UC utilisé à 100% ...

Fermé
laurent59113 Messages postés 50 Date d'inscription vendredi 29 septembre 2006 Statut Membre Dernière intervention 30 juillet 2011 - 13 juin 2007 à 19:50
laurent59113 Messages postés 50 Date d'inscription vendredi 29 septembre 2006 Statut Membre Dernière intervention 30 juillet 2011 - 14 juin 2007 à 16:43
Bonjour à toutes et tous !

Bizarrement mon UC est utilisé à 100% lorsque je consulte le gestionnaire des tâches !

Alors même que rien ne fonctionne sauf peut être un logiciel P2P.

J'ai donc fais un HijackThis et voici le rapport

Vous est-il possible de me dire si il y a quelque chose de particulier ?

merci d'avance pour votre aide

Laurent

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 19:20:35, on 13/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrateur\Bureau\desinfect\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Zone Labs Client] d:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [avast!] "d:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Office SturtUp] osa9.exe
O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Stardock ObjectDock.lnk = D:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://linktrader.cyberspacehq.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - d:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - d:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - d:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - d:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: DDE réseau (NetDDE) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau (NetDDEdsdm) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Telnet (TlntSvr) - Unknown owner - C:\WINDOWS\system32\tlntsvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: DirectX Service (Xuvuq) - Unknown owner - C:\WINDOWS\system32\directx.exe

3 réponses

Utilisateur anonyme
13 juin 2007 à 20:02
Bonjour

Pas très propre en effet. Prècise les anti-spywares que tu as stp


Télécharge ComboScan sur ton Bureau.
---> http://www.techsupportforum.com/sectools/Deckard/dss.exe
Ferme toutes les applications en cours ; antivirus, pare-feu, etc ..
Double-clic sur comboscan.exe A la fenêtre qui s'affiche, clic sur OK.
Soit patient ..
Le rapport Comboscan.txt s'affichera, copie et colle le contenu de ce fichier ici.
Attention, il peut avoir deux, trois rapports mets les tous ici
0
laurent59113 Messages postés 50 Date d'inscription vendredi 29 septembre 2006 Statut Membre Dernière intervention 30 juillet 2011 3
13 juin 2007 à 20:51
Bonsoir et merci pour cette réponse rapide !!

Je n'ai que ZA et Avast et j'utilise de temps en temps Ad Awar pour nettoyer.

Comme demandé voici les rapports de ComboScan, (trois au total)

Merci encore pour les infos :

Deckard's System Scanner v20070611.50
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professionnel (build 2600) SP 2.0
Architecture: X86; Language: French

CPU 0: AMD Athlon(tm)
Percentage of Memory in Use: 17%
Physical Memory (total/avail): 2047.48 MiB / 1680.05 MiB
Pagefile Memory (total/avail): 3943.95 MiB / 3723.87 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1961.73 MiB

C: is Fixed (NTFS) - 74.52 GiB total, 37.83 GiB free.
D: is Fixed (NTFS) - 298.09 GiB total, 174.65 GiB free.
E: is CDROM (CDFS)
F: is CDROM (CDFS)
H: is Fixed (NTFS) - 37.26 GiB total, 24.48 GiB free.


-- Security Center -------------------------------------------------------------

AUOptions is set to notify before install.
Windows Internal Firewall is disabled.

FirstRunDisabled is set.
FirewallDisableNotify is set.
UpdatesDisableNotify is set.
AntivirusOverride is set.
FirewallOverride is set.

FW: ZoneAlarm Firewall v7.0.337.000 (Check Point, LTD.) [COLOR=RED]Disabled[/COLOR]
AV: avast! antivirus 4.7.1001 [VPS 000748-5] v4.7.1001 (ALWIL Software) [COLOR=RED]Disabled[/COLOR]

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\WINDOWS\\Registration\\explorer.exe"="C:\\WINDOWS\\Registration\\explorer.exe:*:Enabled:Explorer"

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\WINDOWS\\Registration\\explorer.exe"="C:\\WINDOWS\\Registration\\explorer.exe:*:Enabled:Explorer"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrateur\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Fichiers communs
COMPUTERNAME=LAURENT
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrateur
LOGONSERVER=\\LAURENT
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 4 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0402
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Administrateur\Local Settings\Temp
TMP=C:\DOCUME~1\Administrateur\Local Settings\Temp
tvdumpflags=8
USERDOMAIN=LAURENT
USERNAME=Administrateur
USERPROFILE=C:\Documents and Settings\Administrateur
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Administrateur [I](admin)[/I]


-- Add/Remove Programs ---------------------------------------------------------



-- End of Deckard's System Scanner: finished at 2007-06-13 at 20:37:09 ---------



Le deuxieme :

Deckard's System Scanner v20070611.50
Run by Administrateur on 2007-06-13 at 20:34:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2007-06-13 18:34:37 UTC - RP1 - Point de vérification système


Backed up registry hives.

Performed disk cleanup.


-- HijackThis Clone ------------------------------------------------------------

Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-06-13 20:36:19
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\explorer.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
D:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Registration\explorer.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Administrateur\Bureau\desinfect\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Zone Labs Client] d:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [avast!] "d:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Office SturtUp] osa9.exe
O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Stardock ObjectDock.lnk = D:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O15 - Trusted Zone: http://linktrader.cyberspacehq.com (HKCU)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} () - http://download.microsoft.com/download/0/f/b/0fb0fab9-7f09-4bb6-86d8-8e791ba99ac5/VirtualEarth3D.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll
O23 - Service: Adobe LM Service - Adobe Systems - "C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: DirectX Service (Xuvuq) - Unknown owner - C:\WINDOWS\system32\directx.exe


-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>

S1 InCDPass - c:\windows\system32\drivers\incdpass.sys (file missing)
S1 InCDRm (InCD Reader) - c:\windows\system32\drivers\incdrm.sys (file missing)
S4 InCDFs (InCD File System) - c:\windows\system32\drivers\incdfs.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S2 Xuvuq (DirectX Service) - c:\windows\system32\directx.exe


-- Files created between 2007-05-13 and 2007-06-13 -----------------------------

2007-06-13 19:28:56 0 d--hs---- C:\Documents and Settings\Administrateur\Recent
2007-06-13 18:18:47 258048 --a------ C:\WINDOWS\zzzip.exe <Not Verified; PKWARE, Inc; PKZIP® Command Line for Windows>
2007-06-13 18:18:47 108792 --a------ C:\WINDOWS\setup.exe
2007-06-13 18:18:46 148368 --a------ C:\WINDOWS\rrrar.exe
2007-06-09 15:26:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-06-09 15:19:58 0 d-------- C:\Program Files\Windows Live
2007-06-05 17:42:20 0 d--hs---- C:\WINDOWS\CSC
2007-06-04 20:43:15 0 d-------- C:\WINDOWS\AU_Temp
2007-06-03 18:00:45 0 d-------- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2007-06-03 18:00:44 0 d-------- C:\Program Files\SmartSound Software
2007-06-03 17:59:49 0 d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2007-06-03 17:58:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-05-31 21:06:47 446464 --a------ C:\WINDOWS\system32\vp31vfw.dll <Not Verified; On2.com; On2_VP3>
2007-05-31 21:06:47 0 d-------- C:\Program Files\On2 Technologies
2007-05-31 20:56:30 0 d-------- C:\Program Files\VDCodecPack3.7
2007-05-31 20:50:34 35946501 --a------ C:\mvinfo.bin
2007-05-29 17:35:41 0 d-------- C:\WINDOWS\system32\NtmsData
2007-05-26 12:07:29 0 d-------- C:\Program Files\Sony
2007-05-25 21:11:59 0 d-------- C:\WINDOWS\report
2007-05-25 21:09:44 0 d-------- C:\WINDOWS\AU_Backup
2007-05-25 21:09:40 267845 --a------ C:\WINDOWS\tsc.exe <Not Verified; Trend Micro Inc.; TrendSystemCleaner>
2007-05-25 21:09:40 71749 --a------ C:\WINDOWS\hcextoutput.dll
2007-05-25 21:09:38 1101904 --a------ C:\WINDOWS\vsapi32.dll <Not Verified; Trend Micro Inc.; VSAPI>
2007-05-25 21:09:38 86094 --a------ C:\WINDOWS\BPMNT.dll <Not Verified; Trend Micro Inc.; VSAPI>
2007-05-25 21:07:29 0 d-------- C:\WINDOWS\AU_Log
2007-05-25 21:07:23 507904 --a------ C:\WINDOWS\TMUPDATE.DLL <Not Verified; Trend Micro Inc.; ActiveUpdate Module>
2007-05-25 21:07:22 69689 --a------ C:\WINDOWS\UNZIP.DLL <Not Verified; Trend Micro Inc.; Trend Active Update 1.32>
2007-05-25 21:07:22 286720 --a------ C:\WINDOWS\PATCH.EXE <Not Verified; Trend Micro Inc.; ActiveUpdate Module>
2007-05-25 14:48:58 5120 --a------ C:\WINDOWS\system\vdsvrlnk.dll <Not Verified; ; VirtualDub>
2007-05-25 14:48:58 7168 --a------ C:\WINDOWS\system\vdremote.dll <Not Verified; ; VirtualDub>
2007-05-22 20:56:42 0 d-------- C:\WINDOWS\system32\appmgmt
2007-05-22 17:52:18 0 d-------- C:\Documents and Settings\All Users\eBay
2007-05-20 20:44:07 273 --a------ C:\WINDOWS\comm.bin
2007-05-20 20:43:53 257 --a------ C:\WINDOWS\msdres.bin
2007-05-20 20:43:47 557805 --a------ C:\WINDOWS\update.exe
2007-05-20 20:43:25 47351 --a------ C:\WINDOWS\system32\osa9.exe
2007-05-20 20:43:25 25600 --a------ C:\WINDOWS\system32\ctccw32.dll
2007-05-20 20:12:00 16384 --a------ C:\WINDOWS\system32\FileOps.exe
2007-05-20 20:11:59 0 d-------- C:\WINDOWS\system32\Adobe
2007-05-20 20:10:12 0 d-------- C:\WINDOWS\Adobe Illustrator CS
2007-05-20 19:49:13 149504 --a------ C:\WINDOWS\UNWISE.EXE
2007-05-18 14:21:10 0 d-------- C:\Program Files\Signal Spam
2007-05-18 14:20:39 0 d-------- C:\Program Files\Microsoft.NET
2007-05-16 19:06:24 0 d-------- C:\super8
2007-05-16 19:05:41 74752 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic pour Windows>


-- Find3M Report ---------------------------------------------------------------

2007-06-13 18:08:25 0 d-------- C:\Program Files\Fichiers communs\System
2007-06-13 17:40:57 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Adobe
2007-06-12 17:46:52 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Audacity
2007-06-09 15:19:58 0 d-------- C:\Program Files\MSN Messenger
2007-06-05 18:02:38 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-06-05 18:02:25 0 d-------- C:\Program Files\QuickTime
2007-06-05 17:47:27 0 d-------- C:\Program Files\Fichiers communs
2007-06-03 21:25:48 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Ulead Systems
2007-05-31 21:07:48 36734 --a------ C:\WINDOWS\system32\OggDSuninst.exe
2007-05-25 13:12:35 0 d-------- C:\Program Files\Fichiers communs\Sage
2007-05-22 21:08:16 536978 --a------ C:\WINDOWS\system32\perfh00C.dat
2007-05-22 21:08:16 101196 --a------ C:\WINDOWS\system32\perfc00C.dat
2007-05-20 20:12:05 0 d-------- C:\Program Files\Fichiers communs\Vbox
2007-05-20 20:11:59 0 d-------- C:\Program Files\Fichiers communs\Adobe
2007-05-20 13:37:15 356352 --a------ C:\WINDOWS\system32\CRun500.dll <Not Verified; Compagnie Internationale d'Edition de Logiciel; CRun Dynamic Link Library>
2007-05-18 14:10:32 0 d-------- C:\Program Files\Fichiers communs\Microsoft Shared
2007-05-10 08:17:20 0 d-------- C:\Program Files\Java
2007-05-03 11:39:36 1044480 -ra------ C:\WINDOWS\system32\roboex32.dll <Not Verified; eHelp Corporation.; RoboHELP for WinHelp 9.2>
2007-05-03 11:39:36 49152 -ra------ C:\WINDOWS\system32\inetwh32.dll <Not Verified; Blue Sky Software Corporation.; Blue Sky Software - INETWH32>
2007-04-19 19:37:14 0 d-------- C:\Program Files\Virtual Earth 3D
2007-04-03 13:48:57 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat


-- Registry Dump ---------------------------------------------------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"Zone Labs Client"="d:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"avast!"="\"d:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Acrobat Assistant 7.0"="\"D:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
@=""
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Office SturtUp"="osa9.exe"
"gfxtray"="rundll32 ctccw32.dll,findwnd"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearDocsOnExit"=dword:00000040
"NoRecentDocsMenu"=dword:00000001
"NoCDBurning"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001
"NoStartBanner"=hex:01,00,00,00
"NoSMHelp"=dword:00000001
"ClearRecentDocsOnExit"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000001
"NoSMBalloonTip"=dword:00000001
"NoDesktopCleanupWizard"=dword:00000001
"NoWelcomeScreen"=dword:00000001
"NoAutoUpdate"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ClearDocsOnExit"=dword:00000040
"NoRecentDocsMenu"=dword:00000001
"NoCDBurning"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001
"NoStartBanner"=hex:01,00,00,00
"NoSMHelp"=dword:00000001
"ClearRecentDocsOnExit"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000001
"NoSMBalloonTip"=dword:00000001
"NoDesktopCleanupWizard"=dword:00000001
"NoWelcomeScreen"=dword:00000001
"NoAutoUpdate"=dword:00000001

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



-- End of Deckard's System Scanner: finished at 2007-06-13 at 20:37:09 ---------

et le dernier :

Directories/Files moved to C:\Deckard\System Scanner\backup

2007-06-09 14:23:40 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\Acrobat Distiller 7
2007-06-12 20:21:10 59964 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\Adobelm_Cleanup.0001 <Not Verified; Macrovision Europe Ltd.; Macrovision Europe Ltd. Cleanup>
2007-06-12 20:21:12 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\Adobelm_Cleanup.0001.dir.0000
2007-06-12 20:21:20 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\Adobelm_Cleanup.0001.dir.0001
2007-06-09 13:38:46 15101 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\AR-1181389126187.pdf
2007-06-12 21:14:33 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\audacity_1_2_temp
2007-06-09 13:40:42 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\hsperfdata_Administrateur
2007-06-09 13:34:12 416 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\java_install_reg.log
2007-06-13 19:34:56 1384 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\jusched.log
2007-06-13 17:55:03 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\MessengerCache
2007-06-05 20:03:07 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\OIS
2007-06-09 13:37:40 6512 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\Resume-1181389060093.pdf
2007-06-09 13:36:57 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\TaoUSign
2007-06-09 15:55:27 896 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\TWAIN.LOG
2007-06-09 15:55:27 3 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\Twain001.Mtx
2007-06-09 15:55:27 156 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\Twunk001.MTX
2007-06-09 14:04:45 0 --a------ C:\DOCUME~1\Administrateur\Local Settings\Temp\Twunk002.MTX
2007-06-13 18:03:01 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\VBE
2007-06-12 07:28:32 1184085 --a-----t C:\DOCUME~1\Administrateur\Local Settings\Temp\VGX158.tmp
2007-06-09 13:39:05 42532 ---h----- C:\DOCUME~1\Administrateur\Local Settings\Temp\Z@R178.tmp
2007-06-07 18:46:43 0 d-------- C:\DOCUME~1\Administrateur\Local Settings\Temp\_avast4_
2007-06-13 18:43:51 0 --a-----t C:\WINDOWS\temp\JET9FAB.tmp
2007-06-13 18:43:55 16384 --a-----t C:\WINDOWS\temp\Perflib_Perfdata_6f8.dat
2007-06-06 07:39:55 256 --a-----t C:\WINDOWS\temp\ZLT03242.TMP
2007-06-06 07:39:56 256 --a-----t C:\WINDOWS\temp\ZLT03245.TMP
2007-06-13 18:17:24 256 --a-----t C:\WINDOWS\temp\ZLT03d19.TMP
2007-06-13 18:17:27 256 --a-----t C:\WINDOWS\temp\ZLT03d23.TMP
2007-06-06 22:09:55 256 --a-----t C:\WINDOWS\temp\ZLT04c21.TMP
2007-06-06 22:09:58 256 --a-----t C:\WINDOWS\temp\ZLT04c2b.TMP
2007-06-13 18:44:03 256 --a-----t C:\WINDOWS\temp\ZLT0517f.TMP
2007-06-13 18:44:07 256 --a-----t C:\WINDOWS\temp\ZLT05189.TMP
2007-06-09 14:32:11 256 --a-----t C:\WINDOWS\temp\ZLT05831.TMP
2007-06-09 14:32:14 256 --a-----t C:\WINDOWS\temp\ZLT0583b.TMP
2007-06-07 07:06:23 256 --a-----t C:\WINDOWS\temp\ZLT066b9.TMP
2007-06-07 07:06:26 256 --a-----t C:\WINDOWS\temp\ZLT066c3.TMP
2007-06-13 20:34:18 0 d-------- C:\WINDOWS\temp\_avast4_
2006-06-20 15:44:04 379704 --a------ C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll <Verified; Microsoft® Corporation; MSN Photo Upload Control>
2006-06-20 15:44:02 117560 --a------ C:\WINDOWS\Downloaded Program Files\PURen-us.dll <Verified; Microsoft® Corporation; MSN Photo Upload Control>
2007-01-09 08:30:14 110592 --a------ C:\WINDOWS\Downloaded Program Files\PURfr-fr.dll <Not Verified; Microsoft® Corporation; Outil MSN Téléchargement de photos>
2006-12-27 18:46:44 2557752 --a------ C:\WINDOWS\Downloaded Program Files\ImageUploader4.ocx <Verified; Aurigma, Inc.; Image Uploader>
2005-11-02 18:07:08 435712 --a------ C:\WINDOWS\Downloaded Program Files\xscan53.ocx <Not Verified; Trend Micro Inc.; Trend Micro HouseCall v5.70.0>

-*- End of Logfile -*-


merci encore

Laurent
0
laurent59113 Messages postés 50 Date d'inscription vendredi 29 septembre 2006 Statut Membre Dernière intervention 30 juillet 2011 3
14 juin 2007 à 16:43
Bonjour,

Quelqu'un peut me renseigner s'il vous plaît ?

merci

Laurent
0