A voir également:
- Pc tourne a 70° normal?
- Remettre a zero un pc - Guide
- Pc lent - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Double ecran pc - Guide
- Forcer demarrage pc - Guide
46 réponses
les manips sont faites sa donne sa:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:06:56, on 02/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Antipub\antipub.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://french.eazel.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - ?Õ - (no file)
O2 - BHO: (no name) - p?Õ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - ¨Õ - (no file)
O2 - BHO: (no name) - ð>Õ - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - https://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:06:56, on 02/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Antipub\antipub.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://french.eazel.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - ?Õ - (no file)
O2 - BHO: (no name) - p?Õ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - ¨Õ - (no file)
O2 - BHO: (no name) - ð>Õ - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - https://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
Bon,
Il est encore infecté....
Si ton PC atteint une température critique il l'éteindra tout seul (protection thermique).
essayons un autre truc :
> Télécharge ComboFix : http://www.pc-xpress.ca/download/ComboFix.exe (par sUBs) sur ton Bureau.
Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
- Double clique combofix.exe :
- Tape sur la touche 1 (Yes) pour démarrer le scan.
- Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.
A+
:)
Il est encore infecté....
Si ton PC atteint une température critique il l'éteindra tout seul (protection thermique).
essayons un autre truc :
> Télécharge ComboFix : http://www.pc-xpress.ca/download/ComboFix.exe (par sUBs) sur ton Bureau.
Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
- Double clique combofix.exe :
- Tape sur la touche 1 (Yes) pour démarrer le scan.
- Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.
A+
:)
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
c'est bon cela donne ca:
ComboFix 08-03-01.3 - Aurélien 2008-03-02 15:42:42.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.494 [GMT 1:00]
Endroit: C:\Documents and Settings\Aurélien\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Aurélien\Application Data\addon.dat
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\dpvwar.dat
c:\windows\system32\dpvwar.exe
C:\WINDOWS\system32\dpvwar_nav.dat
C:\WINDOWS\system32\dpvwar_navps.dat
C:\WINDOWS\system32\hxuftlnuh.dat
C:\WINDOWS\system32\hxuftlnuh_nav.dat
C:\WINDOWS\system32\hxuftlnuh_navps.dat
C:\WINDOWS\system32\ktvuosne.dat
C:\WINDOWS\system32\ktvuosne_nav.dat
C:\WINDOWS\system32\ktvuosne_navps.dat
C:\WINDOWS\system32\vkqttdhnnb.dat
C:\WINDOWS\system32\vkqttdhnnb_nav.dat
C:\WINDOWS\system32\vkqttdhnnb_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
.
2008-03-02 00:29 . 2008-03-02 00:29 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-02 00:01 . 2008-03-02 11:17 <REP> d-------- C:\SDFix
2008-03-01 23:53 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 23:33 . 2008-03-01 23:33 <REP> d-------- C:\Program Files\Trend Micro
2008-03-01 17:57 . 2008-03-02 15:10 <REP> d-------- C:\Program Files\SpeedFan
2008-03-01 17:57 . 2008-03-01 17:57 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-02-28 23:16 . 2008-02-28 23:18 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-26 23:59 . 2008-02-27 00:03 <REP> d-------- C:\Program Files\End It All
2008-02-26 22:18 . 2008-02-26 22:18 <REP> d-------- C:\Program Files\MSXML 4.0
2008-02-18 15:43 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\EoRezo
2008-02-15 15:55 . 2007-07-31 12:02 621,568 --a------ C:\Program Files\TestDriveUnlimited-1.66A-Trn.exe
2008-02-15 15:19 . 2008-02-15 15:40 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-02-14 17:32 . 2008-02-17 19:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2008-02-10 11:56 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\Atari
2008-02-08 16:26 . 1998-08-27 05:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2008-02-08 16:26 . 1998-08-20 12:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2008-02-08 16:26 . 1998-09-02 09:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2008-02-08 16:26 . 1998-09-02 09:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2008-02-08 16:26 . 2006-03-24 20:00 4,639 --a------ C:\WINDOWS\system32\dllcache\mplayer2.exe
2008-02-08 16:25 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2008-02-08 16:25 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2008-02-08 16:25 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-02-08 16:25 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2008-02-08 16:25 . 2008-02-08 16:25 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2008-02-08 16:25 . 2008-02-08 16:25 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2008-02-06 19:44 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\MoviePod
2008-02-06 19:19 . 2008-02-26 22:20 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-02-06 19:15 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\Ripp-it_AM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 23:00 --------- d-----w C:\Program Files\Yahoo!
2008-03-01 22:59 --------- d-----w C:\Program Files\CCleaner
2008-02-28 21:42 --------- d-----w C:\Program Files\DivX
2008-02-26 21:22 --------- d-----w C:\Program Files\LimeWire
2008-02-26 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 21:19 --------- d-----w C:\Program Files\QuickTime
2008-02-26 21:19 --------- d-----w C:\Program Files\iTunes
2008-02-26 21:19 --------- d-----w C:\Program Files\iPod
2008-02-26 21:18 --------- d-----w C:\Program Files\WinAVI MP4 Converter
2008-02-26 21:18 --------- d-----w C:\Program Files\Navilog1
2008-02-26 21:18 --------- d-----w C:\Program Files\EA GAMES
2008-02-26 21:18 --------- d-----w C:\Program Files\Antipub
2008-02-26 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-02-26 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-26 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 21:14 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-15 21:52 --------- d-----w C:\Program Files\Windows Live
2008-01-05 11:57 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-05 11:57 253,952 ------w C:\WINDOWS\Setup1.exe
2007-07-31 11:15 5,360 ----a-w C:\Program Files\Test Drive Unlimited 1.66A Trainer.txt
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-24 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-07-28 07:04 110592]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 01:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 23:26 761945]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 17:09 987136]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:34 64512]
"SMSERIAL"="C:\WINDOWS\sm56hlpr.exe" [2006-03-21 07:54 544768]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"EoEngine"="C:\Program Files\EoRezo\EoEngine.exe" [2008-01-08 15:18 561152]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 03:43 69632 C:\WINDOWS\Alcmtr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-24 20:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\WINSOS\\winsos.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18943:TCP"= 18943:TCP:BitComet 18943 TCP
"18943:UDP"= 18943:UDP:BitComet 18943 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2006-07-11 08:30]
R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2006-03-24 20:00]
R3 SynMini;USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\SynMini.sys [2006-07-02 19:33]
R3 SynScan;USB2.0 1.3M WebCam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2006-06-29 19:40]
S3 iMSPCLOj;iMSPCLOj;C:\DOCUME~1\Aurélien\LOCALS~1\Temp\iMSPCLOj.sys []
S3 ipswuio;ipswuio;C:\WINDOWS\system32\DRIVERS\ipswuio.sys [2006-01-24 10:45]
S3 StMp3Rec;Pilote de périphérique de la restauration de lecteur;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2007-02-15 13:14]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-06-02 11:57]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-26 20:19:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\widupdate.exe
"2007-05-27 10:07:36 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\user32.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:13:55 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\widupdate.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:15:46 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\patcher.exe
"2007-05-27 09:21:02 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\dr.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\patcher.exe
"2008-03-01 18:00:05 C:\WINDOWS\Tasks\Nettoyage de disque.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 15:48:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-02 15:52:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-02 14:51:58
.
2008-02-13 22:34:57 --- E O F ---
ComboFix 08-03-01.3 - Aurélien 2008-03-02 15:42:42.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.494 [GMT 1:00]
Endroit: C:\Documents and Settings\Aurélien\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Aurélien\Application Data\addon.dat
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\dpvwar.dat
c:\windows\system32\dpvwar.exe
C:\WINDOWS\system32\dpvwar_nav.dat
C:\WINDOWS\system32\dpvwar_navps.dat
C:\WINDOWS\system32\hxuftlnuh.dat
C:\WINDOWS\system32\hxuftlnuh_nav.dat
C:\WINDOWS\system32\hxuftlnuh_navps.dat
C:\WINDOWS\system32\ktvuosne.dat
C:\WINDOWS\system32\ktvuosne_nav.dat
C:\WINDOWS\system32\ktvuosne_navps.dat
C:\WINDOWS\system32\vkqttdhnnb.dat
C:\WINDOWS\system32\vkqttdhnnb_nav.dat
C:\WINDOWS\system32\vkqttdhnnb_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
.
2008-03-02 00:29 . 2008-03-02 00:29 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-02 00:01 . 2008-03-02 11:17 <REP> d-------- C:\SDFix
2008-03-01 23:53 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 23:33 . 2008-03-01 23:33 <REP> d-------- C:\Program Files\Trend Micro
2008-03-01 17:57 . 2008-03-02 15:10 <REP> d-------- C:\Program Files\SpeedFan
2008-03-01 17:57 . 2008-03-01 17:57 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-02-28 23:16 . 2008-02-28 23:18 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-26 23:59 . 2008-02-27 00:03 <REP> d-------- C:\Program Files\End It All
2008-02-26 22:18 . 2008-02-26 22:18 <REP> d-------- C:\Program Files\MSXML 4.0
2008-02-18 15:43 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\EoRezo
2008-02-15 15:55 . 2007-07-31 12:02 621,568 --a------ C:\Program Files\TestDriveUnlimited-1.66A-Trn.exe
2008-02-15 15:19 . 2008-02-15 15:40 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-02-14 17:32 . 2008-02-17 19:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2008-02-10 11:56 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\Atari
2008-02-08 16:26 . 1998-08-27 05:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2008-02-08 16:26 . 1998-08-20 12:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2008-02-08 16:26 . 1998-09-02 09:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2008-02-08 16:26 . 1998-09-02 09:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2008-02-08 16:26 . 2006-03-24 20:00 4,639 --a------ C:\WINDOWS\system32\dllcache\mplayer2.exe
2008-02-08 16:25 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2008-02-08 16:25 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2008-02-08 16:25 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-02-08 16:25 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2008-02-08 16:25 . 2008-02-08 16:25 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2008-02-08 16:25 . 2008-02-08 16:25 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2008-02-06 19:44 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\MoviePod
2008-02-06 19:19 . 2008-02-26 22:20 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-02-06 19:15 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\Ripp-it_AM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 23:00 --------- d-----w C:\Program Files\Yahoo!
2008-03-01 22:59 --------- d-----w C:\Program Files\CCleaner
2008-02-28 21:42 --------- d-----w C:\Program Files\DivX
2008-02-26 21:22 --------- d-----w C:\Program Files\LimeWire
2008-02-26 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 21:19 --------- d-----w C:\Program Files\QuickTime
2008-02-26 21:19 --------- d-----w C:\Program Files\iTunes
2008-02-26 21:19 --------- d-----w C:\Program Files\iPod
2008-02-26 21:18 --------- d-----w C:\Program Files\WinAVI MP4 Converter
2008-02-26 21:18 --------- d-----w C:\Program Files\Navilog1
2008-02-26 21:18 --------- d-----w C:\Program Files\EA GAMES
2008-02-26 21:18 --------- d-----w C:\Program Files\Antipub
2008-02-26 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-02-26 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-26 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 21:14 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-15 21:52 --------- d-----w C:\Program Files\Windows Live
2008-01-05 11:57 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-05 11:57 253,952 ------w C:\WINDOWS\Setup1.exe
2007-07-31 11:15 5,360 ----a-w C:\Program Files\Test Drive Unlimited 1.66A Trainer.txt
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-24 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-07-28 07:04 110592]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 01:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 23:26 761945]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 17:09 987136]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:34 64512]
"SMSERIAL"="C:\WINDOWS\sm56hlpr.exe" [2006-03-21 07:54 544768]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"EoEngine"="C:\Program Files\EoRezo\EoEngine.exe" [2008-01-08 15:18 561152]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 03:43 69632 C:\WINDOWS\Alcmtr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-24 20:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\WINSOS\\winsos.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18943:TCP"= 18943:TCP:BitComet 18943 TCP
"18943:UDP"= 18943:UDP:BitComet 18943 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2006-07-11 08:30]
R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2006-03-24 20:00]
R3 SynMini;USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\SynMini.sys [2006-07-02 19:33]
R3 SynScan;USB2.0 1.3M WebCam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2006-06-29 19:40]
S3 iMSPCLOj;iMSPCLOj;C:\DOCUME~1\Aurélien\LOCALS~1\Temp\iMSPCLOj.sys []
S3 ipswuio;ipswuio;C:\WINDOWS\system32\DRIVERS\ipswuio.sys [2006-01-24 10:45]
S3 StMp3Rec;Pilote de périphérique de la restauration de lecteur;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2007-02-15 13:14]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-06-02 11:57]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-26 20:19:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\widupdate.exe
"2007-05-27 10:07:36 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\user32.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:13:55 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\widupdate.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:15:46 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\patcher.exe
"2007-05-27 09:21:02 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\dr.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\patcher.exe
"2008-03-01 18:00:05 C:\WINDOWS\Tasks\Nettoyage de disque.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 15:48:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-02 15:52:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-02 14:51:58
.
2008-02-13 22:34:57 --- E O F ---
Super !
On continue :
> Télécharge Lopxp (by Moe) : http://sosvirus.changelog.fr/Green_day/Lopxpsetup.exe
- Double clic sur Lopxpsetup.exe pour lancer l'installation
- Choisis l'option 1
- Patiente jusqu'à qu'on te demande d'appuyer sur une touche.
- Un rapport sera alors crée, copie/colle le sur le forum.
> Et reposte un nouveau rapport HiJAckT stp
A+
On continue :
> Télécharge Lopxp (by Moe) : http://sosvirus.changelog.fr/Green_day/Lopxpsetup.exe
- Double clic sur Lopxpsetup.exe pour lancer l'installation
- Choisis l'option 1
- Patiente jusqu'à qu'on te demande d'appuyer sur une touche.
- Un rapport sera alors crée, copie/colle le sur le forum.
> Et reposte un nouveau rapport HiJAckT stp
A+
Je crois que la chaleur n'est pas certifiée....
Speed fan n'est pas infaillible... et ce qu'il affiche est à mettre entre guillemets....(interprétation...)
Maintenant je suis sûr que ton PC est infecté....
Tu dois avoir des pubs genre CID dessus...non ?
A+
PS : je cherche d'autres logiciels d'analyse thermique et je t'envoie les liens...
+
Speed fan n'est pas infaillible... et ce qu'il affiche est à mettre entre guillemets....(interprétation...)
Maintenant je suis sûr que ton PC est infecté....
Tu dois avoir des pubs genre CID dessus...non ?
A+
PS : je cherche d'autres logiciels d'analyse thermique et je t'envoie les liens...
+
ComboFix 08-03-01.3 - Aurélien 2008-03-02 15:42:42.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.494 [GMT 1:00]
Endroit: C:\Documents and Settings\Aurélien\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Aurélien\Application Data\addon.dat
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\dpvwar.dat
c:\windows\system32\dpvwar.exe
C:\WINDOWS\system32\dpvwar_nav.dat
C:\WINDOWS\system32\dpvwar_navps.dat
C:\WINDOWS\system32\hxuftlnuh.dat
C:\WINDOWS\system32\hxuftlnuh_nav.dat
C:\WINDOWS\system32\hxuftlnuh_navps.dat
C:\WINDOWS\system32\ktvuosne.dat
C:\WINDOWS\system32\ktvuosne_nav.dat
C:\WINDOWS\system32\ktvuosne_navps.dat
C:\WINDOWS\system32\vkqttdhnnb.dat
C:\WINDOWS\system32\vkqttdhnnb_nav.dat
C:\WINDOWS\system32\vkqttdhnnb_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
.
2008-03-02 00:29 . 2008-03-02 00:29 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-02 00:01 . 2008-03-02 11:17 <REP> d-------- C:\SDFix
2008-03-01 23:53 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 23:33 . 2008-03-01 23:33 <REP> d-------- C:\Program Files\Trend Micro
2008-03-01 17:57 . 2008-03-02 15:10 <REP> d-------- C:\Program Files\SpeedFan
2008-03-01 17:57 . 2008-03-01 17:57 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-02-28 23:16 . 2008-02-28 23:18 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-26 23:59 . 2008-02-27 00:03 <REP> d-------- C:\Program Files\End It All
2008-02-26 22:18 . 2008-02-26 22:18 <REP> d-------- C:\Program Files\MSXML 4.0
2008-02-18 15:43 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\EoRezo
2008-02-15 15:55 . 2007-07-31 12:02 621,568 --a------ C:\Program Files\TestDriveUnlimited-1.66A-Trn.exe
2008-02-15 15:19 . 2008-02-15 15:40 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-02-14 17:32 . 2008-02-17 19:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2008-02-10 11:56 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\Atari
2008-02-08 16:26 . 1998-08-27 05:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2008-02-08 16:26 . 1998-08-20 12:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2008-02-08 16:26 . 1998-09-02 09:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2008-02-08 16:26 . 1998-09-02 09:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2008-02-08 16:26 . 2006-03-24 20:00 4,639 --a------ C:\WINDOWS\system32\dllcache\mplayer2.exe
2008-02-08 16:25 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2008-02-08 16:25 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2008-02-08 16:25 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-02-08 16:25 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2008-02-08 16:25 . 2008-02-08 16:25 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2008-02-08 16:25 . 2008-02-08 16:25 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2008-02-06 19:44 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\MoviePod
2008-02-06 19:19 . 2008-02-26 22:20 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-02-06 19:15 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\Ripp-it_AM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 23:00 --------- d-----w C:\Program Files\Yahoo!
2008-03-01 22:59 --------- d-----w C:\Program Files\CCleaner
2008-02-28 21:42 --------- d-----w C:\Program Files\DivX
2008-02-26 21:22 --------- d-----w C:\Program Files\LimeWire
2008-02-26 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 21:19 --------- d-----w C:\Program Files\QuickTime
2008-02-26 21:19 --------- d-----w C:\Program Files\iTunes
2008-02-26 21:19 --------- d-----w C:\Program Files\iPod
2008-02-26 21:18 --------- d-----w C:\Program Files\WinAVI MP4 Converter
2008-02-26 21:18 --------- d-----w C:\Program Files\Navilog1
2008-02-26 21:18 --------- d-----w C:\Program Files\EA GAMES
2008-02-26 21:18 --------- d-----w C:\Program Files\Antipub
2008-02-26 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-02-26 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-26 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 21:14 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-15 21:52 --------- d-----w C:\Program Files\Windows Live
2008-01-05 11:57 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-05 11:57 253,952 ------w C:\WINDOWS\Setup1.exe
2007-07-31 11:15 5,360 ----a-w C:\Program Files\Test Drive Unlimited 1.66A Trainer.txt
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-24 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-07-28 07:04 110592]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 01:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 23:26 761945]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 17:09 987136]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:34 64512]
"SMSERIAL"="C:\WINDOWS\sm56hlpr.exe" [2006-03-21 07:54 544768]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"EoEngine"="C:\Program Files\EoRezo\EoEngine.exe" [2008-01-08 15:18 561152]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 03:43 69632 C:\WINDOWS\Alcmtr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-24 20:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\WINSOS\\winsos.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18943:TCP"= 18943:TCP:BitComet 18943 TCP
"18943:UDP"= 18943:UDP:BitComet 18943 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2006-07-11 08:30]
R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2006-03-24 20:00]
R3 SynMini;USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\SynMini.sys [2006-07-02 19:33]
R3 SynScan;USB2.0 1.3M WebCam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2006-06-29 19:40]
S3 iMSPCLOj;iMSPCLOj;C:\DOCUME~1\Aurélien\LOCALS~1\Temp\iMSPCLOj.sys []
S3 ipswuio;ipswuio;C:\WINDOWS\system32\DRIVERS\ipswuio.sys [2006-01-24 10:45]
S3 StMp3Rec;Pilote de périphérique de la restauration de lecteur;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2007-02-15 13:14]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-06-02 11:57]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-26 20:19:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\widupdate.exe
"2007-05-27 10:07:36 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\user32.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:13:55 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\widupdate.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:15:46 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\patcher.exe
"2007-05-27 09:21:02 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\dr.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\patcher.exe
"2008-03-01 18:00:05 C:\WINDOWS\Tasks\Nettoyage de disque.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 15:48:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-02 15:52:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-02 14:51:58
.
2008-02-13 22:34:57 --- E O F ---
ComboFix 08-03-01.3 - Aurélien 2008-03-02 15:42:42.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.494 [GMT 1:00]
Endroit: C:\Documents and Settings\Aurélien\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Aurélien\Application Data\addon.dat
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\dpvwar.dat
c:\windows\system32\dpvwar.exe
C:\WINDOWS\system32\dpvwar_nav.dat
C:\WINDOWS\system32\dpvwar_navps.dat
C:\WINDOWS\system32\hxuftlnuh.dat
C:\WINDOWS\system32\hxuftlnuh_nav.dat
C:\WINDOWS\system32\hxuftlnuh_navps.dat
C:\WINDOWS\system32\ktvuosne.dat
C:\WINDOWS\system32\ktvuosne_nav.dat
C:\WINDOWS\system32\ktvuosne_navps.dat
C:\WINDOWS\system32\vkqttdhnnb.dat
C:\WINDOWS\system32\vkqttdhnnb_nav.dat
C:\WINDOWS\system32\vkqttdhnnb_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
.
2008-03-02 00:29 . 2008-03-02 00:29 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-02 00:01 . 2008-03-02 11:17 <REP> d-------- C:\SDFix
2008-03-01 23:53 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 23:33 . 2008-03-01 23:33 <REP> d-------- C:\Program Files\Trend Micro
2008-03-01 17:57 . 2008-03-02 15:10 <REP> d-------- C:\Program Files\SpeedFan
2008-03-01 17:57 . 2008-03-01 17:57 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-02-28 23:16 . 2008-02-28 23:18 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-26 23:59 . 2008-02-27 00:03 <REP> d-------- C:\Program Files\End It All
2008-02-26 22:18 . 2008-02-26 22:18 <REP> d-------- C:\Program Files\MSXML 4.0
2008-02-18 15:43 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\EoRezo
2008-02-15 15:55 . 2007-07-31 12:02 621,568 --a------ C:\Program Files\TestDriveUnlimited-1.66A-Trn.exe
2008-02-15 15:19 . 2008-02-15 15:40 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-02-14 17:32 . 2008-02-17 19:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2008-02-10 11:56 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\Atari
2008-02-08 16:26 . 1998-08-27 05:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2008-02-08 16:26 . 1998-08-20 12:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2008-02-08 16:26 . 1998-09-02 09:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2008-02-08 16:26 . 1998-09-02 09:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2008-02-08 16:26 . 2006-03-24 20:00 4,639 --a------ C:\WINDOWS\system32\dllcache\mplayer2.exe
2008-02-08 16:25 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2008-02-08 16:25 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2008-02-08 16:25 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-02-08 16:25 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2008-02-08 16:25 . 2008-02-08 16:25 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2008-02-08 16:25 . 2008-02-08 16:25 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2008-02-06 19:44 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\MoviePod
2008-02-06 19:19 . 2008-02-26 22:20 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-02-06 19:15 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\Ripp-it_AM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 23:00 --------- d-----w C:\Program Files\Yahoo!
2008-03-01 22:59 --------- d-----w C:\Program Files\CCleaner
2008-02-28 21:42 --------- d-----w C:\Program Files\DivX
2008-02-26 21:22 --------- d-----w C:\Program Files\LimeWire
2008-02-26 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 21:19 --------- d-----w C:\Program Files\QuickTime
2008-02-26 21:19 --------- d-----w C:\Program Files\iTunes
2008-02-26 21:19 --------- d-----w C:\Program Files\iPod
2008-02-26 21:18 --------- d-----w C:\Program Files\WinAVI MP4 Converter
2008-02-26 21:18 --------- d-----w C:\Program Files\Navilog1
2008-02-26 21:18 --------- d-----w C:\Program Files\EA GAMES
2008-02-26 21:18 --------- d-----w C:\Program Files\Antipub
2008-02-26 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-02-26 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-26 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 21:14 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-15 21:52 --------- d-----w C:\Program Files\Windows Live
2008-01-05 11:57 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-05 11:57 253,952 ------w C:\WINDOWS\Setup1.exe
2007-07-31 11:15 5,360 ----a-w C:\Program Files\Test Drive Unlimited 1.66A Trainer.txt
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-24 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-07-28 07:04 110592]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 01:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 23:26 761945]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 17:09 987136]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:34 64512]
"SMSERIAL"="C:\WINDOWS\sm56hlpr.exe" [2006-03-21 07:54 544768]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"EoEngine"="C:\Program Files\EoRezo\EoEngine.exe" [2008-01-08 15:18 561152]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 03:43 69632 C:\WINDOWS\Alcmtr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-24 20:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\WINSOS\\winsos.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18943:TCP"= 18943:TCP:BitComet 18943 TCP
"18943:UDP"= 18943:UDP:BitComet 18943 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2006-07-11 08:30]
R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2006-03-24 20:00]
R3 SynMini;USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\SynMini.sys [2006-07-02 19:33]
R3 SynScan;USB2.0 1.3M WebCam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2006-06-29 19:40]
S3 iMSPCLOj;iMSPCLOj;C:\DOCUME~1\Aurélien\LOCALS~1\Temp\iMSPCLOj.sys []
S3 ipswuio;ipswuio;C:\WINDOWS\system32\DRIVERS\ipswuio.sys [2006-01-24 10:45]
S3 StMp3Rec;Pilote de périphérique de la restauration de lecteur;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2007-02-15 13:14]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-06-02 11:57]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-26 20:19:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\widupdate.exe
"2007-05-27 10:07:36 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\user32.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:13:55 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\widupdate.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:15:46 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\patcher.exe
"2007-05-27 09:21:02 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\dr.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\patcher.exe
"2008-03-01 18:00:05 C:\WINDOWS\Tasks\Nettoyage de disque.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 15:48:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-02 15:52:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-02 14:51:58
.
2008-02-13 22:34:57 --- E O F ---
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.494 [GMT 1:00]
Endroit: C:\Documents and Settings\Aurélien\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Aurélien\Application Data\addon.dat
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\dpvwar.dat
c:\windows\system32\dpvwar.exe
C:\WINDOWS\system32\dpvwar_nav.dat
C:\WINDOWS\system32\dpvwar_navps.dat
C:\WINDOWS\system32\hxuftlnuh.dat
C:\WINDOWS\system32\hxuftlnuh_nav.dat
C:\WINDOWS\system32\hxuftlnuh_navps.dat
C:\WINDOWS\system32\ktvuosne.dat
C:\WINDOWS\system32\ktvuosne_nav.dat
C:\WINDOWS\system32\ktvuosne_navps.dat
C:\WINDOWS\system32\vkqttdhnnb.dat
C:\WINDOWS\system32\vkqttdhnnb_nav.dat
C:\WINDOWS\system32\vkqttdhnnb_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
.
2008-03-02 00:29 . 2008-03-02 00:29 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-02 00:01 . 2008-03-02 11:17 <REP> d-------- C:\SDFix
2008-03-01 23:53 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 23:33 . 2008-03-01 23:33 <REP> d-------- C:\Program Files\Trend Micro
2008-03-01 17:57 . 2008-03-02 15:10 <REP> d-------- C:\Program Files\SpeedFan
2008-03-01 17:57 . 2008-03-01 17:57 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-02-28 23:16 . 2008-02-28 23:18 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-26 23:59 . 2008-02-27 00:03 <REP> d-------- C:\Program Files\End It All
2008-02-26 22:18 . 2008-02-26 22:18 <REP> d-------- C:\Program Files\MSXML 4.0
2008-02-18 15:43 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\EoRezo
2008-02-15 15:55 . 2007-07-31 12:02 621,568 --a------ C:\Program Files\TestDriveUnlimited-1.66A-Trn.exe
2008-02-15 15:19 . 2008-02-15 15:40 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-02-14 17:32 . 2008-02-17 19:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2008-02-10 11:56 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\Atari
2008-02-08 16:26 . 1998-08-27 05:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2008-02-08 16:26 . 1998-08-20 12:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2008-02-08 16:26 . 1998-09-02 09:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2008-02-08 16:26 . 1998-09-02 09:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2008-02-08 16:26 . 2006-03-24 20:00 4,639 --a------ C:\WINDOWS\system32\dllcache\mplayer2.exe
2008-02-08 16:25 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2008-02-08 16:25 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2008-02-08 16:25 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-02-08 16:25 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2008-02-08 16:25 . 2008-02-08 16:25 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2008-02-08 16:25 . 2008-02-08 16:25 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2008-02-06 19:44 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\MoviePod
2008-02-06 19:19 . 2008-02-26 22:20 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-02-06 19:15 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\Ripp-it_AM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 23:00 --------- d-----w C:\Program Files\Yahoo!
2008-03-01 22:59 --------- d-----w C:\Program Files\CCleaner
2008-02-28 21:42 --------- d-----w C:\Program Files\DivX
2008-02-26 21:22 --------- d-----w C:\Program Files\LimeWire
2008-02-26 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 21:19 --------- d-----w C:\Program Files\QuickTime
2008-02-26 21:19 --------- d-----w C:\Program Files\iTunes
2008-02-26 21:19 --------- d-----w C:\Program Files\iPod
2008-02-26 21:18 --------- d-----w C:\Program Files\WinAVI MP4 Converter
2008-02-26 21:18 --------- d-----w C:\Program Files\Navilog1
2008-02-26 21:18 --------- d-----w C:\Program Files\EA GAMES
2008-02-26 21:18 --------- d-----w C:\Program Files\Antipub
2008-02-26 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-02-26 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-26 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 21:14 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-15 21:52 --------- d-----w C:\Program Files\Windows Live
2008-01-05 11:57 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-05 11:57 253,952 ------w C:\WINDOWS\Setup1.exe
2007-07-31 11:15 5,360 ----a-w C:\Program Files\Test Drive Unlimited 1.66A Trainer.txt
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-24 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-07-28 07:04 110592]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 01:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 23:26 761945]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 17:09 987136]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:34 64512]
"SMSERIAL"="C:\WINDOWS\sm56hlpr.exe" [2006-03-21 07:54 544768]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"EoEngine"="C:\Program Files\EoRezo\EoEngine.exe" [2008-01-08 15:18 561152]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 03:43 69632 C:\WINDOWS\Alcmtr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-24 20:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\WINSOS\\winsos.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18943:TCP"= 18943:TCP:BitComet 18943 TCP
"18943:UDP"= 18943:UDP:BitComet 18943 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2006-07-11 08:30]
R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2006-03-24 20:00]
R3 SynMini;USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\SynMini.sys [2006-07-02 19:33]
R3 SynScan;USB2.0 1.3M WebCam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2006-06-29 19:40]
S3 iMSPCLOj;iMSPCLOj;C:\DOCUME~1\Aurélien\LOCALS~1\Temp\iMSPCLOj.sys []
S3 ipswuio;ipswuio;C:\WINDOWS\system32\DRIVERS\ipswuio.sys [2006-01-24 10:45]
S3 StMp3Rec;Pilote de périphérique de la restauration de lecteur;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2007-02-15 13:14]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-06-02 11:57]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-26 20:19:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\widupdate.exe
"2007-05-27 10:07:36 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\user32.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:13:55 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\widupdate.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:15:46 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\patcher.exe
"2007-05-27 09:21:02 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\dr.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\patcher.exe
"2008-03-01 18:00:05 C:\WINDOWS\Tasks\Nettoyage de disque.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 15:48:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-02 15:52:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-02 14:51:58
.
2008-02-13 22:34:57 --- E O F ---
ComboFix 08-03-01.3 - Aurélien 2008-03-02 15:42:42.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.494 [GMT 1:00]
Endroit: C:\Documents and Settings\Aurélien\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Aurélien\Application Data\addon.dat
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\dpvwar.dat
c:\windows\system32\dpvwar.exe
C:\WINDOWS\system32\dpvwar_nav.dat
C:\WINDOWS\system32\dpvwar_navps.dat
C:\WINDOWS\system32\hxuftlnuh.dat
C:\WINDOWS\system32\hxuftlnuh_nav.dat
C:\WINDOWS\system32\hxuftlnuh_navps.dat
C:\WINDOWS\system32\ktvuosne.dat
C:\WINDOWS\system32\ktvuosne_nav.dat
C:\WINDOWS\system32\ktvuosne_navps.dat
C:\WINDOWS\system32\vkqttdhnnb.dat
C:\WINDOWS\system32\vkqttdhnnb_nav.dat
C:\WINDOWS\system32\vkqttdhnnb_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
.
2008-03-02 00:29 . 2008-03-02 00:29 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-02 00:01 . 2008-03-02 11:17 <REP> d-------- C:\SDFix
2008-03-01 23:53 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 23:33 . 2008-03-01 23:33 <REP> d-------- C:\Program Files\Trend Micro
2008-03-01 17:57 . 2008-03-02 15:10 <REP> d-------- C:\Program Files\SpeedFan
2008-03-01 17:57 . 2008-03-01 17:57 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-02-28 23:16 . 2008-02-28 23:18 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-26 23:59 . 2008-02-27 00:03 <REP> d-------- C:\Program Files\End It All
2008-02-26 22:18 . 2008-02-26 22:18 <REP> d-------- C:\Program Files\MSXML 4.0
2008-02-18 15:43 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\EoRezo
2008-02-15 15:55 . 2007-07-31 12:02 621,568 --a------ C:\Program Files\TestDriveUnlimited-1.66A-Trn.exe
2008-02-15 15:19 . 2008-02-15 15:40 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-02-14 17:32 . 2008-02-17 19:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Test Drive Unlimited
2008-02-10 11:56 . 2008-02-26 22:21 <REP> d-------- C:\Program Files\Atari
2008-02-08 16:26 . 1998-08-27 05:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2008-02-08 16:26 . 1998-08-20 12:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2008-02-08 16:26 . 1998-09-02 09:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2008-02-08 16:26 . 1998-09-02 09:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2008-02-08 16:26 . 2006-03-24 20:00 4,639 --a------ C:\WINDOWS\system32\dllcache\mplayer2.exe
2008-02-08 16:25 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2008-02-08 16:25 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2008-02-08 16:25 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-02-08 16:25 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2008-02-08 16:25 . 2008-02-08 16:25 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2008-02-08 16:25 . 2008-02-08 16:25 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2008-02-06 19:44 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\MoviePod
2008-02-06 19:19 . 2008-02-26 22:20 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-02-06 19:15 . 2008-02-26 22:12 <REP> d-------- C:\Program Files\Ripp-it_AM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 23:00 --------- d-----w C:\Program Files\Yahoo!
2008-03-01 22:59 --------- d-----w C:\Program Files\CCleaner
2008-02-28 21:42 --------- d-----w C:\Program Files\DivX
2008-02-26 21:22 --------- d-----w C:\Program Files\LimeWire
2008-02-26 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 21:19 --------- d-----w C:\Program Files\QuickTime
2008-02-26 21:19 --------- d-----w C:\Program Files\iTunes
2008-02-26 21:19 --------- d-----w C:\Program Files\iPod
2008-02-26 21:18 --------- d-----w C:\Program Files\WinAVI MP4 Converter
2008-02-26 21:18 --------- d-----w C:\Program Files\Navilog1
2008-02-26 21:18 --------- d-----w C:\Program Files\EA GAMES
2008-02-26 21:18 --------- d-----w C:\Program Files\Antipub
2008-02-26 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-02-26 21:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-26 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 21:14 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-15 21:52 --------- d-----w C:\Program Files\Windows Live
2008-01-05 11:57 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-05 11:57 253,952 ------w C:\WINDOWS\Setup1.exe
2007-07-31 11:15 5,360 ----a-w C:\Program Files\Test Drive Unlimited 1.66A Trainer.txt
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-24 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-07-28 07:04 110592]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 01:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 23:26 761945]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 17:09 987136]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:34 64512]
"SMSERIAL"="C:\WINDOWS\sm56hlpr.exe" [2006-03-21 07:54 544768]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 19:14 61440]
"EoEngine"="C:\Program Files\EoRezo\EoEngine.exe" [2008-01-08 15:18 561152]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 03:43 69632 C:\WINDOWS\Alcmtr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-24 20:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\WINSOS\\winsos.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18943:TCP"= 18943:TCP:BitComet 18943 TCP
"18943:UDP"= 18943:UDP:BitComet 18943 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2006-07-11 08:30]
R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2006-03-24 20:00]
R3 SynMini;USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\SynMini.sys [2006-07-02 19:33]
R3 SynScan;USB2.0 1.3M WebCam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2006-06-29 19:40]
S3 iMSPCLOj;iMSPCLOj;C:\DOCUME~1\Aurélien\LOCALS~1\Temp\iMSPCLOj.sys []
S3 ipswuio;ipswuio;C:\WINDOWS\system32\DRIVERS\ipswuio.sys [2006-01-24 10:45]
S3 StMp3Rec;Pilote de périphérique de la restauration de lecteur;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2007-02-15 13:14]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-06-02 11:57]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-26 20:19:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\widupdate.exe
"2007-05-27 10:07:36 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\user32.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:13:55 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\widupdate.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\patcher.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\user32.exe
"2007-05-27 10:15:46 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\user32.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\widupdate.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\patcher.exe
"2007-05-27 09:21:02 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\dr.exe
"2008-02-27 21:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\user32.exe
"2007-12-27 16:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\dr.exe
"2008-01-27 13:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\dr.exe
"2008-02-27 19:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\patcher.exe
"2008-03-01 18:00:05 C:\WINDOWS\Tasks\Nettoyage de disque.job"
- C:\WINDOWS\system32\cleanmgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 15:48:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-02 15:52:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-02 14:51:58
.
2008-02-13 22:34:57 --- E O F ---
Re,
Pas besoin de m'envoyer deux fois le même rapport !!!!
Laisse moi le temps de répondre....
As tu fais ceci ?
http://www.commentcamarche.net/forum/affich 5269195 pc tourne a 70 normal?page=2#35
regarde aussi là :
http://www.commentcamarche.net/forum/affich 5269195 pc tourne a 70 normal?page=2#38
A+
Pas besoin de m'envoyer deux fois le même rapport !!!!
Laisse moi le temps de répondre....
As tu fais ceci ?
http://www.commentcamarche.net/forum/affich 5269195 pc tourne a 70 normal?page=2#35
regarde aussi là :
http://www.commentcamarche.net/forum/affich 5269195 pc tourne a 70 normal?page=2#38
A+
voici hijackt
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:09:53, on 02/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://french.eazel.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - ?Õ - (no file)
O2 - BHO: (no name) - p?Õ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - ¨Õ - (no file)
O2 - BHO: (no name) - ð>Õ - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - https://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:09:53, on 02/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://french.eazel.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - ?Õ - (no file)
O2 - BHO: (no name) - p?Õ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - ¨Õ - (no file)
O2 - BHO: (no name) - ð>Õ - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - https://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
le forum veut pas le prendre c'est byzarre c'est la 4em fois que j'essai de le poster!Oui j'ai plein de pûb lorsque je surf sur le net
# Rapport Lopxp fait le 02/03/2008 à 16:07:57
# Exécuté dans : C:\Program Files\Lopxp
# Version 3.08 - Maj du 15/02/2008
========== Listing des dossiers Application Data
+- C:\Documents and Settings\Administrateur\Application Data
2007-07-10 à 12:02:07 - Apple Computer
2006-10-10 à 20:32:20 - ATI
2007-12-19 à 18:22:02 - Grisoft
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2007-12-19 à 22:02:15 - Microsoft
2007-12-19 à 18:47:59 - Mozilla
2006-10-10 à 20:08:34 - Symantec
+- C:\Documents and Settings\Administrateur\Local Settings\Application Data
2006-10-10 à 19:42:02 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2008-03-01 à 23:19:39 - Microsoft
2007-12-19 à 18:47:59 - Mozilla
+- C:\Documents and Settings\All Users\Application Data
2006-10-10 à 20:37:06 - Adobe
2007-07-29 à 19:06:49 - Apple
2007-02-24 à 01:15:38 - Apple Computer
2007-03-03 à 00:37:50 - Autodesk
2007-06-02 à 10:57:32 - BOONTY
2006-11-29 à 16:07:26 - CyberLink
2006-11-28 à 23:22:33 - DVD Shrink
2007-02-11 à 10:35:39 - Google
2007-09-09 à 20:36:47 - Grisoft
2006-10-10 à 20:27:42 - Intel
2007-07-10 à 11:59:30 - Lavasoft
2008-02-26 à 21:18:29 - live 64 math does
2008-02-26 à 21:20:23 - Microsoft
2008-02-26 à 21:15:19 - Spybot - Search & Destroy
2006-11-29 à 03:49:40 - Symantec
2008-02-28 à 22:18:10 - TEMP
2008-02-17 à 18:01:36 - Test Drive Unlimited
2006-11-28 à 22:47:28 - Windows Genuine Advantage
2007-07-13 à 19:19:25 - WindowsLiveInstaller
2007-12-03 à 17:54:52 - WLInstaller
+- C:\Documents and Settings\Aur‚lien\Application Data
2007-05-12 à 11:48:29 - Activision
2007-06-13 à 21:04:27 - Adobe
2007-02-27 à 10:33:03 - AdobeUM
2007-11-20 à 21:37:29 - Adssite Advanced Toolbar
2007-06-10 à 20:30:30 - Apple Computer
2006-11-29 à 04:00:19 - Asus
2006-10-10 à 20:32:20 - ATI
2006-12-24 à 17:07:05 - Autodesk
2006-12-25 à 09:35:36 - CyberLink
2008-02-26 à 21:20:23 - DivX
2007-10-21 à 17:55:04 - dvdcss
2008-03-02 à 14:48:57 - EoRezo
2006-11-28 à 23:48:31 - Google
2008-03-01 à 22:54:21 - Grisoft
2006-12-25 à 10:48:13 - Help
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2008-02-18 à 14:44:53 - ItsLabel
2008-02-29 à 14:26:51 - LimeWire
2006-10-10 à 20:31:36 - Macromedia
2008-02-26 à 21:18:28 - Maxthon2
2008-02-10 à 11:09:32 - Microsoft
2007-10-29 à 22:45:32 - Mozilla
2008-01-10 à 20:47:08 - MxBoost
2007-03-18 à 16:41:12 - Screenshot Sender
2007-08-24 à 17:47:16 - SecondLife
2007-05-27 à 10:05:49 - SecuROM
2007-01-06 à 22:11:08 - Sun
2006-10-10 à 20:08:34 - Symantec
2007-10-29 à 22:36:17 - Talkback
2007-04-25 à 21:25:52 - Toshiba
2008-02-28 à 22:16:10 - URSoft
2008-03-02 à 12:47:25 - uTorrent
2008-02-06 à 15:23:59 - vlc
2007-08-30 à 17:07:16 - WinRAR
2007-12-20 à 19:03:36 - Yahoo!
+- C:\Documents and Settings\Aur‚lien\Local Settings\Application Data
2007-02-03 à 17:28:18 - Adobe
2006-12-26 à 13:13:16 - Ahead
2007-09-21 à 15:34:25 - Apple
2007-04-06 à 19:07:33 - Apple Computer
2007-12-05 à 16:57:06 - ApplicationHistory
2007-08-31 à 22:14:32 - Ares
2006-10-10 à 20:32:20 - ATI
2007-06-24 à 12:36:31 - Codemasters
2006-11-28 à 23:48:04 - Google
2006-12-25 à 10:48:13 - Help
2006-12-25 à 09:57:36 - Identities
2008-02-18 à 14:44:56 - Microsoft
2007-10-29 à 22:45:32 - Mozilla
2007-10-26 à 15:22:41 - NFS Underground 2
2008-02-26 à 21:20:29 - Nullriver,_Inc
2007-10-09 à 23:51:04 - PCHealth
2006-11-29 à 16:21:45 - Toshiba
2006-12-30 à 21:59:57 - WMTools Downloaded Files
2008-02-18 à 19:31:57 - Yahoo
+- C:\Documents and Settings\christine\Application Data
2007-02-07 à 19:42:24 - Adobe
2007-10-29 à 08:56:17 - Apple Computer
2006-10-10 à 20:32:20 - ATI
2006-12-27 à 20:25:49 - Google
2007-10-10 à 10:57:33 - Grisoft
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2007-07-10 à 11:55:51 - Microsoft
2007-10-30 à 19:26:49 - Mozilla
2007-01-11 à 21:59:26 - Skype
2007-03-14 à 20:21:31 - Sun
2006-10-10 à 20:08:34 - Symantec
2007-01-31 à 19:41:23 - vlc
2007-12-21 à 17:07:25 - Yahoo!
+- C:\Documents and Settings\christine\Local Settings\Application Data
2007-02-07 à 19:42:29 - Adobe
2007-10-30 à 20:19:01 - Apple
2007-12-21 à 17:07:01 - Apple Computer
2008-02-06 à 13:45:33 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2006-12-23 à 19:30:12 - Google
2007-04-10 à 19:20:37 - Identities
2007-10-30 à 19:53:28 - Microsoft
2007-10-30 à 19:26:49 - Mozilla
2007-01-08 à 19:05:16 - Toshiba
+- C:\Documents and Settings\eMule_Secure\Application Data
2006-10-10 à 20:32:20 - ATI
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2006-10-10 à 19:29:02 - Microsoft
2006-10-10 à 20:08:34 - Symantec
+- C:\Documents and Settings\eMule_Secure\Local Settings\Application Data
2006-10-10 à 19:42:02 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2006-10-10 à 19:36:52 - Microsoft
+- C:\Documents and Settings\florent\Application Data
2007-05-17 à 10:25:26 - Activision
2007-02-16 à 15:34:42 - Adobe
2007-03-01 à 17:33:21 - Apple Computer
2006-10-10 à 20:32:20 - ATI
2006-12-24 à 13:51:16 - Google
2007-09-12 à 11:41:52 - Grisoft
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2007-04-16 à 12:30:08 - Microsoft
2007-12-19 à 12:54:55 - Mozilla
2007-01-24 à 21:20:09 - Skype
2006-10-10 à 20:08:34 - Symantec
2007-02-02 à 14:09:16 - vlc
# Exécuté dans : C:\Program Files\Lopxp
# Version 3.08 - Maj du 15/02/2008
========== Listing des dossiers Application Data
+- C:\Documents and Settings\Administrateur\Application Data
2007-07-10 à 12:02:07 - Apple Computer
2006-10-10 à 20:32:20 - ATI
2007-12-19 à 18:22:02 - Grisoft
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2007-12-19 à 22:02:15 - Microsoft
2007-12-19 à 18:47:59 - Mozilla
2006-10-10 à 20:08:34 - Symantec
+- C:\Documents and Settings\Administrateur\Local Settings\Application Data
2006-10-10 à 19:42:02 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2008-03-01 à 23:19:39 - Microsoft
2007-12-19 à 18:47:59 - Mozilla
+- C:\Documents and Settings\All Users\Application Data
2006-10-10 à 20:37:06 - Adobe
2007-07-29 à 19:06:49 - Apple
2007-02-24 à 01:15:38 - Apple Computer
2007-03-03 à 00:37:50 - Autodesk
2007-06-02 à 10:57:32 - BOONTY
2006-11-29 à 16:07:26 - CyberLink
2006-11-28 à 23:22:33 - DVD Shrink
2007-02-11 à 10:35:39 - Google
2007-09-09 à 20:36:47 - Grisoft
2006-10-10 à 20:27:42 - Intel
2007-07-10 à 11:59:30 - Lavasoft
2008-02-26 à 21:18:29 - live 64 math does
2008-02-26 à 21:20:23 - Microsoft
2008-02-26 à 21:15:19 - Spybot - Search & Destroy
2006-11-29 à 03:49:40 - Symantec
2008-02-28 à 22:18:10 - TEMP
2008-02-17 à 18:01:36 - Test Drive Unlimited
2006-11-28 à 22:47:28 - Windows Genuine Advantage
2007-07-13 à 19:19:25 - WindowsLiveInstaller
2007-12-03 à 17:54:52 - WLInstaller
+- C:\Documents and Settings\Aur‚lien\Application Data
2007-05-12 à 11:48:29 - Activision
2007-06-13 à 21:04:27 - Adobe
2007-02-27 à 10:33:03 - AdobeUM
2007-11-20 à 21:37:29 - Adssite Advanced Toolbar
2007-06-10 à 20:30:30 - Apple Computer
2006-11-29 à 04:00:19 - Asus
2006-10-10 à 20:32:20 - ATI
2006-12-24 à 17:07:05 - Autodesk
2006-12-25 à 09:35:36 - CyberLink
2008-02-26 à 21:20:23 - DivX
2007-10-21 à 17:55:04 - dvdcss
2008-03-02 à 14:48:57 - EoRezo
2006-11-28 à 23:48:31 - Google
2008-03-01 à 22:54:21 - Grisoft
2006-12-25 à 10:48:13 - Help
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2008-02-18 à 14:44:53 - ItsLabel
2008-02-29 à 14:26:51 - LimeWire
2006-10-10 à 20:31:36 - Macromedia
2008-02-26 à 21:18:28 - Maxthon2
2008-02-10 à 11:09:32 - Microsoft
2007-10-29 à 22:45:32 - Mozilla
2008-01-10 à 20:47:08 - MxBoost
2007-03-18 à 16:41:12 - Screenshot Sender
2007-08-24 à 17:47:16 - SecondLife
2007-05-27 à 10:05:49 - SecuROM
2007-01-06 à 22:11:08 - Sun
2006-10-10 à 20:08:34 - Symantec
2007-10-29 à 22:36:17 - Talkback
2007-04-25 à 21:25:52 - Toshiba
2008-02-28 à 22:16:10 - URSoft
2008-03-02 à 12:47:25 - uTorrent
2008-02-06 à 15:23:59 - vlc
2007-08-30 à 17:07:16 - WinRAR
2007-12-20 à 19:03:36 - Yahoo!
+- C:\Documents and Settings\Aur‚lien\Local Settings\Application Data
2007-02-03 à 17:28:18 - Adobe
2006-12-26 à 13:13:16 - Ahead
2007-09-21 à 15:34:25 - Apple
2007-04-06 à 19:07:33 - Apple Computer
2007-12-05 à 16:57:06 - ApplicationHistory
2007-08-31 à 22:14:32 - Ares
2006-10-10 à 20:32:20 - ATI
2007-06-24 à 12:36:31 - Codemasters
2006-11-28 à 23:48:04 - Google
2006-12-25 à 10:48:13 - Help
2006-12-25 à 09:57:36 - Identities
2008-02-18 à 14:44:56 - Microsoft
2007-10-29 à 22:45:32 - Mozilla
2007-10-26 à 15:22:41 - NFS Underground 2
2008-02-26 à 21:20:29 - Nullriver,_Inc
2007-10-09 à 23:51:04 - PCHealth
2006-11-29 à 16:21:45 - Toshiba
2006-12-30 à 21:59:57 - WMTools Downloaded Files
2008-02-18 à 19:31:57 - Yahoo
+- C:\Documents and Settings\christine\Application Data
2007-02-07 à 19:42:24 - Adobe
2007-10-29 à 08:56:17 - Apple Computer
2006-10-10 à 20:32:20 - ATI
2006-12-27 à 20:25:49 - Google
2007-10-10 à 10:57:33 - Grisoft
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2007-07-10 à 11:55:51 - Microsoft
2007-10-30 à 19:26:49 - Mozilla
2007-01-11 à 21:59:26 - Skype
2007-03-14 à 20:21:31 - Sun
2006-10-10 à 20:08:34 - Symantec
2007-01-31 à 19:41:23 - vlc
2007-12-21 à 17:07:25 - Yahoo!
+- C:\Documents and Settings\christine\Local Settings\Application Data
2007-02-07 à 19:42:29 - Adobe
2007-10-30 à 20:19:01 - Apple
2007-12-21 à 17:07:01 - Apple Computer
2008-02-06 à 13:45:33 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2006-12-23 à 19:30:12 - Google
2007-04-10 à 19:20:37 - Identities
2007-10-30 à 19:53:28 - Microsoft
2007-10-30 à 19:26:49 - Mozilla
2007-01-08 à 19:05:16 - Toshiba
+- C:\Documents and Settings\eMule_Secure\Application Data
2006-10-10 à 20:32:20 - ATI
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2006-10-10 à 19:29:02 - Microsoft
2006-10-10 à 20:08:34 - Symantec
+- C:\Documents and Settings\eMule_Secure\Local Settings\Application Data
2006-10-10 à 19:42:02 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2006-10-10 à 19:36:52 - Microsoft
+- C:\Documents and Settings\florent\Application Data
2007-05-17 à 10:25:26 - Activision
2007-02-16 à 15:34:42 - Adobe
2007-03-01 à 17:33:21 - Apple Computer
2006-10-10 à 20:32:20 - ATI
2006-12-24 à 13:51:16 - Google
2007-09-12 à 11:41:52 - Grisoft
2006-10-10 à 19:37:12 - Identities
2006-10-10 à 20:28:04 - Intel
2006-10-10 à 20:31:36 - Macromedia
2007-04-16 à 12:30:08 - Microsoft
2007-12-19 à 12:54:55 - Mozilla
2007-01-24 à 21:20:09 - Skype
2006-10-10 à 20:08:34 - Symantec
2007-02-02 à 14:09:16 - vlc
+- C:\Documents and Settings\florent\Local Settings\Application Data
2007-02-16 à 15:34:45 - Adobe
2007-12-19 à 12:52:11 - Apple Computer
2008-02-18 à 10:30:12 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2006-12-24 à 13:51:16 - Google
2007-08-01 à 01:23:34 - Identities
2007-12-02 à 18:37:49 - Microsoft
2007-12-19 à 12:54:55 - Mozilla
2007-10-24 à 12:23:21 - NFS Underground 2
2007-02-08 à 11:25:44 - PCHealth
2006-12-27 à 08:09:18 - Toshiba
========== Listing du dossier Program Files
+- C:\Program Files
2007-12-22 à 18:30:46 - 3wPlayer
2007-09-09 à 18:45:35 - 7-Zip
2007-11-23 à 14:02:27 - Adobe
2006-10-10 à 20:03:36 - Ahead
2006-11-29 à 03:58:13 - Alwil Software
2008-02-26 à 21:18:56 - Antipub
2007-09-21 à 15:34:30 - Apple Software Update
2007-05-30 à 15:57:06 - Apple Software Update(2)
2007-08-30 à 22:17:14 - Ares
2007-03-18 à 09:43:15 - Aspyr Media, Inc
2007-10-28 à 21:32:10 - ASUS
2007-05-25 à 22:58:07 - ASUSTeK
2008-02-26 à 21:21:11 - Atari
2006-10-10 à 20:15:54 - ATI Technologies
2008-02-26 à 21:20:28 - AviSynth 2.5
2007-06-24 à 17:20:10 - AVSMedia
2007-09-09 à 18:45:35 - BitComet
2007-06-02 à 10:57:10 - Boonty
2007-10-13 à 11:24:59 - BoontyGames
2008-03-01 à 22:59:55 - CCleaner
2007-11-03 à 09:05:28 - cdv Software Entertainment USA
2007-09-10 à 01:02:39 - DAEMON Tools
2006-12-23 à 23:11:24 - directx
2008-02-28 à 21:42:20 - DivX
2007-11-21 à 18:59:57 - DomPlayer
2008-02-26 à 21:18:44 - EA GAMES
2007-11-21 à 20:41:54 - Electronic Arts
2007-10-26 à 22:08:29 - eMule
2008-02-26 à 23:03:23 - End It All
2008-02-26 à 21:21:53 - EoRezo
2008-01-15 à 21:47:54 - Fichiers communs
2007-10-28 à 21:33:35 - fond-ecran-wallpaper
2007-03-17 à 17:50:21 - Fx Audio Conveter
2007-02-11 à 10:35:40 - Google
2007-12-19 à 18:00:28 - Grisoft
2008-02-26 à 21:20:30 - InstallShield Installation Information
2006-10-10 à 19:58:06 - Intel
2008-02-26 à 21:08:56 - Internet Explorer
2008-02-26 à 21:19:50 - iPod
2007-05-19 à 16:09:24 - iPod(2)
2007-07-13 à 19:19:04 - iPod(3)
2007-12-15 à 23:11:56 - IrfanView
2008-02-26 à 21:19:50 - iTunes
2007-05-19 à 16:09:24 - iTunes(2)
2007-07-13 à 19:19:04 - iTunes(3)
2007-12-15 à 23:34:11 - Java
2006-11-28 à 23:28:18 - K-Lite Codec Pack
2007-07-13 à 19:17:16 - Lavasoft(2)
2008-02-26 à 21:22:32 - LimeWire
2008-03-02 à 15:08:22 - Lopxp
2007-12-28 à 13:00:18 - Meaya
2007-07-01 à 08:10:20 - Messenger
2007-12-23 à 17:07:03 - Messenger Plus! Live
2007-07-13 à 19:34:38 - Microsoft CAPICOM 2.1.0.2
2006-10-10 à 19:37:22 - microsoft frontpage
2006-12-04 à 20:02:34 - Microsoft Office
2006-12-04 à 20:03:02 - Microsoft Visual Studio
2006-10-10 à 19:33:18 - Movie Maker
2008-02-26 à 21:12:01 - MoviePod
2008-03-02 à 14:54:24 - Mozilla Firefox
2007-10-29 à 22:44:48 - mozilla.org
2006-10-10 à 19:32:56 - MSN
2006-10-10 à 19:33:04 - MSN Gaming Zone
2008-02-26 à 21:18:35 - MSXML 4.0
2007-03-17 à 18:01:10 - MyMPxPlayer.org
2008-02-26 à 21:18:28 - Navilog1
2007-07-21 à 17:16:03 - NetMeeting
2006-10-10 à 19:33:40 - Online Services
2007-06-20 à 20:41:50 - Outlook Express
2007-12-22 à 18:44:38 - Panicware
2006-11-28 à 23:27:05 - PDFCreator
2006-10-10 à 20:30:28 - PowerForPhone
2007-11-16 à 19:16:20 - PowerISO
2008-02-26 à 21:19:42 - QuickTime
2007-05-19 à 16:09:40 - QuickTime(2)
2006-10-10 à 20:22:24 - Realtek
2008-02-26 à 21:12:02 - Ripp-it_AM
2007-12-19 à 21:23:39 - RogueRemover FREE
2006-10-10 à 19:35:30 - Services en ligne
2007-06-24 à 18:40:54 - Sony Ericsson
2008-03-02 à 14:10:14 - SpeedFan
2008-02-26 à 21:15:19 - Spybot - Search & Destroy
2006-10-10 à 20:24:16 - Synaptics
2007-09-23 à 09:55:54 - TmSunrise
2007-02-11 à 10:23:34 - ToniArts
2006-10-10 à 20:34:24 - Toshiba
2008-03-01 à 22:33:51 - Trend Micro
2006-10-10 à 20:06:44 - Uninstall Information
2007-11-16 à 20:51:39 - uTorrent
2007-11-24 à 22:14:30 - Veoh Networks
2007-01-04 à 15:36:29 - VideoLAN
2007-08-23 à 18:08:27 - Winamp
2008-02-26 à 21:18:38 - WinAVI MP4 Converter
2008-01-15 à 21:52:21 - Windows Live
2007-06-20 à 20:32:08 - Windows Media Connect 2
2008-02-26 à 21:11:54 - Windows Media Player
2006-10-10 à 19:32:56 - Windows NT
2006-10-10 à 19:33:24 - Windows Plus
2006-10-10 à 19:35:34 - WindowsUpdate
2007-09-11 à 18:35:50 - WinRAR
2007-12-15 à 22:27:06 - Winsos
2006-10-10 à 20:25:20 - Wireless Console 2
2006-10-10 à 19:37:22 - xerox
2008-03-01 à 23:00:01 - Yahoo!
2007-05-13 à 13:59:38 - YDi
2007-02-16 à 15:34:45 - Adobe
2007-12-19 à 12:52:11 - Apple Computer
2008-02-18 à 10:30:12 - ApplicationHistory
2006-10-10 à 20:32:20 - ATI
2006-12-24 à 13:51:16 - Google
2007-08-01 à 01:23:34 - Identities
2007-12-02 à 18:37:49 - Microsoft
2007-12-19 à 12:54:55 - Mozilla
2007-10-24 à 12:23:21 - NFS Underground 2
2007-02-08 à 11:25:44 - PCHealth
2006-12-27 à 08:09:18 - Toshiba
========== Listing du dossier Program Files
+- C:\Program Files
2007-12-22 à 18:30:46 - 3wPlayer
2007-09-09 à 18:45:35 - 7-Zip
2007-11-23 à 14:02:27 - Adobe
2006-10-10 à 20:03:36 - Ahead
2006-11-29 à 03:58:13 - Alwil Software
2008-02-26 à 21:18:56 - Antipub
2007-09-21 à 15:34:30 - Apple Software Update
2007-05-30 à 15:57:06 - Apple Software Update(2)
2007-08-30 à 22:17:14 - Ares
2007-03-18 à 09:43:15 - Aspyr Media, Inc
2007-10-28 à 21:32:10 - ASUS
2007-05-25 à 22:58:07 - ASUSTeK
2008-02-26 à 21:21:11 - Atari
2006-10-10 à 20:15:54 - ATI Technologies
2008-02-26 à 21:20:28 - AviSynth 2.5
2007-06-24 à 17:20:10 - AVSMedia
2007-09-09 à 18:45:35 - BitComet
2007-06-02 à 10:57:10 - Boonty
2007-10-13 à 11:24:59 - BoontyGames
2008-03-01 à 22:59:55 - CCleaner
2007-11-03 à 09:05:28 - cdv Software Entertainment USA
2007-09-10 à 01:02:39 - DAEMON Tools
2006-12-23 à 23:11:24 - directx
2008-02-28 à 21:42:20 - DivX
2007-11-21 à 18:59:57 - DomPlayer
2008-02-26 à 21:18:44 - EA GAMES
2007-11-21 à 20:41:54 - Electronic Arts
2007-10-26 à 22:08:29 - eMule
2008-02-26 à 23:03:23 - End It All
2008-02-26 à 21:21:53 - EoRezo
2008-01-15 à 21:47:54 - Fichiers communs
2007-10-28 à 21:33:35 - fond-ecran-wallpaper
2007-03-17 à 17:50:21 - Fx Audio Conveter
2007-02-11 à 10:35:40 - Google
2007-12-19 à 18:00:28 - Grisoft
2008-02-26 à 21:20:30 - InstallShield Installation Information
2006-10-10 à 19:58:06 - Intel
2008-02-26 à 21:08:56 - Internet Explorer
2008-02-26 à 21:19:50 - iPod
2007-05-19 à 16:09:24 - iPod(2)
2007-07-13 à 19:19:04 - iPod(3)
2007-12-15 à 23:11:56 - IrfanView
2008-02-26 à 21:19:50 - iTunes
2007-05-19 à 16:09:24 - iTunes(2)
2007-07-13 à 19:19:04 - iTunes(3)
2007-12-15 à 23:34:11 - Java
2006-11-28 à 23:28:18 - K-Lite Codec Pack
2007-07-13 à 19:17:16 - Lavasoft(2)
2008-02-26 à 21:22:32 - LimeWire
2008-03-02 à 15:08:22 - Lopxp
2007-12-28 à 13:00:18 - Meaya
2007-07-01 à 08:10:20 - Messenger
2007-12-23 à 17:07:03 - Messenger Plus! Live
2007-07-13 à 19:34:38 - Microsoft CAPICOM 2.1.0.2
2006-10-10 à 19:37:22 - microsoft frontpage
2006-12-04 à 20:02:34 - Microsoft Office
2006-12-04 à 20:03:02 - Microsoft Visual Studio
2006-10-10 à 19:33:18 - Movie Maker
2008-02-26 à 21:12:01 - MoviePod
2008-03-02 à 14:54:24 - Mozilla Firefox
2007-10-29 à 22:44:48 - mozilla.org
2006-10-10 à 19:32:56 - MSN
2006-10-10 à 19:33:04 - MSN Gaming Zone
2008-02-26 à 21:18:35 - MSXML 4.0
2007-03-17 à 18:01:10 - MyMPxPlayer.org
2008-02-26 à 21:18:28 - Navilog1
2007-07-21 à 17:16:03 - NetMeeting
2006-10-10 à 19:33:40 - Online Services
2007-06-20 à 20:41:50 - Outlook Express
2007-12-22 à 18:44:38 - Panicware
2006-11-28 à 23:27:05 - PDFCreator
2006-10-10 à 20:30:28 - PowerForPhone
2007-11-16 à 19:16:20 - PowerISO
2008-02-26 à 21:19:42 - QuickTime
2007-05-19 à 16:09:40 - QuickTime(2)
2006-10-10 à 20:22:24 - Realtek
2008-02-26 à 21:12:02 - Ripp-it_AM
2007-12-19 à 21:23:39 - RogueRemover FREE
2006-10-10 à 19:35:30 - Services en ligne
2007-06-24 à 18:40:54 - Sony Ericsson
2008-03-02 à 14:10:14 - SpeedFan
2008-02-26 à 21:15:19 - Spybot - Search & Destroy
2006-10-10 à 20:24:16 - Synaptics
2007-09-23 à 09:55:54 - TmSunrise
2007-02-11 à 10:23:34 - ToniArts
2006-10-10 à 20:34:24 - Toshiba
2008-03-01 à 22:33:51 - Trend Micro
2006-10-10 à 20:06:44 - Uninstall Information
2007-11-16 à 20:51:39 - uTorrent
2007-11-24 à 22:14:30 - Veoh Networks
2007-01-04 à 15:36:29 - VideoLAN
2007-08-23 à 18:08:27 - Winamp
2008-02-26 à 21:18:38 - WinAVI MP4 Converter
2008-01-15 à 21:52:21 - Windows Live
2007-06-20 à 20:32:08 - Windows Media Connect 2
2008-02-26 à 21:11:54 - Windows Media Player
2006-10-10 à 19:32:56 - Windows NT
2006-10-10 à 19:33:24 - Windows Plus
2006-10-10 à 19:35:34 - WindowsUpdate
2007-09-11 à 18:35:50 - WinRAR
2007-12-15 à 22:27:06 - Winsos
2006-10-10 à 20:25:20 - Wireless Console 2
2006-10-10 à 19:37:22 - xerox
2008-03-01 à 23:00:01 - Yahoo!
2007-05-13 à 13:59:38 - YDi
========== Tâches planifiées
AppleSoftwareUpdate.job: C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
At1.job: C:\WINDOWS\widupdate.exe
At10.job: C:\WINDOWS\user32.exe
At11.job: C:\WINDOWS\widupdate.exe
At12.job: C:\WINDOWS\user32.exe
At13.job: C:\WINDOWS\user32.exe
At14.job: C:\WINDOWS\dr.exe
At15.job: C:\WINDOWS\patcher.exe
At16.job: C:\WINDOWS\user32.exe
At17.job: C:\WINDOWS\dr.exe
At18.job: C:\WINDOWS\widupdate.exe
At19.job: C:\WINDOWS\dr.exe
At2.job: C:\WINDOWS\patcher.exe
At20.job: C:\WINDOWS\user32.exe
At21.job: C:\WINDOWS\user32.exe
At22.job: C:\WINDOWS\dr.exe
At23.job: C:\WINDOWS\widupdate.exe
At24.job: C:\WINDOWS\patcher.exe
At3.job: C:\WINDOWS\user32.exe
At4.job: C:\WINDOWS\dr.exe
At5.job: C:\WINDOWS\dr.exe
At6.job: C:\WINDOWS\user32.exe
At7.job: C:\WINDOWS\dr.exe
At8.job: C:\WINDOWS\dr.exe
At9.job: C:\WINDOWS\patcher.exe
Nettoyage de disque.job: C:\WINDOWS\system32\cleanmgr.exe
AppleSoftwareUpdate.job: C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
At1.job: C:\WINDOWS\widupdate.exe
At10.job: C:\WINDOWS\user32.exe
At11.job: C:\WINDOWS\widupdate.exe
At12.job: C:\WINDOWS\user32.exe
At13.job: C:\WINDOWS\user32.exe
At14.job: C:\WINDOWS\dr.exe
At15.job: C:\WINDOWS\patcher.exe
At16.job: C:\WINDOWS\user32.exe
At17.job: C:\WINDOWS\dr.exe
At18.job: C:\WINDOWS\widupdate.exe
At19.job: C:\WINDOWS\dr.exe
At2.job: C:\WINDOWS\patcher.exe
At20.job: C:\WINDOWS\user32.exe
At21.job: C:\WINDOWS\user32.exe
At22.job: C:\WINDOWS\dr.exe
At23.job: C:\WINDOWS\widupdate.exe
At24.job: C:\WINDOWS\patcher.exe
At3.job: C:\WINDOWS\user32.exe
At4.job: C:\WINDOWS\dr.exe
At5.job: C:\WINDOWS\dr.exe
At6.job: C:\WINDOWS\user32.exe
At7.job: C:\WINDOWS\dr.exe
At8.job: C:\WINDOWS\dr.exe
At9.job: C:\WINDOWS\patcher.exe
Nettoyage de disque.job: C:\WINDOWS\system32\cleanmgr.exe
....sur ton PC...lol
As tu fais les manip ?
A+