Infection PC rapport RSIT
adeline
-
adeline625 Messages postés 4 Statut Membre -
adeline625 Messages postés 4 Statut Membre -
Bonjour,
J'ai restauré mon PC avec l'outil de restauration usine de Packard Bell parce que je pensais être infecté par un virus vu que mon PC était super lent, mais j'ai l'impression que ce n'est pas suffisant parce que ça recommence même après la restauration. Je me dis aussi que c'est peut-être mon disque dur externe qui est infecté. Je ne veux pas le formater car ya un peu toute ma vie dessus..
Donc j'ai décidé de procéder par ordre, j'ai à nouveau restaurer mon PC et je souhaite vérifier qu'il n'y aucune trace de virus puis m'attaquer à mon disque dur externe que j'ai mis dans un coin de ma chambre loin de l'ordi. Le seul hic c'est que je m'y connais pas trop alors je cherche un peu d'aide ici, je suis les étapes qu'il y a sur le site alors je poste mon rapport RSIT. Je rajoute que suite à la restauration, j'ai viré Norton qui fonctionne que si je paie donc j'ai actuellement aucun antivirus.
log :
Logfile of random's system information tool 1.06 (written by random/random)
Run by Charlène at 2010-02-27 12:02:30
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 179 GB (97%) free of 185 GB
Total RAM: 1023 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:35, on 27/02/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Charlène\Local Settings\Temporary Internet Files\Content.IE5\BEOSC11I\RSIT[1].exe
C:\Program Files\trend micro\Charlène.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\APPS\IE\offline\fr.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [EmailChecker] C:\APPS\EmailChecker\ech.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
--
End of file - 6067 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D}]
PBFRV2 - C:\WINDOWS\system32\pbfrv2.dll [2004-03-17 820736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-27 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-27 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-27 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-27 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - PBFRV2 - C:\WINDOWS\system32\pbfrv2.dll [2004-03-17 820736]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-27 279664]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-05 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"Raccourci vers la page des propriétés de High Definition Audio"=C:\WINDOWS\system32\HDAudPropShortcut.exe [2004-03-17 61952]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-09-10 77824]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2004-09-15 2557952]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2004-07-20 57344]
"ATIPTA"=C:\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-03-22 339968]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-02-27 149280]
"PCMService"=c:\Apps\Powercinema\PCMService.exe [2005-01-28 110740]
"ACTIVBOARD"=c:\apps\ABoard\ABoard.exe [2003-05-02 24576]
"EmailChecker"=C:\APPS\EmailChecker\ech.exe [2003-07-02 40960]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-27 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-03-22 46080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%ProgramFiles%\AOL 9.0\aol.exe"="%ProgramFiles%\AOL 9.0\aol.exe:*:Enabled:AOL"
"%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\logo_ubi.exe"="%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
"%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe"="%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:PANDORA"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\APPS\Inventime\my.exe"="C:\APPS\Inventime\my.exe:*:Enabled:INVENTIME"
"C:\Documents and Settings\Charlène\Local Settings\Temp\7zSAE.tmp\SymNRT.exe"="C:\Documents and Settings\Charlène\Local Settings\Temp\7zSAE.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-02-27 20:11:08 ----SHD---- C:\WINDOWS\Installer
2010-02-27 20:11:08 ----SD---- C:\WINDOWS\Tasks
2010-02-27 20:11:08 ----SD---- C:\WINDOWS\system32\Microsoft
2010-02-27 20:11:08 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-02-27 20:11:08 ----RSHD---- C:\WINDOWS\system32\dllcache
2010-02-27 20:11:08 ----RSD---- C:\WINDOWS\Fonts
2010-02-27 20:11:08 ----RD---- C:\WINDOWS\Web
2010-02-27 20:11:08 ----RD---- C:\WINDOWS\Offline Web Pages
2010-02-27 20:11:08 ----HD---- C:\WINDOWS\inf
2010-02-27 20:11:08 ----HD---- C:\WINDOWS\I386
2010-02-27 20:11:08 ----D---- C:\WINDOWS\WinSxS
2010-02-27 20:11:08 ----D---- C:\WINDOWS\twain_32
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Temp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\xircom
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\wins
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\wbem
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\usmt
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\URTTemp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\spool
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ShellExt
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Setup
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Restore
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ras
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\QuickTime
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\oobe
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\npp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\mui
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\MsDtc
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Macromed
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Lang
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\inetsrv
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\IME
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\icsxml
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ias
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\export
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\drivers
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\DirectX
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\dhcp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\config
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Com
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\3com_dmi
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\3076
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\2052
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1054
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1042
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1041
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1037
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1036
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1033
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1031
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1028
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1025
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system
2010-02-27 20:11:08 ----D---- C:\WINDOWS\srchasst
2010-02-27 20:11:08 ----D---- C:\WINDOWS\SoftwareDistribution
2010-02-27 20:11:08 ----D---- C:\WINDOWS\security
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Resources
2010-02-27 20:11:08 ----D---- C:\WINDOWS\REPAIR
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Registration
2010-02-27 20:11:08 ----D---- C:\WINDOWS\RegisteredPackages
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Provisioning
2010-02-27 20:11:08 ----D---- C:\WINDOWS\PREFETCH
2010-02-27 20:11:08 ----D---- C:\WINDOWS\PeerNet
2010-02-27 20:11:08 ----D---- C:\WINDOWS\pchealth
2010-02-27 20:11:08 ----D---- C:\WINDOWS\occache
2010-02-27 20:11:08 ----D---- C:\WINDOWS\mui
2010-02-27 20:11:08 ----D---- C:\WINDOWS\msapps
2010-02-27 20:11:08 ----D---- C:\WINDOWS\msagent
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Media
2010-02-27 20:11:08 ----D---- C:\WINDOWS\java
2010-02-27 20:11:08 ----D---- C:\WINDOWS\ime
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Help
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Driver Cache
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Debug
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Cursors
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Connection Wizard
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Config
2010-02-27 20:11:08 ----AD---- C:\WINDOWS\system32
2010-02-27 20:11:07 ----SHD---- C:\RECYCLER
2010-02-27 20:11:07 ----SHD---- C:\DRIVERS
2010-02-27 20:11:07 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-02-27 20:11:07 ----RSHD---- C:\cmdcons
2010-02-27 20:11:07 ----RSD---- C:\WINDOWS\assembly
2010-02-27 20:11:07 ----RD---- C:\Program Files
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB893086$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB893066$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB891781$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890923$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890859$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890175$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890047$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB888302$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB888113$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB887472$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB886185$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB885836$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB885835$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB885250$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB873339$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB873333$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB835221WXP$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$MSI31Uninstall_KB893803$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-27 20:11:07 ----HD---- C:\Program Files\WindowsUpdate
2010-02-27 20:11:07 ----HD---- C:\Program Files\Uninstall Information
2010-02-27 20:11:07 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-27 20:11:07 ----HD---- C:\PNP
2010-02-27 20:11:07 ----HD---- C:\DIVTOOLS
2010-02-27 20:11:07 ----D---- C:\WINDOWS\AppPatch
2010-02-27 20:11:07 ----D---- C:\WINDOWS\addins
2010-02-27 20:11:07 ----D---- C:\WINDOWS
2010-02-27 20:11:07 ----D---- C:\Program Files\xerox
2010-02-27 20:11:07 ----D---- C:\Program Files\Windows NT
2010-02-27 20:11:07 ----D---- C:\Program Files\Windows Media Player
2010-02-27 20:11:07 ----D---- C:\Program Files\Viewpoint
2010-02-27 20:11:07 ----D---- C:\Program Files\Sonic
2010-02-27 20:11:07 ----D---- C:\Program Files\Services en ligne
2010-02-27 20:11:07 ----D---- C:\Program Files\Realtek
2010-02-27 20:11:07 ----D---- C:\Program Files\Real
2010-02-27 20:11:07 ----D---- C:\Program Files\QuickTime
2010-02-27 20:11:07 ----D---- C:\Program Files\Outlook Express
2010-02-27 20:11:07 ----D---- C:\Program Files\Online Services
2010-02-27 20:11:07 ----D---- C:\Program Files\NetMeeting
2010-02-27 20:11:07 ----D---- C:\Program Files\MSN Gaming Zone
2010-02-27 20:11:07 ----D---- C:\Program Files\MSN
2010-02-27 20:11:07 ----D---- C:\Program Files\Movie Maker
2010-02-27 20:11:07 ----D---- C:\Program Files\microsoft frontpage
2010-02-27 20:11:07 ----D---- C:\Program Files\Messenger
2010-02-27 20:11:07 ----D---- C:\Program Files\Learn2.com
2010-02-27 20:11:07 ----D---- C:\Program Files\Java
2010-02-27 20:11:07 ----D---- C:\Program Files\Internet Explorer
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\xing shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\System
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\SureThing Shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\SpeechEngines
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Sonic Shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Services
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Real
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\ODBC
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Nullsoft
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\MSSoap
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Java
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\InstallShield
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\aolshare
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\AOL
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Adobe
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs
2010-02-27 20:11:07 ----D---- C:\Program Files\Dynamic Toolbar
2010-02-27 20:11:07 ----D---- C:\Program Files\CyberLink
2010-02-27 20:11:07 ----D---- C:\Program Files\ComPlus Applications
2010-02-27 20:11:07 ----D---- C:\Program Files\AOL Compagnon
2010-02-27 20:11:07 ----D---- C:\Program Files\AOL 9.0
2010-02-27 20:11:07 ----D---- C:\Program Files\Adobe
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\SBSI
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\QuickTime
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\CyberLink
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\AOL
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-02-27 20:11:07 ----D---- C:\Documents and Settings
2010-02-27 20:11:07 ----D---- C:\ATI Technologies
2010-02-27 20:11:07 ----D---- C:\APPS
2010-02-27 20:11:06 ----SHD---- C:\System Volume Information
2010-02-27 12:02:30 ----D---- C:\rsit
2010-02-27 12:02:30 ----D---- C:\Program Files\trend micro
2010-02-27 11:46:50 ----D---- C:\Documents and Settings\Charlène\Application Data\Google
2010-02-27 11:36:17 ----D---- C:\Program Files\Google
2010-02-27 11:36:17 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-02-27 11:36:05 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-27 11:36:05 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-02-27 11:23:10 ----ASH---- C:\Documents and Settings\Charlène\Application Data\desktop.ini
2010-02-27 11:23:08 ----D---- C:\Documents and Settings\Charlène\Application Data\Macromedia
2010-02-27 11:23:08 ----D---- C:\Documents and Settings\Charlène\Application Data\Identities
2010-02-27 11:23:07 ----SD---- C:\Documents and Settings\Charlène\Application Data\Microsoft
2010-02-27 11:23:07 ----D---- C:\Documents and Settings\Charlène\Application Data\You've Got Pictures Screensaver
2010-02-27 11:23:07 ----D---- C:\Documents and Settings\Charlène\Application Data\Sun
2010-02-27 11:23:07 ----D---- C:\Documents and Settings\Charlène\Application Data\Real
2010-02-27 11:20:35 ----D---- C:\WINDOWS\system32\SoftwareDistribution
======List of files/folders modified in the last 1 months======
2010-02-27 11:52:37 ----ASH---- C:\BOOT.INI
2010-02-27 11:45:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-27 11:35:55 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-27 11:35:55 ----A---- C:\WINDOWS\system32\java.exe
2010-02-27 11:25:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-27 11:23:57 ----A---- C:\WINDOWS\OEWABLog.txt
2010-02-27 11:22:15 ----A---- C:\WINDOWS\setuplog.txt
2010-02-27 11:21:40 ----A---- C:\WINDOWS\HDReg.ini
2010-02-27 11:18:37 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-05 40320]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-03-22 1034752]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-03-17 135168]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2004-09-16 2257920]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824]
R3 RTL8023;Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver; C:\WINDOWS\system32\DRIVERS\Rtlnic51.sys [2003-12-31 69504]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
S3 3xHybrid;3xHybrid service; C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-04-14 709760]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-03-17 113664]
S3 MPE;Filtre BDA MPE; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-05 17024]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe [2004-04-08 1135728]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-03-22 360448]
R2 CLCapSvc;CyberLink Background Capture Service (CBCS); c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe [2004-12-14 176220]
R2 CLSched;CyberLink Task Scheduler (CTS); c:\APPS\Powercinema\Kernel\TV\CLSched.exe [2004-12-14 110682]
R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe [2005-01-28 24576]
R2 GenericHidService;Generic Service for HID Keyboard Input Collections; c:\APPS\HIDSERVICE\HIDSERVICE.exe [2005-01-07 49152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-27 153376]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-27 135664]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-02-27 182768]
S3 MysqlInventime;MysqlInventime; C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime []
-----------------EOF-----------------
info :
info.txt logfile of random's system information tool 1.06 2010-02-27 12:02:36
======Uninstall list======
-->"c:\apps\skype\phone\unins000.exe"
-->"C:\Program Files\Fichiers communs\aolshare\Coach\AolCInUn.exe" -lang="fr-fr"
-->C:\PROGRA~1\FICHIE~1\AOL\ACS\AcsUninstall.exe /c
-->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
-->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
-->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0A32C786-85DE-48F8-9E54-848B3E34A90C}\setup.exe" -l0x40c -removeonly
-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
Correctif Windows XP - KB873333-->C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Correctif Windows XP - KB885250-->C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Correctif Windows XP - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Correctif Windows XP - KB890047-->C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe
Correctif Windows XP - KB890175-->C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Correctif Windows XP - KB890923-->"C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe"
Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Correctif Windows XP - KB893066-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
Correctif Windows XP - KB893086-->"C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Java 2 Runtime Environment, SE v1.4.2_05-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB886903)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M886903\M886903Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Packard Bell Toolbar 1.0-->"C:\Program Files\Dynamic Toolbar\unins000.exe"
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" REMOVE
Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
======System event log======
Computer Name: Bibi
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.
Record Number: 5
Source Name: Service Control Manager
Time Written: 20100227112345.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 7036
Message: Le service Services Terminal Server est entré dans l'état : en cours d'exécution.
Record Number: 4
Source Name: Service Control Manager
Time Written: 20100227112345.000000+060
Event Type: Informations
User:
Computer Name: Bibi
Event Code: 6005
Message: Le service d'Enregistrement d'événement a démarré.
Record Number: 3
Source Name: EventLog
Time Written: 20100227112303.000000+060
Event Type: Informations
User:
Computer Name: Bibi
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.
Record Number: 2
Source Name: EventLog
Time Written: 20100227112303.000000+060
Event Type: Informations
User:
Computer Name: Bibi
Event Code: 115
Message: Le suivi de la Restauration système a été activé sur tous les lecteurs.
Record Number: 1
Source Name: SRService
Time Written: 20100227112215.000000+060
Event Type: Informations
User:
=====Application event log=====
Computer Name: Bibi
Event Code: 1
Message:
Record Number: 5
Source Name: ccEvtMgr
Time Written: 20100227112317.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 26
Message:
Record Number: 4
Source Name: ccEvtMgr
Time Written: 20100227112314.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 1
Message:
Record Number: 3
Source Name: ccSetMgr
Time Written: 20100227112314.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 26
Message:
Record Number: 2
Source Name: ccSetMgr
Time Written: 20100227112312.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 26
Message:
Record Number: 1
Source Name: ccProxy
Time Written: 20100227112312.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\ATI Technologies\ATI Control Panel;C:\PROGRA~1\FICHIE~1\SONICS~1\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0403
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
J'ai restauré mon PC avec l'outil de restauration usine de Packard Bell parce que je pensais être infecté par un virus vu que mon PC était super lent, mais j'ai l'impression que ce n'est pas suffisant parce que ça recommence même après la restauration. Je me dis aussi que c'est peut-être mon disque dur externe qui est infecté. Je ne veux pas le formater car ya un peu toute ma vie dessus..
Donc j'ai décidé de procéder par ordre, j'ai à nouveau restaurer mon PC et je souhaite vérifier qu'il n'y aucune trace de virus puis m'attaquer à mon disque dur externe que j'ai mis dans un coin de ma chambre loin de l'ordi. Le seul hic c'est que je m'y connais pas trop alors je cherche un peu d'aide ici, je suis les étapes qu'il y a sur le site alors je poste mon rapport RSIT. Je rajoute que suite à la restauration, j'ai viré Norton qui fonctionne que si je paie donc j'ai actuellement aucun antivirus.
log :
Logfile of random's system information tool 1.06 (written by random/random)
Run by Charlène at 2010-02-27 12:02:30
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 179 GB (97%) free of 185 GB
Total RAM: 1023 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:35, on 27/02/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Charlène\Local Settings\Temporary Internet Files\Content.IE5\BEOSC11I\RSIT[1].exe
C:\Program Files\trend micro\Charlène.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://C:\APPS\IE\offline\fr.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [EmailChecker] C:\APPS\EmailChecker\ech.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
--
End of file - 6067 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D}]
PBFRV2 - C:\WINDOWS\system32\pbfrv2.dll [2004-03-17 820736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-27 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-27 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-27 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-27 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - PBFRV2 - C:\WINDOWS\system32\pbfrv2.dll [2004-03-17 820736]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-27 279664]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-05 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"Raccourci vers la page des propriétés de High Definition Audio"=C:\WINDOWS\system32\HDAudPropShortcut.exe [2004-03-17 61952]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-09-10 77824]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2004-09-15 2557952]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2004-07-20 57344]
"ATIPTA"=C:\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-03-22 339968]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-02-27 149280]
"PCMService"=c:\Apps\Powercinema\PCMService.exe [2005-01-28 110740]
"ACTIVBOARD"=c:\apps\ABoard\ABoard.exe [2003-05-02 24576]
"EmailChecker"=C:\APPS\EmailChecker\ech.exe [2003-07-02 40960]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-27 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-03-22 46080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%ProgramFiles%\AOL 9.0\aol.exe"="%ProgramFiles%\AOL 9.0\aol.exe:*:Enabled:AOL"
"%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\logo_ubi.exe"="%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
"%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe"="%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:PANDORA"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\APPS\Inventime\my.exe"="C:\APPS\Inventime\my.exe:*:Enabled:INVENTIME"
"C:\Documents and Settings\Charlène\Local Settings\Temp\7zSAE.tmp\SymNRT.exe"="C:\Documents and Settings\Charlène\Local Settings\Temp\7zSAE.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-02-27 20:11:08 ----SHD---- C:\WINDOWS\Installer
2010-02-27 20:11:08 ----SD---- C:\WINDOWS\Tasks
2010-02-27 20:11:08 ----SD---- C:\WINDOWS\system32\Microsoft
2010-02-27 20:11:08 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-02-27 20:11:08 ----RSHD---- C:\WINDOWS\system32\dllcache
2010-02-27 20:11:08 ----RSD---- C:\WINDOWS\Fonts
2010-02-27 20:11:08 ----RD---- C:\WINDOWS\Web
2010-02-27 20:11:08 ----RD---- C:\WINDOWS\Offline Web Pages
2010-02-27 20:11:08 ----HD---- C:\WINDOWS\inf
2010-02-27 20:11:08 ----HD---- C:\WINDOWS\I386
2010-02-27 20:11:08 ----D---- C:\WINDOWS\WinSxS
2010-02-27 20:11:08 ----D---- C:\WINDOWS\twain_32
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Temp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\xircom
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\wins
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\wbem
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\usmt
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\URTTemp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\spool
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ShellExt
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Setup
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Restore
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ras
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\QuickTime
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\oobe
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\npp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\mui
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\MsDtc
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Macromed
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Lang
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\inetsrv
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\IME
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\icsxml
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\ias
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\export
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\drivers
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\DirectX
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\dhcp
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\config
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\Com
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\3com_dmi
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\3076
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\2052
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1054
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1042
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1041
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1037
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1036
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1033
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1031
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1028
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system32\1025
2010-02-27 20:11:08 ----D---- C:\WINDOWS\system
2010-02-27 20:11:08 ----D---- C:\WINDOWS\srchasst
2010-02-27 20:11:08 ----D---- C:\WINDOWS\SoftwareDistribution
2010-02-27 20:11:08 ----D---- C:\WINDOWS\security
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Resources
2010-02-27 20:11:08 ----D---- C:\WINDOWS\REPAIR
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Registration
2010-02-27 20:11:08 ----D---- C:\WINDOWS\RegisteredPackages
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Provisioning
2010-02-27 20:11:08 ----D---- C:\WINDOWS\PREFETCH
2010-02-27 20:11:08 ----D---- C:\WINDOWS\PeerNet
2010-02-27 20:11:08 ----D---- C:\WINDOWS\pchealth
2010-02-27 20:11:08 ----D---- C:\WINDOWS\occache
2010-02-27 20:11:08 ----D---- C:\WINDOWS\mui
2010-02-27 20:11:08 ----D---- C:\WINDOWS\msapps
2010-02-27 20:11:08 ----D---- C:\WINDOWS\msagent
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Media
2010-02-27 20:11:08 ----D---- C:\WINDOWS\java
2010-02-27 20:11:08 ----D---- C:\WINDOWS\ime
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Help
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Driver Cache
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Debug
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Cursors
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Connection Wizard
2010-02-27 20:11:08 ----D---- C:\WINDOWS\Config
2010-02-27 20:11:08 ----AD---- C:\WINDOWS\system32
2010-02-27 20:11:07 ----SHD---- C:\RECYCLER
2010-02-27 20:11:07 ----SHD---- C:\DRIVERS
2010-02-27 20:11:07 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-02-27 20:11:07 ----RSHD---- C:\cmdcons
2010-02-27 20:11:07 ----RSD---- C:\WINDOWS\assembly
2010-02-27 20:11:07 ----RD---- C:\Program Files
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB893086$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB893066$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB891781$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890923$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890859$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890175$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB890047$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB888302$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB888113$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB887472$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB886185$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB885836$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB885835$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB885250$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB873339$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB873333$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$NtUninstallKB835221WXP$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$MSI31Uninstall_KB893803$
2010-02-27 20:11:07 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-27 20:11:07 ----HD---- C:\Program Files\WindowsUpdate
2010-02-27 20:11:07 ----HD---- C:\Program Files\Uninstall Information
2010-02-27 20:11:07 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-27 20:11:07 ----HD---- C:\PNP
2010-02-27 20:11:07 ----HD---- C:\DIVTOOLS
2010-02-27 20:11:07 ----D---- C:\WINDOWS\AppPatch
2010-02-27 20:11:07 ----D---- C:\WINDOWS\addins
2010-02-27 20:11:07 ----D---- C:\WINDOWS
2010-02-27 20:11:07 ----D---- C:\Program Files\xerox
2010-02-27 20:11:07 ----D---- C:\Program Files\Windows NT
2010-02-27 20:11:07 ----D---- C:\Program Files\Windows Media Player
2010-02-27 20:11:07 ----D---- C:\Program Files\Viewpoint
2010-02-27 20:11:07 ----D---- C:\Program Files\Sonic
2010-02-27 20:11:07 ----D---- C:\Program Files\Services en ligne
2010-02-27 20:11:07 ----D---- C:\Program Files\Realtek
2010-02-27 20:11:07 ----D---- C:\Program Files\Real
2010-02-27 20:11:07 ----D---- C:\Program Files\QuickTime
2010-02-27 20:11:07 ----D---- C:\Program Files\Outlook Express
2010-02-27 20:11:07 ----D---- C:\Program Files\Online Services
2010-02-27 20:11:07 ----D---- C:\Program Files\NetMeeting
2010-02-27 20:11:07 ----D---- C:\Program Files\MSN Gaming Zone
2010-02-27 20:11:07 ----D---- C:\Program Files\MSN
2010-02-27 20:11:07 ----D---- C:\Program Files\Movie Maker
2010-02-27 20:11:07 ----D---- C:\Program Files\microsoft frontpage
2010-02-27 20:11:07 ----D---- C:\Program Files\Messenger
2010-02-27 20:11:07 ----D---- C:\Program Files\Learn2.com
2010-02-27 20:11:07 ----D---- C:\Program Files\Java
2010-02-27 20:11:07 ----D---- C:\Program Files\Internet Explorer
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\xing shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\System
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\SureThing Shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\SpeechEngines
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Sonic Shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Services
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Real
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\ODBC
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Nullsoft
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\MSSoap
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Java
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\InstallShield
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\aolshare
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\AOL
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs\Adobe
2010-02-27 20:11:07 ----D---- C:\Program Files\Fichiers communs
2010-02-27 20:11:07 ----D---- C:\Program Files\Dynamic Toolbar
2010-02-27 20:11:07 ----D---- C:\Program Files\CyberLink
2010-02-27 20:11:07 ----D---- C:\Program Files\ComPlus Applications
2010-02-27 20:11:07 ----D---- C:\Program Files\AOL Compagnon
2010-02-27 20:11:07 ----D---- C:\Program Files\AOL 9.0
2010-02-27 20:11:07 ----D---- C:\Program Files\Adobe
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\SBSI
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\QuickTime
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\CyberLink
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\AOL
2010-02-27 20:11:07 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-02-27 20:11:07 ----D---- C:\Documents and Settings
2010-02-27 20:11:07 ----D---- C:\ATI Technologies
2010-02-27 20:11:07 ----D---- C:\APPS
2010-02-27 20:11:06 ----SHD---- C:\System Volume Information
2010-02-27 12:02:30 ----D---- C:\rsit
2010-02-27 12:02:30 ----D---- C:\Program Files\trend micro
2010-02-27 11:46:50 ----D---- C:\Documents and Settings\Charlène\Application Data\Google
2010-02-27 11:36:17 ----D---- C:\Program Files\Google
2010-02-27 11:36:17 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-02-27 11:36:05 ----A---- C:\WINDOWS\system32\javaws.exe
2010-02-27 11:36:05 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-02-27 11:23:10 ----ASH---- C:\Documents and Settings\Charlène\Application Data\desktop.ini
2010-02-27 11:23:08 ----D---- C:\Documents and Settings\Charlène\Application Data\Macromedia
2010-02-27 11:23:08 ----D---- C:\Documents and Settings\Charlène\Application Data\Identities
2010-02-27 11:23:07 ----SD---- C:\Documents and Settings\Charlène\Application Data\Microsoft
2010-02-27 11:23:07 ----D---- C:\Documents and Settings\Charlène\Application Data\You've Got Pictures Screensaver
2010-02-27 11:23:07 ----D---- C:\Documents and Settings\Charlène\Application Data\Sun
2010-02-27 11:23:07 ----D---- C:\Documents and Settings\Charlène\Application Data\Real
2010-02-27 11:20:35 ----D---- C:\WINDOWS\system32\SoftwareDistribution
======List of files/folders modified in the last 1 months======
2010-02-27 11:52:37 ----ASH---- C:\BOOT.INI
2010-02-27 11:45:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-27 11:35:55 ----A---- C:\WINDOWS\system32\javaw.exe
2010-02-27 11:35:55 ----A---- C:\WINDOWS\system32\java.exe
2010-02-27 11:25:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-27 11:23:57 ----A---- C:\WINDOWS\OEWABLog.txt
2010-02-27 11:22:15 ----A---- C:\WINDOWS\setuplog.txt
2010-02-27 11:21:40 ----A---- C:\WINDOWS\HDReg.ini
2010-02-27 11:18:37 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-05 40320]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-03-22 1034752]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-03-17 135168]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2004-09-16 2257920]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824]
R3 RTL8023;Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver; C:\WINDOWS\system32\DRIVERS\Rtlnic51.sys [2003-12-31 69504]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
S3 3xHybrid;3xHybrid service; C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-04-14 709760]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-03-17 113664]
S3 MPE;Filtre BDA MPE; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-05 17024]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe [2004-04-08 1135728]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-03-22 360448]
R2 CLCapSvc;CyberLink Background Capture Service (CBCS); c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe [2004-12-14 176220]
R2 CLSched;CyberLink Task Scheduler (CTS); c:\APPS\Powercinema\Kernel\TV\CLSched.exe [2004-12-14 110682]
R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe [2005-01-28 24576]
R2 GenericHidService;Generic Service for HID Keyboard Input Collections; c:\APPS\HIDSERVICE\HIDSERVICE.exe [2005-01-07 49152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-27 153376]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-27 135664]
S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-02-27 182768]
S3 MysqlInventime;MysqlInventime; C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime []
-----------------EOF-----------------
info :
info.txt logfile of random's system information tool 1.06 2010-02-27 12:02:36
======Uninstall list======
-->"c:\apps\skype\phone\unins000.exe"
-->"C:\Program Files\Fichiers communs\aolshare\Coach\AolCInUn.exe" -lang="fr-fr"
-->C:\PROGRA~1\FICHIE~1\AOL\ACS\AcsUninstall.exe /c
-->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
-->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
-->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0A32C786-85DE-48F8-9E54-848B3E34A90C}\setup.exe" -l0x40c -removeonly
-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
Correctif Windows XP - KB873333-->C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Correctif Windows XP - KB885250-->C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Correctif Windows XP - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Correctif Windows XP - KB890047-->C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe
Correctif Windows XP - KB890175-->C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Correctif Windows XP - KB890923-->"C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe"
Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Correctif Windows XP - KB893066-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
Correctif Windows XP - KB893086-->"C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Java 2 Runtime Environment, SE v1.4.2_05-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB886903)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M886903\M886903Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Packard Bell Toolbar 1.0-->"C:\Program Files\Dynamic Toolbar\unins000.exe"
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" REMOVE
Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
======System event log======
Computer Name: Bibi
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.
Record Number: 5
Source Name: Service Control Manager
Time Written: 20100227112345.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 7036
Message: Le service Services Terminal Server est entré dans l'état : en cours d'exécution.
Record Number: 4
Source Name: Service Control Manager
Time Written: 20100227112345.000000+060
Event Type: Informations
User:
Computer Name: Bibi
Event Code: 6005
Message: Le service d'Enregistrement d'événement a démarré.
Record Number: 3
Source Name: EventLog
Time Written: 20100227112303.000000+060
Event Type: Informations
User:
Computer Name: Bibi
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.
Record Number: 2
Source Name: EventLog
Time Written: 20100227112303.000000+060
Event Type: Informations
User:
Computer Name: Bibi
Event Code: 115
Message: Le suivi de la Restauration système a été activé sur tous les lecteurs.
Record Number: 1
Source Name: SRService
Time Written: 20100227112215.000000+060
Event Type: Informations
User:
=====Application event log=====
Computer Name: Bibi
Event Code: 1
Message:
Record Number: 5
Source Name: ccEvtMgr
Time Written: 20100227112317.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 26
Message:
Record Number: 4
Source Name: ccEvtMgr
Time Written: 20100227112314.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 1
Message:
Record Number: 3
Source Name: ccSetMgr
Time Written: 20100227112314.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 26
Message:
Record Number: 2
Source Name: ccSetMgr
Time Written: 20100227112312.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: Bibi
Event Code: 26
Message:
Record Number: 1
Source Name: ccProxy
Time Written: 20100227112312.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\ATI Technologies\ATI Control Panel;C:\PROGRA~1\FICHIE~1\SONICS~1\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0403
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
Configuration: Windows XP / Internet Explorer 6.0
A voir également:
- Infection PC rapport RSIT
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Reinitialiser pc - Guide
- Forcer demarrage pc - Guide
- Temperature pc - Guide
- Pc lent - Guide
4 réponses
Voila le rapport mbam :
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3799
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
27/02/2010 12:28:29
mbam-log-2010-02-27 (12-28-29).txt
Type de recherche: Examen rapide
Eléments examinés: 107199
Temps écoulé: 3 minute(s), 59 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 4
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 44
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\pbfrv2.dll (Adware.2020search) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\pbfrv2.pbfrv2 (Adware.2020search) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\dynamic toolbar (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2 (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache (Adware.2020search) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\WINDOWS\system32\pbfrv2.dll (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\batch.bat (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\unins000.dat (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\unins000.exe (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\go.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\home.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\logo_pb.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\parent_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\parent_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\pbfrv2tb0200.cfg (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\popup_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\popup_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\search.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\services.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin1.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin2.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin3.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin4.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin5.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\store.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\style.css (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\support.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\ticker.xml (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\go.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\home.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\logo_pb.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\parent_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\parent_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\popup_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\popup_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\search.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\services.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin1.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin2.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin3.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin4.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin5.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\store.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\style.css (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\support.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\ticker.xml (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\_Ticker_ticker.txt (Adware.2020search) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3799
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
27/02/2010 12:28:29
mbam-log-2010-02-27 (12-28-29).txt
Type de recherche: Examen rapide
Eléments examinés: 107199
Temps écoulé: 3 minute(s), 59 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 4
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 44
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\pbfrv2.dll (Adware.2020search) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\pbfrv2.pbfrv2 (Adware.2020search) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d} (Adware.2020search) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\dynamic toolbar (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2 (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache (Adware.2020search) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\WINDOWS\system32\pbfrv2.dll (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\batch.bat (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\unins000.dat (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\unins000.exe (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\go.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\home.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\logo_pb.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\parent_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\parent_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\pbfrv2tb0200.cfg (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\popup_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\popup_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\search.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\services.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin1.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin2.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin3.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin4.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\skin5.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\store.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\style.css (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\support.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\Cache\ticker.xml (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\go.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\home.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\logo_pb.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\parent_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\parent_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\popup_off.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\popup_on.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\search.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\services.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin1.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin2.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin3.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin4.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\skin5.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\store.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\style.css (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\support.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\ticker.xml (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\PBFRV2\Cache\_Ticker_ticker.txt (Adware.2020search) -> Quarantined and deleted successfully.
Rapport de usbfix :
############################## | UsbFix V6.097 |
User : Charlène (Administrateurs) # Bibi
Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:48:45 | 27/02/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) 4 CPU 3.00GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
C:\ -> Disque fixe local # 180,29 Go (174,32 Go free) [HDD] # NTFS
D:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque fixe local # 298,02 Go (100,3 Go free) [CHAPICHATE] # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Elements infectieux |
################## | Registre |
################## | Mountpoints2 |
################## | Vaccin |
# C:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
# I:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
################## | ! Fin du rapport # UsbFix V6.097 ! |
############################## | UsbFix V6.097 |
User : Charlène (Administrateurs) # Bibi
Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:48:45 | 27/02/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) 4 CPU 3.00GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
C:\ -> Disque fixe local # 180,29 Go (174,32 Go free) [HDD] # NTFS
D:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque fixe local # 298,02 Go (100,3 Go free) [CHAPICHATE] # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Elements infectieux |
################## | Registre |
################## | Mountpoints2 |
################## | Vaccin |
# C:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
# I:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
################## | ! Fin du rapport # UsbFix V6.097 ! |
usbfix option 2 :
############################## | UsbFix V6.097 |
User : Charlène (Administrateurs) # Bibi
Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:54:05 | 27/02/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) 4 CPU 3.00GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
C:\ -> Disque fixe local # 180,29 Go (174,3 Go free) [HDD] # NTFS
D:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque fixe local # 298,02 Go (100,3 Go free) [CHAPICHATE] # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Elements infectieux |
Supprimé ! C:\Recycler\S-1-5-21-2330606641-2566378608-4233264486-1006
Supprimé ! C:\Recycler\S-1-5-21-2642663408-3173496037-3570927397-1003
################## | Registre |
################## | Mountpoints2 |
################## | Listing des fichiers présent |
[04/07/2005 16:56|-rahs----|215] C:\BOOT.BAK
[27/02/2010 11:52|--ahs----|297] C:\BOOT.INI
[05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
[05/08/2004 13:00|-rahs----|263488] C:\cmldr
[04/07/2005 16:43|--a------|5894] C:\DWNLOG.TXT
[?|?|?] C:\hiberfil.sys
[04/07/2005 16:59|-rahs----|0] C:\IO.SYS
[04/07/2005 17:07|--ah-----|815] C:\IPH.PH
[04/07/2005 16:59|-rahs----|0] C:\MSDOS.SYS
[04/07/2005 17:05|--a------|157] C:\MYInventimeSetup.log
[05/08/2004 13:00|--a------|47564] C:\NTDETECT.COM
[05/08/2004 13:00|--a------|251712] C:\NTLDR
[?|?|?] C:\pagefile.sys
[04/07/2005 14:33|--a------|1084] C:\SAUDIT.TXT
[27/02/2010 13:56|--a------|2918] C:\UsbFix.txt
[01/01/1995 01:00|-r-------|44] D:\Track01.cda
[01/01/1995 01:04|-r-------|44] D:\Track02.cda
[01/01/1995 01:08|-r-------|44] D:\Track03.cda
[01/01/1995 01:12|-r-------|44] D:\Track04.cda
[01/01/1995 01:17|-r-------|44] D:\Track05.cda
[01/01/1995 01:21|-r-------|44] D:\Track06.cda
[01/01/1995 01:24|-r-------|44] D:\Track07.cda
[01/01/1995 01:29|-r-------|44] D:\Track08.cda
[01/01/1995 01:33|-r-------|44] D:\Track09.cda
[01/01/1995 01:37|-r-------|44] D:\Track10.cda
[01/01/1995 01:41|-r-------|44] D:\Track11.cda
[01/01/1995 01:46|-r-------|44] D:\Track12.cda
[01/01/1995 01:50|-r-------|44] D:\Track13.cda
[01/01/1995 01:55|-r-------|44] D:\Track14.cda
[01/01/1995 01:59|-r-------|44] D:\Track15.cda
[24/12/2008 18:36|--ah-----|15364] I:\.DS_Store
[03/10/2009 12:21|--a------|40555] I:\CV_Cu_oct09.pdf
[26/12/2008 09:38|--ahs----|16384] I:\Thumbs.db
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
# I:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
################## | Upload |
Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_Bibi.zip : https://www.ionos.fr/?affiliate_id=77097
Merci pour votre contribution .
################## | ! Fin du rapport # UsbFix V6.097 ! |
############################## | UsbFix V6.097 |
User : Charlène (Administrateurs) # Bibi
Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:54:05 | 27/02/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) 4 CPU 3.00GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
C:\ -> Disque fixe local # 180,29 Go (174,3 Go free) [HDD] # NTFS
D:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque fixe local # 298,02 Go (100,3 Go free) [CHAPICHATE] # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Elements infectieux |
Supprimé ! C:\Recycler\S-1-5-21-2330606641-2566378608-4233264486-1006
Supprimé ! C:\Recycler\S-1-5-21-2642663408-3173496037-3570927397-1003
################## | Registre |
################## | Mountpoints2 |
################## | Listing des fichiers présent |
[04/07/2005 16:56|-rahs----|215] C:\BOOT.BAK
[27/02/2010 11:52|--ahs----|297] C:\BOOT.INI
[05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
[05/08/2004 13:00|-rahs----|263488] C:\cmldr
[04/07/2005 16:43|--a------|5894] C:\DWNLOG.TXT
[?|?|?] C:\hiberfil.sys
[04/07/2005 16:59|-rahs----|0] C:\IO.SYS
[04/07/2005 17:07|--ah-----|815] C:\IPH.PH
[04/07/2005 16:59|-rahs----|0] C:\MSDOS.SYS
[04/07/2005 17:05|--a------|157] C:\MYInventimeSetup.log
[05/08/2004 13:00|--a------|47564] C:\NTDETECT.COM
[05/08/2004 13:00|--a------|251712] C:\NTLDR
[?|?|?] C:\pagefile.sys
[04/07/2005 14:33|--a------|1084] C:\SAUDIT.TXT
[27/02/2010 13:56|--a------|2918] C:\UsbFix.txt
[01/01/1995 01:00|-r-------|44] D:\Track01.cda
[01/01/1995 01:04|-r-------|44] D:\Track02.cda
[01/01/1995 01:08|-r-------|44] D:\Track03.cda
[01/01/1995 01:12|-r-------|44] D:\Track04.cda
[01/01/1995 01:17|-r-------|44] D:\Track05.cda
[01/01/1995 01:21|-r-------|44] D:\Track06.cda
[01/01/1995 01:24|-r-------|44] D:\Track07.cda
[01/01/1995 01:29|-r-------|44] D:\Track08.cda
[01/01/1995 01:33|-r-------|44] D:\Track09.cda
[01/01/1995 01:37|-r-------|44] D:\Track10.cda
[01/01/1995 01:41|-r-------|44] D:\Track11.cda
[01/01/1995 01:46|-r-------|44] D:\Track12.cda
[01/01/1995 01:50|-r-------|44] D:\Track13.cda
[01/01/1995 01:55|-r-------|44] D:\Track14.cda
[01/01/1995 01:59|-r-------|44] D:\Track15.cda
[24/12/2008 18:36|--ah-----|15364] I:\.DS_Store
[03/10/2009 12:21|--a------|40555] I:\CV_Cu_oct09.pdf
[26/12/2008 09:38|--ahs----|16384] I:\Thumbs.db
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
# I:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs).
################## | Upload |
Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_Bibi.zip : https://www.ionos.fr/?affiliate_id=77097
Merci pour votre contribution .
################## | ! Fin du rapport # UsbFix V6.097 ! |