2009-06-08 18:41:26 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
    2009-06-08 18:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB963027$
    2009-06-08 18:41:10 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
    2009-06-08 18:41:04 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
    2009-06-08 18:40:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
    2009-06-08 18:40:50 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
    2009-06-08 18:40:44 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
    2009-06-08 18:40:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
    2009-06-08 18:40:31 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2009-06-08 18:40:25 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
    2009-06-08 18:40:19 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2009-06-08 18:40:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
    2009-06-08 18:40:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
    2009-06-08 18:39:52 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
    2009-06-08 18:39:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
    2009-06-08 18:39:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2009-06-08 18:39:33 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2009-06-08 18:39:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
    2009-06-08 18:39:18 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
    2009-06-08 18:39:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2009-06-08 18:39:06 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2009-06-08 18:39:00 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2009-06-08 18:38:53 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
    2009-06-08 18:38:47 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2009-06-08 18:38:41 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
    2009-06-08 18:38:34 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
    2009-06-08 18:34:17 ----D---- C:\WINDOWS\system32\fr
    2009-06-08 18:34:17 ----D---- C:\WINDOWS\l2schemas
    2009-06-08 18:34:16 ----D---- C:\WINDOWS\system32\bits
    2009-06-08 18:31:35 ----D---- C:\WINDOWS\ServicePackFiles
    2009-06-08 18:28:58 ----D---- C:\WINDOWS\network diagnostic
    2009-06-08 18:27:13 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2009-06-08 18:23:43 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
    2009-06-08 18:05:42 ----D---- C:\WINDOWS\ASTULogTemp
    2009-06-08 17:49:15 ----A---- C:\ASLog.txt
    2009-06-08 17:49:00 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-06-08 14:37:49 ----D---- C:\Documents and Settings\DjBenS\Application Data\AdobeUM
    2009-06-08 05:45:17 ----D---- C:\Documents and Settings\DjBenS\Application Data\Media Player Classic
    2009-06-08 05:44:19 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-06-08 05:41:11 ----A---- C:\WINDOWS\rootkitno.ini
    2009-06-08 05:41:02 ----D---- C:\RootkitNO
    2009-06-08 05:36:45 ----D---- C:\Documents and Settings\DjBenS\Application Data\Help
    2009-06-08 05:34:28 ----A---- C:\WINDOWS\system32\PARTIZAN.TXT
    2009-06-08 05:31:18 ----RASHOT---- C:\WINDOWS\winstart.bat
    2009-06-08 05:30:57 ----D---- C:\Program Files\UnHackMe
    2009-06-08 05:00:59 ----A---- C:\WINDOWS\system32\javaws.exe
    2009-06-08 05:00:59 ----A---- C:\WINDOWS\system32\javaw.exe
    2009-06-08 05:00:59 ----A---- C:\WINDOWS\system32\java.exe
    2009-06-08 05:00:59 ----A---- C:\WINDOWS\system32\deploytk.dll
    2009-06-08 05:00:39 ----D---- C:\Program Files\Java
    2009-06-08 04:53:12 ----D---- C:\Documents and Settings\DjBenS\Application Data\Sun
    2009-06-07 18:15:13 ----HDC---- C:\WINDOWS\$NtUninstallKB909394$
    2009-06-07 18:14:44 ----D---- C:\Program Files\Microsoft ActiveSync
    2009-06-07 03:03:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
    2009-06-07 03:03:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
    2009-06-07 03:03:12 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
    2009-06-07 03:03:06 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
    2009-06-07 03:02:59 ----HDC---- C:\WINDOWS\$NtUninstallKB961373_0$
    2009-06-07 03:02:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
    2009-06-07 03:02:46 ----HDC---- C:\WINDOWS\$NtUninstallKB935448$
    2009-06-07 03:02:39 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
    2009-06-07 03:02:31 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
    2009-06-07 03:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
    2009-06-07 03:02:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
    2009-06-07 03:01:40 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
    2009-06-07 03:01:33 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
    2009-06-07 03:01:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
    2009-06-07 03:01:16 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
    2009-06-07 03:01:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
    2009-06-07 03:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
    2009-06-07 03:00:57 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-06-07 03:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB958687_0$
    2009-06-07 03:00:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
    2009-06-07 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
    2009-06-07 03:00:27 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
    2009-06-07 03:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
    2009-06-07 03:00:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958690_0$
    2009-06-07 03:00:02 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
    2009-06-07 02:59:55 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
    2009-06-07 02:59:48 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
    2009-06-07 02:59:42 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
    2009-06-07 02:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
    2009-06-07 02:59:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
    2009-06-07 02:59:00 ----HDC---- C:\WINDOWS\$NtUninstallKB963027_0$
    2009-06-07 02:58:50 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
    2009-06-07 02:58:37 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
    2009-06-06 14:51:07 ----D---- C:\WINDOWS\system32\PreInstall
    2009-06-06 14:51:05 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
    2009-06-06 14:51:05 ----HD---- C:\WINDOWS\$hf_mig$
    2009-06-06 14:04:40 ----A---- C:\WINDOWS\system32\TwnLib20.dll
    2009-06-06 14:04:33 ----N---- C:\WINDOWS\system32\TwnLib4.dll
    2009-06-06 14:04:33 ----N---- C:\WINDOWS\system32\ImagXRA7.dll
    2009-06-06 14:04:33 ----N---- C:\WINDOWS\system32\ImagXR7.dll
    2009-06-06 14:04:32 ----N---- C:\WINDOWS\system32\ImagXpr7.dll
    2009-06-06 14:04:32 ----N---- C:\WINDOWS\system32\ImagX7.dll
    2009-06-06 14:04:30 ----N---- C:\WINDOWS\system32\picn20.dll
    2009-06-06 14:04:25 ----D---- C:\Program Files\Fichiers communs\Ahead
    2009-06-06 14:04:25 ----A---- C:\WINDOWS\system32\NeroCheck.exe
    2009-06-06 14:04:20 ----D---- C:\Program Files\Ahead
    2009-06-06 14:01:36 ----D---- C:\Program Files\Adobe
    2009-06-06 05:36:25 ----D---- C:\WINDOWS\system32\SoftwareDistribution
    2009-06-06 05:00:59 ----A---- C:\WINDOWS\ODBC.INI
    2009-06-06 05:00:19 ----D---- C:\WINDOWS\system32\js
    2009-06-06 05:00:19 ----D---- C:\WINDOWS\system32\images
    2009-06-06 05:00:19 ----D---- C:\WINDOWS\system32\html
    2009-06-06 05:00:19 ----D---- C:\WINDOWS\system32\css
    2009-06-06 05:00:19 ----D---- C:\Program Files\Business Objects
    2009-06-06 04:55:05 ----D---- C:\Program Files\Microsoft SQL Server
    2009-06-06 04:54:29 ----D---- C:\Program Files\Microsoft Device Emulator
    2009-06-06 04:53:19 ----D---- C:\Program Files\Windows Mobile 5.0 SDK R2
    2009-06-06 04:52:28 ----D---- C:\Program Files\Microsoft Synchronization Services
    2009-06-06 04:52:27 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
    2009-06-06 04:44:13 ----D---- C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
    2009-06-06 04:39:33 ----D---- C:\WINDOWS\symbols
    2009-06-06 04:37:29 ----D---- C:\Program Files\Microsoft SDKs
    2009-06-06 04:37:29 ----D---- C:\Program Files\HTML Help Workshop
    2009-06-06 04:37:29 ----D---- C:\Program Files\Fichiers communs\Merge Modules
    2009-06-06 04:37:29 ----D---- C:\Program Files\CE Remote Tools
    2009-06-06 04:37:28 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
    2009-06-06 04:36:01 ----D---- C:\Program Files\Microsoft Web Designer Tools
    2009-06-06 04:32:52 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
    2009-06-06 04:32:33 ----D---- C:\WINDOWS\system32\fr-FR
    2009-06-06 04:30:23 ----D---- C:\WINDOWS\system32\XPSViewer
    2009-06-06 04:30:16 ----D---- C:\WINDOWS\system32\en-us
    2009-06-06 04:30:15 ----D---- C:\Program Files\Reference Assemblies
    2009-06-06 04:29:43 ----N---- C:\WINDOWS\system32\spmsg2.dll
    2009-06-06 04:26:21 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
    2009-06-06 04:26:14 ----D---- C:\Program Files\MSXML 6.0
    2009-06-06 04:24:58 ----D---- C:\Documents and Settings\DjBenS\Application Data\Macromedia
    2009-06-06 04:24:58 ----D---- C:\Documents and Settings\DjBenS\Application Data\Adobe
    2009-06-06 03:53:03 ----D---- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    2009-06-06 02:58:37 ----A---- C:\WINDOWS\system32\h323log.txt
    2009-06-06 02:19:37 ----A---- C:\WINDOWS\system32\usbui.dll
    2009-06-06 02:18:14 ----SHD---- C:\WINDOWS\Installer
    2009-06-06 02:18:14 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-06-06 02:18:13 ----D---- C:\Program Files\Fichiers communs\ODBC
    2009-06-06 02:18:13 ----A---- C:\WINDOWS\ODBCINST.INI
    2009-06-06 02:18:09 ----D---- C:\Program Files\Fichiers communs\SpeechEngines
    2009-06-06 02:18:08 ----RD---- C:\Program Files
    2009-06-06 02:18:08 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
    2009-06-06 02:18:08 ----D---- C:\Program Files\Fichiers communs
    2009-06-06 02:18:05 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
    2009-06-06 02:18:05 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
    2009-06-06 02:18:05 ----RA---- C:\WINDOWS\system32\kbdazel.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdycc.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbduzb.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdur.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdtat.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdru1.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdmon.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
    2009-06-06 02:18:03 ----RA---- C:\WINDOWS\system32\kbdaze.dll
    2009-06-06 02:18:02 ----RA---- C:\WINDOWS\system32\kbdru.dll
    2009-06-06 02:18:02 ----RA---- C:\WINDOWS\system32\kbdbu.dll
    2009-06-06 02:18:02 ----RA---- C:\WINDOWS\system32\kbdblr.dll
    2009-06-06 02:18:01 ----RA---- C:\WINDOWS\system32\kbdhept.dll
    2009-06-06 02:18:01 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
    2009-06-06 02:18:01 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
    2009-06-06 02:18:01 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
    2009-06-06 02:18:00 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
    2009-06-06 02:18:00 ----RA---- C:\WINDOWS\system32\kbdhe.dll
    2009-06-06 02:18:00 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
    2009-06-06 02:17:59 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
    2009-06-06 02:17:59 ----RA---- C:\WINDOWS\system32\kbdlv.dll
    2009-06-06 02:17:59 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
    2009-06-06 02:17:59 ----RA---- C:\WINDOWS\system32\kbdlt.dll
    2009-06-06 02:17:59 ----RA---- C:\WINDOWS\system32\kbdest.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdycl.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdsl.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdro.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdpl.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdhu.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdcz.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\kbdcr.dll
    2009-06-06 02:17:57 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
    2009-06-06 02:17:54 ----A---- C:\WINDOWS\system32\spxcoins.dll
    2009-06-06 02:17:54 ----A---- C:\WINDOWS\system32\irclass.dll
    2009-06-06 02:17:54 ----A---- C:\WINDOWS\system32\EqnClass.Dll
    2009-06-06 02:17:54 ----A---- C:\WINDOWS\system32\dgsetup.dll
    2009-06-06 02:17:54 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
    2009-06-06 02:17:51 ----N---- C:\WINDOWS\system32\CONFIG.TMP
    2009-06-06 02:17:51 ----A---- C:\WINDOWS\TASKMAN.EXE
    2009-06-06 02:17:51 ----A---- C:\WINDOWS\system32\batt.dll
    2009-06-06 02:17:50 ----A---- C:\WINDOWS\notepad.exe
    2009-06-06 02:17:49 ----A---- C:\WINDOWS\system32\storprop.dll
    2009-06-06 02:17:40 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
    2009-06-06 02:17:36 ----RA---- C:\WINDOWS\SET8.tmp
    2009-06-06 02:17:33 ----RA---- C:\WINDOWS\SET4.tmp
    2009-06-06 02:17:31 ----RA---- C:\WINDOWS\SET3.tmp
    2009-06-06 02:17:26 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-06-06 02:17:26 ----D---- C:\WINDOWS\system32\CatRoot
    2009-06-06 02:17:20 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2009-06-06 02:16:51 ----D---- C:\Documents and Settings
    2009-06-06 02:15:37 ----SH---- C:\boot.ini
    2009-06-06 02:12:08 ----SHD---- C:\System Volume Information
    2009-06-06 02:09:23 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-06-06 02:09:23 ----RSD---- C:\WINDOWS\Fonts
    2009-06-06 02:09:23 ----RD---- C:\WINDOWS\Web
    2009-06-06 02:09:23 ----HD---- C:\WINDOWS\inf
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\WinSxS
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\twain_32
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Temp
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\wins
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\wbem
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\usmt
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\spool
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\ShellExt
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\Setup
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\ras
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\oobe
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\npp
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\mui
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\inetsrv
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\IME
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\icsxml
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\ias
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\export
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\drivers
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\dhcp
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\config
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\3com_dmi
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\3076
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\2052
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1054
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1042
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1041
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1037
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1036
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1033
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1031
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1028
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32\1025
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system32
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\system
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\security
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Resources
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\repair
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Provisioning
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\PeerNet
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\pchealth
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\mui
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\msapps
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\msagent
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Media
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\java
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\ime
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Help
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\ehome
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Driver Cache
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Debug
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Cursors
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Connection Wizard
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\Config
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\AppPatch
    2009-06-06 02:09:23 ----D---- C:\WINDOWS\addins
    2009-06-06 02:09:23 ----D---- C:\WINDOWS
    2009-06-06 01:52:31 ----D---- C:\Documents and Settings\DjBenS\Application Data\Mozilla
    2009-06-06 01:52:21 ----D---- C:\Program Files\Mozilla Firefox
    2009-06-06 01:52:04 ----A---- C:\WINDOWS\BricoPackUninst.cmd
    2009-06-06 01:52:02 ----SHD---- C:\RECYCLER
    2009-06-06 01:49:20 ----A---- C:\WINDOWS\BricoPackUninst.txt
    2009-06-06 01:48:20 ----D---- C:\WINDOWS\BricoPacks
    2009-06-06 01:47:29 ----D---- C:\Documents and Settings\DjBenS\Application Data\WinRAR
    2009-06-06 01:44:47 ----D---- C:\Program Files\Windows Live
    2009-06-06 01:44:46 ----D---- C:\Program Files\Messenger Plus! Live
    2009-06-06 01:43:44 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2009-06-06 01:43:14 ----D---- C:\Program Files\MSN Messenger
    2009-06-06 01:40:28 ----D---- C:\Program Files\Microsoft Works
    2009-06-06 01:40:18 ----D---- C:\Program Files\MSBuild
    2009-06-06 01:40:05 ----D---- C:\Program Files\Microsoft Visual Studio
    2009-06-06 01:40:05 ----D---- C:\Program Files\Fichiers communs\DESIGNER
    2009-06-06 01:39:25 ----D---- C:\Program Files\Microsoft.NET
    2009-06-06 01:38:20 ----N---- C:\WINDOWS\system32\vxblock.dll
    2009-06-06 01:38:20 ----N---- C:\WINDOWS\system32\pxwave.dll
    2009-06-06 01:38:20 ----N---- C:\WINDOWS\system32\pxmas.dll
    2009-06-06 01:38:20 ----N---- C:\WINDOWS\system32\pxhpinst.exe
    2009-06-06 01:38:20 ----N---- C:\WINDOWS\system32\pxdrv.dll
    2009-06-06 01:38:20 ----N---- C:\WINDOWS\system32\px.dll
    2009-06-06 01:37:59 ----D---- C:\Program Files\Winamp
    2009-06-06 01:37:59 ----A---- C:\WINDOWS\winamp.ini
    2009-06-06 01:37:06 ----D---- C:\Program Files\Microsoft Visual Studio 8
    2009-06-06 01:36:36 ----D---- C:\WINDOWS\SHELLNEW
    2009-06-06 01:36:17 ----D---- C:\Program Files\Microsoft Office
    2009-06-06 01:36:17 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2009-06-06 01:35:59 ----RHD---- C:\MSOCache
    2009-06-06 01:35:23 ----D---- C:\Documents and Settings\DjBenS\Application Data\vlc
    2009-06-06 01:34:58 ----D---- C:\Program Files\VideoLAN
    2009-06-06 01:34:58 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
    2009-06-06 01:34:45 ----A---- C:\WINDOWS\system32\rmoc3260.dll
    2009-06-06 01:34:45 ----A---- C:\WINDOWS\system32\pndx5032.dll
    2009-06-06 01:34:45 ----A---- C:\WINDOWS\system32\pndx5016.dll
    2009-06-06 01:34:44 ----A---- C:\WINDOWS\system32\pncrt.dll
    2009-06-06 01:34:36 ----A---- C:\WINDOWS\system32\unrar.dll
    2009-06-06 01:34:23 ----A---- C:\WINDOWS\system32\vp7vfw.dll
    2009-06-06 01:34:23 ----A---- C:\WINDOWS\system32\vp6vfw.dll
    2009-06-06 01:34:23 ----A---- C:\WINDOWS\system32\vp31vfw.dll
    2009-06-06 01:34:22 ----A---- C:\WINDOWS\system32\3ivxVfWCodec.dll
    2009-06-06 01:34:21 ----A---- C:\WINDOWS\system32\3ivx.dll
    2009-06-06 01:34:20 ----A---- C:\WINDOWS\system32\WMV9VCM.dll
    2009-06-06 01:34:19 ----A---- C:\WINDOWS\system32\xvidvfw.dll
    2009-06-06 01:34:19 ----A---- C:\WINDOWS\system32\xvidcore.dll
    2009-06-06 01:34:19 ----A---- C:\WINDOWS\system32\ssldivx.dll
    2009-06-06 01:34:15 ----A---- C:\WINDOWS\system32\qt-dx331.dll
    2009-06-06 01:34:15 ----A---- C:\WINDOWS\system32\libdivx.dll
    2009-06-06 01:34:15 ----A---- C:\WINDOWS\system32\dtu100.dll
    2009-06-06 01:34:15 ----A---- C:\WINDOWS\system32\dpv11.dll
    2009-06-06 01:34:15 ----A---- C:\WINDOWS\system32\dpus11.dll
    2009-06-06 01:34:15 ----A---- C:\WINDOWS\system32\dpuGUI11.dll
    2009-06-06 01:34:14 ----A---- C:\WINDOWS\system32\dpu11.dll
    2009-06-06 01:34:14 ----A---- C:\WINDOWS\system32\dpl100.dll
    2009-06-06 01:34:14 ----A---- C:\WINDOWS\system32\divx.dll
    2009-06-06 01:34:12 ----A---- C:\WINDOWS\system32\unicows.dll
    2009-06-06 01:34:12 ----A---- C:\WINDOWS\system32\msvcr70.dll
    2009-06-06 01:34:12 ----A---- C:\WINDOWS\system32\ff_vfw.dll
    2009-06-06 01:34:12 ----A---- C:\WINDOWS\system32\cpuinf32.dll
    2009-06-06 01:34:11 ----D---- C:\Program Files\K-Lite Codec Pack
    2009-06-06 01:34:11 ----D---- C:\Documents and Settings\DjBenS\Application Data\Real
    2009-06-06 01:34:11 ----D---- C:\Documents and Settings\All Users\Application Data\Real
    2009-06-06 01:33:17 ----A---- C:\WINDOWS\system32\MSVCR71.dll
    2009-06-06 01:33:17 ----A---- C:\WINDOWS\system32\MSVCP71.dll
    2009-06-06 01:33:17 ----A---- C:\WINDOWS\system32\MFC71.dll
    2009-06-06 01:33:11 ----D---- C:\Program Files\Alwil Software
    2009-06-06 01:31:57 ----D---- C:\Documents and Settings\DjBenS\Application Data\ATI
    2009-06-06 01:31:54 ----D---- C:\WINDOWS\system32\Lang
    2009-06-06 01:29:38 ----D---- C:\Program Files\WinRAR
    2009-06-06 01:26:22 ----D---- C:\Program Files\ATI Technologies
    2009-06-06 01:24:22 ----RSD---- C:\WINDOWS\assembly
    2009-06-06 01:23:58 ----D---- C:\WINDOWS\Microsoft.NET
    2009-06-06 01:23:38 ----N---- C:\WINDOWS\system32\spmsg.dll
    2009-06-06 01:23:26 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
    2009-06-06 01:22:50 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
    2009-06-06 01:22:48 ----RA---- C:\WINDOWS\system32\ATIDEMGX.dll
    2009-06-06 01:21:58 ----D---- C:\WINDOWS\OPTIONS
    2009-06-06 01:21:05 ----R---- C:\WINDOWS\system32\ChCfg.exe
    2009-06-06 01:20:43 ----D---- C:\WINDOWS\system32\RTCOM
    2009-06-06 01:20:42 ----A---- C:\WINDOWS\system32\ksuser.dll
    2009-06-06 01:20:11 ----A---- C:\WINDOWS\system32\spupdsvc.exe
    2009-06-06 01:20:10 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
    2009-06-06 01:20:07 ----R---- C:\WINDOWS\SoundMan.exe
    2009-06-06 01:20:07 ----R---- C:\WINDOWS\SkyTel.exe
    2009-06-06 01:20:07 ----R---- C:\WINDOWS\RtlUpd.exe
    2009-06-06 01:20:05 ----R---- C:\WINDOWS\RTLCPL.exe
    2009-06-06 01:20:01 ----R---- C:\WINDOWS\RTHDCPL.exe
    2009-06-06 01:20:01 ----R---- C:\WINDOWS\MicCal.exe
    2009-06-06 01:19:59 ----R---- C:\WINDOWS\alcwzrd.exe
    2009-06-06 01:19:59 ----R---- C:\WINDOWS\Alcmtr.exe
    2009-06-06 01:19:58 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-06-06 01:19:58 ----D---- C:\Program Files\Realtek
    2009-06-06 01:19:53 ----R---- C:\WINDOWS\RtlExUpd.dll
    2009-06-06 01:19:53 ----A---- C:\WINDOWS\HideWin.exe
    2009-06-06 01:19:49 ----D---- C:\Program Files\Fichiers communs\InstallShield
    2009-06-06 01:18:56 ----D---- C:\Documents and Settings\DjBenS\Application Data\Identities
    2009-06-06 01:18:54 ----HD---- C:\Program Files\Uninstall Information
    2009-06-06 01:18:48 ----ASH---- C:\Documents and Settings\DjBenS\Application Data\desktop.ini
    2009-06-06 01:18:47 ----SD---- C:\Documents and Settings\DjBenS\Application Data\Microsoft
    2009-06-06 01:17:55 ----D---- C:\WINDOWS\SoftwareDistribution
    2009-06-06 01:17:53 ----SD---- C:\WINDOWS\system32\Microsoft
    2009-06-06 01:17:53 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-06-06 01:08:30 ----D---- C:\WINDOWS\system32\xircom
    2009-06-06 01:08:30 ----D---- C:\Program Files\xerox
    2009-06-06 01:08:30 ----D---- C:\Program Files\microsoft frontpage
    2009-06-06 01:08:09 ----A---- C:\WINDOWS\control.ini
    2009-06-06 01:08:09 ----A---- C:\AUTOEXEC.BAT
    2009-06-06 01:07:53 ----A---- C:\WINDOWS\system32\mapi32.dll
    2009-06-06 01:06:59 ----SD---- C:\WINDOWS\Downloaded Program Files
    2009-06-06 01:06:59 ----RD---- C:\WINDOWS\Offline Web Pages
    2009-06-06 01:06:59 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
    2009-06-06 01:06:52 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
    2009-06-06 01:06:47 ----HD---- C:\Program Files\WindowsUpdate
    2009-06-06 01:06:42 ----D---- C:\Program Files\Services en ligne
    2009-06-06 01:06:24 ----D---- C:\WINDOWS\system32\DirectX
    2009-06-06 01:06:01 ----A---- C:\WINDOWS\system32\atrace.dll
    2009-06-06 01:05:58 ----A---- C:\WINDOWS\system32\desktop.ini
    2009-06-06 01:05:58 ----A---- C:\WINDOWS\desktop.ini
    2009-06-06 01:05:50 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
    2009-06-06 01:05:49 ----A---- C:\WINDOWS\system32\acctres.dll
    2009-06-06 01:05:48 ----D---- C:\Program Files\Fichiers communs\Services
    2009-06-06 01:05:46 ----SD---- C:\WINDOWS\Tasks
    2009-06-06 01:05:46 ----A---- C:\WINDOWS\system32\icfgnt5.dll
    2009-06-06 01:05:44 ----D---- C:\Program Files\Fichiers communs\MSSoap
    2009-06-06 01:05:39 ----D---- C:\WINDOWS\srchasst
    2009-06-06 01:05:38 ----D---- C:\WINDOWS\system32\Macromed
    2009-06-06 01:05:35 ----A---- C:\WINDOWS\system32\wuweb.dll
    2009-06-06 01:05:35 ----A---- C:\WINDOWS\system32\wucltui.dll
    2009-06-06 01:05:35 ----A---- C:\WINDOWS\system32\wuauserv.dll
    2009-06-06 01:05:35 ----A---- C:\WINDOWS\system32\wuaueng1.dll
    2009-06-06 01:05:34 ----A---- C:\WINDOWS\system32\wups.dll
    2009-06-06 01:05:34 ----A---- C:\WINDOWS\system32\wuaueng.dll
    2009-06-06 01:05:34 ----A---- C:\WINDOWS\system32\wuauclt1.exe
    2009-06-06 01:05:34 ----A---- C:\WINDOWS\system32\wuauclt.exe
    2009-06-06 01:05:34 ----A---- C:\WINDOWS\system32\wuapi.dll
    2009-06-06 01:05:34 ----A---- C:\WINDOWS\system32\bitsprx3.dll
    2009-06-06 01:05:34 ----A---- C:\WINDOWS\system32\bitsprx2.dll
    2009-06-06 01:05:33 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
    2009-06-06 01:05:33 ----A---- C:\WINDOWS\system32\qmgr.dll
    2009-06-06 01:05:28 ----D---- C:\Program Files\Movie Maker
    2009-06-06 01:05:24 ----A---- C:\WINDOWS\system32\safrslv.dll
    2009-06-06 01:05:24 ----A---- C:\WINDOWS\system32\safrdm.dll
    2009-06-06 01:05:24 ----A---- C:\WINDOWS\system32\safrcdlg.dll
    2009-06-06 01:05:24 ----A---- C:\WINDOWS\system32\racpldlg.dll
    2009-06-06 01:05:19 ----A---- C:\WINDOWS\system32\fltmc.exe
    2009-06-06 01:05:19 ----A---- C:\WINDOWS\system32\fltlib.dll
    2009-06-06 01:05:18 ----D---- C:\WINDOWS\system32\Restore
    2009-06-06 01:05:18 ----A---- C:\WINDOWS\system32\srsvc.dll
    2009-06-06 01:05:18 ----A---- C:\WINDOWS\system32\srrstr.dll
    2009-06-06 01:05:18 ----A---- C:\WINDOWS\system32\srclient.dll
    2009-06-06 01:05:17 ----A---- C:\WINDOWS\system32\nmmkcert.dll
    2009-06-06 01:05:17 ----A---- C:\WINDOWS\system32\mnmdd.dll
    2009-06-06 01:05:17 ----A---- C:\WINDOWS\system32\isrdbg32.dll
    2009-06-06 01:05:17 ----A---- C:\WINDOWS\system32\ils.dll
    2009-06-06 01:05:16 ----A---- C:\WINDOWS\system32\msconf.dll
    2009-06-06 01:05:16 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
    2009-06-06 01:05:13 ----D---- C:\Program Files\NetMeeting
    2009-06-06 01:05:13 ----A---- C:\WINDOWS\system32\msoert2.dll
    2009-06-06 01:05:13 ----A---- C:\WINDOWS\system32\msoeacct.dll
    2009-06-06 01:05:12 ----A---- C:\WINDOWS\system32\inetres.dll
    2009-06-06 01:05:12 ----A---- C:\WINDOWS\system32\inetcomm.dll
    2009-06-06 01:05:09 ----D---- C:\Program Files\Outlook Express
    2009-06-06 01:05:09 ----A---- C:\WINDOWS\system32\schedsvc.dll
    2009-06-06 01:05:09 ----A---- C:\WINDOWS\system32\mstinit.exe
    2009-06-06 01:05:09 ----A---- C:\WINDOWS\system32\mstask.dll
    2009-06-06 01:05:08 ----A---- C:\WINDOWS\system32\isign32.dll
    2009-06-06 01:05:08 ----A---- C:\WINDOWS\system32\inetcfg.dll
    2009-06-06 01:05:08 ----A---- C:\WINDOWS\system32\icwphbk.dll
    2009-06-06 01:05:08 ----A---- C:\WINDOWS\system32\icwdial.dll
    2009-06-06 01:05:02 ----D---- C:\Program Files\Fichiers communs\System
    2009-06-06 01:04:55 ----D---- C:\Program Files\Internet Explorer
    2009-06-06 01:04:16 ----D---- C:\Program Files\ComPlus Applications
    2009-06-06 01:04:14 ----A---- C:\WINDOWS\vbaddin.ini
    2009-06-06 01:04:14 ----A---- C:\WINDOWS\vb.ini
    2009-06-06 01:04:08 ----D---- C:\WINDOWS\Registration
    2009-06-06 01:03:59 ----D---- C:\Program Files\Windows Media Player
    2009-06-06 01:03:59 ----D---- C:\Program Files\Online Services
    2009-06-06 01:03:52 ----D---- C:\Program Files\Messenger
    2009-06-06 01:03:48 ----D---- C:\Program Files\MSN Gaming Zone
    2009-06-06 01:03:48 ----A---- C:\WINDOWS\system32\write.exe
    2009-06-06 01:03:38 ----A---- C:\WINDOWS\system32\sndvol32.exe
    2009-06-06 01:03:38 ----A---- C:\WINDOWS\system32\hticons.dll
    2009-06-06 01:03:38 ----A---- C:\WINDOWS\system32\avwav.dll
    2009-06-06 01:03:38 ----A---- C:\WINDOWS\system32\avtapi.dll
    2009-06-06 01:03:38 ----A---- C:\WINDOWS\system32\avmeter.dll
    2009-06-06 01:03:37 ----A---- C:\WINDOWS\system32\winchat.exe
    2009-06-06 01:03:31 ----A---- C:\WINDOWS\system32\getuname.dll
    2009-06-06 01:03:30 ----A---- C:\WINDOWS\system32\sol.exe
    2009-06-06 01:03:30 ----A---- C:\WINDOWS\system32\charmap.exe
    2009-06-06 01:03:30 ----A---- C:\WINDOWS\system32\calc.exe
    2009-06-06 01:03:29 ----A---- C:\WINDOWS\system32\winmine.exe
    2009-06-06 01:03:29 ----A---- C:\WINDOWS\system32\usrlogon.cmd
    2009-06-06 01:03:29 ----A---- C:\WINDOWS\system32\reset.exe
    2009-06-06 01:03:29 ----A---- C:\WINDOWS\system32\mshearts.exe
    2009-06-06 01:03:29 ----A---- C:\WINDOWS\system32\freecell.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\tsshutdn.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\tslabels.ini
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\tskill.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\tsdiscon.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\tscon.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\shadow.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\rwinsta.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\regini.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\qwinsta.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\qappsrv.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\msg.exe
    2009-06-06 01:03:28 ----A---- C:\WINDOWS\system32\logoff.exe
    2009-06-06 01:03:27 ----A---- C:\WINDOWS\system32\msdtcprf.ini
    2009-06-06 01:03:27 ----A---- C:\WINDOWS\system32\cdmodem.dll
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\stclient.dll
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\mtxlegih.dll
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\mtxex.dll
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\mtxdm.dll
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\comsnap.dll
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\comrepl.dll
    2009-06-06 01:03:26 ----A---- C:\WINDOWS\system32\comaddin.dll
    2009-06-06 01:03:20 ----A---- C:\WINDOWS\system32\wmimgmt.msc
    2009-06-06 01:03:02 ----D---- C:\Program Files\MSN
    2009-06-06 01:03:01 ----A---- C:\WINDOWS\system32\sndrec32.exe
    2009-06-06 01:03:01 ----A---- C:\WINDOWS\system32\mplay32.exe
    2009-06-06 01:03:01 ----A---- C:\WINDOWS\system32\accwiz.exe
    2009-06-06 01:03:00 ----D---- C:\Program Files\Windows NT
    2009-06-06 01:03:00 ----A---- C:\WINDOWS\system32\mspaint.exe
    2009-06-06 01:03:00 ----A---- C:\WINDOWS\system32\hypertrm.dll
    2009-06-06 01:03:00 ----A---- C:\WINDOWS\system32\clipbrd.exe
    2009-06-06 01:02:59 ----A---- C:\WINDOWS\system32\spider.exe
    2009-06-06 01:02:58 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
    2009-06-06 01:02:58 ----A---- C:\WINDOWS\system32\remotepg.dll
    2009-06-06 01:02:58 ----A---- C:\WINDOWS\system32\rdshost.exe
    2009-06-06 01:02:58 ----A---- C:\WINDOWS\system32\rdsaddin.exe
    2009-06-06 01:02:58 ----A---- C:\WINDOWS\system32\mstscax.dll
    2009-06-06 01:02:58 ----A---- C:\WINDOWS\system32\mstsc.exe
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\tscupgrd.exe
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\termsrv.dll
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\sessmgr.exe
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\rdpwsx.dll
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\rdpsnd.dll
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\rdpclip.exe
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\rdchost.dll
    2009-06-06 01:02:57 ----A---- C:\WINDOWS\system32\qprocess.exe
    2009-06-06 01:02:56 ----D---- C:\WINDOWS\system32\MsDtc
    2009-06-06 01:02:56 ----A---- C:\WINDOWS\system32\mtxoci.dll
    2009-06-06 01:02:56 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
    2009-06-06 01:02:56 ----A---- C:\WINDOWS\system32\icaapi.dll
    2009-06-06 01:02:56 ----A---- C:\WINDOWS\system32\cfgbkend.dll
    2009-06-06 01:02:55 ----A---- C:\WINDOWS\system32\xolehlp.dll
    2009-06-06 01:02:55 ----A---- C:\WINDOWS\system32\msdtctm.dll
    2009-06-06 01:02:55 ----A---- C:\WINDOWS\system32\msdtcprx.dll
    2009-06-06 01:02:55 ----A---- C:\WINDOWS\system32\msdtclog.dll
    2009-06-06 01:02:55 ----A---- C:\WINDOWS\system32\msdtc.exe
    2009-06-06 01:02:54 ----D---- C:\WINDOWS\system32\Com
    2009-06-06 01:02:54 ----A---- C:\WINDOWS\system32\colbact.dll
    2009-06-06 01:02:54 ----A---- C:\WINDOWS\system32\clbcatex.dll
    2009-06-06 01:02:54 ----A---- C:\WINDOWS\system32\catsrvps.dll
    2009-06-06 01:02:53 ----A---- C:\WINDOWS\system32\comsvcs.dll
    2009-06-06 01:02:53 ----A---- C:\WINDOWS\system32\catsrvut.dll
    2009-06-06 01:02:53 ----A---- C:\WINDOWS\system32\catsrv.dll
    2009-06-06 01:02:52 ----A---- C:\WINDOWS\system32\comuid.dll
    2009-06-06 01:02:52 ----A---- C:\WINDOWS\system32\clbcatq.dll
    2009-06-06 01:02:45 ----A---- C:\WINDOWS\system32\servdeps.dll
    2009-06-06 01:02:45 ----A---- C:\WINDOWS\system32\mmfutil.dll
    2009-06-06 01:02:45 ----A---- C:\WINDOWS\system32\licwmi.dll
    2009-06-06 01:02:44 ----A---- C:\WINDOWS\system32\cmprops.dll

    ======List of files/folders modified in the last 2 months======

    2009-06-08 22:14:05 ----A---- C:\WINDOWS\system32\uxtheme.dll
    2009-06-06 02:18:07 ----A---- C:\WINDOWS\system.ini
    2009-06-06 01:36:47 ----A---- C:\WINDOWS\win.ini

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
    R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
    R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-05-15 1977856]
    R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
    R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-15 4474368]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    R3 RT61;Ralink RT61 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2006-08-02 384384]
    R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
    S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
    R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-03-02 185089]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-05-15 438272]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-06-08 152984]
    R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 29178224]
    R2 SQLWriter;Enregistreur VSS SQL Server; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
    R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
    S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
    S4 msvsmon90;Visual Studio 2008 Remote Debugger; c:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2007-11-08 3004416]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]
    S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2007-02-10 242544]

    -----------------EOF-----------------
    0
  12. gen-hackman
     
    ---> Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.

    ---> Télécharge OTM (OldTimer) sur ton Bureau :

    ---> Double-clique sur OTM.exe afin de le lancer.

    ---> Copie (Ctrl+C) le texte suivant ci-dessous :



    :processes
    explorer.exe

    :services

    :files
    C:\WINDOWS\rootkitno.ini
    C:\RootkitNO
    C:\WINDOWS\system32\PARTIZAN.TXT
    C:\WINDOWS\winstart.bat
    C:\WINDOWS\SET*.tmp

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    ""=-
    "MsnMsgr"=-

    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]


    ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

    ---> Clique maintenant sur le bouton MoveIt! puis ferme OTM

    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.

    ---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log
    0
  13. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    ========== FILES ==========
    C:\WINDOWS\rootkitno.ini moved successfully.
    C:\RootkitNO moved successfully.
    C:\WINDOWS\system32\PARTIZAN.TXT moved successfully.
    C:\WINDOWS\winstart.bat moved successfully.
    C:\WINDOWS\SET3.tmp moved successfully.
    C:\WINDOWS\SET4.tmp moved successfully.
    C:\WINDOWS\SET8.tmp moved successfully.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\DjBenS\LOCALS~1\Temp\etilqs_01IKU4izFsvShlrJNYbH scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\DjBenS\LOCALS~1\Temp\etilqs_01IKU4izFsvShlrJNYbH-journal scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\DjBenS\LOCALS~1\Temp\etilqs_FxKRnulz5cpdSfhNVGqK scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\DjBenS\LOCALS~1\Temp\flaA6.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\DjBenS\LOCALS~1\Temp\flaA7.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\DjBenS\LOCALS~1\Temp\flaA8.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\DjBenS\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Internet Explorer cache folder emptied.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    User's Temporary Internet Files folder emptied.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_79c.dat scheduled to be deleted on reboot.
    Network Service Temp folder emptied.
    Network Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_788.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\OfflineCache\index.sqlite scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\02D54F36d01 scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\81B04E62d01 scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\C1C145D8d01 scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\XUL.mfl scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTM by OldTimer - Version 2.1.0.1 log created on 06102009_233911

    Files moved on Reboot...
    File C:\DOCUME~1\DjBenS\LOCALS~1\Temp\etilqs_01IKU4izFsvShlrJNYbH not found!
    File C:\DOCUME~1\DjBenS\LOCALS~1\Temp\etilqs_01IKU4izFsvShlrJNYbH-journal not found!
    File C:\DOCUME~1\DjBenS\LOCALS~1\Temp\etilqs_FxKRnulz5cpdSfhNVGqK not found!
    File C:\DOCUME~1\DjBenS\LOCALS~1\Temp\flaA6.tmp not found!
    File C:\DOCUME~1\DjBenS\LOCALS~1\Temp\flaA7.tmp not found!
    File C:\DOCUME~1\DjBenS\LOCALS~1\Temp\flaA8.tmp not found!
    C:\DOCUME~1\DjBenS\LOCALS~1\Temp\WCESLog.log moved successfully.
    File C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_79c.dat not found!
    File C:\WINDOWS\temp\Perflib_Perfdata_788.dat not found!
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\OfflineCache\index.sqlite moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\02D54F36d01 moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\81B04E62d01 moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\C1C145D8d01 moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_001_ moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_002_ moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_003_ moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\Cache\_CACHE_MAP_ moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\urlclassifier3.sqlite moved successfully.
    C:\Documents and Settings\DjBenS\Local Settings\Application Data\Mozilla\Firefox\Profiles\9n92iadb.default\XUL.mfl moved successfully.

    Registry entries deleted on Reboot...
    0
  14. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    Et .... ca marche tj pas :( écoute vraiment BIG THX !
    Si nn y a t-il pas moyen de faire fonctionné le Microsoft Visual studio 2008 sur Ubuntu ?
    Au moins je n aurais pas ce problème et j aurais accès a mes données !
    0
  15. gen-hackman
     
    desespere pas

    desinstalle ton vieil hijackthis et procede de la sorte :

    Télécharges et installes le logiciel de diagnostic :

    ici Hijackthis
    ou ici Hijackthis
    ou ici Hijackthis

    1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
    A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
    Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
    "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

    tuto pour utilisation :(merci balltrap34)
    Regardes ici, c'est parfaitement expliqué en images ,

    2- !! Déconnectes toi et fermes toute tes applications en cours !!

    Cliques sur le raccourci du bureau pour lancer le prg :

    S'il ne se lance pas clique ici

    fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

    --->copies-colles le rapport généré pour analyse
    0
  16. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 01:14:01, on 11/06/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\trend micro\HijackThis\MonJack.exe

    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    0
  17. gen-hackman
     
    ######## | XP _ Instal & recherche | #######

    Telecharge et install UsbFix (de C_XX & Chiquitine29)

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

    # Double clic sur le raccourci UsbFix présent sur ton bureau .

    # Choisi l option 1 ( Recherche )

    # Laisse travailler l outil.

    # Ensuite post le rapport UsbFix.txt qui apparaitra.

    # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    0
  18. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    J ai aucun périphérique externe aucun disque dure aucun usb !
    0
  19. hbenes Messages postés 37 Date d'inscription   Statut Membre Dernière intervention   2
     
    ############################## [ UsbFix V3.029 | Scan ]

    # User : DjBenS (Administrateurs) # BENS-1BC494609F
    # Update on 05/06/09 by Chiquitine29, C_XX & Chimay8
    # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
    # Start at: 01:23:01 | 11/06/2009

    # Genuine Intel(R) CPU T2080 @ 1.73GHz
    # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    # Internet Explorer 6.0.2900.5512
    # Windows Firewall Status : Enabled
    # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

    # C:\ # Disque fixe local # 29,29 Go (14,36 Go free) # NTFS
    # D:\ # Disque fixe local # 67,84 Go (15,35 Go free) # NTFS
    # E:\ # Disque CD-ROM

    ############################## [ Processus actifs ]

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    C:\Program Files\Winamp\Winamp.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## [ Registre Startup ]

    HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
    HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
    HKCU_Main: "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
    HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
    HKLM_logon: "DefaultUserName"="DjBenS"
    HKLM_logon: "AltDefaultUserName"="DjBenS"
    HKLM_logon: "LegalNoticeCaption"=""
    HKLM_logon: "LegalNoticeText"=""
    HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
    HKCU_Run: msnmsgr="C:\Program Files\MSN Messenger\msnmsgr.exe" /background

    ################## [ Fichiers # Dossiers infectieux ]

    ################## [ Registre # Clés Run infectieuses ]

    ################## [ Registre # Mountpoints2 ]

    ################## [ ! Fin du rapport # UsbFix V3.029 ! ]
    0
  20. gen-hackman
     
    Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

    Télécharges :

    Malwarebytes

    ou :

    Malwarebytes

    * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

    * Potasses le Tuto pour te familiariser avec le prg :

    ( cela dit, il est très simple d'utilisation ).

    relance malwarebytes en suivant scrupuleusement ces consignes :

    ! Déconnecte toi et ferme toutes applications en cours !

    * Lance Malwarebyte's .

    Fais un examen dit "Complet" .

    --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
    --> à la fin tu cliques sur "résultat" .
    --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

    0
  • 1
  • 2