Unité bloquée à 100 %
PHIL6770
-
phil6770 Messages postés 21 Date d'inscription Statut Membre Dernière intervention -
phil6770 Messages postés 21 Date d'inscription Statut Membre Dernière intervention -
Bonjour,
JE suis régulièrement bloqué,mon pc indiquant etre utilisé à 100% lorsque je regarde le gestionnaire de taches.J'ai lancé une analyse minutieuse avec avast ainsi qu'avec spybot et rien.Je navigue avec mozilla ou explorer ce qui ne résous pas le problème.mon ordi est un packard sous xp 2 amd athlon 64 3400 + 2.19 GHZ 2 G DE RAM . voici un scan que je viens de faire .J'ajoute que je ne suis pas un pro!
merci d'avance aux personnes qui se pencheront sur mon cas.
salutations!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:22:59, on 14/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Glary Utilities\memdefrag.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - (no file)
O2 - BHO: (no name) - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://secam.mine.nu:81/VatDec.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1192391109734
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://secam.mine.nu:8002/activex/AMC.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
JE suis régulièrement bloqué,mon pc indiquant etre utilisé à 100% lorsque je regarde le gestionnaire de taches.J'ai lancé une analyse minutieuse avec avast ainsi qu'avec spybot et rien.Je navigue avec mozilla ou explorer ce qui ne résous pas le problème.mon ordi est un packard sous xp 2 amd athlon 64 3400 + 2.19 GHZ 2 G DE RAM . voici un scan que je viens de faire .J'ajoute que je ne suis pas un pro!
merci d'avance aux personnes qui se pencheront sur mon cas.
salutations!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:22:59, on 14/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Glary Utilities\memdefrag.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - (no file)
O2 - BHO: (no name) - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://secam.mine.nu:81/VatDec.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1192391109734
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://secam.mine.nu:8002/activex/AMC.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
A voir également:
- Unité bloquée à 100 %
- Boite gmail bloquée - Guide
- Souris ordinateur bloquée - Guide
- 100 mb en mo ✓ - Forum Matériel & Système
- 100 mo en go ✓ - Forum Windows
- Formate pour taxer client 100€ - Forum Vos droits sur internet
27 réponses
slt,
scan avec
MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
____
Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Sauvegarde le sur ton bureau et pas ailleurs !
Aide à l’utilisation de combofix ici: https://bibou0007.forumpro.fr/login?redirect=%2Ft121-topic
Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
scan avec
MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
____
Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Sauvegarde le sur ton bureau et pas ailleurs !
Aide à l’utilisation de combofix ici: https://bibou0007.forumpro.fr/login?redirect=%2Ft121-topic
Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
j'ai réussi à faire un scan avec combo qui a redemmarer l'ordi mais pas de trace du rapport alors que je n'ai rien touché ! plus d'icone d'avast non plus
e rapport combofix
ComboFix 08-05-12.1 - MAMOUR 2008-05-14 21:56:57.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1527 [GMT 2:00]
Endroit: C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_004804_.tmp.dll
C:\WINDOWS\system32\_004805_.tmp.dll
C:\WINDOWS\system32\_004806_.tmp.dll
C:\WINDOWS\system32\_004807_.tmp.dll
C:\WINDOWS\system32\_004814_.tmp.dll
C:\WINDOWS\system32\_004816_.tmp.dll
C:\WINDOWS\system32\_004817_.tmp.dll
C:\WINDOWS\system32\_004818_.tmp.dll
C:\WINDOWS\system32\_004819_.tmp.dll
C:\WINDOWS\system32\_004820_.tmp.dll
C:\WINDOWS\system32\_004821_.tmp.dll
C:\WINDOWS\system32\_004822_.tmp.dll
C:\WINDOWS\system32\_004823_.tmp.dll
C:\WINDOWS\system32\_004824_.tmp.dll
C:\WINDOWS\system32\_004825_.tmp.dll
C:\WINDOWS\system32\_004826_.tmp.dll
C:\WINDOWS\system32\_004827_.tmp.dll
C:\WINDOWS\system32\_004828_.tmp.dll
C:\WINDOWS\system32\_004829_.tmp.dll
C:\WINDOWS\system32\_004830_.tmp.dll
C:\WINDOWS\system32\_004831_.tmp.dll
C:\WINDOWS\system32\_004832_.tmp.dll
C:\WINDOWS\system32\_004833_.tmp.dll
C:\WINDOWS\system32\_004834_.tmp.dll
C:\WINDOWS\system32\_004835_.tmp.dll
C:\WINDOWS\system32\_004836_.tmp.dll
C:\WINDOWS\system32\_004837_.tmp.dll
C:\WINDOWS\system32\_004838_.tmp.dll
C:\WINDOWS\system32\_004839_.tmp.dll
C:\WINDOWS\system32\_004840_.tmp.dll
C:\WINDOWS\system32\_004841_.tmp.dll
C:\WINDOWS\system32\_004842_.tmp.dll
C:\WINDOWS\system32\_004843_.tmp.dll
C:\WINDOWS\system32\_004844_.tmp.dll
C:\WINDOWS\system32\_004845_.tmp.dll
C:\WINDOWS\system32\_004846_.tmp.dll
C:\WINDOWS\system32\_004847_.tmp.dll
C:\WINDOWS\system32\_004849_.tmp.dll
C:\WINDOWS\system32\_004850_.tmp.dll
C:\WINDOWS\system32\_004851_.tmp.dll
C:\WINDOWS\system32\_004852_.tmp.dll
C:\WINDOWS\system32\_004853_.tmp.dll
C:\WINDOWS\system32\_004854_.tmp.dll
C:\WINDOWS\system32\_004855_.tmp.dll
C:\WINDOWS\system32\_004856_.tmp.dll
C:\WINDOWS\system32\_004857_.tmp.dll
C:\WINDOWS\system32\_004858_.tmp.dll
C:\WINDOWS\system32\_004859_.tmp.dll
C:\WINDOWS\system32\_004860_.tmp.dll
C:\WINDOWS\system32\_004861_.tmp.dll
C:\WINDOWS\system32\_004862_.tmp.dll
C:\WINDOWS\system32\_004863_.tmp.dll
C:\WINDOWS\system32\_004864_.tmp.dll
C:\WINDOWS\system32\_004865_.tmp.dll
C:\WINDOWS\system32\_004866_.tmp.dll
C:\WINDOWS\system32\_004867_.tmp.dll
C:\WINDOWS\system32\_004868_.tmp.dll
C:\WINDOWS\system32\_004869_.tmp.dll
C:\WINDOWS\system32\_004870_.tmp.dll
C:\WINDOWS\system32\_004871_.tmp.dll
C:\WINDOWS\system32\_004872_.tmp.dll
C:\WINDOWS\system32\_004873_.tmp.dll
C:\WINDOWS\system32\_004874_.tmp.dll
C:\WINDOWS\system32\_004875_.tmp.dll
C:\WINDOWS\system32\_004876_.tmp.dll
C:\WINDOWS\system32\_004877_.tmp.dll
C:\WINDOWS\system32\_004878_.tmp.dll
C:\WINDOWS\system32\_004879_.tmp.dll
C:\WINDOWS\system32\_004880_.tmp.dll
C:\WINDOWS\system32\_004881_.tmp.dll
C:\WINDOWS\system32\_004882_.tmp.dll
C:\WINDOWS\system32\_004883_.tmp.dll
C:\WINDOWS\system32\_004884_.tmp.dll
C:\WINDOWS\system32\_004885_.tmp.dll
C:\WINDOWS\system32\_004886_.tmp.dll
C:\WINDOWS\system32\_004887_.tmp.dll
C:\WINDOWS\system32\_004888_.tmp.dll
C:\WINDOWS\system32\_004889_.tmp.dll
C:\WINDOWS\system32\_004890_.tmp.dll
C:\WINDOWS\system32\_004891_.tmp.dll
C:\WINDOWS\system32\_004892_.tmp.dll
C:\WINDOWS\system32\_004893_.tmp.dll
C:\WINDOWS\system32\_004894_.tmp.dll
C:\WINDOWS\system32\_004895_.tmp.dll
C:\WINDOWS\system32\_004896_.tmp.dll
C:\WINDOWS\system32\_004897_.tmp.dll
C:\WINDOWS\system32\_004898_.tmp.dll
C:\WINDOWS\system32\_004899_.tmp.dll
C:\WINDOWS\system32\_004900_.tmp.dll
C:\WINDOWS\system32\_004901_.tmp.dll
C:\WINDOWS\system32\_004902_.tmp.dll
C:\WINDOWS\system32\_004903_.tmp.dll
C:\WINDOWS\system32\_004904_.tmp.dll
C:\WINDOWS\system32\_004905_.tmp.dll
C:\WINDOWS\system32\_004906_.tmp.dll
C:\WINDOWS\system32\_004907_.tmp.dll
C:\WINDOWS\system32\_004908_.tmp.dll
C:\WINDOWS\system32\_004909_.tmp.dll
C:\WINDOWS\system32\_004910_.tmp.dll
C:\WINDOWS\system32\_004911_.tmp.dll
C:\WINDOWS\system32\_004912_.tmp.dll
C:\WINDOWS\system32\_004913_.tmp.dll
C:\WINDOWS\system32\_004914_.tmp.dll
C:\WINDOWS\system32\_004915_.tmp.dll
C:\WINDOWS\system32\_004916_.tmp.dll
C:\WINDOWS\system32\_004917_.tmp.dll
C:\WINDOWS\system32\_004918_.tmp.dll
C:\WINDOWS\system32\_004919_.tmp.dll
C:\WINDOWS\system32\_004920_.tmp.dll
C:\WINDOWS\system32\_004921_.tmp.dll
C:\WINDOWS\system32\_004922_.tmp.dll
C:\WINDOWS\system32\_004923_.tmp.dll
C:\WINDOWS\system32\_004924_.tmp.dll
C:\WINDOWS\system32\_004925_.tmp.dll
C:\WINDOWS\system32\_004926_.tmp.dll
C:\WINDOWS\system32\_004927_.tmp.dll
C:\WINDOWS\system32\_004928_.tmp.dll
C:\WINDOWS\system32\_004929_.tmp.dll
C:\WINDOWS\system32\_004930_.tmp.dll
C:\WINDOWS\system32\_004931_.tmp.dll
C:\WINDOWS\system32\_004932_.tmp.dll
C:\WINDOWS\system32\_004933_.tmp.dll
C:\WINDOWS\system32\_004934_.tmp.dll
C:\WINDOWS\system32\_004935_.tmp.dll
C:\WINDOWS\system32\_004936_.tmp.dll
C:\WINDOWS\system32\_004937_.tmp.dll
C:\WINDOWS\system32\_004938_.tmp.dll
C:\WINDOWS\system32\_004939_.tmp.dll
C:\WINDOWS\system32\_004940_.tmp.dll
C:\WINDOWS\system32\_004941_.tmp.dll
C:\WINDOWS\system32\_004942_.tmp.dll
C:\WINDOWS\system32\_004943_.tmp.dll
C:\WINDOWS\system32\_004944_.tmp.dll
C:\WINDOWS\system32\_004945_.tmp.dll
C:\WINDOWS\system32\_004946_.tmp.dll
C:\WINDOWS\system32\_004947_.tmp.dll
C:\WINDOWS\system32\_004948_.tmp.dll
C:\WINDOWS\system32\_004949_.tmp.dll
C:\WINDOWS\system32\_004950_.tmp.dll
C:\WINDOWS\system32\_004951_.tmp.dll
C:\WINDOWS\system32\_004952_.tmp.dll
C:\WINDOWS\system32\_004953_.tmp.dll
C:\WINDOWS\system32\_004954_.tmp.dll
C:\WINDOWS\system32\_004955_.tmp.dll
C:\WINDOWS\system32\_004956_.tmp.dll
C:\WINDOWS\system32\_004957_.tmp.dll
C:\WINDOWS\system32\_004958_.tmp.dll
C:\WINDOWS\system32\_004959_.tmp.dll
C:\WINDOWS\system32\_004960_.tmp.dll
C:\WINDOWS\system32\_004961_.tmp.dll
C:\WINDOWS\system32\_004962_.tmp.dll
C:\WINDOWS\system32\_004963_.tmp.dll
C:\WINDOWS\system32\_004964_.tmp.dll
C:\WINDOWS\system32\_004965_.tmp.dll
C:\WINDOWS\system32\_004966_.tmp.dll
C:\WINDOWS\system32\_004967_.tmp.dll
C:\WINDOWS\system32\_004968_.tmp.dll
C:\WINDOWS\system32\_004969_.tmp.dll
C:\WINDOWS\system32\_004970_.tmp.dll
C:\WINDOWS\system32\_004971_.tmp.dll
C:\WINDOWS\system32\_004972_.tmp.dll
C:\WINDOWS\system32\_004973_.tmp.dll
C:\WINDOWS\system32\_004974_.tmp.dll
C:\WINDOWS\system32\_004975_.tmp.dll
C:\WINDOWS\system32\_004976_.tmp.dll
C:\WINDOWS\system32\_004978_.tmp.dll
C:\WINDOWS\system32\_004979_.tmp.dll
C:\WINDOWS\system32\_004980_.tmp.dll
C:\WINDOWS\system32\_004982_.tmp.dll
C:\WINDOWS\system32\_004983_.tmp.dll
C:\WINDOWS\system32\_004984_.tmp.dll
C:\WINDOWS\system32\_004985_.tmp.dll
C:\WINDOWS\system32\_004986_.tmp.dll
C:\WINDOWS\system32\_004987_.tmp.dll
C:\WINDOWS\system32\_004988_.tmp.dll
C:\WINDOWS\system32\_004989_.tmp.dll
C:\WINDOWS\system32\_004990_.tmp.dll
C:\WINDOWS\system32\_004991_.tmp.dll
C:\WINDOWS\system32\_004992_.tmp.dll
C:\WINDOWS\system32\_004993_.tmp.dll
C:\WINDOWS\system32\_004994_.tmp.dll
C:\WINDOWS\system32\_004995_.tmp.dll
C:\WINDOWS\system32\_004996_.tmp.dll
C:\WINDOWS\system32\_004997_.tmp.dll
C:\WINDOWS\system32\_004998_.tmp.dll
C:\WINDOWS\system32\_004999_.tmp.dll
C:\WINDOWS\system32\_005000_.tmp.dll
C:\WINDOWS\system32\_005001_.tmp.dll
C:\WINDOWS\system32\_005003_.tmp.dll
C:\WINDOWS\system32\_005004_.tmp.dll
C:\WINDOWS\system32\_005005_.tmp.dll
C:\WINDOWS\system32\_005006_.tmp.dll
C:\WINDOWS\system32\_005008_.tmp.dll
C:\WINDOWS\system32\_005010_.tmp.dll
C:\WINDOWS\system32\_005011_.tmp.dll
C:\WINDOWS\system32\_005012_.tmp.dll
C:\WINDOWS\system32\_005014_.tmp.dll
C:\WINDOWS\system32\_005015_.tmp.dll
C:\WINDOWS\system32\_005016_.tmp.dll
C:\WINDOWS\system32\_005017_.tmp.dll
C:\WINDOWS\system32\_005018_.tmp.dll
C:\WINDOWS\system32\_005019_.tmp.dll
C:\WINDOWS\system32\_005020_.tmp.dll
C:\WINDOWS\system32\_005021_.tmp.dll
C:\WINDOWS\system32\_005022_.tmp.dll
C:\WINDOWS\system32\_005023_.tmp.dll
C:\WINDOWS\system32\_005024_.tmp.dll
C:\WINDOWS\system32\_005025_.tmp.dll
C:\WINDOWS\system32\_005026_.tmp.dll
C:\WINDOWS\system32\_005027_.tmp.dll
C:\WINDOWS\system32\_005028_.tmp.dll
C:\WINDOWS\system32\_005029_.tmp.dll
C:\WINDOWS\system32\_005030_.tmp.dll
C:\WINDOWS\system32\_005031_.tmp.dll
C:\WINDOWS\system32\_005032_.tmp.dll
C:\WINDOWS\system32\_005033_.tmp.dll
C:\WINDOWS\system32\_005035_.tmp.dll
C:\WINDOWS\system32\_005036_.tmp.dll
C:\WINDOWS\system32\_005037_.tmp.dll
C:\WINDOWS\system32\_005038_.tmp.dll
C:\WINDOWS\system32\_005040_.tmp.dll
C:\WINDOWS\system32\_005042_.tmp.dll
C:\WINDOWS\system32\_005043_.tmp.dll
C:\WINDOWS\system32\_005044_.tmp.dll
C:\WINDOWS\system32\_005046_.tmp.dll
C:\WINDOWS\system32\_005047_.tmp.dll
C:\WINDOWS\system32\_005048_.tmp.dll
C:\WINDOWS\system32\_005049_.tmp.dll
C:\WINDOWS\system32\_005050_.tmp.dll
C:\WINDOWS\system32\_005051_.tmp.dll
C:\WINDOWS\system32\_005052_.tmp.dll
C:\WINDOWS\system32\_005053_.tmp.dll
C:\WINDOWS\system32\_005054_.tmp.dll
C:\WINDOWS\system32\_005055_.tmp.dll
C:\WINDOWS\system32\_005056_.tmp.dll
C:\WINDOWS\system32\_005057_.tmp.dll
C:\WINDOWS\system32\_005059_.tmp.dll
C:\WINDOWS\system32\_005061_.tmp.dll
C:\WINDOWS\system32\_005063_.tmp.dll
C:\WINDOWS\system32\_005064_.tmp.dll
C:\WINDOWS\system32\_005065_.tmp.dll
C:\WINDOWS\system32\_005069_.tmp.dll
C:\WINDOWS\system32\_005070_.tmp.dll
C:\WINDOWS\system32\_005072_.tmp.dll
C:\WINDOWS\system32\_005075_.tmp.dll
C:\WINDOWS\system32\_005078_.tmp.dll
C:\WINDOWS\system32\_005079_.tmp.dll
C:\WINDOWS\system32\_005080_.tmp.dll
C:\WINDOWS\system32\_005081_.tmp.dll
C:\WINDOWS\system32\_005084_.tmp.dll
C:\WINDOWS\system32\_005085_.tmp.dll
C:\WINDOWS\system32\_005086_.tmp.dll
C:\WINDOWS\system32\_005087_.tmp.dll
C:\WINDOWS\system32\_005088_.tmp.dll
C:\WINDOWS\system32\_005093_.tmp.dll
C:\WINDOWS\system32\_005095_.tmp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-14 to 2008-05-14 ))))))))))))))))))))))))))))))))))))
.
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-14 15:09 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-14 14:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-13 19:29 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET16A8.tmp
2008-05-13 19:29 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET16CB.tmp
2008-05-13 19:29 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET169A.tmp
2008-05-13 19:29 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET16CD.tmp
2008-05-13 19:29 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET1695.tmp
2008-05-13 19:29 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET16A5.tmp
2008-05-13 19:29 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET16F0.tmp
2008-05-13 19:29 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET169E.tmp
2008-05-13 19:29 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1692.tmp
2008-05-13 19:26 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SET8EB.tmp
2008-05-13 19:25 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET667.tmp
2008-05-13 19:23 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003184_.tmp
2008-05-13 19:21 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004851_.tmp.dll
2008-05-12 21:08 . 2008-05-12 21:08 <REP> d-------- C:\Program Files\OFFICE One6.5
2008-05-12 17:42 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004841_.tmp.dll
2008-05-10 13:07 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004831_.tmp.dll
2008-05-09 13:23 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004821_.tmp.dll
2008-05-09 06:14 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004811_.tmp.dll
2008-05-08 10:55 . 2008-05-08 10:55 <REP> dr-h----- C:\Documents and Settings\MAMOUR\Application Data\SecuROM
2008-05-07 21:03 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004801_.tmp.dll
2008-05-06 22:40 . 2008-05-13 21:11 <REP> d-------- C:\WINDOWS\system32\fr
2008-05-06 22:40 . 2008-05-13 21:11 <REP> d-------- C:\WINDOWS\system32\bits
2008-05-06 22:40 . 2008-05-13 21:11 <REP> d-------- C:\WINDOWS\l2schemas
2008-05-06 22:33 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004791_.tmp.dll
2008-05-06 22:31 . 2008-05-13 20:59 <REP> d-------- C:\WINDOWS\EHome
2008-05-06 21:41 . 2008-05-13 21:09 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-03 09:19 . 2008-05-03 09:19 <REP> d-------- C:\Program Files\EA GAMES
2008-05-02 05:39 . 2008-05-02 05:39 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Panasonic
2008-04-27 22:50 . 2008-05-03 06:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-24 11:32 . 2008-04-24 11:32 26 --a------ C:\UpdaterforApp.ini
2008-04-24 11:29 . 2008-04-24 11:29 <REP> d-------- C:\WINDOWS\system32\MediaImpression Slideshow
2008-04-24 11:29 . 2008-04-24 11:32 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2008-04-24 11:29 . 2007-03-07 16:05 126,976 --a------ C:\WINDOWS\system32\MediaImpression Slideshow.scr
2008-04-24 11:29 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-04-24 11:27 . 2008-04-24 11:27 <REP> d-------- C:\Program Files\Panasonic
2008-04-23 23:00 . 2008-04-23 23:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-23 11:05 . 2008-04-23 11:05 <REP> d-------- C:\Program Files\Electronic Arts
2008-04-23 11:04 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-04-21 22:14 . 2008-04-21 22:14 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-21 10:43 . 2008-04-21 12:29 <REP> d-------- C:\Program Files\a-squared Free
2008-04-20 17:14 . 2008-05-10 20:06 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-04-20 13:10 . 2008-04-20 13:10 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-04-20 13:10 . 2008-04-20 16:47 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\FileZilla
2008-04-19 17:35 . 2008-04-19 17:35 <REP> d-------- C:\WINDOWS\system32\FlashAX
2008-04-19 17:34 . 2008-04-19 17:34 <REP> d-------- C:\MicroGaming
2008-04-19 17:34 . 2008-04-19 17:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microgaming
2008-04-19 17:34 . 2008-04-19 17:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MGS
2008-04-14 12:31 . 1998-06-24 01:00 244,024 --a------ C:\WINDOWS\system32\MSFLXGRD.OCX
2008-04-14 12:29 . 2005-07-25 10:04 48,640 --a------ C:\WINDOWS\system32\drivers\ser2pl.sys
2008-04-14 04:33 . 2008-04-14 04:33 8,517,632 --a------ C:\WINDOWS\system32\SET71B.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET68E.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET2EE.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET290.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET1C3.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET196.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET16A.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET152.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SETA14.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET880.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET74B.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET736.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET595.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET482.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET42A.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET96B.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET8FD.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET896.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET56D.tmp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-14 19:40 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-14 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-14 12:08 --------- d-----w C:\Program Files\Navilog1
2008-05-13 16:32 8 -c--a-w C:\Documents and Settings\MAMOUR\.bztarotcumul.dat
2008-05-12 09:48 --------- d-----w C:\Program Files\eMule
2008-05-10 16:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-10 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-10 14:59 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\OpenOffice.org2
2008-05-09 16:09 1,362 -c--a-w C:\Documents and Settings\MAMOUR\Application Data\wklnhst.dat
2008-05-05 04:04 --------- d-----w C:\Program Files\Glary Utilities
2008-04-24 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 09:29 --------- d-----w C:\Program Files\ArcSoft
2008-04-23 21:00 --------- d-----w C:\Program Files\Lavasoft
2008-04-23 20:59 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-21 20:13 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-04-21 20:11 --------- d-----w C:\Program Files\Java
2008-04-20 19:32 --------- d-----w C:\Program Files\Google
2008-04-15 08:40 --------- d-----w C:\Program Files\DivX
2008-04-14 10:31 --------- d-----w C:\Program Files\gps1
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SETB70.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET9B0.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET947.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET8E7.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET6E4.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B8.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B2.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setb97.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setb96.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setb95.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETAD6.tmp
2008-04-13 17:33 451,072 ----a-w C:\WINDOWS\AppPatch\setb9b.tmp
2008-04-13 17:33 39,424 ----a-w C:\WINDOWS\AppPatch\set173a.tmp
2008-04-13 17:33 245,248 ----a-w C:\WINDOWS\AppPatch\setb99.tmp
2008-04-13 17:33 141,312 ----a-w C:\WINDOWS\AppPatch\setb9a.tmp
2008-04-13 17:33 116,224 ----a-w C:\WINDOWS\AppPatch\setb98.tmp
2008-04-13 17:33 1,852,928 ----a-w C:\WINDOWS\AppPatch\setb9c.tmp
2008-04-06 06:02 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\Spamihilator
2008-04-05 15:56 --------- d-----w C:\Program Files\Panda Security
2008-04-03 04:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 15:52 --------- d-----w C:\Program Files\RegCleaner
2008-04-01 15:36 --------- d-----w C:\Program Files\Jeune Styliste
2008-04-01 15:34 --------- d-----w C:\Program Files\Hewlett-Packard
2008-03-19 04:55 --------- d-----w C:\Program Files\Mattel Interactive
2008-03-19 04:55 --------- d-----w C:\Program Files\Barbie(R) Aventures Équestres
2008-03-15 14:59 --------- d-----w C:\Program Files\Windows Live
2008-03-15 14:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci vers Program Files.lnk
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci (2) vers Program Files.lnk
2006-10-06 07:02 3,185,570 -c--a-w C:\Documents and Settings\MAMOUR\trop_fort.zip
2006-10-02 16:36 3,782,230 -c--a-w C:\Documents and Settings\MAMOUR\wc2.zip
2006-03-19 11:23 256 -c--a-w C:\Program Files\SAVEGAME
2006-03-19 09:52 4,730 -c--a-w C:\Program Files\DeIsL2.isu
2006-03-04 07:22 163 -c-ha-w C:\Documents and Settings\MAMOUR\hpothb07.dat
2006-01-07 16:01 3,401 -c--a-w C:\Program Files\DeIsL1.isu
2006-01-07 16:01 17,825,792 -c--a-w C:\Program Files\pcdogs.pkg
2005-12-27 11:51 164 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-12-27 11:51 0 -c-ha-w C:\Documents and Settings\MAMOUR\Application Data\hpothb07.dat
2003-09-29 10:17 766 -c--a-w C:\Program Files\register.ico
2003-09-29 10:17 593,920 -c--a-w C:\Program Files\THH.exe
2003-09-29 10:17 49,152 -c--a-w C:\Program Files\inetwh32.dll
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\untigghh.ico
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\tiggerhh.ico
2003-09-29 10:17 4,528 -c--a-w C:\Program Files\setbrows.exe
2003-09-29 10:17 30,720 -c--a-w C:\Program Files\remove.dll
2003-09-29 10:17 2,449,408 -c--a-w C:\Program Files\Launcher.exe
2003-09-29 10:17 155 -c--a-w C:\Program Files\title.txt
2003-09-29 10:17 1,698,135 -c--a-w C:\Program Files\TiggerHH.hlp
2003-09-29 10:17 1,584 -c--a-w C:\Program Files\uninst.ini
2000-12-21 12:25 446,464 -c--a-w C:\Program Files\Pcdogs.exe
2000-11-17 14:22 439 -c--a-w C:\Program Files\D3D.log
2000-11-08 16:27 111 -c--a-w C:\Program Files\pcdogs.ini
2000-10-18 15:34 2,251,695 -c--a-w C:\Program Files\102Dalms.hlp
2000-08-18 15:26 630 -c--a-w C:\Program Files\unin102D.ico
2000-08-18 15:25 630 -c--a-w C:\Program Files\102Dalms.ico
2000-07-10 15:33 11 -c--a-w C:\Program Files\message.log
1999-11-01 16:56 327,680 -c--a-w C:\Program Files\mss32.dll
1997-08-14 17:31 98,816 -c--a-w C:\Program Files\DEC130.DLL
1997-08-14 17:24 89,600 -c--a-w C:\Program Files\WINSDEC.DLL
1997-08-14 17:17 117,248 -c--a-w C:\Program Files\EDEC.DLL
1997-08-14 17:06 60,416 -c--a-w C:\Program Files\WINPLAY.DLL
1997-08-14 12:10 80,896 -c--a-w C:\Program Files\WINSTR.DLL
1996-01-25 17:45 39,936 -c--a-w C:\Program Files\D2HTLS32.DLL
1996-01-24 21:43 202,752 -c--a-w C:\Program Files\D2HLNK32.DLL
1995-07-11 09:50 322,832 -c--a-w C:\Program Files\MFC30.DLL
1995-07-11 09:50 253,952 -c--a-w C:\Program Files\MSVCRT20.DLL
2007-08-29 18:03 16,384 -csha-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-05-14_21.55.33.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-14 19:49:11 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-14 20:00:03 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-14 19:49:21 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5bc.dat
+ 2008-05-14 20:00:13 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5bc.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 10:35 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]
"Glary Memory Optimizer"="C:\Program Files\Glary Utilities\memdefrag.exe" [2008-03-05 10:23 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-03 06:22 1836544]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-05 12:26 5566464]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [ ]
"nwiz"="nwiz.exe" [2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ArcSoft Connection Service"="C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 08:45 31232]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli scecli scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Docteur Club Internet.lnk]
backup=C:\WINDOWS\pss\Docteur Club Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NkbMonitor.exe.lnk]
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^MAMOUR^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
backup=C:\WINDOWS\pss\Club Internet.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
--a--c--- 2003-05-02 11:31 24576 c:\apps\ABoard\ABoard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailChecker]
--a--c--- 2003-07-02 11:13 40960 C:\APPS\EmailChecker\ech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-09-03 06:22 1836544 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a--c--- 2004-08-05 14:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a--c--- 2004-10-08 12:06 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2004-10-08 12:31 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a--c--- 2004-10-08 12:24 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-10-08 11:52 221184 C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-03-05 12:26 5566464 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2005-01-28 11:10 110740 c:\Apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StandardInstall]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmtalk]
--a--c--- 2003-07-24 17:21 61440 C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SLService"=2 (0x2)
"SAVScan"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"navapsvc"=2 (0x2)
"MysqlInventime"=3 (0x3)
"ISSVC"=2 (0x2)
"GenericHidService"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"AOL ACS"=2 (0x2)
"Service CANALPLAY"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys [2004-10-11 16:28]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 08:45]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2005-11-04 12:38]
S1 lkbdhlpr;Logitech Keyboard Class Helper Driver;C:\WINDOWS\system32\Drivers\lkbdhlpr.sys []
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2006-03-26 21:15]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys []
S3 SA2KMD;STEL Modem;C:\WINDOWS\system32\DRIVERS\sa2kmd.sys [2004-05-11 03:03]
S3 SA2KPT;STEL OBEX PORT;C:\WINDOWS\system32\DRIVERS\sa2kpt.sys [2004-05-11 03:03]
S3 SACTL;STEL USB HOST DRIVER;C:\WINDOWS\system32\DRIVERS\sactl.sys [2004-05-11 03:02]
S3 SAENUM;STEL Enum Driver;C:\WINDOWS\system32\DRIVERS\saenum.sys [2004-05-11 03:02]
S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-10-08 11:54]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2005-10-21 03:47]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-14 18:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-14 20:00:15 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-14 20:03:15 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-05-14 19:23:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
ComboFix 08-05-12.1 - MAMOUR 2008-05-14 21:56:57.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1527 [GMT 2:00]
Endroit: C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_004804_.tmp.dll
C:\WINDOWS\system32\_004805_.tmp.dll
C:\WINDOWS\system32\_004806_.tmp.dll
C:\WINDOWS\system32\_004807_.tmp.dll
C:\WINDOWS\system32\_004814_.tmp.dll
C:\WINDOWS\system32\_004816_.tmp.dll
C:\WINDOWS\system32\_004817_.tmp.dll
C:\WINDOWS\system32\_004818_.tmp.dll
C:\WINDOWS\system32\_004819_.tmp.dll
C:\WINDOWS\system32\_004820_.tmp.dll
C:\WINDOWS\system32\_004821_.tmp.dll
C:\WINDOWS\system32\_004822_.tmp.dll
C:\WINDOWS\system32\_004823_.tmp.dll
C:\WINDOWS\system32\_004824_.tmp.dll
C:\WINDOWS\system32\_004825_.tmp.dll
C:\WINDOWS\system32\_004826_.tmp.dll
C:\WINDOWS\system32\_004827_.tmp.dll
C:\WINDOWS\system32\_004828_.tmp.dll
C:\WINDOWS\system32\_004829_.tmp.dll
C:\WINDOWS\system32\_004830_.tmp.dll
C:\WINDOWS\system32\_004831_.tmp.dll
C:\WINDOWS\system32\_004832_.tmp.dll
C:\WINDOWS\system32\_004833_.tmp.dll
C:\WINDOWS\system32\_004834_.tmp.dll
C:\WINDOWS\system32\_004835_.tmp.dll
C:\WINDOWS\system32\_004836_.tmp.dll
C:\WINDOWS\system32\_004837_.tmp.dll
C:\WINDOWS\system32\_004838_.tmp.dll
C:\WINDOWS\system32\_004839_.tmp.dll
C:\WINDOWS\system32\_004840_.tmp.dll
C:\WINDOWS\system32\_004841_.tmp.dll
C:\WINDOWS\system32\_004842_.tmp.dll
C:\WINDOWS\system32\_004843_.tmp.dll
C:\WINDOWS\system32\_004844_.tmp.dll
C:\WINDOWS\system32\_004845_.tmp.dll
C:\WINDOWS\system32\_004846_.tmp.dll
C:\WINDOWS\system32\_004847_.tmp.dll
C:\WINDOWS\system32\_004849_.tmp.dll
C:\WINDOWS\system32\_004850_.tmp.dll
C:\WINDOWS\system32\_004851_.tmp.dll
C:\WINDOWS\system32\_004852_.tmp.dll
C:\WINDOWS\system32\_004853_.tmp.dll
C:\WINDOWS\system32\_004854_.tmp.dll
C:\WINDOWS\system32\_004855_.tmp.dll
C:\WINDOWS\system32\_004856_.tmp.dll
C:\WINDOWS\system32\_004857_.tmp.dll
C:\WINDOWS\system32\_004858_.tmp.dll
C:\WINDOWS\system32\_004859_.tmp.dll
C:\WINDOWS\system32\_004860_.tmp.dll
C:\WINDOWS\system32\_004861_.tmp.dll
C:\WINDOWS\system32\_004862_.tmp.dll
C:\WINDOWS\system32\_004863_.tmp.dll
C:\WINDOWS\system32\_004864_.tmp.dll
C:\WINDOWS\system32\_004865_.tmp.dll
C:\WINDOWS\system32\_004866_.tmp.dll
C:\WINDOWS\system32\_004867_.tmp.dll
C:\WINDOWS\system32\_004868_.tmp.dll
C:\WINDOWS\system32\_004869_.tmp.dll
C:\WINDOWS\system32\_004870_.tmp.dll
C:\WINDOWS\system32\_004871_.tmp.dll
C:\WINDOWS\system32\_004872_.tmp.dll
C:\WINDOWS\system32\_004873_.tmp.dll
C:\WINDOWS\system32\_004874_.tmp.dll
C:\WINDOWS\system32\_004875_.tmp.dll
C:\WINDOWS\system32\_004876_.tmp.dll
C:\WINDOWS\system32\_004877_.tmp.dll
C:\WINDOWS\system32\_004878_.tmp.dll
C:\WINDOWS\system32\_004879_.tmp.dll
C:\WINDOWS\system32\_004880_.tmp.dll
C:\WINDOWS\system32\_004881_.tmp.dll
C:\WINDOWS\system32\_004882_.tmp.dll
C:\WINDOWS\system32\_004883_.tmp.dll
C:\WINDOWS\system32\_004884_.tmp.dll
C:\WINDOWS\system32\_004885_.tmp.dll
C:\WINDOWS\system32\_004886_.tmp.dll
C:\WINDOWS\system32\_004887_.tmp.dll
C:\WINDOWS\system32\_004888_.tmp.dll
C:\WINDOWS\system32\_004889_.tmp.dll
C:\WINDOWS\system32\_004890_.tmp.dll
C:\WINDOWS\system32\_004891_.tmp.dll
C:\WINDOWS\system32\_004892_.tmp.dll
C:\WINDOWS\system32\_004893_.tmp.dll
C:\WINDOWS\system32\_004894_.tmp.dll
C:\WINDOWS\system32\_004895_.tmp.dll
C:\WINDOWS\system32\_004896_.tmp.dll
C:\WINDOWS\system32\_004897_.tmp.dll
C:\WINDOWS\system32\_004898_.tmp.dll
C:\WINDOWS\system32\_004899_.tmp.dll
C:\WINDOWS\system32\_004900_.tmp.dll
C:\WINDOWS\system32\_004901_.tmp.dll
C:\WINDOWS\system32\_004902_.tmp.dll
C:\WINDOWS\system32\_004903_.tmp.dll
C:\WINDOWS\system32\_004904_.tmp.dll
C:\WINDOWS\system32\_004905_.tmp.dll
C:\WINDOWS\system32\_004906_.tmp.dll
C:\WINDOWS\system32\_004907_.tmp.dll
C:\WINDOWS\system32\_004908_.tmp.dll
C:\WINDOWS\system32\_004909_.tmp.dll
C:\WINDOWS\system32\_004910_.tmp.dll
C:\WINDOWS\system32\_004911_.tmp.dll
C:\WINDOWS\system32\_004912_.tmp.dll
C:\WINDOWS\system32\_004913_.tmp.dll
C:\WINDOWS\system32\_004914_.tmp.dll
C:\WINDOWS\system32\_004915_.tmp.dll
C:\WINDOWS\system32\_004916_.tmp.dll
C:\WINDOWS\system32\_004917_.tmp.dll
C:\WINDOWS\system32\_004918_.tmp.dll
C:\WINDOWS\system32\_004919_.tmp.dll
C:\WINDOWS\system32\_004920_.tmp.dll
C:\WINDOWS\system32\_004921_.tmp.dll
C:\WINDOWS\system32\_004922_.tmp.dll
C:\WINDOWS\system32\_004923_.tmp.dll
C:\WINDOWS\system32\_004924_.tmp.dll
C:\WINDOWS\system32\_004925_.tmp.dll
C:\WINDOWS\system32\_004926_.tmp.dll
C:\WINDOWS\system32\_004927_.tmp.dll
C:\WINDOWS\system32\_004928_.tmp.dll
C:\WINDOWS\system32\_004929_.tmp.dll
C:\WINDOWS\system32\_004930_.tmp.dll
C:\WINDOWS\system32\_004931_.tmp.dll
C:\WINDOWS\system32\_004932_.tmp.dll
C:\WINDOWS\system32\_004933_.tmp.dll
C:\WINDOWS\system32\_004934_.tmp.dll
C:\WINDOWS\system32\_004935_.tmp.dll
C:\WINDOWS\system32\_004936_.tmp.dll
C:\WINDOWS\system32\_004937_.tmp.dll
C:\WINDOWS\system32\_004938_.tmp.dll
C:\WINDOWS\system32\_004939_.tmp.dll
C:\WINDOWS\system32\_004940_.tmp.dll
C:\WINDOWS\system32\_004941_.tmp.dll
C:\WINDOWS\system32\_004942_.tmp.dll
C:\WINDOWS\system32\_004943_.tmp.dll
C:\WINDOWS\system32\_004944_.tmp.dll
C:\WINDOWS\system32\_004945_.tmp.dll
C:\WINDOWS\system32\_004946_.tmp.dll
C:\WINDOWS\system32\_004947_.tmp.dll
C:\WINDOWS\system32\_004948_.tmp.dll
C:\WINDOWS\system32\_004949_.tmp.dll
C:\WINDOWS\system32\_004950_.tmp.dll
C:\WINDOWS\system32\_004951_.tmp.dll
C:\WINDOWS\system32\_004952_.tmp.dll
C:\WINDOWS\system32\_004953_.tmp.dll
C:\WINDOWS\system32\_004954_.tmp.dll
C:\WINDOWS\system32\_004955_.tmp.dll
C:\WINDOWS\system32\_004956_.tmp.dll
C:\WINDOWS\system32\_004957_.tmp.dll
C:\WINDOWS\system32\_004958_.tmp.dll
C:\WINDOWS\system32\_004959_.tmp.dll
C:\WINDOWS\system32\_004960_.tmp.dll
C:\WINDOWS\system32\_004961_.tmp.dll
C:\WINDOWS\system32\_004962_.tmp.dll
C:\WINDOWS\system32\_004963_.tmp.dll
C:\WINDOWS\system32\_004964_.tmp.dll
C:\WINDOWS\system32\_004965_.tmp.dll
C:\WINDOWS\system32\_004966_.tmp.dll
C:\WINDOWS\system32\_004967_.tmp.dll
C:\WINDOWS\system32\_004968_.tmp.dll
C:\WINDOWS\system32\_004969_.tmp.dll
C:\WINDOWS\system32\_004970_.tmp.dll
C:\WINDOWS\system32\_004971_.tmp.dll
C:\WINDOWS\system32\_004972_.tmp.dll
C:\WINDOWS\system32\_004973_.tmp.dll
C:\WINDOWS\system32\_004974_.tmp.dll
C:\WINDOWS\system32\_004975_.tmp.dll
C:\WINDOWS\system32\_004976_.tmp.dll
C:\WINDOWS\system32\_004978_.tmp.dll
C:\WINDOWS\system32\_004979_.tmp.dll
C:\WINDOWS\system32\_004980_.tmp.dll
C:\WINDOWS\system32\_004982_.tmp.dll
C:\WINDOWS\system32\_004983_.tmp.dll
C:\WINDOWS\system32\_004984_.tmp.dll
C:\WINDOWS\system32\_004985_.tmp.dll
C:\WINDOWS\system32\_004986_.tmp.dll
C:\WINDOWS\system32\_004987_.tmp.dll
C:\WINDOWS\system32\_004988_.tmp.dll
C:\WINDOWS\system32\_004989_.tmp.dll
C:\WINDOWS\system32\_004990_.tmp.dll
C:\WINDOWS\system32\_004991_.tmp.dll
C:\WINDOWS\system32\_004992_.tmp.dll
C:\WINDOWS\system32\_004993_.tmp.dll
C:\WINDOWS\system32\_004994_.tmp.dll
C:\WINDOWS\system32\_004995_.tmp.dll
C:\WINDOWS\system32\_004996_.tmp.dll
C:\WINDOWS\system32\_004997_.tmp.dll
C:\WINDOWS\system32\_004998_.tmp.dll
C:\WINDOWS\system32\_004999_.tmp.dll
C:\WINDOWS\system32\_005000_.tmp.dll
C:\WINDOWS\system32\_005001_.tmp.dll
C:\WINDOWS\system32\_005003_.tmp.dll
C:\WINDOWS\system32\_005004_.tmp.dll
C:\WINDOWS\system32\_005005_.tmp.dll
C:\WINDOWS\system32\_005006_.tmp.dll
C:\WINDOWS\system32\_005008_.tmp.dll
C:\WINDOWS\system32\_005010_.tmp.dll
C:\WINDOWS\system32\_005011_.tmp.dll
C:\WINDOWS\system32\_005012_.tmp.dll
C:\WINDOWS\system32\_005014_.tmp.dll
C:\WINDOWS\system32\_005015_.tmp.dll
C:\WINDOWS\system32\_005016_.tmp.dll
C:\WINDOWS\system32\_005017_.tmp.dll
C:\WINDOWS\system32\_005018_.tmp.dll
C:\WINDOWS\system32\_005019_.tmp.dll
C:\WINDOWS\system32\_005020_.tmp.dll
C:\WINDOWS\system32\_005021_.tmp.dll
C:\WINDOWS\system32\_005022_.tmp.dll
C:\WINDOWS\system32\_005023_.tmp.dll
C:\WINDOWS\system32\_005024_.tmp.dll
C:\WINDOWS\system32\_005025_.tmp.dll
C:\WINDOWS\system32\_005026_.tmp.dll
C:\WINDOWS\system32\_005027_.tmp.dll
C:\WINDOWS\system32\_005028_.tmp.dll
C:\WINDOWS\system32\_005029_.tmp.dll
C:\WINDOWS\system32\_005030_.tmp.dll
C:\WINDOWS\system32\_005031_.tmp.dll
C:\WINDOWS\system32\_005032_.tmp.dll
C:\WINDOWS\system32\_005033_.tmp.dll
C:\WINDOWS\system32\_005035_.tmp.dll
C:\WINDOWS\system32\_005036_.tmp.dll
C:\WINDOWS\system32\_005037_.tmp.dll
C:\WINDOWS\system32\_005038_.tmp.dll
C:\WINDOWS\system32\_005040_.tmp.dll
C:\WINDOWS\system32\_005042_.tmp.dll
C:\WINDOWS\system32\_005043_.tmp.dll
C:\WINDOWS\system32\_005044_.tmp.dll
C:\WINDOWS\system32\_005046_.tmp.dll
C:\WINDOWS\system32\_005047_.tmp.dll
C:\WINDOWS\system32\_005048_.tmp.dll
C:\WINDOWS\system32\_005049_.tmp.dll
C:\WINDOWS\system32\_005050_.tmp.dll
C:\WINDOWS\system32\_005051_.tmp.dll
C:\WINDOWS\system32\_005052_.tmp.dll
C:\WINDOWS\system32\_005053_.tmp.dll
C:\WINDOWS\system32\_005054_.tmp.dll
C:\WINDOWS\system32\_005055_.tmp.dll
C:\WINDOWS\system32\_005056_.tmp.dll
C:\WINDOWS\system32\_005057_.tmp.dll
C:\WINDOWS\system32\_005059_.tmp.dll
C:\WINDOWS\system32\_005061_.tmp.dll
C:\WINDOWS\system32\_005063_.tmp.dll
C:\WINDOWS\system32\_005064_.tmp.dll
C:\WINDOWS\system32\_005065_.tmp.dll
C:\WINDOWS\system32\_005069_.tmp.dll
C:\WINDOWS\system32\_005070_.tmp.dll
C:\WINDOWS\system32\_005072_.tmp.dll
C:\WINDOWS\system32\_005075_.tmp.dll
C:\WINDOWS\system32\_005078_.tmp.dll
C:\WINDOWS\system32\_005079_.tmp.dll
C:\WINDOWS\system32\_005080_.tmp.dll
C:\WINDOWS\system32\_005081_.tmp.dll
C:\WINDOWS\system32\_005084_.tmp.dll
C:\WINDOWS\system32\_005085_.tmp.dll
C:\WINDOWS\system32\_005086_.tmp.dll
C:\WINDOWS\system32\_005087_.tmp.dll
C:\WINDOWS\system32\_005088_.tmp.dll
C:\WINDOWS\system32\_005093_.tmp.dll
C:\WINDOWS\system32\_005095_.tmp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-14 to 2008-05-14 ))))))))))))))))))))))))))))))))))))
.
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-14 15:09 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-14 14:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-13 19:29 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET16A8.tmp
2008-05-13 19:29 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET16CB.tmp
2008-05-13 19:29 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET169A.tmp
2008-05-13 19:29 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET16CD.tmp
2008-05-13 19:29 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET1695.tmp
2008-05-13 19:29 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET16A5.tmp
2008-05-13 19:29 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET16F0.tmp
2008-05-13 19:29 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET169E.tmp
2008-05-13 19:29 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1692.tmp
2008-05-13 19:26 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SET8EB.tmp
2008-05-13 19:25 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET667.tmp
2008-05-13 19:23 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003184_.tmp
2008-05-13 19:21 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004851_.tmp.dll
2008-05-12 21:08 . 2008-05-12 21:08 <REP> d-------- C:\Program Files\OFFICE One6.5
2008-05-12 17:42 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004841_.tmp.dll
2008-05-10 13:07 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004831_.tmp.dll
2008-05-09 13:23 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004821_.tmp.dll
2008-05-09 06:14 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004811_.tmp.dll
2008-05-08 10:55 . 2008-05-08 10:55 <REP> dr-h----- C:\Documents and Settings\MAMOUR\Application Data\SecuROM
2008-05-07 21:03 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004801_.tmp.dll
2008-05-06 22:40 . 2008-05-13 21:11 <REP> d-------- C:\WINDOWS\system32\fr
2008-05-06 22:40 . 2008-05-13 21:11 <REP> d-------- C:\WINDOWS\system32\bits
2008-05-06 22:40 . 2008-05-13 21:11 <REP> d-------- C:\WINDOWS\l2schemas
2008-05-06 22:33 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004791_.tmp.dll
2008-05-06 22:31 . 2008-05-13 20:59 <REP> d-------- C:\WINDOWS\EHome
2008-05-06 21:41 . 2008-05-13 21:09 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-03 09:19 . 2008-05-03 09:19 <REP> d-------- C:\Program Files\EA GAMES
2008-05-02 05:39 . 2008-05-02 05:39 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Panasonic
2008-04-27 22:50 . 2008-05-03 06:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-24 11:32 . 2008-04-24 11:32 26 --a------ C:\UpdaterforApp.ini
2008-04-24 11:29 . 2008-04-24 11:29 <REP> d-------- C:\WINDOWS\system32\MediaImpression Slideshow
2008-04-24 11:29 . 2008-04-24 11:32 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2008-04-24 11:29 . 2007-03-07 16:05 126,976 --a------ C:\WINDOWS\system32\MediaImpression Slideshow.scr
2008-04-24 11:29 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-04-24 11:27 . 2008-04-24 11:27 <REP> d-------- C:\Program Files\Panasonic
2008-04-23 23:00 . 2008-04-23 23:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-23 11:05 . 2008-04-23 11:05 <REP> d-------- C:\Program Files\Electronic Arts
2008-04-23 11:04 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-04-21 22:14 . 2008-04-21 22:14 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-21 10:43 . 2008-04-21 12:29 <REP> d-------- C:\Program Files\a-squared Free
2008-04-20 17:14 . 2008-05-10 20:06 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-04-20 13:10 . 2008-04-20 13:10 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-04-20 13:10 . 2008-04-20 16:47 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\FileZilla
2008-04-19 17:35 . 2008-04-19 17:35 <REP> d-------- C:\WINDOWS\system32\FlashAX
2008-04-19 17:34 . 2008-04-19 17:34 <REP> d-------- C:\MicroGaming
2008-04-19 17:34 . 2008-04-19 17:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microgaming
2008-04-19 17:34 . 2008-04-19 17:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MGS
2008-04-14 12:31 . 1998-06-24 01:00 244,024 --a------ C:\WINDOWS\system32\MSFLXGRD.OCX
2008-04-14 12:29 . 2005-07-25 10:04 48,640 --a------ C:\WINDOWS\system32\drivers\ser2pl.sys
2008-04-14 04:33 . 2008-04-14 04:33 8,517,632 --a------ C:\WINDOWS\system32\SET71B.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET68E.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET2EE.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET290.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET1C3.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET196.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET16A.tmp
2008-04-14 04:32 . 2008-04-14 04:32 5,632 --a------ C:\WINDOWS\system32\SET152.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SETA14.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET880.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET74B.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET736.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET595.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET482.tmp
2008-04-14 04:02 . 2008-04-14 04:02 50,688 --a------ C:\WINDOWS\system32\SET42A.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET96B.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET8FD.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET896.tmp
2008-04-14 03:57 . 2008-04-14 03:57 70,144 --a------ C:\WINDOWS\system32\SET56D.tmp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-14 19:40 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-14 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-14 12:08 --------- d-----w C:\Program Files\Navilog1
2008-05-13 16:32 8 -c--a-w C:\Documents and Settings\MAMOUR\.bztarotcumul.dat
2008-05-12 09:48 --------- d-----w C:\Program Files\eMule
2008-05-10 16:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-10 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-10 14:59 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\OpenOffice.org2
2008-05-09 16:09 1,362 -c--a-w C:\Documents and Settings\MAMOUR\Application Data\wklnhst.dat
2008-05-05 04:04 --------- d-----w C:\Program Files\Glary Utilities
2008-04-24 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 09:29 --------- d-----w C:\Program Files\ArcSoft
2008-04-23 21:00 --------- d-----w C:\Program Files\Lavasoft
2008-04-23 20:59 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-21 20:13 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-04-21 20:11 --------- d-----w C:\Program Files\Java
2008-04-20 19:32 --------- d-----w C:\Program Files\Google
2008-04-15 08:40 --------- d-----w C:\Program Files\DivX
2008-04-14 10:31 --------- d-----w C:\Program Files\gps1
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SETB70.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET9B0.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET947.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET8E7.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET6E4.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B8.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B2.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setb97.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setb96.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setb95.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETAD6.tmp
2008-04-13 17:33 451,072 ----a-w C:\WINDOWS\AppPatch\setb9b.tmp
2008-04-13 17:33 39,424 ----a-w C:\WINDOWS\AppPatch\set173a.tmp
2008-04-13 17:33 245,248 ----a-w C:\WINDOWS\AppPatch\setb99.tmp
2008-04-13 17:33 141,312 ----a-w C:\WINDOWS\AppPatch\setb9a.tmp
2008-04-13 17:33 116,224 ----a-w C:\WINDOWS\AppPatch\setb98.tmp
2008-04-13 17:33 1,852,928 ----a-w C:\WINDOWS\AppPatch\setb9c.tmp
2008-04-06 06:02 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\Spamihilator
2008-04-05 15:56 --------- d-----w C:\Program Files\Panda Security
2008-04-03 04:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 15:52 --------- d-----w C:\Program Files\RegCleaner
2008-04-01 15:36 --------- d-----w C:\Program Files\Jeune Styliste
2008-04-01 15:34 --------- d-----w C:\Program Files\Hewlett-Packard
2008-03-19 04:55 --------- d-----w C:\Program Files\Mattel Interactive
2008-03-19 04:55 --------- d-----w C:\Program Files\Barbie(R) Aventures Équestres
2008-03-15 14:59 --------- d-----w C:\Program Files\Windows Live
2008-03-15 14:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci vers Program Files.lnk
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci (2) vers Program Files.lnk
2006-10-06 07:02 3,185,570 -c--a-w C:\Documents and Settings\MAMOUR\trop_fort.zip
2006-10-02 16:36 3,782,230 -c--a-w C:\Documents and Settings\MAMOUR\wc2.zip
2006-03-19 11:23 256 -c--a-w C:\Program Files\SAVEGAME
2006-03-19 09:52 4,730 -c--a-w C:\Program Files\DeIsL2.isu
2006-03-04 07:22 163 -c-ha-w C:\Documents and Settings\MAMOUR\hpothb07.dat
2006-01-07 16:01 3,401 -c--a-w C:\Program Files\DeIsL1.isu
2006-01-07 16:01 17,825,792 -c--a-w C:\Program Files\pcdogs.pkg
2005-12-27 11:51 164 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-12-27 11:51 0 -c-ha-w C:\Documents and Settings\MAMOUR\Application Data\hpothb07.dat
2003-09-29 10:17 766 -c--a-w C:\Program Files\register.ico
2003-09-29 10:17 593,920 -c--a-w C:\Program Files\THH.exe
2003-09-29 10:17 49,152 -c--a-w C:\Program Files\inetwh32.dll
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\untigghh.ico
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\tiggerhh.ico
2003-09-29 10:17 4,528 -c--a-w C:\Program Files\setbrows.exe
2003-09-29 10:17 30,720 -c--a-w C:\Program Files\remove.dll
2003-09-29 10:17 2,449,408 -c--a-w C:\Program Files\Launcher.exe
2003-09-29 10:17 155 -c--a-w C:\Program Files\title.txt
2003-09-29 10:17 1,698,135 -c--a-w C:\Program Files\TiggerHH.hlp
2003-09-29 10:17 1,584 -c--a-w C:\Program Files\uninst.ini
2000-12-21 12:25 446,464 -c--a-w C:\Program Files\Pcdogs.exe
2000-11-17 14:22 439 -c--a-w C:\Program Files\D3D.log
2000-11-08 16:27 111 -c--a-w C:\Program Files\pcdogs.ini
2000-10-18 15:34 2,251,695 -c--a-w C:\Program Files\102Dalms.hlp
2000-08-18 15:26 630 -c--a-w C:\Program Files\unin102D.ico
2000-08-18 15:25 630 -c--a-w C:\Program Files\102Dalms.ico
2000-07-10 15:33 11 -c--a-w C:\Program Files\message.log
1999-11-01 16:56 327,680 -c--a-w C:\Program Files\mss32.dll
1997-08-14 17:31 98,816 -c--a-w C:\Program Files\DEC130.DLL
1997-08-14 17:24 89,600 -c--a-w C:\Program Files\WINSDEC.DLL
1997-08-14 17:17 117,248 -c--a-w C:\Program Files\EDEC.DLL
1997-08-14 17:06 60,416 -c--a-w C:\Program Files\WINPLAY.DLL
1997-08-14 12:10 80,896 -c--a-w C:\Program Files\WINSTR.DLL
1996-01-25 17:45 39,936 -c--a-w C:\Program Files\D2HTLS32.DLL
1996-01-24 21:43 202,752 -c--a-w C:\Program Files\D2HLNK32.DLL
1995-07-11 09:50 322,832 -c--a-w C:\Program Files\MFC30.DLL
1995-07-11 09:50 253,952 -c--a-w C:\Program Files\MSVCRT20.DLL
2007-08-29 18:03 16,384 -csha-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-05-14_21.55.33.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-14 19:49:11 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-14 20:00:03 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-14 19:49:21 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5bc.dat
+ 2008-05-14 20:00:13 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5bc.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 10:35 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]
"Glary Memory Optimizer"="C:\Program Files\Glary Utilities\memdefrag.exe" [2008-03-05 10:23 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-03 06:22 1836544]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-05 12:26 5566464]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [ ]
"nwiz"="nwiz.exe" [2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ArcSoft Connection Service"="C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 08:45 31232]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli scecli scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Docteur Club Internet.lnk]
backup=C:\WINDOWS\pss\Docteur Club Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NkbMonitor.exe.lnk]
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^MAMOUR^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
backup=C:\WINDOWS\pss\Club Internet.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
--a--c--- 2003-05-02 11:31 24576 c:\apps\ABoard\ABoard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailChecker]
--a--c--- 2003-07-02 11:13 40960 C:\APPS\EmailChecker\ech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-09-03 06:22 1836544 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a--c--- 2004-08-05 14:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a--c--- 2004-10-08 12:06 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2004-10-08 12:31 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a--c--- 2004-10-08 12:24 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-10-08 11:52 221184 C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-03-05 12:26 5566464 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2005-01-28 11:10 110740 c:\Apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StandardInstall]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmtalk]
--a--c--- 2003-07-24 17:21 61440 C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SLService"=2 (0x2)
"SAVScan"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"navapsvc"=2 (0x2)
"MysqlInventime"=3 (0x3)
"ISSVC"=2 (0x2)
"GenericHidService"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"AOL ACS"=2 (0x2)
"Service CANALPLAY"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys [2004-10-11 16:28]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 08:45]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2005-11-04 12:38]
S1 lkbdhlpr;Logitech Keyboard Class Helper Driver;C:\WINDOWS\system32\Drivers\lkbdhlpr.sys []
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2006-03-26 21:15]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys []
S3 SA2KMD;STEL Modem;C:\WINDOWS\system32\DRIVERS\sa2kmd.sys [2004-05-11 03:03]
S3 SA2KPT;STEL OBEX PORT;C:\WINDOWS\system32\DRIVERS\sa2kpt.sys [2004-05-11 03:03]
S3 SACTL;STEL USB HOST DRIVER;C:\WINDOWS\system32\DRIVERS\sactl.sys [2004-05-11 03:02]
S3 SAENUM;STEL Enum Driver;C:\WINDOWS\system32\DRIVERS\saenum.sys [2004-05-11 03:02]
S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-10-08 11:54]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2005-10-21 03:47]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-14 18:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-14 20:00:15 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-14 20:03:15 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-05-14 19:23:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
analyse ces fichiers sur virus total et dis moi ceux qui sont considérés comme inféctés:
https://www.virustotal.com/gui/
C:\WINDOWS\system32\drivers\_004841_.tmp.dll
C:\WINDOWS\system32\drivers\_004831_.tmp.dll
C:\WINDOWS\system32\drivers\_004821_.tmp.dll
C:\WINDOWS\system32\drivers\_004811_.tmp.dll
C:\WINDOWS\system32\drivers\_004801_.tmp.dll
C:\WINDOWS\system32\drivers\_004791_.tmp.dll
________________
colle le rapport d'un scan en ligne
avec un des suivants: (désactiver avast le temps du scan)
bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Panda en ligne :
http://pandasoftware.fr
Kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
https://www.virustotal.com/gui/
C:\WINDOWS\system32\drivers\_004841_.tmp.dll
C:\WINDOWS\system32\drivers\_004831_.tmp.dll
C:\WINDOWS\system32\drivers\_004821_.tmp.dll
C:\WINDOWS\system32\drivers\_004811_.tmp.dll
C:\WINDOWS\system32\drivers\_004801_.tmp.dll
C:\WINDOWS\system32\drivers\_004791_.tmp.dll
________________
colle le rapport d'un scan en ligne
avec un des suivants: (désactiver avast le temps du scan)
bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Panda en ligne :
http://pandasoftware.fr
Kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
désolé pour le retard mais j 'étais absent.Je n'ai pas su analyser les fichiers demandés mais j'ai fait analyser le fichier entier combo et depuis12 h mon ordi est analysé par active scan ce qui me semble trés long!
Dés la fin du scan je poste le rapport
encore merci pour ton aide
Dés la fin du scan je poste le rapport
encore merci pour ton aide
apres 16 h de scan voici le résultat
;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-05-17 05:58:50
PROTECTIONS: 2
MALWARE: 18
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Norton Internet Security 2005 Yes Yes
Avira AntiVir PersonalEdition 8.0.1.15 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.atdmt.com/]
00139535 Application/Processor HackTools No 0 Yes No C:\Program Files\Navilog1\Process.exe
00139535 Application/Processor HackTools No 0 Yes No C:\WINDOWS\system32\Process.exe
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.tribalfusion.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.com.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.xiti.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@xiti[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.bs.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@bs.serving-sys[1].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.weborama.fr/]
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.weborama.fr/]
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.weborama.fr/]
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@weborama[1].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.adtech.de/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@ads.pointroll[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.overture.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.realmedia.com/]
00238695 Application/Pskill.K HackTools No 0 No No C:\TEMP\compagnon_club\LeCompagnonClub.exe[mccEmbInstaller.zip][pskill.exe]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@smartadserver[2].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc11.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc12.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc16.part[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104124.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104136.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104177.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104223.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Documents and Settings\MAMOUR\Mes documents\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 Yes No C:\ComboFix\NirCmdC.cfexe
01185375 Application/Psexec.A HackTools No 0 Yes No C:\WINDOWS\PSEXESVC.EXE
01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP360\A0104571.EXE
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP360\A0104520.sys
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP360\A0104577.sys
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================
QUE DOIS JE FAIRE MAINTENAN?,
;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-05-17 05:58:50
PROTECTIONS: 2
MALWARE: 18
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Norton Internet Security 2005 Yes Yes
Avira AntiVir PersonalEdition 8.0.1.15 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.atdmt.com/]
00139535 Application/Processor HackTools No 0 Yes No C:\Program Files\Navilog1\Process.exe
00139535 Application/Processor HackTools No 0 Yes No C:\WINDOWS\system32\Process.exe
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.247realmedia.com/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.tribalfusion.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.com.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.xiti.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@xiti[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.bs.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@bs.serving-sys[1].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.weborama.fr/]
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.weborama.fr/]
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.weborama.fr/]
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@weborama[1].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.adtech.de/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@ads.pointroll[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.overture.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.realmedia.com/]
00238695 Application/Pskill.K HackTools No 0 No No C:\TEMP\compagnon_club\LeCompagnonClub.exe[mccEmbInstaller.zip][pskill.exe]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Cookies\mamour@smartadserver[2].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\MAMOUR\Application Data\Mozilla\Firefox\Profiles\2ar7dpna.default\cookies.txt[.smartadserver.com/]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc11.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc12.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc16.part[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104124.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104136.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104177.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP359\A0104223.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Documents and Settings\MAMOUR\Mes documents\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 Yes No C:\ComboFix\NirCmdC.cfexe
01185375 Application/Psexec.A HackTools No 0 Yes No C:\WINDOWS\PSEXESVC.EXE
01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP360\A0104571.EXE
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP360\A0104520.sys
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP360\A0104577.sys
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================
QUE DOIS JE FAIRE MAINTENAN?,
vide ta corbeille
_______
supprime combofix de ton ordinateur
____________
télécharge OTMoveIt
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
Citation :
C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc11.exe
C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc12.exe
C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc16.part
C:\WINDOWS\PSEXESVC.EXE
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
__________________
si tout c'est bien passé désactive la restauration système pour purger les virus qui seraient dedans
puis redemarre ton ordi
puis réactive là : https://www.informatruc.com
___________________
encore des problèmes
_______
supprime combofix de ton ordinateur
____________
télécharge OTMoveIt
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
Citation :
C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc11.exe
C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc12.exe
C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc16.part
C:\WINDOWS\PSEXESVC.EXE
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
__________________
si tout c'est bien passé désactive la restauration système pour purger les virus qui seraient dedans
puis redemarre ton ordi
puis réactive là : https://www.informatruc.com
___________________
encore des problèmes
salut voici le résultat
File/Folder C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc11.exe not found.
File/Folder C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc12.exe not found.
File/Folder C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc16.part not found.
C:\WINDOWS\PSEXESVC.EXE moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05172008_163455
File/Folder C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc11.exe not found.
File/Folder C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc12.exe not found.
File/Folder C:\RECYCLER\S-1-5-21-575791932-3721507337-1765965167-1006\Dc16.part not found.
C:\WINDOWS\PSEXESVC.EXE moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05172008_163455
la a l'air d'aller mieux meme si lorsque je veux instaler xp3 avc explorer il bloque une fois sur 2.De toute façon il y a des progrés certains!!
Par contre xp3 s'arrete après la clef du registre et l'acces est refusé!
Je pense changer d'antivirus :que me conseilles tu pour remplacer avast.
merci
salutations
Par contre xp3 s'arrete après la clef du registre et l'acces est refusé!
Je pense changer d'antivirus :que me conseilles tu pour remplacer avast.
merci
salutations
utilise ccleaner pour nettoyer ton ordi
https://www.malekal.com/tutoriel-ccleaner/
__________
installe antivir a la place d'avast et colle un rapport
https://www.malekal.com/avira-free-security-antivirus-gratuit/
___________
recolle un hijakchtis et dis tes soucis
https://www.malekal.com/tutoriel-ccleaner/
__________
installe antivir a la place d'avast et colle un rapport
https://www.malekal.com/avira-free-security-antivirus-gratuit/
___________
recolle un hijakchtis et dis tes soucis
merci encore pour tes conseils
j'ai changé l'antivirus
voici les résultats des scan antivir et hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34, on 2008-05-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://secam.mine.nu:81/VatDec.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1192391109734
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://secam.mine.nu:8002/activex/AMC.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
j'ai changé l'antivirus
voici les résultats des scan antivir et hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34, on 2008-05-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://secam.mine.nu:81/VatDec.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1192391109734
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://secam.mine.nu:8002/activex/AMC.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
vire spyware doctor
_____________
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://secam.mine.nu:81/VatDec.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://secam.mine.nu:8002/activex/AMC.cab
_______________
Il y a qlque chose qui me chagrine sur le rapport hijackthis , j'aimerai que l'on arrête le service concernant Boonty Games ( nid à spam et autres )
Voici une petite information sur Boonty games
Leur politique :
"Il se peut que nous partageons aussi des informations payantes avec des tiers
qui fournissent des services payants et partage des données regroupées montrant le type
et le nombre de jeux vidéos que vous téléchargez, votre age, votre sexe, vos occupations,
niveau d'éducation, localité géographique, données sur l'équipement de votre ordinateur,
internet et intérêts pour les jeux vidéos, activités et entraînement des jeux édités.
De plus, nous partageons les adresses email avec des tiers fournisseurs de compte mails
qui nous assistent en envoyant nos mails a de nombreux clients en même temps..."
Si tu n'y vois aucune objection , libre à toi ... on passe
sinon pour supprimer :
fais ceci :
« Démarrer » > « Executer » > taper cmd > valide par ok
dans la fenetre noire tape ceci en respectant bien les espaces et guillemets
sc stop "Boonty Games" ==> [Enter]
sc config "Boonty Games" start= disabled ==> [Enter]
sc delete "Boonty Games" ==> [Enter]
* Double-clique sur OTMoveIt.exe pour lancer le programme,
* Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste Custom List of Files/Folders to Move" :
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Program Files\boontyGames
C:\Program Files\boonty
* Clique sur MoveIt! pour lancer la suppression,
* Le résultat appraraîtra dans le cadre Results.
* Clique sur Exit pour fermer le programme.
* Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
* Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.
post le rapport de ot_move it ainsi qu´un nouveau hijack this
_______________________
voilà si pas de souci c'est fini
pour protéger gratos ton ordi
http://www.commentcamarche.net/telecharger/logiciel 4 securite
mettre un antivirus
AVAST en français ou ANTIVIR (en anglais mais très efficace)
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
-------------
des anti-espions :
MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
WINDOWS DEFENDER ou SPYWARE TERMINATOR
+
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
Rq : spybot et ad-aware ont sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
--------
un pare feu :
celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)
http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm
-----------
CCLEANER pour effacer les traces de surf
---------
naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
http://www.mozilla-europe.org/fr/products/firefox/
_____________
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://secam.mine.nu:81/VatDec.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://secam.mine.nu:8002/activex/AMC.cab
_______________
Il y a qlque chose qui me chagrine sur le rapport hijackthis , j'aimerai que l'on arrête le service concernant Boonty Games ( nid à spam et autres )
Voici une petite information sur Boonty games
Leur politique :
"Il se peut que nous partageons aussi des informations payantes avec des tiers
qui fournissent des services payants et partage des données regroupées montrant le type
et le nombre de jeux vidéos que vous téléchargez, votre age, votre sexe, vos occupations,
niveau d'éducation, localité géographique, données sur l'équipement de votre ordinateur,
internet et intérêts pour les jeux vidéos, activités et entraînement des jeux édités.
De plus, nous partageons les adresses email avec des tiers fournisseurs de compte mails
qui nous assistent en envoyant nos mails a de nombreux clients en même temps..."
Si tu n'y vois aucune objection , libre à toi ... on passe
sinon pour supprimer :
fais ceci :
« Démarrer » > « Executer » > taper cmd > valide par ok
dans la fenetre noire tape ceci en respectant bien les espaces et guillemets
sc stop "Boonty Games" ==> [Enter]
sc config "Boonty Games" start= disabled ==> [Enter]
sc delete "Boonty Games" ==> [Enter]
* Double-clique sur OTMoveIt.exe pour lancer le programme,
* Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste Custom List of Files/Folders to Move" :
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Program Files\boontyGames
C:\Program Files\boonty
* Clique sur MoveIt! pour lancer la suppression,
* Le résultat appraraîtra dans le cadre Results.
* Clique sur Exit pour fermer le programme.
* Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
* Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.
post le rapport de ot_move it ainsi qu´un nouveau hijack this
_______________________
voilà si pas de souci c'est fini
pour protéger gratos ton ordi
http://www.commentcamarche.net/telecharger/logiciel 4 securite
mettre un antivirus
AVAST en français ou ANTIVIR (en anglais mais très efficace)
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
-------------
des anti-espions :
MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
WINDOWS DEFENDER ou SPYWARE TERMINATOR
+
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
Rq : spybot et ad-aware ont sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
--------
un pare feu :
celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)
http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm
-----------
CCLEANER pour effacer les traces de surf
---------
naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
http://www.mozilla-europe.org/fr/products/firefox/
j'ai fait toutes les opérations demandées et voici les rapports:
je ne suis pas sur que cela fonctionne car il s'est bloqué quand j'ai ouvert ma page firefox comprenant l'ouverture simultanée du site l'équipe,eurosport et ebay
sinon je vais suivre tes précieux conseils pour mon pc
merci beaucoup!!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:51, on 2008-05-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Glary Utilities\memdefrag.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1192391109734
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
je ne suis pas sur que cela fonctionne car il s'est bloqué quand j'ai ouvert ma page firefox comprenant l'ouverture simultanée du site l'équipe,eurosport et ebay
sinon je vais suivre tes précieux conseils pour mon pc
merci beaucoup!!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:51, on 2008-05-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Glary Utilities\memdefrag.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Glary Memory Optimizer] "C:\Program Files\Glary Utilities\memdefrag.exe" /autostart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1192391109734
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
répare windows
https://www.pcastuces.com/pratique/windows/xp/default.htm
_________
recolle un rapport combofix
https://www.pcastuces.com/pratique/windows/xp/default.htm
_________
recolle un rapport combofix
voici le rapport
ComboFix 08-05-19.4 - MAMOUR 2008-05-20 19:49:45.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1551 [GMT 2:00]
Endroit: C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_004804_.tmp.dll
C:\WINDOWS\system32\_004805_.tmp.dll
C:\WINDOWS\system32\_004806_.tmp.dll
C:\WINDOWS\system32\_004807_.tmp.dll
C:\WINDOWS\system32\_004814_.tmp.dll
C:\WINDOWS\system32\_004816_.tmp.dll
C:\WINDOWS\system32\_004817_.tmp.dll
C:\WINDOWS\system32\_004818_.tmp.dll
C:\WINDOWS\system32\_004819_.tmp.dll
C:\WINDOWS\system32\_004820_.tmp.dll
C:\WINDOWS\system32\_004821_.tmp.dll
C:\WINDOWS\system32\_004822_.tmp.dll
C:\WINDOWS\system32\_004823_.tmp.dll
C:\WINDOWS\system32\_004824_.tmp.dll
C:\WINDOWS\system32\_004825_.tmp.dll
C:\WINDOWS\system32\_004826_.tmp.dll
C:\WINDOWS\system32\_004827_.tmp.dll
C:\WINDOWS\system32\_004828_.tmp.dll
C:\WINDOWS\system32\_004829_.tmp.dll
C:\WINDOWS\system32\_004830_.tmp.dll
C:\WINDOWS\system32\_004831_.tmp.dll
C:\WINDOWS\system32\_004832_.tmp.dll
C:\WINDOWS\system32\_004833_.tmp.dll
C:\WINDOWS\system32\_004834_.tmp.dll
C:\WINDOWS\system32\_004835_.tmp.dll
C:\WINDOWS\system32\_004836_.tmp.dll
C:\WINDOWS\system32\_004837_.tmp.dll
C:\WINDOWS\system32\_004838_.tmp.dll
C:\WINDOWS\system32\_004839_.tmp.dll
C:\WINDOWS\system32\_004840_.tmp.dll
C:\WINDOWS\system32\_004841_.tmp.dll
C:\WINDOWS\system32\_004842_.tmp.dll
C:\WINDOWS\system32\_004843_.tmp.dll
C:\WINDOWS\system32\_004844_.tmp.dll
C:\WINDOWS\system32\_004845_.tmp.dll
C:\WINDOWS\system32\_004846_.tmp.dll
C:\WINDOWS\system32\_004847_.tmp.dll
C:\WINDOWS\system32\_004849_.tmp.dll
C:\WINDOWS\system32\_004850_.tmp.dll
C:\WINDOWS\system32\_004851_.tmp.dll
C:\WINDOWS\system32\_004852_.tmp.dll
C:\WINDOWS\system32\_004853_.tmp.dll
C:\WINDOWS\system32\_004854_.tmp.dll
C:\WINDOWS\system32\_004855_.tmp.dll
C:\WINDOWS\system32\_004856_.tmp.dll
C:\WINDOWS\system32\_004857_.tmp.dll
C:\WINDOWS\system32\_004858_.tmp.dll
C:\WINDOWS\system32\_004859_.tmp.dll
C:\WINDOWS\system32\_004860_.tmp.dll
C:\WINDOWS\system32\_004861_.tmp.dll
C:\WINDOWS\system32\_004862_.tmp.dll
C:\WINDOWS\system32\_004863_.tmp.dll
C:\WINDOWS\system32\_004864_.tmp.dll
C:\WINDOWS\system32\_004865_.tmp.dll
C:\WINDOWS\system32\_004866_.tmp.dll
C:\WINDOWS\system32\_004867_.tmp.dll
C:\WINDOWS\system32\_004868_.tmp.dll
C:\WINDOWS\system32\_004869_.tmp.dll
C:\WINDOWS\system32\_004870_.tmp.dll
C:\WINDOWS\system32\_004871_.tmp.dll
C:\WINDOWS\system32\_004872_.tmp.dll
C:\WINDOWS\system32\_004873_.tmp.dll
C:\WINDOWS\system32\_004874_.tmp.dll
C:\WINDOWS\system32\_004875_.tmp.dll
C:\WINDOWS\system32\_004876_.tmp.dll
C:\WINDOWS\system32\_004877_.tmp.dll
C:\WINDOWS\system32\_004878_.tmp.dll
C:\WINDOWS\system32\_004879_.tmp.dll
C:\WINDOWS\system32\_004880_.tmp.dll
C:\WINDOWS\system32\_004881_.tmp.dll
C:\WINDOWS\system32\_004882_.tmp.dll
C:\WINDOWS\system32\_004883_.tmp.dll
C:\WINDOWS\system32\_004884_.tmp.dll
C:\WINDOWS\system32\_004885_.tmp.dll
C:\WINDOWS\system32\_004886_.tmp.dll
C:\WINDOWS\system32\_004887_.tmp.dll
C:\WINDOWS\system32\_004888_.tmp.dll
C:\WINDOWS\system32\_004889_.tmp.dll
C:\WINDOWS\system32\_004890_.tmp.dll
C:\WINDOWS\system32\_004891_.tmp.dll
C:\WINDOWS\system32\_004892_.tmp.dll
C:\WINDOWS\system32\_004893_.tmp.dll
C:\WINDOWS\system32\_004894_.tmp.dll
C:\WINDOWS\system32\_004895_.tmp.dll
C:\WINDOWS\system32\_004896_.tmp.dll
C:\WINDOWS\system32\_004897_.tmp.dll
C:\WINDOWS\system32\_004898_.tmp.dll
C:\WINDOWS\system32\_004899_.tmp.dll
C:\WINDOWS\system32\_004900_.tmp.dll
C:\WINDOWS\system32\_004901_.tmp.dll
C:\WINDOWS\system32\_004902_.tmp.dll
C:\WINDOWS\system32\_004903_.tmp.dll
C:\WINDOWS\system32\_004904_.tmp.dll
C:\WINDOWS\system32\_004905_.tmp.dll
C:\WINDOWS\system32\_004906_.tmp.dll
C:\WINDOWS\system32\_004907_.tmp.dll
C:\WINDOWS\system32\_004908_.tmp.dll
C:\WINDOWS\system32\_004909_.tmp.dll
C:\WINDOWS\system32\_004910_.tmp.dll
C:\WINDOWS\system32\_004911_.tmp.dll
C:\WINDOWS\system32\_004912_.tmp.dll
C:\WINDOWS\system32\_004913_.tmp.dll
C:\WINDOWS\system32\_004914_.tmp.dll
C:\WINDOWS\system32\_004915_.tmp.dll
C:\WINDOWS\system32\_004916_.tmp.dll
C:\WINDOWS\system32\_004917_.tmp.dll
C:\WINDOWS\system32\_004918_.tmp.dll
C:\WINDOWS\system32\_004919_.tmp.dll
C:\WINDOWS\system32\_004920_.tmp.dll
C:\WINDOWS\system32\_004921_.tmp.dll
C:\WINDOWS\system32\_004922_.tmp.dll
C:\WINDOWS\system32\_004923_.tmp.dll
C:\WINDOWS\system32\_004924_.tmp.dll
C:\WINDOWS\system32\_004925_.tmp.dll
C:\WINDOWS\system32\_004926_.tmp.dll
C:\WINDOWS\system32\_004927_.tmp.dll
C:\WINDOWS\system32\_004928_.tmp.dll
C:\WINDOWS\system32\_004929_.tmp.dll
C:\WINDOWS\system32\_004930_.tmp.dll
C:\WINDOWS\system32\_004931_.tmp.dll
C:\WINDOWS\system32\_004932_.tmp.dll
C:\WINDOWS\system32\_004933_.tmp.dll
C:\WINDOWS\system32\_004934_.tmp.dll
C:\WINDOWS\system32\_004935_.tmp.dll
C:\WINDOWS\system32\_004936_.tmp.dll
C:\WINDOWS\system32\_004937_.tmp.dll
C:\WINDOWS\system32\_004938_.tmp.dll
C:\WINDOWS\system32\_004939_.tmp.dll
C:\WINDOWS\system32\_004940_.tmp.dll
C:\WINDOWS\system32\_004941_.tmp.dll
C:\WINDOWS\system32\_004942_.tmp.dll
C:\WINDOWS\system32\_004943_.tmp.dll
C:\WINDOWS\system32\_004944_.tmp.dll
C:\WINDOWS\system32\_004945_.tmp.dll
C:\WINDOWS\system32\_004946_.tmp.dll
C:\WINDOWS\system32\_004947_.tmp.dll
C:\WINDOWS\system32\_004948_.tmp.dll
C:\WINDOWS\system32\_004949_.tmp.dll
C:\WINDOWS\system32\_004950_.tmp.dll
C:\WINDOWS\system32\_004951_.tmp.dll
C:\WINDOWS\system32\_004952_.tmp.dll
C:\WINDOWS\system32\_004953_.tmp.dll
C:\WINDOWS\system32\_004954_.tmp.dll
C:\WINDOWS\system32\_004955_.tmp.dll
C:\WINDOWS\system32\_004956_.tmp.dll
C:\WINDOWS\system32\_004957_.tmp.dll
C:\WINDOWS\system32\_004958_.tmp.dll
C:\WINDOWS\system32\_004959_.tmp.dll
C:\WINDOWS\system32\_004960_.tmp.dll
C:\WINDOWS\system32\_004961_.tmp.dll
C:\WINDOWS\system32\_004962_.tmp.dll
C:\WINDOWS\system32\_004963_.tmp.dll
C:\WINDOWS\system32\_004964_.tmp.dll
C:\WINDOWS\system32\_004965_.tmp.dll
C:\WINDOWS\system32\_004966_.tmp.dll
C:\WINDOWS\system32\_004967_.tmp.dll
C:\WINDOWS\system32\_004968_.tmp.dll
C:\WINDOWS\system32\_004969_.tmp.dll
C:\WINDOWS\system32\_004970_.tmp.dll
C:\WINDOWS\system32\_004971_.tmp.dll
C:\WINDOWS\system32\_004972_.tmp.dll
C:\WINDOWS\system32\_004973_.tmp.dll
C:\WINDOWS\system32\_004974_.tmp.dll
C:\WINDOWS\system32\_004975_.tmp.dll
C:\WINDOWS\system32\_004976_.tmp.dll
C:\WINDOWS\system32\_004978_.tmp.dll
C:\WINDOWS\system32\_004979_.tmp.dll
C:\WINDOWS\system32\_004980_.tmp.dll
C:\WINDOWS\system32\_004982_.tmp.dll
C:\WINDOWS\system32\_004983_.tmp.dll
C:\WINDOWS\system32\_004984_.tmp.dll
C:\WINDOWS\system32\_004985_.tmp.dll
C:\WINDOWS\system32\_004986_.tmp.dll
C:\WINDOWS\system32\_004987_.tmp.dll
C:\WINDOWS\system32\_004988_.tmp.dll
C:\WINDOWS\system32\_004989_.tmp.dll
C:\WINDOWS\system32\_004990_.tmp.dll
C:\WINDOWS\system32\_004991_.tmp.dll
C:\WINDOWS\system32\_004992_.tmp.dll
C:\WINDOWS\system32\_004993_.tmp.dll
C:\WINDOWS\system32\_004994_.tmp.dll
C:\WINDOWS\system32\_004995_.tmp.dll
C:\WINDOWS\system32\_004996_.tmp.dll
C:\WINDOWS\system32\_004997_.tmp.dll
C:\WINDOWS\system32\_004998_.tmp.dll
C:\WINDOWS\system32\_004999_.tmp.dll
C:\WINDOWS\system32\_005000_.tmp.dll
C:\WINDOWS\system32\_005001_.tmp.dll
C:\WINDOWS\system32\_005003_.tmp.dll
C:\WINDOWS\system32\_005004_.tmp.dll
C:\WINDOWS\system32\_005005_.tmp.dll
C:\WINDOWS\system32\_005006_.tmp.dll
C:\WINDOWS\system32\_005008_.tmp.dll
C:\WINDOWS\system32\_005010_.tmp.dll
C:\WINDOWS\system32\_005011_.tmp.dll
C:\WINDOWS\system32\_005012_.tmp.dll
C:\WINDOWS\system32\_005014_.tmp.dll
C:\WINDOWS\system32\_005015_.tmp.dll
C:\WINDOWS\system32\_005016_.tmp.dll
C:\WINDOWS\system32\_005017_.tmp.dll
C:\WINDOWS\system32\_005018_.tmp.dll
C:\WINDOWS\system32\_005019_.tmp.dll
C:\WINDOWS\system32\_005020_.tmp.dll
C:\WINDOWS\system32\_005021_.tmp.dll
C:\WINDOWS\system32\_005022_.tmp.dll
C:\WINDOWS\system32\_005023_.tmp.dll
C:\WINDOWS\system32\_005024_.tmp.dll
C:\WINDOWS\system32\_005025_.tmp.dll
C:\WINDOWS\system32\_005026_.tmp.dll
C:\WINDOWS\system32\_005027_.tmp.dll
C:\WINDOWS\system32\_005028_.tmp.dll
C:\WINDOWS\system32\_005029_.tmp.dll
C:\WINDOWS\system32\_005030_.tmp.dll
C:\WINDOWS\system32\_005031_.tmp.dll
C:\WINDOWS\system32\_005032_.tmp.dll
C:\WINDOWS\system32\_005033_.tmp.dll
C:\WINDOWS\system32\_005035_.tmp.dll
C:\WINDOWS\system32\_005036_.tmp.dll
C:\WINDOWS\system32\_005037_.tmp.dll
C:\WINDOWS\system32\_005038_.tmp.dll
C:\WINDOWS\system32\_005040_.tmp.dll
C:\WINDOWS\system32\_005042_.tmp.dll
C:\WINDOWS\system32\_005043_.tmp.dll
C:\WINDOWS\system32\_005044_.tmp.dll
C:\WINDOWS\system32\_005046_.tmp.dll
C:\WINDOWS\system32\_005047_.tmp.dll
C:\WINDOWS\system32\_005048_.tmp.dll
C:\WINDOWS\system32\_005049_.tmp.dll
C:\WINDOWS\system32\_005050_.tmp.dll
C:\WINDOWS\system32\_005051_.tmp.dll
C:\WINDOWS\system32\_005052_.tmp.dll
C:\WINDOWS\system32\_005053_.tmp.dll
C:\WINDOWS\system32\_005054_.tmp.dll
C:\WINDOWS\system32\_005055_.tmp.dll
C:\WINDOWS\system32\_005056_.tmp.dll
C:\WINDOWS\system32\_005057_.tmp.dll
C:\WINDOWS\system32\_005059_.tmp.dll
C:\WINDOWS\system32\_005061_.tmp.dll
C:\WINDOWS\system32\_005063_.tmp.dll
C:\WINDOWS\system32\_005064_.tmp.dll
C:\WINDOWS\system32\_005065_.tmp.dll
C:\WINDOWS\system32\_005069_.tmp.dll
C:\WINDOWS\system32\_005070_.tmp.dll
C:\WINDOWS\system32\_005072_.tmp.dll
C:\WINDOWS\system32\_005075_.tmp.dll
C:\WINDOWS\system32\_005078_.tmp.dll
C:\WINDOWS\system32\_005079_.tmp.dll
C:\WINDOWS\system32\_005080_.tmp.dll
C:\WINDOWS\system32\_005081_.tmp.dll
C:\WINDOWS\system32\_005084_.tmp.dll
C:\WINDOWS\system32\_005085_.tmp.dll
C:\WINDOWS\system32\_005086_.tmp.dll
C:\WINDOWS\system32\_005087_.tmp.dll
C:\WINDOWS\system32\_005088_.tmp.dll
C:\WINDOWS\system32\_005093_.tmp.dll
C:\WINDOWS\system32\_005095_.tmp.dll
C:\WINDOWS\system32\MSINET.oca
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-20 to 2008-05-20 ))))))))))))))))))))))))))))))))))))
.
2008-05-19 20:37 . 2008-05-19 20:40 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\MSBuild
2008-05-19 20:36 . 2008-05-19 20:36 <REP> d-------- C:\Program Files\MSXML 6.0
2008-05-19 20:36 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-19 20:01 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET194D.tmp
2008-05-19 20:01 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1970.tmp
2008-05-19 20:01 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET193F.tmp
2008-05-19 20:01 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1972.tmp
2008-05-19 20:01 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET193A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET194A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET1995.tmp
2008-05-19 20:01 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET199C.tmp
2008-05-19 20:01 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1943.tmp
2008-05-19 20:01 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1937.tmp
2008-05-19 19:56 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETB9B.tmp
2008-05-19 19:55 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET9B4.tmp
2008-05-19 19:53 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003195_.tmp
2008-05-19 19:19 . 2008-05-20 19:05 <REP> d-------- C:\Program Files\Mozilla Sunbird
2008-05-18 22:07 . 2008-05-18 22:08 <REP> d-------- C:\Program Files\SpywareBlaster
2008-05-17 17:40 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET185D.tmp
2008-05-17 17:40 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1880.tmp
2008-05-17 17:40 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET184F.tmp
2008-05-17 17:40 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1882.tmp
2008-05-17 17:40 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET184A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET185A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET18A5.tmp
2008-05-17 17:40 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET18AC.tmp
2008-05-17 17:40 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1853.tmp
2008-05-17 17:40 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1847.tmp
2008-05-17 17:35 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETAB9.tmp
2008-05-17 17:34 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET8D2.tmp
2008-05-17 17:32 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003186_.tmp
2008-05-17 17:30 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004836_.tmp.dll
2008-05-17 16:34 . 2008-05-17 16:34 <REP> d-------- C:\_OTMoveIt
2008-05-17 15:21 . 2008-05-17 15:21 <REP> dr-h----- C:\Documents and Settings\MAMOUR\Application Data\SecuROM
2008-05-16 12:40 . 2008-05-16 13:47 <REP> d-------- C:\Program Files\BitDefender
2008-05-16 11:50 . 2008-05-16 11:50 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Program Files\Avira
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-14 15:09 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-14 14:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-13 21:01 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004825_.tmp.dll
2008-05-13 19:29 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET16A8.tmp
2008-05-13 19:29 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET16CB.tmp
2008-05-13 19:29 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET169A.tmp
2008-05-13 19:29 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET16CD.tmp
2008-05-13 19:29 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET1695.tmp
2008-05-13 19:29 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET16A5.tmp
2008-05-13 19:29 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET16F0.tmp
2008-05-13 19:29 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET169E.tmp
2008-05-13 19:29 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1692.tmp
2008-05-13 19:26 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SET8EB.tmp
2008-05-13 19:25 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET667.tmp
2008-05-13 19:23 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003184_.tmp
2008-05-13 19:21 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004851_.tmp.dll
2008-05-12 21:08 . 2008-05-12 21:08 <REP> d-------- C:\Program Files\OFFICE One6.5
2008-05-12 17:42 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004841_.tmp.dll
2008-05-10 13:07 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004831_.tmp.dll
2008-05-09 13:23 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004821_.tmp.dll
2008-05-09 06:14 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004811_.tmp.dll
2008-05-07 21:03 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004801_.tmp.dll
2008-05-06 22:40 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\fr
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\system32\bits
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\l2schemas
2008-05-06 22:33 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004791_.tmp.dll
2008-05-06 22:31 . 2008-05-19 19:50 <REP> d-------- C:\WINDOWS\EHome
2008-05-06 21:41 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-03 09:19 . 2008-05-03 09:19 <REP> d-------- C:\Program Files\EA GAMES
2008-05-02 05:39 . 2008-05-02 05:39 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Panasonic
2008-04-27 22:50 . 2008-05-03 06:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-24 11:32 . 2008-04-24 11:32 26 --a------ C:\UpdaterforApp.ini
2008-04-24 11:29 . 2008-04-24 11:29 <REP> d-------- C:\WINDOWS\system32\MediaImpression Slideshow
2008-04-24 11:29 . 2008-04-24 11:32 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2008-04-24 11:29 . 2007-03-07 16:05 126,976 --a------ C:\WINDOWS\system32\MediaImpression Slideshow.scr
2008-04-24 11:29 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-04-24 11:27 . 2008-04-24 11:27 <REP> d-------- C:\Program Files\Panasonic
2008-04-23 23:00 . 2008-04-23 23:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-23 11:05 . 2008-04-23 11:05 <REP> d-------- C:\Program Files\Electronic Arts
2008-04-23 11:04 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-04-21 22:14 . 2008-04-21 22:14 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-21 10:43 . 2008-04-21 12:29 <REP> d-------- C:\Program Files\a-squared Free
2008-04-20 17:14 . 2008-05-10 20:06 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-04-20 13:10 . 2008-04-20 13:10 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-04-20 13:10 . 2008-04-20 16:47 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\FileZilla
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 17:36 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\OpenOffice.org2
2008-05-20 17:09 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-19 18:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-19 17:07 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-17 17:49 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\Spamihilator
2008-05-17 16:55 --------- d-----w C:\Program Files\Google
2008-05-17 14:50 --------- d-----w C:\Program Files\Fichiers communs\Softwin
2008-05-17 14:32 --------- d-----w C:\Program Files\Panda Security
2008-05-16 10:40 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-05-16 05:29 --------- d-----w C:\Program Files\eMule
2008-05-14 12:08 --------- d-----w C:\Program Files\Navilog1
2008-05-13 16:32 8 -c--a-w C:\Documents and Settings\MAMOUR\.bztarotcumul.dat
2008-05-10 16:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-10 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 16:09 1,362 -c--a-w C:\Documents and Settings\MAMOUR\Application Data\wklnhst.dat
2008-05-05 04:04 --------- d-----w C:\Program Files\Glary Utilities
2008-04-24 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 09:29 --------- d-----w C:\Program Files\ArcSoft
2008-04-23 21:00 --------- d-----w C:\Program Files\Lavasoft
2008-04-23 20:59 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-21 20:13 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-04-21 20:11 --------- d-----w C:\Program Files\Java
2008-04-19 15:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-04-19 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microgaming
2008-04-15 08:40 --------- d-----w C:\Program Files\DivX
2008-04-14 10:31 --------- d-----w C:\Program Files\gps1
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SETB70.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET9B0.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET947.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET8E7.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET6E4.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B8.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B2.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\SETE3C.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setd4c.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setb97.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\SETE3B.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setd4b.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setb96.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\SETE3A.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setd4a.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setb95.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETD7C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETC8C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETAD6.tmp
2008-04-03 04:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 15:52 --------- d-----w C:\Program Files\RegCleaner
2008-04-01 15:36 --------- d-----w C:\Program Files\Jeune Styliste
2008-04-01 15:34 --------- d-----w C:\Program Files\Hewlett-Packard
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci vers Program Files.lnk
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci (2) vers Program Files.lnk
2006-10-06 07:02 3,185,570 -c--a-w C:\Documents and Settings\MAMOUR\trop_fort.zip
2006-10-02 16:36 3,782,230 -c--a-w C:\Documents and Settings\MAMOUR\wc2.zip
2006-03-19 11:23 256 -c--a-w C:\Program Files\SAVEGAME
2006-03-19 09:52 4,730 -c--a-w C:\Program Files\DeIsL2.isu
2006-03-04 07:22 163 -c-ha-w C:\Documents and Settings\MAMOUR\hpothb07.dat
2006-01-07 16:01 3,401 -c--a-w C:\Program Files\DeIsL1.isu
2006-01-07 16:01 17,825,792 -c--a-w C:\Program Files\pcdogs.pkg
2005-12-27 11:51 164 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-12-27 11:51 0 -c-ha-w C:\Documents and Settings\MAMOUR\Application Data\hpothb07.dat
2003-09-29 10:17 766 -c--a-w C:\Program Files\register.ico
2003-09-29 10:17 593,920 -c--a-w C:\Program Files\THH.exe
2003-09-29 10:17 49,152 -c--a-w C:\Program Files\inetwh32.dll
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\untigghh.ico
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\tiggerhh.ico
2003-09-29 10:17 4,528 -c--a-w C:\Program Files\setbrows.exe
2003-09-29 10:17 30,720 -c--a-w C:\Program Files\remove.dll
2003-09-29 10:17 2,449,408 -c--a-w C:\Program Files\Launcher.exe
2003-09-29 10:17 155 -c--a-w C:\Program Files\title.txt
2003-09-29 10:17 1,698,135 -c--a-w C:\Program Files\TiggerHH.hlp
2003-09-29 10:17 1,584 -c--a-w C:\Program Files\uninst.ini
2000-12-21 12:25 446,464 -c--a-w C:\Program Files\Pcdogs.exe
2000-11-17 14:22 439 -c--a-w C:\Program Files\D3D.log
2000-11-08 16:27 111 -c--a-w C:\Program Files\pcdogs.ini
2000-10-18 15:34 2,251,695 -c--a-w C:\Program Files\102Dalms.hlp
2000-08-18 15:26 630 -c--a-w C:\Program Files\unin102D.ico
2000-08-18 15:25 630 -c--a-w C:\Program Files\102Dalms.ico
2000-07-10 15:33 11 -c--a-w C:\Program Files\message.log
1999-11-01 16:56 327,680 -c--a-w C:\Program Files\mss32.dll
1997-08-14 17:31 98,816 -c--a-w C:\Program Files\DEC130.DLL
1997-08-14 17:24 89,600 -c--a-w C:\Program Files\WINSDEC.DLL
1997-08-14 17:17 117,248 -c--a-w C:\Program Files\EDEC.DLL
1997-08-14 17:06 60,416 -c--a-w C:\Program Files\WINPLAY.DLL
1997-08-14 12:10 80,896 -c--a-w C:\Program Files\WINSTR.DLL
1996-01-25 17:45 39,936 -c--a-w C:\Program Files\D2HTLS32.DLL
1996-01-24 21:43 202,752 -c--a-w C:\Program Files\D2HLNK32.DLL
1995-07-11 09:50 322,832 -c--a-w C:\Program Files\MFC30.DLL
1995-07-11 09:50 253,952 -c--a-w C:\Program Files\MSVCRT20.DLL
.
((((((((((((((((((((((((((((( snapshot@2008-05-20_19.00.48.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 16:52:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-20 17:55:21 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 10:35 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]
"Glary Memory Optimizer"="C:\Program Files\Glary Utilities\memdefrag.exe" [2008-03-05 10:23 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 05:51 29744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-05 12:26 5566464]
"ArcSoft Connection Service"="C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 08:45 31232]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Docteur Club Internet.lnk]
backup=C:\WINDOWS\pss\Docteur Club Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NkbMonitor.exe.lnk]
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^MAMOUR^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
backup=C:\WINDOWS\pss\Club Internet.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
--a--c--- 2003-05-02 11:31 24576 c:\apps\ABoard\ABoard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailChecker]
--a--c--- 2003-07-02 11:13 40960 C:\APPS\EmailChecker\ech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-05-20 05:51 29744 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a--c--- 2004-08-05 14:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a--c--- 2004-10-08 12:06 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2004-10-08 12:31 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a--c--- 2004-10-08 12:24 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-10-08 11:52 221184 C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-03-05 12:26 5566464 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2005-01-28 11:10 110740 c:\Apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StandardInstall]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmtalk]
--a--c--- 2003-07-24 17:21 61440 C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SLService"=2 (0x2)
"SAVScan"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"navapsvc"=2 (0x2)
"MysqlInventime"=3 (0x3)
"ISSVC"=2 (0x2)
"GenericHidService"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"AOL ACS"=2 (0x2)
"Service CANALPLAY"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys [2004-10-11 16:28]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 08:45]
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2005-11-04 12:38]
S1 lkbdhlpr;Logitech Keyboard Class Helper Driver;C:\WINDOWS\system32\Drivers\lkbdhlpr.sys []
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys []
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2006-03-26 21:15]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 05:51]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys []
S3 SA2KMD;STEL Modem;C:\WINDOWS\system32\DRIVERS\sa2kmd.sys [2004-05-11 03:03]
S3 SA2KPT;STEL OBEX PORT;C:\WINDOWS\system32\DRIVERS\sa2kpt.sys [2004-05-11 03:03]
S3 SACTL;STEL USB HOST DRIVER;C:\WINDOWS\system32\DRIVERS\sactl.sys [2004-05-11 03:02]
S3 SAENUM;STEL Enum Driver;C:\WINDOWS\system32\DRIVERS\saenum.sys [2004-05-11 03:02]
S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-10-08 11:54]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-05 14:00]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-20 17:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-20 17:55:43 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-20 17:58:31 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-05-20 17:23:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
ComboFix 08-05-19.4 - MAMOUR 2008-05-20 19:49:45.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1551 [GMT 2:00]
Endroit: C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_004804_.tmp.dll
C:\WINDOWS\system32\_004805_.tmp.dll
C:\WINDOWS\system32\_004806_.tmp.dll
C:\WINDOWS\system32\_004807_.tmp.dll
C:\WINDOWS\system32\_004814_.tmp.dll
C:\WINDOWS\system32\_004816_.tmp.dll
C:\WINDOWS\system32\_004817_.tmp.dll
C:\WINDOWS\system32\_004818_.tmp.dll
C:\WINDOWS\system32\_004819_.tmp.dll
C:\WINDOWS\system32\_004820_.tmp.dll
C:\WINDOWS\system32\_004821_.tmp.dll
C:\WINDOWS\system32\_004822_.tmp.dll
C:\WINDOWS\system32\_004823_.tmp.dll
C:\WINDOWS\system32\_004824_.tmp.dll
C:\WINDOWS\system32\_004825_.tmp.dll
C:\WINDOWS\system32\_004826_.tmp.dll
C:\WINDOWS\system32\_004827_.tmp.dll
C:\WINDOWS\system32\_004828_.tmp.dll
C:\WINDOWS\system32\_004829_.tmp.dll
C:\WINDOWS\system32\_004830_.tmp.dll
C:\WINDOWS\system32\_004831_.tmp.dll
C:\WINDOWS\system32\_004832_.tmp.dll
C:\WINDOWS\system32\_004833_.tmp.dll
C:\WINDOWS\system32\_004834_.tmp.dll
C:\WINDOWS\system32\_004835_.tmp.dll
C:\WINDOWS\system32\_004836_.tmp.dll
C:\WINDOWS\system32\_004837_.tmp.dll
C:\WINDOWS\system32\_004838_.tmp.dll
C:\WINDOWS\system32\_004839_.tmp.dll
C:\WINDOWS\system32\_004840_.tmp.dll
C:\WINDOWS\system32\_004841_.tmp.dll
C:\WINDOWS\system32\_004842_.tmp.dll
C:\WINDOWS\system32\_004843_.tmp.dll
C:\WINDOWS\system32\_004844_.tmp.dll
C:\WINDOWS\system32\_004845_.tmp.dll
C:\WINDOWS\system32\_004846_.tmp.dll
C:\WINDOWS\system32\_004847_.tmp.dll
C:\WINDOWS\system32\_004849_.tmp.dll
C:\WINDOWS\system32\_004850_.tmp.dll
C:\WINDOWS\system32\_004851_.tmp.dll
C:\WINDOWS\system32\_004852_.tmp.dll
C:\WINDOWS\system32\_004853_.tmp.dll
C:\WINDOWS\system32\_004854_.tmp.dll
C:\WINDOWS\system32\_004855_.tmp.dll
C:\WINDOWS\system32\_004856_.tmp.dll
C:\WINDOWS\system32\_004857_.tmp.dll
C:\WINDOWS\system32\_004858_.tmp.dll
C:\WINDOWS\system32\_004859_.tmp.dll
C:\WINDOWS\system32\_004860_.tmp.dll
C:\WINDOWS\system32\_004861_.tmp.dll
C:\WINDOWS\system32\_004862_.tmp.dll
C:\WINDOWS\system32\_004863_.tmp.dll
C:\WINDOWS\system32\_004864_.tmp.dll
C:\WINDOWS\system32\_004865_.tmp.dll
C:\WINDOWS\system32\_004866_.tmp.dll
C:\WINDOWS\system32\_004867_.tmp.dll
C:\WINDOWS\system32\_004868_.tmp.dll
C:\WINDOWS\system32\_004869_.tmp.dll
C:\WINDOWS\system32\_004870_.tmp.dll
C:\WINDOWS\system32\_004871_.tmp.dll
C:\WINDOWS\system32\_004872_.tmp.dll
C:\WINDOWS\system32\_004873_.tmp.dll
C:\WINDOWS\system32\_004874_.tmp.dll
C:\WINDOWS\system32\_004875_.tmp.dll
C:\WINDOWS\system32\_004876_.tmp.dll
C:\WINDOWS\system32\_004877_.tmp.dll
C:\WINDOWS\system32\_004878_.tmp.dll
C:\WINDOWS\system32\_004879_.tmp.dll
C:\WINDOWS\system32\_004880_.tmp.dll
C:\WINDOWS\system32\_004881_.tmp.dll
C:\WINDOWS\system32\_004882_.tmp.dll
C:\WINDOWS\system32\_004883_.tmp.dll
C:\WINDOWS\system32\_004884_.tmp.dll
C:\WINDOWS\system32\_004885_.tmp.dll
C:\WINDOWS\system32\_004886_.tmp.dll
C:\WINDOWS\system32\_004887_.tmp.dll
C:\WINDOWS\system32\_004888_.tmp.dll
C:\WINDOWS\system32\_004889_.tmp.dll
C:\WINDOWS\system32\_004890_.tmp.dll
C:\WINDOWS\system32\_004891_.tmp.dll
C:\WINDOWS\system32\_004892_.tmp.dll
C:\WINDOWS\system32\_004893_.tmp.dll
C:\WINDOWS\system32\_004894_.tmp.dll
C:\WINDOWS\system32\_004895_.tmp.dll
C:\WINDOWS\system32\_004896_.tmp.dll
C:\WINDOWS\system32\_004897_.tmp.dll
C:\WINDOWS\system32\_004898_.tmp.dll
C:\WINDOWS\system32\_004899_.tmp.dll
C:\WINDOWS\system32\_004900_.tmp.dll
C:\WINDOWS\system32\_004901_.tmp.dll
C:\WINDOWS\system32\_004902_.tmp.dll
C:\WINDOWS\system32\_004903_.tmp.dll
C:\WINDOWS\system32\_004904_.tmp.dll
C:\WINDOWS\system32\_004905_.tmp.dll
C:\WINDOWS\system32\_004906_.tmp.dll
C:\WINDOWS\system32\_004907_.tmp.dll
C:\WINDOWS\system32\_004908_.tmp.dll
C:\WINDOWS\system32\_004909_.tmp.dll
C:\WINDOWS\system32\_004910_.tmp.dll
C:\WINDOWS\system32\_004911_.tmp.dll
C:\WINDOWS\system32\_004912_.tmp.dll
C:\WINDOWS\system32\_004913_.tmp.dll
C:\WINDOWS\system32\_004914_.tmp.dll
C:\WINDOWS\system32\_004915_.tmp.dll
C:\WINDOWS\system32\_004916_.tmp.dll
C:\WINDOWS\system32\_004917_.tmp.dll
C:\WINDOWS\system32\_004918_.tmp.dll
C:\WINDOWS\system32\_004919_.tmp.dll
C:\WINDOWS\system32\_004920_.tmp.dll
C:\WINDOWS\system32\_004921_.tmp.dll
C:\WINDOWS\system32\_004922_.tmp.dll
C:\WINDOWS\system32\_004923_.tmp.dll
C:\WINDOWS\system32\_004924_.tmp.dll
C:\WINDOWS\system32\_004925_.tmp.dll
C:\WINDOWS\system32\_004926_.tmp.dll
C:\WINDOWS\system32\_004927_.tmp.dll
C:\WINDOWS\system32\_004928_.tmp.dll
C:\WINDOWS\system32\_004929_.tmp.dll
C:\WINDOWS\system32\_004930_.tmp.dll
C:\WINDOWS\system32\_004931_.tmp.dll
C:\WINDOWS\system32\_004932_.tmp.dll
C:\WINDOWS\system32\_004933_.tmp.dll
C:\WINDOWS\system32\_004934_.tmp.dll
C:\WINDOWS\system32\_004935_.tmp.dll
C:\WINDOWS\system32\_004936_.tmp.dll
C:\WINDOWS\system32\_004937_.tmp.dll
C:\WINDOWS\system32\_004938_.tmp.dll
C:\WINDOWS\system32\_004939_.tmp.dll
C:\WINDOWS\system32\_004940_.tmp.dll
C:\WINDOWS\system32\_004941_.tmp.dll
C:\WINDOWS\system32\_004942_.tmp.dll
C:\WINDOWS\system32\_004943_.tmp.dll
C:\WINDOWS\system32\_004944_.tmp.dll
C:\WINDOWS\system32\_004945_.tmp.dll
C:\WINDOWS\system32\_004946_.tmp.dll
C:\WINDOWS\system32\_004947_.tmp.dll
C:\WINDOWS\system32\_004948_.tmp.dll
C:\WINDOWS\system32\_004949_.tmp.dll
C:\WINDOWS\system32\_004950_.tmp.dll
C:\WINDOWS\system32\_004951_.tmp.dll
C:\WINDOWS\system32\_004952_.tmp.dll
C:\WINDOWS\system32\_004953_.tmp.dll
C:\WINDOWS\system32\_004954_.tmp.dll
C:\WINDOWS\system32\_004955_.tmp.dll
C:\WINDOWS\system32\_004956_.tmp.dll
C:\WINDOWS\system32\_004957_.tmp.dll
C:\WINDOWS\system32\_004958_.tmp.dll
C:\WINDOWS\system32\_004959_.tmp.dll
C:\WINDOWS\system32\_004960_.tmp.dll
C:\WINDOWS\system32\_004961_.tmp.dll
C:\WINDOWS\system32\_004962_.tmp.dll
C:\WINDOWS\system32\_004963_.tmp.dll
C:\WINDOWS\system32\_004964_.tmp.dll
C:\WINDOWS\system32\_004965_.tmp.dll
C:\WINDOWS\system32\_004966_.tmp.dll
C:\WINDOWS\system32\_004967_.tmp.dll
C:\WINDOWS\system32\_004968_.tmp.dll
C:\WINDOWS\system32\_004969_.tmp.dll
C:\WINDOWS\system32\_004970_.tmp.dll
C:\WINDOWS\system32\_004971_.tmp.dll
C:\WINDOWS\system32\_004972_.tmp.dll
C:\WINDOWS\system32\_004973_.tmp.dll
C:\WINDOWS\system32\_004974_.tmp.dll
C:\WINDOWS\system32\_004975_.tmp.dll
C:\WINDOWS\system32\_004976_.tmp.dll
C:\WINDOWS\system32\_004978_.tmp.dll
C:\WINDOWS\system32\_004979_.tmp.dll
C:\WINDOWS\system32\_004980_.tmp.dll
C:\WINDOWS\system32\_004982_.tmp.dll
C:\WINDOWS\system32\_004983_.tmp.dll
C:\WINDOWS\system32\_004984_.tmp.dll
C:\WINDOWS\system32\_004985_.tmp.dll
C:\WINDOWS\system32\_004986_.tmp.dll
C:\WINDOWS\system32\_004987_.tmp.dll
C:\WINDOWS\system32\_004988_.tmp.dll
C:\WINDOWS\system32\_004989_.tmp.dll
C:\WINDOWS\system32\_004990_.tmp.dll
C:\WINDOWS\system32\_004991_.tmp.dll
C:\WINDOWS\system32\_004992_.tmp.dll
C:\WINDOWS\system32\_004993_.tmp.dll
C:\WINDOWS\system32\_004994_.tmp.dll
C:\WINDOWS\system32\_004995_.tmp.dll
C:\WINDOWS\system32\_004996_.tmp.dll
C:\WINDOWS\system32\_004997_.tmp.dll
C:\WINDOWS\system32\_004998_.tmp.dll
C:\WINDOWS\system32\_004999_.tmp.dll
C:\WINDOWS\system32\_005000_.tmp.dll
C:\WINDOWS\system32\_005001_.tmp.dll
C:\WINDOWS\system32\_005003_.tmp.dll
C:\WINDOWS\system32\_005004_.tmp.dll
C:\WINDOWS\system32\_005005_.tmp.dll
C:\WINDOWS\system32\_005006_.tmp.dll
C:\WINDOWS\system32\_005008_.tmp.dll
C:\WINDOWS\system32\_005010_.tmp.dll
C:\WINDOWS\system32\_005011_.tmp.dll
C:\WINDOWS\system32\_005012_.tmp.dll
C:\WINDOWS\system32\_005014_.tmp.dll
C:\WINDOWS\system32\_005015_.tmp.dll
C:\WINDOWS\system32\_005016_.tmp.dll
C:\WINDOWS\system32\_005017_.tmp.dll
C:\WINDOWS\system32\_005018_.tmp.dll
C:\WINDOWS\system32\_005019_.tmp.dll
C:\WINDOWS\system32\_005020_.tmp.dll
C:\WINDOWS\system32\_005021_.tmp.dll
C:\WINDOWS\system32\_005022_.tmp.dll
C:\WINDOWS\system32\_005023_.tmp.dll
C:\WINDOWS\system32\_005024_.tmp.dll
C:\WINDOWS\system32\_005025_.tmp.dll
C:\WINDOWS\system32\_005026_.tmp.dll
C:\WINDOWS\system32\_005027_.tmp.dll
C:\WINDOWS\system32\_005028_.tmp.dll
C:\WINDOWS\system32\_005029_.tmp.dll
C:\WINDOWS\system32\_005030_.tmp.dll
C:\WINDOWS\system32\_005031_.tmp.dll
C:\WINDOWS\system32\_005032_.tmp.dll
C:\WINDOWS\system32\_005033_.tmp.dll
C:\WINDOWS\system32\_005035_.tmp.dll
C:\WINDOWS\system32\_005036_.tmp.dll
C:\WINDOWS\system32\_005037_.tmp.dll
C:\WINDOWS\system32\_005038_.tmp.dll
C:\WINDOWS\system32\_005040_.tmp.dll
C:\WINDOWS\system32\_005042_.tmp.dll
C:\WINDOWS\system32\_005043_.tmp.dll
C:\WINDOWS\system32\_005044_.tmp.dll
C:\WINDOWS\system32\_005046_.tmp.dll
C:\WINDOWS\system32\_005047_.tmp.dll
C:\WINDOWS\system32\_005048_.tmp.dll
C:\WINDOWS\system32\_005049_.tmp.dll
C:\WINDOWS\system32\_005050_.tmp.dll
C:\WINDOWS\system32\_005051_.tmp.dll
C:\WINDOWS\system32\_005052_.tmp.dll
C:\WINDOWS\system32\_005053_.tmp.dll
C:\WINDOWS\system32\_005054_.tmp.dll
C:\WINDOWS\system32\_005055_.tmp.dll
C:\WINDOWS\system32\_005056_.tmp.dll
C:\WINDOWS\system32\_005057_.tmp.dll
C:\WINDOWS\system32\_005059_.tmp.dll
C:\WINDOWS\system32\_005061_.tmp.dll
C:\WINDOWS\system32\_005063_.tmp.dll
C:\WINDOWS\system32\_005064_.tmp.dll
C:\WINDOWS\system32\_005065_.tmp.dll
C:\WINDOWS\system32\_005069_.tmp.dll
C:\WINDOWS\system32\_005070_.tmp.dll
C:\WINDOWS\system32\_005072_.tmp.dll
C:\WINDOWS\system32\_005075_.tmp.dll
C:\WINDOWS\system32\_005078_.tmp.dll
C:\WINDOWS\system32\_005079_.tmp.dll
C:\WINDOWS\system32\_005080_.tmp.dll
C:\WINDOWS\system32\_005081_.tmp.dll
C:\WINDOWS\system32\_005084_.tmp.dll
C:\WINDOWS\system32\_005085_.tmp.dll
C:\WINDOWS\system32\_005086_.tmp.dll
C:\WINDOWS\system32\_005087_.tmp.dll
C:\WINDOWS\system32\_005088_.tmp.dll
C:\WINDOWS\system32\_005093_.tmp.dll
C:\WINDOWS\system32\_005095_.tmp.dll
C:\WINDOWS\system32\MSINET.oca
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-20 to 2008-05-20 ))))))))))))))))))))))))))))))))))))
.
2008-05-19 20:37 . 2008-05-19 20:40 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\MSBuild
2008-05-19 20:36 . 2008-05-19 20:36 <REP> d-------- C:\Program Files\MSXML 6.0
2008-05-19 20:36 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-19 20:01 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET194D.tmp
2008-05-19 20:01 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1970.tmp
2008-05-19 20:01 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET193F.tmp
2008-05-19 20:01 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1972.tmp
2008-05-19 20:01 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET193A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET194A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET1995.tmp
2008-05-19 20:01 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET199C.tmp
2008-05-19 20:01 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1943.tmp
2008-05-19 20:01 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1937.tmp
2008-05-19 19:56 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETB9B.tmp
2008-05-19 19:55 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET9B4.tmp
2008-05-19 19:53 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003195_.tmp
2008-05-19 19:19 . 2008-05-20 19:05 <REP> d-------- C:\Program Files\Mozilla Sunbird
2008-05-18 22:07 . 2008-05-18 22:08 <REP> d-------- C:\Program Files\SpywareBlaster
2008-05-17 17:40 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET185D.tmp
2008-05-17 17:40 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1880.tmp
2008-05-17 17:40 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET184F.tmp
2008-05-17 17:40 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1882.tmp
2008-05-17 17:40 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET184A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET185A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET18A5.tmp
2008-05-17 17:40 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET18AC.tmp
2008-05-17 17:40 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1853.tmp
2008-05-17 17:40 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1847.tmp
2008-05-17 17:35 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETAB9.tmp
2008-05-17 17:34 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET8D2.tmp
2008-05-17 17:32 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003186_.tmp
2008-05-17 17:30 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004836_.tmp.dll
2008-05-17 16:34 . 2008-05-17 16:34 <REP> d-------- C:\_OTMoveIt
2008-05-17 15:21 . 2008-05-17 15:21 <REP> dr-h----- C:\Documents and Settings\MAMOUR\Application Data\SecuROM
2008-05-16 12:40 . 2008-05-16 13:47 <REP> d-------- C:\Program Files\BitDefender
2008-05-16 11:50 . 2008-05-16 11:50 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Program Files\Avira
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-14 15:09 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-14 14:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-13 21:01 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004825_.tmp.dll
2008-05-13 19:29 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET16A8.tmp
2008-05-13 19:29 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET16CB.tmp
2008-05-13 19:29 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET169A.tmp
2008-05-13 19:29 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET16CD.tmp
2008-05-13 19:29 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET1695.tmp
2008-05-13 19:29 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET16A5.tmp
2008-05-13 19:29 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET16F0.tmp
2008-05-13 19:29 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET169E.tmp
2008-05-13 19:29 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1692.tmp
2008-05-13 19:26 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SET8EB.tmp
2008-05-13 19:25 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET667.tmp
2008-05-13 19:23 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003184_.tmp
2008-05-13 19:21 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004851_.tmp.dll
2008-05-12 21:08 . 2008-05-12 21:08 <REP> d-------- C:\Program Files\OFFICE One6.5
2008-05-12 17:42 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004841_.tmp.dll
2008-05-10 13:07 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004831_.tmp.dll
2008-05-09 13:23 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004821_.tmp.dll
2008-05-09 06:14 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004811_.tmp.dll
2008-05-07 21:03 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004801_.tmp.dll
2008-05-06 22:40 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\fr
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\system32\bits
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\l2schemas
2008-05-06 22:33 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004791_.tmp.dll
2008-05-06 22:31 . 2008-05-19 19:50 <REP> d-------- C:\WINDOWS\EHome
2008-05-06 21:41 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-03 09:19 . 2008-05-03 09:19 <REP> d-------- C:\Program Files\EA GAMES
2008-05-02 05:39 . 2008-05-02 05:39 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Panasonic
2008-04-27 22:50 . 2008-05-03 06:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-24 11:32 . 2008-04-24 11:32 26 --a------ C:\UpdaterforApp.ini
2008-04-24 11:29 . 2008-04-24 11:29 <REP> d-------- C:\WINDOWS\system32\MediaImpression Slideshow
2008-04-24 11:29 . 2008-04-24 11:32 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2008-04-24 11:29 . 2007-03-07 16:05 126,976 --a------ C:\WINDOWS\system32\MediaImpression Slideshow.scr
2008-04-24 11:29 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-04-24 11:27 . 2008-04-24 11:27 <REP> d-------- C:\Program Files\Panasonic
2008-04-23 23:00 . 2008-04-23 23:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-23 11:05 . 2008-04-23 11:05 <REP> d-------- C:\Program Files\Electronic Arts
2008-04-23 11:04 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-04-21 22:14 . 2008-04-21 22:14 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-21 10:43 . 2008-04-21 12:29 <REP> d-------- C:\Program Files\a-squared Free
2008-04-20 17:14 . 2008-05-10 20:06 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-04-20 13:10 . 2008-04-20 13:10 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-04-20 13:10 . 2008-04-20 16:47 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\FileZilla
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 17:36 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\OpenOffice.org2
2008-05-20 17:09 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-19 18:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-19 17:07 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-17 17:49 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\Spamihilator
2008-05-17 16:55 --------- d-----w C:\Program Files\Google
2008-05-17 14:50 --------- d-----w C:\Program Files\Fichiers communs\Softwin
2008-05-17 14:32 --------- d-----w C:\Program Files\Panda Security
2008-05-16 10:40 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-05-16 05:29 --------- d-----w C:\Program Files\eMule
2008-05-14 12:08 --------- d-----w C:\Program Files\Navilog1
2008-05-13 16:32 8 -c--a-w C:\Documents and Settings\MAMOUR\.bztarotcumul.dat
2008-05-10 16:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-10 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 16:09 1,362 -c--a-w C:\Documents and Settings\MAMOUR\Application Data\wklnhst.dat
2008-05-05 04:04 --------- d-----w C:\Program Files\Glary Utilities
2008-04-24 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 09:29 --------- d-----w C:\Program Files\ArcSoft
2008-04-23 21:00 --------- d-----w C:\Program Files\Lavasoft
2008-04-23 20:59 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-21 20:13 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-04-21 20:11 --------- d-----w C:\Program Files\Java
2008-04-19 15:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-04-19 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microgaming
2008-04-15 08:40 --------- d-----w C:\Program Files\DivX
2008-04-14 10:31 --------- d-----w C:\Program Files\gps1
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SETB70.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET9B0.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET947.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET8E7.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET6E4.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B8.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B2.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\SETE3C.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setd4c.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setb97.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\SETE3B.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setd4b.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setb96.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\SETE3A.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setd4a.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setb95.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETD7C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETC8C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETAD6.tmp
2008-04-03 04:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 15:52 --------- d-----w C:\Program Files\RegCleaner
2008-04-01 15:36 --------- d-----w C:\Program Files\Jeune Styliste
2008-04-01 15:34 --------- d-----w C:\Program Files\Hewlett-Packard
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci vers Program Files.lnk
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci (2) vers Program Files.lnk
2006-10-06 07:02 3,185,570 -c--a-w C:\Documents and Settings\MAMOUR\trop_fort.zip
2006-10-02 16:36 3,782,230 -c--a-w C:\Documents and Settings\MAMOUR\wc2.zip
2006-03-19 11:23 256 -c--a-w C:\Program Files\SAVEGAME
2006-03-19 09:52 4,730 -c--a-w C:\Program Files\DeIsL2.isu
2006-03-04 07:22 163 -c-ha-w C:\Documents and Settings\MAMOUR\hpothb07.dat
2006-01-07 16:01 3,401 -c--a-w C:\Program Files\DeIsL1.isu
2006-01-07 16:01 17,825,792 -c--a-w C:\Program Files\pcdogs.pkg
2005-12-27 11:51 164 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-12-27 11:51 0 -c-ha-w C:\Documents and Settings\MAMOUR\Application Data\hpothb07.dat
2003-09-29 10:17 766 -c--a-w C:\Program Files\register.ico
2003-09-29 10:17 593,920 -c--a-w C:\Program Files\THH.exe
2003-09-29 10:17 49,152 -c--a-w C:\Program Files\inetwh32.dll
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\untigghh.ico
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\tiggerhh.ico
2003-09-29 10:17 4,528 -c--a-w C:\Program Files\setbrows.exe
2003-09-29 10:17 30,720 -c--a-w C:\Program Files\remove.dll
2003-09-29 10:17 2,449,408 -c--a-w C:\Program Files\Launcher.exe
2003-09-29 10:17 155 -c--a-w C:\Program Files\title.txt
2003-09-29 10:17 1,698,135 -c--a-w C:\Program Files\TiggerHH.hlp
2003-09-29 10:17 1,584 -c--a-w C:\Program Files\uninst.ini
2000-12-21 12:25 446,464 -c--a-w C:\Program Files\Pcdogs.exe
2000-11-17 14:22 439 -c--a-w C:\Program Files\D3D.log
2000-11-08 16:27 111 -c--a-w C:\Program Files\pcdogs.ini
2000-10-18 15:34 2,251,695 -c--a-w C:\Program Files\102Dalms.hlp
2000-08-18 15:26 630 -c--a-w C:\Program Files\unin102D.ico
2000-08-18 15:25 630 -c--a-w C:\Program Files\102Dalms.ico
2000-07-10 15:33 11 -c--a-w C:\Program Files\message.log
1999-11-01 16:56 327,680 -c--a-w C:\Program Files\mss32.dll
1997-08-14 17:31 98,816 -c--a-w C:\Program Files\DEC130.DLL
1997-08-14 17:24 89,600 -c--a-w C:\Program Files\WINSDEC.DLL
1997-08-14 17:17 117,248 -c--a-w C:\Program Files\EDEC.DLL
1997-08-14 17:06 60,416 -c--a-w C:\Program Files\WINPLAY.DLL
1997-08-14 12:10 80,896 -c--a-w C:\Program Files\WINSTR.DLL
1996-01-25 17:45 39,936 -c--a-w C:\Program Files\D2HTLS32.DLL
1996-01-24 21:43 202,752 -c--a-w C:\Program Files\D2HLNK32.DLL
1995-07-11 09:50 322,832 -c--a-w C:\Program Files\MFC30.DLL
1995-07-11 09:50 253,952 -c--a-w C:\Program Files\MSVCRT20.DLL
.
((((((((((((((((((((((((((((( snapshot@2008-05-20_19.00.48.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 16:52:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-20 17:55:21 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 10:35 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]
"Glary Memory Optimizer"="C:\Program Files\Glary Utilities\memdefrag.exe" [2008-03-05 10:23 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 05:51 29744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-05 12:26 5566464]
"ArcSoft Connection Service"="C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 08:45 31232]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Docteur Club Internet.lnk]
backup=C:\WINDOWS\pss\Docteur Club Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NkbMonitor.exe.lnk]
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^MAMOUR^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
backup=C:\WINDOWS\pss\Club Internet.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
--a--c--- 2003-05-02 11:31 24576 c:\apps\ABoard\ABoard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailChecker]
--a--c--- 2003-07-02 11:13 40960 C:\APPS\EmailChecker\ech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-05-20 05:51 29744 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a--c--- 2004-08-05 14:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a--c--- 2004-10-08 12:06 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2004-10-08 12:31 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a--c--- 2004-10-08 12:24 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-10-08 11:52 221184 C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-03-05 12:26 5566464 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2005-01-28 11:10 110740 c:\Apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StandardInstall]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmtalk]
--a--c--- 2003-07-24 17:21 61440 C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SLService"=2 (0x2)
"SAVScan"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"navapsvc"=2 (0x2)
"MysqlInventime"=3 (0x3)
"ISSVC"=2 (0x2)
"GenericHidService"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"AOL ACS"=2 (0x2)
"Service CANALPLAY"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys [2004-10-11 16:28]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 08:45]
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2005-11-04 12:38]
S1 lkbdhlpr;Logitech Keyboard Class Helper Driver;C:\WINDOWS\system32\Drivers\lkbdhlpr.sys []
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys []
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2006-03-26 21:15]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 05:51]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys []
S3 SA2KMD;STEL Modem;C:\WINDOWS\system32\DRIVERS\sa2kmd.sys [2004-05-11 03:03]
S3 SA2KPT;STEL OBEX PORT;C:\WINDOWS\system32\DRIVERS\sa2kpt.sys [2004-05-11 03:03]
S3 SACTL;STEL USB HOST DRIVER;C:\WINDOWS\system32\DRIVERS\sactl.sys [2004-05-11 03:02]
S3 SAENUM;STEL Enum Driver;C:\WINDOWS\system32\DRIVERS\saenum.sys [2004-05-11 03:02]
S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-10-08 11:54]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-05 14:00]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-20 17:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-20 17:55:43 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-20 17:58:31 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-05-20 17:23:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
refais en un nouveau puis dis moi tes soucis
voici le nouveau scan je te econtacte demain soir si problemes
merci
ComboFix 08-05-19.4 - MAMOUR 2008-05-20 21:20:19.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1545 [GMT 2:00]
Endroit: C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_004804_.tmp.dll
C:\WINDOWS\system32\_004805_.tmp.dll
C:\WINDOWS\system32\_004806_.tmp.dll
C:\WINDOWS\system32\_004807_.tmp.dll
C:\WINDOWS\system32\_004814_.tmp.dll
C:\WINDOWS\system32\_004816_.tmp.dll
C:\WINDOWS\system32\_004817_.tmp.dll
C:\WINDOWS\system32\_004818_.tmp.dll
C:\WINDOWS\system32\_004819_.tmp.dll
C:\WINDOWS\system32\_004820_.tmp.dll
C:\WINDOWS\system32\_004821_.tmp.dll
C:\WINDOWS\system32\_004822_.tmp.dll
C:\WINDOWS\system32\_004823_.tmp.dll
C:\WINDOWS\system32\_004824_.tmp.dll
C:\WINDOWS\system32\_004825_.tmp.dll
C:\WINDOWS\system32\_004826_.tmp.dll
C:\WINDOWS\system32\_004827_.tmp.dll
C:\WINDOWS\system32\_004828_.tmp.dll
C:\WINDOWS\system32\_004829_.tmp.dll
C:\WINDOWS\system32\_004830_.tmp.dll
C:\WINDOWS\system32\_004831_.tmp.dll
C:\WINDOWS\system32\_004832_.tmp.dll
C:\WINDOWS\system32\_004833_.tmp.dll
C:\WINDOWS\system32\_004834_.tmp.dll
C:\WINDOWS\system32\_004835_.tmp.dll
C:\WINDOWS\system32\_004836_.tmp.dll
C:\WINDOWS\system32\_004837_.tmp.dll
C:\WINDOWS\system32\_004838_.tmp.dll
C:\WINDOWS\system32\_004839_.tmp.dll
C:\WINDOWS\system32\_004840_.tmp.dll
C:\WINDOWS\system32\_004841_.tmp.dll
C:\WINDOWS\system32\_004842_.tmp.dll
C:\WINDOWS\system32\_004843_.tmp.dll
C:\WINDOWS\system32\_004844_.tmp.dll
C:\WINDOWS\system32\_004845_.tmp.dll
C:\WINDOWS\system32\_004846_.tmp.dll
C:\WINDOWS\system32\_004847_.tmp.dll
C:\WINDOWS\system32\_004849_.tmp.dll
C:\WINDOWS\system32\_004850_.tmp.dll
C:\WINDOWS\system32\_004851_.tmp.dll
C:\WINDOWS\system32\_004852_.tmp.dll
C:\WINDOWS\system32\_004853_.tmp.dll
C:\WINDOWS\system32\_004854_.tmp.dll
C:\WINDOWS\system32\_004855_.tmp.dll
C:\WINDOWS\system32\_004856_.tmp.dll
C:\WINDOWS\system32\_004857_.tmp.dll
C:\WINDOWS\system32\_004858_.tmp.dll
C:\WINDOWS\system32\_004859_.tmp.dll
C:\WINDOWS\system32\_004860_.tmp.dll
C:\WINDOWS\system32\_004861_.tmp.dll
C:\WINDOWS\system32\_004862_.tmp.dll
C:\WINDOWS\system32\_004863_.tmp.dll
C:\WINDOWS\system32\_004864_.tmp.dll
C:\WINDOWS\system32\_004865_.tmp.dll
C:\WINDOWS\system32\_004866_.tmp.dll
C:\WINDOWS\system32\_004867_.tmp.dll
C:\WINDOWS\system32\_004868_.tmp.dll
C:\WINDOWS\system32\_004869_.tmp.dll
C:\WINDOWS\system32\_004870_.tmp.dll
C:\WINDOWS\system32\_004871_.tmp.dll
C:\WINDOWS\system32\_004872_.tmp.dll
C:\WINDOWS\system32\_004873_.tmp.dll
C:\WINDOWS\system32\_004874_.tmp.dll
C:\WINDOWS\system32\_004875_.tmp.dll
C:\WINDOWS\system32\_004876_.tmp.dll
C:\WINDOWS\system32\_004877_.tmp.dll
C:\WINDOWS\system32\_004878_.tmp.dll
C:\WINDOWS\system32\_004879_.tmp.dll
C:\WINDOWS\system32\_004880_.tmp.dll
C:\WINDOWS\system32\_004881_.tmp.dll
C:\WINDOWS\system32\_004882_.tmp.dll
C:\WINDOWS\system32\_004883_.tmp.dll
C:\WINDOWS\system32\_004884_.tmp.dll
C:\WINDOWS\system32\_004885_.tmp.dll
C:\WINDOWS\system32\_004886_.tmp.dll
C:\WINDOWS\system32\_004887_.tmp.dll
C:\WINDOWS\system32\_004888_.tmp.dll
C:\WINDOWS\system32\_004889_.tmp.dll
C:\WINDOWS\system32\_004890_.tmp.dll
C:\WINDOWS\system32\_004891_.tmp.dll
C:\WINDOWS\system32\_004892_.tmp.dll
C:\WINDOWS\system32\_004893_.tmp.dll
C:\WINDOWS\system32\_004894_.tmp.dll
C:\WINDOWS\system32\_004895_.tmp.dll
C:\WINDOWS\system32\_004896_.tmp.dll
C:\WINDOWS\system32\_004897_.tmp.dll
C:\WINDOWS\system32\_004898_.tmp.dll
C:\WINDOWS\system32\_004899_.tmp.dll
C:\WINDOWS\system32\_004900_.tmp.dll
C:\WINDOWS\system32\_004901_.tmp.dll
C:\WINDOWS\system32\_004902_.tmp.dll
C:\WINDOWS\system32\_004903_.tmp.dll
C:\WINDOWS\system32\_004904_.tmp.dll
C:\WINDOWS\system32\_004905_.tmp.dll
C:\WINDOWS\system32\_004906_.tmp.dll
C:\WINDOWS\system32\_004907_.tmp.dll
C:\WINDOWS\system32\_004908_.tmp.dll
C:\WINDOWS\system32\_004909_.tmp.dll
C:\WINDOWS\system32\_004910_.tmp.dll
C:\WINDOWS\system32\_004911_.tmp.dll
C:\WINDOWS\system32\_004912_.tmp.dll
C:\WINDOWS\system32\_004913_.tmp.dll
C:\WINDOWS\system32\_004914_.tmp.dll
C:\WINDOWS\system32\_004915_.tmp.dll
C:\WINDOWS\system32\_004916_.tmp.dll
C:\WINDOWS\system32\_004917_.tmp.dll
C:\WINDOWS\system32\_004918_.tmp.dll
C:\WINDOWS\system32\_004919_.tmp.dll
C:\WINDOWS\system32\_004920_.tmp.dll
C:\WINDOWS\system32\_004921_.tmp.dll
C:\WINDOWS\system32\_004922_.tmp.dll
C:\WINDOWS\system32\_004923_.tmp.dll
C:\WINDOWS\system32\_004924_.tmp.dll
C:\WINDOWS\system32\_004925_.tmp.dll
C:\WINDOWS\system32\_004926_.tmp.dll
C:\WINDOWS\system32\_004927_.tmp.dll
C:\WINDOWS\system32\_004928_.tmp.dll
C:\WINDOWS\system32\_004929_.tmp.dll
C:\WINDOWS\system32\_004930_.tmp.dll
C:\WINDOWS\system32\_004931_.tmp.dll
C:\WINDOWS\system32\_004932_.tmp.dll
C:\WINDOWS\system32\_004933_.tmp.dll
C:\WINDOWS\system32\_004934_.tmp.dll
C:\WINDOWS\system32\_004935_.tmp.dll
C:\WINDOWS\system32\_004936_.tmp.dll
C:\WINDOWS\system32\_004937_.tmp.dll
C:\WINDOWS\system32\_004938_.tmp.dll
C:\WINDOWS\system32\_004939_.tmp.dll
C:\WINDOWS\system32\_004940_.tmp.dll
C:\WINDOWS\system32\_004941_.tmp.dll
C:\WINDOWS\system32\_004942_.tmp.dll
C:\WINDOWS\system32\_004943_.tmp.dll
C:\WINDOWS\system32\_004944_.tmp.dll
C:\WINDOWS\system32\_004945_.tmp.dll
C:\WINDOWS\system32\_004946_.tmp.dll
C:\WINDOWS\system32\_004947_.tmp.dll
C:\WINDOWS\system32\_004948_.tmp.dll
C:\WINDOWS\system32\_004949_.tmp.dll
C:\WINDOWS\system32\_004950_.tmp.dll
C:\WINDOWS\system32\_004951_.tmp.dll
C:\WINDOWS\system32\_004952_.tmp.dll
C:\WINDOWS\system32\_004953_.tmp.dll
C:\WINDOWS\system32\_004954_.tmp.dll
C:\WINDOWS\system32\_004955_.tmp.dll
C:\WINDOWS\system32\_004956_.tmp.dll
C:\WINDOWS\system32\_004957_.tmp.dll
C:\WINDOWS\system32\_004958_.tmp.dll
C:\WINDOWS\system32\_004959_.tmp.dll
C:\WINDOWS\system32\_004960_.tmp.dll
C:\WINDOWS\system32\_004961_.tmp.dll
C:\WINDOWS\system32\_004962_.tmp.dll
C:\WINDOWS\system32\_004963_.tmp.dll
C:\WINDOWS\system32\_004964_.tmp.dll
C:\WINDOWS\system32\_004965_.tmp.dll
C:\WINDOWS\system32\_004966_.tmp.dll
C:\WINDOWS\system32\_004967_.tmp.dll
C:\WINDOWS\system32\_004968_.tmp.dll
C:\WINDOWS\system32\_004969_.tmp.dll
C:\WINDOWS\system32\_004970_.tmp.dll
C:\WINDOWS\system32\_004971_.tmp.dll
C:\WINDOWS\system32\_004972_.tmp.dll
C:\WINDOWS\system32\_004973_.tmp.dll
C:\WINDOWS\system32\_004974_.tmp.dll
C:\WINDOWS\system32\_004975_.tmp.dll
C:\WINDOWS\system32\_004976_.tmp.dll
C:\WINDOWS\system32\_004978_.tmp.dll
C:\WINDOWS\system32\_004979_.tmp.dll
C:\WINDOWS\system32\_004980_.tmp.dll
C:\WINDOWS\system32\_004982_.tmp.dll
C:\WINDOWS\system32\_004983_.tmp.dll
C:\WINDOWS\system32\_004984_.tmp.dll
C:\WINDOWS\system32\_004985_.tmp.dll
C:\WINDOWS\system32\_004986_.tmp.dll
C:\WINDOWS\system32\_004987_.tmp.dll
C:\WINDOWS\system32\_004988_.tmp.dll
C:\WINDOWS\system32\_004989_.tmp.dll
C:\WINDOWS\system32\_004990_.tmp.dll
C:\WINDOWS\system32\_004991_.tmp.dll
C:\WINDOWS\system32\_004992_.tmp.dll
C:\WINDOWS\system32\_004993_.tmp.dll
C:\WINDOWS\system32\_004994_.tmp.dll
C:\WINDOWS\system32\_004995_.tmp.dll
C:\WINDOWS\system32\_004996_.tmp.dll
C:\WINDOWS\system32\_004997_.tmp.dll
C:\WINDOWS\system32\_004998_.tmp.dll
C:\WINDOWS\system32\_004999_.tmp.dll
C:\WINDOWS\system32\_005000_.tmp.dll
C:\WINDOWS\system32\_005001_.tmp.dll
C:\WINDOWS\system32\_005003_.tmp.dll
C:\WINDOWS\system32\_005004_.tmp.dll
C:\WINDOWS\system32\_005005_.tmp.dll
C:\WINDOWS\system32\_005006_.tmp.dll
C:\WINDOWS\system32\_005008_.tmp.dll
C:\WINDOWS\system32\_005010_.tmp.dll
C:\WINDOWS\system32\_005011_.tmp.dll
C:\WINDOWS\system32\_005012_.tmp.dll
C:\WINDOWS\system32\_005014_.tmp.dll
C:\WINDOWS\system32\_005015_.tmp.dll
C:\WINDOWS\system32\_005016_.tmp.dll
C:\WINDOWS\system32\_005017_.tmp.dll
C:\WINDOWS\system32\_005018_.tmp.dll
C:\WINDOWS\system32\_005019_.tmp.dll
C:\WINDOWS\system32\_005020_.tmp.dll
C:\WINDOWS\system32\_005021_.tmp.dll
C:\WINDOWS\system32\_005022_.tmp.dll
C:\WINDOWS\system32\_005023_.tmp.dll
C:\WINDOWS\system32\_005024_.tmp.dll
C:\WINDOWS\system32\_005025_.tmp.dll
C:\WINDOWS\system32\_005026_.tmp.dll
C:\WINDOWS\system32\_005027_.tmp.dll
C:\WINDOWS\system32\_005028_.tmp.dll
C:\WINDOWS\system32\_005029_.tmp.dll
C:\WINDOWS\system32\_005030_.tmp.dll
C:\WINDOWS\system32\_005031_.tmp.dll
C:\WINDOWS\system32\_005032_.tmp.dll
C:\WINDOWS\system32\_005033_.tmp.dll
C:\WINDOWS\system32\_005035_.tmp.dll
C:\WINDOWS\system32\_005036_.tmp.dll
C:\WINDOWS\system32\_005037_.tmp.dll
C:\WINDOWS\system32\_005038_.tmp.dll
C:\WINDOWS\system32\_005040_.tmp.dll
C:\WINDOWS\system32\_005042_.tmp.dll
C:\WINDOWS\system32\_005043_.tmp.dll
C:\WINDOWS\system32\_005044_.tmp.dll
C:\WINDOWS\system32\_005046_.tmp.dll
C:\WINDOWS\system32\_005047_.tmp.dll
C:\WINDOWS\system32\_005048_.tmp.dll
C:\WINDOWS\system32\_005049_.tmp.dll
C:\WINDOWS\system32\_005050_.tmp.dll
C:\WINDOWS\system32\_005051_.tmp.dll
C:\WINDOWS\system32\_005052_.tmp.dll
C:\WINDOWS\system32\_005053_.tmp.dll
C:\WINDOWS\system32\_005054_.tmp.dll
C:\WINDOWS\system32\_005055_.tmp.dll
C:\WINDOWS\system32\_005056_.tmp.dll
C:\WINDOWS\system32\_005057_.tmp.dll
C:\WINDOWS\system32\_005059_.tmp.dll
C:\WINDOWS\system32\_005061_.tmp.dll
C:\WINDOWS\system32\_005063_.tmp.dll
C:\WINDOWS\system32\_005064_.tmp.dll
C:\WINDOWS\system32\_005065_.tmp.dll
C:\WINDOWS\system32\_005069_.tmp.dll
C:\WINDOWS\system32\_005070_.tmp.dll
C:\WINDOWS\system32\_005072_.tmp.dll
C:\WINDOWS\system32\_005075_.tmp.dll
C:\WINDOWS\system32\_005078_.tmp.dll
C:\WINDOWS\system32\_005079_.tmp.dll
C:\WINDOWS\system32\_005080_.tmp.dll
C:\WINDOWS\system32\_005081_.tmp.dll
C:\WINDOWS\system32\_005084_.tmp.dll
C:\WINDOWS\system32\_005085_.tmp.dll
C:\WINDOWS\system32\_005086_.tmp.dll
C:\WINDOWS\system32\_005087_.tmp.dll
C:\WINDOWS\system32\_005088_.tmp.dll
C:\WINDOWS\system32\_005093_.tmp.dll
C:\WINDOWS\system32\_005095_.tmp.dll
C:\WINDOWS\system32\MSINET.oca
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-20 to 2008-05-20 ))))))))))))))))))))))))))))))))))))
.
2008-05-19 20:37 . 2008-05-19 20:40 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\MSBuild
2008-05-19 20:36 . 2008-05-19 20:36 <REP> d-------- C:\Program Files\MSXML 6.0
2008-05-19 20:36 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-19 20:01 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET194D.tmp
2008-05-19 20:01 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1970.tmp
2008-05-19 20:01 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET193F.tmp
2008-05-19 20:01 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1972.tmp
2008-05-19 20:01 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET193A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET194A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET1995.tmp
2008-05-19 20:01 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET199C.tmp
2008-05-19 20:01 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1943.tmp
2008-05-19 20:01 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1937.tmp
2008-05-19 19:56 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETB9B.tmp
2008-05-19 19:55 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET9B4.tmp
2008-05-19 19:53 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003195_.tmp
2008-05-19 19:19 . 2008-05-20 19:05 <REP> d-------- C:\Program Files\Mozilla Sunbird
2008-05-18 22:07 . 2008-05-18 22:08 <REP> d-------- C:\Program Files\SpywareBlaster
2008-05-17 17:40 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET185D.tmp
2008-05-17 17:40 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1880.tmp
2008-05-17 17:40 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET184F.tmp
2008-05-17 17:40 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1882.tmp
2008-05-17 17:40 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET184A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET185A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET18A5.tmp
2008-05-17 17:40 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET18AC.tmp
2008-05-17 17:40 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1853.tmp
2008-05-17 17:40 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1847.tmp
2008-05-17 17:35 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETAB9.tmp
2008-05-17 17:34 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET8D2.tmp
2008-05-17 17:32 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003186_.tmp
2008-05-17 17:30 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004836_.tmp.dll
2008-05-17 16:34 . 2008-05-17 16:34 <REP> d-------- C:\_OTMoveIt
2008-05-17 15:21 . 2008-05-17 15:21 <REP> dr-h----- C:\Documents and Settings\MAMOUR\Application Data\SecuROM
2008-05-16 12:40 . 2008-05-16 13:47 <REP> d-------- C:\Program Files\BitDefender
2008-05-16 11:50 . 2008-05-16 11:50 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Program Files\Avira
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-14 15:09 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-14 14:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-13 21:01 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004825_.tmp.dll
2008-05-13 19:29 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET16A8.tmp
2008-05-13 19:29 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET16CB.tmp
2008-05-13 19:29 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET169A.tmp
2008-05-13 19:29 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET16CD.tmp
2008-05-13 19:29 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET1695.tmp
2008-05-13 19:29 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET16A5.tmp
2008-05-13 19:29 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET16F0.tmp
2008-05-13 19:29 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET169E.tmp
2008-05-13 19:29 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1692.tmp
2008-05-13 19:26 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SET8EB.tmp
2008-05-13 19:25 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET667.tmp
2008-05-13 19:23 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003184_.tmp
2008-05-13 19:21 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004851_.tmp.dll
2008-05-12 21:08 . 2008-05-12 21:08 <REP> d-------- C:\Program Files\OFFICE One6.5
2008-05-12 17:42 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004841_.tmp.dll
2008-05-10 13:07 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004831_.tmp.dll
2008-05-09 13:23 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004821_.tmp.dll
2008-05-09 06:14 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004811_.tmp.dll
2008-05-07 21:03 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004801_.tmp.dll
2008-05-06 22:40 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\fr
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\system32\bits
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\l2schemas
2008-05-06 22:33 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004791_.tmp.dll
2008-05-06 22:31 . 2008-05-19 19:50 <REP> d-------- C:\WINDOWS\EHome
2008-05-06 21:41 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-03 09:19 . 2008-05-03 09:19 <REP> d-------- C:\Program Files\EA GAMES
2008-05-02 05:39 . 2008-05-02 05:39 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Panasonic
2008-04-27 22:50 . 2008-05-03 06:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-24 11:32 . 2008-04-24 11:32 26 --a------ C:\UpdaterforApp.ini
2008-04-24 11:29 . 2008-04-24 11:29 <REP> d-------- C:\WINDOWS\system32\MediaImpression Slideshow
2008-04-24 11:29 . 2008-04-24 11:32 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2008-04-24 11:29 . 2007-03-07 16:05 126,976 --a------ C:\WINDOWS\system32\MediaImpression Slideshow.scr
2008-04-24 11:29 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-04-24 11:27 . 2008-04-24 11:27 <REP> d-------- C:\Program Files\Panasonic
2008-04-23 23:00 . 2008-04-23 23:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-23 11:05 . 2008-04-23 11:05 <REP> d-------- C:\Program Files\Electronic Arts
2008-04-23 11:04 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-04-21 22:14 . 2008-04-21 22:14 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-21 10:43 . 2008-04-21 12:29 <REP> d-------- C:\Program Files\a-squared Free
2008-04-20 17:14 . 2008-05-10 20:06 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-04-20 13:10 . 2008-04-20 13:10 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-04-20 13:10 . 2008-04-20 16:47 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\FileZilla
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 18:14 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-20 17:36 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\OpenOffice.org2
2008-05-19 18:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-19 17:07 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-17 17:49 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\Spamihilator
2008-05-17 16:55 --------- d-----w C:\Program Files\Google
2008-05-17 14:50 --------- d-----w C:\Program Files\Fichiers communs\Softwin
2008-05-17 14:32 --------- d-----w C:\Program Files\Panda Security
2008-05-16 10:40 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-05-16 05:29 --------- d-----w C:\Program Files\eMule
2008-05-14 12:08 --------- d-----w C:\Program Files\Navilog1
2008-05-13 16:32 8 -c--a-w C:\Documents and Settings\MAMOUR\.bztarotcumul.dat
2008-05-10 16:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-10 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 16:09 1,362 -c--a-w C:\Documents and Settings\MAMOUR\Application Data\wklnhst.dat
2008-05-05 04:04 --------- d-----w C:\Program Files\Glary Utilities
2008-04-24 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 09:29 --------- d-----w C:\Program Files\ArcSoft
2008-04-23 21:00 --------- d-----w C:\Program Files\Lavasoft
2008-04-23 20:59 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-21 20:13 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-04-21 20:11 --------- d-----w C:\Program Files\Java
2008-04-19 15:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-04-19 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microgaming
2008-04-15 08:40 --------- d-----w C:\Program Files\DivX
2008-04-14 10:31 --------- d-----w C:\Program Files\gps1
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SETB70.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET9B0.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET947.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET8E7.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET6E4.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B8.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B2.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\SETE3C.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setd4c.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setb97.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\SETE3B.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setd4b.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setb96.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\SETE3A.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setd4a.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setb95.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETD7C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETC8C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETAD6.tmp
2008-04-03 04:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 15:52 --------- d-----w C:\Program Files\RegCleaner
2008-04-01 15:36 --------- d-----w C:\Program Files\Jeune Styliste
2008-04-01 15:34 --------- d-----w C:\Program Files\Hewlett-Packard
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci vers Program Files.lnk
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci (2) vers Program Files.lnk
2006-10-06 07:02 3,185,570 -c--a-w C:\Documents and Settings\MAMOUR\trop_fort.zip
2006-10-02 16:36 3,782,230 -c--a-w C:\Documents and Settings\MAMOUR\wc2.zip
2006-03-19 11:23 256 -c--a-w C:\Program Files\SAVEGAME
2006-03-19 09:52 4,730 -c--a-w C:\Program Files\DeIsL2.isu
2006-03-04 07:22 163 -c-ha-w C:\Documents and Settings\MAMOUR\hpothb07.dat
2006-01-07 16:01 3,401 -c--a-w C:\Program Files\DeIsL1.isu
2006-01-07 16:01 17,825,792 -c--a-w C:\Program Files\pcdogs.pkg
2005-12-27 11:51 164 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-12-27 11:51 0 -c-ha-w C:\Documents and Settings\MAMOUR\Application Data\hpothb07.dat
2003-09-29 10:17 766 -c--a-w C:\Program Files\register.ico
2003-09-29 10:17 593,920 -c--a-w C:\Program Files\THH.exe
2003-09-29 10:17 49,152 -c--a-w C:\Program Files\inetwh32.dll
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\untigghh.ico
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\tiggerhh.ico
2003-09-29 10:17 4,528 -c--a-w C:\Program Files\setbrows.exe
2003-09-29 10:17 30,720 -c--a-w C:\Program Files\remove.dll
2003-09-29 10:17 2,449,408 -c--a-w C:\Program Files\Launcher.exe
2003-09-29 10:17 155 -c--a-w C:\Program Files\title.txt
2003-09-29 10:17 1,698,135 -c--a-w C:\Program Files\TiggerHH.hlp
2003-09-29 10:17 1,584 -c--a-w C:\Program Files\uninst.ini
2000-12-21 12:25 446,464 -c--a-w C:\Program Files\Pcdogs.exe
2000-11-17 14:22 439 -c--a-w C:\Program Files\D3D.log
2000-11-08 16:27 111 -c--a-w C:\Program Files\pcdogs.ini
2000-10-18 15:34 2,251,695 -c--a-w C:\Program Files\102Dalms.hlp
2000-08-18 15:26 630 -c--a-w C:\Program Files\unin102D.ico
2000-08-18 15:25 630 -c--a-w C:\Program Files\102Dalms.ico
2000-07-10 15:33 11 -c--a-w C:\Program Files\message.log
1999-11-01 16:56 327,680 -c--a-w C:\Program Files\mss32.dll
1997-08-14 17:31 98,816 -c--a-w C:\Program Files\DEC130.DLL
1997-08-14 17:24 89,600 -c--a-w C:\Program Files\WINSDEC.DLL
1997-08-14 17:17 117,248 -c--a-w C:\Program Files\EDEC.DLL
1997-08-14 17:06 60,416 -c--a-w C:\Program Files\WINPLAY.DLL
1997-08-14 12:10 80,896 -c--a-w C:\Program Files\WINSTR.DLL
1996-01-25 17:45 39,936 -c--a-w C:\Program Files\D2HTLS32.DLL
1996-01-24 21:43 202,752 -c--a-w C:\Program Files\D2HLNK32.DLL
1995-07-11 09:50 322,832 -c--a-w C:\Program Files\MFC30.DLL
1995-07-11 09:50 253,952 -c--a-w C:\Program Files\MSVCRT20.DLL
.
((((((((((((((((((((((((((((( snapshot@2008-05-20_19.00.48.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 16:52:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-20 19:26:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 10:35 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]
"Glary Memory Optimizer"="C:\Program Files\Glary Utilities\memdefrag.exe" [2008-03-05 10:23 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 19:56 29744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-05 12:26 5566464]
"ArcSoft Connection Service"="C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 08:45 31232]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Docteur Club Internet.lnk]
backup=C:\WINDOWS\pss\Docteur Club Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NkbMonitor.exe.lnk]
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^MAMOUR^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
backup=C:\WINDOWS\pss\Club Internet.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
--a--c--- 2003-05-02 11:31 24576 c:\apps\ABoard\ABoard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailChecker]
--a--c--- 2003-07-02 11:13 40960 C:\APPS\EmailChecker\ech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-05-20 19:56 29744 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a--c--- 2004-08-05 14:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a--c--- 2004-10-08 12:06 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2004-10-08 12:31 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a--c--- 2004-10-08 12:24 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-10-08 11:52 221184 C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-03-05 12:26 5566464 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2005-01-28 11:10 110740 c:\Apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StandardInstall]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmtalk]
--a--c--- 2003-07-24 17:21 61440 C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SLService"=2 (0x2)
"SAVScan"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"navapsvc"=2 (0x2)
"MysqlInventime"=3 (0x3)
"ISSVC"=2 (0x2)
"GenericHidService"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"AOL ACS"=2 (0x2)
"Service CANALPLAY"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys [2004-10-11 16:28]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 08:45]
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2005-11-04 12:38]
S1 lkbdhlpr;Logitech Keyboard Class Helper Driver;C:\WINDOWS\system32\Drivers\lkbdhlpr.sys []
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys []
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2006-03-26 21:15]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 19:56]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys []
S3 SA2KMD;STEL Modem;C:\WINDOWS\system32\DRIVERS\sa2kmd.sys [2004-05-11 03:03]
S3 SA2KPT;STEL OBEX PORT;C:\WINDOWS\system32\DRIVERS\sa2kpt.sys [2004-05-11 03:03]
S3 SACTL;STEL USB HOST DRIVER;C:\WINDOWS\system32\DRIVERS\sactl.sys [2004-05-11 03:02]
S3 SAENUM;STEL Enum Driver;C:\WINDOWS\system32\DRIVERS\saenum.sys [2004-05-11 03:02]
S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-10-08 11:54]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-05 14:00]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-20 18:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-20 19:26:27 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-20 19:29:18 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-05-20 19:23:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
merci
ComboFix 08-05-19.4 - MAMOUR 2008-05-20 21:20:19.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1545 [GMT 2:00]
Endroit: C:\Documents and Settings\MAMOUR\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_004804_.tmp.dll
C:\WINDOWS\system32\_004805_.tmp.dll
C:\WINDOWS\system32\_004806_.tmp.dll
C:\WINDOWS\system32\_004807_.tmp.dll
C:\WINDOWS\system32\_004814_.tmp.dll
C:\WINDOWS\system32\_004816_.tmp.dll
C:\WINDOWS\system32\_004817_.tmp.dll
C:\WINDOWS\system32\_004818_.tmp.dll
C:\WINDOWS\system32\_004819_.tmp.dll
C:\WINDOWS\system32\_004820_.tmp.dll
C:\WINDOWS\system32\_004821_.tmp.dll
C:\WINDOWS\system32\_004822_.tmp.dll
C:\WINDOWS\system32\_004823_.tmp.dll
C:\WINDOWS\system32\_004824_.tmp.dll
C:\WINDOWS\system32\_004825_.tmp.dll
C:\WINDOWS\system32\_004826_.tmp.dll
C:\WINDOWS\system32\_004827_.tmp.dll
C:\WINDOWS\system32\_004828_.tmp.dll
C:\WINDOWS\system32\_004829_.tmp.dll
C:\WINDOWS\system32\_004830_.tmp.dll
C:\WINDOWS\system32\_004831_.tmp.dll
C:\WINDOWS\system32\_004832_.tmp.dll
C:\WINDOWS\system32\_004833_.tmp.dll
C:\WINDOWS\system32\_004834_.tmp.dll
C:\WINDOWS\system32\_004835_.tmp.dll
C:\WINDOWS\system32\_004836_.tmp.dll
C:\WINDOWS\system32\_004837_.tmp.dll
C:\WINDOWS\system32\_004838_.tmp.dll
C:\WINDOWS\system32\_004839_.tmp.dll
C:\WINDOWS\system32\_004840_.tmp.dll
C:\WINDOWS\system32\_004841_.tmp.dll
C:\WINDOWS\system32\_004842_.tmp.dll
C:\WINDOWS\system32\_004843_.tmp.dll
C:\WINDOWS\system32\_004844_.tmp.dll
C:\WINDOWS\system32\_004845_.tmp.dll
C:\WINDOWS\system32\_004846_.tmp.dll
C:\WINDOWS\system32\_004847_.tmp.dll
C:\WINDOWS\system32\_004849_.tmp.dll
C:\WINDOWS\system32\_004850_.tmp.dll
C:\WINDOWS\system32\_004851_.tmp.dll
C:\WINDOWS\system32\_004852_.tmp.dll
C:\WINDOWS\system32\_004853_.tmp.dll
C:\WINDOWS\system32\_004854_.tmp.dll
C:\WINDOWS\system32\_004855_.tmp.dll
C:\WINDOWS\system32\_004856_.tmp.dll
C:\WINDOWS\system32\_004857_.tmp.dll
C:\WINDOWS\system32\_004858_.tmp.dll
C:\WINDOWS\system32\_004859_.tmp.dll
C:\WINDOWS\system32\_004860_.tmp.dll
C:\WINDOWS\system32\_004861_.tmp.dll
C:\WINDOWS\system32\_004862_.tmp.dll
C:\WINDOWS\system32\_004863_.tmp.dll
C:\WINDOWS\system32\_004864_.tmp.dll
C:\WINDOWS\system32\_004865_.tmp.dll
C:\WINDOWS\system32\_004866_.tmp.dll
C:\WINDOWS\system32\_004867_.tmp.dll
C:\WINDOWS\system32\_004868_.tmp.dll
C:\WINDOWS\system32\_004869_.tmp.dll
C:\WINDOWS\system32\_004870_.tmp.dll
C:\WINDOWS\system32\_004871_.tmp.dll
C:\WINDOWS\system32\_004872_.tmp.dll
C:\WINDOWS\system32\_004873_.tmp.dll
C:\WINDOWS\system32\_004874_.tmp.dll
C:\WINDOWS\system32\_004875_.tmp.dll
C:\WINDOWS\system32\_004876_.tmp.dll
C:\WINDOWS\system32\_004877_.tmp.dll
C:\WINDOWS\system32\_004878_.tmp.dll
C:\WINDOWS\system32\_004879_.tmp.dll
C:\WINDOWS\system32\_004880_.tmp.dll
C:\WINDOWS\system32\_004881_.tmp.dll
C:\WINDOWS\system32\_004882_.tmp.dll
C:\WINDOWS\system32\_004883_.tmp.dll
C:\WINDOWS\system32\_004884_.tmp.dll
C:\WINDOWS\system32\_004885_.tmp.dll
C:\WINDOWS\system32\_004886_.tmp.dll
C:\WINDOWS\system32\_004887_.tmp.dll
C:\WINDOWS\system32\_004888_.tmp.dll
C:\WINDOWS\system32\_004889_.tmp.dll
C:\WINDOWS\system32\_004890_.tmp.dll
C:\WINDOWS\system32\_004891_.tmp.dll
C:\WINDOWS\system32\_004892_.tmp.dll
C:\WINDOWS\system32\_004893_.tmp.dll
C:\WINDOWS\system32\_004894_.tmp.dll
C:\WINDOWS\system32\_004895_.tmp.dll
C:\WINDOWS\system32\_004896_.tmp.dll
C:\WINDOWS\system32\_004897_.tmp.dll
C:\WINDOWS\system32\_004898_.tmp.dll
C:\WINDOWS\system32\_004899_.tmp.dll
C:\WINDOWS\system32\_004900_.tmp.dll
C:\WINDOWS\system32\_004901_.tmp.dll
C:\WINDOWS\system32\_004902_.tmp.dll
C:\WINDOWS\system32\_004903_.tmp.dll
C:\WINDOWS\system32\_004904_.tmp.dll
C:\WINDOWS\system32\_004905_.tmp.dll
C:\WINDOWS\system32\_004906_.tmp.dll
C:\WINDOWS\system32\_004907_.tmp.dll
C:\WINDOWS\system32\_004908_.tmp.dll
C:\WINDOWS\system32\_004909_.tmp.dll
C:\WINDOWS\system32\_004910_.tmp.dll
C:\WINDOWS\system32\_004911_.tmp.dll
C:\WINDOWS\system32\_004912_.tmp.dll
C:\WINDOWS\system32\_004913_.tmp.dll
C:\WINDOWS\system32\_004914_.tmp.dll
C:\WINDOWS\system32\_004915_.tmp.dll
C:\WINDOWS\system32\_004916_.tmp.dll
C:\WINDOWS\system32\_004917_.tmp.dll
C:\WINDOWS\system32\_004918_.tmp.dll
C:\WINDOWS\system32\_004919_.tmp.dll
C:\WINDOWS\system32\_004920_.tmp.dll
C:\WINDOWS\system32\_004921_.tmp.dll
C:\WINDOWS\system32\_004922_.tmp.dll
C:\WINDOWS\system32\_004923_.tmp.dll
C:\WINDOWS\system32\_004924_.tmp.dll
C:\WINDOWS\system32\_004925_.tmp.dll
C:\WINDOWS\system32\_004926_.tmp.dll
C:\WINDOWS\system32\_004927_.tmp.dll
C:\WINDOWS\system32\_004928_.tmp.dll
C:\WINDOWS\system32\_004929_.tmp.dll
C:\WINDOWS\system32\_004930_.tmp.dll
C:\WINDOWS\system32\_004931_.tmp.dll
C:\WINDOWS\system32\_004932_.tmp.dll
C:\WINDOWS\system32\_004933_.tmp.dll
C:\WINDOWS\system32\_004934_.tmp.dll
C:\WINDOWS\system32\_004935_.tmp.dll
C:\WINDOWS\system32\_004936_.tmp.dll
C:\WINDOWS\system32\_004937_.tmp.dll
C:\WINDOWS\system32\_004938_.tmp.dll
C:\WINDOWS\system32\_004939_.tmp.dll
C:\WINDOWS\system32\_004940_.tmp.dll
C:\WINDOWS\system32\_004941_.tmp.dll
C:\WINDOWS\system32\_004942_.tmp.dll
C:\WINDOWS\system32\_004943_.tmp.dll
C:\WINDOWS\system32\_004944_.tmp.dll
C:\WINDOWS\system32\_004945_.tmp.dll
C:\WINDOWS\system32\_004946_.tmp.dll
C:\WINDOWS\system32\_004947_.tmp.dll
C:\WINDOWS\system32\_004948_.tmp.dll
C:\WINDOWS\system32\_004949_.tmp.dll
C:\WINDOWS\system32\_004950_.tmp.dll
C:\WINDOWS\system32\_004951_.tmp.dll
C:\WINDOWS\system32\_004952_.tmp.dll
C:\WINDOWS\system32\_004953_.tmp.dll
C:\WINDOWS\system32\_004954_.tmp.dll
C:\WINDOWS\system32\_004955_.tmp.dll
C:\WINDOWS\system32\_004956_.tmp.dll
C:\WINDOWS\system32\_004957_.tmp.dll
C:\WINDOWS\system32\_004958_.tmp.dll
C:\WINDOWS\system32\_004959_.tmp.dll
C:\WINDOWS\system32\_004960_.tmp.dll
C:\WINDOWS\system32\_004961_.tmp.dll
C:\WINDOWS\system32\_004962_.tmp.dll
C:\WINDOWS\system32\_004963_.tmp.dll
C:\WINDOWS\system32\_004964_.tmp.dll
C:\WINDOWS\system32\_004965_.tmp.dll
C:\WINDOWS\system32\_004966_.tmp.dll
C:\WINDOWS\system32\_004967_.tmp.dll
C:\WINDOWS\system32\_004968_.tmp.dll
C:\WINDOWS\system32\_004969_.tmp.dll
C:\WINDOWS\system32\_004970_.tmp.dll
C:\WINDOWS\system32\_004971_.tmp.dll
C:\WINDOWS\system32\_004972_.tmp.dll
C:\WINDOWS\system32\_004973_.tmp.dll
C:\WINDOWS\system32\_004974_.tmp.dll
C:\WINDOWS\system32\_004975_.tmp.dll
C:\WINDOWS\system32\_004976_.tmp.dll
C:\WINDOWS\system32\_004978_.tmp.dll
C:\WINDOWS\system32\_004979_.tmp.dll
C:\WINDOWS\system32\_004980_.tmp.dll
C:\WINDOWS\system32\_004982_.tmp.dll
C:\WINDOWS\system32\_004983_.tmp.dll
C:\WINDOWS\system32\_004984_.tmp.dll
C:\WINDOWS\system32\_004985_.tmp.dll
C:\WINDOWS\system32\_004986_.tmp.dll
C:\WINDOWS\system32\_004987_.tmp.dll
C:\WINDOWS\system32\_004988_.tmp.dll
C:\WINDOWS\system32\_004989_.tmp.dll
C:\WINDOWS\system32\_004990_.tmp.dll
C:\WINDOWS\system32\_004991_.tmp.dll
C:\WINDOWS\system32\_004992_.tmp.dll
C:\WINDOWS\system32\_004993_.tmp.dll
C:\WINDOWS\system32\_004994_.tmp.dll
C:\WINDOWS\system32\_004995_.tmp.dll
C:\WINDOWS\system32\_004996_.tmp.dll
C:\WINDOWS\system32\_004997_.tmp.dll
C:\WINDOWS\system32\_004998_.tmp.dll
C:\WINDOWS\system32\_004999_.tmp.dll
C:\WINDOWS\system32\_005000_.tmp.dll
C:\WINDOWS\system32\_005001_.tmp.dll
C:\WINDOWS\system32\_005003_.tmp.dll
C:\WINDOWS\system32\_005004_.tmp.dll
C:\WINDOWS\system32\_005005_.tmp.dll
C:\WINDOWS\system32\_005006_.tmp.dll
C:\WINDOWS\system32\_005008_.tmp.dll
C:\WINDOWS\system32\_005010_.tmp.dll
C:\WINDOWS\system32\_005011_.tmp.dll
C:\WINDOWS\system32\_005012_.tmp.dll
C:\WINDOWS\system32\_005014_.tmp.dll
C:\WINDOWS\system32\_005015_.tmp.dll
C:\WINDOWS\system32\_005016_.tmp.dll
C:\WINDOWS\system32\_005017_.tmp.dll
C:\WINDOWS\system32\_005018_.tmp.dll
C:\WINDOWS\system32\_005019_.tmp.dll
C:\WINDOWS\system32\_005020_.tmp.dll
C:\WINDOWS\system32\_005021_.tmp.dll
C:\WINDOWS\system32\_005022_.tmp.dll
C:\WINDOWS\system32\_005023_.tmp.dll
C:\WINDOWS\system32\_005024_.tmp.dll
C:\WINDOWS\system32\_005025_.tmp.dll
C:\WINDOWS\system32\_005026_.tmp.dll
C:\WINDOWS\system32\_005027_.tmp.dll
C:\WINDOWS\system32\_005028_.tmp.dll
C:\WINDOWS\system32\_005029_.tmp.dll
C:\WINDOWS\system32\_005030_.tmp.dll
C:\WINDOWS\system32\_005031_.tmp.dll
C:\WINDOWS\system32\_005032_.tmp.dll
C:\WINDOWS\system32\_005033_.tmp.dll
C:\WINDOWS\system32\_005035_.tmp.dll
C:\WINDOWS\system32\_005036_.tmp.dll
C:\WINDOWS\system32\_005037_.tmp.dll
C:\WINDOWS\system32\_005038_.tmp.dll
C:\WINDOWS\system32\_005040_.tmp.dll
C:\WINDOWS\system32\_005042_.tmp.dll
C:\WINDOWS\system32\_005043_.tmp.dll
C:\WINDOWS\system32\_005044_.tmp.dll
C:\WINDOWS\system32\_005046_.tmp.dll
C:\WINDOWS\system32\_005047_.tmp.dll
C:\WINDOWS\system32\_005048_.tmp.dll
C:\WINDOWS\system32\_005049_.tmp.dll
C:\WINDOWS\system32\_005050_.tmp.dll
C:\WINDOWS\system32\_005051_.tmp.dll
C:\WINDOWS\system32\_005052_.tmp.dll
C:\WINDOWS\system32\_005053_.tmp.dll
C:\WINDOWS\system32\_005054_.tmp.dll
C:\WINDOWS\system32\_005055_.tmp.dll
C:\WINDOWS\system32\_005056_.tmp.dll
C:\WINDOWS\system32\_005057_.tmp.dll
C:\WINDOWS\system32\_005059_.tmp.dll
C:\WINDOWS\system32\_005061_.tmp.dll
C:\WINDOWS\system32\_005063_.tmp.dll
C:\WINDOWS\system32\_005064_.tmp.dll
C:\WINDOWS\system32\_005065_.tmp.dll
C:\WINDOWS\system32\_005069_.tmp.dll
C:\WINDOWS\system32\_005070_.tmp.dll
C:\WINDOWS\system32\_005072_.tmp.dll
C:\WINDOWS\system32\_005075_.tmp.dll
C:\WINDOWS\system32\_005078_.tmp.dll
C:\WINDOWS\system32\_005079_.tmp.dll
C:\WINDOWS\system32\_005080_.tmp.dll
C:\WINDOWS\system32\_005081_.tmp.dll
C:\WINDOWS\system32\_005084_.tmp.dll
C:\WINDOWS\system32\_005085_.tmp.dll
C:\WINDOWS\system32\_005086_.tmp.dll
C:\WINDOWS\system32\_005087_.tmp.dll
C:\WINDOWS\system32\_005088_.tmp.dll
C:\WINDOWS\system32\_005093_.tmp.dll
C:\WINDOWS\system32\_005095_.tmp.dll
C:\WINDOWS\system32\MSINET.oca
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-20 to 2008-05-20 ))))))))))))))))))))))))))))))))))))
.
2008-05-19 20:37 . 2008-05-19 20:40 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-19 20:37 . 2008-05-19 20:37 <REP> d-------- C:\Program Files\MSBuild
2008-05-19 20:36 . 2008-05-19 20:36 <REP> d-------- C:\Program Files\MSXML 6.0
2008-05-19 20:36 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-19 20:01 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET194D.tmp
2008-05-19 20:01 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1970.tmp
2008-05-19 20:01 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET193F.tmp
2008-05-19 20:01 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1972.tmp
2008-05-19 20:01 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET193A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET194A.tmp
2008-05-19 20:01 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET1995.tmp
2008-05-19 20:01 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET199C.tmp
2008-05-19 20:01 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1943.tmp
2008-05-19 20:01 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1937.tmp
2008-05-19 19:56 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETB9B.tmp
2008-05-19 19:55 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET9B4.tmp
2008-05-19 19:53 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003195_.tmp
2008-05-19 19:19 . 2008-05-20 19:05 <REP> d-------- C:\Program Files\Mozilla Sunbird
2008-05-18 22:07 . 2008-05-18 22:08 <REP> d-------- C:\Program Files\SpywareBlaster
2008-05-17 17:40 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET185D.tmp
2008-05-17 17:40 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET1880.tmp
2008-05-17 17:40 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET184F.tmp
2008-05-17 17:40 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET1882.tmp
2008-05-17 17:40 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET184A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET185A.tmp
2008-05-17 17:40 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET18A5.tmp
2008-05-17 17:40 . 2008-04-13 19:33 16,896 --a------ C:\WINDOWS\system32\SET18AC.tmp
2008-05-17 17:40 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET1853.tmp
2008-05-17 17:40 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1847.tmp
2008-05-17 17:35 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SETAB9.tmp
2008-05-17 17:34 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET8D2.tmp
2008-05-17 17:32 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003186_.tmp
2008-05-17 17:30 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004836_.tmp.dll
2008-05-17 16:34 . 2008-05-17 16:34 <REP> d-------- C:\_OTMoveIt
2008-05-17 15:21 . 2008-05-17 15:21 <REP> dr-h----- C:\Documents and Settings\MAMOUR\Application Data\SecuROM
2008-05-16 12:40 . 2008-05-16 13:47 <REP> d-------- C:\Program Files\BitDefender
2008-05-16 11:50 . 2008-05-16 11:50 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Program Files\Avira
2008-05-14 23:03 . 2008-05-14 23:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-14 15:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-14 15:09 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-14 15:09 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-14 14:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-13 21:01 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004825_.tmp.dll
2008-05-13 19:29 . 2008-04-13 11:36 2,986,496 --a------ C:\WINDOWS\system32\SET16A8.tmp
2008-05-13 19:29 . 2008-04-13 19:33 539,136 --a------ C:\WINDOWS\system32\SET16CB.tmp
2008-05-13 19:29 . 2008-04-13 19:33 354,304 --a------ C:\WINDOWS\system32\SET169A.tmp
2008-05-13 19:29 . 2008-04-13 19:31 177,152 --a------ C:\WINDOWS\system32\SET16CD.tmp
2008-05-13 19:29 . 2008-04-13 19:33 80,896 --a------ C:\WINDOWS\system32\SET1695.tmp
2008-05-13 19:29 . 2008-04-13 19:33 75,776 --a------ C:\WINDOWS\system32\SET16A5.tmp
2008-05-13 19:29 . 2008-04-13 19:33 24,576 --a------ C:\WINDOWS\system32\SET16F0.tmp
2008-05-13 19:29 . 2008-04-13 19:33 15,872 --a------ C:\WINDOWS\system32\SET169E.tmp
2008-05-13 19:29 . 2008-04-13 19:33 6,656 --a------ C:\WINDOWS\system32\SET1692.tmp
2008-05-13 19:26 . 2008-04-13 19:33 2,843,136 --a------ C:\WINDOWS\system32\SET8EB.tmp
2008-05-13 19:25 . 2008-04-13 19:33 8,517,632 --a------ C:\WINDOWS\system32\SET667.tmp
2008-05-13 19:23 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\003184_.tmp
2008-05-13 19:21 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004851_.tmp.dll
2008-05-12 21:08 . 2008-05-12 21:08 <REP> d-------- C:\Program Files\OFFICE One6.5
2008-05-12 17:42 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004841_.tmp.dll
2008-05-10 13:07 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004831_.tmp.dll
2008-05-09 13:23 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004821_.tmp.dll
2008-05-09 06:14 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004811_.tmp.dll
2008-05-07 21:03 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004801_.tmp.dll
2008-05-06 22:40 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\fr
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\system32\bits
2008-05-06 22:40 . 2008-05-19 20:04 <REP> d-------- C:\WINDOWS\l2schemas
2008-05-06 22:33 . 2004-08-05 14:00 71,040 --------- C:\WINDOWS\system32\drivers\_004791_.tmp.dll
2008-05-06 22:31 . 2008-05-19 19:50 <REP> d-------- C:\WINDOWS\EHome
2008-05-06 21:41 . 2008-05-19 20:01 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-03 09:19 . 2008-05-03 09:19 <REP> d-------- C:\Program Files\EA GAMES
2008-05-02 05:39 . 2008-05-02 05:39 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\Panasonic
2008-04-27 22:50 . 2008-05-03 06:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-24 11:32 . 2008-04-24 11:32 26 --a------ C:\UpdaterforApp.ini
2008-04-24 11:29 . 2008-04-24 11:29 <REP> d-------- C:\WINDOWS\system32\MediaImpression Slideshow
2008-04-24 11:29 . 2008-04-24 11:32 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2008-04-24 11:29 . 2007-03-07 16:05 126,976 --a------ C:\WINDOWS\system32\MediaImpression Slideshow.scr
2008-04-24 11:29 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-04-24 11:27 . 2008-04-24 11:27 <REP> d-------- C:\Program Files\Panasonic
2008-04-23 23:00 . 2008-04-23 23:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-23 11:05 . 2008-04-23 11:05 <REP> d-------- C:\Program Files\Electronic Arts
2008-04-23 11:04 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-04-21 22:14 . 2008-04-21 22:14 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-21 10:43 . 2008-04-21 12:29 <REP> d-------- C:\Program Files\a-squared Free
2008-04-20 17:14 . 2008-05-10 20:06 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-04-20 13:10 . 2008-04-20 13:10 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-04-20 13:10 . 2008-04-20 16:47 <REP> d-------- C:\Documents and Settings\MAMOUR\Application Data\FileZilla
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 18:14 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-20 17:36 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\OpenOffice.org2
2008-05-19 18:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-19 17:07 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-17 17:49 --------- d-----w C:\Documents and Settings\MAMOUR\Application Data\Spamihilator
2008-05-17 16:55 --------- d-----w C:\Program Files\Google
2008-05-17 14:50 --------- d-----w C:\Program Files\Fichiers communs\Softwin
2008-05-17 14:32 --------- d-----w C:\Program Files\Panda Security
2008-05-16 10:40 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-05-16 05:29 --------- d-----w C:\Program Files\eMule
2008-05-14 12:08 --------- d-----w C:\Program Files\Navilog1
2008-05-13 16:32 8 -c--a-w C:\Documents and Settings\MAMOUR\.bztarotcumul.dat
2008-05-10 16:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-10 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 16:09 1,362 -c--a-w C:\Documents and Settings\MAMOUR\Application Data\wklnhst.dat
2008-05-05 04:04 --------- d-----w C:\Program Files\Glary Utilities
2008-04-24 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 09:29 --------- d-----w C:\Program Files\ArcSoft
2008-04-23 21:00 --------- d-----w C:\Program Files\Lavasoft
2008-04-23 20:59 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-21 20:13 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-04-21 20:11 --------- d-----w C:\Program Files\Java
2008-04-19 15:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-04-19 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microgaming
2008-04-15 08:40 --------- d-----w C:\Program Files\DivX
2008-04-14 10:31 --------- d-----w C:\Program Files\gps1
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SETB70.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET9B0.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET947.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET8E7.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET6E4.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B8.tmp
2008-04-14 02:34 1,037,824 ----a-w C:\WINDOWS\SET5B2.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\SETE3C.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setd4c.tmp
2008-04-13 17:36 239,006 ----a-w C:\WINDOWS\AppPatch\setb97.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\SETE3B.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setd4b.tmp
2008-04-13 17:36 204,396 ----a-w C:\WINDOWS\AppPatch\setb96.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\SETE3A.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setd4a.tmp
2008-04-13 17:36 1,202,774 ----a-w C:\WINDOWS\AppPatch\setb95.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETD7C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETC8C.tmp
2008-04-13 17:34 1,037,824 ----a-w C:\WINDOWS\SETAD6.tmp
2008-04-03 04:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 15:52 --------- d-----w C:\Program Files\RegCleaner
2008-04-01 15:36 --------- d-----w C:\Program Files\Jeune Styliste
2008-04-01 15:34 --------- d-----w C:\Program Files\Hewlett-Packard
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci vers Program Files.lnk
2007-04-28 13:29 385 -c--a-w C:\Program Files\Raccourci (2) vers Program Files.lnk
2006-10-06 07:02 3,185,570 -c--a-w C:\Documents and Settings\MAMOUR\trop_fort.zip
2006-10-02 16:36 3,782,230 -c--a-w C:\Documents and Settings\MAMOUR\wc2.zip
2006-03-19 11:23 256 -c--a-w C:\Program Files\SAVEGAME
2006-03-19 09:52 4,730 -c--a-w C:\Program Files\DeIsL2.isu
2006-03-04 07:22 163 -c-ha-w C:\Documents and Settings\MAMOUR\hpothb07.dat
2006-01-07 16:01 3,401 -c--a-w C:\Program Files\DeIsL1.isu
2006-01-07 16:01 17,825,792 -c--a-w C:\Program Files\pcdogs.pkg
2005-12-27 11:51 164 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-12-27 11:51 0 -c-ha-w C:\Documents and Settings\MAMOUR\Application Data\hpothb07.dat
2003-09-29 10:17 766 -c--a-w C:\Program Files\register.ico
2003-09-29 10:17 593,920 -c--a-w C:\Program Files\THH.exe
2003-09-29 10:17 49,152 -c--a-w C:\Program Files\inetwh32.dll
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\untigghh.ico
2003-09-29 10:17 4,710 -c--a-w C:\Program Files\tiggerhh.ico
2003-09-29 10:17 4,528 -c--a-w C:\Program Files\setbrows.exe
2003-09-29 10:17 30,720 -c--a-w C:\Program Files\remove.dll
2003-09-29 10:17 2,449,408 -c--a-w C:\Program Files\Launcher.exe
2003-09-29 10:17 155 -c--a-w C:\Program Files\title.txt
2003-09-29 10:17 1,698,135 -c--a-w C:\Program Files\TiggerHH.hlp
2003-09-29 10:17 1,584 -c--a-w C:\Program Files\uninst.ini
2000-12-21 12:25 446,464 -c--a-w C:\Program Files\Pcdogs.exe
2000-11-17 14:22 439 -c--a-w C:\Program Files\D3D.log
2000-11-08 16:27 111 -c--a-w C:\Program Files\pcdogs.ini
2000-10-18 15:34 2,251,695 -c--a-w C:\Program Files\102Dalms.hlp
2000-08-18 15:26 630 -c--a-w C:\Program Files\unin102D.ico
2000-08-18 15:25 630 -c--a-w C:\Program Files\102Dalms.ico
2000-07-10 15:33 11 -c--a-w C:\Program Files\message.log
1999-11-01 16:56 327,680 -c--a-w C:\Program Files\mss32.dll
1997-08-14 17:31 98,816 -c--a-w C:\Program Files\DEC130.DLL
1997-08-14 17:24 89,600 -c--a-w C:\Program Files\WINSDEC.DLL
1997-08-14 17:17 117,248 -c--a-w C:\Program Files\EDEC.DLL
1997-08-14 17:06 60,416 -c--a-w C:\Program Files\WINPLAY.DLL
1997-08-14 12:10 80,896 -c--a-w C:\Program Files\WINSTR.DLL
1996-01-25 17:45 39,936 -c--a-w C:\Program Files\D2HTLS32.DLL
1996-01-24 21:43 202,752 -c--a-w C:\Program Files\D2HLNK32.DLL
1995-07-11 09:50 322,832 -c--a-w C:\Program Files\MFC30.DLL
1995-07-11 09:50 253,952 -c--a-w C:\Program Files\MSVCRT20.DLL
.
((((((((((((((((((((((((((((( snapshot@2008-05-20_19.00.48.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 16:52:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-20 19:26:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 10:35 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]
"Glary Memory Optimizer"="C:\Program Files\Glary Utilities\memdefrag.exe" [2008-03-05 10:23 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 19:56 29744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-05 12:26 5566464]
"ArcSoft Connection Service"="C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 08:45 31232]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Docteur Club Internet.lnk]
backup=C:\WINDOWS\pss\Docteur Club Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NkbMonitor.exe.lnk]
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^MAMOUR^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
backup=C:\WINDOWS\pss\Club Internet.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
--a--c--- 2003-05-02 11:31 24576 c:\apps\ABoard\ABoard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailChecker]
--a--c--- 2003-07-02 11:13 40960 C:\APPS\EmailChecker\ech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-05-20 19:56 29744 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a--c--- 2004-08-05 14:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a--c--- 2004-10-08 12:06 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2004-10-08 12:31 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a--c--- 2004-10-08 12:24 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-10-08 11:52 221184 C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-03-05 12:26 5566464 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-03-05 12:26 1495040 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2005-01-28 11:10 110740 c:\Apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a--c--- 2004-08-05 14:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StandardInstall]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmtalk]
--a--c--- 2003-07-24 17:21 61440 C:\Program Files\Fichiers communs\Talkway\vmtalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SLService"=2 (0x2)
"SAVScan"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"navapsvc"=2 (0x2)
"MysqlInventime"=3 (0x3)
"ISSVC"=2 (0x2)
"GenericHidService"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"AOL ACS"=2 (0x2)
"Service CANALPLAY"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys [2004-10-11 16:28]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 08:45]
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2005-11-04 12:38]
S1 lkbdhlpr;Logitech Keyboard Class Helper Driver;C:\WINDOWS\system32\Drivers\lkbdhlpr.sys []
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys []
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2006-03-26 21:15]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-20 19:56]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys []
S3 SA2KMD;STEL Modem;C:\WINDOWS\system32\DRIVERS\sa2kmd.sys [2004-05-11 03:03]
S3 SA2KPT;STEL OBEX PORT;C:\WINDOWS\system32\DRIVERS\sa2kpt.sys [2004-05-11 03:03]
S3 SACTL;STEL USB HOST DRIVER;C:\WINDOWS\system32\DRIVERS\sactl.sys [2004-05-11 03:02]
S3 SAENUM;STEL Enum Driver;C:\WINDOWS\system32\DRIVERS\saenum.sys [2004-05-11 03:02]
S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-10-08 11:54]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-05 14:00]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-20 18:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-20 19:26:27 C:\WINDOWS\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-20 19:29:18 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-05-20 19:23:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
adfix
Téléchargez ceci (de gchris) : http://gchrisftp.free.fr/divers/Ad-Fix/Ad-Fix.zip
Dézippez-le sur votre bureau (clic droit -> extraire tout).
Vérifiez que vous êtes bien connecté à internet.
Dans le dossier créé, double-cliquez sur le fichier "Ad-Fix.bat" ou "Ad-fix"
Choisissez l'option 1.
Si vous avez un message de votre pare-feu qui vous demande si vous voulez autoriser le fichier URL2FILE.EXE à
se connecter à Internet, Autorisez, c'est nécessaire à ad-fix pour vérifier la version.
Quand c'est finit (cela peut prendre plusieurs minutes), un rapport s'ouvre avec le bloc-notes.
Merci de faire un copier/coller ici du contenu du rapport (Ad-Fix.txt)
Téléchargez ceci (de gchris) : http://gchrisftp.free.fr/divers/Ad-Fix/Ad-Fix.zip
Dézippez-le sur votre bureau (clic droit -> extraire tout).
Vérifiez que vous êtes bien connecté à internet.
Dans le dossier créé, double-cliquez sur le fichier "Ad-Fix.bat" ou "Ad-fix"
Choisissez l'option 1.
Si vous avez un message de votre pare-feu qui vous demande si vous voulez autoriser le fichier URL2FILE.EXE à
se connecter à Internet, Autorisez, c'est nécessaire à ad-fix pour vérifier la version.
Quand c'est finit (cela peut prendre plusieurs minutes), un rapport s'ouvre avec le bloc-notes.
Merci de faire un copier/coller ici du contenu du rapport (Ad-Fix.txt)
voila ton rapport!je vais devenir un pro grace à toi!
Ad-Fix v0.101e
by gchris
OPTION 1 (Scan) :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Démarré à :
22:30:51.48 2008-05-20
Executé depuis :
C:\Documents and Settings\MAMOUR\Local Settings\Temp\Ad-Fix\Ad-Fix
Os :
Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichier manquant
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichiers cachés (pas forcément mauvais)
Fichiers cachés à la racine du disque système :
BOOT.BAK
BOOT.INI
Bootfont.bin
cmldr
hiberfil.sys
hpothb07.dat
hpothb07.tif
IO.SYS
IPH.PH
MSDOS.SYS
pagefile.sys
sqmdata00.sqm
sqmdata01.sqm
sqmdata02.sqm
sqmdata03.sqm
sqmdata04.sqm
sqmdata05.sqm
sqmdata06.sqm
sqmdata07.sqm
sqmdata08.sqm
sqmdata09.sqm
sqmdata10.sqm
sqmdata11.sqm
sqmdata12.sqm
sqmdata13.sqm
sqmdata14.sqm
sqmdata15.sqm
sqmdata16.sqm
sqmdata17.sqm
sqmdata18.sqm
sqmdata19.sqm
sqmnoopt00.sqm
sqmnoopt01.sqm
sqmnoopt02.sqm
sqmnoopt03.sqm
sqmnoopt04.sqm
sqmnoopt05.sqm
sqmnoopt06.sqm
sqmnoopt07.sqm
sqmnoopt08.sqm
sqmnoopt09.sqm
sqmnoopt10.sqm
sqmnoopt11.sqm
sqmnoopt12.sqm
sqmnoopt13.sqm
sqmnoopt14.sqm
sqmnoopt15.sqm
sqmnoopt16.sqm
sqmnoopt17.sqm
sqmnoopt18.sqm
sqmnoopt19.sqm
Fichiers cachés dans le répertoire Windows :
VgaQI.dat
WindowsShell.Manifest
winnt.bmp
winnt256.bmp
Fichiers cachés dans le répertoire System32 :
cdplayer.exe.manifest
logonui.exe.manifest
ncpa.cpl.manifest
nwc.cpl.manifest
sapi.cpl.manifest
WindowsLogon.manifest
wuaucpl.cpl.manifest
zllictbl.dat
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Analyse du registre
---------- USER AGENT -- POST PLATFORM
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
----------
HKCR\Component Categories\{00021494-0000-0000-C000-000000000046} Détecté !
HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Détecté !
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Détecté !
HKLM\SOFTWARE\Classes\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Détecté !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net Détecté !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\net-nucleus.com Détecté !
Complete!
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichiers et dossiers
C:\Progra~1\FreeGo Détecté !
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Terminé à 22:40:50.68
Ad-Fix v0.101e
by gchris
OPTION 1 (Scan) :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Démarré à :
22:30:51.48 2008-05-20
Executé depuis :
C:\Documents and Settings\MAMOUR\Local Settings\Temp\Ad-Fix\Ad-Fix
Os :
Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichier manquant
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichiers cachés (pas forcément mauvais)
Fichiers cachés à la racine du disque système :
BOOT.BAK
BOOT.INI
Bootfont.bin
cmldr
hiberfil.sys
hpothb07.dat
hpothb07.tif
IO.SYS
IPH.PH
MSDOS.SYS
pagefile.sys
sqmdata00.sqm
sqmdata01.sqm
sqmdata02.sqm
sqmdata03.sqm
sqmdata04.sqm
sqmdata05.sqm
sqmdata06.sqm
sqmdata07.sqm
sqmdata08.sqm
sqmdata09.sqm
sqmdata10.sqm
sqmdata11.sqm
sqmdata12.sqm
sqmdata13.sqm
sqmdata14.sqm
sqmdata15.sqm
sqmdata16.sqm
sqmdata17.sqm
sqmdata18.sqm
sqmdata19.sqm
sqmnoopt00.sqm
sqmnoopt01.sqm
sqmnoopt02.sqm
sqmnoopt03.sqm
sqmnoopt04.sqm
sqmnoopt05.sqm
sqmnoopt06.sqm
sqmnoopt07.sqm
sqmnoopt08.sqm
sqmnoopt09.sqm
sqmnoopt10.sqm
sqmnoopt11.sqm
sqmnoopt12.sqm
sqmnoopt13.sqm
sqmnoopt14.sqm
sqmnoopt15.sqm
sqmnoopt16.sqm
sqmnoopt17.sqm
sqmnoopt18.sqm
sqmnoopt19.sqm
Fichiers cachés dans le répertoire Windows :
VgaQI.dat
WindowsShell.Manifest
winnt.bmp
winnt256.bmp
Fichiers cachés dans le répertoire System32 :
cdplayer.exe.manifest
logonui.exe.manifest
ncpa.cpl.manifest
nwc.cpl.manifest
sapi.cpl.manifest
WindowsLogon.manifest
wuaucpl.cpl.manifest
zllictbl.dat
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Analyse du registre
---------- USER AGENT -- POST PLATFORM
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
----------
HKCR\Component Categories\{00021494-0000-0000-C000-000000000046} Détecté !
HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Détecté !
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Détecté !
HKLM\SOFTWARE\Classes\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Détecté !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net Détecté !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\net-nucleus.com Détecté !
Complete!
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichiers et dossiers
C:\Progra~1\FreeGo Détecté !
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Terminé à 22:40:50.68
¤Démarre en mode sans échec :
Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
(Si F8 ne marche pas utilise la touche F5).
Lancez de nouveau Ad-fix
Choisissez l'option 2
Le bureau ou les icônes vont disparaître, c'est normal.
Quand c'est terminé, pressez la touche "entrée" pour redémarrer l'ordinateur.
Copiez collez ici, le contenu du nouveau rapport.
________
tu as un rapport antivir aussi svp
Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
(Si F8 ne marche pas utilise la touche F5).
Lancez de nouveau Ad-fix
Choisissez l'option 2
Le bureau ou les icônes vont disparaître, c'est normal.
Quand c'est terminé, pressez la touche "entrée" pour redémarrer l'ordinateur.
Copiez collez ici, le contenu du nouveau rapport.
________
tu as un rapport antivir aussi svp
voila le rapport ad par contre faut il faire un scan de l'ordi pour antivir?de plus lorsque je clic sur ton lien une page explorer s'ouvre et rien ne se passe ;je reviens donc sur mozilla
Ad-Fix v0.101e
by gchris
OPTION 2 (Fix) :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Démarré à :
23:07:07.95 2008-05-20
en mode sans échec
Executé depuis :
C:\DOCUME~1\MAMOUR\LOCALS~1\Temp\Ad-Fix-1\Ad-Fix
Os :
Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichier manquant
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nettoyage du registre
HKCR\Component Categories\{00021494-0000-0000-C000-000000000046} Supprimé !
HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Supprimé !
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Supprimé !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net Supprimé !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\net-nucleus.com Supprimé !
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Suppression des fichiers
C:\Progra~1\FreeGo Supprimé !
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Terminé à 23:13:10.84
Redémarrage effectué
Ad-Fix v0.101e
by gchris
OPTION 2 (Fix) :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Démarré à :
23:07:07.95 2008-05-20
en mode sans échec
Executé depuis :
C:\DOCUME~1\MAMOUR\LOCALS~1\Temp\Ad-Fix-1\Ad-Fix
Os :
Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Recherche de fichier manquant
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nettoyage du registre
HKCR\Component Categories\{00021494-0000-0000-C000-000000000046} Supprimé !
HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Supprimé !
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Supprimé !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net Supprimé !
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\net-nucleus.com Supprimé !
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Suppression des fichiers
C:\Progra~1\FreeGo Supprimé !
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Terminé à 23:13:10.84
Redémarrage effectué
voici le résultat Malwarebytes' Anti-Malware 1.12
Version de la base de données: 745
Type de recherche: Examen complet (C:\|)
Eléments examinés: 195439
Temps écoulé: 53 minute(s), 53 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\_004815_.tmp.dll (Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_004848_.tmp.dll (Dropped.Malware) -> Quarantined and deleted successfully.
encore merci