Impossible d'enlever des virus
Résolu/Fermé
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
-
13 janv. 2010 à 18:48
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 - 24 mars 2010 à 17:43
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 - 24 mars 2010 à 17:43
A voir également:
- Impossible d'enlever des virus
- Enlever pub youtube - Accueil - Streaming
- Comment enlever une page sur word - Guide
- Virus mcafee - Accueil - Piratage
- Faux message virus ordinateur - Accueil - Arnaque
- Enlever mode sécurisé samsung - Guide
70 réponses
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
16 févr. 2010 à 11:02
16 févr. 2010 à 11:02
bizare car tu n'as pas à le renommer tu fais enregistrer sur le bureau et c'est tous ou à moins que tu est déja combofix sur le pc et la il te demande de le renommé, tu fais ce qui suit et puis tu le téléchargera de nouveau en l'enregistrant sur le bureau et si tu le renomme pas grave mais tu lui met remimimy ton pseudo
pour être sur que plus de combofix sur le pc tu appuis sur la touches windows " celle avec le drapeau " et sur R dans la fenêtre exécuter qui s'ouvre tu met combofix /u tu valide avec ok et si il le trouve il le virera , après tu le téélcharges et si tu veux le renommer ok fais le
pour être sur que plus de combofix sur le pc tu appuis sur la touches windows " celle avec le drapeau " et sur R dans la fenêtre exécuter qui s'ouvre tu met combofix /u tu valide avec ok et si il le trouve il le virera , après tu le téélcharges et si tu veux le renommer ok fais le
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
16 févr. 2010 à 14:35
16 févr. 2010 à 14:35
mé oui mé je peut pas a cause de sa:
https://www.facebook.com/album.php?aid=15141&id=100000037449597&saved!/photo.php?pid=217604&id=100000037449597
https://www.facebook.com/album.php?aid=15141&id=100000037449597&saved!/photo.php?pid=217604&id=100000037449597
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
16 févr. 2010 à 14:42
16 févr. 2010 à 14:42
que viens faire l'adresse de cette merde de facebook dans le fait que tu ne puisse pas faire combofix ??
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
16 févr. 2010 à 15:54
16 févr. 2010 à 15:54
parseke je ne sait pas mettre une photo sur le site alors je les mis sur facebook comme sa vs pouver la voir
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
16 févr. 2010 à 16:20
16 févr. 2010 à 16:20
ok mais ton lien ne donne rien !! si tuas une capture d'écran ou photo aide toi ce ce lien https://www.commentcamarche.net/informatique/windows/149-faire-des-captures-d-ecran-avec-windows-10/
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
16 févr. 2010 à 21:04
16 févr. 2010 à 21:04
voila mon blem
https://imageshack.com/
https://imageshack.com/
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
16 févr. 2010 à 21:36
16 févr. 2010 à 21:36
ou la j'aime pas voire un écran comme cela , je reprends le sujet depuis le début pour essayer de comprendre !! si je peux !!
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
16 févr. 2010 à 21:38
16 févr. 2010 à 21:38
voila sa m'enerve sa s'affiche de temp en temp
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
16 févr. 2010 à 21:52
16 févr. 2010 à 21:52
tu appuis sur la touche windows "celle avec le drapeau" et la touche R et dans la fenêtre exécuter tu mets
CHKDSK /f /r et valides avec ok
il de dira qu'il ne peut pas le faire car un des disques est occupé et te demande si tu veut le faire au prochain démarrage tu mets O la lettre o pas le 0 zéro pour oui
tu redémarres le pc et tu laisse faire
CHKDSK /f /r et valides avec ok
il de dira qu'il ne peut pas le faire car un des disques est occupé et te demande si tu veut le faire au prochain démarrage tu mets O la lettre o pas le 0 zéro pour oui
tu redémarres le pc et tu laisse faire
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 08:10
17 févr. 2010 à 08:10
bonjour.
c bon je les fé cette nuit seulement il n'ya pas de rapport ni tien c normal
mercije lance combofix
c bon je les fé cette nuit seulement il n'ya pas de rapport ni tien c normal
mercije lance combofix
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 09:15
17 févr. 2010 à 09:15
ComboFix 10-02-16.02 - Rémi 17/02/2010 8:34.7.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3066.2024 [GMT 1:00]
Lancé depuis: c:\users\Rémi\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3317431821-2754218308-1391888111-500
c:\$recycle.bin\S-1-5-21-4064497093-2334084104-1137348868-500
c:\users\Rémi\AppData\Roaming\MSLiveUpdate.exe
c:\users\Rémi\AppData\Roaming\setup.exe
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\msetup
c:\windows\msetup\BASW-00503A66\data1.cab
c:\windows\msetup\BASW-00503A66\data1.hdr
c:\windows\msetup\BASW-00503A66\data2.cab
c:\windows\msetup\BASW-00503A66\engine32.cab
c:\windows\msetup\BASW-00503A66\layout.bin
c:\windows\msetup\BASW-00503A66\PlayCamera\CameraOn.wav
c:\windows\msetup\BASW-00503A66\PlayCamera\Click.wav
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_chs_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_cht_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_deu_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_eng_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_esp_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_fra_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_ita_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_kor_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_ptg_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_rus_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_ukr_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\HookDllPS2.dll
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\Back_Big.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\Back_Small.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbCancel.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbHelp.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbOk.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbOpen.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbPreviewOff.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbPreviewOn.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbRecordOff.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbRecordOn.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbSnap.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\PlayCamera.ico
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_chs.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_cht.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_deu.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_eng.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_esp.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_fra.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_ita.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_kor.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_ptg.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_rus.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_ukr.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\PlayCamera.exe
c:\windows\msetup\BASW-00503A66\PlayCamera\SSHook.dll
c:\windows\msetup\BASW-00503A66\PlayCamera\Uninst.ico
c:\windows\msetup\BASW-00503A66\setup.exe
c:\windows\msetup\BASW-00503A66\setup.ibt
c:\windows\msetup\BASW-00503A66\setup.ini
c:\windows\msetup\BASW-00503A66\setup.iss
c:\windows\msetup\BASW-00503A66\SWDesc.txt
c:\windows\msetup\BASW-01038A05\ChgWLANSettings.exe
c:\windows\msetup\MSetup.exe
c:\windows\msetup\MSetupLog.log
c:\windows\system32\zzop93.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-01-17 au 2010-02-17 ))))))))))))))))))))))))))))))))))))
.
2010-02-17 07:51 . 2010-02-17 07:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-15 05:26 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-15 05:26 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-15 05:25 . 2009-12-04 18:29 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-02-15 05:25 . 2009-12-04 18:30 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-02-15 05:25 . 2009-12-04 18:28 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-02-15 05:25 . 2009-12-04 18:28 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-02-15 05:25 . 2009-12-04 18:28 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-02-15 05:25 . 2009-12-04 18:28 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-02-15 05:25 . 2009-12-04 18:28 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-02-15 05:25 . 2009-12-04 18:28 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-02-15 05:25 . 2009-12-04 18:27 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-02-15 05:25 . 2009-12-04 15:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-15 05:25 . 2009-12-04 15:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-14 09:03 . 2009-12-08 20:01 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-14 09:03 . 2009-12-08 17:26 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-02-08 16:10 . 2010-02-08 16:10 -------- d-----w- C:\rsit
2010-02-06 22:04 . 2010-02-06 22:04 -------- d-----w- c:\program files\Regensoft
2010-02-06 22:04 . 2010-02-06 22:04 -------- d-----w- c:\program files\AviSynth 2.5
2010-02-06 19:15 . 2010-02-06 19:15 -------- d-----w- c:\program files\Pinnacle Systems
2010-02-06 19:14 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-02-02 11:45 . 2010-02-02 11:45 -------- d-----w- c:\program files\LimeWire
2010-01-25 20:28 . 2009-04-02 14:21 84480 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-25 20:28 . 2008-06-08 22:58 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2010-01-25 20:27 . 2007-10-09 06:06 626688 ----a-w- c:\windows\system32\msvcr80.dll
2010-01-25 20:27 . 2005-09-23 04:48 1171456 ----a-w- c:\windows\system32\msvcr80d.dll
2010-01-25 20:27 . 2010-01-25 20:30 -------- d-----w- c:\program files\Video Convert Master
2010-01-18 12:45 . 2010-01-18 12:45 -------- d-----w- C:\Autodesk
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 07:14 . 2009-04-29 11:36 163116 ----a-w- c:\programdata\nvModes.dat
2010-02-17 07:12 . 2008-12-30 18:27 12 ----a-w- c:\windows\bthservsdp.dat
2010-02-16 12:23 . 2009-04-25 17:07 -------- d-----w- c:\programdata\Google Updater
2010-02-15 05:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-15 05:03 . 2008-12-30 02:28 -------- d-----w- c:\programdata\Microsoft Help
2010-02-14 12:02 . 2008-12-30 01:21 724052 ----a-w- c:\windows\system32\perfh00C.dat
2010-02-14 12:02 . 2008-12-30 01:21 146398 ----a-w- c:\windows\system32\perfc00C.dat
2010-02-07 06:34 . 2009-04-25 16:50 -------- d-----w- c:\program files\Red Kawa
2010-02-07 06:26 . 2009-05-06 14:25 -------- d-----w- c:\program files\AVS4YOU
2010-02-05 17:55 . 2009-12-28 20:20 166807 ----a-w- c:\windows\hpoins30.dat
2010-02-05 17:22 . 2009-08-10 16:16 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-22 12:26 . 2009-04-27 11:33 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 09:39 . 2009-05-06 14:25 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-01-15 06:37 . 2010-01-15 06:37 -------- d-----w- c:\program files\Trend Micro
2010-01-15 06:17 . 2010-01-14 17:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 06:38 . 2010-01-23 19:05 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-23 19:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-23 19:05 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-23 19:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-01-01 22:56 . 2009-12-25 17:48 -------- d-----w- c:\programdata\HP
2010-01-01 22:55 . 2010-01-01 22:48 78336 ----a-w- c:\windows\hpqins05.dat
2010-01-01 22:50 . 2010-01-01 22:50 -------- d-----w- c:\programdata\HP Product Assistant
2010-01-01 22:43 . 2009-12-25 18:42 -------- d-----w- c:\program files\HP
2009-12-28 20:26 . 2009-12-28 20:26 -------- d-----w- c:\program files\Common Files\HP
2009-12-28 20:26 . 2009-12-28 20:26 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-27 10:45 . 2009-12-27 10:45 -------- d-----w- c:\program files\MSXML 4.0
2009-12-26 22:41 . 2009-12-26 22:41 -------- d-----w- c:\programdata\WEBREG
2009-12-25 18:43 . 2009-12-25 18:43 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-12-25 13:16 . 2009-12-25 13:16 -------- d-----w- c:\programdata\Avery
2009-12-25 13:16 . 2009-12-25 13:16 -------- d-----w- c:\program files\Avery Dennison
2009-12-24 20:10 . 2009-05-01 09:23 -------- d-----w- c:\program files\Orange
2009-12-21 19:40 . 2009-12-21 19:40 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-12-21 19:40 . 2009-12-21 19:40 -------- d-----w- c:\program files\TechSmith
2009-12-19 22:07 . 2009-12-19 22:08 36864 ----a-w- c:\programdata\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2009-12-15 22:30 . 2009-12-15 22:30 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-12-10 16:49 . 2009-12-10 16:49 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-30 17:02 . 2009-11-30 17:02 171144 ----a-w- c:\windows\system32\xliveinstall.dll
2009-11-30 17:02 . 2009-11-30 17:02 72840 ----a-w- c:\windows\system32\xliveinstallhost.exe
2009-11-27 20:33 . 2009-05-12 16:49 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-11-24 23:54 . 2009-04-26 13:38 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2009-04-26 13:39 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-04-26 13:39 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-04-26 13:38 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2009-04-26 13:39 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-04-26 13:39 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-04-26 13:39 97480 ----a-w- c:\windows\system32\AvastSS.scr
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e802027b-1f2b-40bd-b307-0bd96d036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e802027b-1f2b-40bd-b307-0bd96d036835}]
2009-10-27 10:45 2325528 ----a-w- c:\program files\AstroburnBar\tbAstr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e802027b-1f2b-40bd-b307-0bd96d036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E802027B-1F2B-40BD-B307-0BD96D036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"VistaStartMenu"="c:\program files\Vista Start Menu\VistaStartMenu.exe" [2009-04-13 2171392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-06 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-26 13548064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-26 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-08 6273568]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1029416]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"SetPoint"="c:\program files\Logitech\SetPoint\SetPoint.EXE" [2005-05-25 450560]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
c:\users\R‚mi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-5-16 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Rémi^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\users\Rémi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 14:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
2008-07-03 09:37 812952 ----a-w- c:\program files\Registry Mechanic\RMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-14 19:01 71216 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2009-10-26 11:45 306088 ----a-w- c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxAssistant]
2003-02-27 03:38 86016 ----a-w- c:\program files\Common Files\Roxio Shared\Upgrade\roxassist.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
2003-02-26 14:50 253952 ----a-w- c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2003-02-27 02:36 757760 ----a-w- c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
2003-02-27 03:31 69632 ----a-w- c:\program files\Common Files\Roxio Shared\System\EngUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-06 13:20 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wallpaper]
2007-08-20 23:27 233472 ----a-w- c:\program files\Wallpaper\Wallpaper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):28,05,2b,f4,c5,51,ca,01
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [26/04/2009 14:39 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [26/04/2009 14:39 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [26/04/2009 14:38 53328]
R2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\System32\drivers\KMDFMEMIO.sys [30/12/2008 02:43 13312]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [30/12/2008 02:12 44576]
R3 VMC302;Vimicro Camera Service VMC302;c:\windows\System32\drivers\vmc302.sys [30/12/2008 02:40 242048]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [10/08/2009 12:16 691696]
S2 gupdate1c9ce5ea1fe4e1b;Service Google Update (gupdate1c9ce5ea1fe4e1b);c:\program files\Google\Update\GoogleUpdate.exe [06/05/2009 16:23 133104]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [02/10/2009 22:04 54632]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [14/01/2010 18:09 38224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ejmpnqkh
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contenu du dossier 'Tâches planifiées'
2010-02-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-06 15:11]
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 15:23]
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 15:23]
2010-02-17 c:\windows\Tasks\User_Feed_Synchronization-{8F6A0045-9292-4AA8-9D96-059047D8898F}.job
- c:\windows\system32\msfeedssync.exe [2010-01-23 04:56]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Rémi\AppData\Roaming\Mozilla\Firefox\Profiles\mm4m83kc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - SearchTheWeb
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\Rémi\AppData\Roaming\Mozilla\Firefox\Profiles\mm4m83kc.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Video Convert Master\codec\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\Video Convert Master\codec\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{0000041B-0000-0000-0000-00004455A000} - (no file)
WebBrowser-{0000041B-0000-0000-0000-000004083801} - (no file)
WebBrowser-{FFFFFFFF-8CFF-7647-0000-000000000000} - (no file)
HKLM-Run-TkBellExe - c:\program files\Video Convert Master\codec\real\Update_OB\realsched.exe
HKLM-Run-CloneCDTray - c:\program files\SlySoft\CloneCD\CloneCDTray.exe
Notify-zzop93 - zzop93.dll
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-HijackThis - c:\users\RMI~1\AppData\Local\Temp\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-17 08:52
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x85C91618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8aeabd24
\Driver\ACPI -> acpi.sys @ 0x82e45d68
\Driver\atapi -> ataport.SYS @ 0x8a8f1a2c
\Driver\iaStor -> iaStor.sys @ 0x8a8494fc
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3b,a9,39,58,6c,cc,cd,4f,a4,cd,1d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3b,a9,39,58,6c,cc,cd,4f,a4,cd,1d,\
[HKEY_USERS\S-1-5-21-4064497093-2334084104-1137348868-1003\Software\SecuROM\License information*]
"datasecu"=hex:45,7f,b1,be,97,1a,bc,b5,2b,0c,ed,51,f7,53,03,16,e8,cb,9c,e4,eb,
2e,fb,e3,22,3d,16,0a,d1,fb,be,f8,cf,34,e9,2b,12,07,05,cf,9f,ee,f6,5f,a1,94,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
Heure de fin: 2010-02-17 08:58:40
ComboFix-quarantined-files.txt 2010-02-17 07:58
Avant-CF: 7 167 373 312 octets libres
Après-CF: 7 185 195 008 octets libres
- - End Of File - - 18E6321F0E4C5E215991BFEE85930440
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3066.2024 [GMT 1:00]
Lancé depuis: c:\users\Rémi\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3317431821-2754218308-1391888111-500
c:\$recycle.bin\S-1-5-21-4064497093-2334084104-1137348868-500
c:\users\Rémi\AppData\Roaming\MSLiveUpdate.exe
c:\users\Rémi\AppData\Roaming\setup.exe
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\msetup
c:\windows\msetup\BASW-00503A66\data1.cab
c:\windows\msetup\BASW-00503A66\data1.hdr
c:\windows\msetup\BASW-00503A66\data2.cab
c:\windows\msetup\BASW-00503A66\engine32.cab
c:\windows\msetup\BASW-00503A66\layout.bin
c:\windows\msetup\BASW-00503A66\PlayCamera\CameraOn.wav
c:\windows\msetup\BASW-00503A66\PlayCamera\Click.wav
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_chs_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_cht_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_deu_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_eng_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_esp_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_fra_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_ita_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_kor_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_ptg_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_rus_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\Help\PlayCamera_ukr_s.chm
c:\windows\msetup\BASW-00503A66\PlayCamera\HookDllPS2.dll
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\Back_Big.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\Back_Small.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbCancel.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbHelp.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbOk.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbOpen.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbPreviewOff.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbPreviewOn.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbRecordOff.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbRecordOn.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\gbSnap.bmp
c:\windows\msetup\BASW-00503A66\PlayCamera\Images\PlayCamera.ico
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_chs.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_cht.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_deu.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_eng.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_esp.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_fra.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_ita.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_kor.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_ptg.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_rus.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\Language\PlayCamera_ukr.txt
c:\windows\msetup\BASW-00503A66\PlayCamera\PlayCamera.exe
c:\windows\msetup\BASW-00503A66\PlayCamera\SSHook.dll
c:\windows\msetup\BASW-00503A66\PlayCamera\Uninst.ico
c:\windows\msetup\BASW-00503A66\setup.exe
c:\windows\msetup\BASW-00503A66\setup.ibt
c:\windows\msetup\BASW-00503A66\setup.ini
c:\windows\msetup\BASW-00503A66\setup.iss
c:\windows\msetup\BASW-00503A66\SWDesc.txt
c:\windows\msetup\BASW-01038A05\ChgWLANSettings.exe
c:\windows\msetup\MSetup.exe
c:\windows\msetup\MSetupLog.log
c:\windows\system32\zzop93.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-01-17 au 2010-02-17 ))))))))))))))))))))))))))))))))))))
.
2010-02-17 07:51 . 2010-02-17 07:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-15 05:26 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-15 05:26 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-15 05:25 . 2009-12-04 18:29 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-02-15 05:25 . 2009-12-04 18:30 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-02-15 05:25 . 2009-12-04 18:28 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-02-15 05:25 . 2009-12-04 18:28 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-02-15 05:25 . 2009-12-04 18:28 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-02-15 05:25 . 2009-12-04 18:28 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-02-15 05:25 . 2009-12-04 18:28 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-02-15 05:25 . 2009-12-04 18:28 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-02-15 05:25 . 2009-12-04 18:27 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-02-15 05:25 . 2009-12-04 15:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-15 05:25 . 2009-12-04 15:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-14 09:03 . 2009-12-08 20:01 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-14 09:03 . 2009-12-08 17:26 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-02-08 16:10 . 2010-02-08 16:10 -------- d-----w- C:\rsit
2010-02-06 22:04 . 2010-02-06 22:04 -------- d-----w- c:\program files\Regensoft
2010-02-06 22:04 . 2010-02-06 22:04 -------- d-----w- c:\program files\AviSynth 2.5
2010-02-06 19:15 . 2010-02-06 19:15 -------- d-----w- c:\program files\Pinnacle Systems
2010-02-06 19:14 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-02-02 11:45 . 2010-02-02 11:45 -------- d-----w- c:\program files\LimeWire
2010-01-25 20:28 . 2009-04-02 14:21 84480 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-25 20:28 . 2008-06-08 22:58 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2010-01-25 20:27 . 2007-10-09 06:06 626688 ----a-w- c:\windows\system32\msvcr80.dll
2010-01-25 20:27 . 2005-09-23 04:48 1171456 ----a-w- c:\windows\system32\msvcr80d.dll
2010-01-25 20:27 . 2010-01-25 20:30 -------- d-----w- c:\program files\Video Convert Master
2010-01-18 12:45 . 2010-01-18 12:45 -------- d-----w- C:\Autodesk
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 07:14 . 2009-04-29 11:36 163116 ----a-w- c:\programdata\nvModes.dat
2010-02-17 07:12 . 2008-12-30 18:27 12 ----a-w- c:\windows\bthservsdp.dat
2010-02-16 12:23 . 2009-04-25 17:07 -------- d-----w- c:\programdata\Google Updater
2010-02-15 05:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-15 05:03 . 2008-12-30 02:28 -------- d-----w- c:\programdata\Microsoft Help
2010-02-14 12:02 . 2008-12-30 01:21 724052 ----a-w- c:\windows\system32\perfh00C.dat
2010-02-14 12:02 . 2008-12-30 01:21 146398 ----a-w- c:\windows\system32\perfc00C.dat
2010-02-07 06:34 . 2009-04-25 16:50 -------- d-----w- c:\program files\Red Kawa
2010-02-07 06:26 . 2009-05-06 14:25 -------- d-----w- c:\program files\AVS4YOU
2010-02-05 17:55 . 2009-12-28 20:20 166807 ----a-w- c:\windows\hpoins30.dat
2010-02-05 17:22 . 2009-08-10 16:16 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-22 12:26 . 2009-04-27 11:33 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 09:39 . 2009-05-06 14:25 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-01-15 06:37 . 2010-01-15 06:37 -------- d-----w- c:\program files\Trend Micro
2010-01-15 06:17 . 2010-01-14 17:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 06:38 . 2010-01-23 19:05 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-23 19:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-23 19:05 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-23 19:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-01-01 22:56 . 2009-12-25 17:48 -------- d-----w- c:\programdata\HP
2010-01-01 22:55 . 2010-01-01 22:48 78336 ----a-w- c:\windows\hpqins05.dat
2010-01-01 22:50 . 2010-01-01 22:50 -------- d-----w- c:\programdata\HP Product Assistant
2010-01-01 22:43 . 2009-12-25 18:42 -------- d-----w- c:\program files\HP
2009-12-28 20:26 . 2009-12-28 20:26 -------- d-----w- c:\program files\Common Files\HP
2009-12-28 20:26 . 2009-12-28 20:26 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-27 10:45 . 2009-12-27 10:45 -------- d-----w- c:\program files\MSXML 4.0
2009-12-26 22:41 . 2009-12-26 22:41 -------- d-----w- c:\programdata\WEBREG
2009-12-25 18:43 . 2009-12-25 18:43 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-12-25 13:16 . 2009-12-25 13:16 -------- d-----w- c:\programdata\Avery
2009-12-25 13:16 . 2009-12-25 13:16 -------- d-----w- c:\program files\Avery Dennison
2009-12-24 20:10 . 2009-05-01 09:23 -------- d-----w- c:\program files\Orange
2009-12-21 19:40 . 2009-12-21 19:40 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-12-21 19:40 . 2009-12-21 19:40 -------- d-----w- c:\program files\TechSmith
2009-12-19 22:07 . 2009-12-19 22:08 36864 ----a-w- c:\programdata\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2009-12-15 22:30 . 2009-12-15 22:30 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-12-10 16:49 . 2009-12-10 16:49 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-30 17:02 . 2009-11-30 17:02 171144 ----a-w- c:\windows\system32\xliveinstall.dll
2009-11-30 17:02 . 2009-11-30 17:02 72840 ----a-w- c:\windows\system32\xliveinstallhost.exe
2009-11-27 20:33 . 2009-05-12 16:49 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-11-24 23:54 . 2009-04-26 13:38 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2009-04-26 13:39 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-04-26 13:39 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-04-26 13:38 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2009-04-26 13:39 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-04-26 13:39 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-04-26 13:39 97480 ----a-w- c:\windows\system32\AvastSS.scr
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e802027b-1f2b-40bd-b307-0bd96d036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e802027b-1f2b-40bd-b307-0bd96d036835}]
2009-10-27 10:45 2325528 ----a-w- c:\program files\AstroburnBar\tbAstr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e802027b-1f2b-40bd-b307-0bd96d036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E802027B-1F2B-40BD-B307-0BD96D036835}"= "c:\program files\AstroburnBar\tbAstr.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{e802027b-1f2b-40bd-b307-0bd96d036835}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"VistaStartMenu"="c:\program files\Vista Start Menu\VistaStartMenu.exe" [2009-04-13 2171392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-06 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-26 13548064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-26 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-08 6273568]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1029416]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"SetPoint"="c:\program files\Logitech\SetPoint\SetPoint.EXE" [2005-05-25 450560]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
c:\users\R‚mi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-5-16 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Rémi^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\users\Rémi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 14:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
2008-07-03 09:37 812952 ----a-w- c:\program files\Registry Mechanic\RMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-14 19:01 71216 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2009-10-26 11:45 306088 ----a-w- c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxAssistant]
2003-02-27 03:38 86016 ----a-w- c:\program files\Common Files\Roxio Shared\Upgrade\roxassist.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
2003-02-26 14:50 253952 ----a-w- c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2003-02-27 02:36 757760 ----a-w- c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
2003-02-27 03:31 69632 ----a-w- c:\program files\Common Files\Roxio Shared\System\EngUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-06 13:20 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wallpaper]
2007-08-20 23:27 233472 ----a-w- c:\program files\Wallpaper\Wallpaper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):28,05,2b,f4,c5,51,ca,01
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [26/04/2009 14:39 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [26/04/2009 14:39 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [26/04/2009 14:38 53328]
R2 KMDFMEMIO;SAMSUNG Kernel Driver;c:\windows\System32\drivers\KMDFMEMIO.sys [30/12/2008 02:43 13312]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [30/12/2008 02:12 44576]
R3 VMC302;Vimicro Camera Service VMC302;c:\windows\System32\drivers\vmc302.sys [30/12/2008 02:40 242048]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [10/08/2009 12:16 691696]
S2 gupdate1c9ce5ea1fe4e1b;Service Google Update (gupdate1c9ce5ea1fe4e1b);c:\program files\Google\Update\GoogleUpdate.exe [06/05/2009 16:23 133104]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [02/10/2009 22:04 54632]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [14/01/2010 18:09 38224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ejmpnqkh
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contenu du dossier 'Tâches planifiées'
2010-02-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-06 15:11]
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 15:23]
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 15:23]
2010-02-17 c:\windows\Tasks\User_Feed_Synchronization-{8F6A0045-9292-4AA8-9D96-059047D8898F}.job
- c:\windows\system32\msfeedssync.exe [2010-01-23 04:56]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Rémi\AppData\Roaming\Mozilla\Firefox\Profiles\mm4m83kc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - SearchTheWeb
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\Rémi\AppData\Roaming\Mozilla\Firefox\Profiles\mm4m83kc.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Video Convert Master\codec\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\Video Convert Master\codec\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{0000041B-0000-0000-0000-00004455A000} - (no file)
WebBrowser-{0000041B-0000-0000-0000-000004083801} - (no file)
WebBrowser-{FFFFFFFF-8CFF-7647-0000-000000000000} - (no file)
HKLM-Run-TkBellExe - c:\program files\Video Convert Master\codec\real\Update_OB\realsched.exe
HKLM-Run-CloneCDTray - c:\program files\SlySoft\CloneCD\CloneCDTray.exe
Notify-zzop93 - zzop93.dll
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-HijackThis - c:\users\RMI~1\AppData\Local\Temp\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-17 08:52
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x85C91618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8aeabd24
\Driver\ACPI -> acpi.sys @ 0x82e45d68
\Driver\atapi -> ataport.SYS @ 0x8a8f1a2c
\Driver\iaStor -> iaStor.sys @ 0x8a8494fc
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3b,a9,39,58,6c,cc,cd,4f,a4,cd,1d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3b,a9,39,58,6c,cc,cd,4f,a4,cd,1d,\
[HKEY_USERS\S-1-5-21-4064497093-2334084104-1137348868-1003\Software\SecuROM\License information*]
"datasecu"=hex:45,7f,b1,be,97,1a,bc,b5,2b,0c,ed,51,f7,53,03,16,e8,cb,9c,e4,eb,
2e,fb,e3,22,3d,16,0a,d1,fb,be,f8,cf,34,e9,2b,12,07,05,cf,9f,ee,f6,5f,a1,94,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
Heure de fin: 2010-02-17 08:58:40
ComboFix-quarantined-files.txt 2010-02-17 07:58
Avant-CF: 7 167 373 312 octets libres
Après-CF: 7 185 195 008 octets libres
- - End Of File - - 18E6321F0E4C5E215991BFEE85930440
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 11:09
17 févr. 2010 à 11:09
bon alors bonnne chance en esperant que vous aller y arriver
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
17 févr. 2010 à 11:28
17 févr. 2010 à 11:28
bonjour,
comment va le pc combofix a nettoyer pas mal de chose
comment va le pc combofix a nettoyer pas mal de chose
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 12:04
17 févr. 2010 à 12:04
je c pas trop g c pas trop g pas eu le temps de regarder gt au course je v voir
merci beaucou^p
merci beaucou^p
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 12:06
17 févr. 2010 à 12:06
g fé un coup de ccleaner
ps connaisser vous un logiciel dans le genre qui serai mieux
mais celui la est deja super mé comme vous avé l'air calé
ps connaisser vous un logiciel dans le genre qui serai mieux
mais celui la est deja super mé comme vous avé l'air calé
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 12:16
17 févr. 2010 à 12:16
c paske je vous repond sur l'ordi de mon papi
je v vopir tt de suite
je v vopir tt de suite
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 12:23
17 févr. 2010 à 12:23
super
sa va beaucoup mieu il lui fo 1min 20 pour m'afficher le bureau
mais 2min 54 avant que je puisse demarer internet c mieu qu'avant mais bon sa vous n'i pouver rien en fait c super car je n'ai plus sans cesse des message des page qui s'ouvre des truc comme ne repond pas tt le tremps cete page bleu la etc merci beaucoup
sa va beaucoup mieu il lui fo 1min 20 pour m'afficher le bureau
mais 2min 54 avant que je puisse demarer internet c mieu qu'avant mais bon sa vous n'i pouver rien en fait c super car je n'ai plus sans cesse des message des page qui s'ouvre des truc comme ne repond pas tt le tremps cete page bleu la etc merci beaucoup
jacques.gache
Messages postés
33453
Date d'inscription
mardi 13 novembre 2007
Statut
Contributeur sécurité
Dernière intervention
25 janvier 2016
1 616
17 févr. 2010 à 12:44
17 févr. 2010 à 12:44
ton problème d'ouverture de page internet c'est avec IE ou mozilla
pour IE 8 regarde et fais cela : https://www.commentcamarche.net/faq/17570-internet-explorer-8-lent
et pour firefox : https://www.commentcamarche.net/faq/852-optimiser-firefox
peux tu poster un nouveau hijackthis , merci
pour IE 8 regarde et fais cela : https://www.commentcamarche.net/faq/17570-internet-explorer-8-lent
et pour firefox : https://www.commentcamarche.net/faq/852-optimiser-firefox
peux tu poster un nouveau hijackthis , merci
remimimy
Messages postés
172
Date d'inscription
lundi 17 mars 2008
Statut
Membre
Dernière intervention
21 avril 2016
31
17 févr. 2010 à 21:00
17 févr. 2010 à 21:00
dsl mais j'ai encore un virus malware gen comme la derniere fois
psLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:59:54, on 17/02/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Vista Start Menu\VistaStartMenu.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAstr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAstr.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAstr.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SetPoint] C:\Program Files\Logitech\SetPoint\SetPoint.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [VistaStartMenu] "C:\Program Files\Vista Start Menu\VistaStartMenu.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Service Google Update (gupdate1c9ce5ea1fe4e1b) (gupdate1c9ce5ea1fe4e1b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
psLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:59:54, on 17/02/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Vista Start Menu\VistaStartMenu.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAstr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAstr.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AstroburnBar Toolbar - {e802027b-1f2b-40bd-b307-0bd96d036835} - C:\Program Files\AstroburnBar\tbAstr.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SetPoint] C:\Program Files\Logitech\SetPoint\SetPoint.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [VistaStartMenu] "C:\Program Files\Vista Start Menu\VistaStartMenu.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Service Google Update (gupdate1c9ce5ea1fe4e1b) (gupdate1c9ce5ea1fe4e1b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe