PC infecté HELP!

Résolu
Bonjour,

Voici la liste des virus ci-dessous...

Win32:Rootkit-gen [Rtk] C:\Documents and Settings\Déb\Local Settings\Temp\.tt10.tmp\[Embedded#06d4]
Win32:Rootkit-gen [Rtk] C:\Documents and Settings\Déb\Local Settings\Temp\.tt10.tmp
Win32:Rootkit-gen [Rtk] C:\Documents and Settings\Déb\Local Settings\Temporary Internet Files\Content.IE5\7NTXBR2H\._file[1].exe
Win32:Trojan-gen {Other} C:\Program Files\rhcr1cj0er1q\rhcr1cj0er1q.exe
Win32:Rootkit-gen [Rtk] C:\WINDOWS\system32\drivers\svchost.exe
Win32:Trojan-gen {Other} C:\WINDOWS\system32\lphcv1cj0er1q.exe
Win32:FraudTool-GI [Tool]c:\WINDOWS\system32\pphcv1cj0er1q.exe
Win32:Trojan-gen {Other} C:\WINDOWs\system32\blphcv1cj0er1q.scr

Que faire pour supprimer les trojans?

Merci d'avance pour votre aide
Configuration: Windows Vista
Internet Explorer 7.0

43 réponses

Résumé de la discussion

Plusieurs messages décrivent une infection par des trojans et des rootkits sous Windows XP et Windows Vista, avec des détections récurrentes de Win32:Rootkit-gen et Win32:Trojan-gen et des fichiers système compromis. Pour la suppression, les conseils privilégient le démarrage en mode sans échec et l’usage d’outils dédiés tels SmitFraudFix et SDFix, complétés par des scans rootkit comme GMER. Les résultats cités indiquent la détection et la suppression des composants malveillants, avec des rapports détaillant les fichiers suspects, les services modifiés et les entrées système à nettoyer ou restaurer. Une nuance utile est que le succès dépend souvent du mode sans échec et de l’identification correcte des rootkits, avec des outils complémentaires recommandés selon le contexte.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    Bonjour,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. merci pour ton aide mais je suis pas sur le pc infecté la donc je ferai un rapport surement ce soir et donc par conséquent j'aimerai que tu y jette si possible un coup d'oeil car perso je n'y connais pas grand chose alors ton aide me serai précieuse.

      Merci
      0
      1. Contributeur sécurité
        Re,

        je serai là ce soir.

        J'examinerai les rapports et je te donnerai la marche à suivre pour t'en débarrasser.
        0
        1. merci bien et pour infos ca ne sera pas avant 21h30 pour le rapport...je ne pourrai pas avant donc voila et encore merci pour ton aide
          0
          1. Log.txt

            Logfile of random's system information tool 1.02 (written by random/random)
            Run by Déb at 2008-09-18 21:39:33
            Microsoft Windows XP Édition familiale Service Pack 3
            System drive C: has 10 GB (22%) free of 45 GB
            Total RAM: 1014 MB (53% free)

            HijackThis download failed

            ======Registry dump======

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
            Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-07-07 439872]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
            Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
            RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2007-11-19 370296]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]
            EoBho Class - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll []

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
            Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-04-17 323904]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
            Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll [2008-08-03 654320]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - Acer eDataSecurity Management - C:\WINDOWS\system32\ToolBand.dll [2005-10-19 94208]
            {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-07-07 439872]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "LaunchApp"=Alaunch []
            "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-11-16 15600128]
            "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
            "SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2005-01-07 102491]
            "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-01-07 692315]
            "PCMService"=C:\Program Files\Acer\Acer Arcade\PCMService.exe [2005-08-31 147456]
            "IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-05 208952]
            "MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-05 59392]
            "PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
            "PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
            "igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2005-07-18 94208]
            "igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2005-07-18 77824]
            "igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2005-07-18 114688]
            "eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2005-10-19 69632]
            "EPM-DM"=c:\acer\Empowering Technology\ePower\epm-dm.exe [2005-11-25 212992]
            "Acer ePower Management"=C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe [2005-11-09 3084288]
            "LManager"=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [2005-12-01 458752]
            "eRecoveryService"=C:\Acer\Empowering Technology\eRecovery\Monitor.exe [2005-11-16 397312]
            "ADMTray.exe"=C:\Acer\Empowering Technology\admtray.exe [2005-10-24 2462208]
            "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2004-12-18 278528]
            "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-08-20 98304]
            "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-07-19 78008]
            "SpeedTouch USB Diagnostics"=C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe [2003-09-05 878080]
            "EoEngine"=C:\Program Files\eoRezo\EoEngine.exe []
            "EoTraduction"=C:\WINDOWS\system32\
            "TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2007-11-19 185896]
            "sysrest32.exe"=C:\WINDOWS\system32\sysrest32.exe [2008-09-18 23552]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
            "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
            "kifaavli"=c:\documents and settings\déb\local settings\application data\kifaavli.exe kifaavli []
            "Run"=C:\Documents and Settings\Déb\Application Data\Adobe\Manager.exe []
            "eMuleAutoStart"=C:\Program Files\eMule\emule.exe [2007-05-13 5308416]

            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
            Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            Outil de mise à jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
            C:\WINDOWS\system32\Ati2evxx.dll [2005-12-11 47104]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
            C:\WINDOWS\system32\igfxdev.dll [2005-07-18 135168]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
            C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
            WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "NoDispBackgroundPage"=1
            "NoDispScrSavPage"=1

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "dontdisplaylastusername"=0
            "legalnoticecaption"=
            "legalnoticetext"=
            "shutdownwithoutlogon"=1
            "undockwithoutlogon"=1

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveTypeAutoRun"=00000000

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\Program Files\Acer\Acer Arcade\PCMService.exe"="C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
            "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
            "C:\Program Files\Messenger\MSMSGS.EXE"="C:\Program Files\Messenger\MSMSGS.EXE:*:Enabled:Windows Messenger"
            "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
            "C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
            "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Disabled:Veoh Client"
            "C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
            "C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
            "C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
            "C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
            "C:\Program Files\MSN Messenger\MsnMsgr.Exe"="C:\Program Files\MSN Messenger\MsnMsgr.Exe:*:Enabled:Windows Live Messenger 8.1"
            "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
            "C:\WINDOWS\System32\DRIVERS\svchost.exe"="C:\WINDOWS\System32\DRIVERS\svchost.exe:*:Disabled:svchost"
            "C:\Documents and Settings\Déb\Local Settings\Temp\.tt10.tmp"="C:\Documents and Settings\Déb\Local Settings\Temp\.tt10.tmp:*:Enabled:enable"

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
            "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "C:\Program Files\MSN Messenger\MsnMsgr.Exe"="C:\Program Files\MSN Messenger\MsnMsgr.Exe:*:Enabled:Windows Live Messenger 8.1"
            "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6d342616-85b8-11dd-90bc-00166f90054e}]
            shell\AutoRun\command - v.cmd
            shell\explore\command - v.cmd
            shell\open\command - v.cmd

            ======List of files/folders created in the last 1 months======

            2008-09-18 21:39:34 ----D---- C:\Program Files\trend micro
            2008-09-18 21:39:33 ----D---- C:\rsit
            2008-09-18 10:46:58 ----A---- C:\WINDOWS\system32\sysrest32.exe
            2008-09-18 10:34:24 ----D---- C:\WINDOWS\Minidump
            2008-09-17 11:44:20 ----D---- C:\Documents and Settings\Déb\Application Data\rhcr1cj0er1q
            2008-09-17 11:44:07 ----D---- C:\Program Files\rhcr1cj0er1q
            2008-09-16 10:28:12 ----SHD---- C:\FOUND.017
            2008-09-15 21:06:04 ----SHD---- C:\FOUND.016
            2008-09-14 14:29:36 ----D---- C:\Documents and Settings\All Users\Application Data\Google
            2008-09-13 07:58:58 ----SHD---- C:\FOUND.015
            2008-09-11 23:40:23 ----HD---- C:\WINDOWS\$NtUninstallKB951978$
            2008-09-11 19:59:02 ----SHD---- C:\FOUND.014
            2008-09-10 19:12:42 ----SHD---- C:\Config.Msi
            2008-09-10 19:10:26 ----D---- C:\WINDOWS\Prefetch
            2008-09-10 18:55:42 ----HD---- C:\WINDOWS\$NtUninstallKB938464$
            2008-09-10 18:55:35 ----HD---- C:\WINDOWS\$NtUninstallKB946648$
            2008-09-10 18:55:25 ----HD---- C:\WINDOWS\$NtUninstallKB952287$
            2008-09-10 18:55:15 ----HD---- C:\WINDOWS\$NtUninstallKB951066$
            2008-09-10 18:55:09 ----HD---- C:\WINDOWS\$NtUninstallKB952954$
            2008-09-10 18:55:03 ----HD---- C:\WINDOWS\$NtUninstallKB950974$
            2008-09-10 18:54:56 ----HD---- C:\WINDOWS\$NtUninstallKB951748$
            2008-09-10 18:54:50 ----HD---- C:\WINDOWS\$NtUninstallKB951376-v2$
            2008-09-10 18:54:44 ----HD---- C:\WINDOWS\$NtUninstallKB950762$
            2008-09-10 18:54:38 ----HD---- C:\WINDOWS\$NtUninstallKB951376$
            2008-09-10 18:54:31 ----HD---- C:\WINDOWS\$NtUninstallKB951698$
            2008-09-10 18:50:56 ----D---- C:\WINDOWS\l2schemas
            2008-09-10 18:50:55 ----D---- C:\WINDOWS\system32\fr
            2008-09-10 18:50:55 ----D---- C:\WINDOWS\system32\bits
            2008-09-10 18:48:26 ----D---- C:\WINDOWS\ServicePackFiles
            2008-09-10 18:40:19 ----HD---- C:\WINDOWS\$NtServicePackUninstall$
            2008-09-10 18:40:18 ----D---- C:\WINDOWS\EHome
            2008-09-10 18:30:42 ----HD---- C:\WINDOWS\$NtUninstallKB938464_0$
            2008-09-10 18:30:23 ----HD---- C:\WINDOWS\$NtUninstallKB954154_WM11$
            2008-09-03 15:55:17 ----D---- C:\Program Files\SopCast
            2008-09-03 15:53:53 ----A---- C:\Program Files\StreamPlayer-3.0.3-2008-4-30_090415.exe
            2008-09-03 15:31:31 ----D---- C:\Program Files\eMule
            2008-09-03 15:31:09 ----A---- C:\Program Files\Official-eMule_setup.exe

            ======List of files/folders modified in the last 1 months======

            2008-09-18 21:38:16 ----A---- C:\WINDOWS\win.ini
            2008-09-18 21:38:08 ----A---- C:\WINDOWS\system32\eRLog.ini
            2008-09-18 21:38:00 ----A---- C:\WINDOWS\ModemLog_HDAUDIO Soft Data Fax Modem with SmartCP.txt
            2008-09-18 21:34:26 ----A---- C:\WINDOWS\SchedLgU.Txt
            2008-09-16 12:28:14 ----A---- C:\WINDOWS\DUMP5062.tmp
            2008-09-10 19:12:38 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
            2008-09-10 19:11:08 ----A---- C:\WINDOWS\OEWABLog.txt
            2008-09-10 19:10:22 ----A---- C:\WINDOWS\setuplog.txt
            2008-09-10 18:55:48 ----A---- C:\WINDOWS\imsins.BAK
            2008-08-26 22:28:12 ----A---- C:\WINDOWS\system32\MRT.exe

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
            R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
            R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
            R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
            R1 OsaFsLoc;OsaFsLoc; \??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys []
            R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
            R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.9.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-08-19 21275]
            R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
            R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
            R2 EpmPsd;Acer EPM Power Scheme Driver; \??\C:\WINDOWS\system32\drivers\epm-psd.sys []
            R2 EpmShd;Acer EPM System Hardware Driver; \??\C:\WINDOWS\system32\drivers\epm-shd.sys []
            R2 int15.sys;int15.sys; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys []
            R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
            R2 osaio;osaio; \??\C:\WINDOWS\system32\drivers\osaio.sys []
            R2 osanbm;osanbm; \??\C:\WINDOWS\system32\drivers\osanbm.sys []
            R2 s24trans;Transport RLAN; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-11-09 13440]
            R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
            R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
            R3 DKbFltr;Dritek Keyboard Filter Driver; C:\WINDOWS\system32\DRIVERS\DKbFltr.sys [2004-12-08 16896]
            R3 GEARAspiWDM;GEAR CDRom Filter; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2004-09-14 13872]
            R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
            R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-10-18 998656]
            R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-10-23 218496]
            R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-07-18 1049180]
            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-11-17 4069888]
            R3 NdisFilt;OSA NdisFilter Protocol; C:\WINDOWS\System32\Drivers\NdisFilt.sys [2005-09-13 4392]
            R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys [2006-01-06 6144]
            R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2005-09-29 78720]
            R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-01-07 191456]
            R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
            R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
            R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
            R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
            R3 w29n51;Pilote de carte de connexion réseau Intel(R) PRO/Wireless 2200BG pour Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2005-09-11 3298432]
            R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-10-18 721280]
            S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-12-11 1414656]
            S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
            S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-07-07 55216]
            S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
            S3 NETMNT;Acer NetMonitor Protocol; C:\WINDOWS\system32\DRIVERS\NETMNT.sys [2005-05-02 9600]
            S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2005-08-03 32512]
            S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320]
            S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336]
            S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000]
            S3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\IDS-DI~1\20050901.036\symidsco.sys []
            S3 sysrest.sys;sysrest.sys; \??\C:\WINDOWS\system32\sysrest.sys []
            S3 USB_RNDIS;Thomson ST Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
            S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
            S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
            S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-07-19 16056]
            R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-07-19 147640]
            R2 AWService;AdminWorks Agent X6; C:\Acer\Empowering Technology\admServ.exe [2005-10-24 1314816]
            R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe [2005-08-31 249954]
            R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe [2005-08-31 114784]
            R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe [2005-08-31 61440]
            R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-11-09 114753]
            R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-08-06 138680]
            R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-11-09 217164]
            R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-09-20 143360]
            R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-11-09 540745]
            R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-07-19 250040]
            R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-07-23 348344]
            R3 iPodService;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2004-12-18 327680]
            S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-12-11 393216]
            S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
            S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
            S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
            S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2005-08-03 86016]
            S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
            S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
            S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

            -----------------EOF-----------------
            0
            1. Info.txt

              info.txt logfile of random's system information tool 1.02 2008-09-18 21:39:36

              ======Uninstall list======

              -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
              -->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Acer Inc.\Acer French Guide Link\Uninst.isu"
              -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{13E613EF-BB55-11D9-9D77-000129760D75}\setup.exe" -uninstall
              -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC4F90EC-B1DA-11D9-9D77-000129760D75}\setup.exe" -uninstall
              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
              Acer Arcade-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
              Acer eDataSecurity Management 1.00.23-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E431C518-2EE2-471E-9234-BE995C36D513}\setup.exe" -l0x40c -removeonly
              Acer eLock Management-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}
              Acer Empowering Technology framework-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{15B70821-7893-4607-805A-BB80F3EA8279}
              Acer eNet Management-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C06554A1-2C1E-4D20-B613-EE62C79927CC}\Setup.exe" -l0x40c
              Acer ePerformance Management-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{DEE08946-40F0-4890-853E-60A6C3306041}
              Acer ePower Management-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\Setup.exe" -l0x9
              Acer ePresentation Management-->C:\WINDOWS\UnInst32.exe AcerePrj.UNI
              Acer eSettings Management-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}
              Acer GridVista-->C:\WINDOWS\UnInst32.exe GridV.UNI
              Acer Screensaver-->MsiExec.exe /I{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}
              Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
              Adobe Reader 7.0.9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
              AntivirXP08-->"C:\Program Files\rhcr1cj0er1q\uninstall.exe"
              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
              Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
              Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
              Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
              DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
              eMule-->"C:\Program Files\eMule\Uninstall.exe"
              eoEngine 4.9-->"C:\Program Files\eoRezo\unins000.exe"
              eoTraduction 1.0-->"C:\Program Files\eoRezo\EoTraduction\unins000.exe"
              Favorit-->"c:\documents and settings\déb\local settings\application data\kifaavli.exe" -uninstall
              Freecorder 2.3 (with Skype Call Recording)-->C:\WINDOWS\iun6002.exe "D:\Emule\Virginie\irunin.ini"
              Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
              HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_AcrS009E\HXFSETUP.EXE -U -IAcrS009E.inf
              High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
              Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
              Intel(R) Graphics Media Accelerator Driver for Mobile-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2792 PCI\VEN_8086&DEV_2592
              iPod for Windows 2005-03-23-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{44A537A5-859C-43A6-8285-C0668142A090} /l1036
              iTunes-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3CB41017-F5CA-4C56-934C-ED02156251E6}
              Launch Manager-->C:\WINDOWS\UnInst32.exe QtZgAcer.UNI
              Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
              Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
              mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
              Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
              Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
              Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
              Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
              Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
              Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
              Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
              mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
              Mozilla Firefox (2.0.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
              mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
              MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
              MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
              mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
              mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
              NTI Backup NOW! 4-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{385979FE-DC4F-4140-8EAD-A59625000D72} /l1036 BUN4
              NTI CD & DVD-Maker-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
              Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
              PCFriendly-->C:\Program Files\PCFriendly\inuninst.exe
              PhotoCite Collection-->"C:\Program Files\PhotoCite Collection\unins000.exe"
              PowerProducer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
              QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
              RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
              Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
              SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
              SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
              Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
              SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
              SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
              Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
              Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
              SpeedTouch USB Software-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}\Setup.exe" /l040c -Control_Panel
              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
              VideoLAN VLC media player 0.8.6-->C:\Program Files\VideoLAN\VLC\uninstall.exe
              Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
              Windows Live Sign-in Assistant-->MsiExec.exe /I{F652D238-5F29-42D5-BAF3-0115EF977EC2}
              Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
              Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
              Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
              Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
              Yahoo! Anti-Spy-->C:\PROGRA~1\YAHOO!\COMMON\unypsr.exe
              Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\WINDOWS\cache\YINSTH~1.DLL
              Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->C:\PROGRA~1\YAHOO!\COMMON\unyt.exe

              ======Security center information======

              AV: avast! antivirus 4.8.1229 [VPS 080917-0]

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\Wireless\Bin\;C:\Program Files\Samsung\Samsung PC Studio 3\
              "windir"=%SystemRoot%
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "PROCESSOR_ARCHITECTURE"=x86
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
              "PROCESSOR_REVISION"=0d08
              "NUMBER_OF_PROCESSORS"=1
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP

              -----------------EOF-----------------
              0
              1. Contributeur sécurité
                Bonsoir,

                Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
                et télécharge SmitfraudFix.exe.

                Regarde le tuto
                Exécute le en choisissant l’option 1, il va générer un rapport
                Copie/colle le sur le poste stp.
                0
                1. ok je fais ca la un peu de patience merci
                  0
                  1. SmitFraudFix v2.352

                    Rapport fait à 22:22:04,57, 18/09/2008
                    Executé à partir de C:\Documents and Settings\D‚b\Bureau\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est
                    Fix executé en mode normal

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Acer\Empowering Technology\admServ.exe
                    C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                    C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                    C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Acer\Acer Arcade\PCMService.exe
                    C:\WINDOWS\system32\igfxtray.exe
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                    C:\acer\Empowering Technology\ePower\epm-dm.exe
                    C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
                    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                    C:\Acer\Empowering Technology\admtray.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\WINDOWS\system32\igfxsrvc.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\eMule\emule.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                    C:\WINDOWS\system32\igfxext.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\Documents and Settings\Déb\Bureau\SmitfraudFix\Policies.exe
                    C:\WINDOWS\system32\cmd.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    C:\WINDOWS\system32\tdssservers.dat détecté, utilisez un scanner de Rootkit
                    C:\WINDOWS\system32\tdssadw.dll détecté, utilisez un scanner de Rootkit
                    C:\WINDOWS\system32\tdssinit.dll détecté, utilisez un scanner de Rootkit
                    C:\WINDOWS\system32\tdssl.dll détecté, utilisez un scanner de Rootkit
                    C:\WINDOWS\system32\tdsslog.dll détecté, utilisez un scanner de Rootkit
                    C:\WINDOWS\system32\tdssmain.dll détecté, utilisez un scanner de Rootkit
                    C:\WINDOWS\system32\drivers\tdssserv.sys détecté, utilisez un scanner de Rootkit

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\D‚b

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\D‚b\Application Data

                    C:\Documents and Settings\D‚b\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk PRESENT !

                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\DÉB\FAVORIS

                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="Ma page d'accueil"

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    404Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    AntiXPVSTFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{4D127212-D21A-422E-B0A4-BCA2909B187F}: DhcpNameServer=212.27.40.241 212.27.40.240
                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin
                    0
                    1. Contributeur sécurité
                      Re,

                      pas de problème pour le temps. je devrais être là jusque vers minuit.

                      On continue comme ça :

                      Relance le programme Smitfraud,
                      Cette fois choisit l’option 2, répond oui a tous ;
                      Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                      Imprime ces instructions car tu n'y auras pas accès durant le passage en mode sans échec.
                      Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                      http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                      Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié dans C:\. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                      • Redémarre ton ordinateur
                      • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                      • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                      • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                      • Choisis ton compte.
                      Déroule la liste des instructions ci-dessous :
                      • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le scrïpt.
                      • Appuie sur Y pour commencer le processus de nettoyage.
                      • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                      • Appuie sur une touche pour redémarrer le PC.
                      • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                      • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                      • Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
                      • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                      • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse

                      Refais tourner RSIT et poste le rapport (log)

                      0
                      1. rapport de smit option 2
                        ci-dessous

                        SmitFraudFix v2.352

                        Rapport fait à 22:53:48,15, 18/09/2008
                        Executé à partir de C:\Documents and Settings\D‚b\Bureau\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est
                        Fix executé en mode normal

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        127.0.0.1 localhost

                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                        VACFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                        S!Ri's WS2Fix: LSP not Found.

                        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                        GenericRenosFix by S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                        C:\Documents and Settings\D‚b\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk supprimé

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                        IEDFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                        404Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                        AntiXPVSTFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» RK

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{4D127212-D21A-422E-B0A4-BCA2909B187F}: DhcpNameServer=212.27.40.241 212.27.40.240
                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240

                        »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "System"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                        Nettoyage terminé.

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                        0
                        1. impossible de demarrer en mode ss échec, comment faire?
                          0
                          1. Contributeur sécurité
                            Re,

                            on va changer d'outil.

                            Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                            - Va dans démarrer puis panneau de configuration
                            - Double Clique sur l'icône "Comptes d'utilisateurs"
                            - Clique ensuite sur désactiver et valide.

                            télécharge combofix (par sUBs) ici :

                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                            et enregistre le sur le Bureau.

                            déconnecte toi d'internet et ferme toutes tes applications.

                            désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                            double-clique sur combofix.exe et suis les instructions

                            à la fin, il va produire un rapport C:\ComboFix.txt

                            réactive ton parefeu, ton antivirus, la garde de ton antispyware

                            copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                            Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                            Tu as un tutoriel complet ici :

                            https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                            0
                            1. Ok je vais faire la manip ce midi je pense.
                              Merci encore pour ton aide.
                              0
                              1. Sur XP je ne vois pas une fonction pour désactivé le compte utilisateur... comment faire?
                                0
                                1. Contributeur sécurité
                                  Re,

                                  oublie ....
                                  En fait, ton message initial a été émis d'un autre ordi que celui que l'on traite (et qui est sous Vista).

                                  quand j'ai vérifié ton OS, je suis remonté là au lieu de vérifier sur ton rapport RSIT.

                                  Tu commences à "télécharge Combofix ...." et tu ignores les lignes qui sont au-dessus.
                                  0
                                  1. voici le rapport de Combo...

                                    ComboFix 08-09-16.05 - Déb 2008-09-19 13:20:16.1 - [color=red][b]FAT32[/b][/color]x86
                                    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.539 [GMT 2:00]
                                    Lancé depuis: C:\Documents and Settings\Déb\Bureau\ComboFix.exe
                                    * Un nouveau point de restauration a été créé

                                    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                                    .

                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Antivirus XP 2008
                                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Antivirus XP 2008.lnk
                                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Antivirus XP 2008\Antivirus XP 2008.lnk
                                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
                                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Antivirus XP 2008\License Agreement.lnk
                                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Antivirus XP 2008\Register Antivirus XP 2008.lnk
                                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Antivirus XP 2008\Uninstall.lnk
                                    C:\Documents and Settings\Déb\Application Data\Adobe\crc.dat
                                    C:\Documents and Settings\Déb\Application Data\rhcr1cj0er1q
                                    C:\Documents and Settings\Déb\Cookies\déb@bluestreak[1].txt
                                    C:\Documents and Settings\Déb\Cookies\déb@tradedoubler[2].txt
                                    C:\Documents and Settings\Déb\Cookies\déb@wss.hbpl.co[2].txt
                                    C:\Documents and Settings\Déb\Local Settings\Application Data\kifaavli.dat
                                    C:\Documents and Settings\Déb\Local Settings\Application Data\kifaavli_nav.dat
                                    C:\Documents and Settings\Déb\Local Settings\Application Data\kifaavli_navps.dat
                                    C:\WINDOWS\system32\drivers\npf.sys
                                    C:\WINDOWS\system32\packet.dll
                                    C:\WINDOWS\system32\phcv1cj0er1q.bmp
                                    C:\WINDOWS\system32\pthreadVC.dll
                                    C:\WINDOWS\system32\tdssadw.dll
                                    C:\WINDOWS\system32\tdssinit.dll
                                    C:\WINDOWS\system32\tdssl.dll
                                    C:\WINDOWS\system32\tdsslog.dll
                                    C:\WINDOWS\system32\tdssmain.dll
                                    C:\WINDOWS\system32\tdssserf.dll
                                    C:\WINDOWS\system32\tdssservers.dat
                                    C:\WINDOWS\system32\WanPacket.dll
                                    C:\WINDOWS\system32\wpcap.dll
                                    F:\autorun.inf

                                    .
                                    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    -------\Legacy_SYSREST.SYS
                                    -------\Service_NPF
                                    -------\Service_sysrest.sys

                                    ((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-19 au 2008-09-19 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2008-09-19 13:16 . 2008-09-19 13:16 <REP> d--hs---- C:\FOUND.018
                                    2008-09-18 23:06 . 2008-09-16 17:42 <REP> d-------- C:\SDFix
                                    2008-09-18 22:22 . 2008-09-18 22:58 4,746 --a------ C:\WINDOWS\system32\tmp.reg
                                    2008-09-18 22:16 . 2008-09-18 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
                                    2008-09-18 22:16 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                                    2008-09-18 22:10 . 2008-09-18 10:46 23,552 --------- C:\WINDOWS\system32\trz2.tmp
                                    2008-09-18 21:39 . 2008-09-18 21:39 <REP> d-------- C:\rsit
                                    2008-09-18 21:39 . 2008-09-18 21:39 <REP> d-------- C:\Program Files\trend micro
                                    2008-09-17 11:44 . 2008-09-17 11:44 <REP> d-------- C:\Program Files\rhcr1cj0er1q
                                    2008-09-16 10:28 . 2008-09-16 10:28 <REP> d--hs---- C:\FOUND.017
                                    2008-09-15 21:06 . 2008-09-15 21:06 <REP> d--hs---- C:\FOUND.016
                                    2008-09-13 07:58 . 2008-09-13 07:58 <REP> d--hs---- C:\FOUND.015
                                    2008-09-11 19:59 . 2008-09-11 19:59 <REP> d--hs---- C:\FOUND.014
                                    2008-09-10 18:50 . 2008-09-10 18:50 <REP> d-------- C:\WINDOWS\system32\fr
                                    2008-09-10 18:50 . 2008-09-10 18:50 <REP> d-------- C:\WINDOWS\system32\bits
                                    2008-09-10 18:50 . 2008-09-10 18:50 <REP> d-------- C:\WINDOWS\l2schemas
                                    2008-09-10 18:48 . 2008-09-10 18:48 <REP> d-------- C:\WINDOWS\ServicePackFiles
                                    2008-09-10 18:40 . 2008-09-10 18:40 <REP> d-------- C:\WINDOWS\EHome
                                    2008-09-03 15:55 . 2008-09-03 15:55 <REP> d-------- C:\Program Files\SopCast
                                    2008-09-03 15:53 . 2008-09-03 15:53 3,239,612 --a------ C:\Program Files\StreamPlayer-3.0.3-2008-4-30_090415.exe
                                    2008-09-03 15:31 . 2008-09-03 15:31 <REP> d-------- C:\Program Files\eMule
                                    2008-09-03 15:31 . 2008-09-03 15:31 3,792,267 --a------ C:\Program Files\Official-eMule_setup.exe
                                    2008-08-26 21:16 . 2004-08-03 22:29 1,897,408 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2008-09-18 21:13 90,112 ----a-w C:\WINDOWS\DUMP3587.tmp
                                    2008-09-18 21:08 90,112 ----a-w C:\WINDOWS\DUMP0fee.tmp
                                    2008-09-18 20:14 90,112 ----a-w C:\WINDOWS\DUMP3661.tmp
                                    2008-09-16 10:28 90,112 ----a-w C:\WINDOWS\DUMP5062.tmp
                                    2008-07-30 19:13 6,626,040 ----a-w C:\Program Files\FirefoxGoogleToolbarSetup.exe
                                    2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
                                    2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
                                    2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
                                    2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
                                    2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
                                    2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
                                    2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
                                    2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
                                    2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
                                    2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
                                    2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
                                    2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
                                    2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
                                    2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
                                    2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
                                    2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
                                    2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
                                    2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
                                    2008-06-24 16:44 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
                                    2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
                                    2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
                                    2008-06-23 09:21 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
                                    2008-06-23 09:21 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
                                    2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
                                    2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
                                    2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
                                    2008-06-20 17:47 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
                                    2008-06-20 17:47 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
                                    2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
                                    2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
                                    2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
                                    2007-10-07 20:07 3,954,000 ----a-w C:\Program Files\MsgPlusLive-423.exe
                                    2007-08-09 15:21 4,374,807 ----a-w C:\Program Files\traducteur.exe
                                    2007-08-06 08:06 880,064 ----a-w C:\Program Files\Google_Updater.exe
                                    2006-12-21 09:25 9,451,515 ----a-w C:\Program Files\vlc-0.8.6-win32.exe
                                    2006-12-07 18:57 7,516,896 ----a-w C:\Program Files\PhotoCite_Collection.exe
                                    2006-09-01 06:01 1,126,352 ----a-w C:\Program Files\wrar360fr.exe
                                    2006-08-30 19:26 15,295,272 ----a-w C:\Program Files\Install_Messenger.exe
                                    2006-08-30 16:09 1,104,734 ----a-w C:\Program Files\dvdshrink_3.2.0.16_fr.zip
                                    2006-08-29 19:26 11,803,568 ----a-w C:\Program Files\setupfre.exe
                                    .

                                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
                                    REGEDIT4

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
                                    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
                                    "eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 5308416]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "LaunchApp"="Alaunch" [X]
                                    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 102491]
                                    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 692315]
                                    "PCMService"="C:\Program Files\Acer\Acer Arcade\PCMService.exe" [2005-08-31 147456]
                                    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
                                    "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
                                    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                                    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                                    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-18 94208]
                                    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-18 77824]
                                    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-18 114688]
                                    "eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-10-19 69632]
                                    "EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-25 212992]
                                    "Acer ePower Management"="C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]
                                    "LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752]
                                    "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
                                    "ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
                                    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-12-18 278528]
                                    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-20 98304]
                                    "SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2003-09-05 878080]
                                    "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-11-19 185896]
                                    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
                                    "RTHDCPL"="RTHDCPL.EXE" [2005-11-16 C:\WINDOWS\RTHDCPL.exe]

                                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                    "msacm.mkdmp3enc"= C:\PROGRA~1\Acer\ACERAR~1\Kernel\Burner\MKDMP3Enc.ACM

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                    "EnableFirewall"= 0 (0x0)

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                    "%windir%\\system32\\sessmgr.exe"=
                                    "C:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
                                    "C:\\Program Files\\iTunes\\iTunes.exe"=
                                    "C:\\Program Files\\Messenger\\MSMSGS.EXE"=
                                    "C:\\Program Files\\eMule\\emule.exe"=
                                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                    "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
                                    "C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
                                    "C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe"=
                                    "C:\\Program Files\\MSN Messenger\\livecall.exe"=

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                                    "65091:TCP"= 65091:TCP:emule_TCP
                                    "16689:UDP"= 16689:UDP:emule_UDP

                                    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
                                    R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 12106]
                                    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
                                    R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 4096]
                                    R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-04-07 78208]
                                    R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 69632]
                                    R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 7296]
                                    R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 4010]
                                    R3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 4392]
                                    .
                                    - - - - ORPHELINS SUPPRIMES - - - -

                                    HKCU-Run-kifaavli - c:\documents and settings\déb\local settings\application data\kifaavli.exe
                                    HKLM-Run-EoEngine - C:\Program Files\eoRezo\EoEngine.exe
                                    HKLM-Run-sysrest32.exe - C:\WINDOWS\system32\sysrest32.exe
                                    HKLM-Run-EoTraduction - (no file)

                                    .
                                    ------- Examen suppl‚mentaire -------
                                    .
                                    FireFox -: Profile - C:\Documents and Settings\Déb\Application Data\Mozilla\Firefox\Profiles\9868f9pj.default\
                                    .

                                    **************************************************************************

                                    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2008-09-19 13:26:34
                                    Windows 5.1.2600 Service Pack 3 FAT NTAPI

                                    Recherche de processus cach‚s ...

                                    Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...

                                    Recherche de fichiers cach‚s ...

                                    Scan termin‚ avec succŠs
                                    Fichiers cach‚s: 0

                                    **************************************************************************
                                    .
                                    ------------------------ Autres processus actifs ------------------------
                                    .
                                    C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE
                                    C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE
                                    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
                                    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
                                    C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.EXE
                                    C:\ACER\EMPOWERING TECHNOLOGY\ADMSERV.EXE
                                    C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\TV\CLCAPSVC.EXE
                                    C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\CLML_NTSERVICE\CLMLSERVER.EXE
                                    C:\PROGRAM FILES\GOOGLE\COMMON\GOOGLE UPDATER\GOOGLEUPDATERSERVICE.EXE
                                    C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\CLML_NTSERVICE\CLMLSERVICE.EXE
                                    C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE
                                    C:\PROGRAM FILES\CYBERLINK\SHARED FILES\RICHVIDEO.EXE
                                    C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\TV\CLSCHED.EXE
                                    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
                                    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\PROGRAM FILES\LAUNCH MANAGER\QTZGACER.EXE
                                    C:\Program Files\iPod\bin\iPodService.exe
                                    C:\WINDOWS\system32\igfxext.exe
                                    C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE
                                    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                    C:\PROGRAM FILES\GOOGLE\GOOGLE UPDATER\GOOGLEUPDATER.EXE
                                    C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
                                    .
                                    **************************************************************************
                                    .
                                    Heure de fin: 2008-09-19 13:29:35 - La machine a red‚marr‚
                                    ComboFix-quarantined-files.txt 2008-09-19 11:29:28

                                    Avant-CF: 10,731,618,304 octets libres
                                    AprŠs-CF: 11,865,391,104 octets libres

                                    233 --- E O F --- 2008-09-11 21:40:30
                                    0
                                    1. Contributeur sécurité
                                      Re,

                                      je n'ai pas vraiment le temps d'examiner en détail avant ce soir.

                                      Pour avancer, essaye de refaire la deuxième partie du post 10 (SDFix en mode sans échec), puis, après retour en mode normal, un nouveau rapport RSIT.

                                      Si tu ne peux toujours pas faire SDFix, fais RSIT quand même.
                                      0
                                      1. Ok merci, je vais réessayer dans la soirée de faire en mode sans échec.
                                        A+
                                        0
                                        1. C'est bon cette fois-ci ca à marché en mode sans échec voici le rapport...

                                          [b]SDFix: Version 1.226 [/b]
                                          Run by D‚b on 19/09/2008 at 18:19

                                          Microsoft Windows XP [version 5.1.2600]
                                          Running From: C:\SDFix

                                          [b]Checking Services [/b]:

                                          Restoring Default Security Values
                                          Restoring Default Hosts File

                                          Rebooting

                                          [b]Checking Files [/b]:

                                          Trojan Files Found:

                                          C:\WINDOWS\antiv.exe - Deleted

                                          Removing Temp Files

                                          [b]ADS Check [/b]:

                                          [b]Final Check [/b]:

                                          catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                          Rootkit scan 2008-09-19 18:22:46
                                          Windows 5.1.2600 Service Pack 3 FAT NTAPI

                                          scanning hidden processes ...

                                          scanning hidden services ...

                                          scanning hidden autostart entries ...

                                          scanning hidden files ...

                                          scan completed successfully
                                          hidden processes: 0
                                          hidden services: 0
                                          hidden files: 0

                                          [b]Remaining Services [/b]:

                                          Authorized Application Key Export:

                                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                          "C:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"="C:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
                                          "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                                          "C:\\Program Files\\Messenger\\MSMSGS.EXE"="C:\\Program Files\\Messenger\\MSMSGS.EXE:*:Enabled:Windows Messenger"
                                          "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                                          "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
                                          "C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
                                          "C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe"="C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe:*:Enabled:Windows Live Messenger 8.1"
                                          "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                          "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
                                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                                          "C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe"="C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe:*:Enabled:Windows Live Messenger 8.1"
                                          "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                                          [b]Remaining Files [/b]:

                                          File Backups: - C:\SDFix\backups\backups.zip

                                          [b]Files with Hidden Attributes [/b]:

                                          Fri 6 Jan 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTIBUN4.dll"
                                          Fri 6 Jan 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTICDMK7.dll"
                                          Fri 6 Jan 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTIMPEG2.dll"
                                          Fri 6 Jan 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTIMP3.dll"
                                          Fri 6 Jan 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTIFCD3.dll"
                                          Fri 22 Sep 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                                          Sun 4 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                                          Sat 5 Apr 2008 143,872 ...H. --- "C:\Documents and Settings\D‚b\Application Data\Microsoft\Word\~WRL2480.tmp"

                                          [b]Finished![/b]
                                          0
                                          • 1
                                          • 2
                                          • 3