Probleme win 32 cheval de troie
phil
-
Destrio5 Messages postés 99820 Date d'inscription Statut Modérateur Dernière intervention -
Destrio5 Messages postés 99820 Date d'inscription Statut Modérateur Dernière intervention -
Bonjour,
veuillez trouver ci-joijnt le log telecharger, pouvez vous m'aider a supprimer le ccheval de troie
Logfile of random's system information tool 1.06 (written by random/random)
Run by gladys at 2009-09-17 07:56:39
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 136 GB (89%) free of 153 GB
Total RAM: 894 MB (15% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:57:25, on 17/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Registry Winner\RegistryWinner.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\gladys\Local Settings\Temporary Internet Files\Content.IE5\KOD9BH4X\RSIT[1].exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\trend micro\gladys.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-2881553755-2800076197-2324534425-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrateur')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = philingerie.local
O17 - HKLM\Software\..\Telephony: DomainName = philingerie.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{94AC9E9A-193D-4B06-A314-5D1F39A524D1}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{A98A0FDE-830A-4844-9E56-199E272B076E}: NameServer = 192.168.11.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = philingerie.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = philingerie.local
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
--
End of file - 7649 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Maintenance en 1 clic.job
C:\WINDOWS\tasks\Registry Winner Schedule.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-06-08 976424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
myBabylon English Toolbar - C:\Program Files\myBabylon_English\tbmyB1.dll [2009-07-06 2215960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - myBabylon English Toolbar - C:\Program Files\myBabylon_English\tbmyB1.dll [2009-07-06 2215960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-07-01 1447168]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-09-16 520024]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2007-06-08 23233576]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2006-01-04 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-07-01 1447168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^gladys^Menu Démarrer^Programmes^Démarrage^ikowin32.exe]
C:\Documents and Settings\gladys\Menu Démarrer\Programmes\Démarrage\ikowin32.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"WinVNC4"=2
"TuneUp.ProgramStatisticsSvc"=2
"TuneUp.Defrag"=3
"SeaPort"=2
"ose"=3
"NVSvc"=2
"idsvc"=3
"fsssvc"=3
"ekrn"=2
"EhttpSrv"=3
"DWMRCS"=2
"Client32"=2
"ATI Smart"=2
"Ati HotKey Poller"=2
"aaadub2esyuyi"=2
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-09-09 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 240128]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\client32]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\NetSupport Manager\client32.exe"="C:\Program Files\NetSupport Manager\client32.exe:*:Enabled:NetSupport Client"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\NetSupport Manager\client32.exe"="C:\Program Files\NetSupport Manager\client32.exe:*:Enabled:NetSupport Client"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0babc9a0-191d-11dc-900d-00105a176973}]
shell\Auto\command - AdobeR.exe e
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{42302ff9-28ca-11dd-a78a-0019db5b8e75}]
shell\AutoRun\command - E:\m9j.com
shell\explore\command - E:\m9j.com
shell\open\command - E:\m9j.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70902047-3a16-11dc-a647-0019db5b8e75}]
shell\AutoRun\command - readme.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{908f5046-86f4-11dc-a6ac-0019db5b8e75}]
shell\AutoRun\command - droit.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4f37914-9378-11dc-a6be-0019db5b8e75}]
shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e9d1ef0b-3ed5-11dd-a7ad-0019db5b8e75}]
shell\Auto\command - AdobeR.exe e
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f090f83e-9dc1-11dc-a6d1-0019db5b8e75}]
shell\Auto\command - AdobeR.exe e
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9791395-0af7-11dd-a767-0019db5b8e75}]
shell\AutoRun\command - m9j.com
shell\explore\command - m9j.com
shell\open\command - m9j.com
======File associations======
.bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1"
.ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1"
======List of files/folders created in the last 1 months======
2009-09-17 07:56:59 ----HDC---- C:\WINDOWS\$NtUninstallKB943729$
2009-09-17 07:56:47 ----D---- C:\Program Files\trend micro
2009-09-17 07:56:39 ----D---- C:\rsit
2009-09-17 07:55:43 ----D---- C:\Documents and Settings\gladys\Application Data\Windows Search
2009-09-17 07:55:27 ----D---- C:\Documents and Settings\gladys\Application Data\Windows Desktop Search
2009-09-17 07:54:51 ----D---- C:\Program Files\Windows Desktop Search
2009-09-17 07:54:33 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2009-09-17 07:54:27 ----A---- C:\WINDOWS\imsins.BAK
2009-09-17 07:54:22 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2009-09-17 07:53:21 ----D---- C:\WINDOWS\LastGood
2009-09-17 07:53:01 ----D---- C:\1beedaa91baef6598bc7478c
2009-09-17 07:46:12 ----D---- C:\Program Files\Registry Winner
2009-09-16 18:07:24 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-09-16 09:14:25 ----HDC---- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-09-16 09:14:14 ----D---- C:\Program Files\Lavasoft
2009-09-16 09:14:14 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-09-16 09:12:04 ----A---- C:\WINDOWS\system32\TUProgSt.exe
2009-09-16 09:12:01 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2009-09-16 09:11:55 ----A---- C:\WINDOWS\system32\TuneUpDefragService.exe
2009-09-11 08:29:09 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-09-11 08:28:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-09-09 08:09:13 ----A---- C:\cleannavi.txt
2009-09-09 08:08:11 ----D---- C:\Program Files\Navilog1
2009-08-31 18:28:38 ----D---- C:\Documents and Settings\gladys\Application Data\ATI
2009-08-31 13:41:44 ----A---- C:\WINDOWS\Language_trs.ini
2009-08-31 11:52:44 ----D---- C:\Program Files\RALINK
2009-08-31 11:03:43 ----D---- C:\Intel
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Ikeyrfk8.dll
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Amsample.dll
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Amoures.dll
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Amhooker.dll
2009-08-31 10:49:12 ----D---- C:\ATI
2009-08-31 10:47:46 ----D---- C:\WINDOWS\OPTIONS
2009-08-31 10:45:21 ----D---- C:\WINDOWS\Drivers
2009-08-31 10:41:53 ----D---- C:\SWSetup
2009-08-31 10:36:06 ----D---- C:\Program Files\HP R837 SW
2009-08-31 09:38:47 ----D---- C:\Documents and Settings\All Users\Application Data\LogiShrd
2009-08-31 09:38:44 ----D---- C:\Documents and Settings\gladys\Application Data\Logitech
2009-08-31 09:38:33 ----A---- C:\WINDOWS\system32\msxml3a.dll
2009-08-31 09:37:42 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2009-08-31 09:37:09 ----D---- C:\6c3e8b87f5896be5e0e31a0456
2009-08-31 09:37:03 ----A---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
2009-08-31 09:37:03 ----A---- C:\WINDOWS\KHALMNPR.Exe
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\KemXML.dll
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\KemWnd.dll
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\KemUtil.dll
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\kemutb.dll
2009-08-31 09:36:47 ----D---- C:\Documents and Settings\All Users\Application Data\Logitech
2009-08-31 09:36:46 ----D---- C:\Program Files\Logitech
2009-08-31 09:36:46 ----D---- C:\Program Files\Fichiers communs\Logitech
2009-08-31 09:22:51 ----D---- C:\Program Files\A4Tech
2009-08-31 08:54:39 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2009-08-31 08:54:31 ----D---- C:\Program Files\PC Drivers HeadQuarters
2009-08-27 13:58:02 ----D---- C:\Documents and Settings\gladys\Application Data\Yahoo!
2009-08-27 13:58:00 ----D---- C:\Program Files\Yahoo!
2009-08-27 13:57:57 ----D---- C:\Program Files\CCleaner
2009-08-26 16:14:20 ----D---- C:\Program Files\WinPcap
2009-08-26 08:58:48 ----D---- C:\Documents and Settings\gladys\Application Data\TuneUp Software
2009-08-26 08:58:27 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2009-08-26 08:58:24 ----D---- C:\Program Files\TuneUp Utilities 2009
2009-08-26 08:58:04 ----SHD---- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-08-21 14:33:25 ----D---- C:\Documents and Settings\All Users\Application Data\19112964
2009-08-18 18:30:14 ----D---- C:\WINDOWS\system32\XPSViewer
2009-08-18 18:30:10 ----D---- C:\Program Files\MSBuild
2009-08-18 18:30:09 ----D---- C:\WINDOWS\system32\en-US
2009-08-18 18:30:03 ----D---- C:\Program Files\Reference Assemblies
2009-08-18 18:29:39 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-08-18 18:29:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-08-18 18:29:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-08-18 18:29:39 ----D---- C:\06861285f3d851f7ff3513dc25516d
2009-08-18 08:49:51 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-08-18 08:49:09 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-08-18 08:48:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
======List of files/folders modified in the last 1 months======
2009-09-17 07:57:22 ----D---- C:\WINDOWS\Temp
2009-09-17 07:57:14 ----D---- C:\WINDOWS
2009-09-17 07:57:04 ----D---- C:\WINDOWS\system32\wbem
2009-09-17 07:57:03 ----D---- C:\WINDOWS\system32
2009-09-17 07:56:53 ----HD---- C:\WINDOWS\inf
2009-09-17 07:56:47 ----RD---- C:\Program Files
2009-09-17 07:55:17 ----D---- C:\WINDOWS\Prefetch
2009-09-17 07:55:07 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-09-17 07:55:00 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-09-17 07:54:54 ----D---- C:\WINDOWS\system32\fr-fr
2009-09-17 07:54:24 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-09-17 07:53:19 ----D---- C:\WINDOWS\system32\CatRoot2
2009-09-17 07:52:49 ----SHD---- C:\WINDOWS\Installer
2009-09-17 07:52:48 ----RSD---- C:\WINDOWS\assembly
2009-09-17 07:46:18 ----SD---- C:\WINDOWS\Tasks
2009-09-17 07:42:30 ----D---- C:\WINDOWS\Debug
2009-09-17 07:36:41 ----D---- C:\WINDOWS\security
2009-09-16 18:29:25 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-09-16 09:18:22 ----D---- C:\WINDOWS\system32\drivers
2009-09-16 09:18:09 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-09-16 09:14:07 ----D---- C:\WINDOWS\WinSxS
2009-09-16 08:43:38 ----D---- C:\Documents and Settings\gladys\Application Data\Skype
2009-09-15 14:42:03 ----D---- C:\EXPINET
2009-09-11 08:35:57 ----D---- C:\Program Files\Fastmag Boutique
2009-09-11 08:28:29 ----HD---- C:\WINDOWS\$hf_mig$
2009-09-11 08:28:22 ----D---- C:\Program Files\Microsoft Silverlight
2009-09-11 08:28:08 ----D---- C:\WINDOWS\ie8updates
2009-09-03 09:39:11 ----D---- C:\WINDOWS\pss
2009-09-03 09:12:49 ----D---- C:\Documents and Settings\gladys\Application Data\Ante Bags
2009-09-03 08:51:56 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB927802$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB926255$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB923689$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB923414$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB917953$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB917734_WMP9$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB914440$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB911927$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB905749$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB904942$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB896428$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB888302$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2009-09-03 08:51:32 ----HD---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2009-09-03 08:51:32 ----HD---- C:\WINDOWS\$NtUninstallKB885222$
2009-09-03 08:51:32 ----HD---- C:\WINDOWS\$NtUninstallKB815304$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951376_0$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB942763$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB941693$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB941644$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB938464_0$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP9$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB936357$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB933360$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB931836$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB931261$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB930178$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB929969$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-09-02 08:58:36 ----D---- C:\WINDOWS\Microsoft.NET
2009-08-31 11:52:44 ----HD---- C:\Program Files\InstallShield Installation Information
2009-08-31 11:05:49 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-08-31 10:47:46 ----D---- C:\Program Files\Realtek
2009-08-31 10:43:18 ----D---- C:\Program Files\ATI Technologies
2009-08-31 09:36:46 ----D---- C:\Program Files\Fichiers communs
2009-08-28 19:50:11 ----A---- C:\WINDOWS\win.ini
2009-08-28 17:38:20 ----A---- C:\WINDOWS\system32\MRT.exe
2009-08-27 15:40:44 ----ASH---- C:\boot.ini
2009-08-27 15:40:44 ----A---- C:\WINDOWS\system.ini
2009-08-27 14:04:29 ----D---- C:\WINDOWS\Minidump
2009-08-27 09:54:12 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-08-27 09:45:07 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-27 09:44:39 ----D---- C:\Program Files\Mozilla Firefox
2009-08-20 18:12:48 ----D---- C:\Program Files\Windows Live Safety Center
2009-08-19 09:49:36 ----D---- C:\WINDOWS\system32\CatRoot
2009-08-18 18:30:08 ----RSD---- C:\WINDOWS\Fonts
2009-08-18 18:29:53 ----D---- C:\WINDOWS\system32\spool
2009-08-18 08:48:31 ----D---- C:\Program Files\Outlook Express
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-07-01 53256]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
R1 PCISys;PCISys; C:\WINDOWS\system32\drivers\PCISys.sys [2006-11-10 32824]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-08-31 21419]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-07-01 39944]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-15 34064]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service; C:\WINDOWS\System32\Drivers\ousbehci.sys [2005-09-29 45824]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-09-09 1754624]
R3 gdihook5;gdihook5; C:\WINDOWS\system32\DRIVERS\gdihook5.sys [2006-11-10 24634]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-08-01 4356608]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2007-04-11 20496]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-04-11 34832]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-04-11 36112]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2007-04-11 28688]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support; C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2005-09-29 56960]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2005-09-14 83968]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S1 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
S1 P3;Pilote processeur Intel Pentium III; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-13 46848]
S3 ac97intc;Service d'installation du pilote audio Intel(r) 82801 (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver; C:\WINDOWS\system32\DRIVERS\Amps2prt.sys [2004-08-25 9984]
S3 catchme;catchme; \??\C:\DOCUME~1\gladys\LOCALS~1\Temp\catchme.sys []
S3 E100B;Pilote de carte Intel (R) PRO; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-23 117760]
S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 i81x;i81x; C:\WINDOWS\system32\DRIVERS\i81xnt5.sys [2004-08-03 161020]
S3 iAimFP0;iAimFP0; C:\WINDOWS\system32\DRIVERS\wADV01nt.sys [2004-08-03 12415]
S3 iAimFP1;iAimFP1; C:\WINDOWS\system32\DRIVERS\wADV02NT.sys [2004-08-03 12127]
S3 iAimFP2;iAimFP2; C:\WINDOWS\system32\DRIVERS\wADV05NT.sys [2004-08-03 11775]
S3 iAimFP3;iAimFP3; C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys [2004-08-03 12063]
S3 iAimFP4;iAimFP4; C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys [2004-08-03 19455]
S3 iAimFP5;iAimFP5; C:\WINDOWS\system32\DRIVERS\wADV07nt.sys [2004-08-03 11807]
S3 iAimFP6;iAimFP6; C:\WINDOWS\system32\DRIVERS\wADV08nt.sys [2004-08-03 11295]
S3 iAimFP7;iAimFP7; C:\WINDOWS\system32\DRIVERS\wADV09nt.sys [2004-08-03 11871]
S3 iAimTV0;iAimTV0; C:\WINDOWS\system32\DRIVERS\wATV01nt.sys [2004-08-03 29311]
S3 iAimTV1;iAimTV1; C:\WINDOWS\system32\DRIVERS\wATV02NT.sys [2004-08-03 19551]
S3 iAimTV3;iAimTV3; C:\WINDOWS\system32\DRIVERS\wATV04nt.sys [2004-08-03 33599]
S3 iAimTV4;iAimTV4; C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys [2004-08-03 23615]
S3 iAimTV5;iAimTV5; C:\WINDOWS\system32\DRIVERS\wATV10nt.sys [2004-08-03 25471]
S3 iAimTV6;iAimTV6; C:\WINDOWS\system32\DRIVERS\wATV06nt.sys [2004-08-03 22271]
S3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2007-04-11 63248]
S3 LMouKE;SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2007-04-11 79376]
S3 RT2500;RT2500 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2500.sys [2004-09-09 212096]
S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 slabbus;CP210x USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\slabbus.sys [2007-03-01 58368]
S3 slabser;CP210x USB to UART Bridge Controller Drivers; C:\WINDOWS\system32\DRIVERS\slabser.sys [2007-03-01 75776]
S3 SONYPVU1;Pilote de filtrage Sony USB (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 win32x;win32x; \??\C:\WINDOWS\system32\drivers\win32x.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 adpu320;adpu320; C:\WINDOWS\system32\DRIVERS\adpu320.sys [2002-05-08 105472]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 Symmpi;Symmpi; C:\WINDOWS\system32\DRIVERS\symmpi.sys [2002-04-04 28416]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-09-09 425984]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-09-16 1029456]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-09-16 604488]
R2 UxTuneUp;TuneUp Extension de thème; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-07-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-09-16 361288]
S4 aaadub2esyuyi;Print Spooler Service; C:\WINDOWS\system32\edydsyu.exe /service []
S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-01-04 520192]
S4 Client32;Client32; C:\PROGRA~1\NETSUP~1\client32.exe [2006-11-10 24640]
S4 DWMRCS;DameWare Mini Remote Control; C:\WINDOWS\SYSTEM32\DWRCS.EXE [2007-02-02 208384]
S4 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WinVNC4;VNC Server Version 4; C:\Program Files\FastMag boutique\vnc4\winvnc4.exe [2004-06-15 380928]
S4 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
-----------------EOF-----------------
veuillez trouver ci-joijnt le log telecharger, pouvez vous m'aider a supprimer le ccheval de troie
Logfile of random's system information tool 1.06 (written by random/random)
Run by gladys at 2009-09-17 07:56:39
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 136 GB (89%) free of 153 GB
Total RAM: 894 MB (15% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:57:25, on 17/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Registry Winner\RegistryWinner.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\gladys\Local Settings\Temporary Internet Files\Content.IE5\KOD9BH4X\RSIT[1].exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\trend micro\gladys.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyB1.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-2881553755-2800076197-2324534425-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrateur')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = philingerie.local
O17 - HKLM\Software\..\Telephony: DomainName = philingerie.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{94AC9E9A-193D-4B06-A314-5D1F39A524D1}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{A98A0FDE-830A-4844-9E56-199E272B076E}: NameServer = 192.168.11.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = philingerie.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = philingerie.local
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
--
End of file - 7649 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Maintenance en 1 clic.job
C:\WINDOWS\tasks\Registry Winner Schedule.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-06-08 976424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
myBabylon English Toolbar - C:\Program Files\myBabylon_English\tbmyB1.dll [2009-07-06 2215960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - myBabylon English Toolbar - C:\Program Files\myBabylon_English\tbmyB1.dll [2009-07-06 2215960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-07-01 1447168]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-09-16 520024]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2007-06-08 23233576]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2006-01-04 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-07-01 1447168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^gladys^Menu Démarrer^Programmes^Démarrage^ikowin32.exe]
C:\Documents and Settings\gladys\Menu Démarrer\Programmes\Démarrage\ikowin32.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"WinVNC4"=2
"TuneUp.ProgramStatisticsSvc"=2
"TuneUp.Defrag"=3
"SeaPort"=2
"ose"=3
"NVSvc"=2
"idsvc"=3
"fsssvc"=3
"ekrn"=2
"EhttpSrv"=3
"DWMRCS"=2
"Client32"=2
"ATI Smart"=2
"Ati HotKey Poller"=2
"aaadub2esyuyi"=2
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-09-09 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 240128]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\client32]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\NetSupport Manager\client32.exe"="C:\Program Files\NetSupport Manager\client32.exe:*:Enabled:NetSupport Client"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\NetSupport Manager\client32.exe"="C:\Program Files\NetSupport Manager\client32.exe:*:Enabled:NetSupport Client"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0babc9a0-191d-11dc-900d-00105a176973}]
shell\Auto\command - AdobeR.exe e
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{42302ff9-28ca-11dd-a78a-0019db5b8e75}]
shell\AutoRun\command - E:\m9j.com
shell\explore\command - E:\m9j.com
shell\open\command - E:\m9j.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70902047-3a16-11dc-a647-0019db5b8e75}]
shell\AutoRun\command - readme.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{908f5046-86f4-11dc-a6ac-0019db5b8e75}]
shell\AutoRun\command - droit.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4f37914-9378-11dc-a6be-0019db5b8e75}]
shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e9d1ef0b-3ed5-11dd-a7ad-0019db5b8e75}]
shell\Auto\command - AdobeR.exe e
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f090f83e-9dc1-11dc-a6d1-0019db5b8e75}]
shell\Auto\command - AdobeR.exe e
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9791395-0af7-11dd-a767-0019db5b8e75}]
shell\AutoRun\command - m9j.com
shell\explore\command - m9j.com
shell\open\command - m9j.com
======File associations======
.bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1"
.ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1"
======List of files/folders created in the last 1 months======
2009-09-17 07:56:59 ----HDC---- C:\WINDOWS\$NtUninstallKB943729$
2009-09-17 07:56:47 ----D---- C:\Program Files\trend micro
2009-09-17 07:56:39 ----D---- C:\rsit
2009-09-17 07:55:43 ----D---- C:\Documents and Settings\gladys\Application Data\Windows Search
2009-09-17 07:55:27 ----D---- C:\Documents and Settings\gladys\Application Data\Windows Desktop Search
2009-09-17 07:54:51 ----D---- C:\Program Files\Windows Desktop Search
2009-09-17 07:54:33 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2009-09-17 07:54:27 ----A---- C:\WINDOWS\imsins.BAK
2009-09-17 07:54:22 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2009-09-17 07:53:21 ----D---- C:\WINDOWS\LastGood
2009-09-17 07:53:01 ----D---- C:\1beedaa91baef6598bc7478c
2009-09-17 07:46:12 ----D---- C:\Program Files\Registry Winner
2009-09-16 18:07:24 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-09-16 09:14:25 ----HDC---- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-09-16 09:14:14 ----D---- C:\Program Files\Lavasoft
2009-09-16 09:14:14 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-09-16 09:12:04 ----A---- C:\WINDOWS\system32\TUProgSt.exe
2009-09-16 09:12:01 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2009-09-16 09:11:55 ----A---- C:\WINDOWS\system32\TuneUpDefragService.exe
2009-09-11 08:29:09 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-09-11 08:28:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-09-09 08:09:13 ----A---- C:\cleannavi.txt
2009-09-09 08:08:11 ----D---- C:\Program Files\Navilog1
2009-08-31 18:28:38 ----D---- C:\Documents and Settings\gladys\Application Data\ATI
2009-08-31 13:41:44 ----A---- C:\WINDOWS\Language_trs.ini
2009-08-31 11:52:44 ----D---- C:\Program Files\RALINK
2009-08-31 11:03:43 ----D---- C:\Intel
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Ikeyrfk8.dll
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Amsample.dll
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Amoures.dll
2009-08-31 10:51:39 ----A---- C:\WINDOWS\system32\Amhooker.dll
2009-08-31 10:49:12 ----D---- C:\ATI
2009-08-31 10:47:46 ----D---- C:\WINDOWS\OPTIONS
2009-08-31 10:45:21 ----D---- C:\WINDOWS\Drivers
2009-08-31 10:41:53 ----D---- C:\SWSetup
2009-08-31 10:36:06 ----D---- C:\Program Files\HP R837 SW
2009-08-31 09:38:47 ----D---- C:\Documents and Settings\All Users\Application Data\LogiShrd
2009-08-31 09:38:44 ----D---- C:\Documents and Settings\gladys\Application Data\Logitech
2009-08-31 09:38:33 ----A---- C:\WINDOWS\system32\msxml3a.dll
2009-08-31 09:37:42 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2009-08-31 09:37:09 ----D---- C:\6c3e8b87f5896be5e0e31a0456
2009-08-31 09:37:03 ----A---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
2009-08-31 09:37:03 ----A---- C:\WINDOWS\KHALMNPR.Exe
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\KemXML.dll
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\KemWnd.dll
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\KemUtil.dll
2009-08-31 09:36:54 ----A---- C:\WINDOWS\system32\kemutb.dll
2009-08-31 09:36:47 ----D---- C:\Documents and Settings\All Users\Application Data\Logitech
2009-08-31 09:36:46 ----D---- C:\Program Files\Logitech
2009-08-31 09:36:46 ----D---- C:\Program Files\Fichiers communs\Logitech
2009-08-31 09:22:51 ----D---- C:\Program Files\A4Tech
2009-08-31 08:54:39 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2009-08-31 08:54:31 ----D---- C:\Program Files\PC Drivers HeadQuarters
2009-08-27 13:58:02 ----D---- C:\Documents and Settings\gladys\Application Data\Yahoo!
2009-08-27 13:58:00 ----D---- C:\Program Files\Yahoo!
2009-08-27 13:57:57 ----D---- C:\Program Files\CCleaner
2009-08-26 16:14:20 ----D---- C:\Program Files\WinPcap
2009-08-26 08:58:48 ----D---- C:\Documents and Settings\gladys\Application Data\TuneUp Software
2009-08-26 08:58:27 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2009-08-26 08:58:24 ----D---- C:\Program Files\TuneUp Utilities 2009
2009-08-26 08:58:04 ----SHD---- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-08-21 14:33:25 ----D---- C:\Documents and Settings\All Users\Application Data\19112964
2009-08-18 18:30:14 ----D---- C:\WINDOWS\system32\XPSViewer
2009-08-18 18:30:10 ----D---- C:\Program Files\MSBuild
2009-08-18 18:30:09 ----D---- C:\WINDOWS\system32\en-US
2009-08-18 18:30:03 ----D---- C:\Program Files\Reference Assemblies
2009-08-18 18:29:39 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-08-18 18:29:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-08-18 18:29:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-08-18 18:29:39 ----D---- C:\06861285f3d851f7ff3513dc25516d
2009-08-18 08:49:51 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-08-18 08:49:09 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-08-18 08:48:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
======List of files/folders modified in the last 1 months======
2009-09-17 07:57:22 ----D---- C:\WINDOWS\Temp
2009-09-17 07:57:14 ----D---- C:\WINDOWS
2009-09-17 07:57:04 ----D---- C:\WINDOWS\system32\wbem
2009-09-17 07:57:03 ----D---- C:\WINDOWS\system32
2009-09-17 07:56:53 ----HD---- C:\WINDOWS\inf
2009-09-17 07:56:47 ----RD---- C:\Program Files
2009-09-17 07:55:17 ----D---- C:\WINDOWS\Prefetch
2009-09-17 07:55:07 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-09-17 07:55:00 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-09-17 07:54:54 ----D---- C:\WINDOWS\system32\fr-fr
2009-09-17 07:54:24 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-09-17 07:53:19 ----D---- C:\WINDOWS\system32\CatRoot2
2009-09-17 07:52:49 ----SHD---- C:\WINDOWS\Installer
2009-09-17 07:52:48 ----RSD---- C:\WINDOWS\assembly
2009-09-17 07:46:18 ----SD---- C:\WINDOWS\Tasks
2009-09-17 07:42:30 ----D---- C:\WINDOWS\Debug
2009-09-17 07:36:41 ----D---- C:\WINDOWS\security
2009-09-16 18:29:25 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-09-16 09:18:22 ----D---- C:\WINDOWS\system32\drivers
2009-09-16 09:18:09 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-09-16 09:14:07 ----D---- C:\WINDOWS\WinSxS
2009-09-16 08:43:38 ----D---- C:\Documents and Settings\gladys\Application Data\Skype
2009-09-15 14:42:03 ----D---- C:\EXPINET
2009-09-11 08:35:57 ----D---- C:\Program Files\Fastmag Boutique
2009-09-11 08:28:29 ----HD---- C:\WINDOWS\$hf_mig$
2009-09-11 08:28:22 ----D---- C:\Program Files\Microsoft Silverlight
2009-09-11 08:28:08 ----D---- C:\WINDOWS\ie8updates
2009-09-03 09:39:11 ----D---- C:\WINDOWS\pss
2009-09-03 09:12:49 ----D---- C:\Documents and Settings\gladys\Application Data\Ante Bags
2009-09-03 08:51:56 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB927802$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB926255$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB923689$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB923414$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB917953$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB917734_WMP9$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB914440$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB911927$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB905749$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB904942$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB896428$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB888302$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2009-09-03 08:51:32 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2009-09-03 08:51:32 ----HD---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2009-09-03 08:51:32 ----HD---- C:\WINDOWS\$NtUninstallKB885222$
2009-09-03 08:51:32 ----HD---- C:\WINDOWS\$NtUninstallKB815304$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951376_0$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB942763$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB941693$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB941644$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB938464_0$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP9$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB936357$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB933360$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB931836$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB931261$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB930178$
2009-09-03 08:51:31 ----HDC---- C:\WINDOWS\$NtUninstallKB929969$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-09-03 08:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-09-02 08:58:36 ----D---- C:\WINDOWS\Microsoft.NET
2009-08-31 11:52:44 ----HD---- C:\Program Files\InstallShield Installation Information
2009-08-31 11:05:49 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-08-31 10:47:46 ----D---- C:\Program Files\Realtek
2009-08-31 10:43:18 ----D---- C:\Program Files\ATI Technologies
2009-08-31 09:36:46 ----D---- C:\Program Files\Fichiers communs
2009-08-28 19:50:11 ----A---- C:\WINDOWS\win.ini
2009-08-28 17:38:20 ----A---- C:\WINDOWS\system32\MRT.exe
2009-08-27 15:40:44 ----ASH---- C:\boot.ini
2009-08-27 15:40:44 ----A---- C:\WINDOWS\system.ini
2009-08-27 14:04:29 ----D---- C:\WINDOWS\Minidump
2009-08-27 09:54:12 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-08-27 09:45:07 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-27 09:44:39 ----D---- C:\Program Files\Mozilla Firefox
2009-08-20 18:12:48 ----D---- C:\Program Files\Windows Live Safety Center
2009-08-19 09:49:36 ----D---- C:\WINDOWS\system32\CatRoot
2009-08-18 18:30:08 ----RSD---- C:\WINDOWS\Fonts
2009-08-18 18:29:53 ----D---- C:\WINDOWS\system32\spool
2009-08-18 08:48:31 ----D---- C:\Program Files\Outlook Express
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-07-01 53256]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
R1 PCISys;PCISys; C:\WINDOWS\system32\drivers\PCISys.sys [2006-11-10 32824]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-08-31 21419]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-07-01 39944]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-15 34064]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service; C:\WINDOWS\System32\Drivers\ousbehci.sys [2005-09-29 45824]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-09-09 1754624]
R3 gdihook5;gdihook5; C:\WINDOWS\system32\DRIVERS\gdihook5.sys [2006-11-10 24634]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-08-01 4356608]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2007-04-11 20496]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-04-11 34832]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-04-11 36112]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2007-04-11 28688]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support; C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2005-09-29 56960]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2005-09-14 83968]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S1 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
S1 P3;Pilote processeur Intel Pentium III; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-13 46848]
S3 ac97intc;Service d'installation du pilote audio Intel(r) 82801 (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver; C:\WINDOWS\system32\DRIVERS\Amps2prt.sys [2004-08-25 9984]
S3 catchme;catchme; \??\C:\DOCUME~1\gladys\LOCALS~1\Temp\catchme.sys []
S3 E100B;Pilote de carte Intel (R) PRO; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-23 117760]
S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 i81x;i81x; C:\WINDOWS\system32\DRIVERS\i81xnt5.sys [2004-08-03 161020]
S3 iAimFP0;iAimFP0; C:\WINDOWS\system32\DRIVERS\wADV01nt.sys [2004-08-03 12415]
S3 iAimFP1;iAimFP1; C:\WINDOWS\system32\DRIVERS\wADV02NT.sys [2004-08-03 12127]
S3 iAimFP2;iAimFP2; C:\WINDOWS\system32\DRIVERS\wADV05NT.sys [2004-08-03 11775]
S3 iAimFP3;iAimFP3; C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys [2004-08-03 12063]
S3 iAimFP4;iAimFP4; C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys [2004-08-03 19455]
S3 iAimFP5;iAimFP5; C:\WINDOWS\system32\DRIVERS\wADV07nt.sys [2004-08-03 11807]
S3 iAimFP6;iAimFP6; C:\WINDOWS\system32\DRIVERS\wADV08nt.sys [2004-08-03 11295]
S3 iAimFP7;iAimFP7; C:\WINDOWS\system32\DRIVERS\wADV09nt.sys [2004-08-03 11871]
S3 iAimTV0;iAimTV0; C:\WINDOWS\system32\DRIVERS\wATV01nt.sys [2004-08-03 29311]
S3 iAimTV1;iAimTV1; C:\WINDOWS\system32\DRIVERS\wATV02NT.sys [2004-08-03 19551]
S3 iAimTV3;iAimTV3; C:\WINDOWS\system32\DRIVERS\wATV04nt.sys [2004-08-03 33599]
S3 iAimTV4;iAimTV4; C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys [2004-08-03 23615]
S3 iAimTV5;iAimTV5; C:\WINDOWS\system32\DRIVERS\wATV10nt.sys [2004-08-03 25471]
S3 iAimTV6;iAimTV6; C:\WINDOWS\system32\DRIVERS\wATV06nt.sys [2004-08-03 22271]
S3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2007-04-11 63248]
S3 LMouKE;SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2007-04-11 79376]
S3 RT2500;RT2500 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2500.sys [2004-09-09 212096]
S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 slabbus;CP210x USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\slabbus.sys [2007-03-01 58368]
S3 slabser;CP210x USB to UART Bridge Controller Drivers; C:\WINDOWS\system32\DRIVERS\slabser.sys [2007-03-01 75776]
S3 SONYPVU1;Pilote de filtrage Sony USB (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 win32x;win32x; \??\C:\WINDOWS\system32\drivers\win32x.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 adpu320;adpu320; C:\WINDOWS\system32\DRIVERS\adpu320.sys [2002-05-08 105472]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 Symmpi;Symmpi; C:\WINDOWS\system32\DRIVERS\symmpi.sys [2002-04-04 28416]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-09-09 425984]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-09-16 1029456]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-09-16 604488]
R2 UxTuneUp;TuneUp Extension de thème; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-07-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-09-16 361288]
S4 aaadub2esyuyi;Print Spooler Service; C:\WINDOWS\system32\edydsyu.exe /service []
S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-01-04 520192]
S4 Client32;Client32; C:\PROGRA~1\NETSUP~1\client32.exe [2006-11-10 24640]
S4 DWMRCS;DameWare Mini Remote Control; C:\WINDOWS\SYSTEM32\DWRCS.EXE [2007-02-02 208384]
S4 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WinVNC4;VNC Server Version 4; C:\Program Files\FastMag boutique\vnc4\winvnc4.exe [2004-06-15 380928]
S4 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
-----------------EOF-----------------
Configuration: Windows XP Internet Explorer 7.0
A voir également:
- Probleme win 32 cheval de troie
- Cle win 8.1 - Guide
- Power iso 32 bit - Télécharger - Gravure
- 32 bits - Guide
- Win rar - Télécharger - Compression & Décompression
- Win zip - Télécharger - Compression & Décompression
1 réponse
Bonjour,
--> Télécharge UsbFix (de Chiquitine29 & C_XX) sur ton Bureau.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur le programme UsbFix situé sur ton Bureau.
(Sous Vista, il faut cliquer droit sur UsbFix et choisir Exécuter en tant qu'administrateur)
--> Choisis l'option 1 (Recherche).
--> Laisse travailler l'outil.
--> Poste le rapport UsbFix.txt.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
--> Télécharge UsbFix (de Chiquitine29 & C_XX) sur ton Bureau.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur le programme UsbFix situé sur ton Bureau.
(Sous Vista, il faut cliquer droit sur UsbFix et choisir Exécuter en tant qu'administrateur)
--> Choisis l'option 1 (Recherche).
--> Laisse travailler l'outil.
--> Poste le rapport UsbFix.txt.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.