Infection Toj. Generic.DIT

Résolu
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   -  
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour,

Pourriez-vous m'aider SVP

Mes logiciels de sécurité ne cessent de détecter des TRACKING COOKIES lors des analyses quotidiennes... Je ne sais pas s'il y a un virus ou quoi mais mon ordi est très lent et il bogue souvent. Quelqu'un pourrait-il m'aider à vérifier tout ca et à me débarrasser de ces cookies une fois pour toutes (pcq je les supprimes, mais ils reviennent sans arrêt).

Merci beaucoup de votre aide!!!

Je poste les rapports...

Logfile of random's system information tool 1.06 (written by random/random)
Run by HP_Administrator at 2009-10-13 12:14:32
Microsoft Windows XP Professional Service Pack 3
System drive C: has 161 GB (88%) free of 183 GB
Total RAM: 503 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:01, on 2009-10-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\HP_Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\HP_Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.gamenext.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: SVIEBHO Class - {B3C54716-9D0A-4666-A81A-6072A6325A5A} - C:\Program Files\SelectView\svie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: SelectView - {16D60F96-2FF6-40b2-96D3-C32170E45A01} - C:\Program Files\SelectView\svie.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} (ActiveReceiver Control) - http://www.meetstream.com/activex/28014/activereceiver.cab
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - (no file)
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 14950 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Connexion facile à Internet.job
C:\WINDOWS\tasks\Norton Security Scan for HP_Administrator.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{14A18F9C-8275-4067-B3CB-617437F4508B}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-11-22 399352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\ctbr.dll [2009-06-26 1215488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
Click-to-Call BHO - C:\Program Files\Windows Live\Messenger\wlchtc.dll [2009-02-06 73072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9AA2F14F-E956-44B8-8694-A5B615CDF341}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar4.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll [2008-08-11 734704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3C54716-9D0A-4666-A81A-6072A6325A5A}]
SVIEBHO Class - C:\Program Files\SelectView\svie.dll [2007-06-06 720896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-07 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e0007d18-baa4-4573-ae78-8bea0958c610}]
P2P Max DE Toolbar - C:\Program Files\P2P_Max_DE\tbP2P1.dll [2009-08-23 2215960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-07 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-11-22 399352]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{e0007d18-baa4-4573-ae78-8bea0958c610} - P2P Max DE Toolbar - C:\Program Files\P2P_Max_DE\tbP2P1.dll [2009-08-23 2215960]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Barre d'outils &Crawler - C:\PROGRA~1\Crawler\ctbr.dll [2009-06-26 1215488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2004-08-10 59392]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-08 61952]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-06-08 77824]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2005-06-08 114688]
"HPBootOp"=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2005-02-26 245760]
"LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2005-05-10 253952]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPwuSchd2.exe [2005-05-12 49152]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2006-09-11 218032]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-11 86960]
"PS2"=C:\WINDOWS\system32\ps2.exe [2004-10-25 90112]
"Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2008-04-13 143360]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2008-09-07 1783808]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-10-01 111936]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
""= []
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-08-16 236016]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe [2007-03-16 63712]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-07 149280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-11 68856]
"MessengerPlus3"=C:\Program Files\MessengerPlus! 3\MsgPlus.exe [2008-09-01 190024]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-09-11 218032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
C:\Program Files\Picasa2\PicasaMediaDetector.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
C:\DOCUME~1\DAPHNE~1\Desktop\Photo\LimeWire\LimeWire.exe []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
Desktop Manager.lnk - C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe
Outil de notification Live Search.lnk - C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-06-08 131072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"C:\WINDOWS\system32\ntvdm.exe"="C:\WINDOWS\system32\ntvdm.exe:*:Enabled:NTVDM.EXE"
"C:\Documents and Settings\DA PH N EE\Desktop\Photo\LimeWire\LimeWire.exe"="C:\Documents and Settings\DA PH N EE\Desktop\Photo\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Documents and Settings\DA PH N EE\Local Settings\Temp\ImInstaller\incredimail_installer.exe"="C:\Documents and Settings\DA PH N EE\Local Settings\Temp\ImInstaller\incredimail_installer.exe:*:Enabled:IncrediMail Installer"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\1215660015\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1215660015\EE\AOLServiceHost.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\1165105190\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1165105190\EE\AOLServiceHost.exe:*:Disabled:AOL"
"C:\Program Files\AOL 9.0a\waol.exe"="C:\Program Files\AOL 9.0a\waol.exe:*:Disabled:AOL"
"C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Disabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Disabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Disabled:AOLTsMon"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\iTunes\iTunes.exe"="%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

======List of files/folders created in the last 3 months======

2009-10-12 16:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\java.exe
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-10-02 16:13:19 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
2009-10-02 16:13:10 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-02 16:13:10 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-10-02 15:39:26 ----D---- C:\rsit
2009-09-30 22:17:06 ----D---- C:\Program Files\PhotoScape
2009-09-30 17:41:51 ----D---- C:\Program Files\Common Files\Adobe
2009-09-11 18:20:01 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-09-09 16:20:01 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-09-09 16:19:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-09-09 16:14:40 ----HDC---- C:\WINDOWS\$NtUninstallKB973768$
2009-09-08 23:40:22 ----D---- C:\Program Files\Photosynth
2009-09-08 23:07:26 ----D---- C:\Documents and Settings\All Users\Application Data\Team MediaPortal
2009-09-08 23:06:14 ----D---- C:\Program Files\Team MediaPortal
2009-09-08 22:55:54 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2009-09-08 22:55:54 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2009-09-08 22:55:53 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2009-09-08 22:55:52 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2009-09-08 22:55:52 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2009-09-08 22:55:51 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2009-09-08 22:55:50 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2009-09-08 22:55:50 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2009-09-08 22:55:49 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2009-09-08 22:55:49 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2009-09-08 22:55:48 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2009-09-08 22:55:48 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2009-09-08 22:55:47 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2009-09-08 22:55:43 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2009-09-08 22:55:42 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2009-09-08 22:55:42 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2009-09-08 22:55:41 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2009-09-08 22:55:41 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2009-09-08 22:55:41 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2009-09-08 22:55:40 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2009-09-08 22:55:38 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2009-09-08 22:55:38 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2009-09-08 22:55:36 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2009-09-08 22:55:34 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2009-09-08 22:55:33 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2009-09-08 22:55:33 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2009-09-08 22:55:31 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2009-09-08 22:55:30 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2009-09-08 22:55:30 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2009-09-08 22:55:29 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2009-09-08 22:55:29 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2009-09-08 22:55:26 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2009-09-08 22:55:25 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2009-09-08 22:55:23 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2009-09-08 22:55:22 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2009-09-08 22:55:22 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2009-09-08 22:55:17 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2009-09-08 22:55:16 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2009-09-08 22:55:16 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2009-09-08 22:55:12 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2009-09-08 22:55:12 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2009-09-08 22:55:10 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2009-09-08 22:55:07 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2009-09-08 22:55:06 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2009-09-08 22:55:05 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2009-09-08 22:55:04 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-09-08 22:54:56 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2009-09-08 22:54:23 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-09-08 22:54:22 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2009-09-08 22:54:22 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2009-09-08 22:54:19 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-09-08 22:54:16 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-09-08 22:54:14 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-09-08 22:54:14 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-09-08 22:54:13 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-09-08 22:54:12 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-09-08 22:54:03 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-09-08 22:52:51 ----D---- C:\WINDOWS\Logs
2009-09-08 21:36:56 ----D---- C:\Program Files\Bonjour
2009-09-07 01:45:08 ----D---- C:\Program Files\Norton Security Scan
2009-09-07 01:45:08 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
2009-09-07 01:45:01 ----D---- C:\Program Files\NortonInstaller
2009-09-07 01:45:01 ----D---- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2009-09-06 22:40:24 ----D---- C:\WINDOWS\system32\Adobe
2009-09-05 16:40:39 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-09-05 16:39:41 ----D---- C:\Documents and Settings\All Users\Application Data\Oberon Media
2009-09-05 16:32:38 ----D---- C:\Program Files\Oberon Media
2009-09-05 16:32:38 ----D---- C:\Program Files\Gamenext
2009-09-05 16:32:38 ----D---- C:\Program Files\Common Files\Oberon Media
2009-08-27 16:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
2009-08-20 16:01:47 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2009-08-19 02:16:18 ----D---- C:\Program Files\Microsoft Silverlight
2009-08-19 02:15:08 ----D---- C:\Program Files\Microsoft Sync Framework
2009-08-19 02:13:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954708$
2009-08-19 02:11:06 ----D---- C:\Program Files\Windows Live SkyDrive
2009-08-19 01:35:46 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Roxio
2009-08-19 01:27:35 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Research In Motion
2009-08-19 01:27:06 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\InstallShield
2009-08-19 01:13:55 ----D---- C:\Documents and Settings\All Users\Application Data\Roxio
2009-08-19 01:13:48 ----D---- C:\Program Files\Roxio
2009-08-19 01:13:35 ----D---- C:\Program Files\Common Files\Roxio Shared
2009-08-19 01:01:37 ----D---- C:\Program Files\Common Files\Research In Motion
2009-08-19 01:01:10 ----D---- C:\Program Files\Research In Motion
2009-08-15 13:07:58 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-08-15 12:31:53 ----D---- C:\Program Files\Avira
2009-08-15 12:31:53 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-08-14 16:08:33 ----D---- C:\WINDOWS\system32\XPSViewer
2009-08-14 16:08:27 ----D---- C:\Program Files\MSBuild
2009-08-14 16:08:15 ----D---- C:\Program Files\Reference Assemblies
2009-08-14 16:07:19 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-08-14 16:07:18 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-08-14 16:07:18 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-08-14 16:07:18 ----D---- C:\9a75388fceff2697814682
2009-08-13 18:21:29 ----D---- C:\WINDOWS\ie8updates
2009-08-13 18:18:16 ----HDC---- C:\WINDOWS\ie8
2009-08-13 13:42:02 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-08-13 13:41:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-08-13 13:41:48 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-08-13 13:41:41 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2009-08-13 13:41:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-08-13 13:41:24 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-08-13 13:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-08-13 13:41:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2009-08-13 13:38:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-08-05 15:21:54 ----D---- C:\Program Files\Crawler
2009-08-03 09:39:03 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2009-08-02 22:35:26 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-08-02 22:35:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-08-02 22:34:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-08-02 16:05:14 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-08-02 16:04:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-08-02 16:04:42 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-08-02 16:04:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-08-02 16:03:40 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-08-02 16:03:31 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-08-02 16:03:20 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-08-02 16:01:17 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-08-02 16:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-08-02 11:23:56 ----N---- C:\WINDOWS\system32\xpsp4res.dll

======List of files/folders modified in the last 3 months======

2009-10-13 12:14:38 ----D---- C:\Program Files\Trend Micro
2009-10-13 12:14:26 ----D---- C:\WINDOWS\Prefetch
2009-10-13 12:09:40 ----D---- C:\Program Files\Mozilla Firefox
2009-10-13 12:07:34 ----SHD---- C:\WINDOWS\Installer
2009-10-13 12:07:07 ----D---- C:\WINDOWS\Temp
2009-10-13 12:06:13 ----D---- C:\WINDOWS
2009-10-13 12:05:45 ----HD---- C:\WINDOWS\system32\CatRoot2
2009-10-13 12:05:40 ----D---- C:\WINDOWS\Registration
2009-10-13 11:17:01 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-10-13 11:15:17 ----D---- C:\Program Files\Spyware Terminator
2009-10-13 11:15:17 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2009-10-13 11:00:50 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Spyware Terminator
2009-10-13 07:59:27 ----HD---- C:\Config.Msi
2009-10-13 07:47:01 ----HD---- C:\WINDOWS\system32
2009-10-12 16:01:41 ----HD---- C:\WINDOWS\inf
2009-10-12 16:01:32 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-10-12 16:01:30 ----HD---- C:\WINDOWS\system32\drivers
2009-10-12 15:55:57 ----A---- C:\WINDOWS\WORDPAD.INI
2009-10-12 15:42:19 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-08 15:27:02 ----SHD---- C:\WINDOWS\CSC
2009-10-07 13:51:29 ----D---- C:\Program Files\Java
2009-10-07 08:15:48 ----D---- C:\Program Files\SelectView
2009-10-02 16:25:20 ----D---- C:\Program Files
2009-10-02 16:06:10 ----D---- C:\WINDOWS\Minidump
2009-10-02 16:06:10 ----D---- C:\WINDOWS\Debug
2009-09-30 22:44:40 ----D---- C:\Program Files\PhotoFiltre
2009-09-30 17:42:32 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Adobe
2009-09-30 17:41:53 ----RSD---- C:\WINDOWS\Fonts
2009-09-30 17:41:51 ----D---- C:\Program Files\Common Files
2009-09-30 17:41:51 ----D---- C:\Program Files\Adobe
2009-09-30 17:41:51 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-09-30 17:41:15 ----D---- C:\WINDOWS\Downloaded Installations
2009-09-21 19:10:50 ----D---- C:\Program Files\WinClamAVShield
2009-09-14 16:12:19 ----A---- C:\WINDOWS\win.ini
2009-09-09 17:37:34 ----HD---- C:\WINDOWS\system32\Macromed
2009-09-09 16:14:46 ----D---- C:\WINDOWS\ehome
2009-09-09 00:26:33 ----A---- C:\WINDOWS\ULead32.ini
2009-09-08 23:40:22 ----D---- C:\WINDOWS\WinSxS
2009-09-08 23:23:27 ----SHD---- C:\System Volume Information
2009-09-08 22:55:56 ----HD---- C:\WINDOWS\system32\DirectX
2009-09-08 22:54:55 ----RSD---- C:\WINDOWS\assembly
2009-09-08 22:54:27 ----D---- C:\WINDOWS\Microsoft.NET
2009-09-07 01:45:20 ----SD---- C:\WINDOWS\Tasks
2009-09-07 01:45:08 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-09-05 16:33:30 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-08-31 14:00:06 ----D---- C:\hegames
2009-08-28 17:38:20 ----A---- C:\WINDOWS\system32\MRT.exe
2009-08-23 15:30:46 ----D---- C:\WINDOWS\network diagnostic
2009-08-23 14:18:15 ----D---- C:\Program Files\P2P_Max_DE
2009-08-20 16:55:06 ----D---- C:\Program Files\Internet Explorer
2009-08-19 18:13:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-08-19 12:54:16 ----D---- C:\Program Files\Messenger Plus! Live
2009-08-19 12:52:29 ----SD---- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
2009-08-19 02:16:08 ----HDC---- C:\WINDOWS\system32\DRVSTORE
2009-08-19 02:15:29 ----D---- C:\Program Files\Windows Live Toolbar
2009-08-19 02:14:20 ----D---- C:\Program Files\Windows Live
2009-08-19 02:11:50 ----D---- C:\Program Files\MSN Messenger
2009-08-19 01:19:08 ----D---- C:\Documents and Settings\All Users\Application Data\Sonic
2009-08-19 01:18:26 ----D---- C:\Program Files\Common Files\Sonic Shared
2009-08-19 01:16:30 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-08-19 01:07:22 ----D---- C:\temp
2009-08-19 01:03:47 ----HD---- C:\WINDOWS\system32\ReinstallBackups
2009-08-15 17:00:29 ----D---- C:\Program Files\Circle Developement
2009-08-15 15:23:10 ----D---- C:\Program Files\LimeWire
2009-08-15 13:08:12 ----HD---- C:\WINDOWS\system32\CatRoot
2009-08-14 16:08:29 ----HD---- C:\WINDOWS\system32\en-US
2009-08-14 16:07:47 ----HD---- C:\WINDOWS\system32\spool
2009-08-13 18:43:05 ----D---- C:\WINDOWS\Media
2009-08-13 18:43:05 ----D---- C:\WINDOWS\Help
2009-08-13 13:41:19 ----D---- C:\Program Files\Outlook Express
2009-08-05 05:01:48 ----AH---- C:\WINDOWS\system32\mswebdvd.dll
2009-08-02 23:47:30 ----HD---- C:\WINDOWS\system32\wbem
2009-08-02 22:35:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-08-02 16:11:26 ----D---- C:\WINDOWS\AppPatch
2009-07-19 18:48:58 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-07-19 09:18:59 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-07-17 15:01:06 ----AH---- C:\WINDOWS\system32\atl.dll
2009-07-14 07:03:14 ----H---- C:\WINDOWS\system32\tzchange.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 sdcplh;sdcplh; C:\WINDOWS\System32\drivers\sdcplh.sys [2005-09-15 40576]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-08-15 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-08-18 55656]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-10 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-10 55936]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-12-15 1038208]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2004-12-15 220928]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-06-08 1050140]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-06-08 3160576]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2004-12-06 10368]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2001-06-04 14112]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-10 5888]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-12-15 703232]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 ATWPKT2;ATWPKT2; \??\C:\Program Files\Common Files\AOL\ACS\ATWPKT2.SYS []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-08 145920]
S3 HidBatt;HID UPS Battery Driver; C:\WINDOWS\system32\DRIVERS\HidBatt.sys [2008-04-13 20352]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-04 606684]
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\15.tmp []
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 RimUsb;Téléphone intelligent BlackBerry ; C:\WINDOWS\System32\Drivers\RimUsb.sys [2007-05-31 22656]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SNPP106;PC Camera (6029 CIF); C:\WINDOWS\system32\DRIVERS\snpp106.sys [2003-04-09 227200]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-10 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-08-15 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-18 185089]
R2 APC UPS Service;APC UPS Service; C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe [2004-07-21 176241]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2004-09-28 195584]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2004-08-10 102912]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-07 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-06-21 53248]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 NWCWorkstation;Client Service for NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 NwSapAgent;SAP Agent; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-09-07 570880]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-07-24 358896]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2007-08-16 309744]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-08-16 166384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-05 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-07-24 88560]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-08-16 1092080]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 2896
Windows 5.1.2600 Service Pack 3

2009-10-13 12:53:17
mbam-log-2009-10-13 (12-53-17).txt

Type de recherche: Examen rapide
Eléments examinés: 118071
Temps écoulé: 7 minute(s), 19 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

Aussi, Trend Micro m'a trouvé un trojan Generic.DIT mais je ne sais pas comment avoir le rapport de l'analyse en ligne...

Merci pour votre aide!!!
Configuration: Windows XP
Firefox 3.5.3

13 réponses

kduc Messages postés 1537 Statut Membre 133
 
Salut,

Supprime ce programme -> P2P_Max_DE en allant dans :

1/ Démarrer > Panneau de Config. > Ajout/suppres… des progr.

2/ Démarrer > Poste de travail > C:\Program Files\...

---
Lis ce qui suit :

https://forum.malekal.com/viewtopic.php?t=893&start=

Ensuite, ...

Télécharge Toolbar S&D (Team IDN) sur ton Bureau : https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

Lance l'installation du programme en exécutant le fichier téléchargé.
Double-clique maintenant sur le raccourci de Toolbar-S&D.
Sélectionne la langue de ton choix puis, valide avec la touche "Entrée".
Ensuite, choisis l'option 1 (Recherche).
Patiente jusqu'à la fin de la recherche.
Le contenu du rapport est situé dans : C:\TB.txt
Poste-le.

Puis, télécharge Genproc : http://www.genproc.com/GenProc.exe ;
puis, double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre.
0
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   36
 
Merci pour ton aide et désolée de ne pas avoir répondu plus tôt... Je fais ça pour l'ordinateur de ma mère alors, je n'y viens pas tous les jours... Si tu es toujours disposé à m'aider, j'en serais bien ravie! Aussi, je voudrais ajouter qu'une amie a fait un grand ménage dans les programmes et fichiers, alors je ne sais pas si une nouvelle analyse serait de mise.... Tu me diras ce que tu en penses... Quoi qu'il en soit;
Je te poste le rapport que tu m'a demandé du logiciel toolbar...

-----------\\ ToolBar S&D 1.2.9 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 2.93GHz )
BIOS : BIOS Date: 09/06/05 17:46:49 Ver: 08.00.10
USER : HP_Administrator ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091021-0] 4.8.1356 (Activated)
C:\ (Local Disk) - NTFS - Total:178 Go (Free:156 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [1] ( 2009-10-22|15:14 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\KaZaA
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml

-----------\\ Extensions

(HP_Administrator) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-ca"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

1 - "C:\ToolBar SD\TB_1.txt" - 2009-10-22|15:15 - Option : [1]

-----------\\ Fin du rapport a 15:15:30,70

Et l'autre rapport:

Rapport GenProc 2.640 [1] - 2009-10-22 à 15:25:39
@ Windows XP Service Pack 3 - Mode normal
@ Internet Explorer (8.0.6001.18702) [Navigateur par défaut]

Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures" ; par la suite, laisse-le avec ses réglages par défaut. C'est tout.

# Etape 1/ Télécharge :

- Lop S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2 (Eric 71 & Angeldark) sur ton Bureau.

- Toolbar-S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3 (Team IDN) sur ton Bureau.

Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** HP_Administrator *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).

# Etape 2/

Lance Toolbar-S&D situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

# Etape 3/

Double-clique sur Lop S&D pour lancer l'installation, séléctionne la langue souhaitée, puis choisis l'Option 2 - Suppression - et patiente jusqu'à ce qu'il ait terminé.

# Etape 4/

Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

# Etape 5/

Redémarre normalement et poste, dans la même réponse :

- Le contenu du rapport TB.txt situé dans C:\ ;
- Le contenu du rapport lopR.txt situé dans C:\ ;
- Un nouveau rapport HijackThis https://forums.cnetfrance.fr/tutoriels-securite-informatique/1549-hijackthis-comment-l-utiliser ;
- Un nouveau rapport GenProc ;

Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

~~ Arguments de la procédure ~~

# Détections [1] GenProc 2.640 2009-10-22 à 15:26:01
Lop:le 2009-10-22 à 15:27:10 "C:\Program Files\Circle Developement"
Toolbar:le 2009-10-22 à 15:27:12 "C:\Program Files\KaZaA"

----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------

~~ Fin à 15:27:56 ~~

Merci encore!!!

PS Dis-moi est-ce que je dois suivre les étapes qui sont inscrites dans le rapport????
0
kduc Messages postés 1537 Statut Membre 133
 
Salut phoenixgirl,

Suis les étapes de la procédure Genproc (ou tu retrouveras la suite de Toolbar S&D) et poste les rapports.
0
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   36
 
-----------\\ ToolBar S&D 1.2.9 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 2.93GHz )
BIOS : BIOS Date: 09/06/05 17:46:49 Ver: 08.00.10
USER : HP_Administrator ( Administrator )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091025-0] 4.8.1356 (Activated)
C:\ (Local Disk) - NTFS - Total:178 Go (Free:157 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [2] ( 2009-10-25|18:07 )

-----------\\ SUPPRESSION

Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\KaZaA

-----------\\ Recherche de Fichiers / Dossiers ...

-----------\\ Extensions

(HP_Administrator) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(HP_Administrator) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-ca"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\HP_ADM~1\Local Settings\Temporary Internet Files\Content.IE5\NNKD1NCJ\crackyfred_1237318629[1].jpg

1 - "C:\ToolBar SD\TB_1.txt" - 2009-10-22|15:15 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 2009-10-25|18:09 - Option : [2]

-----------\\ Fin du rapport a 18:09:37,51

lop rapport:

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 2.93GHz )
BIOS : BIOS Date: 09/06/05 17:46:49 Ver: 08.00.10
USER : HP_Administrator ( Administrator )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091025-0] 4.8.1356 (Activated)
C:\ (Local Disk) - NTFS - Total:178 Go (Free:157 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 2009-10-25|18:10 )

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\Circle Developement

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

--------------------\\ Listing des dossiers dans APPLIC~1

[2005-09-09|22:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[2005-06-10|13:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[2009-10-14|14:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[2005-09-09|22:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[2005-09-09|22:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
[2005-09-09|22:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec

[2008-11-08|13:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009-09-30|17:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2008-09-06|16:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[2008-08-12|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2008-08-12|19:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2009-10-14|14:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
[2008-08-25|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[2009-10-14|13:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-09-09|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[2005-09-09|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
[2005-09-09|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[2005-09-09|22:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[2005-09-09|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intuit
[2008-09-06|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak
[2008-09-04|21:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[2009-10-02|16:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[2006-09-26|18:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[2009-09-05|16:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2005-11-15|20:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSScanAppDataDir
[2005-12-27|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
[2008-09-06|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Netscape Internet Service
[2008-11-07|20:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NokiaMusic
[2009-10-14|13:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Norton
[2009-09-07|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NortonInstaller
[2008-09-12|14:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[2009-09-05|16:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Media
[2005-12-27|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Otto
[2005-10-15|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[2009-10-14|14:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Roxio
[2005-09-09|21:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[2009-08-19|01:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[2009-10-14|13:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2008-09-11|09:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
[2009-09-07|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2009-09-08|23:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Team MediaPortal
[2009-09-05|17:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2006-08-02|21:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-12-29|19:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[2008-12-29|18:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-02-11|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[2009-10-14|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[2005-09-09|22:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Apple Computer
[2005-06-10|13:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[2005-09-09|22:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Intuit
[2005-09-09|22:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2005-09-09|22:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[2005-09-09|22:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[2005-09-09|22:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec

[2007-08-15|12:15] C:\DOCUME~1\Guest\APPLIC~1\AOL
[2005-09-09|22:28] C:\DOCUME~1\Guest\APPLIC~1\Apple Computer
[2008-03-06|22:48] C:\DOCUME~1\Guest\APPLIC~1\Google
[2008-03-06|22:58] C:\DOCUME~1\Guest\APPLIC~1\HP
[2005-06-10|13:02] C:\DOCUME~1\Guest\APPLIC~1\Identities
[2005-09-09|22:32] C:\DOCUME~1\Guest\APPLIC~1\Intuit
[2009-10-14|14:52] C:\DOCUME~1\Guest\APPLIC~1\Microsoft
[2005-09-09|22:12] C:\DOCUME~1\Guest\APPLIC~1\Real
[2005-09-09|22:33] C:\DOCUME~1\Guest\APPLIC~1\SampleView
[2007-12-30|02:27] C:\DOCUME~1\Guest\APPLIC~1\SlipStream
[2005-09-09|22:48] C:\DOCUME~1\Guest\APPLIC~1\Symantec

[2008-11-08|11:19] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ActiveState
[2009-09-30|17:42] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Adobe
[2008-11-01|17:36] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Apple Computer
[2008-08-25|09:52] C:\DOCUME~1\HP_ADM~1\APPLIC~1\AVS4YOU
[2008-09-09|13:13] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Google
[2008-09-09|11:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Grisoft
[2008-09-14|11:59] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Help
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Hewlett-Packard
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\HP
[2008-09-14|14:01] C:\DOCUME~1\HP_ADM~1\APPLIC~1\HPQ
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Identities
[2008-12-23|23:30] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Image Zone Express
[2009-08-19|01:27] C:\DOCUME~1\HP_ADM~1\APPLIC~1\InstallShield
[2005-10-19|02:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\InterVideo
[2005-09-09|22:32] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Intuit
[2005-10-21|00:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Leadertech
[2008-09-06|17:44] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Macromedia
[2009-10-02|16:13] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Malwarebytes
[2009-10-14|14:52] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Microsoft
[2008-09-06|17:18] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Mozilla
[2005-12-27|21:30] C:\DOCUME~1\HP_ADM~1\APPLIC~1\muvee Technologies
[2008-08-31|18:12] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Netscape
[2005-12-27|21:28] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Otto
[2008-11-07|19:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Real
[2009-08-19|01:35] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Roxio
[2008-09-08|09:47] C:\DOCUME~1\HP_ADM~1\APPLIC~1\SampleView
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\SlipStream
[2005-10-21|00:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Sonic
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Sun
[2005-10-14|22:07] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Symantec
[2005-10-15|11:42] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Template
[2008-09-06|15:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Uniblue
[2005-11-30|23:06] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Verbatim Software
[2005-11-30|23:05] C:\DOCUME~1\HP_ADM~1\APPLIC~1\V-Safe
[2006-12-02|20:20] C:\DOCUME~1\HP_ADM~1\APPLIC~1\You've Got Pictures Screensaver

[2009-10-14|14:52] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2009-08-19|01:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Roxio

[2009-10-14|14:52] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[2005-10-16|01:41] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[2009-10-25 15:45][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{14A18F9C-8275-4067-B3CB-617437F4508B}.job
[2008-09-29 17:53][--a------] C:\WINDOWS\tasks\Connexion facile … Internet.job
[2009-10-25 18:02][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-10 22:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ MsgPlus SPONSOR INSTALLED !

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"SponsorInstalled"=dword:00000000

--------------------\\ Listing des dossiers dans C:\Program Files

[2009-09-30|17:41] C:\Program Files\Adobe
[2006-03-05|21:11] C:\Program Files\Alwil Software
[2008-08-30|15:46] C:\Program Files\AVG
[2008-09-06|17:18] C:\Program Files\AVS4YOU
[2009-10-14|15:05] C:\Program Files\CCleaner
[2006-06-07|17:12] C:\Program Files\CDS
[2009-10-14|14:08] C:\Program Files\Common Files
[2005-06-08|12:59] C:\Program Files\ComPlus Applications
[2009-10-14|15:31] C:\Program Files\CONEXANT
[2008-01-16|18:39] C:\Program Files\dat
[2008-08-04|14:53] C:\Program Files\Easy Internet signup
[2007-10-28|20:31] C:\Program Files\EnglishOtto
[2008-01-16|18:39] C:\Program Files\fnt
[2009-09-09|07:39] C:\Program Files\Gamenext
[2007-10-28|20:31] C:\Program Files\GemMaster
[2009-10-14|13:33] C:\Program Files\Google
[2005-09-09|22:56] C:\Program Files\Hewlett-Packard
[2005-11-15|20:53] C:\Program Files\HP
[2009-10-14|13:47] C:\Program Files\InstallShield Installation Information
[2007-10-28|20:31] C:\Program Files\IntelliMover Data Transfer Demo
[2008-09-06|17:23] C:\Program Files\InterActual
[2009-10-15|17:58] C:\Program Files\Internet Explorer
[2005-09-09|22:21] C:\Program Files\InterVideo
[2008-11-08|13:54] C:\Program Files\iPod
[2008-11-08|13:55] C:\Program Files\iTunes
[2009-10-07|13:51] C:\Program Files\Java
[2008-12-28|18:03] C:\Program Files\Jeune Styliste 2
[2008-09-06|16:53] C:\Program Files\Kodak
[2009-08-15|15:23] C:\Program Files\LimeWire
[2008-09-04|15:05] C:\Program Files\Messenger
[2009-08-19|12:54] C:\Program Files\Messenger Plus! Live
[2008-09-01|12:35] C:\Program Files\MessengerPlus! 3
[2008-11-23|20:35] C:\Program Files\Microsoft
[2008-08-05|16:12] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2005-06-10|13:04] C:\Program Files\microsoft frontpage
[2007-08-21|19:48] C:\Program Files\Microsoft Games
[2008-04-22|20:55] C:\Program Files\Microsoft Money 2005
[2006-01-09|19:54] C:\Program Files\Microsoft Office
[2005-09-09|22:23] C:\Program Files\Microsoft Plus! Dancer LE
[2005-09-09|22:23] C:\Program Files\Microsoft Plus! Digital Media Edition
[2005-09-09|22:23] C:\Program Files\Microsoft Plus! Photo Story 2 LE
[2009-09-09|19:08] C:\Program Files\Microsoft Silverlight
[2008-08-05|11:22] C:\Program Files\Microsoft SQL Server Compact Edition
[2009-08-19|02:15] C:\Program Files\Microsoft Sync Framework
[2005-09-09|22:26] C:\Program Files\Microsoft Visual Studio
[2007-10-28|20:31] C:\Program Files\Microsoft Works
[2008-01-16|18:39] C:\Program Files\mid
[2008-09-04|14:46] C:\Program Files\Movie Maker
[2009-10-25|18:06] C:\Program Files\Mozilla Firefox
[2009-08-14|16:08] C:\Program Files\MSBuild
[2008-12-29|17:42] C:\Program Files\MSECACHE
[2005-10-20|20:16] C:\Program Files\MSN
[2007-10-28|20:31] C:\Program Files\MSN Encarta Standard
[2006-01-16|15:36] C:\Program Files\MSN Games
[2005-06-10|13:04] C:\Program Files\MSN Gaming Zone
[2009-08-19|02:11] C:\Program Files\MSN Messenger
[2008-08-05|16:03] C:\Program Files\MSXML 4.0
[2005-09-09|22:31] C:\Program Files\muvee Technologies
[2008-09-04|14:41] C:\Program Files\NetMeeting
[2006-08-18|16:33] C:\Program Files\Netscape
[2008-09-06|17:13] C:\Program Files\Netscape Internet Service
[2008-09-12|14:50] C:\Program Files\NOS
[2009-09-05|16:32] C:\Program Files\Oberon Media
[2005-09-09|22:44] C:\Program Files\Online Services
[2009-08-13|13:41] C:\Program Files\Outlook Express
[2007-10-28|20:31] C:\Program Files\PC-Doctor 5 for Windows
[2005-09-09|22:40] C:\Program Files\PC-Doctor for DOS
[2008-01-16|18:39] C:\Program Files\Pcx
[2009-09-30|22:44] C:\Program Files\PhotoFiltre
[2009-09-30|22:44] C:\Program Files\PhotoScape
[2009-09-08|23:40] C:\Program Files\Photosynth
[2009-10-15|15:02] C:\Program Files\QUAD Utilities
[2009-10-14|13:35] C:\Program Files\Quicken
[2008-11-08|13:49] C:\Program Files\QuickTime
[2008-11-07|19:36] C:\Program Files\Real
[2009-08-14|16:08] C:\Program Files\Reference Assemblies
[2009-08-19|01:01] C:\Program Files\Research In Motion
[2009-10-21|13:14] C:\Program Files\SelectView
[2008-01-16|18:39] C:\Program Files\snd
[2009-10-14|13:57] C:\Program Files\Sonic
[2008-09-14|11:48] C:\Program Files\Sophos
[2008-01-16|18:39] C:\Program Files\spr
[2009-10-14|13:41] C:\Program Files\Spybot - Search & Destroy
[2008-05-05|17:12] C:\Program Files\Styliste2
[2006-03-06|10:25] C:\Program Files\Symantec
[2009-09-08|23:06] C:\Program Files\Team MediaPortal
[2008-12-28|18:03] C:\Program Files\TMNT
[2009-10-13|12:14] C:\Program Files\Trend Micro
[2007-09-28|16:55] C:\Program Files\ubisoft
[2006-04-30|19:34] C:\Program Files\Ulead Systems
[2005-06-08|12:59] C:\Program Files\Uninstall Information
[2008-12-17|22:39] C:\Program Files\WildTangent
[2008-12-29|17:42] C:\Program Files\Windows Installer Clean Up
[2009-08-19|02:14] C:\Program Files\Windows Live
[2008-08-05|11:36] C:\Program Files\Windows Live Favorites
[2008-09-16|09:03] C:\Program Files\Windows Live Safety Center
[2009-08-19|02:11] C:\Program Files\Windows Live SkyDrive
[2009-08-19|02:15] C:\Program Files\Windows Live Toolbar
[2008-11-08|15:41] C:\Program Files\Windows Media Player
[2008-09-04|14:41] C:\Program Files\Windows NT
[2005-06-10|13:05] C:\Program Files\Windows Plus
[2005-06-08|13:00] C:\Program Files\WindowsUpdate
[2005-06-10|13:05] C:\Program Files\xerox
[2006-02-11|12:10] C:\Program Files\Yahoo!
[2008-03-06|22:33] C:\Program Files\Zuma Deluxe

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[2009-09-30|17:41] C:\Program Files\Common Files\Adobe
[2008-09-06|17:26] C:\Program Files\Common Files\AOL
[2008-11-08|13:47] C:\Program Files\Common Files\Apple
[2008-09-06|17:17] C:\Program Files\Common Files\AVSMedia
[2005-09-09|22:07] C:\Program Files\Common Files\Hewlett-Packard
[2005-09-09|22:04] C:\Program Files\Common Files\HP
[2005-09-09|22:30] C:\Program Files\Common Files\InstallShield
[2005-09-09|22:21] C:\Program Files\Common Files\InterVideo
[2008-09-12|13:58] C:\Program Files\Common Files\Java
[2005-09-09|22:20] C:\Program Files\Common Files\LightScribe
[2009-08-02|22:35] C:\Program Files\Common Files\Microsoft Shared
[2005-06-10|13:03] C:\Program Files\Common Files\MSSoap
[2005-09-09|22:30] C:\Program Files\Common Files\muvee Technologies
[2006-12-02|20:20] C:\Program Files\Common Files\Nullsoft
[2009-09-05|16:32] C:\Program Files\Common Files\Oberon Media
[2005-06-10|13:03] C:\Program Files\Common Files\ODBC
[2008-11-07|19:38] C:\Program Files\Common Files\Real
[2009-10-14|14:16] C:\Program Files\Common Files\Roxio Shared
[2005-06-10|13:03] C:\Program Files\Common Files\Services
[2006-05-09|19:07] C:\Program Files\Common Files\snpp106
[2009-10-14|14:16] C:\Program Files\Common Files\Sonic Shared
[2005-06-10|13:03] C:\Program Files\Common Files\SpeechEngines
[2007-05-15|16:59] C:\Program Files\Common Files\SWF Studio
[2009-10-14|13:31] C:\Program Files\Common Files\Symantec Shared
[2008-09-04|14:41] C:\Program Files\Common Files\System
[2005-10-22|04:30] C:\Program Files\Common Files\Totem Shared
[2008-11-23|20:02] C:\Program Files\Common Files\Windows Live
[2008-08-05|11:12] C:\Program Files\Common Files\WindowsLiveInstaller

--------------------\\ Process

( 15 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-25 18:12:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\HP_ADM~1\Local Settings\Temporary Internet Files\Content.IE5\NNKD1NCJ\crackyfred_1237318629[1].jpg

[F:49][D:5]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
[F:30][D:0]-> C:\DOCUME~1\HP_ADM~1\Cookies
[F:2894][D:6]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 2009-10-25|18:14 - Option : [2]

--------------------\\ Fin du rapport a 18:14:06
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
kduc Messages postés 1537 Statut Membre 133
 
Salut,

Tu as, semble-t'il, des restes de Norton/Symantec sur le PC !

Peut-être une version pré-installée à l' achat ; pour supprimer cet antivirus, utilise cet outil :

http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

---
Redémarre le PC en mode sans échec ...
https://www.pcastuces.com/pratique/windows/mode_sans_echec/page2.html
(méthode F8 de préférence)

--------------------------------------------
Tu n' auras pas accès à Internet pendant le "mode sans échec".
Aussi, copie/colle la procédure dans un fichier texte (word) et mets-la
sur le "bureau" pour l' avoir à ta disposition.
--------------------------------------------

Ferme toutes les fenêtres et applications.
Relance HijackThis et clique sur > Do a system scan only puis, coche
les cases devant les lignes qui suivent (et uniquement ces lignes), si tjrs présentes :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.gamenext.com
R3 - URLSearchHook: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
O2 - BHO: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O3 - Toolbar: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu

Ensuite, clique sur > Fix checked et valide par "Yes". Referme HijackThis.

Affiche les fichiers et dossiers cachés
Pour ce faire, tu vas dans un dossier, par ex. "Mes Images".
Ensuite, clique sur > Outils > Options des dossiers ...
clique sur l' onglet « Affichage » et ...
coche --> Afficher les fichiers et dossiers cachés
décoche > Masquer les extensions des fichiers dont le type est connu
décoche > Masquer les fichiers protégés du système d' exploitation (recommandé).
« Appliquer » et « OK ».

Rends-toi dans > Démarrer > Panneau de config. > Ajout/suppres… de programmes

Supprime, si tu le(s) trouves > WildTangent, QUAD Utilities, P2P_Max_DE et Crawler

Ensuite, va dans > Démarrer > Poste de travail > C:\

et supprime le(s) programme(s)/ fichier(s) en gras, ci-dessous, si tu le(s) trouves.

C:\PROGRA~1\Crawler <-
C:\Program Files\WildTangent <-
C:\Program Files\QUAD Utilities <-
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM <-

Remet les fichiers et dossiers cachés comme tu les as trouvés !

Lance CCleaner ...
Clique sur > Analyser > Nettoyer, puis sur OK dans la fenêtre qui s' affiche.
(re)Lance le nettoyage et (re)confirme par OK.

Redémarre le PC en mode normal ...

Télécharge Ad-Remover : http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe (de Cyrildu17 / C_XX) sur ton Bureau.
http://pagesperso-orange.fr/NosTools/ad_remover.html

! Déconnecte-toi du net et ferme toutes applications en cours.

1. Double-clique sur le programme d'installation ; laisse-le
s’ installer par défaut (C:\Program files).
2. Double-clique sur l'icône AD-Remover située sur ton Bureau.
(Pour Vista : clique droit > "Exécuter en tant qu'administrateur")
3. Au menu principal, choisis l'option L.
L’ outil débute sa recherche … Laisse-le travailler !
Le scan achevé, une fenêtre va s’ afficher.
4. Poste (copie-colle) le rapport qui apparaît à la fin.

PS : tu trouveras aussi le rapport sous C:\Ad-report(date).log)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

Note : "Process.exe", une composante de l'outil peut être
détecté par certains antivirus comme une infection ; donc, ne pas en tenir compte : il s'agit d'un faux positif.
0
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   36
 
.
======= LOGFILE OF AD-REMOVER 1.1.4.6_A | ONLY XP/VISTA/7 =======
.
Updated by C_XX on 18.10.2009 at 19:05
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Launch at: 16:58:44, 2009-11-05 | Normal Boot | Option: CLEAN
Executed from: C:\Program Files\Ad-Remover\
Operating system: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Computer Name: PAM_ALEX | Current user: HP_Administrator
.
============== NEUTRALIZED ELEMENT(S) ==============
.

HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKCU\Software\SWEETIE
HKCU\Software\SweetIM
HKLM\Software\SweetIM
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\DOCUME~1\HP_ADM~1\APPLIC~1\Mozilla\Firefox\Profiles\iw3l14e0.default\searchplugins\sweetim.xml

(!) -- Temp files deleted.

.
============== Added scan ==============
.
.
* Mozilla FireFox Version 3.5.4 [fr] *
.
ProfilePath: iw3l14e0.default (HP_Administrator)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Google");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://search.live.com/results.aspx?FORM=IEFM1&q=");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.4");
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Start Page: hxxp://fr.msn.com/
Search Page: hxxp://www.google.com
Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchAssistant:
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
3072 Byte(s) - C:\Ad-Report-CLEAN[1].log
.
1 File(s) - C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
3 File(s) - C:\WINDOWS\Temp
.
18 File(s) - C:\Program Files\Ad-Remover\BACKUP
1 File(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
End at: 17:08:35 | 2009-11-05 - CLEAN[1]
.
============== E.O.F ==============
.
0
kduc Messages postés 1537 Statut Membre 133
 
Salut,

"Mes logiciels de sécurité ne cessent de détecter des TRACKING COOKIES lors des analyses quotidiennes...
Je ne sais pas s'il y a un virus ou quoi mais mon ordi est très lent et il bogue souvent
."

C' est tjrs d' actualité ?

---
Fais un clic droit sur le lien pour installer SDFix (par AndyManchesta) :
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Choisis "Enregistrer sous" (dans IE c'est "Enregistrer la cible/le lien sous..")
et sauvegarde-le (Enregistrer dans) sur le Bureau.

Important : dans "Nom du fichier" enregistre (renomme) "sdfix" ou "SdFix.exe" en sd-fix.exe

Redémarre en mode sans échec ...
https://www.pcastuces.com/pratique/windows/mode_sans_echec/page2.htm
(de préférence par F8 au démarrage).

--------------------------------------------
Tu n' auras pas accès à Internet pendant le "mode sans échec".
Aussi, copie/colle la procédure dans un fichier texte (word) et mets-la
sur le "bureau" pour l' avoir à ta disposition.
--------------------------------------------

Sur le bureau, double-clique sur sd-fix.exe et choisis Install pour l'extraire sur le Bureau.
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur
RunThis.cmd (ou RunThis.bat) pour lancer le script.

Appuie sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre des trojans trouvés puis te
demandera d'appuyer sur une touche pour redémarrer. Fais-le.

Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va
continuer à s'exécuter et supprimer des fichiers.

Après le chargement du Bureau, l'outil terminera son travail et affichera "Finished".
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.

Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera
aussi dans le dossier SDFix sous le nom Report.txt.

Copie/colle le contenu du fichier Report.txt dans ta prochaine réponse.

Tuto : https://www.malekal.com/slenfbot-still-an-other-irc-bot/

Ensuite, ...

Télécharge, installe et mets à jour Malwarebytes Anti-Malwares
http://forum.telecharger.01net.com/microhebdo/6/tuto-securite/tuto-malwaresbytes-anti-malware-352008/messages-1.html puis, lance un scan COMPLET et poste le rapport.

PS : si MalwareByte's a détecté des infections, clique sur Afficher les résultats,
puis sur Supprimer la sélection.
0
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   36
 
Ca ne fonctionne pas!! Lorsque j'exécute SdFix, une fenêtre bleue s'ouvre et je tappe Y, mais ca ne se lance pas... Je ne comprends...... : (
0
kduc Messages postés 1537 Statut Membre 133
 
Salut,

OK.

Alors, enchaîne avec Malwarebytes.
0
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   36
 
Malwarebytes' Anti-Malware 1.42
Version de la base de données: 3340
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2009-12-10 15:52:50
mbam-log-2009-12-10 (15-52-50).txt

Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Eléments examinés: 250387
Temps écoulé: 1 hour(s), 23 minute(s), 58 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 6

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\RECYCLER\S-1-5-21-3112294194-1157658477-1820155173-1008\Dc2\dummy.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-3112294194-1157658477-1820155173-1008\Dc2\apps\dummy.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\SdFix\dummy.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\SdFix\apps\dummy.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D7BD54B8-C977-4903-8CE7-9415B851EC71}\RP919\A0223816.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D7BD54B8-C977-4903-8CE7-9415B851EC71}\RP919\A0223817.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
0
kduc Messages postés 1537 Statut Membre 133
 
Salut,

Clique droit sur ce lien pour installer ComboFix (par sUBs) :

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Choisis "Enregistrer sous" (dans IE c'est "Enregistrer la cible/le lien sous..")
et sauvegarde-le (Enregistrer dans) sur le Bureau.

Important : dans "Nom du fichier" enregistre (renomme) "combofix" en combo-fix.exe

Prends connaissance de ce tutoriel : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

Ferme toutes les fenêtres et applications.
Déconnecte-toi du net et désactive tes protections résidentes :
https://forum.pcastuces.com/default.asp

Sur le bureau, double clique combo-fix.exe.
(si l' installation de la Console de récipération est demandé : accepte)
Tape sur la touche Y (Yes) pour démarrer le scan.
ComboFix redémarrera ton PC.
Lorsque le scan sera complété, un rapport apparaîtra.
Copie/colle ce rapport dans ta prochaine réponse et nouveau rapport hijackthis.

PS : Le rapport se trouve également ici : C:\Combofix.txt

Ne clique pas dans la fenêtre de Combofix durant l’analyse : cela pourrait provoquer le gel du programme !
0
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   36
 
ComboFix 10-01-04.01 - HP_Administrator 2010-01-05 14:03:31.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.2.1033.18.503.123 [GMT -5:00]
Lancé depuis: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\LOG.TXT
c:\recycler\S-1-5-21-3112294194-1157658477-1820155173-1009
c:\windows\system32\ps2.bat
c:\windows\system32\Thumbs.db
D:\Autorun.inf

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-05 au 2010-01-05 ))))))))))))))))))))))))))))))))))))
.

2009-12-25 00:59 . 2009-12-25 00:59 -------- d-----w- c:\program files\iPod
2009-12-25 00:59 . 2009-12-25 01:00 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-25 00:57 . 2009-12-25 00:57 -------- d-----w- c:\program files\Bonjour
2009-12-25 00:55 . 2009-12-25 00:56 -------- d-----w- c:\program files\QuickTime
2009-12-25 00:53 . 2009-12-25 00:53 -------- d-----w- c:\program files\Apple Software Update
2009-12-25 00:52 . 2009-08-29 00:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-12-25 00:52 . 2009-08-29 00:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-12-16 20:18 . 2009-12-16 20:18 -------- d-----w- C:\$AVG
2009-12-16 20:18 . 2009-12-16 20:18 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-16 20:18 . 2009-12-16 20:18 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-16 20:17 . 2009-12-16 20:17 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-16 20:17 . 2009-12-16 20:17 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-16 20:17 . 2010-01-05 14:41 -------- d-----w- c:\windows\system32\drivers\Avg
2009-12-16 20:17 . 2009-12-16 20:23 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-16 20:17 . 2009-12-16 20:17 -------- d-----w- c:\program files\AVG
2009-12-16 20:17 . 2009-12-16 20:17 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-16 18:57 . 2009-12-16 18:57 -------- d-----w- c:\program files\Zylom Games

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 18:55 . 2008-09-13 14:43 -------- d-----w- c:\program files\SelectView
2009-12-27 00:54 . 2005-09-10 02:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-25 01:25 . 2008-01-31 00:11 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Apple Computer
2009-12-25 01:25 . 2005-09-10 02:28 -------- d-----w- c:\program files\iTunes
2009-12-25 00:59 . 2008-08-12 23:21 -------- d-----w- c:\program files\Common Files\Apple
2009-12-24 01:33 . 2008-12-28 20:09 86576 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
2009-12-24 01:33 . 2008-12-28 20:09 392728 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
2009-12-24 01:33 . 2008-12-28 20:09 132672 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
2009-12-22 13:38 . 2009-12-17 13:39 4043544 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-22 13:37 . 2009-12-17 13:39 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-18 14:14 . 2009-12-18 14:15 294656 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-17 13:38 . 2009-12-17 13:39 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-12-17 13:38 . 2009-12-17 13:39 3776280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-17 13:37 . 2009-12-17 13:39 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-10 19:23 . 2009-11-27 22:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-10 19:21 . 2009-12-10 19:21 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-03 21:14 . 2009-11-27 22:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 21:13 . 2009-11-27 22:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-27 22:20 . 2009-11-27 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-24 19:39 . 2008-12-28 20:09 0 ----a-r- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
2009-11-12 22:07 . 2009-11-12 22:07 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-09 23:04 . 2008-08-05 15:06 -------- d-----w- c:\program files\Windows Live
2009-11-05 20:09 . 2009-11-05 20:09 152576 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-10-23 20:01 . 2009-12-16 18:57 102400 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-10-16 17:12 . 2009-12-16 20:23 1119488 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-10-15 18:52 . 2005-10-15 02:40 85256 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-14 18:05 . 2009-08-19 05:30 256 ----a-w- c:\windows\system32\pool.bin
2009-10-11 09:17 . 2009-10-07 17:52 411368 ----a-w- c:\windows\system32\deploytk.dll
2008-01-16 22:39 . 2008-01-16 22:39 13903 ----a-w- c:\program files\Uninst.isu
2005-12-27 17:35 . 2005-12-27 17:35 251 ----a-w- c:\program files\wt3d.ini
1997-11-05 21:07 . 2008-01-16 22:39 1047152 ----a-w- c:\program files\scrabble.exe
1996-11-04 16:44 . 2008-01-16 22:39 151 ----a-w- c:\program files\MplayNow.ini
1996-10-30 22:13 . 2008-01-16 22:39 68970 ----a-w- c:\program files\SCRSAVE.DAT
1996-10-30 22:13 . 2008-01-16 22:39 570 ----a-w- c:\program files\SCRHISC.DAT
1996-10-30 22:13 . 2008-01-16 22:39 1627 ----a-w- c:\program files\SCROPT.DAT
1996-09-11 18:34 . 2008-01-16 22:39 3007 ----a-w- c:\program files\ReadMe.txt
1996-09-09 17:06 . 2008-01-16 22:39 1620 ----a-w- c:\program files\Scrabble.mpi
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-16 17:12 1119488 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-21 468408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-11 59392]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-08 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-31 2033432]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-7-31 139776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-16 20:18 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 21:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\ntvdm.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2005-12-28 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2005-12-28 5248]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-16 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-16 360584]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-08-19 54752]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\15.tmp --> c:\windows\system32\15.tmp [?]
.
Contenu du dossier 'Tâches planifiées'

2009-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2008-09-29 c:\windows\Tasks\Connexion facile à Internet.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2005-05-24 23:46]

2010-01-05 c:\windows\Tasks\User_Feed_Synchronization-{14A18F9C-8275-4067-B3CB-617437F4508B}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xport to Microsoft Excel
IE: {{16D60F96-2FF6-40b2-96D3-C32170E45A01} - {DA45FFEB-CD7D-4220-9B9B-F71967DE2B60} - c:\program files\SelectView\svie.dll
DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} - hxxp://www.meetstream.com/activex/28014/activereceiver.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\iw3l14e0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -

MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
AddRemove-Notification de cadeaux MSN - c:\documents and settings\HP_Administrator\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-05 14:17
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys sdcplh.sys hal.dll >>UNKNOWN [0x82B8F0F0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf86a7f28
\Driver\ACPI -> ACPI.sys @ 0xf84e4cb8
\Driver\atapi -> sdcplh.sys @ 0xf88876f8
\Driver\iaStor -> iaStor.sys @ 0xf83c5ade
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
SecurityProcedure -> ntkrnlpa.exe @ 0x80583d4a
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf8253bd4
PacketIndicateHandler -> NDIS.sys @ 0xf825fa21
SendHandler -> NDIS.sys @ 0xf8253d44
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\15.tmp"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'explorer.exe'(1220)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~1\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\AVG\AVG9\avgwdsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG9\avgemc.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\hp\KBD\KBD.EXE
.
**************************************************************************
.
Heure de fin: 2010-01-05 14:31:14 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-01-05 19:31

Avant-CF: 167 637 004 288 bytes free
Après-CF: 168 181 231 616 bytes free

- - End Of File - - 1C2EC7FF79A78399906710DD2D7DFF6E
0
phoenixgirl Messages postés 218 Date d'inscription   Statut Membre Dernière intervention   36
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:13:35, on 2010-01-05
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: SVIEBHO Class - {B3C54716-9D0A-4666-A81A-6072A6325A5A} - C:\Program Files\SelectView\svie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SIMBAR Enabled; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 3.1; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"https://www.voodoo.com/?domain=absoluflash.com&http_host=www.absoluflash.com"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: SelectView - {16D60F96-2FF6-40b2-96D3-C32170E45A01} - C:\Program Files\SelectView\svie.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} (ActiveReceiver Control) - http://www.meetstream.com/activex/28014/activereceiver.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - (no file)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
0