Rapport rsit, possible infection
Fermé
bob
-
16 mai 2010 à 13:16
Destrio5 Messages postés 85926 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 16 mai 2010 à 14:56
Destrio5 Messages postés 85926 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 16 mai 2010 à 14:56
A voir également:
- Rapport rsit, possible infection
- Impossible d'afficher le rapport de tableau croisé dynamique sur un rapport existant ✓ - Forum Excel
- Rapport de stage - Guide
- Exemple de rapport de travail word ✓ - Forum Word
- Avant propos rapport de stage - Forum Programmation
- Impossible d'afficher le tableau dynamique sur un rapport existant - Forum Bureautique
5 réponses
Logfile of random's system information tool 1.07 (written by random/random)
Run by Utilisateur at 2010-05-16 13:09:41
Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 2
System drive C: has 197 GB (87%) free of 227 GB
Total RAM: 3070 MB (62% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-10-20 68112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-24 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-20 268816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - Veoh Web Player Video Finder - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll [2009-05-20 429816]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{1c99b848-84cb-4ce4-8cd8-ed5719484d9f} - Kiwee Toolbar - C:\Windows\system32\mscoree.dll [2009-03-29 278848]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"toolbar_eula_launcher"=C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe [2007-02-20 28672]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-02-09 845360]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2008-01-20 92704]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-01-20 88608]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-01-20 8534560]
"CardReaderMonitor"=C:\Program Files\Realtek Semiconductor Corp.\Realtek Card Reader Monitor\CardReaderMonitor.exe [2007-07-25 643072]
"CarboniteSetupLite"=C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe [2008-02-22 262080]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"VeohPlugin"=C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [2009-05-20 3561720]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2009-05-26 4351216]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-01-14 1688872]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-07 102400]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Report.lnk - C:\REPORT\WebForm.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2009-10-20 219664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"UacDisableNotify"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a0cd610-7de9-11de-8a41-00140b48057a}]
shell\AUtopLay\command - wfnu.exe
shell\AutoRun\command - wfnu.exe
shell\EXPLOre\command - wfnu.exe
shell\Open\command - wfnu.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-05-16 12:58:43 ----D---- C:\Program Files\trend micro
2010-05-16 12:58:42 ----D---- C:\rsit
2010-05-15 22:23:59 ----D---- C:\ProgramData\Kaspersky Lab
2010-05-15 22:23:59 ----D---- C:\Program Files\Kaspersky Lab
2010-05-15 22:21:45 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2010-05-15 22:13:13 ----D---- C:\Program Files\a-squared Free
2010-05-15 22:04:53 ----A---- C:\Windows\system32\inetcomm.dll
2010-05-15 22:04:45 ----A---- C:\mbam-error.txt
2010-05-03 20:02:08 ----D---- C:\Program Files\AbiWord
2010-05-01 21:32:29 ----D---- C:\Users\Utilisateur\AppData\Roaming\Template
2010-04-30 13:43:15 ----D---- C:\ProgramData\DivX
2010-04-25 00:01:58 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-04-25 00:00:43 ----D---- C:\Program Files\SpywareBlaster
2010-04-24 23:58:37 ----D---- C:\Users\Utilisateur\AppData\Roaming\Opera
2010-04-24 23:58:14 ----D---- C:\Program Files\Opera
2010-04-24 23:55:17 ----A---- C:\Windows\system32\javaws.exe
2010-04-24 23:55:17 ----A---- C:\Windows\system32\javaw.exe
2010-04-24 23:55:17 ----A---- C:\Windows\system32\java.exe
2010-04-24 23:49:33 ----D---- C:\Program Files\CCleaner
2010-04-24 20:11:24 ----D---- C:\Windows\pss
2010-04-24 19:54:37 ----SHD---- C:\Windows\system32\%APPDATA%
2010-04-24 18:28:59 ----A---- C:\Windows\system32\TURegOpt.exe
2010-04-24 18:28:57 ----A---- C:\Windows\system32\uxtuneup.dll
2010-04-24 18:28:57 ----A---- C:\Windows\system32\authuitu.dll
2010-04-24 18:28:31 ----D---- C:\Users\Utilisateur\AppData\Roaming\TuneUp Software
2010-04-24 18:28:22 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-04-24 18:28:11 ----D---- C:\ProgramData\TuneUp Software
2010-04-24 18:28:04 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-04-24 18:19:13 ----D---- C:\Windows\temp
2010-04-24 18:12:28 ----D---- C:\$RECYCLE.BIN
2010-04-24 17:57:56 ----A---- C:\Windows\zip.exe
2010-04-24 17:57:56 ----A---- C:\Windows\SWSC.exe
2010-04-24 17:57:56 ----A---- C:\Windows\SWREG.exe
2010-04-24 17:57:56 ----A---- C:\Windows\sed.exe
2010-04-24 17:57:56 ----A---- C:\Windows\PEV.exe
2010-04-24 17:57:56 ----A---- C:\Windows\NIRCMD.exe
2010-04-24 17:57:56 ----A---- C:\Windows\MBR.exe
2010-04-24 17:57:56 ----A---- C:\Windows\grep.exe
2010-04-24 17:57:50 ----D---- C:\Windows\ERDNT
2010-04-24 17:57:11 ----A---- C:\Windows\SWXCACLS.exe
2010-04-24 17:07:29 ----A---- C:\Windows\NeroDigital.ini
2010-04-19 18:52:33 ----D---- C:\ProgramData\Sun
2010-04-19 18:52:32 ----D---- C:\Program Files\Common Files\Java
2010-04-19 18:33:39 ----A---- C:\Windows\system32\deployJava1.dll
2010-04-17 02:17:52 ----A---- C:\Windows\system32\browserchoice.exe
======List of files/folders modified in the last 1 months======
2010-05-16 13:09:37 ----D---- C:\Windows\prefetch
2010-05-16 13:03:06 ----D---- C:\Windows\inf
2010-05-16 13:03:06 ----AD---- C:\Windows\System32
2010-05-16 13:03:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-05-16 12:58:43 ----RD---- C:\Program Files
2010-05-16 10:18:46 ----D---- C:\ProgramData
2010-05-16 10:18:45 ----AD---- C:\Windows\system32\drivers
2010-05-16 01:04:51 ----SHD---- C:\Windows\Installer
2010-05-16 01:04:46 ----D---- C:\Config.Msi
2010-05-16 01:04:45 ----D---- C:\ProgramData\Microsoft Help
2010-05-15 23:08:22 ----D---- C:\Windows
2010-05-15 22:28:14 ----SHD---- C:\System Volume Information
2010-05-15 22:25:39 ----D---- C:\Windows\system32\catroot
2010-05-15 22:09:43 ----D---- C:\Windows\winsxs
2010-05-15 22:06:53 ----D---- C:\Windows\Debug
2010-05-15 22:06:46 ----D---- C:\Program Files\Windows Mail
2010-05-15 22:06:42 ----AD---- C:\ProgramData\TEMP
2010-05-15 22:04:21 ----D---- C:\Windows\system32\catroot2
2010-05-15 13:56:39 ----D---- C:\Program Files\Jeux.fr
2010-05-15 13:54:41 ----D---- C:\Program Files\Anuman Interactive
2010-05-15 13:54:34 ----D---- C:\Program Files\Common Files
2010-05-15 13:53:02 ----SD---- C:\Users\Utilisateur\AppData\Roaming\Microsoft
2010-05-06 10:36:38 ----N---- C:\Windows\system32\MpSigStub.exe
2010-05-03 20:31:44 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2010-05-03 20:29:49 ----D---- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2010-05-03 20:02:57 ----RSD---- C:\Windows\Fonts
2010-05-03 19:53:04 ----D---- C:\Program Files\Microsoft
2010-04-30 20:51:06 ----A---- C:\Windows\system32\mrt.exe
2010-04-29 23:39:20 ----D---- C:\Users\Utilisateur\AppData\Roaming\dvdcss
2010-04-29 20:05:37 ----D---- C:\Windows\system32\Tasks
2010-04-25 00:34:51 ----D---- C:\Windows\Tasks
2010-04-25 00:31:33 ----D---- C:\Program Files\Packard Bell
2010-04-25 00:07:10 ----D---- C:\Windows\system32\LogFiles
2010-04-24 23:53:03 ----D---- C:\Users\Utilisateur\AppData\Roaming\Mozilla
2010-04-24 23:52:54 ----D---- C:\Program Files\Mozilla Firefox
2010-04-24 18:12:46 ----A---- C:\Windows\system.ini
2010-04-24 18:05:23 ----D---- C:\Windows\AppPatch
2010-04-24 17:25:59 ----SD---- C:\Windows\Downloaded Program Files
2010-04-24 16:27:55 ----D---- C:\ProgramData\NVIDIA
2010-04-24 15:39:55 ----D---- C:\Program Files\Yahoo!
2010-04-21 13:24:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-21 13:24:31 ----D---- C:\Program Files\Google
2010-04-19 18:33:33 ----D---- C:\Program Files\Java
2010-04-18 21:48:12 ----D---- C:\Users\Utilisateur\AppData\Roaming\LimeWire
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2009-09-01 128016]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2010-05-15 311312]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2009-09-14 21520]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
R3 netr28;Ralink 802.11n Wireless Driver for Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2007-11-21 327168]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-01-20 8240256]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-03-26 64000]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-02-09 182456]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-10 73216]
R3 vm331avs;Bison Webcam; C:\Windows\System32\Drivers\vm331avs.sys [2007-09-07 943016]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-07-09 39424]
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2010-04-15 1872320]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6; C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-07-09 144712]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-04-07 233472]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-11-13 1021256]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-01-14 447784]
S2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-05-23 654848]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 TuneUp.Defrag;@C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-04-24 435016]
-----------------EOF-----------------
Run by Utilisateur at 2010-05-16 13:09:41
Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 2
System drive C: has 197 GB (87%) free of 227 GB
Total RAM: 3070 MB (62% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-10-20 68112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-24 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-20 268816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - Veoh Web Player Video Finder - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll [2009-05-20 429816]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{1c99b848-84cb-4ce4-8cd8-ed5719484d9f} - Kiwee Toolbar - C:\Windows\system32\mscoree.dll [2009-03-29 278848]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"toolbar_eula_launcher"=C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe [2007-02-20 28672]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-02-09 845360]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2008-01-20 92704]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-01-20 88608]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-01-20 8534560]
"CardReaderMonitor"=C:\Program Files\Realtek Semiconductor Corp.\Realtek Card Reader Monitor\CardReaderMonitor.exe [2007-07-25 643072]
"CarboniteSetupLite"=C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe [2008-02-22 262080]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"VeohPlugin"=C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [2009-05-20 3561720]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2009-05-26 4351216]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-01-14 1688872]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-07 102400]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Report.lnk - C:\REPORT\WebForm.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2009-10-20 219664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"UacDisableNotify"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a0cd610-7de9-11de-8a41-00140b48057a}]
shell\AUtopLay\command - wfnu.exe
shell\AutoRun\command - wfnu.exe
shell\EXPLOre\command - wfnu.exe
shell\Open\command - wfnu.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-05-16 12:58:43 ----D---- C:\Program Files\trend micro
2010-05-16 12:58:42 ----D---- C:\rsit
2010-05-15 22:23:59 ----D---- C:\ProgramData\Kaspersky Lab
2010-05-15 22:23:59 ----D---- C:\Program Files\Kaspersky Lab
2010-05-15 22:21:45 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2010-05-15 22:13:13 ----D---- C:\Program Files\a-squared Free
2010-05-15 22:04:53 ----A---- C:\Windows\system32\inetcomm.dll
2010-05-15 22:04:45 ----A---- C:\mbam-error.txt
2010-05-03 20:02:08 ----D---- C:\Program Files\AbiWord
2010-05-01 21:32:29 ----D---- C:\Users\Utilisateur\AppData\Roaming\Template
2010-04-30 13:43:15 ----D---- C:\ProgramData\DivX
2010-04-25 00:01:58 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-04-25 00:00:43 ----D---- C:\Program Files\SpywareBlaster
2010-04-24 23:58:37 ----D---- C:\Users\Utilisateur\AppData\Roaming\Opera
2010-04-24 23:58:14 ----D---- C:\Program Files\Opera
2010-04-24 23:55:17 ----A---- C:\Windows\system32\javaws.exe
2010-04-24 23:55:17 ----A---- C:\Windows\system32\javaw.exe
2010-04-24 23:55:17 ----A---- C:\Windows\system32\java.exe
2010-04-24 23:49:33 ----D---- C:\Program Files\CCleaner
2010-04-24 20:11:24 ----D---- C:\Windows\pss
2010-04-24 19:54:37 ----SHD---- C:\Windows\system32\%APPDATA%
2010-04-24 18:28:59 ----A---- C:\Windows\system32\TURegOpt.exe
2010-04-24 18:28:57 ----A---- C:\Windows\system32\uxtuneup.dll
2010-04-24 18:28:57 ----A---- C:\Windows\system32\authuitu.dll
2010-04-24 18:28:31 ----D---- C:\Users\Utilisateur\AppData\Roaming\TuneUp Software
2010-04-24 18:28:22 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-04-24 18:28:11 ----D---- C:\ProgramData\TuneUp Software
2010-04-24 18:28:04 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-04-24 18:19:13 ----D---- C:\Windows\temp
2010-04-24 18:12:28 ----D---- C:\$RECYCLE.BIN
2010-04-24 17:57:56 ----A---- C:\Windows\zip.exe
2010-04-24 17:57:56 ----A---- C:\Windows\SWSC.exe
2010-04-24 17:57:56 ----A---- C:\Windows\SWREG.exe
2010-04-24 17:57:56 ----A---- C:\Windows\sed.exe
2010-04-24 17:57:56 ----A---- C:\Windows\PEV.exe
2010-04-24 17:57:56 ----A---- C:\Windows\NIRCMD.exe
2010-04-24 17:57:56 ----A---- C:\Windows\MBR.exe
2010-04-24 17:57:56 ----A---- C:\Windows\grep.exe
2010-04-24 17:57:50 ----D---- C:\Windows\ERDNT
2010-04-24 17:57:11 ----A---- C:\Windows\SWXCACLS.exe
2010-04-24 17:07:29 ----A---- C:\Windows\NeroDigital.ini
2010-04-19 18:52:33 ----D---- C:\ProgramData\Sun
2010-04-19 18:52:32 ----D---- C:\Program Files\Common Files\Java
2010-04-19 18:33:39 ----A---- C:\Windows\system32\deployJava1.dll
2010-04-17 02:17:52 ----A---- C:\Windows\system32\browserchoice.exe
======List of files/folders modified in the last 1 months======
2010-05-16 13:09:37 ----D---- C:\Windows\prefetch
2010-05-16 13:03:06 ----D---- C:\Windows\inf
2010-05-16 13:03:06 ----AD---- C:\Windows\System32
2010-05-16 13:03:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-05-16 12:58:43 ----RD---- C:\Program Files
2010-05-16 10:18:46 ----D---- C:\ProgramData
2010-05-16 10:18:45 ----AD---- C:\Windows\system32\drivers
2010-05-16 01:04:51 ----SHD---- C:\Windows\Installer
2010-05-16 01:04:46 ----D---- C:\Config.Msi
2010-05-16 01:04:45 ----D---- C:\ProgramData\Microsoft Help
2010-05-15 23:08:22 ----D---- C:\Windows
2010-05-15 22:28:14 ----SHD---- C:\System Volume Information
2010-05-15 22:25:39 ----D---- C:\Windows\system32\catroot
2010-05-15 22:09:43 ----D---- C:\Windows\winsxs
2010-05-15 22:06:53 ----D---- C:\Windows\Debug
2010-05-15 22:06:46 ----D---- C:\Program Files\Windows Mail
2010-05-15 22:06:42 ----AD---- C:\ProgramData\TEMP
2010-05-15 22:04:21 ----D---- C:\Windows\system32\catroot2
2010-05-15 13:56:39 ----D---- C:\Program Files\Jeux.fr
2010-05-15 13:54:41 ----D---- C:\Program Files\Anuman Interactive
2010-05-15 13:54:34 ----D---- C:\Program Files\Common Files
2010-05-15 13:53:02 ----SD---- C:\Users\Utilisateur\AppData\Roaming\Microsoft
2010-05-06 10:36:38 ----N---- C:\Windows\system32\MpSigStub.exe
2010-05-03 20:31:44 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2010-05-03 20:29:49 ----D---- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2010-05-03 20:02:57 ----RSD---- C:\Windows\Fonts
2010-05-03 19:53:04 ----D---- C:\Program Files\Microsoft
2010-04-30 20:51:06 ----A---- C:\Windows\system32\mrt.exe
2010-04-29 23:39:20 ----D---- C:\Users\Utilisateur\AppData\Roaming\dvdcss
2010-04-29 20:05:37 ----D---- C:\Windows\system32\Tasks
2010-04-25 00:34:51 ----D---- C:\Windows\Tasks
2010-04-25 00:31:33 ----D---- C:\Program Files\Packard Bell
2010-04-25 00:07:10 ----D---- C:\Windows\system32\LogFiles
2010-04-24 23:53:03 ----D---- C:\Users\Utilisateur\AppData\Roaming\Mozilla
2010-04-24 23:52:54 ----D---- C:\Program Files\Mozilla Firefox
2010-04-24 18:12:46 ----A---- C:\Windows\system.ini
2010-04-24 18:05:23 ----D---- C:\Windows\AppPatch
2010-04-24 17:25:59 ----SD---- C:\Windows\Downloaded Program Files
2010-04-24 16:27:55 ----D---- C:\ProgramData\NVIDIA
2010-04-24 15:39:55 ----D---- C:\Program Files\Yahoo!
2010-04-21 13:24:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-21 13:24:31 ----D---- C:\Program Files\Google
2010-04-19 18:33:33 ----D---- C:\Program Files\Java
2010-04-18 21:48:12 ----D---- C:\Users\Utilisateur\AppData\Roaming\LimeWire
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2009-09-01 128016]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2010-05-15 311312]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2009-09-14 21520]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
R3 netr28;Ralink 802.11n Wireless Driver for Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2007-11-21 327168]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-01-20 8240256]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-03-26 64000]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-02-09 182456]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-10 73216]
R3 vm331avs;Bison Webcam; C:\Windows\System32\Drivers\vm331avs.sys [2007-09-07 943016]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-07-09 39424]
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2010-04-15 1872320]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6; C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-07-09 144712]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-04-07 233472]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-11-13 1021256]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-01-14 447784]
S2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-05-23 654848]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 TuneUp.Defrag;@C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-04-24 435016]
-----------------EOF-----------------
Destrio5
Messages postés
85926
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
16 mai 2010 à 13:29
16 mai 2010 à 13:29
Bonjour,
--> Télécharge UsbFix (par El Desaparecido & C_XX) sur ton Bureau.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur le programme UsbFix situé sur ton Bureau.
--> Choisis l'option 1 (Recherche).
--> Laisse travailler l'outil.
--> Poste le rapport UsbFix.txt.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
--> Télécharge UsbFix (par El Desaparecido & C_XX) sur ton Bureau.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur le programme UsbFix situé sur ton Bureau.
--> Choisis l'option 1 (Recherche).
--> Laisse travailler l'outil.
--> Poste le rapport UsbFix.txt.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
par contre usb.fix faudrait revoir le programme, depuis quand hijackthis et un log de rsit sont des élements infectieux !!!! lol
############################## | UsbFix V6.113 |
User : Utilisateur (Administrateurs) # PC-DE-UTILISATE
Update on 13/05/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:35:59 | 16/05/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
AMD Turion(tm) 64 X2 Mobile Technology TL-62
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18904
Windows Firewall Status : Disabled
C:\ -> Disque fixe local # 221,24 Go (192,24 Go free) [HDD] # NTFS
D:\ -> Disque CD-ROM
E:\ -> Disque amovible # 3,8 Go (3,79 Go free) # FAT32
################## | Elements infectieux |
E:\log.txt
E:\HiJackThis.exe
################## | Registre |
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
################## | Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{5a0cd610-7de9-11de-8a41-00140b48057a}
sHELL\AUtopLay\cOmmand =wfnu.exe
sHELL\AutoRun\command =wfnu.exe
sHELL\EXPLOre\CommanD =wfnu.exe
sHELL\Open\CoMmaNd =wfnu.exe
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné !
################## | ! Fin du rapport # UsbFix V6.113 ! |
############################## | UsbFix V6.113 |
User : Utilisateur (Administrateurs) # PC-DE-UTILISATE
Update on 13/05/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:35:59 | 16/05/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
AMD Turion(tm) 64 X2 Mobile Technology TL-62
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18904
Windows Firewall Status : Disabled
C:\ -> Disque fixe local # 221,24 Go (192,24 Go free) [HDD] # NTFS
D:\ -> Disque CD-ROM
E:\ -> Disque amovible # 3,8 Go (3,79 Go free) # FAT32
################## | Elements infectieux |
E:\log.txt
E:\HiJackThis.exe
################## | Registre |
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
################## | Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{5a0cd610-7de9-11de-8a41-00140b48057a}
sHELL\AUtopLay\cOmmand =wfnu.exe
sHELL\AutoRun\command =wfnu.exe
sHELL\EXPLOre\CommanD =wfnu.exe
sHELL\Open\CoMmaNd =wfnu.exe
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné !
################## | ! Fin du rapport # UsbFix V6.113 ! |
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Destrio5
Messages postés
85926
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
16 mai 2010 à 14:56
16 mai 2010 à 14:56
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur UsbFix présent sur ton Bureau.
--> Choisis l'option 2 (Suppression).
--> Ton Bureau disparaîtra et le PC redémarrera.
--> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.
--> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
--> Double-clique sur UsbFix présent sur ton Bureau.
--> Choisis l'option 2 (Suppression).
--> Ton Bureau disparaîtra et le PC redémarrera.
--> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.
--> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).