Pc lleno de virus
Resuelto
marjorie2604
-
Usuario anónimo -
Usuario anónimo -
Hola,
como protección utilizo Avira Antivir y tan pronto como enciendo mi PC, me dice que tengo virus, los coloco en cuarentena y no sirve de nada, sigo teniendo virus, no sé qué hacer, gracias por su ayuda
como protección utilizo Avira Antivir y tan pronto como enciendo mi PC, me dice que tengo virus, los coloco en cuarentena y no sirve de nada, sigo teniendo virus, no sé qué hacer, gracias por su ayuda
Configuración: Windows Vista Firefox 3.0.17
19 respuestas
Hola Marjorie ,
• Descarga la herramienta de información del sistema de Random (RSIT) (por random/random) en tu escritorio.
• Haz doble clic en RSIT.exe para iniciar el programa.
• Haz clic en Continuar en la pantalla de Aviso.
• Si la herramienta HijackThis (versión actualizada) no está presente o no se detecta en el ordenador, RSIT la descargará (permite el acceso en tu cortafuegos, si se solicita) y tendrás que aceptar la licencia.
• Cuando el análisis haya terminado, se abrirán dos archivos de texto. Publica el contenido de log.txt (es el que aparece en la pantalla) así como de info.txt (que verás en la barra de tareas).
Nota: los informes se guardan en la carpeta C:\rsit.
• Descarga la herramienta de información del sistema de Random (RSIT) (por random/random) en tu escritorio.
• Haz doble clic en RSIT.exe para iniciar el programa.
• Haz clic en Continuar en la pantalla de Aviso.
• Si la herramienta HijackThis (versión actualizada) no está presente o no se detecta en el ordenador, RSIT la descargará (permite el acceso en tu cortafuegos, si se solicita) y tendrás que aceptar la licencia.
• Cuando el análisis haya terminado, se abrirán dos archivos de texto. Publica el contenido de log.txt (es el que aparece en la pantalla) así como de info.txt (que verás en la barra de tareas).
Nota: los informes se guardan en la carpeta C:\rsit.
Re Marjorie ,
De hecho, tienes varias infecciones. Vamos a empezar por la infección Renos.
• Descarga UsbFix en tu escritorio:
(!) Conecta tus fuentes de datos externas a tu PC (memoria USB, disco duro externo, etc...) que podrían haber sido infectadas sin abrirlas.
• Haz doble clic en UsbFix.exe que está en tu escritorio.
• En el menú principal elige la opción " F " para francés y presiona [enter].
• En el segundo menú elige la opción " 2 " (Eliminación) y presiona [enter]
• Tu escritorio desaparecerá y el PC se reiniciará.
• Al reiniciar, UsbFix escaneará tu PC, deja que la herramienta trabaje.
• Luego publica el informe UsbFix.txt que aparecerá en el escritorio.
• Nota: El informe UsbFix.txt se guarda en la raíz del disco. (C:\UsbFix.txt)
( CTRL+A para seleccionar todo, CTRL+C para copiar y CTRL+V para pegar )
Nota: "Process.exe", un componente de la herramienta, es detectado por algunos antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) como un RiskTool.
No es un virus, sino una utilidad destinada a finalizar procesos.
En malas manos, esta utilidad podría detener programas de seguridad (Antivirus, Firewall...) de ahí la alerta emitida por estos antivirus.
• Tutorial: http://pagesperso-orange.fr/NosTools/usbfix.html
De hecho, tienes varias infecciones. Vamos a empezar por la infección Renos.
• Descarga UsbFix en tu escritorio:
(!) Conecta tus fuentes de datos externas a tu PC (memoria USB, disco duro externo, etc...) que podrían haber sido infectadas sin abrirlas.
• Haz doble clic en UsbFix.exe que está en tu escritorio.
• En el menú principal elige la opción " F " para francés y presiona [enter].
• En el segundo menú elige la opción " 2 " (Eliminación) y presiona [enter]
• Tu escritorio desaparecerá y el PC se reiniciará.
• Al reiniciar, UsbFix escaneará tu PC, deja que la herramienta trabaje.
• Luego publica el informe UsbFix.txt que aparecerá en el escritorio.
• Nota: El informe UsbFix.txt se guarda en la raíz del disco. (C:\UsbFix.txt)
( CTRL+A para seleccionar todo, CTRL+C para copiar y CTRL+V para pegar )
Nota: "Process.exe", un componente de la herramienta, es detectado por algunos antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) como un RiskTool.
No es un virus, sino una utilidad destinada a finalizar procesos.
En malas manos, esta utilidad podría detener programas de seguridad (Antivirus, Firewall...) de ahí la alerta emitida por estos antivirus.
• Tutorial: http://pagesperso-orange.fr/NosTools/usbfix.html
############################## | UsbFix V6.080 |
Utilisateur : doudou (Administrateurs) # PC-DE-DOUDOU
Mise à jour le 27/01/2010 par El Desaparecido, C_XX & Chimay8
Démarrer à : 19:37:10 | 27/01/2010
Site web : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
AMD Athlon(tm) X2 Dual-Core QL-64
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 7.0.6001.18000
Statut du pare-feu Windows : Activé
C:\ -> Disque fixe local # 138,49 Go (37,46 Go libre) # NTFS
D:\ -> Disque fixe local # 10,55 Go (1,78 Go libre) [RÉCUPÉRATION] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local # 465,65 Go (330,67 Go libre) [Données] # FAT32
############################## | Processus actifs |
C:\Windows\System32\smss.exe 432
C:\Windows\system32\csrss.exe 504
C:\Windows\system32\wininit.exe 564
C:\Windows\system32\csrss.exe 572
C:\Windows\system32\services.exe 612
C:\Windows\system32\lsass.exe 628
C:\Windows\system32\lsm.exe 636
C:\Windows\system32\winlogon.exe 676
C:\Windows\system32\svchost.exe 828
C:\Windows\system32\svchost.exe 896
C:\Windows\System32\svchost.exe 940
C:\Windows\system32\Ati2evxx.exe 992
C:\Windows\System32\svchost.exe 1020
C:\Windows\System32\svchost.exe 1176
C:\Windows\system32\svchost.exe 1196
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe 1220
C:\Windows\system32\SLsvc.exe 1384
C:\Windows\system32\Ati2evxx.exe 1432
C:\Windows\system32\svchost.exe 1448
C:\Windows\system32\Hpservice.exe 1596
C:\Windows\system32\Dwm.exe 1720
C:\Windows\system32\svchost.exe 1804
C:\Windows\Explorer.EXE 1904
C:\Windows\system32\runonce.exe 1964
C:\Windows\system32\WLANExt.exe 1972
C:\Windows\System32\spoolsv.exe 2028
C:\Windows\system32\taskeng.exe 2036
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe 444
C:\Users\doudou\AppData\Local\Temp\Hxr.exe 464
C:\Windows\system32\conime.exe 576
C:\Windows\system32\svchost.exe 820
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe 1668
C:\Windows\system32\taskeng.exe 1592
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe 1004
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 2120
C:\Program Files\Bonjour\mDNSResponder.exe 2168
C:\Windows\system32\svchost.exe 2188
C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2244
C:\Windows\system32\lxdxcoms.exe 2268
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe 2344
C:\Windows\system32\svchost.exe 2400
C:\Program Files\SMINST\BLService.exe 2420
C:\Program Files\CyberLink\Shared files\RichVideo.exe 2540
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2552
C:\Windows\system32\svchost.exe 2612
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe 2684
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe 2720
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe 2736
C:\Windows\System32\svchost.exe 2760
C:\Windows\system32\SearchIndexer.exe 2796
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 2944
C:\Windows\system32\wbem\wmiprvse.exe 3676
################## | Éléments infectieux |
Supprimé ! C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
Supprimé ! C:\Users\doudou\AppData\Local\Temp\Hxp.exe
Supprimé ! C:\Users\doudou\AppData\Local\Temp\Hxq.exe
Supprimé ! C:\Users\doudou\AppData\Local\Temp\Hxr.exe
Supprimé ! C:\Users\doudou\AppData\Local\Temp\a.dat
Supprimé ! C:\$Recycle.Bin\S-1-5-18
Supprimé ! C:\$Recycle.Bin\S-1-5-21-1106465231-353655327-60150735-500
Supprimé ! C:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-1000
Supprimé ! C:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-500
Supprimé ! D:\$Recycle.Bin\S-1-5-18
Supprimé ! D:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-1000
Supprimé ! D:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-500
################## | Registre |
Supprimé ! [HKCU\SOFTWARE\BMIMZMHMFM]
Supprimé ! [HKCU\SOFTWARE\Microsoft\Handle]
Supprimé ! [HKCU\SOFTWARE\WS9E3IQBKY]
Supprimé ! [HKCU\SOFTWARE\XML]
Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BMIMZMHMFM"
Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LosAlamos"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
Supprimé ! [HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] "DisableSR"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoClose"
################## | Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{26f6fe00-f16c-11de-88b7-00238b53fa22}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4936e25d-e726-11de-806b-00238b53fa22}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{8d6e00f9-ea15-11dd-9d90-00238b53fa22}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b52f6ccf-e469-11de-849b-00238b53fa22}\Shell\AutoRun\Command
################## | Liste des fichiers présents |
[18/09/2006 22:43|--a------|24] C:\autoexec.bat
[21/01/2008 03:24|-rahs----|333203] C:\bootmgr
[18/09/2006 22:43|--a------|10] C:\config.sys
[?|?|?] C:\hiberfil.sys
[?|?|?] C:\pagefile.sys
[30/11/2009 17:53|--a------|507] C:\TCleaner.txt
[27/01/2010 19:48|--a------|5377] C:\UsbFix.txt
[11/01/2009 00:38|---hs----|13] D:\BLOCK.RIN
[04/10/2006 00:02|---hs----|438328] D:\bootmgr
[12/09/2008 19:00|---hs----|1199] D:\Desktop.ini
[10/09/2002 17:14|---hs----|8134] D:\Folder.htt
[18/01/2009 16:13|--ahs----|22] D:\HPCD.sys
[27/01/2010 19:36|--ahs----|282] D:\MASTER.LOG
[12/09/2008 18:17|---hs----|381873] D:\protect.arabic
[15/09/2008 16:57|---hs----|182624] D:\protect.bulgarian
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese hong kong
[16/09/2002 15:37|---hs----|181916] D:\protect.chinese simplified
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese traditional
[27/04/2006 17:19|---hs----|181865] D:\protect.czech
[03/11/2005 16:21|---hs----|181726] D:\protect.danish
[10/09/2002 14:56|---hs----|181605] D:\protect.dutch
[10/09/2002 14:50|---hs----|181651] D:\protect.ed
[22/11/2004 16:28|---hs----|181648] D:\protect.english
[03/11/2005 16:20|---hs----|181673] D:\protect.finnish
[03/11/2005 16:19|---hs----|181736] D:\protect.french
[03/11/2005 16:18|---hs----|181669] D:\protect.german
[23/11/2005 16:56|---hs----|182689] D:\protect.greek
[23/01/2006 10:18|---hs----|182605] D:\protect.hebrew
[28/08/2007 15:58|---hs----|181696] D:\protect.hungarian
[03/11/2005 16:17|---hs----|181554] D:\protect.italian
[19/06/2007 16:22|---hs----|182351] D:\protect.japanese
[24/11/2005 12:24|---hs----|218295] D:\protect.korean
[03/11/2005 16:15|---hs----|181578] D:\protect.norwegian
[25/04/2006 15:44|---hs----|181789] D:\protect.polish
[03/11/2005 16:13|---hs----|181624] D:\protect.portuguese
[27/10/2005 20:24|---hs----|181882] D:\protect.portuguese brazilian
[15/09/2008 16:57|---hs----|181735] D:\protect.romanian
[28/06/2004 09:52|--a------|211936] D:\protect.russian
[04/07/2007 12:46|---hs----|181954] D:\protect.slovak
[03/11/2005 16:11|---hs----|181586] D:\protect.spanish
[10/09/2002 15:15|---hs----|181602] D:\protect.swedish
[12/08/2003 11:37|--a------|181783] D:\protect.turkish
[18/01/2009 14:45|-r-hs----|26] D:\RCBoot.sys
[18/01/2005 18:05|--a------|2144811] F:\Riddla - 05 - Parce Qu'on Vient De Loin.mp3
[20/12/2005 00:35|--a------|5670144] F:\Nina Sky & NORE - Oye Mi Canto.mp3
[20/12/2005 00:33|--a------|6960401] F:\Royal Gigolos - California dreaming.mp3
[30/12/2006 19:31|--a------|514510966] F:\rv.nrg
[21/05/2007 15:14|--a------|1849] F:\12.nri
[24/08/2006 19:32|--a------|11385] F:\msn.rtf
[04/09/2007 15:28|--a------|585] F:\Mes dossiers de partage.lnk
[08/07/2006 12:46|--a------|37896236] F:\ Sean Paul - Get Busy.wav
[26/03/2006 17:04|--a------|4407623] F:\ Whitney Houston & Mariah Carey - When You Believe.mp3
[08/07/2006 12:46|--a------|48704052] F:\ Whitney Houston & Mariah Carey - When You Believe.wav
[26/03/2006 17:31|--a------|3657856] F:\(Laam) Petite soeur.mp3
[08/07/2006 12:46|--a------|40322100] F:\(Laam) Petite soeur.wav
[20/08/2006 18:58|--a------|3734758] F:\01 01 Piste 1.wma
[20/08/2006 18:58|--a------|2951574] F:\01 All About Us.wma
[01/09/2006 18:34|--a------|3764496] F:\01 match nul.wma
[20/08/2006 18:58|--a------|3841998] F:\01 Rich Girl [Version Album].wma
[06/05/2007 21:45|--a------|3477462] F:\01 Someone.wma
[30/12/2007 22:44|--a------|4039206] F:\01 un jour de paix.wma
[10/12/2006 17:06|--a------|3148782] F:\01 Vois sur leur chemin.wma
[06/12/2006 12:08|--a------|3501654] F:\02 Boo.wma
[06/12/2006 11:59|--a------|5112772] F:\02 Schnappi das kleine krokodil.mp3
[08/07/2006 12:46|--a------|22549044] F:\02 Schnappi das kleine krokodil.wav
[20/08/2006 18:58|--a------|3573078] F:\02 What You Waiting For [Five].wma
[20/08/2006 18:59|--a------|4807106] F:\2_2_Maria carey - get your number.mp3
[08/07/2006 12:46|--a------|34511412] F:\2_2_Maria carey - get your number.wav
[20/08/2006 19:05|--a------|5275409] F:\2_Kelly Clarkson - Because Of You.mp3
[08/07/2006 12:46|--a------|38736948] F:\2_Kelly Clarkson - Because Of You.wav
[27/10/2006 16:21|--a------|5821589] F:\2_MarlŠne Duval et Phil Barney - avoir un seul enfant de toi.mp3
[08/07/2006 12:46|--a------|42757676] F:\2_MarlŠne Duval et Phil Barney - avoir un seul enfant de toi.wav
[26/03/2006 17:01|--a------|5931601] F:\2_Reggaeton ~ Pitbull Sean Paul Lil Jon - Culo Remix.mp3
[08/07/2006 12:46|--a------|53178420] F:\2_Reggaeton ~ Pitbull Sean Paul Lil Jon - Culo Remix.wav
[01/09/2006 18:34|--a------|4764032] F:\2_Sean Paul - Temperature.mp3
[08/07/2006 12:46|--a------|38248500] F:\2_Sean Paul - Temperature.wav
[19/04/2006 00:47|--a------|3812334] F:\03 03 Piste 3.wma
[20/08/2006 18:58|--a------|3131182] F:\04 04 Piste 4.wma
[20/08/2006 18:59|--a------|3148998] F:\04 Hey Sexy Wow.wma
[19/04/2006 00:47|--a------|3615126] F:\05 05 Piste 5.wma
[06/12/2006 12:08|--a------|3985750] F:\05 Et Si Tu N'Existais Pas.wma
[20/08/2006 18:59|--a------|4523478] F:\05 une époque formidable.wma
[20/08/2006 19:05|--a------|9945088] F:\06 - Baila Morena.mp3
[08/07/2006 12:46|--a------|43838004] F:\06 - Baila Morena.wav
[06/12/2006 12:08|--a------|3310462] F:\06 L'Enjeu (Enlève le Bas).wma
[06/12/2006 11:59|--a------|6044020] F:\06 Maria isabel antes muerta que sencilla.mp3
[08/07/2006 12:46|--a------|26659380] F:\06 Maria isabel antes muerta que sencilla.wav
[19/04/2006 00:47|--a------|3782454] F:\07 07 Piste 7.wma
[06/12/2006 12:08|--a------|3250682] F:\07 L'Homme Libre.wma
[29/03/2006 18:49|--a------|3283890] F:\07 Piste 7.wma
[29/03/2006 18:49|--a------|3259986] F:\08 Piste 8.wma
[06/12/2006 12:08|--a------|3639132] F:\09 Je Fais le Serment.wma
[20/08/2006 18:59|--a------|4051556] F:\09 ma vie.wma
[20/08/2006 18:58|--a------|3836350] F:\10 10 Piste 10.wma
[06/12/2006 12:08|--a------|3119234] F:\10 Le Meilleur Comme le Pire.wma
[06/12/2006 11:59|--a------|8958868] F:\11 Leslie vivons pour demain.mp3
[08/07/2006 12:46|--a------|39524916] F:\11 Leslie vivons pour demain.wav
[06/12/2006 12:08|--a------|3465818] F:\11 Mon Aphrodite.wma
[08/07/2006 12:46|--a------|63564852] F:\11. Confessions Nocturnes avec Vitaa.wav
[06/12/2006 12:08|--a------|5294486] F:\12 Donnez-Moi la Force.wma
[29/03/2006 18:50|--a------|2518962] F:\12 Piste 12.wma
[20/08/2006 18:58|--a------|3555478] F:\13 13 Piste 13.wma
[06/12/2006 12:08|--a------|4248666] F:\13 Hello [-].wma
[06/12/2006 12:08|--a------|4194884] F:\14 Beauté [-].wma
[19/04/2006 00:47|--a------|4314318] F:\15 15 Piste 15.wma
[20/08/2006 18:58|--a------|2844334] F:\16 16 Piste 16.wma
[19/04/2006 00:47|--a------|4756542] F:\17 17 Piste 17.wma
[20/08/2006 18:58|--a------|3609262] F:\18 18 Piste 18.wma
[19/04/2006 00:48|--a------|3292422] F:\19 19 Piste 19.wma
[20/08/2006 18:58|--a------|7003630] F:\20 20 Piste 20.wma
[29/03/2006 18:51|--a------|3660378] F:\20 Piste 20.wma
[29/03/2006 18:51|--a------|3355602] F:\21 Piste 21.wma
[26/03/2006 09:32|--a------|3863586] F:\Akon Lonely.wma
[20/08/2006 18:59|--a------|3588642] F:\Amel bent Ne retiens pas tes larmes.wma
[22/06/2006 18:39|--a------|6403232] F:\Black Eyed Peas - Pump It.mp3
[08/07/2006 12:46|--a------|41131052] F:\Black Eyed Peas - Pump It.wav
[23/08/2006 19:54|--a------|226] F:\DEFAULT.PLS
[09/04/2006 13:23|--a------|2961222] F:\Lou Bega.wma
[30/01/2009 16:57|--a------|4290183] F:\Carla_Bruni_-_Quelqu'un_m'a_dit.mp3
[08/07/2006 12:47|--a------|29405748] F:\Carla_Bruni_-_Quelqu'un_m'a_dit.wav
[20/08/2006 22:34|--a------|4841539] F:\Celine Dion - D'amour et d'amitie.mp3
[30/06/2006 13:23|--a------|3013112] F:\Choum - Mamie Girl (Barby Girl).mp3
[08/07/2006 12:47|--a------|33292844] F:\Choum - Mamie Girl (Barby Girl).wav
[30/06/2006 13:44|--a------|960436] F:\Choum Chanson cochonne - Jai la quequette qui colle.mp3
[08/07/2006 12:47|--a------|2648244] F:\Choum Chanson cochonne - Jai la quequette qui colle.wav
[23/08/2006 17:55|--a------|3694803] F:\Dadoo feat Vitaa-Fille facile(1).mp3
[25/03/2006 20:21|--a------|1682595] F:\Dezil La rivière.wma
[20/08/2006 14:08|--a------|4082251] F:\Didier Barbelivien & Felix Gray - A toutes les filles.mp3
[20/08/2006 19:05|--a------|5729456] F:\Doc Gyneco et Jhonny Hallyday - Le temps passe.mp3
[08/07/2006 12:47|--a------|42358836] F:\Doc Gyneco et Jhonny Hallyday - Le temps passe.wav
[09/12/2005 07:22|--a------|703] F:\échantillons de musique.lnk
[26/03/2006 17:47|--a------|7242571] F:\Emmanuel Moire - Mon Essentiel- Le Roi Soleil.mp3
[08/07/2006 12:47|--a------|31940148] F:\Emmanuel Moire - Mon Essentiel- Le Roi Soleil.wav
[14/03/2006 14:28|--a------|2763258] F:\frederica felini Je T'aime.mp3
[08/07/2006 12:47|--a------|30458924] F:\frederica felini Je T'aime.wav
[15/06/2005 08:07|--a------|403456] F:\Get More with Jukebox Plus.mp3
[08/07/2006 12:47|--a------|2932276] F:\Get More with Jukebox Plus.wav
[01/04/2008 21:44|--a------|2832500] F:\homme-femme acte II.wma
[12/03/2006 13:02|--a------|5750912] F:\KAYSHA ET LYNNSHA - Mélanger (Kaysha Et Lynsha).mp3
[08/07/2006 12:47|--a------|63398964] F:\KAYSHA ET LYNNSHA - Mélanger (Kaysha Et Lynsha).wav
[09/04/2006 12:00|--a------|3224166] F:\les bronzés.wma
[24/08/2006 18:59|--a------|3235738] F:\Keny Arkana - un joli rêve.mp3
[21/08/2006 20:54|--a------|1644674] F:\Keny Arkana-Mise A L Amende.mp3
[29/08/2006 23:43|--a------|10413948] F:\Kizito - Réponse au clash de Sinik et Diams.mp3
[30/06/2006 15:31|--a------|4503562] F:\Le 6-9 Nrj - D'Jeuner (Parodie Dj Diam's).mp3
[08/07/2006 12:47|--a------|28368948] F:\Le 6-9 Nrj - D'Jeuner (Parodie Dj Diam's).wav
[21/08/2006 20:52|--a------|5126277] F:\Les Murs De Ma Ville 1.mp3
[20/08/2006 18:59|--a------|3857578] F:\live is life.wma
[28/08/2006 17:36|--a------|3313726] F:\Lord Kossity- Sexe dans la piscine.mp3
[11/03/2006 23:45|--a------|4810628] F:\Lynsha - Rendez vous.mp3
[08/07/2006 12:47|--a------|35357228] F:\Lynsha - Rendez vous.wav
[26/03/2006 17:24|--a------|4066864] F:\Mariah Carey & Jay-Z - Heartbreaker.mp3
[08/07/2006 12:47|--a------|44835884] F:\Mariah Carey & Jay-Z - Heartbreaker.wav
[08/07/2006 00:00|--a------|328] F:\Mes documents.lnk
[06/11/2007 22:07|--a------|5117952] F:\james deano - branleur_de_service.mp3
[06/11/2007 21:20|--a------|1219988] F:\James deano - Esclave du système.loris.mp3
[06/11/2007 21:20|--a------|4753102] F:\James Deano - tu t'es vue.mp3
[19/11/2007 22:43|--a------|2479879] F:\African Drums - Surutu Kunu - Djembe solo.mp3
[06/11/2007 21:19|--a------|2402432] F:\James Deano - Ma vie c'est Koh-Lanta.mp3
[06/11/2007 21:23|--a------|3199521] F:\James Deano - Marijuana (Feat. S.KAA).mp3
[06/11/2007 21:24|--a------|6509802] F:\James Deano - Unknown Album - J'aime le shit.mp3
[06/11/2007 21:22|--a------|5304714] F:\james_deano - alcooliques_(inedit).mp3
[06/11/2007 21:49|--a------|3845269] F:\Leyla & Samia-laisse moi l'aimer(creil).mp3
[06/11/2007 21:38|--a------|4843779] F:\Samia - Etre là une dernière fois..mp3
[06/11/2007 21:51|--a------|3896838] F:\Samia - J'Vis Mon Rêve.mp3
[06/11/2007 21:47|--a------|3313387] F:\Samia - Mélancolique anonyme.mp3
[06/11/2007 22:04|--a------|3660128] F:\Samiam - Regret.mp3
[06/11/2007 21:36|--a------|2986361] F:\Samia - Papa.mp3
[06/11/2007 21:38|--a------|1770278] F:\Samia - Toi.mp3
[06/11/2007 21:37|--a------|4896776] F:\SAMIA Trop jeune.mp3
[06/11/2007 21:36|--a------|3781320] F:\SAMIA_reviens ma soeur.mp3
[06/11/2007 21:53|--a------|3428903] F:\Sig ft samia - tant de mal.mp3
[19/11/2007 23:16|--a------|5763208] F:\01. Sinik - De tout là haut.mp3
[19/11/2007 22:54|--a------|121836] F:\Album Sherifa Luna.mp3
[18/11/2007 15:50|--a------|8331079] F:\Blow Coxx - A LA RECHERCHE DE MA NOUVELLE MEUF.mp3
[18/11/2007 15:05|--a------|5794519] F:\Britney Spears - Gimmie more(1).mp3
[19/11/2007 23:19|--a------|6022501] F:\Dans mon club - Sinik - Le toit du monde.mp3
[19/11/2007 22:40|--a------|116877] F:\Je T'aime Lea Et Soprano.mp3
[18/11/2007 15:09|--a------|3450829] F:\Jenifer - Tourner la page.mp3
[19/11/2007 23:14|--a------|1939040] F:\Le toit du monde - 04 - Sinik - Dans mon club.mp3
[18/11/2007 15:19|--a------|3649534] F:\Monsieur R & Akhenaton - Et si c'était demain.mp3
[18/11/2007 15:03|--a------|5061161] F:\Sherifa Luna - Quelque part (Top Qualité).mp3
[19/11/2007 22:54|--a------|1901295] F:\Sherifa,Zack & StCyr - Quelqu'un comme toi (Pop Star).mp3
[19/11/2007 22:57|--a------|3562197] F:\Sheryfa_Luna_-_Il_Avait_Les_Mots-2007-BY_POP.mp3
[19/11/2007 23:19|--a------|1530883] F:\Sinik - Le monde est à vous.mp3
[19/11/2007 23:15|--a------|4013448] F:\Sinik - Le toit du monde - Trop pour un seul homme_.mp3
[18/11/2007 15:20|--a------|5420038] F:\Sinik feat Kayna Samet - De tout là haut.mp3
[19/11/2007 22:42|--a------|5839143] F:\Soprano - On Nous A Dit.mp3
[15/09/2007 14:22|--a------|4815717] F:\Fireball - WHAT I WANT (Greatest Riddim) (Soca 2007).mp3
[14/10/2007 14:18|--a------|7211874] F:\Hymnes de football - Supporters Marseillais - Live Marseille Au Vlodrome - Chants
Utilisateur : doudou (Administrateurs) # PC-DE-DOUDOU
Mise à jour le 27/01/2010 par El Desaparecido, C_XX & Chimay8
Démarrer à : 19:37:10 | 27/01/2010
Site web : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
AMD Athlon(tm) X2 Dual-Core QL-64
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 7.0.6001.18000
Statut du pare-feu Windows : Activé
C:\ -> Disque fixe local # 138,49 Go (37,46 Go libre) # NTFS
D:\ -> Disque fixe local # 10,55 Go (1,78 Go libre) [RÉCUPÉRATION] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local # 465,65 Go (330,67 Go libre) [Données] # FAT32
############################## | Processus actifs |
C:\Windows\System32\smss.exe 432
C:\Windows\system32\csrss.exe 504
C:\Windows\system32\wininit.exe 564
C:\Windows\system32\csrss.exe 572
C:\Windows\system32\services.exe 612
C:\Windows\system32\lsass.exe 628
C:\Windows\system32\lsm.exe 636
C:\Windows\system32\winlogon.exe 676
C:\Windows\system32\svchost.exe 828
C:\Windows\system32\svchost.exe 896
C:\Windows\System32\svchost.exe 940
C:\Windows\system32\Ati2evxx.exe 992
C:\Windows\System32\svchost.exe 1020
C:\Windows\System32\svchost.exe 1176
C:\Windows\system32\svchost.exe 1196
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe 1220
C:\Windows\system32\SLsvc.exe 1384
C:\Windows\system32\Ati2evxx.exe 1432
C:\Windows\system32\svchost.exe 1448
C:\Windows\system32\Hpservice.exe 1596
C:\Windows\system32\Dwm.exe 1720
C:\Windows\system32\svchost.exe 1804
C:\Windows\Explorer.EXE 1904
C:\Windows\system32\runonce.exe 1964
C:\Windows\system32\WLANExt.exe 1972
C:\Windows\System32\spoolsv.exe 2028
C:\Windows\system32\taskeng.exe 2036
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe 444
C:\Users\doudou\AppData\Local\Temp\Hxr.exe 464
C:\Windows\system32\conime.exe 576
C:\Windows\system32\svchost.exe 820
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe 1668
C:\Windows\system32\taskeng.exe 1592
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe 1004
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 2120
C:\Program Files\Bonjour\mDNSResponder.exe 2168
C:\Windows\system32\svchost.exe 2188
C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2244
C:\Windows\system32\lxdxcoms.exe 2268
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe 2344
C:\Windows\system32\svchost.exe 2400
C:\Program Files\SMINST\BLService.exe 2420
C:\Program Files\CyberLink\Shared files\RichVideo.exe 2540
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2552
C:\Windows\system32\svchost.exe 2612
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe 2684
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe 2720
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe 2736
C:\Windows\System32\svchost.exe 2760
C:\Windows\system32\SearchIndexer.exe 2796
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 2944
C:\Windows\system32\wbem\wmiprvse.exe 3676
################## | Éléments infectieux |
Supprimé ! C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
Supprimé ! C:\Users\doudou\AppData\Local\Temp\Hxp.exe
Supprimé ! C:\Users\doudou\AppData\Local\Temp\Hxq.exe
Supprimé ! C:\Users\doudou\AppData\Local\Temp\Hxr.exe
Supprimé ! C:\Users\doudou\AppData\Local\Temp\a.dat
Supprimé ! C:\$Recycle.Bin\S-1-5-18
Supprimé ! C:\$Recycle.Bin\S-1-5-21-1106465231-353655327-60150735-500
Supprimé ! C:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-1000
Supprimé ! C:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-500
Supprimé ! D:\$Recycle.Bin\S-1-5-18
Supprimé ! D:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-1000
Supprimé ! D:\$Recycle.Bin\S-1-5-21-617543292-1238902445-2930710245-500
################## | Registre |
Supprimé ! [HKCU\SOFTWARE\BMIMZMHMFM]
Supprimé ! [HKCU\SOFTWARE\Microsoft\Handle]
Supprimé ! [HKCU\SOFTWARE\WS9E3IQBKY]
Supprimé ! [HKCU\SOFTWARE\XML]
Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BMIMZMHMFM"
Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LosAlamos"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
Supprimé ! [HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] "DisableSR"
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoClose"
################## | Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{26f6fe00-f16c-11de-88b7-00238b53fa22}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4936e25d-e726-11de-806b-00238b53fa22}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{8d6e00f9-ea15-11dd-9d90-00238b53fa22}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b52f6ccf-e469-11de-849b-00238b53fa22}\Shell\AutoRun\Command
################## | Liste des fichiers présents |
[18/09/2006 22:43|--a------|24] C:\autoexec.bat
[21/01/2008 03:24|-rahs----|333203] C:\bootmgr
[18/09/2006 22:43|--a------|10] C:\config.sys
[?|?|?] C:\hiberfil.sys
[?|?|?] C:\pagefile.sys
[30/11/2009 17:53|--a------|507] C:\TCleaner.txt
[27/01/2010 19:48|--a------|5377] C:\UsbFix.txt
[11/01/2009 00:38|---hs----|13] D:\BLOCK.RIN
[04/10/2006 00:02|---hs----|438328] D:\bootmgr
[12/09/2008 19:00|---hs----|1199] D:\Desktop.ini
[10/09/2002 17:14|---hs----|8134] D:\Folder.htt
[18/01/2009 16:13|--ahs----|22] D:\HPCD.sys
[27/01/2010 19:36|--ahs----|282] D:\MASTER.LOG
[12/09/2008 18:17|---hs----|381873] D:\protect.arabic
[15/09/2008 16:57|---hs----|182624] D:\protect.bulgarian
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese hong kong
[16/09/2002 15:37|---hs----|181916] D:\protect.chinese simplified
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese traditional
[27/04/2006 17:19|---hs----|181865] D:\protect.czech
[03/11/2005 16:21|---hs----|181726] D:\protect.danish
[10/09/2002 14:56|---hs----|181605] D:\protect.dutch
[10/09/2002 14:50|---hs----|181651] D:\protect.ed
[22/11/2004 16:28|---hs----|181648] D:\protect.english
[03/11/2005 16:20|---hs----|181673] D:\protect.finnish
[03/11/2005 16:19|---hs----|181736] D:\protect.french
[03/11/2005 16:18|---hs----|181669] D:\protect.german
[23/11/2005 16:56|---hs----|182689] D:\protect.greek
[23/01/2006 10:18|---hs----|182605] D:\protect.hebrew
[28/08/2007 15:58|---hs----|181696] D:\protect.hungarian
[03/11/2005 16:17|---hs----|181554] D:\protect.italian
[19/06/2007 16:22|---hs----|182351] D:\protect.japanese
[24/11/2005 12:24|---hs----|218295] D:\protect.korean
[03/11/2005 16:15|---hs----|181578] D:\protect.norwegian
[25/04/2006 15:44|---hs----|181789] D:\protect.polish
[03/11/2005 16:13|---hs----|181624] D:\protect.portuguese
[27/10/2005 20:24|---hs----|181882] D:\protect.portuguese brazilian
[15/09/2008 16:57|---hs----|181735] D:\protect.romanian
[28/06/2004 09:52|--a------|211936] D:\protect.russian
[04/07/2007 12:46|---hs----|181954] D:\protect.slovak
[03/11/2005 16:11|---hs----|181586] D:\protect.spanish
[10/09/2002 15:15|---hs----|181602] D:\protect.swedish
[12/08/2003 11:37|--a------|181783] D:\protect.turkish
[18/01/2009 14:45|-r-hs----|26] D:\RCBoot.sys
[18/01/2005 18:05|--a------|2144811] F:\Riddla - 05 - Parce Qu'on Vient De Loin.mp3
[20/12/2005 00:35|--a------|5670144] F:\Nina Sky & NORE - Oye Mi Canto.mp3
[20/12/2005 00:33|--a------|6960401] F:\Royal Gigolos - California dreaming.mp3
[30/12/2006 19:31|--a------|514510966] F:\rv.nrg
[21/05/2007 15:14|--a------|1849] F:\12.nri
[24/08/2006 19:32|--a------|11385] F:\msn.rtf
[04/09/2007 15:28|--a------|585] F:\Mes dossiers de partage.lnk
[08/07/2006 12:46|--a------|37896236] F:\ Sean Paul - Get Busy.wav
[26/03/2006 17:04|--a------|4407623] F:\ Whitney Houston & Mariah Carey - When You Believe.mp3
[08/07/2006 12:46|--a------|48704052] F:\ Whitney Houston & Mariah Carey - When You Believe.wav
[26/03/2006 17:31|--a------|3657856] F:\(Laam) Petite soeur.mp3
[08/07/2006 12:46|--a------|40322100] F:\(Laam) Petite soeur.wav
[20/08/2006 18:58|--a------|3734758] F:\01 01 Piste 1.wma
[20/08/2006 18:58|--a------|2951574] F:\01 All About Us.wma
[01/09/2006 18:34|--a------|3764496] F:\01 match nul.wma
[20/08/2006 18:58|--a------|3841998] F:\01 Rich Girl [Version Album].wma
[06/05/2007 21:45|--a------|3477462] F:\01 Someone.wma
[30/12/2007 22:44|--a------|4039206] F:\01 un jour de paix.wma
[10/12/2006 17:06|--a------|3148782] F:\01 Vois sur leur chemin.wma
[06/12/2006 12:08|--a------|3501654] F:\02 Boo.wma
[06/12/2006 11:59|--a------|5112772] F:\02 Schnappi das kleine krokodil.mp3
[08/07/2006 12:46|--a------|22549044] F:\02 Schnappi das kleine krokodil.wav
[20/08/2006 18:58|--a------|3573078] F:\02 What You Waiting For [Five].wma
[20/08/2006 18:59|--a------|4807106] F:\2_2_Maria carey - get your number.mp3
[08/07/2006 12:46|--a------|34511412] F:\2_2_Maria carey - get your number.wav
[20/08/2006 19:05|--a------|5275409] F:\2_Kelly Clarkson - Because Of You.mp3
[08/07/2006 12:46|--a------|38736948] F:\2_Kelly Clarkson - Because Of You.wav
[27/10/2006 16:21|--a------|5821589] F:\2_MarlŠne Duval et Phil Barney - avoir un seul enfant de toi.mp3
[08/07/2006 12:46|--a------|42757676] F:\2_MarlŠne Duval et Phil Barney - avoir un seul enfant de toi.wav
[26/03/2006 17:01|--a------|5931601] F:\2_Reggaeton ~ Pitbull Sean Paul Lil Jon - Culo Remix.mp3
[08/07/2006 12:46|--a------|53178420] F:\2_Reggaeton ~ Pitbull Sean Paul Lil Jon - Culo Remix.wav
[01/09/2006 18:34|--a------|4764032] F:\2_Sean Paul - Temperature.mp3
[08/07/2006 12:46|--a------|38248500] F:\2_Sean Paul - Temperature.wav
[19/04/2006 00:47|--a------|3812334] F:\03 03 Piste 3.wma
[20/08/2006 18:58|--a------|3131182] F:\04 04 Piste 4.wma
[20/08/2006 18:59|--a------|3148998] F:\04 Hey Sexy Wow.wma
[19/04/2006 00:47|--a------|3615126] F:\05 05 Piste 5.wma
[06/12/2006 12:08|--a------|3985750] F:\05 Et Si Tu N'Existais Pas.wma
[20/08/2006 18:59|--a------|4523478] F:\05 une époque formidable.wma
[20/08/2006 19:05|--a------|9945088] F:\06 - Baila Morena.mp3
[08/07/2006 12:46|--a------|43838004] F:\06 - Baila Morena.wav
[06/12/2006 12:08|--a------|3310462] F:\06 L'Enjeu (Enlève le Bas).wma
[06/12/2006 11:59|--a------|6044020] F:\06 Maria isabel antes muerta que sencilla.mp3
[08/07/2006 12:46|--a------|26659380] F:\06 Maria isabel antes muerta que sencilla.wav
[19/04/2006 00:47|--a------|3782454] F:\07 07 Piste 7.wma
[06/12/2006 12:08|--a------|3250682] F:\07 L'Homme Libre.wma
[29/03/2006 18:49|--a------|3283890] F:\07 Piste 7.wma
[29/03/2006 18:49|--a------|3259986] F:\08 Piste 8.wma
[06/12/2006 12:08|--a------|3639132] F:\09 Je Fais le Serment.wma
[20/08/2006 18:59|--a------|4051556] F:\09 ma vie.wma
[20/08/2006 18:58|--a------|3836350] F:\10 10 Piste 10.wma
[06/12/2006 12:08|--a------|3119234] F:\10 Le Meilleur Comme le Pire.wma
[06/12/2006 11:59|--a------|8958868] F:\11 Leslie vivons pour demain.mp3
[08/07/2006 12:46|--a------|39524916] F:\11 Leslie vivons pour demain.wav
[06/12/2006 12:08|--a------|3465818] F:\11 Mon Aphrodite.wma
[08/07/2006 12:46|--a------|63564852] F:\11. Confessions Nocturnes avec Vitaa.wav
[06/12/2006 12:08|--a------|5294486] F:\12 Donnez-Moi la Force.wma
[29/03/2006 18:50|--a------|2518962] F:\12 Piste 12.wma
[20/08/2006 18:58|--a------|3555478] F:\13 13 Piste 13.wma
[06/12/2006 12:08|--a------|4248666] F:\13 Hello [-].wma
[06/12/2006 12:08|--a------|4194884] F:\14 Beauté [-].wma
[19/04/2006 00:47|--a------|4314318] F:\15 15 Piste 15.wma
[20/08/2006 18:58|--a------|2844334] F:\16 16 Piste 16.wma
[19/04/2006 00:47|--a------|4756542] F:\17 17 Piste 17.wma
[20/08/2006 18:58|--a------|3609262] F:\18 18 Piste 18.wma
[19/04/2006 00:48|--a------|3292422] F:\19 19 Piste 19.wma
[20/08/2006 18:58|--a------|7003630] F:\20 20 Piste 20.wma
[29/03/2006 18:51|--a------|3660378] F:\20 Piste 20.wma
[29/03/2006 18:51|--a------|3355602] F:\21 Piste 21.wma
[26/03/2006 09:32|--a------|3863586] F:\Akon Lonely.wma
[20/08/2006 18:59|--a------|3588642] F:\Amel bent Ne retiens pas tes larmes.wma
[22/06/2006 18:39|--a------|6403232] F:\Black Eyed Peas - Pump It.mp3
[08/07/2006 12:46|--a------|41131052] F:\Black Eyed Peas - Pump It.wav
[23/08/2006 19:54|--a------|226] F:\DEFAULT.PLS
[09/04/2006 13:23|--a------|2961222] F:\Lou Bega.wma
[30/01/2009 16:57|--a------|4290183] F:\Carla_Bruni_-_Quelqu'un_m'a_dit.mp3
[08/07/2006 12:47|--a------|29405748] F:\Carla_Bruni_-_Quelqu'un_m'a_dit.wav
[20/08/2006 22:34|--a------|4841539] F:\Celine Dion - D'amour et d'amitie.mp3
[30/06/2006 13:23|--a------|3013112] F:\Choum - Mamie Girl (Barby Girl).mp3
[08/07/2006 12:47|--a------|33292844] F:\Choum - Mamie Girl (Barby Girl).wav
[30/06/2006 13:44|--a------|960436] F:\Choum Chanson cochonne - Jai la quequette qui colle.mp3
[08/07/2006 12:47|--a------|2648244] F:\Choum Chanson cochonne - Jai la quequette qui colle.wav
[23/08/2006 17:55|--a------|3694803] F:\Dadoo feat Vitaa-Fille facile(1).mp3
[25/03/2006 20:21|--a------|1682595] F:\Dezil La rivière.wma
[20/08/2006 14:08|--a------|4082251] F:\Didier Barbelivien & Felix Gray - A toutes les filles.mp3
[20/08/2006 19:05|--a------|5729456] F:\Doc Gyneco et Jhonny Hallyday - Le temps passe.mp3
[08/07/2006 12:47|--a------|42358836] F:\Doc Gyneco et Jhonny Hallyday - Le temps passe.wav
[09/12/2005 07:22|--a------|703] F:\échantillons de musique.lnk
[26/03/2006 17:47|--a------|7242571] F:\Emmanuel Moire - Mon Essentiel- Le Roi Soleil.mp3
[08/07/2006 12:47|--a------|31940148] F:\Emmanuel Moire - Mon Essentiel- Le Roi Soleil.wav
[14/03/2006 14:28|--a------|2763258] F:\frederica felini Je T'aime.mp3
[08/07/2006 12:47|--a------|30458924] F:\frederica felini Je T'aime.wav
[15/06/2005 08:07|--a------|403456] F:\Get More with Jukebox Plus.mp3
[08/07/2006 12:47|--a------|2932276] F:\Get More with Jukebox Plus.wav
[01/04/2008 21:44|--a------|2832500] F:\homme-femme acte II.wma
[12/03/2006 13:02|--a------|5750912] F:\KAYSHA ET LYNNSHA - Mélanger (Kaysha Et Lynsha).mp3
[08/07/2006 12:47|--a------|63398964] F:\KAYSHA ET LYNNSHA - Mélanger (Kaysha Et Lynsha).wav
[09/04/2006 12:00|--a------|3224166] F:\les bronzés.wma
[24/08/2006 18:59|--a------|3235738] F:\Keny Arkana - un joli rêve.mp3
[21/08/2006 20:54|--a------|1644674] F:\Keny Arkana-Mise A L Amende.mp3
[29/08/2006 23:43|--a------|10413948] F:\Kizito - Réponse au clash de Sinik et Diams.mp3
[30/06/2006 15:31|--a------|4503562] F:\Le 6-9 Nrj - D'Jeuner (Parodie Dj Diam's).mp3
[08/07/2006 12:47|--a------|28368948] F:\Le 6-9 Nrj - D'Jeuner (Parodie Dj Diam's).wav
[21/08/2006 20:52|--a------|5126277] F:\Les Murs De Ma Ville 1.mp3
[20/08/2006 18:59|--a------|3857578] F:\live is life.wma
[28/08/2006 17:36|--a------|3313726] F:\Lord Kossity- Sexe dans la piscine.mp3
[11/03/2006 23:45|--a------|4810628] F:\Lynsha - Rendez vous.mp3
[08/07/2006 12:47|--a------|35357228] F:\Lynsha - Rendez vous.wav
[26/03/2006 17:24|--a------|4066864] F:\Mariah Carey & Jay-Z - Heartbreaker.mp3
[08/07/2006 12:47|--a------|44835884] F:\Mariah Carey & Jay-Z - Heartbreaker.wav
[08/07/2006 00:00|--a------|328] F:\Mes documents.lnk
[06/11/2007 22:07|--a------|5117952] F:\james deano - branleur_de_service.mp3
[06/11/2007 21:20|--a------|1219988] F:\James deano - Esclave du système.loris.mp3
[06/11/2007 21:20|--a------|4753102] F:\James Deano - tu t'es vue.mp3
[19/11/2007 22:43|--a------|2479879] F:\African Drums - Surutu Kunu - Djembe solo.mp3
[06/11/2007 21:19|--a------|2402432] F:\James Deano - Ma vie c'est Koh-Lanta.mp3
[06/11/2007 21:23|--a------|3199521] F:\James Deano - Marijuana (Feat. S.KAA).mp3
[06/11/2007 21:24|--a------|6509802] F:\James Deano - Unknown Album - J'aime le shit.mp3
[06/11/2007 21:22|--a------|5304714] F:\james_deano - alcooliques_(inedit).mp3
[06/11/2007 21:49|--a------|3845269] F:\Leyla & Samia-laisse moi l'aimer(creil).mp3
[06/11/2007 21:38|--a------|4843779] F:\Samia - Etre là une dernière fois..mp3
[06/11/2007 21:51|--a------|3896838] F:\Samia - J'Vis Mon Rêve.mp3
[06/11/2007 21:47|--a------|3313387] F:\Samia - Mélancolique anonyme.mp3
[06/11/2007 22:04|--a------|3660128] F:\Samiam - Regret.mp3
[06/11/2007 21:36|--a------|2986361] F:\Samia - Papa.mp3
[06/11/2007 21:38|--a------|1770278] F:\Samia - Toi.mp3
[06/11/2007 21:37|--a------|4896776] F:\SAMIA Trop jeune.mp3
[06/11/2007 21:36|--a------|3781320] F:\SAMIA_reviens ma soeur.mp3
[06/11/2007 21:53|--a------|3428903] F:\Sig ft samia - tant de mal.mp3
[19/11/2007 23:16|--a------|5763208] F:\01. Sinik - De tout là haut.mp3
[19/11/2007 22:54|--a------|121836] F:\Album Sherifa Luna.mp3
[18/11/2007 15:50|--a------|8331079] F:\Blow Coxx - A LA RECHERCHE DE MA NOUVELLE MEUF.mp3
[18/11/2007 15:05|--a------|5794519] F:\Britney Spears - Gimmie more(1).mp3
[19/11/2007 23:19|--a------|6022501] F:\Dans mon club - Sinik - Le toit du monde.mp3
[19/11/2007 22:40|--a------|116877] F:\Je T'aime Lea Et Soprano.mp3
[18/11/2007 15:09|--a------|3450829] F:\Jenifer - Tourner la page.mp3
[19/11/2007 23:14|--a------|1939040] F:\Le toit du monde - 04 - Sinik - Dans mon club.mp3
[18/11/2007 15:19|--a------|3649534] F:\Monsieur R & Akhenaton - Et si c'était demain.mp3
[18/11/2007 15:03|--a------|5061161] F:\Sherifa Luna - Quelque part (Top Qualité).mp3
[19/11/2007 22:54|--a------|1901295] F:\Sherifa,Zack & StCyr - Quelqu'un comme toi (Pop Star).mp3
[19/11/2007 22:57|--a------|3562197] F:\Sheryfa_Luna_-_Il_Avait_Les_Mots-2007-BY_POP.mp3
[19/11/2007 23:19|--a------|1530883] F:\Sinik - Le monde est à vous.mp3
[19/11/2007 23:15|--a------|4013448] F:\Sinik - Le toit du monde - Trop pour un seul homme_.mp3
[18/11/2007 15:20|--a------|5420038] F:\Sinik feat Kayna Samet - De tout là haut.mp3
[19/11/2007 22:42|--a------|5839143] F:\Soprano - On Nous A Dit.mp3
[15/09/2007 14:22|--a------|4815717] F:\Fireball - WHAT I WANT (Greatest Riddim) (Soca 2007).mp3
[14/10/2007 14:18|--a------|7211874] F:\Hymnes de football - Supporters Marseillais - Live Marseille Au Vlodrome - Chants
Ok, he visto el informe en mp.
#####
• Descarga OTM (OldTimer) en tu Escritorio.
• Haz clic derecho en OTM.exe y elige Ejecutar como administrador.
• Copia (Ctrl+C) el siguiente texto a continuación:
:processes
explorer.exe
:files
c:\windows\system32\frcqtxz.dll
C:\Users\doudou\AppData\Local\Temp\mldnjz.exe
C:\Users\doudou\AppData\Roaming\SystemProc
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"sefjhf98jfoidsfoishgoiusgdgfgd"=-
:commands
[purity]
[emptytemp]
[reboot]
• Pega (Ctrl+V) el texto copiado anteriormente en el cuadro Pegar Instrucciones para Elementos a Mover.
• Ahora haz clic en el botón MoveIt! y luego cierra OTM.
---> Si un archivo o carpeta no se puede eliminar inmediatamente, el software te pedirá que reinicies.
Acepta haciendo clic en YES.
• Publica el informe ubicado en esta carpeta: C:\_OTM\MovedFiles\
---> El nombre del informe corresponde al momento de su creación: fecha_hora.log
#########
• Descarga Malwarebytes' Anti-Malware (MBAM) en tu Escritorio.
• Haz doble clic en el archivo descargado para iniciar el proceso de instalación.
• En la pestaña Actualización, haz clic en el botón Buscar actualizaciones: si el firewall solicita autorización a MBAM para conectarse a Internet, acepta.
• Una vez que se complete la actualización, ve a la pestaña Análisis.
• Selecciona Ejecutar un análisis rápido.
• Haz clic en Buscar. El análisis comenzará.
• Al final del análisis, aparecerá un mensaje:
"El análisis se ha completado normalmente. Haz clic en 'Mostrar resultados' para ver todos los objetos encontrados."
• Haz clic en Aceptar para continuar. Si MBAM no ha encontrado nada, también te lo dirá.
• Cierra tus navegadores.
• Si se han detectado malware, haz clic en Mostrar resultados.
• Selecciona todo (o deja marcado) y haz clic en Eliminar selección, MBAM destruirá los archivos y claves de registro infectados y pondrá una copia en cuarentena.
• MBAM abrirá el Bloc de notas y copiará el informe del análisis. Copia y pega este informe en tu próxima respuesta.
#####
• Descarga OTM (OldTimer) en tu Escritorio.
• Haz clic derecho en OTM.exe y elige Ejecutar como administrador.
• Copia (Ctrl+C) el siguiente texto a continuación:
:processes
explorer.exe
:files
c:\windows\system32\frcqtxz.dll
C:\Users\doudou\AppData\Local\Temp\mldnjz.exe
C:\Users\doudou\AppData\Roaming\SystemProc
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"sefjhf98jfoidsfoishgoiusgdgfgd"=-
:commands
[purity]
[emptytemp]
[reboot]
• Pega (Ctrl+V) el texto copiado anteriormente en el cuadro Pegar Instrucciones para Elementos a Mover.
• Ahora haz clic en el botón MoveIt! y luego cierra OTM.
---> Si un archivo o carpeta no se puede eliminar inmediatamente, el software te pedirá que reinicies.
Acepta haciendo clic en YES.
• Publica el informe ubicado en esta carpeta: C:\_OTM\MovedFiles\
---> El nombre del informe corresponde al momento de su creación: fecha_hora.log
#########
• Descarga Malwarebytes' Anti-Malware (MBAM) en tu Escritorio.
• Haz doble clic en el archivo descargado para iniciar el proceso de instalación.
• En la pestaña Actualización, haz clic en el botón Buscar actualizaciones: si el firewall solicita autorización a MBAM para conectarse a Internet, acepta.
• Una vez que se complete la actualización, ve a la pestaña Análisis.
• Selecciona Ejecutar un análisis rápido.
• Haz clic en Buscar. El análisis comenzará.
• Al final del análisis, aparecerá un mensaje:
"El análisis se ha completado normalmente. Haz clic en 'Mostrar resultados' para ver todos los objetos encontrados."
• Haz clic en Aceptar para continuar. Si MBAM no ha encontrado nada, también te lo dirá.
• Cierra tus navegadores.
• Si se han detectado malware, haz clic en Mostrar resultados.
• Selecciona todo (o deja marcado) y haz clic en Eliminar selección, MBAM destruirá los archivos y claves de registro infectados y pondrá una copia en cuarentena.
• MBAM abrirá el Bloc de notas y copiará el informe del análisis. Copia y pega este informe en tu próxima respuesta.
Todos los procesos finalizados
========== PROCESOS ==========
¡No se encontró ningún proceso activo llamado explorer.exe!
========== ARCHIVOS ==========
Archivo/Carpeta c:\windows\system32\frcqtxz.dll no encontrado.
Archivo/Carpeta C:\Users\doudou\AppData\Local\Temp\mldnjz.exe no encontrado.
La carpeta C:\Users\doudou\AppData\Roaming\SystemProc se movió correctamente.
========== REGISTRO ==========
No se encontró la clave del registro HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}\.
La clave del registro HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}\ se eliminó correctamente.
No se encontró la clave del registro HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.
========== COMANDOS ==========
[EMPTYTEMP]
Usuario: Todos los Usuarios
Usuario: Predeterminado
->Se vació la carpeta Temp: 0 bytes
->Se vació la carpeta de Archivos Temporales de Internet: 33170 bytes
Usuario: Usuario Predeterminado
->Se vació la carpeta Temp: 0 bytes
->Se vació la carpeta de Archivos Temporales de Internet: 0 bytes
Usuario: doudou
->Se vació la carpeta Temp: 1375232923 bytes
->Se vació la carpeta de Archivos Temporales de Internet: 66695955 bytes
->Se vació la caché de Java: 26033020 bytes
->Se vació la caché de FireFox: 38833782 bytes
Usuario: Público
Archivos .tmp eliminados de %systemdrive%: 0 bytes
Archivos .tmp eliminados de %systemroot%: 0 bytes
Archivos .tmp eliminados de %systemroot%\System32: 0 bytes
Archivos .tmp eliminados de %systemroot%\System32\drivers: 0 bytes
Se vació la carpeta Temp de Windows: 13341516 bytes
Se vació la carpeta de Archivos Temporales de Internet de %systemroot%\system32\config\systemprofile\Local Settings: 0 bytes
Se vació la carpeta de Archivos Temporales de Internet de %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows: 114143 bytes
La Papelera de reciclaje se vació: 0 bytes
Total de Archivos Limpiados = 1 450,00 mb
OTM by OldTimer - Versión 3.1.7.0 registro creado el 01272010_203103
Archivos movidos al reiniciar...
¡Archivo C:\Windows\temp\TMP00000041AB6BCEE3DD0BFA40 no encontrado!
¡Archivo C:\Windows\temp\TMP0000004E1585CE48354408B5 no encontrado!
Entradas del registro eliminadas al reiniciar...
========== PROCESOS ==========
¡No se encontró ningún proceso activo llamado explorer.exe!
========== ARCHIVOS ==========
Archivo/Carpeta c:\windows\system32\frcqtxz.dll no encontrado.
Archivo/Carpeta C:\Users\doudou\AppData\Local\Temp\mldnjz.exe no encontrado.
La carpeta C:\Users\doudou\AppData\Roaming\SystemProc se movió correctamente.
========== REGISTRO ==========
No se encontró la clave del registro HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}\.
La clave del registro HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}\ se eliminó correctamente.
No se encontró la clave del registro HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.
========== COMANDOS ==========
[EMPTYTEMP]
Usuario: Todos los Usuarios
Usuario: Predeterminado
->Se vació la carpeta Temp: 0 bytes
->Se vació la carpeta de Archivos Temporales de Internet: 33170 bytes
Usuario: Usuario Predeterminado
->Se vació la carpeta Temp: 0 bytes
->Se vació la carpeta de Archivos Temporales de Internet: 0 bytes
Usuario: doudou
->Se vació la carpeta Temp: 1375232923 bytes
->Se vació la carpeta de Archivos Temporales de Internet: 66695955 bytes
->Se vació la caché de Java: 26033020 bytes
->Se vació la caché de FireFox: 38833782 bytes
Usuario: Público
Archivos .tmp eliminados de %systemdrive%: 0 bytes
Archivos .tmp eliminados de %systemroot%: 0 bytes
Archivos .tmp eliminados de %systemroot%\System32: 0 bytes
Archivos .tmp eliminados de %systemroot%\System32\drivers: 0 bytes
Se vació la carpeta Temp de Windows: 13341516 bytes
Se vació la carpeta de Archivos Temporales de Internet de %systemroot%\system32\config\systemprofile\Local Settings: 0 bytes
Se vació la carpeta de Archivos Temporales de Internet de %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows: 114143 bytes
La Papelera de reciclaje se vació: 0 bytes
Total de Archivos Limpiados = 1 450,00 mb
OTM by OldTimer - Versión 3.1.7.0 registro creado el 01272010_203103
Archivos movidos al reiniciar...
¡Archivo C:\Windows\temp\TMP00000041AB6BCEE3DD0BFA40 no encontrado!
¡Archivo C:\Windows\temp\TMP0000004E1585CE48354408B5 no encontrado!
Entradas del registro eliminadas al reiniciar...
Malwarebytes' Anti-Malware 1.44
Versión de la base de datos: 3646
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
27/01/2010 21:00:40
mbam-log-2010-01-27 (21-00-40).txt
Tipo de búsqueda: Análisis rápido
Elementos examinados: 100280
Tiempo transcurrido: 8 minuto(s), 27 segundo(s)
Procesos en memoria infectados: 0
Módulo(s) en memoria infectados: 0
Clave(s) del Registro infectada(s): 1
Valor(es) del Registro infectado(s): 2
Elemento(s) de datos del Registro infectado(s): 0
Carpeta(s) infectada(s): 3
Archivo(s) infectado(s): 4
Procesos en memoria infectados:
(Ningún elemento dañino detectado)
Módulo(s) en memoria infectados:
(Ningún elemento dañino detectado)
Clave(s) del Registro infectada(s):
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Puesta en cuarentena y eliminada con éxito.
Valor(es) del Registro infectado(s):
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls\appsecdll (Spyware.Passwords) -> Puesta en cuarentena y eliminada con éxito.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sefjhf98jfoidsfoishgoiusgdgfgd (Trojan.Downloader) -> Puesta en cuarentena y eliminada con éxito.
Elemento(s) de datos del Registro infectado(s):
(Ningún elemento dañino detectado)
Carpeta(s) infectada(s):
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D} (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
Archivo(s) infectado(s):
C:\Windows\system32\Drivers\lidnfab.sys (Rootkit.Agent) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
Versión de la base de datos: 3646
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
27/01/2010 21:00:40
mbam-log-2010-01-27 (21-00-40).txt
Tipo de búsqueda: Análisis rápido
Elementos examinados: 100280
Tiempo transcurrido: 8 minuto(s), 27 segundo(s)
Procesos en memoria infectados: 0
Módulo(s) en memoria infectados: 0
Clave(s) del Registro infectada(s): 1
Valor(es) del Registro infectado(s): 2
Elemento(s) de datos del Registro infectado(s): 0
Carpeta(s) infectada(s): 3
Archivo(s) infectado(s): 4
Procesos en memoria infectados:
(Ningún elemento dañino detectado)
Módulo(s) en memoria infectados:
(Ningún elemento dañino detectado)
Clave(s) del Registro infectada(s):
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Puesta en cuarentena y eliminada con éxito.
Valor(es) del Registro infectado(s):
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls\appsecdll (Spyware.Passwords) -> Puesta en cuarentena y eliminada con éxito.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sefjhf98jfoidsfoishgoiusgdgfgd (Trojan.Downloader) -> Puesta en cuarentena y eliminada con éxito.
Elemento(s) de datos del Registro infectado(s):
(Ningún elemento dañino detectado)
Carpeta(s) infectada(s):
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D} (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
Archivo(s) infectado(s):
C:\Windows\system32\Drivers\lidnfab.sys (Rootkit.Agent) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Trojan.Swisyn) -> Puesta en cuarentena y eliminada con éxito.
Reabre Malwarebytes, ve a cuarentena y elimina todo.
¿Cómo va el PC? ¿mejor?
####
Haz un escaneo de RSIT de nuevo y publica el log.txt por favor.
¿Cómo va el PC? ¿mejor?
####
Haz un escaneo de RSIT de nuevo y publica el log.txt por favor.
Registro de la herramienta de información del sistema de random 1.06 (escrito por random/random)
Ejecutado por doudou el 27-01-2010 a las 21:08:48
Microsoft® Windows Vista™ Edición Familiar Premium Service Pack 1
La unidad del sistema C: tiene 39 GB (28%) libres de 142 GB
Total de RAM: 3069 MB (60% libres)
Registro de Trend Micro HijackThis v2.0.2
Escaneo guardado a las 21:08:52, el 27/01/2010
Plataforma: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18385)
Modo de arranque: Normal
Procesos en ejecución:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\doudou\Downloads\RSIT.exe
C:\Program Files\trend micro\doudou.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Programa de ayuda del Asistente de conexión Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (sin nombre) - {BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2} - (sin archivo)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\STEAM2\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Usuario 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Usuario 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Usuario 'SERVICIO DE RED')
O4 - HKUS\S-1-5-18\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (Usuario 'SISTEMA')
O4 - HKUS\.DEFAULT\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (Usuario 'Usuario predeterminado')
O8 - Elemento adicional del menú contextual: &Búsqueda en AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\fr-FR\local\search.html
O8 - Elemento adicional del menú contextual: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Botón adicional: Agregar Directo - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Elemento de menú adicional 'Herramientas': &Agregar Directo en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Botón adicional: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Elemento de menú adicional 'Herramientas': &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Botón adicional: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Botón adicional: Investigación - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Botón adicional: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo faltante)
O9 - Elemento de menú adicional 'Herramientas': PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo faltante)
O13 - Prefijo Gopher:
O20 - AppInit_DLLs: C:\Windows\system32\kbdsock.dll
O23 - Servicio: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe
O23 - Servicio: Planificador Avira AntiVir Personal - Antivirus gratuito (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Servicio: Avira AntiVir Personal - Guardias de Antivirus gratuito (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Servicio: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Servicio: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Servicio: Servicio Bonjour - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Servicio: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Servicio: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Servicio: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Servicio: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Servicio: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Servicio: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Servicio: Servicio de iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Servicio: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Servicio: lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Servicio: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Servicio: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Servicio: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Servicio: Recovery Service for Windows - Propietario desconocido - C:\Program Files\SMINST\BLService.exe
O23 - Servicio: Cyberlink RichVideo Service(CRVS) (RichVideo) - Propietario desconocido - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Servicio: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Servicio: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
O23 - Servicio: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Servicio: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Servicio: TV Background Capture Service (TVBCS) (TVCapSvc) - Propietario desconocido - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Servicio: TV Task Scheduler (TVTS) (TVSched) - Propietario desconocido - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
--
Fin del archivo - 10003 bytes
======Volcado de registro======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programa de ayuda del Asistente de conexión Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2008-09-11 446556]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-08-13 177440]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
"Hiyo"=C:\Program Files\HiYo\bin\HiYo.exe [2010-01-08 230768]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-11-13 247144]
"Steam"=C:\Program Files\STEAM2\Steam.exe [2009-12-12 1217808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer for HP TouchSmart]
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2008-09-25 189736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent]
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe [2008-09-26 1148200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-16 75008]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2008-09-30 972080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-09-05 206128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
C:\Program Files\Shareaza\Shareaza.exe [2008-10-01 5723136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartMenu]
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2008-10-03 912688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-01 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-06-20 1316136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSMAgent]
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [2008-09-25 1152296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent]
C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe [2008-09-24 206120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-09-26 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\system32\kbdsock.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"HideFastUserSwitching"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoLogoff"=0
"NoDriveAutoRun"=128
"NoDriveTypeAutoRun"=128
"HonorAutoRunSetting"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======Lista de archivos/carpetas creados en el último mes======
2010-01-27 20:31:03 ----D---- C:\_OTM
2010-01-27 19:48:10 ----RASHD---- C:\autorun.inf
2010-01-27 19:37:01 ----A---- C:\UsbFix.txt
2010-01-27 19:32:19 ----D---- C:\UsbFix
2010-01-27 19:19:23 ----D---- C:\rsit
2010-01-23 19:07:39 ----D---- C:\Program Files\DivX
2010-01-23 19:07:39 ----D---- C:\Program Files\Common Files\DivX Shared
2010-01-23 18:23:21 ----D---- C:\Windows\Minidump
2010-01-22 18:49:30 ----D---- C:\ProgramData\WindowsSearch
2010-01-22 15:11:35 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 15:11:34 ----A---- C:\Windows\system32\occache.dll
2010-01-22 15:11:33 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 15:11:33 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 15:11:32 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 15:11:32 ----A---- C:\Windows\system32\ieapfltr.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iertutil.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iepeers.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\ieaksie.dll
2010-01-22 15:11:30 ----A---- C:\Windows\system32\mstime.dll
2010-01-22 15:11:30 ----A---- C:\Windows\system32\ieencode.dll
2010-01-22 15:11:29 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-13 18:40:10 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 18:40:10 ----A---- C:\Windows\system32\fontsub.dll
2010-01-08 21:56:47 ----D---- C:\Program Files\Adobe
2010-01-08 15:25:35 ----D---- C:\Users\doudou\AppData\Roaming\HiYo
2010-01-08 15:25:05 ----D---- C:\ProgramData\HiYo
2010-01-08 15:25:05 ----D---- C:\Program Files\HiYo
======Lista de archivos/carpetas modificados en el último mes======
2010-01-27 21:08:50 ----D---- C:\Windows\Temp
2010-01-27 21:08:49 ----D---- C:\Program Files\trend micro
2010-01-27 21:07:23 ----D---- C:\Windows\system32\drivers
2010-01-27 21:07:23 ----D---- C:\Windows\Logs
2010-01-27 21:03:00 ----D---- C:\Program Files\Mozilla Firefox
2010-01-27 20:57:43 ----D---- C:\Windows\System32
2010-01-27 20:57:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-27 20:57:42 ----D---- C:\Windows\inf
2010-01-27 20:52:13 ----D---- C:\Program Files\STEAM2
2010-01-27 20:47:59 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-27 19:46:15 ----SHD---- C:\$RECYCLE.BIN
2010-01-27 19:40:00 ----D---- C:\Windows\Tasks
2010-01-27 19:37:54 ----D---- C:\Windows\Prefetch
2010-01-27 19:36:53 ----D---- C:\Windows\system32\Tasks
2010-01-26 22:46:58 ----A---- C:\Windows\NeroDigital.ini
2010-01-24 21:46:42 ----D---- C:\Users\doudou\AppData\Roaming\uTorrent
2010-01-24
Ejecutado por doudou el 27-01-2010 a las 21:08:48
Microsoft® Windows Vista™ Edición Familiar Premium Service Pack 1
La unidad del sistema C: tiene 39 GB (28%) libres de 142 GB
Total de RAM: 3069 MB (60% libres)
Registro de Trend Micro HijackThis v2.0.2
Escaneo guardado a las 21:08:52, el 27/01/2010
Plataforma: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18385)
Modo de arranque: Normal
Procesos en ejecución:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\doudou\Downloads\RSIT.exe
C:\Program Files\trend micro\doudou.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Programa de ayuda del Asistente de conexión Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (sin nombre) - {BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2} - (sin archivo)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\STEAM2\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Usuario 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Usuario 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Usuario 'SERVICIO DE RED')
O4 - HKUS\S-1-5-18\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (Usuario 'SISTEMA')
O4 - HKUS\.DEFAULT\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (Usuario 'Usuario predeterminado')
O8 - Elemento adicional del menú contextual: &Búsqueda en AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\fr-FR\local\search.html
O8 - Elemento adicional del menú contextual: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Botón adicional: Agregar Directo - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Elemento de menú adicional 'Herramientas': &Agregar Directo en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Botón adicional: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Elemento de menú adicional 'Herramientas': &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Botón adicional: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Botón adicional: Investigación - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Botón adicional: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo faltante)
O9 - Elemento de menú adicional 'Herramientas': PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo faltante)
O13 - Prefijo Gopher:
O20 - AppInit_DLLs: C:\Windows\system32\kbdsock.dll
O23 - Servicio: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe
O23 - Servicio: Planificador Avira AntiVir Personal - Antivirus gratuito (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Servicio: Avira AntiVir Personal - Guardias de Antivirus gratuito (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Servicio: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Servicio: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Servicio: Servicio Bonjour - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Servicio: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Servicio: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Servicio: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Servicio: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Servicio: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Servicio: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Servicio: Servicio de iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Servicio: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Servicio: lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Servicio: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Servicio: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Servicio: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Servicio: Recovery Service for Windows - Propietario desconocido - C:\Program Files\SMINST\BLService.exe
O23 - Servicio: Cyberlink RichVideo Service(CRVS) (RichVideo) - Propietario desconocido - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Servicio: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Servicio: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
O23 - Servicio: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Servicio: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Servicio: TV Background Capture Service (TVBCS) (TVCapSvc) - Propietario desconocido - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Servicio: TV Task Scheduler (TVTS) (TVSched) - Propietario desconocido - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
--
Fin del archivo - 10003 bytes
======Volcado de registro======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programa de ayuda del Asistente de conexión Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2008-09-11 446556]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-08-13 177440]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
"Hiyo"=C:\Program Files\HiYo\bin\HiYo.exe [2010-01-08 230768]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-11-13 247144]
"Steam"=C:\Program Files\STEAM2\Steam.exe [2009-12-12 1217808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer for HP TouchSmart]
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2008-09-25 189736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent]
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe [2008-09-26 1148200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-16 75008]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2008-09-30 972080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-09-05 206128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
C:\Program Files\Shareaza\Shareaza.exe [2008-10-01 5723136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartMenu]
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2008-10-03 912688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-01 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-06-20 1316136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSMAgent]
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [2008-09-25 1152296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent]
C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe [2008-09-24 206120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-09-26 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\system32\kbdsock.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"HideFastUserSwitching"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoLogoff"=0
"NoDriveAutoRun"=128
"NoDriveTypeAutoRun"=128
"HonorAutoRunSetting"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======Lista de archivos/carpetas creados en el último mes======
2010-01-27 20:31:03 ----D---- C:\_OTM
2010-01-27 19:48:10 ----RASHD---- C:\autorun.inf
2010-01-27 19:37:01 ----A---- C:\UsbFix.txt
2010-01-27 19:32:19 ----D---- C:\UsbFix
2010-01-27 19:19:23 ----D---- C:\rsit
2010-01-23 19:07:39 ----D---- C:\Program Files\DivX
2010-01-23 19:07:39 ----D---- C:\Program Files\Common Files\DivX Shared
2010-01-23 18:23:21 ----D---- C:\Windows\Minidump
2010-01-22 18:49:30 ----D---- C:\ProgramData\WindowsSearch
2010-01-22 15:11:35 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 15:11:34 ----A---- C:\Windows\system32\occache.dll
2010-01-22 15:11:33 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 15:11:33 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 15:11:32 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 15:11:32 ----A---- C:\Windows\system32\ieapfltr.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iertutil.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iepeers.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\ieaksie.dll
2010-01-22 15:11:30 ----A---- C:\Windows\system32\mstime.dll
2010-01-22 15:11:30 ----A---- C:\Windows\system32\ieencode.dll
2010-01-22 15:11:29 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-13 18:40:10 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 18:40:10 ----A---- C:\Windows\system32\fontsub.dll
2010-01-08 21:56:47 ----D---- C:\Program Files\Adobe
2010-01-08 15:25:35 ----D---- C:\Users\doudou\AppData\Roaming\HiYo
2010-01-08 15:25:05 ----D---- C:\ProgramData\HiYo
2010-01-08 15:25:05 ----D---- C:\Program Files\HiYo
======Lista de archivos/carpetas modificados en el último mes======
2010-01-27 21:08:50 ----D---- C:\Windows\Temp
2010-01-27 21:08:49 ----D---- C:\Program Files\trend micro
2010-01-27 21:07:23 ----D---- C:\Windows\system32\drivers
2010-01-27 21:07:23 ----D---- C:\Windows\Logs
2010-01-27 21:03:00 ----D---- C:\Program Files\Mozilla Firefox
2010-01-27 20:57:43 ----D---- C:\Windows\System32
2010-01-27 20:57:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-27 20:57:42 ----D---- C:\Windows\inf
2010-01-27 20:52:13 ----D---- C:\Program Files\STEAM2
2010-01-27 20:47:59 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-27 19:46:15 ----SHD---- C:\$RECYCLE.BIN
2010-01-27 19:40:00 ----D---- C:\Windows\Tasks
2010-01-27 19:37:54 ----D---- C:\Windows\Prefetch
2010-01-27 19:36:53 ----D---- C:\Windows\system32\Tasks
2010-01-26 22:46:58 ----A---- C:\Windows\NeroDigital.ini
2010-01-24 21:46:42 ----D---- C:\Users\doudou\AppData\Roaming\uTorrent
2010-01-24
Buenas noches yoyoutte, a veces Avira detecta virus incluso si no hay ninguno. Si quieres, te doy el antivirus Avast con su serial que funciona muy bien.
Ok, está limpio.
Ve a este archivo: C:\Program Files\trend micro\doudou.exe
Es hijackthis renombrado. Haz clic derecho sobre él y elige ejecutar como administrador.
Luego selecciona hacer solo un escaneo del sistema.
Cierra tu navegador y en la lista selecciona estas líneas:
O9 - Botón extra: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo ausente)
O9 - Elemento del menú 'Herramientas' extra: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo ausente)
O2 - BHO: (sin nombre) - {BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2} - (sin archivo)
Las seleccionas y haces clic en arreglar seleccionados.
#######
• Descarga ToolsCleaner2 en tu escritorio.
• Haz clic derecho en ToolsCleaner2.exe y elige ejecutar como administrador.
• Haz clic en Buscar y deja que el escaneo actúe.
• Haz clic en Suprimir para finalizar.
• Puedes, si lo deseas, utilizar las Opciones Opcionales.
• Haz clic en Salir para obtener el informe.
• Publica el informe (TCleaner.txt) que se encuentra en la raíz de tu disco duro (C:\).
Ve a este archivo: C:\Program Files\trend micro\doudou.exe
Es hijackthis renombrado. Haz clic derecho sobre él y elige ejecutar como administrador.
Luego selecciona hacer solo un escaneo del sistema.
Cierra tu navegador y en la lista selecciona estas líneas:
O9 - Botón extra: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo ausente)
O9 - Elemento del menú 'Herramientas' extra: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (archivo ausente)
O2 - BHO: (sin nombre) - {BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2} - (sin archivo)
Las seleccionas y haces clic en arreglar seleccionados.
#######
• Descarga ToolsCleaner2 en tu escritorio.
• Haz clic derecho en ToolsCleaner2.exe y elige ejecutar como administrador.
• Haz clic en Buscar y deja que el escaneo actúe.
• Haz clic en Suprimir para finalizar.
• Puedes, si lo deseas, utilizar las Opciones Opcionales.
• Haz clic en Salir para obtener el informe.
• Publica el informe (TCleaner.txt) que se encuentra en la raíz de tu disco duro (C:\).
Reabre usbfix y elige desinstalar.
Elimina OTM.exe, Toolcleaner.exe y usbfix.exe
Elimina C:\UsbFix, C:\_OtM y C:\Rsit y hemos terminado.
--
@+
Elimina OTM.exe, Toolcleaner.exe y usbfix.exe
Elimina C:\UsbFix, C:\_OtM y C:\Rsit y hemos terminado.
--
@+
No puedo eliminar el USB, me dice que la carpeta está abierta, sin embargo, todo está cerrado, no entiendo.
Exécuté par doudou le 27-01-2010 à 19:19:23
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
Le disque système C: a 38 Go (27 %) de libre sur 142 Go
RAM totale : 3069 Mo (59 % libre)
Logfile de Trend Micro HijackThis v2.0.2
Scan enregistré à 19:20:16, le 27/01/2010
Plateforme : Windows Vista SP1 (WinNT 6.00.1905)
MSIE : Internet Explorer v7.00 (7.00.6001.18385)
Mode de démarrage : Normal
Processus en cours d'exécution :
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Users\doudou\AppData\Local\Temp\Hxr.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\doudou\Downloads\RSIT.exe
C:\Program Files\trend micro\doudou.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.hiyo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2} - c:\windows\system32\frcqtxz.dll (fichier manquant)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\STEAM2\Steam.exe" -silent
O4 - HKCU\..\Run: [sefjhf98jfoidsfoishgoiusgdgfgd] C:\Users\doudou\AppData\Local\Temp\mldnjz.exe
O4 - HKCU\..\Run: [LosAlamos] rundll32.exe C:\Windows\system32\sshnas21.dll,AttachConsoleA
O4 - HKCU\..\Run: [BMIMZMHMFM] C:\Users\doudou\AppData\Local\Temp\Hxr.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Utilisateur 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Utilisateur 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Utilisateur 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (Utilisateur 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (Utilisateur 'Utilisateur par défaut')
O8 - Élément de menu contextuel supplémentaire : &Recherche AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\fr-FR\local\search.html
O8 - Élément de menu contextuel supplémentaire : E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Bouton supplémentaire : Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Élément de menu 'Outils' supplémentaire : &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Bouton supplémentaire : Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Élément de menu 'Outils' supplémentaire : &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Bouton supplémentaire : PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Bouton supplémentaire : Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Bouton supplémentaire : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (fichier manquant)
O9 - Élément de menu 'Outils' supplémentaire : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (fichier manquant)
O13 - Préfixe Gopher :
O20 - AppInit_DLLs : C:\Windows\system32\kbdsock.dll
O23 - Service : Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe
O23 - Service : Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service : Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service : Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service : Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service : Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service : Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service : GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service : HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service : hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service : HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service : InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service : Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service : LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service : lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Service : NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service : Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service : NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service : Recovery Service for Windows - Propriétaire inconnu - C:\Program Files\SMINST\BLService.exe
O23 - Service : Cyberlink RichVideo Service(CRVS) (RichVideo) - Propriétaire inconnu - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service : SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service : Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
O23 - Service : Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service : TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service : TV Background Capture Service (TVBCS) (TVCapSvc) - Propriétaire inconnu - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service : TV Task Scheduler (TVTS) (TVSched) - Propriétaire inconnu - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
--
Fin du fichier - 10521 octets
======Dossier des tâches planifiées======
C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
======Dump du registre======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC463ACF-6A9C-4933-B751-3F8E8E0AE1E2}]
c:\windows\system32\frcqtxz.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2008-09-11 446556]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-08-13 177440]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"Hiyo"=C:\Program Files\HiYo\bin\HiYo.exe [2010-01-08 230768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-11-13 247144]
"Steam"=C:\Program Files\STEAM2\Steam.exe [2009-12-12 1217808]
"sefjhf98jfoidsfoishgoiusgdgfgd"=C:\Users\doudou\AppData\Local\Temp\mldnjz.exe []
"LosAlamos"=C:\Windows\system32\sshnas21.dll,AttachConsoleA []
"BMIMZMHMFM"=C:\Users\doudou\AppData\Local\Temp\Hxr.exe [2010-01-22 174592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer for HP TouchSmart]
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2008-09-25 189736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent]
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe [2008-09-26 1148200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-16 75008]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2008-09-30 972080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-09-05 206128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
C:\Program Files\Shareaza\Shareaza.exe [2008-10-01 5723136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartMenu]
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2008-10-03 912688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-01 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-06-20 1316136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSMAgent]
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [2008-09-25 1152296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent]
C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe [2008-09-24 206120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-09-26 210216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\system32\kbdsock.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"HideFastUserSwitching"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoLogoff"=0
"NoClose"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26f6fe00-f16c-11de-88b7-00238b53fa22}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.garmin.com/agent
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4936e25d-e726-11de-806b-00238b53fa22}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8d6e00f9-ea15-11dd-9d90-00238b53fa22}]
shell\AutoRun\command - H:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b52f6ccf-e469-11de-849b-00238b53fa22}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe
======Liste des fichiers/dossiers créés au cours des 1 derniers mois======
2010-01-27 19:19:23 ----D---- C:\rsit
2010-01-23 19:07:39 ----D---- C:\Program Files\DivX
2010-01-23 19:07:39 ----D---- C:\Program Files\Common Files\DivX Shared
2010-01-23 18:23:21 ----D---- C:\Windows\Minidump
2010-01-22 18:49:30 ----D---- C:\ProgramData\WindowsSearch
2010-01-22 16:46:48 ----SHD---- C:\Users\doudou\AppData\Roaming\SystemProc
2010-01-22 15:11:35 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 15:11:34 ----A---- C:\Windows\system32\occache.dll
2010-01-22 15:11:33 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 15:11:33 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 15:11:32 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 15:11:32 ----A---- C:\Windows\system32\ieapfltr.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iertutil.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iepeers.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 15:11:31 ----A---- C:\Windows\system32\ieaksie.dll
2010-01-22 15:11:30 ----A---- C:\Windows\system32\mstime.dll
2010-01-22 15:11:30 ----A---- C:\Windows\system32\ieencode.dll
2010-01-22 15:11:29 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-13 18:40:10 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 18:40:10 ----A---- C:\Windows\system32\fontsub.dll
2010-01-08 21:56:47 ----D---- C:\Program Files\Adobe
2010-01-08 15:25:35 ----D---- C:\Users\doudou\AppData\Roaming\HiYo
2010-01-08 15:25:05 ----D---- C:\ProgramData\HiYo
2010-01-08 15:25:05 ----D---- C:\Program Files\HiYo
======Liste des fichiers/dossiers modifiés au cours des 1 derniers mois======
======Liste de désinstallation======
-->"C:\Program Files\HP Games\5 Card Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Agatha Christie - Death on the Nile\Uninstall.exe"
-->"C:\Program Files\HP Games\Age of Castles\Uninstall.exe"
-->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
-->"C:\Program Files\HP Games\Build-a-lot 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Cake Mania\Uninstall.exe"
-->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
-->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
-->"C:\Program Files\HP Games\FATE\Uninstall.exe"
-->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
-->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
-->"C:\Program Files\HP Games\Granny in Paradise\Uninstall.exe"
-->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Mahjongg Artifacts\Uninstall.exe"
-->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
-->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
-->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Pool\Uninstall.exe"
-->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
-->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\SPORE Creature Creator Trial Edition\Uninstall.exe"
-->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\The Treasures of Montezuma\Uninstall.exe"
-->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
-->"C:\Program Files\HP Games\Virtual Villagers - The Secret City\Uninstall.exe"
-->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
-->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
-->C:\Windows\UNNeroShowTime.exe /UNINSTALL
-->C:\Windows\UNNeroVision.exe /UNINSTALL
-->C:\Windows\UNRecode.exe /UNINSTALL
-->MsiExec /X{5DB65884-C963-4454-AABA-4CA3089281FA}
Assistant d’activation pour les suites Microsoft Office 2007-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Composant ActiveCheck pour HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Shockwave Player-->MsiExec.exe /X{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}
Filtre de pilote de son USB AMD-->MsiExec.exe /X{A3AB35FA-943E-4799-99DC-46EFD59E998F}
Barre d’outils AOL 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
Programme d’installation du pilote Atheros-->C:\Program Files\InstallShield Installation Information\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}\setup.exe -runfromtemp -l0x040c
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
BetClic Poker-->C:\PROGRA~1\BETCLI~1\UNWISE.EXE C:\PROGRA~1\BETCLI~1\INSTALL.LOG
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Catalyst Control Center - Branding-->MsiExec.exe /I{558FF444-F562-4E4C-98BD-7B20EE184D2E}
Module Cisco EAP-FAST-->MsiExec.exe /I{415B2719-AD3A-4944-B404-C472DB6085B3}
Module Cisco LEAP-->MsiExec.exe /I{83770D14-21B9-44B3-8689-F7B523F94560}
Module Cisco PEAP-->MsiExec.exe /I{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}
CyberLink DVD Suite-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall
CyberLink DVD Suite-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall
DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
ESU pour Microsoft Vista-->MsiExec.exe /I{3877C901-7B90-4727-A639-B6ED2DD59D43}
Football Manager 2010-->"C:\Program Files\Sports Interactive\Football Manager 2010\Uninstall_Football Manager 2010\Désinstaller Football Manager 2010.exe"
Football Manager 2010-->"C:\Program Files\STEAM2\steam.exe" steam://uninstall/34000
Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
Garmin POI Loader-->MsiExec.exe /X{328019A7-0012-401D-96A2-4CDDD02675A8}
Pilotes USB Garmin-->MsiExec.exe /X{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
HiYo -->MsiExec.exe /X{00E1E235-AB45-4695-A156-073118949ED4} ARPVAL="UnInst" /qf /L*V "%temp%\HiYoUninstallLog.log"
HiYo-->MsiExec.exe /X{00E1E235-AB45-4695-A156-073118949ED4}
Hotfix pour Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix pour Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}\setup.exe -runfromtemp -l0x0409
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}\setup.exe" -l0x9 -removeonly
HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
HP Help and Support-->MsiExec.exe /I{0054A0F6-00C9-4498-B821-B5C9578F433E}
HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall
HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall /zMS
HP MediaSmart SmartMenu-->MsiExec.exe /I{D8BB0945-B990-47DC-BFE3-3FDE1E165B30}
HP MediaSmart TV-->"C:\Program Files\InstallShield Installation Information\{67626E09-5366-4480-8F1E-93FADF50CA15}\setup.exe" /z-uninstall
HP MediaSmart TV-->"C:\Program Files\InstallShield Installation Information\{67626E09-5366-4480-8F1E-93FADF50CA15}\setup.exe" /z-uninstall
HP MediaSmart Webcam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
HP MediaSmart Webcam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
HP Quick Launch Buttons 6.40 J1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
HP Total Care Advisor-->MsiExec.exe /X{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}
HP Update-->MsiExec.exe /X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
HP User Guides 0128-->MsiExec.exe /X{07A5026D-5F9F-43D1-9073-C2F882D417E7}
HP Wireless Assistant-->MsiExec.exe /I{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}
Composant HPAsset pour HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
HPTCSSetup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{846DDADA-0239-4B67-A6B1-33658863793B}\setup.exe" -l0x9 -removeonly
IDT Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -l0x40c -remove -removeonly
Plugin Imikimi-->"C:\Program Files\Imikimi\uninstall.exe"
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
iTunes-->MsiExec.exe /I{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Contrôleur de mémoire flash JMicron JMB38X-->"C:\Program Files\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" delpkg
Mise à jour du filtre de courriers indésirables-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
LightScribe System Software 1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee Security Scan-->"C:\Program Files\McAfee Security Scan\uninstall.exe"
Pack de langue Microsoft .NET Framework 3.5 SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Excel MUI (Français) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office OneNote MUI (Français) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Français) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (Français)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
Microsoft Office Proof (Arabe) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Néerlandais) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (Anglais) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (Français) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Allemand) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Espagnol) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (Français) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Shared MUI (Français) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (Français) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Pack d’amélioration de recherche Microsoft-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
MobileMe Control Panel-->MsiExec.exe /I{3AC54383-31D1-4907-961B-B12CBB1D0AE8}
Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
muvee Reveal-->MsiExec.exe /X{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}
Mes jeux HP-->"C:\Program Files\HP Games\Uninstall.exe"
Nero 7 Ultra Edition-->MsiExec.exe /X{CF097717-F174-4144-954A-FBC4BF301036}
Nero 9 Trial-->C:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="8M01-A098-TC9C-CZPE-8HE4-T757-014K-1C1T"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA PhysX-->MsiExec.exe /X{5DB65884-C963-4454-AABA-4CA3089281FA}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Package de pilotes Windows - ENE (enecir) HIDClass (09/04/2008 2.6.0.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\enecir.inf_1a3c82dd\enecir.inf
Pixillion Image Converter-->C:\Program Files\NCH Software\Pixillion\uninst.exe
PKR-->"C:\Program Files\PKR\uninstall-pkr.exe"
PokerStars-->"C:\Program Files\PokerStars\PokerStarsUninstall.exe" /u:PokerStars
Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
Protection de disque dur ProtectSmart-->MsiExec.exe /X{9D615069-AA8F-4E89-AE9D-77AAE90F529F}
QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
Pilote Ethernet Realtek 8169 8168 8101E 8102E-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
Safari-->MsiExec.exe /I{E56D39F8-2A9F-44B4-B068-A72E45A073E6}
Mise à jour de sécurité pour le système Microsoft Office 2007 (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Mise à jour de sécurité pour le système Microsoft Office 2007 (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
Mise à jour de sécurité pour Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
Mise à jour de sécurité pour Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Mise à jour de sécurité pour le système Microsoft Office 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Mise à jour de sécurité pour le système Microsoft Office 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Mise à jour de sécurité pour le système Microsoft Office 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Mise à jour de sécurité pour Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
SPORE Creature Creator Trial Edition-->"C:\Program Files\HP Games\SPORE Creature Creator Trial Edition\Uninstall.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Pilote de dispositif de pointage Synaptics-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Team Fortress 2-->"C:\Program Files\STEAM2\steam.exe" steam://uninstall/440
TomTom HOME 2.7.3.1894-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
Modules de fusion Visual Studio TomTom HOME-->MsiExec.exe /I{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}
Mise à jour pour le système Microsoft Office 2007 (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Mise à jour pour Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Mise à jour pour Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
Mise à jour pour Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
Utilitaire de configuration iPhone-->MsiExec.exe /I{FA54AFB1-5745-4389-B8C1-9F7509672ED1}
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)-->rundll32.exe C:\PROGRA~1\DIFX\15B7F172FC21855D\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\Windows\System32\DriverStore\FileRepository\grmnusb.inf_0efc767c\grmnusb.inf
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
Windows Live Movie Maker-->MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
Plugin Firefox Windows Media Player-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Wondershare Streaming Audio Recorder(Build 1.0.6.0)-->"C:\Program Files\Wondershare\Streaming Audio Recorder\unins000.exe"
Série XDV-S-->MsiExec.exe /I{591A436F-56DC-4304-B415-0964D9B4210E}
=====Sauvegardes HijackThis=====
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [2009-11-30]
O4 - Démarrage global: McAfee Security Scan.lnk = ? [2009-11-30]
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2009-11-30]
O2 - BHO: (aucun nom) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (aucun fichier) [2009-11-30]
======Information sur le centre de sécurité======
AS: Spybot - Search and Destroy (désactivé) (obsolète)
AS: Windows Defender
======Journal des événements système======
Nom de l’ordinateur : PC-de-doudou
Code d’événement : 3004
Message : L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
Pour plus d’informations, consultez les données suivantes :
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=TrojanDownloader%3aWin32%2fRenos.JM&threatid=143866
ID d’analyse : {52238813-CA24-40DF-8D1D-8AB3E142A4B5}
Utilisateur : PC-de-doudou\doudou
Nom : TrojanDownloader:Win32/Renos.JM
ID : 143866
ID de gravité : 5
ID de catégorie : 4
Chemin d’accès trouvé : process:pid:2044
Type d’alerte : Logiciel espion ou autre logiciel non désiré
Type de détection : Heuristiques
Numéro d'enregistrement: 63694
Nom de la source: Microsoft-Windows-Windows Defender
Temps d’écriture: 20100127180909.000000-000