Rapport UsbFix
limzo
-
Destrio5 Messages postés 99820 Statut Modérateur -
Destrio5 Messages postés 99820 Statut Modérateur -
Bonjour,
un scan de mon pc avec UsbFix me donne le rapport suivant. je ne sais malheureusement pas l'interpréter. Ce qui m'a emmené à ce logiciel est l'impossibilité pour moi d'afficher les dossiers de ma clé usb, suite à une infection. alors au secours. merci d'avance.
############################## | UsbFix V6.055 |
User : Alimou Sow (Administrateurs) # LIM-Y075K8FAAUG
Update on 18/11/2009 by Chiquitine29, C_XX & Chimay8
Start at: 17:54:03 | 19/11/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) M processor 1400MHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Disabled
AV : AVG Internet Security 8.5 [ Enabled | Updated ]
FW : AVG Firewall[ Enabled ]8.5
C:\ -> Disque fixe local # 13,97 Go (1,67 Go free) # NTFS
D:\ -> Disque fixe local # 13,96 Go (6,89 Go free) [SOFTS] # FAT32
E:\ -> Disque fixe local # 13,96 Go (6,02 Go free) [PHOTO-VID] # FAT32
F:\ -> Disque fixe local # 13,96 Go (3,83 Go free) [MUSIQUE] # FAT32
G:\ -> Disque CD-ROM
H:\ -> Disque amovible # 7,46 Go (1,75 Go free) [LIM] # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe 1188
C:\WINDOWS\system32\csrss.exe 1236
C:\WINDOWS\system32\winlogon.exe 1260
C:\WINDOWS\system32\services.exe 1304
C:\WINDOWS\system32\lsass.exe 1316
C:\WINDOWS\System32\Ati2evxx.exe 1464
C:\WINDOWS\system32\svchost.exe 1480
C:\WINDOWS\system32\svchost.exe 1580
C:\WINDOWS\System32\svchost.exe 1616
C:\WINDOWS\system32\S24EvMon.exe 1660
C:\WINDOWS\System32\svchost.exe 1716
C:\WINDOWS\System32\svchost.exe 1936
C:\WINDOWS\system32\spoolsv.exe 624
C:\WINDOWS\System32\SCardSvr.exe 680
C:\WINDOWS\System32\svchost.exe 852
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1068
C:\WINDOWS\system32\ZCfgSvc.exe 1108
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 1868
C:\PROGRA~1\AVG\AVG8\avgfws8.exe 224
C:\Program Files\Bonjour\mDNSResponder.exe 252
C:\WINDOWS\system32\Ati2evxx.exe 260
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe 416
C:\WINDOWS\Explorer.EXE 484
C:\WINDOWS\system32\RegSrvc.exe 896
C:\WINDOWS\System32\svchost.exe 1120
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe 1500
C:\Program Files\NCH Swift Sound\WebDictate\webdictate.exe 1648
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 1760
C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe 1852
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe 204
C:\PROGRA~1\AVG\AVG8\avgtray.exe 240
C:\Program Files\Dell\QuickSet\quickset.exe 308
C:\Program Files\SuperCopier2\SuperCopier2.exe 388
C:\Program Files\Windows Live\Messenger\msnmsgr.exe 384
C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE 420
C:\WINDOWS\system32\ctfmon.exe 456
C:\PROGRA~1\AVG\AVG8\avgemc.exe 908
C:\PROGRA~1\AVG\AVG8\avgam.exe 1096
C:\PROGRA~1\AVG\AVG8\avgrsx.exe 1012
C:\PROGRA~1\AVG\AVG8\avgnsx.exe 120
C:\Program Files\AVG\AVG8\avgcsrvx.exe 2880
C:\WINDOWS\system32\wbem\wmiprvse.exe 2944
C:\WINDOWS\System32\alg.exe 3716
C:\WINDOWS\system32\1XConfig.exe 3988
C:\Program Files\Windows Live\Contacts\wlcomm.exe 2904
C:\Program Files\Mozilla Firefox\firefox.exe 2148
C:\WINDOWS\system32\wuauclt.exe 3260
C:\WINDOWS\system32\wuauclt.exe 3784
C:\WINDOWS\system32\wbem\wmiprvse.exe 1980
################## | Fichiers # Dossiers infectieux |
C:\WINDOWS\System32\bycool1
################## | Registre # Clés infectieuses |
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{058698e0-6bc3-11de-86e8-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{4e99597b-c9dc-11de-b27f-000e35b021df}
Shell\AutoRun\command =H:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{5f016cc9-50e5-11de-86d0-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{6b47feb1-621e-11de-86df-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{74d33dd2-8125-11de-b251-000e35b021df}
Shell\AutoRun\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
Shell\open\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
HKCU\..\..\Explorer\MountPoints2\{74d33ddc-8125-11de-b251-000e35b021df}
Shell\1\Command =Recycle.exe
Shell\2\Command =Recycle.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe
HKCU\..\..\Explorer\MountPoints2\{74d33ddd-8125-11de-b251-000e35b021df}
Shell\1\Command =Recycle.exe
Shell\2\Command =Recycle.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe
HKCU\..\..\Explorer\MountPoints2\{74d33dde-8125-11de-b251-000e35b021df}
Shell\1\Command =Recycle.exe
Shell\2\Command =Recycle.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe
HKCU\..\..\Explorer\MountPoints2\{79d389b6-994a-11de-b261-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DXGDIALOG.EXE
HKCU\..\..\Explorer\MountPoints2\{79d389e7-994a-11de-b261-000e35b021df}
Shell\AutoRun\command =H:\d1vmq.exe
Shell\open\Command =H:\d1vmq.exe
HKCU\..\..\Explorer\MountPoints2\{79d389e9-994a-11de-b261-000e35b021df}
Shell\AutoRun\command =H:\d1vmq.exe
Shell\open\Command =H:\d1vmq.exe
HKCU\..\..\Explorer\MountPoints2\{7b5f8881-8a90-11de-b259-000e35b021df}
Shell\AutoRun\command =I:\zPharaoh.exe
Shell\explore\command =I:\zPharaoh.exe
Shell\open\command =I:\zPharaoh.exe
HKCU\..\..\Explorer\MountPoints2\{93507310-841b-11de-b252-000e35b021df}
Shell\AutoRun\command =H:\AutoRun.exe
HKCU\..\..\Explorer\MountPoints2\{9482ab31-7f74-11de-b24f-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DXGDIALOG.EXE
HKCU\..\..\Explorer\MountPoints2\{969c7eab-5460-11de-86d6-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DXGDIALOG.EXE
HKCU\..\..\Explorer\MountPoints2\{969c7eb0-5460-11de-86d6-000e35b021df}
Shell\AutoRun\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
Shell\open\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
HKCU\..\..\Explorer\MountPoints2\{a130e8f4-5c11-11de-86d9-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{a91c5b93-8bee-11de-b25c-000e35b021df}
Shell\AutoRun\command =I:\zPharaoh.exe
Shell\explore\command =I:\zPharaoh.exe
Shell\open\command =I:\zPharaoh.exe
HKCU\..\..\Explorer\MountPoints2\{aacc1931-6ef0-11de-86ee-000e35b021df}
Shell\AutoRun\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
Shell\open\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
HKCU\..\..\Explorer\MountPoints2\{b3078752-60b0-11de-86dc-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{c6ae3770-510c-11de-86d2-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{fb5e2c29-cfd5-11de-b283-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =log.exe
################## | Cracks / Keygens / Serials |
"D:\mes logiciel\NOD32.Antivirus.v2.50.41.FR.(Version.Windows_XP_2000_2003_NT).Incl-Crack.par.eMule-Paradise.com\nentfrst.exe"
06/09/2005 11:47 |Size 9990600 |Crc32 430025b2 |Md5 c6443897925597d5c9308ea92e9448a7
"D:\mes logiciel\NOD32.Antivirus.v2.50.41.FR.(Version.Windows_XP_2000_2003_NT).Incl-Crack.par.eMule-Paradise.com\Crack\NOD32.FiX.v1.9-nsane.exe"
06/09/2005 11:51 |Size 302844 |Crc32 f1fe3d20 |Md5 1a5e36204f702a11a73a2f4fcb32b319
"D:\mes logiciel\Nero-7012-FR+ENG+Keygen\nero_7.0.1.2_francais.exe"
24/11/2005 15:49 |Size 111231344 |Crc32 f8217905 |Md5 688266e3fdfbb528bf9f33ba6fab3c38
"D:\mes logiciel\Nero-7012-FR+ENG+Keygen\Keygen.exe"
31/10/2005 23:18 |Size 101888 |Crc32 a4b5f8e3 |Md5 47d56fbab005991cc0a3b3a1d6e5d09e
"D:\mes logiciel\Partition Magic 8 + Crack\Crack.exe"
22/09/2002 05:00 |Size 14518 |Crc32 6fca3494 |Md5 a26056d4e9072ce6d33fe432488cebe5
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\instmsia.exe"
11/03/2002 06:45 |Size 1708856 |Crc32 3ccaccf9 |Md5 43f7305c2e5dd4a8f3c5abeb2ffe4833
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\instmsiw.exe"
11/03/2002 07:06 |Size 1822520 |Crc32 be716ace |Md5 61a5fb191ae2ae876db31dcce75e4183
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\setup.exe"
18/09/2002 05:26 |Size 217088 |Crc32 25bb2048 |Md5 c36de9988d860d5ebefbb3c972a20d8f
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\Tutorial Interactif\PM8Flash.exe"
05/09/2002 14:06 |Size 5890825 |Crc32 d9777504 |Md5 a71e5f690258c7aa692d00dbadf816d1
"D:\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
19/01/2007 14:09 |Size 9657352 |Crc32 fffb9cfd |Md5 ad2eba479fa525b2c4759ce72125630e
"D:\Uvs 10+crack\uvs10_tbyb_(f).exe"
16/09/2006 12:03 |Size 142456841 |Crc32 fefd9bfd |Md5 e1f912bdf97e7635f4a66f6e9d224b4a
"H:\mes docs\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
04/11/2009 13:21 |Size 9657352 |Crc32 1a4c4e20 |Md5 2143123c7c343fb2265cb168566fbaaa
"H:\logiciels et autres\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
04/11/2009 13:32 |Size 9657352 |Crc32 1a4c4e20 |Md5 2143123c7c343fb2265cb168566fbaaa
"H:\logiciels et autres\Uvs 10+crack\uvs10_tbyb_(f).exe"
04/11/2009 13:32 |Size 142456841 |Crc32 178c86d3 |Md5 5ab9d5d7cd77f597c4e35ef4ed2517ef
################## | ! Fin du rapport # UsbFix V6.055 ! |
un scan de mon pc avec UsbFix me donne le rapport suivant. je ne sais malheureusement pas l'interpréter. Ce qui m'a emmené à ce logiciel est l'impossibilité pour moi d'afficher les dossiers de ma clé usb, suite à une infection. alors au secours. merci d'avance.
############################## | UsbFix V6.055 |
User : Alimou Sow (Administrateurs) # LIM-Y075K8FAAUG
Update on 18/11/2009 by Chiquitine29, C_XX & Chimay8
Start at: 17:54:03 | 19/11/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) M processor 1400MHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Disabled
AV : AVG Internet Security 8.5 [ Enabled | Updated ]
FW : AVG Firewall[ Enabled ]8.5
C:\ -> Disque fixe local # 13,97 Go (1,67 Go free) # NTFS
D:\ -> Disque fixe local # 13,96 Go (6,89 Go free) [SOFTS] # FAT32
E:\ -> Disque fixe local # 13,96 Go (6,02 Go free) [PHOTO-VID] # FAT32
F:\ -> Disque fixe local # 13,96 Go (3,83 Go free) [MUSIQUE] # FAT32
G:\ -> Disque CD-ROM
H:\ -> Disque amovible # 7,46 Go (1,75 Go free) [LIM] # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe 1188
C:\WINDOWS\system32\csrss.exe 1236
C:\WINDOWS\system32\winlogon.exe 1260
C:\WINDOWS\system32\services.exe 1304
C:\WINDOWS\system32\lsass.exe 1316
C:\WINDOWS\System32\Ati2evxx.exe 1464
C:\WINDOWS\system32\svchost.exe 1480
C:\WINDOWS\system32\svchost.exe 1580
C:\WINDOWS\System32\svchost.exe 1616
C:\WINDOWS\system32\S24EvMon.exe 1660
C:\WINDOWS\System32\svchost.exe 1716
C:\WINDOWS\System32\svchost.exe 1936
C:\WINDOWS\system32\spoolsv.exe 624
C:\WINDOWS\System32\SCardSvr.exe 680
C:\WINDOWS\System32\svchost.exe 852
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1068
C:\WINDOWS\system32\ZCfgSvc.exe 1108
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 1868
C:\PROGRA~1\AVG\AVG8\avgfws8.exe 224
C:\Program Files\Bonjour\mDNSResponder.exe 252
C:\WINDOWS\system32\Ati2evxx.exe 260
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe 416
C:\WINDOWS\Explorer.EXE 484
C:\WINDOWS\system32\RegSrvc.exe 896
C:\WINDOWS\System32\svchost.exe 1120
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe 1500
C:\Program Files\NCH Swift Sound\WebDictate\webdictate.exe 1648
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 1760
C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe 1852
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe 204
C:\PROGRA~1\AVG\AVG8\avgtray.exe 240
C:\Program Files\Dell\QuickSet\quickset.exe 308
C:\Program Files\SuperCopier2\SuperCopier2.exe 388
C:\Program Files\Windows Live\Messenger\msnmsgr.exe 384
C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE 420
C:\WINDOWS\system32\ctfmon.exe 456
C:\PROGRA~1\AVG\AVG8\avgemc.exe 908
C:\PROGRA~1\AVG\AVG8\avgam.exe 1096
C:\PROGRA~1\AVG\AVG8\avgrsx.exe 1012
C:\PROGRA~1\AVG\AVG8\avgnsx.exe 120
C:\Program Files\AVG\AVG8\avgcsrvx.exe 2880
C:\WINDOWS\system32\wbem\wmiprvse.exe 2944
C:\WINDOWS\System32\alg.exe 3716
C:\WINDOWS\system32\1XConfig.exe 3988
C:\Program Files\Windows Live\Contacts\wlcomm.exe 2904
C:\Program Files\Mozilla Firefox\firefox.exe 2148
C:\WINDOWS\system32\wuauclt.exe 3260
C:\WINDOWS\system32\wuauclt.exe 3784
C:\WINDOWS\system32\wbem\wmiprvse.exe 1980
################## | Fichiers # Dossiers infectieux |
C:\WINDOWS\System32\bycool1
################## | Registre # Clés infectieuses |
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{058698e0-6bc3-11de-86e8-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{4e99597b-c9dc-11de-b27f-000e35b021df}
Shell\AutoRun\command =H:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{5f016cc9-50e5-11de-86d0-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{6b47feb1-621e-11de-86df-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{74d33dd2-8125-11de-b251-000e35b021df}
Shell\AutoRun\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
Shell\open\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
HKCU\..\..\Explorer\MountPoints2\{74d33ddc-8125-11de-b251-000e35b021df}
Shell\1\Command =Recycle.exe
Shell\2\Command =Recycle.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe
HKCU\..\..\Explorer\MountPoints2\{74d33ddd-8125-11de-b251-000e35b021df}
Shell\1\Command =Recycle.exe
Shell\2\Command =Recycle.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe
HKCU\..\..\Explorer\MountPoints2\{74d33dde-8125-11de-b251-000e35b021df}
Shell\1\Command =Recycle.exe
Shell\2\Command =Recycle.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe
HKCU\..\..\Explorer\MountPoints2\{79d389b6-994a-11de-b261-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DXGDIALOG.EXE
HKCU\..\..\Explorer\MountPoints2\{79d389e7-994a-11de-b261-000e35b021df}
Shell\AutoRun\command =H:\d1vmq.exe
Shell\open\Command =H:\d1vmq.exe
HKCU\..\..\Explorer\MountPoints2\{79d389e9-994a-11de-b261-000e35b021df}
Shell\AutoRun\command =H:\d1vmq.exe
Shell\open\Command =H:\d1vmq.exe
HKCU\..\..\Explorer\MountPoints2\{7b5f8881-8a90-11de-b259-000e35b021df}
Shell\AutoRun\command =I:\zPharaoh.exe
Shell\explore\command =I:\zPharaoh.exe
Shell\open\command =I:\zPharaoh.exe
HKCU\..\..\Explorer\MountPoints2\{93507310-841b-11de-b252-000e35b021df}
Shell\AutoRun\command =H:\AutoRun.exe
HKCU\..\..\Explorer\MountPoints2\{9482ab31-7f74-11de-b24f-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DXGDIALOG.EXE
HKCU\..\..\Explorer\MountPoints2\{969c7eab-5460-11de-86d6-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DXGDIALOG.EXE
HKCU\..\..\Explorer\MountPoints2\{969c7eb0-5460-11de-86d6-000e35b021df}
Shell\AutoRun\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
Shell\open\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
HKCU\..\..\Explorer\MountPoints2\{a130e8f4-5c11-11de-86d9-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{a91c5b93-8bee-11de-b25c-000e35b021df}
Shell\AutoRun\command =I:\zPharaoh.exe
Shell\explore\command =I:\zPharaoh.exe
Shell\open\command =I:\zPharaoh.exe
HKCU\..\..\Explorer\MountPoints2\{aacc1931-6ef0-11de-86ee-000e35b021df}
Shell\AutoRun\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
Shell\open\command =H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.iniise.exe
HKCU\..\..\Explorer\MountPoints2\{b3078752-60b0-11de-86dc-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{c6ae3770-510c-11de-86d2-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =H:\log.exe
HKCU\..\..\Explorer\MountPoints2\{fb5e2c29-cfd5-11de-b283-000e35b021df}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL log.exe
Shell\Ouvrir\command =log.exe
################## | Cracks / Keygens / Serials |
"D:\mes logiciel\NOD32.Antivirus.v2.50.41.FR.(Version.Windows_XP_2000_2003_NT).Incl-Crack.par.eMule-Paradise.com\nentfrst.exe"
06/09/2005 11:47 |Size 9990600 |Crc32 430025b2 |Md5 c6443897925597d5c9308ea92e9448a7
"D:\mes logiciel\NOD32.Antivirus.v2.50.41.FR.(Version.Windows_XP_2000_2003_NT).Incl-Crack.par.eMule-Paradise.com\Crack\NOD32.FiX.v1.9-nsane.exe"
06/09/2005 11:51 |Size 302844 |Crc32 f1fe3d20 |Md5 1a5e36204f702a11a73a2f4fcb32b319
"D:\mes logiciel\Nero-7012-FR+ENG+Keygen\nero_7.0.1.2_francais.exe"
24/11/2005 15:49 |Size 111231344 |Crc32 f8217905 |Md5 688266e3fdfbb528bf9f33ba6fab3c38
"D:\mes logiciel\Nero-7012-FR+ENG+Keygen\Keygen.exe"
31/10/2005 23:18 |Size 101888 |Crc32 a4b5f8e3 |Md5 47d56fbab005991cc0a3b3a1d6e5d09e
"D:\mes logiciel\Partition Magic 8 + Crack\Crack.exe"
22/09/2002 05:00 |Size 14518 |Crc32 6fca3494 |Md5 a26056d4e9072ce6d33fe432488cebe5
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\instmsia.exe"
11/03/2002 06:45 |Size 1708856 |Crc32 3ccaccf9 |Md5 43f7305c2e5dd4a8f3c5abeb2ffe4833
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\instmsiw.exe"
11/03/2002 07:06 |Size 1822520 |Crc32 be716ace |Md5 61a5fb191ae2ae876db31dcce75e4183
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\setup.exe"
18/09/2002 05:26 |Size 217088 |Crc32 25bb2048 |Md5 c36de9988d860d5ebefbb3c972a20d8f
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\Tutorial Interactif\PM8Flash.exe"
05/09/2002 14:06 |Size 5890825 |Crc32 d9777504 |Md5 a71e5f690258c7aa692d00dbadf816d1
"D:\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
19/01/2007 14:09 |Size 9657352 |Crc32 fffb9cfd |Md5 ad2eba479fa525b2c4759ce72125630e
"D:\Uvs 10+crack\uvs10_tbyb_(f).exe"
16/09/2006 12:03 |Size 142456841 |Crc32 fefd9bfd |Md5 e1f912bdf97e7635f4a66f6e9d224b4a
"H:\mes docs\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
04/11/2009 13:21 |Size 9657352 |Crc32 1a4c4e20 |Md5 2143123c7c343fb2265cb168566fbaaa
"H:\logiciels et autres\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
04/11/2009 13:32 |Size 9657352 |Crc32 1a4c4e20 |Md5 2143123c7c343fb2265cb168566fbaaa
"H:\logiciels et autres\Uvs 10+crack\uvs10_tbyb_(f).exe"
04/11/2009 13:32 |Size 142456841 |Crc32 178c86d3 |Md5 5ab9d5d7cd77f597c4e35ef4ed2517ef
################## | ! Fin du rapport # UsbFix V6.055 ! |
4 réponses
Bonjour,
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur UsbFix présent sur ton Bureau.
--> Choisis l'option 2 (Suppression).
--> Ton Bureau disparaîtra et le PC redémarrera.
--> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.
--> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur UsbFix présent sur ton Bureau.
--> Choisis l'option 2 (Suppression).
--> Ton Bureau disparaîtra et le PC redémarrera.
--> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.
--> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
--> Relance UsbFix et choisis l'option 5 pour le désinstaller.
--> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
--> Double-clique sur RSIT.exe afin de lancer le programme.
(Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
--> Clique sur Continue à l'écran Disclaimer.
--> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
--> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : les rapports sont sauvegardés dans le dossier C:\rsit.
--> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
--> Double-clique sur RSIT.exe afin de lancer le programme.
(Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
--> Clique sur Continue à l'écran Disclaimer.
--> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
--> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : les rapports sont sauvegardés dans le dossier C:\rsit.
merci voici les 2 rapports:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Alimou Sow at 2009-11-19 18:39:29
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 2 GB (12%) free of 14 GB
Total RAM: 511 MB (12% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Maintenance en 1 clic.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2009-03-13 908528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-06-29 94308]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-08-15 1111320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-09-02 1107200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2db4fe6-8409-45ce-8010-189a7b5cce86}]
NCH Toolbar - C:\Program Files\NCH\tbNC1.dll [2009-11-19 2166296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-16 163840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2009-03-13 165616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-09-02 1107200]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2009-03-13 908528]
{c2db4fe6-8409-45ce-8010-189a7b5cce86} - NCH Toolbar - C:\Program Files\NCH\tbNC1.dll [2009-11-19 2166296]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2003-07-29 335872]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-10-31 2025752]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2007-05-14 1191936]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=C:\Program Files\SuperCopier2\SuperCopier2.exe [2005-03-13 1057280]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"L08FXLRD_83639266"=C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE [2007-06-12 351000]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a²]
C:\Program Files\a2\a2guard.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\FlashGet.exe [2007-06-29 1990704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe [2003-12-19 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="MsgPlusLoader.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2003-07-29 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-08-15 11952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]
c:\WINDOWS\system32\LgNotify.dll [2004-01-13 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=145
"HonorAutoRunSetting"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\FlashGet\flashget.exe"="C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
======List of files/folders created in the last 1 months======
2009-11-19 18:39:36 ----DC---- C:\Program Files\trend micro
2009-11-19 18:39:29 ----DC---- C:\rsit
2009-11-19 18:22:14 ----RASHDC---- C:\autorun.inf
2009-11-19 17:50:23 ----DC---- C:\UsbFix
2009-11-14 07:48:06 ----DC---- C:\Program Files\Nero
2009-11-14 07:48:06 ----DC---- C:\Program Files\Fichiers communs\Ahead
2009-11-07 18:09:58 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\U3
2009-11-05 19:04:23 ----AC---- C:\WINDOWS\Multimedia manager.INI
2009-11-05 18:37:07 ----DC---- C:\ConvertTemp
2009-11-05 18:28:05 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\Samsung
2009-11-05 18:22:38 ----AC---- C:\WINDOWS\system32\framedyn.dll
2009-11-05 18:21:40 ----DC---- C:\WINDOWS\system32\Samsung_USB_Drivers
2009-11-05 18:20:54 ----DC---- C:\Program Files\Samsung
2009-10-31 10:01:34 ----AC---- C:\Documents and Settings\Alimou Sow\Application Data\FrameFun.ini
2009-10-31 10:00:38 ----DC---- C:\Program Files\FrameFun
======List of files/folders modified in the last 1 months======
2009-11-19 18:39:36 ----RDC---- C:\Program Files
2009-11-19 18:38:24 ----DC---- C:\Program Files\FlashGet
2009-11-19 18:38:18 ----DC---- C:\Downloads
2009-11-19 18:27:16 ----DC---- C:\WINDOWS\Prefetch
2009-11-19 18:26:57 ----DC---- C:\Program Files\Mozilla Firefox
2009-11-19 18:25:09 ----DC---- C:\Program Files\NCH
2009-11-19 18:23:48 ----DC---- C:\WINDOWS\Temp
2009-11-19 18:22:09 ----SHDC---- C:\RECYCLER
2009-11-19 18:20:58 ----DC---- C:\WINDOWS
2009-11-19 18:20:00 ----DC---- C:\WINDOWS\system32
2009-11-19 18:16:52 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-19 14:31:46 ----AC---- C:\WINDOWS\NeroDigital.ini
2009-11-18 20:30:30 ----DC---- C:\WINDOWS\system32\CatRoot2
2009-11-17 11:24:03 ----HDC---- C:\WINDOWS\inf
2009-11-17 11:18:53 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-17 11:01:20 ----DC---- C:\WINDOWS\Help
2009-11-15 12:05:09 ----HDC---- C:\$AVG8.VAULT$
2009-11-14 07:51:57 ----SHDC---- C:\WINDOWS\Installer
2009-11-14 07:51:43 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\Ahead
2009-11-14 07:49:44 ----DC---- C:\WINDOWS\system32\drivers
2009-11-14 07:48:06 ----DC---- C:\Program Files\Fichiers communs
2009-11-14 07:28:08 ----DC---- C:\Documents and Settings\All Users\Application Data\Nero
2009-11-14 07:25:17 ----AC---- C:\WINDOWS\system32\MsiExec.exe.log
2009-11-11 18:53:39 ----DC---- C:\WINDOWS\Minidump
2009-11-07 21:50:28 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\Audacity
2009-11-07 15:28:47 ----DC---- C:\Program Files\EDGE
2009-11-07 15:28:31 ----AC---- C:\WINDOWS\ModemLog_ZTE GSM USB Modem.txt
2009-11-05 18:25:08 ----DC---- C:\Program Files\Fichiers communs\Adobe
2009-11-05 18:20:54 ----HDC---- C:\Program Files\InstallShield Installation Information
2009-11-02 15:45:32 ----HDC---- C:\WINDOWS\$hf_mig$
2009-10-30 07:46:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-10-30 07:46:47 ----DC---- C:\Program Files\iPod
2009-10-30 07:26:50 ----DC---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-10-21 18:14:05 ----DC---- C:\Program Files\Microsoft Etudes
2009-10-21 18:13:54 ----SDC---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-21 18:13:54 ----DC---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-10-21 18:10:47 ----RSDC---- C:\WINDOWS\assembly
2009-10-21 18:10:47 ----DC---- C:\WINDOWS\system32\DirectX
2009-10-21 18:09:22 ----DC---- C:\Program Files\NCH Swift Sound
2009-10-21 18:07:15 ----DC---- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-08-15 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-08-15 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-07-14 108552]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 40576]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.2.1.0; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2009-06-03 14037]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2003-09-15 11258]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2003-08-21 94600]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2003-07-29 587264]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-07-14 29208]
R3 b57w2k;Broadcom 570x Gigabit Integrated Controller; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2003-05-21 175360]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-07-03 1063936]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2003-07-03 189056]
R3 O2SCBUS;O2Micro SmartCardBus Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2003-12-11 91395]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2004-04-01 10368]
R3 STAC97;Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\STAC97.sys [2003-04-25 220176]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w22n51;Pilote Intel(R) PRO/Wireless 2200 Adapter; C:\WINDOWS\system32\DRIVERS\w22n51.sys [2004-01-14 1648640]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-07-03 631680]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-07-14 29208]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SRS_SSCFilter;SRS Labs Audio Sandbox (WDM); C:\WINDOWS\system32\drivers\srs_sscfilter_i386.sys [2007-07-26 39808]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-09-05 36864]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbvideo;Périphérique vidéo USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZTEGsmDataCard;ZTE USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\zteusbgser.sys [2008-12-15 104704]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Pilote de filtre de restauration système; C:\WINDOWS\System32\DRIVERS\sr.sys [2008-04-13 73600]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-05 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2003-07-29 323584]
R2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-08-15 908056]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-08-15 297752]
R2 avgfws8;AVG8 Firewall; C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2009-08-15 1370488]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 DialDictateService;Dial Dictate; C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe [2009-09-19 880644]
R2 NICCONFIGSVC;NICCONFIGSVC; C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [2007-05-14 475136]
R2 RegSrvc;RegSrvc; C:\WINDOWS\system32\RegSrvc.exe [2004-01-13 122880]
R2 S24EventMonitor;Spectrum24 Event Monitor; C:\WINDOWS\system32\S24EvMon.exe [2004-01-13 311363]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe [2005-01-31 49152]
R2 UxTuneUp;Extension de conception TuneUp; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 WebDictateService;Web Dictate; C:\Program Files\NCH Swift Sound\WebDictate\webdictate.exe [2009-09-19 589828]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2009-11-19 18:39:49
======Uninstall list======
-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->MsiExec.exe /I{0F122737-72B2-4095-8B3E-7AAE753DFD3D}
-->MsiExec.exe /I{B5D8CCBF-08D8-46C0-8B04-3BC0CAEDA094}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
ALPS Touch Pad Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.exe" UNINSTALL
Apple Mobile Device Support-->MsiExec.exe /I{C7C895CA-331B-4D7D-A0FB-D3BC637949F9}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Ashampoo MP3 AudioCenter-->C:\PROGRA~1\Ashampoo\ASHAMP~1\UNWISE.EXE C:\PROGRA~1\Ashampoo\ASHAMP~1\AUCN_INSTALL.LOG
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Audacity 1.3.7 (Unicode)-->"C:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
Audio Comparer-->"C:\Program Files\AudioComparer\unins000.exe"
AVG 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Broadcom Gigabit Integrated Controller-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BE6890C7-31EF-478C-812E-1E2899ABFCA9} /l1036
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
CommentCaMarche 2.0.6-->"C:\Program Files\CommentCaMarche\unins000.exe"
Complément Microsoft Enregistrer en tant que PDF ou XPS pour programmes Microsoft Office 2007-->MsiExec.exe /X{90120000-00B2-040C-0000-0000000FF1CE}
Conexant D480 MDC V.9x Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1\HXFSETUP.EXE -U -Idel5422k.inf
Dell ResourceCD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Dial Dictate-->C:\Program Files\NCH Swift Sound\DialDictate\uninst.exe
EDGE USB MODEM-->"C:\Program Files\InstallShield Installation Information\{C5C38AA6-C887-4B31-8B76-77C1CC40FFC7}\setup.exe" -runfromtemp -l0x040c -removeonly
Express Dictate-->C:\Program Files\NCH Swift Sound\Express\uninst.exe
Express Scribe-->C:\Program Files\NCH Swift Sound\Scribe\uninst.exe
FastFox-->C:\Program Files\NCH Swift Sound\FastFox\uninst.exe
FlashGet 1.9.0.1012-->C:\Program Files\FlashGet\uninst.exe
FrameFun 2.0.0.7-->"C:\Program Files\FrameFun\unins000.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Intel(R) mDriver-->MsiExec.exe /I{DDD512C6-2251-4046-8F25-1A5EB355015E}
Intel(R) PROSet for Wireless-->MsiExec.exe /I{5380063E-2909-4d72-BFA3-625881F2E78B}
Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
KeyBlaze Typing Tutor-->C:\Program Files\NCH Software\KeyBlaze\uninst.exe
L&H Power Translator Pro 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\LHSP\L&H Power Translator Pro\Uninst.isu" -c"C:\Program Files\LHSP\L&H Power Translator Pro\Uninstall.dll"
LAME v3.98.2 for Audacity-->"C:\Program Files\Lame for Audacity\unins000.exe"
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Les Indispensables Éducation pour Microsoft Office-->MsiExec.exe /X{75F3A4B2-F6E8-434D-A2EF-DBBC016C6CB2}
Messenger Plus! 3-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Calculatrice Plus-->MsiExec.exe /I{13922F10-BD74-4912-AB11-E34B35062700}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Encarta 2008 - Études-->MsiExec.exe /I{08181881-FCA5-44A7-B863-D66037A16AAF}
Microsoft Encarta Maths-->MsiExec.exe /I{07183840-959A-4B0D-8825-2C533F0DDB19}
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Mise à jour pour Windows Internet Explorer 8 (KB971930)-->"C:\WINDOWS\ie8updates\KB971930-IE8\spuninst\spuninst.exe"
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
Mozilla Firefox (3.5.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB927977)-->MsiExec.exe /I{5A710547-B58E-488B-828D-CA9A25A0533C}
NCH Toolbar-->C:\PROGRA~1\NCH\UNWISE.EXE /U C:\PROGRA~1\NCH\INSTALL.LOG
Nero 7 Demo-->MsiExec.exe /I{C985153C-3801-EB63-1432-088E71801036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
O2Micro Smartcard Driver-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{E1547FCE-F5DD-4D77-8C71-13B6A2B8F527} /l1033
Onglet Commencer de Microsoft Office Word 2007-->MsiExec.exe /I{68B52EFD-86CC-486E-A8D0-A3A1554CB5BC}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
Pilotes Audio SigmaTel AC97-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7959721D-8268-4565-9E0E-C41A9F4848A9}\setup.exe" -l0x40c -nodialog -uninstall
QuickSet-->C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe -runfromtemp -l0x040c APPDRVNT4 -removeonly
QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083} /l1036
SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
SmartSound Quicktracks Plugin-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
Tap'Touche 5-->"C:\Program Files\Tap'Touche 5\désinstaller.exe"
TOEFL POWERPREP-->C:\WINDOWS\IsUninst.exe -fC:\ETS\PPTOEFL.ISU
Total Video Converter 3.10-->"C:\Program Files\Total Video Converter\unins000.exe"
TuneUp Utilities 2007-->MsiExec.exe /I{C8BB4912-12D9-42AE-B571-E580D8CD1B5B}
Ulead VideoStudio 10-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E188D820-1218-4E28-8BCA-91134C3664C2}\setup.exe" -l0x40c
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Outlook 2007 Junk Email Filter (kb973514)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {03B11C77-336F-43B4-9B43-79890BA84504}
VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
WBEncarta-->RunDll32.exe advpack.dll, LaunchINFSectionEx C:\Program Files\Learning Essentials\1.0\fr\FR\WBEncarta\Uninstall\Uninstall.inf,Uninstall,,,N
Web Dictate-->C:\Program Files\NCH Swift Sound\WebDictate\uninst.exe
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Search Protection-->C:\PROGRA~1\Yahoo!\SEARCH~1\UNINST~1.EXE
Yahoo! Software Update-->C:\PROGRA~1\Yahoo!\SOFTWA~1\UNINST~1.EXE
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
======Security center information======
AV: AVG Internet Security
FW: AVG Firewall
======System event log======
Computer Name: LIM-Y075K8FAAUG
Event Code: 4202
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{1A056EE7-A2D0-46D0-B74B-6E55DD92763A} était déconnectée du réseau,
et la configuration réseau de la carte a été abandonnée. Si la carte
réseau n'était pas déconnectée, ceci peut indiquer un disfonctionnement.
Contactez le fabricant pour des pilotes mis à jour.
Record Number: 3998
Source Name: Tcpip
Time Written: 20090908080204.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1003
Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir
du serveur DHCP) pour la carte réseau dont l'adresse réseau est 000E35B021DF. Il s'est
produit l'erreur suivante :
L'opération a été annulée par l'utilisateur.
.
Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du
serveur d'adresse réseau (DHCP).
Record Number: 3997
Source Name: Dhcp
Time Written: 20090908080157.000000+000
Event Type: Avertissement
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 7036
Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.
Record Number: 3996
Source Name: Service Control Manager
Time Written: 20090907130642.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.
Record Number: 3995
Source Name: Service Control Manager
Time Written: 20090907130637.000000+000
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: LIM-Y075K8FAAUG
Event Code: 7036
Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.
Record Number: 3994
Source Name: Service Control Manager
Time Written: 20090907130637.000000+000
Event Type: Informations
User:
=====Application event log=====
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1031
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1030
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1029
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1028
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1027
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Samsung\Samsung PC Studio 3\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 9 Stepping 5, GenuineIntel
"PROCESSOR_REVISION"=0905
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Alimou Sow at 2009-11-19 18:39:29
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 2 GB (12%) free of 14 GB
Total RAM: 511 MB (12% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Maintenance en 1 clic.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2009-03-13 908528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-06-29 94308]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-08-15 1111320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-09-02 1107200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2db4fe6-8409-45ce-8010-189a7b5cce86}]
NCH Toolbar - C:\Program Files\NCH\tbNC1.dll [2009-11-19 2166296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-16 163840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2009-03-13 165616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-09-02 1107200]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2009-03-13 908528]
{c2db4fe6-8409-45ce-8010-189a7b5cce86} - NCH Toolbar - C:\Program Files\NCH\tbNC1.dll [2009-11-19 2166296]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2003-07-29 335872]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-10-31 2025752]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2007-05-14 1191936]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=C:\Program Files\SuperCopier2\SuperCopier2.exe [2005-03-13 1057280]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"L08FXLRD_83639266"=C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE [2007-06-12 351000]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a²]
C:\Program Files\a2\a2guard.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\FlashGet.exe [2007-06-29 1990704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe [2003-12-19 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="MsgPlusLoader.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2003-07-29 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-08-15 11952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]
c:\WINDOWS\system32\LgNotify.dll [2004-01-13 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=145
"HonorAutoRunSetting"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\FlashGet\flashget.exe"="C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
======List of files/folders created in the last 1 months======
2009-11-19 18:39:36 ----DC---- C:\Program Files\trend micro
2009-11-19 18:39:29 ----DC---- C:\rsit
2009-11-19 18:22:14 ----RASHDC---- C:\autorun.inf
2009-11-19 17:50:23 ----DC---- C:\UsbFix
2009-11-14 07:48:06 ----DC---- C:\Program Files\Nero
2009-11-14 07:48:06 ----DC---- C:\Program Files\Fichiers communs\Ahead
2009-11-07 18:09:58 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\U3
2009-11-05 19:04:23 ----AC---- C:\WINDOWS\Multimedia manager.INI
2009-11-05 18:37:07 ----DC---- C:\ConvertTemp
2009-11-05 18:28:05 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\Samsung
2009-11-05 18:22:38 ----AC---- C:\WINDOWS\system32\framedyn.dll
2009-11-05 18:21:40 ----DC---- C:\WINDOWS\system32\Samsung_USB_Drivers
2009-11-05 18:20:54 ----DC---- C:\Program Files\Samsung
2009-10-31 10:01:34 ----AC---- C:\Documents and Settings\Alimou Sow\Application Data\FrameFun.ini
2009-10-31 10:00:38 ----DC---- C:\Program Files\FrameFun
======List of files/folders modified in the last 1 months======
2009-11-19 18:39:36 ----RDC---- C:\Program Files
2009-11-19 18:38:24 ----DC---- C:\Program Files\FlashGet
2009-11-19 18:38:18 ----DC---- C:\Downloads
2009-11-19 18:27:16 ----DC---- C:\WINDOWS\Prefetch
2009-11-19 18:26:57 ----DC---- C:\Program Files\Mozilla Firefox
2009-11-19 18:25:09 ----DC---- C:\Program Files\NCH
2009-11-19 18:23:48 ----DC---- C:\WINDOWS\Temp
2009-11-19 18:22:09 ----SHDC---- C:\RECYCLER
2009-11-19 18:20:58 ----DC---- C:\WINDOWS
2009-11-19 18:20:00 ----DC---- C:\WINDOWS\system32
2009-11-19 18:16:52 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-19 14:31:46 ----AC---- C:\WINDOWS\NeroDigital.ini
2009-11-18 20:30:30 ----DC---- C:\WINDOWS\system32\CatRoot2
2009-11-17 11:24:03 ----HDC---- C:\WINDOWS\inf
2009-11-17 11:18:53 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-17 11:01:20 ----DC---- C:\WINDOWS\Help
2009-11-15 12:05:09 ----HDC---- C:\$AVG8.VAULT$
2009-11-14 07:51:57 ----SHDC---- C:\WINDOWS\Installer
2009-11-14 07:51:43 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\Ahead
2009-11-14 07:49:44 ----DC---- C:\WINDOWS\system32\drivers
2009-11-14 07:48:06 ----DC---- C:\Program Files\Fichiers communs
2009-11-14 07:28:08 ----DC---- C:\Documents and Settings\All Users\Application Data\Nero
2009-11-14 07:25:17 ----AC---- C:\WINDOWS\system32\MsiExec.exe.log
2009-11-11 18:53:39 ----DC---- C:\WINDOWS\Minidump
2009-11-07 21:50:28 ----DC---- C:\Documents and Settings\Alimou Sow\Application Data\Audacity
2009-11-07 15:28:47 ----DC---- C:\Program Files\EDGE
2009-11-07 15:28:31 ----AC---- C:\WINDOWS\ModemLog_ZTE GSM USB Modem.txt
2009-11-05 18:25:08 ----DC---- C:\Program Files\Fichiers communs\Adobe
2009-11-05 18:20:54 ----HDC---- C:\Program Files\InstallShield Installation Information
2009-11-02 15:45:32 ----HDC---- C:\WINDOWS\$hf_mig$
2009-10-30 07:46:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-10-30 07:46:47 ----DC---- C:\Program Files\iPod
2009-10-30 07:26:50 ----DC---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-10-21 18:14:05 ----DC---- C:\Program Files\Microsoft Etudes
2009-10-21 18:13:54 ----SDC---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-21 18:13:54 ----DC---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-10-21 18:10:47 ----RSDC---- C:\WINDOWS\assembly
2009-10-21 18:10:47 ----DC---- C:\WINDOWS\system32\DirectX
2009-10-21 18:09:22 ----DC---- C:\Program Files\NCH Swift Sound
2009-10-21 18:07:15 ----DC---- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-08-15 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-08-15 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-07-14 108552]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 40576]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.2.1.0; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2009-06-03 14037]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2003-09-15 11258]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2003-08-21 94600]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2003-07-29 587264]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-07-14 29208]
R3 b57w2k;Broadcom 570x Gigabit Integrated Controller; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2003-05-21 175360]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-07-03 1063936]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2003-07-03 189056]
R3 O2SCBUS;O2Micro SmartCardBus Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2003-12-11 91395]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2004-04-01 10368]
R3 STAC97;Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\STAC97.sys [2003-04-25 220176]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w22n51;Pilote Intel(R) PRO/Wireless 2200 Adapter; C:\WINDOWS\system32\DRIVERS\w22n51.sys [2004-01-14 1648640]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-07-03 631680]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-07-14 29208]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SRS_SSCFilter;SRS Labs Audio Sandbox (WDM); C:\WINDOWS\system32\drivers\srs_sscfilter_i386.sys [2007-07-26 39808]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-09-05 36864]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbvideo;Périphérique vidéo USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZTEGsmDataCard;ZTE USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\zteusbgser.sys [2008-12-15 104704]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Pilote de filtre de restauration système; C:\WINDOWS\System32\DRIVERS\sr.sys [2008-04-13 73600]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-05 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2003-07-29 323584]
R2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-08-15 908056]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-08-15 297752]
R2 avgfws8;AVG8 Firewall; C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2009-08-15 1370488]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 DialDictateService;Dial Dictate; C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe [2009-09-19 880644]
R2 NICCONFIGSVC;NICCONFIGSVC; C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [2007-05-14 475136]
R2 RegSrvc;RegSrvc; C:\WINDOWS\system32\RegSrvc.exe [2004-01-13 122880]
R2 S24EventMonitor;Spectrum24 Event Monitor; C:\WINDOWS\system32\S24EvMon.exe [2004-01-13 311363]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe [2005-01-31 49152]
R2 UxTuneUp;Extension de conception TuneUp; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 WebDictateService;Web Dictate; C:\Program Files\NCH Swift Sound\WebDictate\webdictate.exe [2009-09-19 589828]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2009-11-19 18:39:49
======Uninstall list======
-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->MsiExec.exe /I{0F122737-72B2-4095-8B3E-7AAE753DFD3D}
-->MsiExec.exe /I{B5D8CCBF-08D8-46C0-8B04-3BC0CAEDA094}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
ALPS Touch Pad Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.exe" UNINSTALL
Apple Mobile Device Support-->MsiExec.exe /I{C7C895CA-331B-4D7D-A0FB-D3BC637949F9}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Ashampoo MP3 AudioCenter-->C:\PROGRA~1\Ashampoo\ASHAMP~1\UNWISE.EXE C:\PROGRA~1\Ashampoo\ASHAMP~1\AUCN_INSTALL.LOG
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Audacity 1.3.7 (Unicode)-->"C:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
Audio Comparer-->"C:\Program Files\AudioComparer\unins000.exe"
AVG 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Broadcom Gigabit Integrated Controller-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BE6890C7-31EF-478C-812E-1E2899ABFCA9} /l1036
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
CommentCaMarche 2.0.6-->"C:\Program Files\CommentCaMarche\unins000.exe"
Complément Microsoft Enregistrer en tant que PDF ou XPS pour programmes Microsoft Office 2007-->MsiExec.exe /X{90120000-00B2-040C-0000-0000000FF1CE}
Conexant D480 MDC V.9x Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1\HXFSETUP.EXE -U -Idel5422k.inf
Dell ResourceCD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Dial Dictate-->C:\Program Files\NCH Swift Sound\DialDictate\uninst.exe
EDGE USB MODEM-->"C:\Program Files\InstallShield Installation Information\{C5C38AA6-C887-4B31-8B76-77C1CC40FFC7}\setup.exe" -runfromtemp -l0x040c -removeonly
Express Dictate-->C:\Program Files\NCH Swift Sound\Express\uninst.exe
Express Scribe-->C:\Program Files\NCH Swift Sound\Scribe\uninst.exe
FastFox-->C:\Program Files\NCH Swift Sound\FastFox\uninst.exe
FlashGet 1.9.0.1012-->C:\Program Files\FlashGet\uninst.exe
FrameFun 2.0.0.7-->"C:\Program Files\FrameFun\unins000.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Intel(R) mDriver-->MsiExec.exe /I{DDD512C6-2251-4046-8F25-1A5EB355015E}
Intel(R) PROSet for Wireless-->MsiExec.exe /I{5380063E-2909-4d72-BFA3-625881F2E78B}
Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
KeyBlaze Typing Tutor-->C:\Program Files\NCH Software\KeyBlaze\uninst.exe
L&H Power Translator Pro 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\LHSP\L&H Power Translator Pro\Uninst.isu" -c"C:\Program Files\LHSP\L&H Power Translator Pro\Uninstall.dll"
LAME v3.98.2 for Audacity-->"C:\Program Files\Lame for Audacity\unins000.exe"
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Les Indispensables Éducation pour Microsoft Office-->MsiExec.exe /X{75F3A4B2-F6E8-434D-A2EF-DBBC016C6CB2}
Messenger Plus! 3-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Calculatrice Plus-->MsiExec.exe /I{13922F10-BD74-4912-AB11-E34B35062700}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Encarta 2008 - Études-->MsiExec.exe /I{08181881-FCA5-44A7-B863-D66037A16AAF}
Microsoft Encarta Maths-->MsiExec.exe /I{07183840-959A-4B0D-8825-2C533F0DDB19}
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Mise à jour pour Windows Internet Explorer 8 (KB971930)-->"C:\WINDOWS\ie8updates\KB971930-IE8\spuninst\spuninst.exe"
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
Mozilla Firefox (3.5.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB927977)-->MsiExec.exe /I{5A710547-B58E-488B-828D-CA9A25A0533C}
NCH Toolbar-->C:\PROGRA~1\NCH\UNWISE.EXE /U C:\PROGRA~1\NCH\INSTALL.LOG
Nero 7 Demo-->MsiExec.exe /I{C985153C-3801-EB63-1432-088E71801036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
O2Micro Smartcard Driver-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{E1547FCE-F5DD-4D77-8C71-13B6A2B8F527} /l1033
Onglet Commencer de Microsoft Office Word 2007-->MsiExec.exe /I{68B52EFD-86CC-486E-A8D0-A3A1554CB5BC}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
Pilotes Audio SigmaTel AC97-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7959721D-8268-4565-9E0E-C41A9F4848A9}\setup.exe" -l0x40c -nodialog -uninstall
QuickSet-->C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe -runfromtemp -l0x040c APPDRVNT4 -removeonly
QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083} /l1036
SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
SmartSound Quicktracks Plugin-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
Tap'Touche 5-->"C:\Program Files\Tap'Touche 5\désinstaller.exe"
TOEFL POWERPREP-->C:\WINDOWS\IsUninst.exe -fC:\ETS\PPTOEFL.ISU
Total Video Converter 3.10-->"C:\Program Files\Total Video Converter\unins000.exe"
TuneUp Utilities 2007-->MsiExec.exe /I{C8BB4912-12D9-42AE-B571-E580D8CD1B5B}
Ulead VideoStudio 10-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E188D820-1218-4E28-8BCA-91134C3664C2}\setup.exe" -l0x40c
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Outlook 2007 Junk Email Filter (kb973514)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {03B11C77-336F-43B4-9B43-79890BA84504}
VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
WBEncarta-->RunDll32.exe advpack.dll, LaunchINFSectionEx C:\Program Files\Learning Essentials\1.0\fr\FR\WBEncarta\Uninstall\Uninstall.inf,Uninstall,,,N
Web Dictate-->C:\Program Files\NCH Swift Sound\WebDictate\uninst.exe
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Search Protection-->C:\PROGRA~1\Yahoo!\SEARCH~1\UNINST~1.EXE
Yahoo! Software Update-->C:\PROGRA~1\Yahoo!\SOFTWA~1\UNINST~1.EXE
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
======Security center information======
AV: AVG Internet Security
FW: AVG Firewall
======System event log======
Computer Name: LIM-Y075K8FAAUG
Event Code: 4202
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{1A056EE7-A2D0-46D0-B74B-6E55DD92763A} était déconnectée du réseau,
et la configuration réseau de la carte a été abandonnée. Si la carte
réseau n'était pas déconnectée, ceci peut indiquer un disfonctionnement.
Contactez le fabricant pour des pilotes mis à jour.
Record Number: 3998
Source Name: Tcpip
Time Written: 20090908080204.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1003
Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir
du serveur DHCP) pour la carte réseau dont l'adresse réseau est 000E35B021DF. Il s'est
produit l'erreur suivante :
L'opération a été annulée par l'utilisateur.
.
Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du
serveur d'adresse réseau (DHCP).
Record Number: 3997
Source Name: Dhcp
Time Written: 20090908080157.000000+000
Event Type: Avertissement
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 7036
Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.
Record Number: 3996
Source Name: Service Control Manager
Time Written: 20090907130642.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.
Record Number: 3995
Source Name: Service Control Manager
Time Written: 20090907130637.000000+000
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: LIM-Y075K8FAAUG
Event Code: 7036
Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.
Record Number: 3994
Source Name: Service Control Manager
Time Written: 20090907130637.000000+000
Event Type: Informations
User:
=====Application event log=====
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1031
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1030
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1029
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1028
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
Computer Name: LIM-Y075K8FAAUG
Event Code: 1904
Message:
Record Number: 1027
Source Name: HHCTRL
Time Written: 20090910091630.000000+000
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Samsung\Samsung PC Studio 3\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 9 Stepping 5, GenuineIntel
"PROCESSOR_REVISION"=0905
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
-----------------EOF-----------------
Tu te sers de NCH Toolbar ?
La version 9 d'AVG est disponible.
La version 9 d'AVG est disponible.
en fait j'ai avg pro, à jour en plus. mais lorsque je scanne le pc ou la clé, il me dit qu'elle est clean! en fait au début il a détecté des virus et les a surpprimés. mais depuis lors je ne peux afficher sur la clé que les fichiers qui n'étaient pas ds un dossier. tous les autres dossiers sont masqués. je les vois. alors que pendant le scan, ils sont repérés par AVG. suis allé ds outils affiché les fichiers cachés, rien a faire toujours "cachés", et ça me casse le moral grave. merci encore.
Ok.
NCH Toolbar, ça te dit quelque chose ?
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
NCH Toolbar, ça te dit quelque chose ?
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
############################## | UsbFix V6.055 |
User : Alimou Sow (Administrateurs) # LIM-Y075K8FAAUG
Update on 18/11/2009 by Chiquitine29, C_XX & Chimay8
Start at: 18:19:49 | 19/11/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) M processor 1400MHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Disabled
AV : AVG Internet Security 8.5 [ Enabled | Updated ]
FW : AVG Firewall[ Enabled ]8.5
C:\ -> Disque fixe local # 13,97 Go (1,65 Go free) # NTFS
D:\ -> Disque fixe local # 13,96 Go (6,89 Go free) [SOFTS] # FAT32
E:\ -> Disque fixe local # 13,96 Go (6,02 Go free) [PHOTO-VID] # FAT32
F:\ -> Disque fixe local # 13,96 Go (3,83 Go free) [MUSIQUE] # FAT32
G:\ -> Disque CD-ROM
H:\ -> Disque amovible # 7,46 Go (1,75 Go free) [LIM] # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe 1184
C:\WINDOWS\system32\csrss.exe 1232
C:\WINDOWS\system32\winlogon.exe 1256
C:\WINDOWS\system32\services.exe 1300
C:\WINDOWS\system32\lsass.exe 1312
C:\WINDOWS\System32\Ati2evxx.exe 1460
C:\WINDOWS\system32\svchost.exe 1476
C:\WINDOWS\system32\svchost.exe 1588
C:\WINDOWS\System32\svchost.exe 1632
C:\WINDOWS\system32\S24EvMon.exe 1668
C:\WINDOWS\System32\svchost.exe 1740
C:\WINDOWS\System32\svchost.exe 1936
C:\WINDOWS\system32\spoolsv.exe 432
C:\WINDOWS\System32\SCardSvr.exe 476
C:\WINDOWS\system32\ZCfgSvc.exe 840
C:\WINDOWS\system32\Ati2evxx.exe 1216
C:\WINDOWS\system32\WgaTray.exe 1516
C:\WINDOWS\Explorer.EXE 1488
C:\WINDOWS\System32\svchost.exe 132
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 168
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 248
C:\PROGRA~1\AVG\AVG8\avgfws8.exe 236
C:\Program Files\Bonjour\mDNSResponder.exe 308
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe 1964
C:\WINDOWS\system32\RegSrvc.exe 740
C:\WINDOWS\System32\svchost.exe 1220
C:\PROGRA~1\AVG\AVG8\avgam.exe 620
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe 636
C:\Program Files\NCH Swift Sound\WebDictate\webdictate.exe 680
C:\PROGRA~1\AVG\AVG8\avgrsx.exe 728
C:\PROGRA~1\AVG\AVG8\avgnsx.exe 760
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 776
C:\PROGRA~1\AVG\AVG8\avgemc.exe 952
C:\Program Files\NCH Swift Sound\DialDictate\dialdictate.exe 1148
C:\WINDOWS\system32\wuauclt.exe 2200
C:\Program Files\AVG\AVG8\avgcsrvx.exe 2400
C:\WINDOWS\system32\wbem\wmiprvse.exe 2844
C:\WINDOWS\System32\alg.exe 3048
C:\WINDOWS\system32\wbem\wmiprvse.exe 3128
C:\WINDOWS\system32\1XConfig.exe 3684
################## | Fichiers # Dossiers infectieux |
Supprimé ! C:\WINDOWS\System32\bycool1
################## | Registre # Clés infectieuses |
Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{058698e0-6bc3-11de-86e8-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4e99597b-c9dc-11de-b27f-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{5f016cc9-50e5-11de-86d0-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{6b47feb1-621e-11de-86df-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{74d33dd2-8125-11de-b251-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{74d33ddc-8125-11de-b251-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{74d33ddd-8125-11de-b251-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{74d33dde-8125-11de-b251-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{79d389b6-994a-11de-b261-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{79d389e7-994a-11de-b261-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{79d389e9-994a-11de-b261-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{7b5f8881-8a90-11de-b259-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{93507310-841b-11de-b252-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{9482ab31-7f74-11de-b24f-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{969c7eab-5460-11de-86d6-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{969c7eb0-5460-11de-86d6-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{a130e8f4-5c11-11de-86d9-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{a91c5b93-8bee-11de-b25c-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{aacc1931-6ef0-11de-86ee-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b3078752-60b0-11de-86dc-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{c6ae3770-510c-11de-86d2-000e35b021df}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{fb5e2c29-cfd5-11de-b283-000e35b021df}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[03/06/2009 18:00|--a--c---|0] C:\AUTOEXEC.BAT
[29/07/2009 08:16|-rahsc---|212] C:\boot.ini
[28/08/2001 12:00|-rahsc---|4952] C:\Bootfont.bin
[05/11/2009 18:26|--a--c---|74] C:\CMLoader.log
[03/06/2009 18:00|--a--c---|0] C:\CONFIG.SYS
[?|?|?] C:\hiberfil.sys
[03/06/2009 18:00|-rahsc---|0] C:\IO.SYS
[03/06/2009 18:00|-rahsc---|0] C:\MSDOS.SYS
[03/06/2009 18:35|-rahs----|47564] C:\NTDETECT.COM
[04/06/2009 13:16|-rahs----|252240] C:\ntldr
[?|?|?] C:\pagefile.sys
[03/10/2009 17:39|--a--c---|45] C:\TEST.XML
[19/11/2009 18:22|--a--c---|5935] C:\UsbFix.txt
[01/10/2008 12:00|--a------|18734784] D:\WDM_A406.exe
[11/04/2009 17:23|--a------|232210] D:\Bubbles.zip
[29/09/2009 08:34|--a------|114] D:\Clean.bat
[28/02/2008 10:37|--a------|1491592] D:\install_flash_player.exe
[11/04/2009 17:47|--a------|34175] D:\macosxcur.zip
[20/06/2006 11:14|--a------|1689600] D:\Maison_Ronaldinho_Espagne[1].ppt
[13/04/2009 09:23|--a------|28160] D:\meeting cellou.doc
[16/05/2009 15:53|--a------|143903] D:\cpro-widget-Picturebox-0.93.exe
[25/07/2009 07:12|--a------|469869806] E:\Clips_vid‚os.rar
[26/03/2007 09:37|--a------|686028800] F:\Film Horreur - R‚v‚lations - Real Stuart Urban Av Terence Stamp Etjames D'arcy - 2002 - Rip Fr Dvd.avi
[31/01/2007 11:50|--a------|732057600] F:\Ocean's Twelve Dvdrip Fr Ripped By Sel 2 Mer (2005) Version Fr Non Canadienne.avi
[23/05/2009 18:59|--ahs----|4096] F:\Thumbs.db
[06/10/2009 09:52|--a------|692280442] F:\New clips(vcd).rar
[19/09/2009 11:53|--a------|734368] H:\essetup.exe
[13/10/2009 18:53|--a------|417846956] H:\AVSEQ01.DAT
[04/11/2009 13:18|--a------|5268640] H:\R133052.EXE
[27/10/2009 11:14|--a------|97947] H:\soucis.pdf
[26/10/2009 16:28|--a------|47104] H:\rapport-octobreDSD.doc
[19/11/2009 18:18|--a------|1562] H:\BOOTEX.LOG
[25/05/2009 08:36|--a------|228732] H:\attest_recensement.pdf
[26/04/2009 20:39|--a------|68608] H:\prospecto.pub
[04/11/2009 13:53|--a------|15229628] H:\ALIMOU.wav
[25/05/2009 13:15|--a------|65873] H:\cv limmodifi‚.pdf
[06/07/2009 09:14|--a------|1998336] H:\resultats3Šadm.xls
[27/10/2009 08:45|--a------|140561] H:\offre_formation.pdf
[31/10/2009 15:07|--a------|157401] H:\princesse.pdf
[26/04/2009 19:50|--a------|26112] H:\invitation.doc
[03/05/2009 08:25|--a------|78848] H:\certificat.pub
[20/05/2009 16:02|--a------|228691] H:\REGLEMENTS INTERIEURS DU CLUB RFI LABE.pdf
[27/10/2009 08:47|--a------|103936] H:\offre_formation.pub
[31/10/2009 07:55|--a------|10999219] H:\faire-part.princesse.pdf
[04/11/2009 13:53|--a------|178720] H:\ALIMOU.pk
[01/07/2009 15:22|--a------|57856] H:\MA.doc
[31/10/2009 07:54|--a------|163328] H:\faire-part.princesse.pub
[13/08/2009 13:58|--a------|245248] H:\Les familles Bald‚.doc
[31/10/2009 11:32|--a------|232039] H:\carte-mariage.pdf
[02/09/2009 12:04|--a------|45056] H:\RA MOB.doc
[16/07/2009 10:51|--a------|1781427] H:\dipl“me.jpg
[16/07/2009 10:53|--a------|624773] H:\C accr‚ditation.jpg
[05/10/2009 10:19|--a------|27136] H:\Lab‚ l'a ‚chapp‚ belle.doc
[11/01/2009 19:34|--a------|4752698] H:\La Famme de Mon Patron.mp3
[26/09/2009 10:54|--a------|4838192] H:\f‚ticheurs!.JPG
[25/08/2009 14:32|--a------|29696] H:\Convention.doc
[25/08/2009 15:02|--a------|184817] H:\Convention.pdf
[26/08/2009 14:36|--a------|250087] H:\ConventionEAD.pdf
[01/11/2009 18:05|--a------|165376] H:\attestation-formation.pub
[22/07/2009 11:25|--a------|8172456] H:\Firefox Setup 3.5.1.exe
[18/09/2009 14:30|--a------|149477] H:\affich-4049123-virus-autorun-inf-aie.htm
[28/07/2009 17:22|--a------|69632] H:\transcription_UGVD.doc
[06/09/2009 18:24|--a------|118784] H:\couverture.pub
[25/09/2009 19:26|--a------|125440] H:\Tribunal.doc
[06/09/2009 18:22|--a------|138425] H:\couverture.pdf
[25/09/2009 19:26|--a------|569221] H:\Tribunal2.pdf
[31/10/2009 20:23|--a------|475136] H:\Navigation et Recherche Internet.doc
[01/11/2009 18:05|--a------|275556] H:\attestation-formation.pdf
[02/11/2009 08:15|--a------|65536] H:\Rapport.HRW.massacre-du-28-septembre.doc
[09/09/2009 10:43|--a------|296617] H:\DSC00984.JPG
[05/10/2009 11:27|--a------|36864] H:\y‚rim … dadis.doc
[26/09/2009 07:54|--a------|48128] H:\rapport-SeptembrDSD.doc
[12/10/2009 08:41|--a------|30720] H:\Draft_‚mission.doc
[13/09/2009 11:26|--a------|27648] H:\divagation des animaux.doc
[13/09/2009 16:55|--a------|23040] H:\palais-kolima.doc
[19/09/2007 00:19|--a------|22016] H:\Alimou.doc
[18/09/2009 14:10|--a------|20992] H:\macka b.doc
[25/09/2002 03:17|--a------|24064] H:\Questionnaire_Touffik.doc
[04/11/2009 13:19|--a------|447488] H:\anti-autorun.inf141.exe
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par UsbFix.
# D:\autorun.inf -> Dossier créé par UsbFix.
# E:\autorun.inf -> Dossier créé par UsbFix.
# F:\autorun.inf -> Dossier créé par UsbFix.
# H:\autorun.inf -> Dossier créé par UsbFix.
################## | Suspect | https://www.virustotal.com/gui/ |
################## | Cracks / Keygens / Serials |
"D:\mes logiciel\NOD32.Antivirus.v2.50.41.FR.(Version.Windows_XP_2000_2003_NT).Incl-Crack.par.eMule-Paradise.com\nentfrst.exe"
06/09/2005 11:47 |Size 9990600 |Crc32 430025b2 |Md5 c6443897925597d5c9308ea92e9448a7
"D:\mes logiciel\NOD32.Antivirus.v2.50.41.FR.(Version.Windows_XP_2000_2003_NT).Incl-Crack.par.eMule-Paradise.com\Crack\NOD32.FiX.v1.9-nsane.exe"
06/09/2005 11:51 |Size 302844 |Crc32 f1fe3d20 |Md5 1a5e36204f702a11a73a2f4fcb32b319
"D:\mes logiciel\Nero-7012-FR+ENG+Keygen\nero_7.0.1.2_francais.exe"
24/11/2005 15:49 |Size 111231344 |Crc32 f8217905 |Md5 688266e3fdfbb528bf9f33ba6fab3c38
"D:\mes logiciel\Nero-7012-FR+ENG+Keygen\Keygen.exe"
31/10/2005 23:18 |Size 101888 |Crc32 a4b5f8e3 |Md5 47d56fbab005991cc0a3b3a1d6e5d09e
"D:\mes logiciel\Partition Magic 8 + Crack\Crack.exe"
22/09/2002 05:00 |Size 14518 |Crc32 6fca3494 |Md5 a26056d4e9072ce6d33fe432488cebe5
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\instmsia.exe"
11/03/2002 06:45 |Size 1708856 |Crc32 3ccaccf9 |Md5 43f7305c2e5dd4a8f3c5abeb2ffe4833
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\instmsiw.exe"
11/03/2002 07:06 |Size 1822520 |Crc32 be716ace |Md5 61a5fb191ae2ae876db31dcce75e4183
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\setup.exe"
18/09/2002 05:26 |Size 217088 |Crc32 25bb2048 |Md5 c36de9988d860d5ebefbb3c972a20d8f
"D:\mes logiciel\Partition Magic 8 + Crack\Setup\Tutorial Interactif\PM8Flash.exe"
05/09/2002 14:06 |Size 5890825 |Crc32 d9777504 |Md5 a71e5f690258c7aa692d00dbadf816d1
"D:\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
19/01/2007 14:09 |Size 9657352 |Crc32 fffb9cfd |Md5 ad2eba479fa525b2c4759ce72125630e
"D:\Uvs 10+crack\uvs10_tbyb_(f).exe"
16/09/2006 12:03 |Size 142456841 |Crc32 fefd9bfd |Md5 e1f912bdf97e7635f4a66f6e9d224b4a
"H:\mes docs\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
04/11/2009 13:21 |Size 9657352 |Crc32 1a4c4e20 |Md5 2143123c7c343fb2265cb168566fbaaa
"H:\logiciels et autres\TuneUp Utilities 2007 v6.0.1256 + Keygen_Fr\TU2007TrialFR.exe"
04/11/2009 13:32 |Size 9657352 |Crc32 1a4c4e20 |Md5 2143123c7c343fb2265cb168566fbaaa
"H:\logiciels et autres\Uvs 10+crack\uvs10_tbyb_(f).exe"
04/11/2009 13:32 |Size 142456841 |Crc32 178c86d3 |Md5 5ab9d5d7cd77f597c4e35ef4ed2517ef