Mon pc bloque sans cesse
j'ai besoin d'aide car mon ordi bloque tres souvent malgré tous les netoyages au quotidien
merci de m'aider
Configuration: Windows Vista Firefox 3.5.3
22 réponses
Blocage fréquent de l’ordinateur sous Windows Vista et Firefox 3.5.3 malgré des nettoyages quotidiens, ce qui peut indiquer une infection ou une maintenance inappropriée persistance. Parmi les réponses, il est conseillé d’arrêter l’outil OTM, puis de désactiver des comptes d’utilisateur et de relancer OTM en mode administrateur afin d’initier un diagnostic sur l’infection. En cas de persistance, des solutions complémentaires évoquent RSIT et ComboFix, puis Malwarebytes et une restauration système, avec vérification des rapports et réactivation de la protection en temps réel après le diagnostic. Des échanges ultérieurs signalent l’importance de disposer d’un antivirus et de nettoyer les rapports de scan, et montrent qu’un point de restauration ou l’absence d’antivirus peut influencer les résultats et la stabilité du système.
-
Essayes de le démmarrer en mode sans échec:
==> Comment aller en Mode sans échec
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis l' option : Sans Échec avec prise en charge rèseau et valide avec "Entrée"
a+ -
je note quand mème que "relevantknowledje" est toujours visible dans__tous les programmes
Supprime le manuellement (clc droit).
a+-
-
bonjour archet9,
j'ai un gros soussis,alors que tout allé bien,haujourd'hui vers midi,le pc à planté completement
j'ai éssayé de le faire partir mais je n'y arrive pas,je voudrais avoir accés à la restauration système que j'ai fait hier mais je ne sais pas faire puisque le seul moyen d'accés c'est en tapotant les touches f9,f12,supprime,etc
as-tu une soluce
merci
-
-
Donc si tout va bien...
Pour desinstaller les outils utilisés
Telecharge ToolsCleaner2--> http://pc-system.fr/
-Une fois téléchargé, installe-le et lance-le
-Clique sur Recherche et laisse le scan se terminer
-Clique sur SUPPRESSION
-Clique sur Quitter pour que le rapport puisse se créer
-Poste moi le rapport se trouvant ici--> C:\TCleaner.txt
puis
---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse(Sauvegarde la base de registre).
* Décoche la case plus vieux que 48 h
TRES IMPORTANT:
---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
XP:
https://www.tayo.fr/desactiver-restauration-systeme-sur-windows-xp-tutoriel.php
VISTA:
https://www.tayo.fr/desactiver-restauration-windows-vista-tutoriel.php
---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
https://www.vulgarisation-informatique.com/creer-point-restauration.php
a+
-
j'ai fais ce que tu m'as demandé,mais Tcleaner me refuse le log text:
(impossible de creer le fichier "c:\Tcleaner,txt"accés refusé) mais j'ai quand mème suprimé les outils
je note quand mème que "relevantknowledje" est toujours visible dans__tous les programmes__
sinon il ne me reste plus qu'a purger la restauration système
voila,voila
-
-
Voyons voir ce qu'en pense Genproc:
Telecharge GENPROC
http://www.genproc.com/GenProc.exe
Copie et colle le rapport stp...
a+
-
voila chef
Rapport GenProc 2.640 [1] - 26/10/2009 à 19:33:00
@ Windows Vista Service Pack 2 - Mode normal
@ Mozilla Firefox (3.5.3) [Navigateur par défaut]
GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :
Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
- coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
C:\Program Files\EsetOnlineScanner\log.txt
~~~~ INFORMATION COMPLEMENTAIRE ~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:33:49, on 26/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\cmd.exe
C:\GenProc\outil\jc-joce_GenProc.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files\RelevantKnowledge\rlservice.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
-
-
j'ai oublié de te dire que une restauration systeme à été faite
==> Et RelevantKnowledge est revenu avec la restauration système....
Relances malwarebytes
mets le a jour...(onglet mise a jour)
Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".
a+-
le voici
et merci encore pour ta patience
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 3036
Windows 6.0.6002 Service Pack 2
26/10/2009 19:15:49
mbam-log-2009-10-26 (19-15-49).txt
Type de recherche: Examen rapide
Eléments examinés: 90874
Temps écoulé: 2 minute(s), 9 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
-
-
re,
Relances à nouveau RSIT er si tout est ok, on finira!
a+-
re
j'ai oublié de te dire que une restauration systeme à été faite et qu'on à remis l'anti-virus de chez microsoft
voici le log en deux parties
Logfile of random's system information tool 1.06 (written by random/random)
Run by jc-joce at 2009-10-26 18:12:50
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 584 GB (96%) free of 610 GB
Total RAM: 3326 MB (70% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:13:39, on 26/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\jc-joce\Downloads\RSIT.exe
C:\Program Files\trend micro\jc-joce.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files\RelevantKnowledge\rlservice.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
-
et le deux
2009-10-19 07:08:41 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\scecli.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasplap.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasgcw.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\PnPUnattend.exe
2009-10-19 07:08:41 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2009-10-19 07:08:41 ----A---- C:\Windows\system32\fdWSD.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\cmmon32.exe
2009-10-19 07:08:40 ----A---- C:\Windows\system32\wiaaut.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\whealogr.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\srcore.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\SCardSvr.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\raschap.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\MSVidCtl.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\fontext.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\conime.exe
2009-10-19 07:08:40 ----A---- C:\Windows\system32\cmdial32.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\WMVXENCD.DLL
2009-10-19 07:08:39 ----A---- C:\Windows\system32\wlanui.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\shwebsvc.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\rasppp.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\PnPutil.exe
2009-10-19 07:08:39 ----A---- C:\Windows\system32\oobefldr.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\dsprop.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\dimsroam.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\wmdrmsdk.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\wlgpclnt.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\shsetup.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\rasmontr.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\mscandui.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\modemui.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\dataclen.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\chtbrkr.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\blackbox.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\WSDMon.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\wmpeffects.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\smss.exe
2009-10-19 07:08:37 ----A---- C:\Windows\system32\rdpwsx.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\networkexplorer.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\netplwiz.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\ifmon.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\credui.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\certprop.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\wscapi.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\wpcsvc.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\thawbrkr.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\softkbd.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\sendmail.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\msscp.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\msimtf.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\logagent.exe
2009-10-19 07:08:36 ----A---- C:\Windows\system32\InkEd.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\gpresult.exe
2009-10-19 07:08:36 ----A---- C:\Windows\system32\cipher.exe
2009-10-19 07:08:35 ----A---- C:\Windows\system32\puiapi.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\olepro32.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\msctfui.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\input.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\ExplorerFrame.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\drmmgrtn.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\dmsynth.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\cdd.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\wshbth.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\version.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\SLLUA.exe
2009-10-19 07:08:34 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\msisip.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\mprapi.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\fdSSDP.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\fc.exe
2009-10-19 07:08:34 ----A---- C:\Windows\system32\dmusic.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\cscapi.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\wsdchngr.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\Storprop.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\SMBHelperClass.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdial.exe
2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdiag.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\msjint40.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\l2nacp.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\ftp.exe
2009-10-19 07:08:33 ----A---- C:\Windows\system32\fdWCN.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\eapp3hst.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\dot3cfg.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\cscdll.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthudtask.exe
2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthci.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\tscupgrd.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\slcinst.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\ocsetup.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\nslookup.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\networkitemfactory.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\ipconfig.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\hbaapi.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\fdeploy.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappgnui.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappcfg.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2009-10-19 07:08:31 ----A---- C:\Windows\system32\PNPXAssoc.dll
2009-10-19 07:08:31 ----A---- C:\Windows\system32\mmcico.dll
2009-10-19 07:08:31 ----A---- C:\Windows\system32\gpupdate.exe
2009-10-19 07:08:31 ----A---- C:\Windows\system32\cbsra.exe
2009-10-19 07:08:30 ----A---- C:\Windows\system32\winrnr.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\vdmdbg.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\slwga.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\odbcconf.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\NcdProp.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\iscsilog.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\inetppui.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\csrstub.exe
2009-10-19 07:08:30 ----A---- C:\Windows\system32\bitsigd.dll
2009-10-19 07:08:29 ----A---- C:\Windows\system32\midimap.dll
2009-10-19 07:08:28 ----A---- C:\Windows\system32\msimsg.dll
2009-10-19 07:08:28 ----A---- C:\Windows\system32\f3ahvoas.dll
2009-10-19 07:08:19 ----A---- C:\Windows\system32\SmiEngine.dll
2009-10-19 07:08:18 ----A---- C:\Windows\system32\wdscore.dll
2009-10-19 07:08:18 ----A---- C:\Windows\system32\PkgMgr.exe
2009-10-19 07:08:17 ----A---- C:\Windows\system32\drvstore.dll
2009-10-19 04:27:16 ----A---- C:\Windows\system32\Oemdspif.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdva.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdag.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atitmmxx.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atipdlxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atioglxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe.manifest
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe.manifest
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atidxx32.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIDEMGX.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atibrtmon.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atiadlxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ati2edxx.dll
2009-10-19 04:27:13 ----A---- C:\Windows\system32\amdpcom32.dll
2009-10-18 21:51:41 ----A---- C:\Windows\system32\jscript.dll
2009-10-18 21:48:52 ----D---- C:\Users\jc-joce\AppData\Roaming\WinRAR
2009-10-18 21:47:09 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-10-18 21:46:46 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-10-18 21:45:27 ----D---- C:\Program Files\CCleaner
2009-10-18 21:43:15 ----D---- C:\Program Files\WinRAR
2009-10-18 21:40:10 ----D---- C:\Program Files\Microsoft
2009-10-18 21:39:54 ----D---- C:\Program Files\Windows Live SkyDrive
2009-10-18 21:39:38 ----D---- C:\Program Files\Windows Live
2009-10-18 21:33:20 ----N---- C:\Windows\system32\MpSigStub.exe
2009-10-18 21:32:37 ----D---- C:\Program Files\Common Files\Windows Live
2009-10-18 21:29:57 ----D---- C:\Program Files\Microsoft Security Essentials
2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Wide).ini
2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Normal).ini
2009-10-18 21:18:38 ----D---- C:\Windows\Acer_Wide
2009-10-18 21:18:38 ----D---- C:\Program Files\Acer Incorporated
2009-10-18 21:18:36 ----D---- C:\Windows\Acer_Normal
2009-10-18 21:17:59 ----D---- C:\Users\jc-joce\AppData\Roaming\Mozilla
2009-10-18 21:17:53 ----D---- C:\Program Files\Mozilla Firefox
2009-10-18 21:17:29 ----D---- C:\Users\jc-joce\AppData\Roaming\InstallShield
2009-10-18 21:17:14 ----D---- C:\Program Files\Northstar
2009-10-18 21:13:23 ----A---- C:\Windows\system32\occache.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\ieui.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\iepeers.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\wininet.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\msfeedssync.exe
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iesetup.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iertutil.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iernonce.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\ie4uinit.exe
2009-10-18 21:13:20 ----A---- C:\Windows\system32\urlmon.dll
2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-18 21:13:20 ----A---- C:\Windows\system32\iesysprep.dll
2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieframe.dll
2009-10-18 21:13:19 ----A---- C:\Windows\system32\mshtml.dll
2009-10-18 21:11:43 ----A---- C:\Windows\system32\mshtmled.dll
2009-10-18 21:11:43 ----A---- C:\Windows\system32\icardie.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\msls31.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\mshtmler.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\imgutil.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\ieakeng.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\dxtmsft.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\corpol.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\admparse.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\webcheck.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\msrating.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\licmgr10.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\inseng.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\ieaksie.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\dxtrans.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\WinFXDocObj.exe
2009-10-18 21:11:40 ----A---- C:\Windows\system32\wextract.exe
2009-10-18 21:11:40 ----A---- C:\Windows\system32\pngfilt.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\mstime.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieapfltr.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieakui.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\advpack.dll
2009-10-18 21:11:39 ----A---- C:\Windows\system32\vbscript.dll
2009-10-18 21:11:39 ----A---- C:\Windows\system32\url.dll
2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetDepNx.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\PDMSetup.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\mshta.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\iexpress.exe
2009-10-18 21:10:04 ----D---- C:\Users\jc-joce\AppData\Roaming\Macromedia
2009-10-18 21:07:27 ----D---- C:\Users\jc-joce\AppData\Roaming\Adobe
2009-10-18 21:07:21 ----D---- C:\Users\jc-joce\AppData\Roaming\Google
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32_priv.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32_priv.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwi2c32.dll
2009-10-18 21:01:38 ----A---- C:\Windows\system32\tzres.dll
2009-10-18 20:16:37 ----A---- C:\Windows\system32\netfxperf.dll
2009-10-18 20:15:15 ----D---- C:\Program Files\MSXML 4.0
2009-10-18 20:02:30 ----A---- C:\Windows\system32\netiohlp.dll
2009-10-18 20:02:27 ----A---- C:\Windows\system32\NETSTAT.EXE
2009-10-18 20:02:27 ----A---- C:\Windows\system32\ARP.EXE
2009-10-18 20:02:26 ----A---- C:\Windows\system32\TCPSVCS.EXE
2009-10-18 20:02:25 ----A---- C:\Windows\system32\HOSTNAME.EXE
2009-10-18 20:02:25 ----A---- C:\Windows\system32\finger.exe
2009-10-18 20:02:24 ----A---- C:\Windows\system32\ROUTE.EXE
2009-10-18 20:02:24 ----A---- C:\Windows\system32\MRINFO.EXE
2009-10-18 20:02:21 ----A---- C:\Windows\system32\netevent.dll
2009-10-18 20:01:21 ----A---- C:\Windows\system32\gameux.dll
2009-10-18 20:01:18 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-10-18 20:01:15 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-10-18 20:01:12 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-10-18 20:01:12 ----A---- C:\Windows\system32\mf.dll
2009-10-18 20:01:10 ----A---- C:\Windows\system32\rrinstaller.exe
2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfps.dll
2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfpmp.exe
2009-10-18 20:01:09 ----A---- C:\Windows\system32\mferror.dll
2009-10-18 20:00:43 ----A---- C:\Windows\system32\rpcrt4.dll
2009-10-18 20:00:36 ----A---- C:\Windows\system32\lsasrv.dll
2009-10-18 20:00:36 ----A---- C:\Windows\system32\kerberos.dll
2009-10-18 20:00:35 ----A---- C:\Windows\system32\wdigest.dll
2009-10-18 20:00:35 ----A---- C:\Windows\system32\schannel.dll
2009-10-18 20:00:32 ----A---- C:\Windows\system32\secur32.dll
2009-10-18 20:00:30 ----A---- C:\Windows\system32\lsass.exe
2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-18 20:00:20 ----A---- C:\Windows\system32\wmp.dll
2009-10-18 20:00:18 ----A---- C:\Windows\system32\wmpdxm.dll
2009-10-18 20:00:15 ----A---- C:\Windows\system32\spwmp.dll
2009-10-18 20:00:13 ----A---- C:\Windows\system32\dxmasf.dll
2009-10-18 20:00:12 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-18 20:00:05 ----A---- C:\Windows\system32\localspl.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansvc.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansec.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanmsm.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanhlp.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\L2SecHC.dll
2009-10-18 19:59:59 ----A---- C:\Windows\system32\wlanapi.dll
2009-10-18 19:59:54 ----A---- C:\Windows\system32\tsgqec.dll
2009-10-18 19:59:54 ----A---- C:\Windows\system32\mstscax.dll
2009-10-18 19:59:54 ----A---- C:\Windows\system32\aaclient.dll
2009-10-18 19:59:50 ----A---- C:\Windows\system32\t2embed.dll
2009-10-18 19:59:50 ----A---- C:\Windows\system32\fontsub.dll
2009-10-18 19:59:50 ----A---- C:\Windows\system32\atmfd.dll
2009-10-18 19:59:49 ----A---- C:\Windows\system32\lpk.dll
2009-10-18 19:59:49 ----A---- C:\Windows\system32\atmlib.dll
2009-10-18 19:59:47 ----A---- C:\Windows\system32\dciman32.dll
2009-10-18 19:59:44 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-18 19:59:20 ----A---- C:\Windows\system32\wkssvc.dll
2009-10-18 19:59:03 ----A---- C:\Windows\system32\avifil32.dll
2009-10-18 19:58:56 ----A---- C:\Windows\system32\atl.dll
2009-10-18 19:55:01 ----A---- C:\Windows\system32\msasn1.dll
2009-10-18 19:49:22 ----D---- C:\ProgramData\ATI
2009-10-18 19:49:21 ----D---- C:\Users\jc-joce\AppData\Roaming\ATI
2009-10-18 19:49:13 ----SHD---- C:\$RECYCLE.BIN
2009-10-18 19:48:56 ----D---- C:\Users\jc-joce\AppData\Roaming\Identities
2009-10-18 19:48:49 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2009-10-18 19:48:19 ----D---- C:\ProgramData\Partner
2009-10-18 19:47:42 ----D---- C:\ProgramData\Google
2009-10-18 19:47:39 ----D---- C:\Program Files\Google
2009-10-18 19:45:00 ----SD---- C:\Users\jc-joce\AppData\Roaming\Microsoft
2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Media Center Programs
2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Acer GameZone Console
2009-10-18 19:42:14 ----A---- C:\Windows\system32\wups2.dll
2009-10-18 19:42:14 ----A---- C:\Windows\system32\wucltux.dll
2009-10-18 19:42:14 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-18 19:42:13 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-18 19:42:06 ----A---- C:\Windows\system32\wups.dll
2009-10-18 19:42:06 ----A---- C:\Windows\system32\wudriver.dll
2009-10-18 19:42:05 ----A---- C:\Windows\system32\wuapi.dll
2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuapp.exe
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Modèles
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Menu Démarrer
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Favoris
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Bureau
2009-10-18 19:41:29 ----SHD---- C:\Program Files\Fichiers communs
2009-10-18 19:35:33 ----D---- C:\Program Files\ATI Technologies
2009-10-18 19:32:38 ----D---- C:\Program Files\ATI
2009-10-18 19:32:28 ----A---- C:\Windows\ATIDetect.txt
2009-10-18 19:30:35 ----A---- C:\Windows\system32\nvraiins.dll
2009-10-18 19:30:32 ----D---- C:\Windows\SoftwareDistribution
======List of files/folders modified in the last 1 months======
2009-10-26 17:01:43 ----D---- C:\Windows\System32
2009-10-26 17:01:43 ----D---- C:\Windows\inf
2009-10-26 17:01:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-10-26 16:57:24 ----D---- C:\Windows
2009-10-26 16:13:36 ----D---- C:\Windows\system32\LogFiles
2009-10-26 14:41:55 ----HD---- C:\Windows\system32\GroupPolicy
2009-10-26 14:41:55 ----HD---- C:\ProgramData
2009-10-26 14:08:35 ----RD---- C:\Program Files
2009-10-26 13:48:56 ----SHD---- C:\System Volume Information
2009-10-26 13:15:48 ----D---- C:\Windows\rescache
2009-10-26 13:12:25 ----SHD---- C:\Windows\Installer
2009-10-26 12:39:28 ----D---- C:\Windows\winsxs
2009-10-26 12:39:26 ----D---- C:\Windows\system32\migration
2009-10-26 12:39:26 ----D---- C:\Windows\system32\fr-FR
2009-10-26 12:39:25 ----D---- C:\Windows\system32\inetsrv
2009-10-26 07:13:37 ----D---- C:\Windows\system32\config
2009-10-26 07:13:32 ----D---- C:\Windows\Tasks
2009-10-26 07:13:32 ----D---- C:\Windows\system32\spool
2009-10-26 07:13:31 ----SD---- C:\ProgramData\Microsoft
2009-10-26 07:13:31 ----D---- C:\Windows\system32\drivers
2009-10-26 07:13:31 ----D---- C:\Windows\system32\CodeIntegrity
2009-10-26 07:13:30 ----D---- C:\Windows\registration
2009-10-26 06:16:06 ----D---- C:\Windows\system32\catroot2
2009-10-26 06:14:19 ----D---- C:\Windows\system32\Msdtc
2009-10-26 06:14:18 ----D---- C:\Windows\system32\wbem
2009-10-25 15:14:25 ----D---- C:\Windows\AppPatch
2009-10-25 15:14:25 ----D---- C:\Program Files\Common Files
2009-10-25 14:08:07 ----D---- C:\Windows\Prefetch
2009-10-24 19:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-24 19:29:42 ----RSD---- C:\Windows\Fonts
2009-10-24 19:29:41 ----SD---- C:\Windows\Downloaded Program Files
2009-10-24 19:29:41 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-24 16:33:30 ----D---- C:\PerfLogs
2009-10-23 15:06:04 ----D---- C:\Windows\ShellNew
2009-10-23 07:25:11 ----D---- C:\Windows\Logs
2009-10-22 06:39:42 ----D---- C:\Windows\system32\Tasks
2009-10-21 08:13:28 ----D---- C:\Windows\system32\NDF
2009-10-19 19:50:37 ----D---- C:\Windows\twain_32
2009-10-19 19:50:17 ----A---- C:\Windows\win.ini
2009-10-19 15:24:11 ----D---- C:\Windows\Microsoft.NET
2009-10-19 15:24:04 ----RSD---- C:\Windows\assembly
2009-10-19 15:14:27 ----D---- C:\Windows\system32\catroot
2009-10-19 14:41:10 ----D---- C:\ProgramData\CyberLink
2009-10-19 09:13:32 ----D---- C:\Program Files\Common Files\Adobe
2009-10-19 09:13:28 ----D---- C:\ProgramData\Adobe
2009-10-19 07:24:45 ----D---- C:\Boot
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Sidebar
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Media Player
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Mail
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Collaboration
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Calendar
2009-10-19 07:20:50 ----D---- C:\Program Files\Movie Maker
2009-10-19 07:20:50 ----D---- C:\Program Files\Internet Explorer
2009-10-19 07:20:49 ----D---- C:\Program Files\Windows Photo Gallery
2009-10-19 07:20:49 ----D---- C:\Program Files\Common Files\System
2009-10-19 07:20:48 ----D---- C:\Windows\servicing
2009-10-19 07:20:48 ----D---- C:\Windows\ehome
2009-10-19 07:20:48 ----D---- C:\Program Files\Windows Defender
2009-10-19 07:20:46 ----D---- C:\Windows\system32\lv-LV
2009-10-19 07:20:46 ----D---- C:\Windows\IME
2009-10-19 07:20:45 ----D---- C:\Windows\system32\XPSViewer
2009-10-19 07:20:45 ----D---- C:\Windows\system32\sk-SK
2009-10-19 07:20:45 ----D---- C:\Windows\system32\ru-RU
2009-10-19 07:20:45 ----D---- C:\Windows\system32\oobe
2009-10-19 07:20:45 ----D---- C:\Windows\system32\ko-KR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\it-IT
2009-10-19 07:20:45 ----D---- C:\Windows\system32\hr-HR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr
2009-10-19 07:20:45 ----D---- C:\Windows\system32\et-EE
2009-10-19 07:20:45 ----D---- C:\Windows\system32\en-US
2009-10-19 07:20:45 ----D---- C:\Windows\system32\el-GR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\de-DE
2009-10-19 07:20:45 ----D---- C:\Windows\system32\da-DK
2009-10-19 07:20:45 ----D---- C:\Windows\system32\AdvancedInstallers
2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-TW
2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-CN
2009-10-19 07:20:44 ----D---- C:\Windows\system32\uk-UA
2009-10-19 07:20:44 ----D---- C:\Windows\system32\th-TH
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sv-SE
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sr-Latn-CS
2009-10-19 07:20:44 ----D---- C:\Windows\system32\SLUI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sl-SI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\setup
2009-10-19 07:20:44 ----D---- C:\Windows\system32\ro-RO
2009-10-19 07:20:44 ----D---- C:\Windows\system32\pt-PT
2009-10-19 07:20:44 ----D---- C:\Windows\system32\pl-PL
2009-10-19 07:20:44 ----D---- C:\Windows\system32\manifeststore
2009-10-19 07:20:44 ----D---- C:\Windows\system32\ja-JP
2009-10-19 07:20:44 ----D---- C:\Windows\system32\hu-HU
2009-10-19 07:20:44 ----D---- C:\Windows\system32\he-IL
2009-10-19 07:20:44 ----D---- C:\Windows\system32\fi-FI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\es-ES
2009-10-19 07:20:44 ----D---- C:\Windows\system32\cs-CZ
2009-10-19 07:20:44 ----D---- C:\Windows\system32\bg-BG
2009-10-19 07:20:43 ----D---- C:\Windows\system32\tr-TR
2009-10-19 07:20:43 ----D---- C:\Windows\system32\pt-BR
2009-10-19 07:20:43 ----D---- C:\Windows\system32\nl-NL
2009-10-19 07:20:43 ----D---- C:\Windows\system32\nb-NO
2009-10-19 07:20:43 ----D---- C:\Windows\system32\migwiz
2009-10-19 07:20:43 ----D---- C:\Windows\system32\lt-LT
2009-10-19 07:20:43 ----D---- C:\Windows\system32\ar-SA
2009-10-19 07:20:35 ----D---- C:\Windows\system32\Boot
2009-10-19 07:19:30 ----D---- C:\Windows\system32\RTCOM
2009-10-18 22:26:52 ----D---- C:\Windows\Debug
2009-10-18 22:06:49 ----D---- C:\Windows\system32\WDI
2009-10-18 21:50:23 ----D---- C:\ProgramData\Microsoft Help
2009-10-18 21:47:38 ----D---- C:\Program Files\Common Files\microsoft shared
2009-10-18 21:47:31 ----D---- C:\Program Files\Microsoft Works
2009-10-18 21:26:37 ----D---- C:\ACER
2009-10-18 21:21:11 ----D---- C:\Windows\PolicyDefinitions
2009-10-18 21:20:43 ----D---- C:\Windows\system32\OEM
2009-10-18 21:17:31 ----D---- C:\Windows\system
2009-10-18 19:51:46 ----D---- C:\ProgramData\SiteAdvisor
2009-10-18 19:48:11 ----D---- C:\Program Files\Acer
2009-10-18 19:44:49 ----RD---- C:\Users
2009-10-18 19:41:53 ----D---- C:\Windows\system32\restore
2009-10-18 19:41:29 ----D---- C:\Program Files\Windows NT
2009-10-18 19:36:17 ----D---- C:\Windows\Panther
2009-10-02 10:01:58 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-06-18 142832]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-08-19 15392]
R2 irda;Protocole IrDA; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60464]
R2 RMCAST;Pilote du protocole RMCAT PGMP; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-04-11 113664]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-10-03 3977728]
R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-04 2161496]
R3 irsir;Pilote série infrarouge Microsoft; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-21 20992]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2009-06-18 42480]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-07 1050656]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-08-24 15872]
R3 snpstd2;Trek 310; C:\Windows\system32\DRIVERS\snpstd2.sys [2007-06-26 343808]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-10-03 704512]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2008-09-08 450560]
R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 MsMpSvc;@c:\Program Files\Microsoft Security Essentials\MpAsDesc.dll,-241; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-07-02 17904]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2008-09-08 184320]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-05-29 241734]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-08-14 9728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-19 133104]
S2 RelevantKnowledge;RelevantKnowledge; C:\Program Files\RelevantKnowledge\rlservice.exe /service []
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-18 24064]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-18 182768]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2008-01-21 21504]
-----------------EOF-----------------
-
-
est ce qu'il-y-a encore moyen de ratraper mes co....?
Nok...tu n'as pas fais de conneries....
C''était a moi de le voir !!!
==> Nous sommes là pour ça....</gras
>Mais la j'ai toit de même un gros doute ....
Car l'infection a bien éré identififiée...et le premier MBAM ne l'a pas vue !!!!!
==> je vais vérifier les<gras> MAJ
En attendant...Comment se comporte le pc ?
a+
-
bonjour archet9,
je viens d'arriver,j'ai demandé à ma femme pour le pc,elle a travaillée toute la journée dessus,et
c'est RAS; elle a fait du nétoyage dessus, et la pour le moment il tourne impec
ma femme à également scané avec malwarebytes anti-malware +anti-virus et les logs sont sains
cordialement
-
-
Excuses moi mich,
Mais là tu me poses un sérieux pronblème:
Excuses moi mich,
Je t'avais demandé MBAM:
Je l'avais déja à jour, et c'est le quatrième scan que je fais depuis se matin avec voici le log
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 3028
Windows 6.0.6002 Service Pack 2
25/10/2009 12:12:45
mbam-log-2009-10-25 (12-12-45).txt
==> Result :
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
ENSUITE:
==> je te demannde ceci:(avec OTM)
:processes
explorer.exe
:services
relevantknowledge
:files
c:\program files\relevantknowledge\rlservice.exe
:reg
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RelevantKnowledge
:commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Et enfin:
Tu me colles un rapport MBAM:
avec ttes les suppressionns !
Processus mémoire infecté(s):
C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> Unloaded process successfully. C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.MarketScore) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
AS-TU UNE EXPLICATON ?
a+-
je suis vraiment désolé,les rapports que j'ai posté ce sont les plus recents,franchement j'ettais à mille lieux de
savoir qu'un log d'hier était utile, cette pièce je la gardais pour mémoire au cas ou je serais de nouveau infecté
par ces memes virus, ça porte peutètre à sourire mais mes connaissances en informatique est assez limité, et il est vrai que j'aurais put ne pas l'avoir
je suis vraiment confus
est ce qu'il-y-a encore moyen de ratraper mes co....?
A+
-
-
post le...
a+-
le voila et encore merci pour ton aide
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 3023
Windows 6.0.6002 Service Pack 2
24/10/2009 08:43:14
mbam-log-2009-10-24 (08-43-14).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 220292
Temps écoulé: 30 minute(s), 37 second(s)
Processus mémoire infecté(s): 2
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 4
Processus mémoire infecté(s):
C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> Unloaded process successfully.
C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.MarketScore) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
-
-
As tu beaucuop de choses à sauvegarder ?
==> Sinon fais une restauration complète et remmets ton pc comme au premier jour ....
a+ -
A tout hasard....
aurais-tu un point de restauration antérieur a ton problème?
a+-
-
@michsi ça peut aider j'ai un rapport d'hier de malwarebytes anti-malware
-
-
la fin stp
-
3eme tentative de remise
il à encore bloqué
le voici
2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasplap.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasgcw.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\PnPUnattend.exe
2009-10-19 07:08:41 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2009-10-19 07:08:41 ----A---- C:\Windows\system32\fdWSD.dll
2009-10-19 07:08:41 ----A---- C:\Windows\system32\cmmon32.exe
2009-10-19 07:08:40 ----A---- C:\Windows\system32\wiaaut.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\whealogr.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\srcore.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\SCardSvr.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\raschap.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\MSVidCtl.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\fontext.dll
2009-10-19 07:08:40 ----A---- C:\Windows\system32\conime.exe
2009-10-19 07:08:40 ----A---- C:\Windows\system32\cmdial32.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\WMVXENCD.DLL
2009-10-19 07:08:39 ----A---- C:\Windows\system32\wlanui.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\shwebsvc.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\rasppp.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\PnPutil.exe
2009-10-19 07:08:39 ----A---- C:\Windows\system32\oobefldr.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\dsprop.dll
2009-10-19 07:08:39 ----A---- C:\Windows\system32\dimsroam.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\wmdrmsdk.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\wlgpclnt.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\shsetup.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\rasmontr.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\mscandui.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\modemui.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\dataclen.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\chtbrkr.dll
2009-10-19 07:08:38 ----A---- C:\Windows\system32\blackbox.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\WSDMon.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\wmpeffects.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\smss.exe
2009-10-19 07:08:37 ----A---- C:\Windows\system32\rdpwsx.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\networkexplorer.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\netplwiz.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\ifmon.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\credui.dll
2009-10-19 07:08:37 ----A---- C:\Windows\system32\certprop.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\wscapi.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\wpcsvc.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\thawbrkr.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\softkbd.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\sendmail.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\msscp.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\msimtf.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\logagent.exe
2009-10-19 07:08:36 ----A---- C:\Windows\system32\InkEd.dll
2009-10-19 07:08:36 ----A---- C:\Windows\system32\gpresult.exe
2009-10-19 07:08:36 ----A---- C:\Windows\system32\cipher.exe
2009-10-19 07:08:35 ----A---- C:\Windows\system32\puiapi.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\olepro32.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\msctfui.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\input.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\ExplorerFrame.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\drmmgrtn.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\dmsynth.dll
2009-10-19 07:08:35 ----A---- C:\Windows\system32\cdd.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\wshbth.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\version.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\SLLUA.exe
2009-10-19 07:08:34 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\msisip.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\mprapi.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\fdSSDP.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\fc.exe
2009-10-19 07:08:34 ----A---- C:\Windows\system32\dmusic.dll
2009-10-19 07:08:34 ----A---- C:\Windows\system32\cscapi.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\wsdchngr.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\Storprop.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\SMBHelperClass.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdial.exe
2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdiag.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\msjint40.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\l2nacp.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\ftp.exe
2009-10-19 07:08:33 ----A---- C:\Windows\system32\fdWCN.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\eapp3hst.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\dot3cfg.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\cscdll.dll
2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthudtask.exe
2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthci.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\tscupgrd.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\slcinst.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\ocsetup.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\nslookup.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\networkitemfactory.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\ipconfig.exe
2009-10-19 07:08:32 ----A---- C:\Windows\system32\hbaapi.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\fdeploy.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappgnui.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappcfg.dll
2009-10-19 07:08:32 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2009-10-19 07:08:31 ----A---- C:\Windows\system32\PNPXAssoc.dll
2009-10-19 07:08:31 ----A---- C:\Windows\system32\mmcico.dll
2009-10-19 07:08:31 ----A---- C:\Windows\system32\gpupdate.exe
2009-10-19 07:08:31 ----A---- C:\Windows\system32\cbsra.exe
2009-10-19 07:08:30 ----A---- C:\Windows\system32\winrnr.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\vdmdbg.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\slwga.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\odbcconf.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\NcdProp.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\iscsilog.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\inetppui.dll
2009-10-19 07:08:30 ----A---- C:\Windows\system32\csrstub.exe
2009-10-19 07:08:30 ----A---- C:\Windows\system32\bitsigd.dll
2009-10-19 07:08:29 ----A---- C:\Windows\system32\midimap.dll
2009-10-19 07:08:28 ----A---- C:\Windows\system32\msimsg.dll
2009-10-19 07:08:28 ----A---- C:\Windows\system32\f3ahvoas.dll
2009-10-19 07:08:19 ----A---- C:\Windows\system32\SmiEngine.dll
2009-10-19 07:08:18 ----A---- C:\Windows\system32\wdscore.dll
2009-10-19 07:08:18 ----A---- C:\Windows\system32\PkgMgr.exe
2009-10-19 07:08:17 ----A---- C:\Windows\system32\drvstore.dll
2009-10-19 04:27:16 ----A---- C:\Windows\system32\Oemdspif.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdva.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdag.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atitmmxx.dll
2009-10-19 04:27:15 ----A---- C:\Windows\system32\atipdlxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atioglxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe.manifest
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe.manifest
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atidxx32.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIDEMGX.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atibrtmon.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\atiadlxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.exe
2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.dll
2009-10-19 04:27:14 ----A---- C:\Windows\system32\ati2edxx.dll
2009-10-19 04:27:13 ----A---- C:\Windows\system32\amdpcom32.dll
2009-10-18 21:51:41 ----A---- C:\Windows\system32\jscript.dll
2009-10-18 21:48:52 ----D---- C:\Users\jc-joce\AppData\Roaming\WinRAR
2009-10-18 21:47:09 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-10-18 21:46:46 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-10-18 21:45:27 ----D---- C:\Program Files\CCleaner
2009-10-18 21:43:15 ----D---- C:\Program Files\WinRAR
2009-10-18 21:40:10 ----D---- C:\Program Files\Microsoft
2009-10-18 21:39:54 ----D---- C:\Program Files\Windows Live SkyDrive
2009-10-18 21:39:38 ----D---- C:\Program Files\Windows Live
2009-10-18 21:33:20 ----N---- C:\Windows\system32\MpSigStub.exe
2009-10-18 21:32:37 ----D---- C:\Program Files\Common Files\Windows Live
2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Wide).ini
2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Normal).ini
2009-10-18 21:18:38 ----D---- C:\Windows\Acer_Wide
2009-10-18 21:18:38 ----D---- C:\Program Files\Acer Incorporated
2009-10-18 21:18:36 ----D---- C:\Windows\Acer_Normal
2009-10-18 21:17:59 ----D---- C:\Users\jc-joce\AppData\Roaming\Mozilla
2009-10-18 21:17:53 ----D---- C:\Program Files\Mozilla Firefox
2009-10-18 21:17:29 ----D---- C:\Users\jc-joce\AppData\Roaming\InstallShield
2009-10-18 21:17:14 ----D---- C:\Program Files\Northstar
2009-10-18 21:13:23 ----A---- C:\Windows\system32\occache.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\ieui.dll
2009-10-18 21:13:22 ----A---- C:\Windows\system32\iepeers.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\wininet.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\msfeedssync.exe
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iesetup.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iertutil.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iernonce.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-18 21:13:21 ----A---- C:\Windows\system32\ie4uinit.exe
2009-10-18 21:13:20 ----A---- C:\Windows\system32\urlmon.dll
2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-18 21:13:20 ----A---- C:\Windows\system32\iesysprep.dll
2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieframe.dll
2009-10-18 21:13:19 ----A---- C:\Windows\system32\mshtml.dll
2009-10-18 21:11:43 ----A---- C:\Windows\system32\mshtmled.dll
2009-10-18 21:11:43 ----A---- C:\Windows\system32\icardie.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\msls31.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\mshtmler.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\imgutil.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\ieakeng.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\dxtmsft.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\corpol.dll
2009-10-18 21:11:42 ----A---- C:\Windows\system32\admparse.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\webcheck.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\msrating.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\licmgr10.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\inseng.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\ieaksie.dll
2009-10-18 21:11:41 ----A---- C:\Windows\system32\dxtrans.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\WinFXDocObj.exe
2009-10-18 21:11:40 ----A---- C:\Windows\system32\wextract.exe
2009-10-18 21:11:40 ----A---- C:\Windows\system32\pngfilt.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\mstime.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieapfltr.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieakui.dll
2009-10-18 21:11:40 ----A---- C:\Windows\system32\advpack.dll
2009-10-18 21:11:39 ----A---- C:\Windows\system32\vbscript.dll
2009-10-18 21:11:39 ----A---- C:\Windows\system32\url.dll
2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetDepNx.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\PDMSetup.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\mshta.exe
2009-10-18 21:11:38 ----A---- C:\Windows\system32\iexpress.exe
2009-10-18 21:10:04 ----D---- C:\Users\jc-joce\AppData\Roaming\Macromedia
2009-10-18 21:07:27 ----D---- C:\Users\jc-joce\AppData\Roaming\Adobe
2009-10-18 21:07:21 ----D---- C:\Users\jc-joce\AppData\Roaming\Google
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32_priv.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32_priv.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32.dll
2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwi2c32.dll
2009-10-18 21:01:38 ----A---- C:\Windows\system32\tzres.dll
2009-10-18 20:16:37 ----A---- C:\Windows\system32\netfxperf.dll
2009-10-18 20:15:15 ----D---- C:\Program Files\MSXML 4.0
2009-10-18 20:02:30 ----A---- C:\Windows\system32\netiohlp.dll
2009-10-18 20:02:27 ----A---- C:\Windows\system32\NETSTAT.EXE
2009-10-18 20:02:27 ----A---- C:\Windows\system32\ARP.EXE
2009-10-18 20:02:26 ----A---- C:\Windows\system32\TCPSVCS.EXE
2009-10-18 20:02:25 ----A---- C:\Windows\system32\HOSTNAME.EXE
2009-10-18 20:02:25 ----A---- C:\Windows\system32\finger.exe
2009-10-18 20:02:24 ----A---- C:\Windows\system32\ROUTE.EXE
2009-10-18 20:02:24 ----A---- C:\Windows\system32\MRINFO.EXE
2009-10-18 20:02:21 ----A---- C:\Windows\system32\netevent.dll
2009-10-18 20:01:21 ----A---- C:\Windows\system32\gameux.dll
2009-10-18 20:01:18 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-10-18 20:01:15 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-10-18 20:01:12 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-10-18 20:01:12 ----A---- C:\Windows\system32\mf.dll
2009-10-18 20:01:10 ----A---- C:\Windows\system32\rrinstaller.exe
2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfps.dll
2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfpmp.exe
2009-10-18 20:01:09 ----A---- C:\Windows\system32\mferror.dll
2009-10-18 20:00:43 ----A---- C:\Windows\system32\rpcrt4.dll
2009-10-18 20:00:36 ----A---- C:\Windows\system32\lsasrv.dll
2009-10-18 20:00:36 ----A---- C:\Windows\system32\kerberos.dll
2009-10-18 20:00:35 ----A---- C:\Windows\system32\wdigest.dll
2009-10-18 20:00:35 ----A---- C:\Windows\system32\schannel.dll
2009-10-18 20:00:32 ----A---- C:\Windows\system32\secur32.dll
2009-10-18 20:00:30 ----A---- C:\Windows\system32\lsass.exe
2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-18 20:00:20 ----A---- C:\Windows\system32\wmp.dll
2009-10-18 20:00:18 ----A---- C:\Windows\system32\wmpdxm.dll
2009-10-18 20:00:15 ----A---- C:\Windows\system32\spwmp.dll
2009-10-18 20:00:13 ----A---- C:\Windows\system32\dxmasf.dll
2009-10-18 20:00:12 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-18 20:00:05 ----A---- C:\Windows\system32\localspl.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansvc.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansec.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanmsm.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanhlp.dll
2009-10-18 20:00:01 ----A---- C:\Windows\system32\L2SecHC.dll
2009-10-18 19:59:59 ----A---- C:\Windows\system32\wlanapi.dll
2009-10-18 19:59:54 ----A---- C:\Windows\system32\tsgqec.dll
2009-10-18 19:59:54 ----A---- C:\Windows\system32\mstscax.dll
2009-10-18 19:59:54 ----A---- C:\Windows\system32\aaclient.dll
2009-10-18 19:59:50 ----A---- C:\Windows\system32\t2embed.dll
2009-10-18 19:59:50 ----A---- C:\Windows\system32\fontsub.dll
2009-10-18 19:59:50 ----A---- C:\Windows\system32\atmfd.dll
2009-10-18 19:59:49 ----A---- C:\Windows\system32\lpk.dll
2009-10-18 19:59:49 ----A---- C:\Windows\system32\atmlib.dll
2009-10-18 19:59:47 ----A---- C:\Windows\system32\dciman32.dll
2009-10-18 19:59:44 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-18 19:59:20 ----A---- C:\Windows\system32\wkssvc.dll
2009-10-18 19:59:03 ----A---- C:\Windows\system32\avifil32.dll
2009-10-18 19:58:56 ----A---- C:\Windows\system32\atl.dll
2009-10-18 19:55:01 ----A---- C:\Windows\system32\msasn1.dll
2009-10-18 19:49:22 ----D---- C:\ProgramData\ATI
2009-10-18 19:49:21 ----D---- C:\Users\jc-joce\AppData\Roaming\ATI
2009-10-18 19:49:13 ----D---- C:\$RECYCLE.BIN
2009-10-18 19:48:56 ----D---- C:\Users\jc-joce\AppData\Roaming\Identities
2009-10-18 19:48:49 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2009-10-18 19:48:19 ----D---- C:\ProgramData\Partner
2009-10-18 19:47:42 ----D---- C:\ProgramData\Google
2009-10-18 19:47:39 ----D---- C:\Program Files\Google
2009-10-18 19:45:00 ----SD---- C:\Users\jc-joce\AppData\Roaming\Microsoft
2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Media Center Programs
2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Acer GameZone Console
2009-10-18 19:42:14 ----A---- C:\Windows\system32\wups2.dll
2009-10-18 19:42:14 ----A---- C:\Windows\system32\wucltux.dll
2009-10-18 19:42:14 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-18 19:42:13 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-18 19:42:06 ----A---- C:\Windows\system32\wups.dll
2009-10-18 19:42:06 ----A---- C:\Windows\system32\wudriver.dll
2009-10-18 19:42:05 ----A---- C:\Windows\system32\wuapi.dll
2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuapp.exe
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Modèles
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Menu Démarrer
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Favoris
2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Bureau
2009-10-18 19:41:29 ----SHD---- C:\Program Files\Fichiers communs
2009-10-18 19:35:33 ----D---- C:\Program Files\ATI Technologies
2009-10-18 19:32:38 ----D---- C:\Program Files\ATI
2009-10-18 19:32:28 ----A---- C:\Windows\ATIDetect.txt
2009-10-18 19:30:35 ----A---- C:\Windows\system32\nvraiins.dll
2009-10-18 19:30:32 ----D---- C:\Windows\SoftwareDistribution
======List of files/folders modified in the last 1 months======
2009-10-25 17:08:39 ----D---- C:\Windows\System32
2009-10-25 17:08:39 ----D---- C:\Windows\inf
2009-10-25 17:08:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-10-25 15:17:05 ----D---- C:\Windows
2009-10-25 15:16:13 ----N---- C:\Windows\system.ini
2009-10-25 15:14:25 ----D---- C:\Windows\system32\drivers
2009-10-25 15:14:25 ----D---- C:\Windows\AppPatch
2009-10-25 15:14:25 ----D---- C:\Program Files\Common Files
2009-10-25 14:08:07 ----D---- C:\Windows\Prefetch
2009-10-25 13:56:59 ----D---- C:\Windows\system32\catroot2
2009-10-25 10:34:48 ----RD---- C:\Program Files
2009-10-24 23:47:55 ----SHD---- C:\Windows\Installer
2009-10-24 23:47:48 ----SD---- C:\ProgramData\Microsoft
2009-10-24 22:25:39 ----D---- C:\Windows\system32\wbem
2009-10-24 22:24:59 ----D---- C:\Windows\system32\config
2009-10-24 22:24:54 ----D---- C:\Windows\Tasks
2009-10-24 22:24:54 ----D---- C:\Windows\system32\spool
2009-10-24 22:24:54 ----D---- C:\Windows\system32\Msdtc
2009-10-24 22:24:54 ----D---- C:\Windows\system32\CodeIntegrity
2009-10-24 22:24:53 ----D---- C:\Windows\registration
2009-10-24 22:24:09 ----SHD---- C:\System Volume Information
2009-10-24 19:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-24 19:29:42 ----RSD---- C:\Windows\Fonts
2009-10-24 19:29:41 ----SD---- C:\Windows\Downloaded Program Files
2009-10-24 19:29:41 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-24 19:29:29 ----D---- C:\ProgramData
2009-10-24 16:33:30 ----D---- C:\PerfLogs
2009-10-23 15:22:49 ----D---- C:\Windows\rescache
2009-10-23 15:06:04 ----D---- C:\Windows\ShellNew
2009-10-23 15:05:20 ----D---- C:\Windows\winsxs
2009-10-23 07:25:11 ----D---- C:\Windows\Logs
2009-10-22 17:28:32 ----D---- C:\Windows\system32\LogFiles
2009-10-22 06:39:42 ----D---- C:\Windows\system32\Tasks
2009-10-21 08:13:28 ----D---- C:\Windows\system32\NDF
2009-10-19 19:50:37 ----D---- C:\Windows\twain_32
2009-10-19 19:50:17 ----A---- C:\Windows\win.ini
2009-10-19 15:24:11 ----D---- C:\Windows\Microsoft.NET
2009-10-19 15:24:04 ----RSD---- C:\Windows\assembly
2009-10-19 15:14:27 ----D---- C:\Windows\system32\catroot
2009-10-19 14:41:10 ----D---- C:\ProgramData\CyberLink
2009-10-19 09:13:32 ----D---- C:\Program Files\Common Files\Adobe
2009-10-19 09:13:28 ----D---- C:\ProgramData\Adobe
2009-10-19 07:24:45 ----D---- C:\Boot
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Sidebar
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Media Player
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Mail
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Collaboration
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Calendar
2009-10-19 07:20:50 ----D---- C:\Program Files\Movie Maker
2009-10-19 07:20:50 ----D---- C:\Program Files\Internet Explorer
2009-10-19 07:20:49 ----D---- C:\Program Files\Windows Photo Gallery
2009-10-19 07:20:49 ----D---- C:\Program Files\Common Files\System
2009-10-19 07:20:48 ----D---- C:\Windows\servicing
2009-10-19 07:20:48 ----D---- C:\Windows\ehome
2009-10-19 07:20:48 ----D---- C:\Program Files\Windows Defender
2009-10-19 07:20:46 ----D---- C:\Windows\system32\lv-LV
2009-10-19 07:20:46 ----D---- C:\Windows\IME
2009-10-19 07:20:45 ----D---- C:\Windows\system32\XPSViewer
2009-10-19 07:20:45 ----D---- C:\Windows\system32\sk-SK
2009-10-19 07:20:45 ----D---- C:\Windows\system32\ru-RU
2009-10-19 07:20:45 ----D---- C:\Windows\system32\oobe
2009-10-19 07:20:45 ----D---- C:\Windows\system32\migration
2009-10-19 07:20:45 ----D---- C:\Windows\system32\ko-KR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\it-IT
2009-10-19 07:20:45 ----D---- C:\Windows\system32\hr-HR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr-FR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr
2009-10-19 07:20:45 ----D---- C:\Windows\system32\et-EE
2009-10-19 07:20:45 ----D---- C:\Windows\system32\en-US
2009-10-19 07:20:45 ----D---- C:\Windows\system32\el-GR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\de-DE
2009-10-19 07:20:45 ----D---- C:\Windows\system32\da-DK
2009-10-19 07:20:45 ----D---- C:\Windows\system32\AdvancedInstallers
2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-TW
2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-CN
2009-10-19 07:20:44 ----D---- C:\Windows\system32\uk-UA
2009-10-19 07:20:44 ----D---- C:\Windows\system32\th-TH
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sv-SE
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sr-Latn-CS
2009-10-19 07:20:44 ----D---- C:\Windows\system32\SLUI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sl-SI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\setup
2009-10-19 07:20:44 ----D---- C:\Windows\system32\ro-RO
2009-10-19 07:20:44 ----D---- C:\Windows\system32\pt-PT
2009-10-19 07:20:44 ----D---- C:\Windows\system32\pl-PL
2009-10-19 07:20:44 ----D---- C:\Windows\system32\manifeststore
2009-10-19 07:20:44 ----D---- C:\Windows\system32\ja-JP
2009-10-19 07:20:44 ----D---- C:\Windows\system32\hu-HU
2009-10-19 07:20:44 ----D---- C:\Windows\system32\he-IL
2009-10-19 07:20:44 ----D---- C:\Windows\system32\fi-FI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\es-ES
2009-10-19 07:20:44 ----D---- C:\Windows\system32\cs-CZ
2009-10-19 07:20:44 ----D---- C:\Windows\system32\bg-BG
2009-10-19 07:20:43 ----D---- C:\Windows\system32\tr-TR
2009-10-19 07:20:43 ----D---- C:\Windows\system32\pt-BR
2009-10-19 07:20:43 ----D---- C:\Windows\system32\nl-NL
2009-10-19 07:20:43 ----D---- C:\Windows\system32\nb-NO
2009-10-19 07:20:43 ----D---- C:\Windows\system32\migwiz
2009-10-19 07:20:43 ----D---- C:\Windows\system32\lt-LT
2009-10-19 07:20:43 ----D---- C:\Windows\system32\ar-SA
2009-10-19 07:20:35 ----D---- C:\Windows\system32\Boot
2009-10-19 07:19:30 ----D---- C:\Windows\system32\RTCOM
2009-10-18 22:26:52 ----D---- C:\Windows\Debug
2009-10-18 22:06:49 ----D---- C:\Windows\system32\WDI
2009-10-18 21:50:23 ----D---- C:\ProgramData\Microsoft Help
2009-10-18 21:47:38 ----D---- C:\Program Files\Common Files\microsoft shared
2009-10-18 21:47:31 ----D---- C:\Program Files\Microsoft Works
2009-10-18 21:26:37 ----D---- C:\ACER
2009-10-18 21:21:11 ----D---- C:\Windows\PolicyDefinitions
2009-10-18 21:20:43 ----D---- C:\Windows\system32\OEM
2009-10-18 21:17:31 ----D---- C:\Windows\system
2009-10-18 19:51:46 ----D---- C:\ProgramData\SiteAdvisor
2009-10-18 19:48:11 ----D---- C:\Program Files\Acer
2009-10-18 19:44:49 ----RD---- C:\Users
2009-10-18 19:41:53 ----D---- C:\Windows\system32\restore
2009-10-18 19:41:29 ----D---- C:\Program Files\Windows NT
2009-10-18 19:36:17 ----D---- C:\Windows\Panther
2009-10-02 10:01:58 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-08-19 15392]
R2 irda;Protocole IrDA; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60464]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-10-03 3977728]
R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-04 2161496]
R3 irsir;Pilote série infrarouge Microsoft; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-21 20992]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-07 1050656]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-08-24 15872]
R3 snpstd2;Trek 310; C:\Windows\system32\DRIVERS\snpstd2.sys [2007-06-26 343808]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 catchme;catchme; \??\C:\Users\jc-joce\AppData\Local\Temp\catchme.sys []
S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-10-03 704512]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2008-09-08 450560]
R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2008-09-08 184320]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-05-29 241734]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-19 133104]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-18 24064]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-18 182768]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
-
-
ok
le voici posté en deux fois
Logfile of random's system information tool 1.06 (written by random/random)
Run by jc-joce at 2009-10-25 16:43:27
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 579 GB (95%) free of 610 GB
Total RAM: 3326 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:43:41, on 25/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\mobsync.exe
C:\Users\jc-joce\Downloads\RSIT.exe
C:\Program Files\trend micro\jc-joce.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
-
Non ...pas télécharger mais relancer puisque l'icone se trouve normalement sur ton burau...
a+ -
Refais un RSIT stp...
Tu n'auras que le logtxt cette fois...
c'est normal
a+
-
re
excuse mon ignorance,mais pour ne pas mourir con,
dit moi stp ce que veut dire rsit
et infin,si c'est le logtxt que tu veux,le voici puisque combofix ma donné les deux
ComboFix 09-10-24.01 - jc-joce 25/10/2009 15:11.1.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3326.2493 [GMT 1:00]
Lancé depuis: c:\users\jc-joce\Downloads\ComboFix.exe
AV: VirusKeeper 2007 Pro *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-25 au 2009-10-25 ))))))))))))))))))))))))))))))))))))
.
2009-10-25 11:41 . 2009-10-25 11:41 -------- d-----w- C:\_OTM
2009-10-25 09:34 . 2009-10-25 14:08 -------- d-----w- c:\program files\trend micro
2009-10-25 09:34 . 2009-10-25 09:35 -------- d-----w- C:\rsit
2009-10-24 22:45 . 2009-10-24 22:45 -------- d-----w- c:\program files\AxBx
2009-10-23 19:01 . 2009-10-23 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\KC Softwares
2009-10-22 18:35 . 2009-10-22 18:35 -------- d-----w- c:\programdata\Messenger Plus!
2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\Messenger Plus! Live
2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Malwarebytes
2009-10-20 18:44 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-20 18:44 . 2009-10-20 19:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\programdata\Malwarebytes
2009-10-20 18:44 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-20 10:20 . 2009-10-20 10:20 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Trial Creator
2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\Public\MediaServer
2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Connect
2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Auslogics
2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\program files\Auslogics
2009-10-19 18:50 . 2005-11-23 11:55 53248 ----a-w- c:\windows\system32\csnpstd2.dll
2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Common Files\Trek310
2009-10-19 18:50 . 2007-06-26 08:06 343808 ----a-w- c:\windows\system32\drivers\snpstd2.sys
2009-10-19 18:50 . 2007-04-13 11:52 307200 ----a-w- c:\windows\vsnpstd2.exe
2009-10-19 18:50 . 2007-03-29 12:52 36864 ----a-w- c:\windows\system32\vsnpstd2.dll
2009-10-19 18:50 . 2004-09-24 14:24 57344 ----a-w- c:\windows\system32\rsnpstd2.dll
2009-10-19 18:50 . 2003-08-05 11:48 65536 ----a-w- c:\windows\amcap.exe
2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Trek 310
2009-10-19 15:00 . 2009-10-19 15:00 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Template
2009-10-19 14:58 . 2009-10-19 14:58 -------- d-----w- c:\users\jc-joce\Option
2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer Arcade Live
2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Roaming\CyberLink
2009-10-19 09:17 . 1999-05-05 20:22 73728 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll
2009-10-19 09:17 . 1999-05-05 20:22 65536 ----a-w- c:\windows\system32\drivers\IYUV_32.DLL
2009-10-19 09:17 . 1999-05-05 20:22 257808 ----a-w- c:\windows\system32\drivers\MSH263.DRV
2009-10-19 09:17 . 1999-05-05 20:22 15664 ----a-w- c:\windows\system32\drivers\vfwwdm.drv
2009-10-19 09:15 . 2009-10-19 09:15 -------- d-----w- c:\program files\Managed DirectX (0900)
2009-10-19 09:14 . 2009-10-19 09:14 -------- d-----w- c:\windows\Cache
2009-10-19 08:21 . 2009-10-19 08:21 -------- d-----w- c:\users\jc-joce\AppData\Roaming\igraal
2009-10-19 07:39 . 2009-10-19 07:40 160168 ----a-w- c:\windows\hpqins00.dat
2009-10-19 07:38 . 2009-10-19 07:38 -------- d-----w- c:\programdata\HP Product Assistant
2009-10-19 07:36 . 2009-10-22 08:25 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HpUpdate
2009-10-19 07:36 . 2009-10-19 07:36 -------- d-----w- c:\windows\Hewlett-Packard
2009-10-19 07:28 . 2009-10-22 16:45 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HP
2009-10-19 07:27 . 2009-10-19 07:27 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Printer Info Cache
2009-10-19 07:27 . 2009-10-23 18:19 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Image Zone Express
2009-10-19 07:25 . 2009-10-19 07:25 -------- d-----w- c:\programdata\HPSSUPPLY
2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Hewlett-Packard
2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-10-19 07:24 . 2009-10-19 07:25 -------- d-----w- c:\program files\Common Files\HP
2009-10-19 07:22 . 2009-10-19 07:25 -------- d-----w- c:\program files\HP
2009-10-19 07:21 . 2009-10-19 07:28 164276 ----a-w- c:\windows\hpoins19.dat
2009-10-19 07:20 . 2009-10-22 16:48 -------- d-----w- c:\programdata\HP
2009-10-19 07:20 . 2006-11-20 21:36 258048 ----a-w- c:\windows\system32\hpzids01.dll
2009-10-19 07:20 . 2006-12-16 06:19 303104 ----a-w- c:\windows\system32\hpovst01.dll
2009-10-19 07:20 . 2006-12-16 06:19 573440 ----a-w- c:\windows\system32\hpotscl1.dll
2009-10-19 07:20 . 2007-03-13 19:55 26952 ----a-w- c:\windows\hpomdl19.dat
2009-10-19 06:54 . 2009-10-19 06:54 -------- d-----w- c:\windows\Album
2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\ca-ES
2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\eu-ES
2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\vi-VN
2009-10-19 06:10 . 2009-10-19 06:10 -------- d-----w- c:\windows\system32\EventProviders
2009-10-19 06:08 . 2009-04-11 06:32 122344 ----a-w- c:\windows\system32\drivers\Storport.sys
2009-10-19 03:27 . 2008-10-03 17:39 262144 ----a-w- c:\windows\system32\Oemdspif.dll
2009-10-18 21:01 . 2009-10-19 08:05 -------- d-----w- c:\users\jc-joce\AppData\Local\Adobe
2009-10-18 20:48 . 2009-10-25 07:53 -------- d-----w- c:\users\jc-joce\Tracing
2009-10-18 20:47 . 2009-10-18 20:47 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2009-10-18 20:47 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-10-18 20:46 . 2009-10-18 20:46 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-18 20:45 . 2009-10-18 20:45 -------- d-----w- c:\program files\CCleaner
2009-10-18 20:40 . 2009-10-18 20:40 -------- d-----w- c:\program files\Microsoft
2009-10-18 20:39 . 2009-10-18 20:39 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-18 20:39 . 2009-10-18 20:47 -------- d-----w- c:\program files\Windows Live
2009-10-18 20:33 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-18 20:32 . 2009-10-18 20:32 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Wide).scr
2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Normal).scr
2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\windows\Acer_Wide
2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\program files\Acer Incorporated
2009-10-18 20:18 . 2009-10-18 20:23 -------- d-----w- c:\windows\Acer_Normal
2009-10-18 20:18 . 2009-10-18 20:18 0 ----a-w- c:\windows\nsreg.dat
2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Local\Mozilla
2009-10-18 20:17 . 2008-06-05 17:01 62464 ----a-w- c:\windows\system32\drivers\RTSTOR.sys
2009-10-18 20:17 . 2008-05-06 15:41 6416928 ----a-w- c:\windows\system\DriveIcon.dll
2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Roaming\InstallShield
2009-10-18 20:17 . 2009-10-18 21:36 -------- d-----w- c:\program files\Northstar
2009-10-18 20:07 . 2009-10-19 19:31 -------- d-----w- c:\users\jc-joce\AppData\Local\Google
2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32_priv.dll
2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32.dll
2009-10-18 20:07 . 2007-05-15 14:46 98360 ----a-w- c:\windows\system32\hcwi2c32.dll
2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32_priv.dll
2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32.dll
2009-10-18 20:01 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-18 19:16 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-10-18 19:15 . 2009-10-18 19:15 -------- d-----w- c:\program files\MSXML 4.0
2009-10-18 19:02 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-10-18 19:02 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-10-18 19:02 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-10-18 19:02 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-10-18 19:02 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-10-18 19:02 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-10-18 19:02 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-10-18 19:02 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-10-18 19:02 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-10-18 19:02 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-10-18 19:02 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-10-18 19:01 . 2009-04-11 06:28 1696768 ----a-w- c:\windows\system32\gameux.dll
2009-10-18 19:01 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-10-18 19:01 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-10-18 19:01 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-10-18 19:01 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll
2009-10-18 19:01 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2009-10-18 19:01 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-10-18 19:01 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll
2009-10-18 18:59 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-10-18 18:58 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2009-10-18 18:55 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-18 18:50 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\programdata\ATI
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Roaming\ATI
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\ATI
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\PowerCinema
2009-10-18 18:48 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-18 18:48 . 2009-10-20 20:10 -------- d-----w- c:\programdata\Partner
2009-10-18 18:48 . 2009-10-24 21:27 70104 ----a-w- c:\users\jc-joce\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-18 18:47 . 2009-10-19 15:24 -------- d-----w- c:\program files\Google
2009-10-18 18:44 . 2009-10-24 23:39 -------- d-----w- c:\users\jc-joce
2009-10-18 18:42 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 13:11 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-25 13:11 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-24 18:37 . 2008-10-31 04:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-24 18:29 . 2008-10-31 04:30 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-23 22:48 . 2009-10-19 15:00 170 ----a-w- c:\users\jc-joce\AppData\Roaming\wklnhst.dat
2009-10-21 15:10 . 2009-10-21 15:10 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-10-19 13:41 . 2008-10-31 04:41 -------- d-----w- c:\programdata\CyberLink
2009-10-19 08:13 . 2008-10-31 04:46 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-10-19 06:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-10-18 20:50 . 2008-10-31 05:01 -------- d-----w- c:\programdata\Microsoft Help
2009-10-18 20:47 . 2008-10-31 05:03 -------- d-----w- c:\program files\Microsoft Works
2009-10-18 18:51 . 2008-10-31 04:38 -------- d-----w- c:\programdata\SiteAdvisor
2009-10-18 18:48 . 2008-10-31 04:34 -------- d-----w- c:\program files\Acer
2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Modèles
2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Menu Démarrer
2009-10-18 18:31 . 2009-10-18 18:31 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-09-14 09:29 . 2009-10-18 18:59 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-18 18:59 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-27 05:22 . 2009-10-18 20:13 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-18 20:13 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-18 20:13 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-18 20:13 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 12:34 . 2009-10-18 19:00 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-08-04 12:34 . 2009-10-18 19:00 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirusKeeper"="c:\program files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe" [2009-09-23 2609008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):a1,b5,94,fc,84,50,ca,01
R0 nvamacpi;Nvidia Away Mode System;c:\windows\System32\drivers\nvamacpi.sys [31/10/2008 13:56 24608]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [31/10/2008 05:34 24576]
S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [31/10/2008 05:43 269448]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 13:11 16384]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19/10/2009 16:23 133104]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [25/04/2008 21:36 45056]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [25/04/2008 21:36 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [18/10/2009 21:13 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]
2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]
.
.
------- Examen supplémentaire -------
.
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
FF - ProfilePath - c:\users\jc-joce\AppData\Roaming\Mozilla\Firefox\Profiles\4029skmd.default\
FF - prefs.js: browser.startup.homepage - hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-25 15:16
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(2276)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
Heure de fin: 2009-10-25 15:17
ComboFix-quarantined-files.txt 2009-10-25 14:17
Avant-CF: 607 100 076 032 octets libres
Après-CF: 607 120 744 448 octets libres
- - End Of File - - E4FCDEAD90E2A97F66D5BEB8A8DF7E4F -
-
-
Ok laisse tomber....
---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\
---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"
---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.
/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\
En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
Une fois le scan achevé, un rapport va s'afficher : Poste son contenu
/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\
Note : Le rapport se trouve également là : C:\ComboFix.txt
a+-
désolé pour ma lenteur
voici le log combofix
ComboFix 09-10-24.01 - jc-joce 25/10/2009 15:11.1.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3326.2493 [GMT 1:00]
Lancé depuis: c:\users\jc-joce\Downloads\ComboFix.exe
AV: VirusKeeper 2007 Pro *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-25 au 2009-10-25 ))))))))))))))))))))))))))))))))))))
.
2009-10-25 11:41 . 2009-10-25 11:41 -------- d-----w- C:\_OTM
2009-10-25 09:34 . 2009-10-25 14:08 -------- d-----w- c:\program files\trend micro
2009-10-25 09:34 . 2009-10-25 09:35 -------- d-----w- C:\rsit
2009-10-24 22:45 . 2009-10-24 22:45 -------- d-----w- c:\program files\AxBx
2009-10-23 19:01 . 2009-10-23 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\KC Softwares
2009-10-22 18:35 . 2009-10-22 18:35 -------- d-----w- c:\programdata\Messenger Plus!
2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\Messenger Plus! Live
2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Malwarebytes
2009-10-20 18:44 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-20 18:44 . 2009-10-20 19:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\programdata\Malwarebytes
2009-10-20 18:44 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-20 10:20 . 2009-10-20 10:20 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Trial Creator
2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\Public\MediaServer
2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Connect
2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Auslogics
2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\program files\Auslogics
2009-10-19 18:50 . 2005-11-23 11:55 53248 ----a-w- c:\windows\system32\csnpstd2.dll
2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Common Files\Trek310
2009-10-19 18:50 . 2007-06-26 08:06 343808 ----a-w- c:\windows\system32\drivers\snpstd2.sys
2009-10-19 18:50 . 2007-04-13 11:52 307200 ----a-w- c:\windows\vsnpstd2.exe
2009-10-19 18:50 . 2007-03-29 12:52 36864 ----a-w- c:\windows\system32\vsnpstd2.dll
2009-10-19 18:50 . 2004-09-24 14:24 57344 ----a-w- c:\windows\system32\rsnpstd2.dll
2009-10-19 18:50 . 2003-08-05 11:48 65536 ----a-w- c:\windows\amcap.exe
2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Trek 310
2009-10-19 15:00 . 2009-10-19 15:00 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Template
2009-10-19 14:58 . 2009-10-19 14:58 -------- d-----w- c:\users\jc-joce\Option
2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer Arcade Live
2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Roaming\CyberLink
2009-10-19 09:17 . 1999-05-05 20:22 73728 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll
2009-10-19 09:17 . 1999-05-05 20:22 65536 ----a-w- c:\windows\system32\drivers\IYUV_32.DLL
2009-10-19 09:17 . 1999-05-05 20:22 257808 ----a-w- c:\windows\system32\drivers\MSH263.DRV
2009-10-19 09:17 . 1999-05-05 20:22 15664 ----a-w- c:\windows\system32\drivers\vfwwdm.drv
2009-10-19 09:15 . 2009-10-19 09:15 -------- d-----w- c:\program files\Managed DirectX (0900)
2009-10-19 09:14 . 2009-10-19 09:14 -------- d-----w- c:\windows\Cache
2009-10-19 08:21 . 2009-10-19 08:21 -------- d-----w- c:\users\jc-joce\AppData\Roaming\igraal
2009-10-19 07:39 . 2009-10-19 07:40 160168 ----a-w- c:\windows\hpqins00.dat
2009-10-19 07:38 . 2009-10-19 07:38 -------- d-----w- c:\programdata\HP Product Assistant
2009-10-19 07:36 . 2009-10-22 08:25 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HpUpdate
2009-10-19 07:36 . 2009-10-19 07:36 -------- d-----w- c:\windows\Hewlett-Packard
2009-10-19 07:28 . 2009-10-22 16:45 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HP
2009-10-19 07:27 . 2009-10-19 07:27 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Printer Info Cache
2009-10-19 07:27 . 2009-10-23 18:19 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Image Zone Express
2009-10-19 07:25 . 2009-10-19 07:25 -------- d-----w- c:\programdata\HPSSUPPLY
2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Hewlett-Packard
2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-10-19 07:24 . 2009-10-19 07:25 -------- d-----w- c:\program files\Common Files\HP
2009-10-19 07:22 . 2009-10-19 07:25 -------- d-----w- c:\program files\HP
2009-10-19 07:21 . 2009-10-19 07:28 164276 ----a-w- c:\windows\hpoins19.dat
2009-10-19 07:20 . 2009-10-22 16:48 -------- d-----w- c:\programdata\HP
2009-10-19 07:20 . 2006-11-20 21:36 258048 ----a-w- c:\windows\system32\hpzids01.dll
2009-10-19 07:20 . 2006-12-16 06:19 303104 ----a-w- c:\windows\system32\hpovst01.dll
2009-10-19 07:20 . 2006-12-16 06:19 573440 ----a-w- c:\windows\system32\hpotscl1.dll
2009-10-19 07:20 . 2007-03-13 19:55 26952 ----a-w- c:\windows\hpomdl19.dat
2009-10-19 06:54 . 2009-10-19 06:54 -------- d-----w- c:\windows\Album
2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\ca-ES
2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\eu-ES
2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\vi-VN
2009-10-19 06:10 . 2009-10-19 06:10 -------- d-----w- c:\windows\system32\EventProviders
2009-10-19 06:08 . 2009-04-11 06:32 122344 ----a-w- c:\windows\system32\drivers\Storport.sys
2009-10-19 03:27 . 2008-10-03 17:39 262144 ----a-w- c:\windows\system32\Oemdspif.dll
2009-10-18 21:01 . 2009-10-19 08:05 -------- d-----w- c:\users\jc-joce\AppData\Local\Adobe
2009-10-18 20:48 . 2009-10-25 07:53 -------- d-----w- c:\users\jc-joce\Tracing
2009-10-18 20:47 . 2009-10-18 20:47 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2009-10-18 20:47 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-10-18 20:46 . 2009-10-18 20:46 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-18 20:45 . 2009-10-18 20:45 -------- d-----w- c:\program files\CCleaner
2009-10-18 20:40 . 2009-10-18 20:40 -------- d-----w- c:\program files\Microsoft
2009-10-18 20:39 . 2009-10-18 20:39 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-18 20:39 . 2009-10-18 20:47 -------- d-----w- c:\program files\Windows Live
2009-10-18 20:33 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-18 20:32 . 2009-10-18 20:32 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Wide).scr
2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Normal).scr
2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\windows\Acer_Wide
2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\program files\Acer Incorporated
2009-10-18 20:18 . 2009-10-18 20:23 -------- d-----w- c:\windows\Acer_Normal
2009-10-18 20:18 . 2009-10-18 20:18 0 ----a-w- c:\windows\nsreg.dat
2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Local\Mozilla
2009-10-18 20:17 . 2008-06-05 17:01 62464 ----a-w- c:\windows\system32\drivers\RTSTOR.sys
2009-10-18 20:17 . 2008-05-06 15:41 6416928 ----a-w- c:\windows\system\DriveIcon.dll
2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Roaming\InstallShield
2009-10-18 20:17 . 2009-10-18 21:36 -------- d-----w- c:\program files\Northstar
2009-10-18 20:07 . 2009-10-19 19:31 -------- d-----w- c:\users\jc-joce\AppData\Local\Google
2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32_priv.dll
2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32.dll
2009-10-18 20:07 . 2007-05-15 14:46 98360 ----a-w- c:\windows\system32\hcwi2c32.dll
2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32_priv.dll
2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32.dll
2009-10-18 20:01 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-18 19:16 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-10-18 19:15 . 2009-10-18 19:15 -------- d-----w- c:\program files\MSXML 4.0
2009-10-18 19:02 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-10-18 19:02 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-10-18 19:02 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-10-18 19:02 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-10-18 19:02 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-10-18 19:02 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-10-18 19:02 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-10-18 19:02 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-10-18 19:02 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-10-18 19:02 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-10-18 19:02 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-10-18 19:01 . 2009-04-11 06:28 1696768 ----a-w- c:\windows\system32\gameux.dll
2009-10-18 19:01 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-10-18 19:01 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-10-18 19:01 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-10-18 19:01 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll
2009-10-18 19:01 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe
2009-10-18 19:01 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-10-18 19:01 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll
2009-10-18 18:59 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-10-18 18:58 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2009-10-18 18:55 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-18 18:50 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\programdata\ATI
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Roaming\ATI
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\ATI
2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\PowerCinema
2009-10-18 18:48 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-18 18:48 . 2009-10-20 20:10 -------- d-----w- c:\programdata\Partner
2009-10-18 18:48 . 2009-10-24 21:27 70104 ----a-w- c:\users\jc-joce\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-18 18:47 . 2009-10-19 15:24 -------- d-----w- c:\program files\Google
2009-10-18 18:44 . 2009-10-24 23:39 -------- d-----w- c:\users\jc-joce
2009-10-18 18:42 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 13:11 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-25 13:11 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-24 18:37 . 2008-10-31 04:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-24 18:29 . 2008-10-31 04:30 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-23 22:48 . 2009-10-19 15:00 170 ----a-w- c:\users\jc-joce\AppData\Roaming\wklnhst.dat
2009-10-21 15:10 . 2009-10-21 15:10 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-10-19 13:41 . 2008-10-31 04:41 -------- d-----w- c:\programdata\CyberLink
2009-10-19 08:13 . 2008-10-31 04:46 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-10-19 06:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-10-18 20:50 . 2008-10-31 05:01 -------- d-----w- c:\programdata\Microsoft Help
2009-10-18 20:47 . 2008-10-31 05:03 -------- d-----w- c:\program files\Microsoft Works
2009-10-18 18:51 . 2008-10-31 04:38 -------- d-----w- c:\programdata\SiteAdvisor
2009-10-18 18:48 . 2008-10-31 04:34 -------- d-----w- c:\program files\Acer
2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Modèles
2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Menu Démarrer
2009-10-18 18:31 . 2009-10-18 18:31 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-09-14 09:29 . 2009-10-18 18:59 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-18 18:59 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-27 05:22 . 2009-10-18 20:13 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-18 20:13 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-18 20:13 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-18 20:13 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 12:34 . 2009-10-18 19:00 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-08-04 12:34 . 2009-10-18 19:00 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirusKeeper"="c:\program files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe" [2009-09-23 2609008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):a1,b5,94,fc,84,50,ca,01
R0 nvamacpi;Nvidia Away Mode System;c:\windows\System32\drivers\nvamacpi.sys [31/10/2008 13:56 24608]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [31/10/2008 05:34 24576]
S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [31/10/2008 05:43 269448]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 13:11 16384]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19/10/2009 16:23 133104]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [25/04/2008 21:36 45056]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [25/04/2008 21:36 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [18/10/2009 21:13 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]
2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]
.
.
------- Examen supplémentaire -------
.
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
FF - ProfilePath - c:\users\jc-joce\AppData\Roaming\Mozilla\Firefox\Profiles\4029skmd.default\
FF - prefs.js: browser.startup.homepage - hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-25 15:16
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(2276)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
Heure de fin: 2009-10-25 15:17
ComboFix-quarantined-files.txt 2009-10-25 14:17
Avant-CF: 607 100 076 032 octets libres
Après-CF: 607 120 744 448 octets libres
- - End Of File - - E4FCDEAD90E2A97F66D5BEB8A8DF7E4F
-
-
Greeee ==> VISTA.....
Non cela n'est pas normal....
==> Stop OTM....
Ensuite:
desactives tes comptes d'utilisateur:
https://www.zebulon.fr/astuces/pratique/220-desactiver-l-uac-dans-vista.html
Puis relances OTM en faisant un clic droit (sur l'icone OTM) et choisis:
"Exécuter en tant qu'administrateur"
a+ -
---> Télécharge OTM (OldTimer) sur ton Bureau :
http: http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :
:processes
explorer.exe
:services
relevantknowledge
:files
c:\program files\relevantknowledge\rlservice.exe
:reg
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RelevantKnowledge
:commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre : Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
a+
-
j'ai colé les textes en gras comme tu m'as dit,seulement j'ai pas de reponse de otmovelt par ailleurs à part
l'écran d'accueil et le volet de otm je n'ais rien d'autre: démarrer,barre des taches,racourcis,etc je n'ais plus rien sur l'écran, le petit sablier tourne en permanance
c'est normal?
la je suis sur le pc de mon fils
a+
-
-
Fais un scan avec cet antispyware :
Telecharges Malwarebytes + tutoriel
Tu l´installes; mets le a jour...(onglet mise a jour)
Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".
Puis click sur "rechercher".
Laisses le scanner le pc...Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "oui".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
Copies et colles le rapport stp.
a+
-
je l'avais déja à jour, et c'est le quatrième scan que je fais depuis se matin avec
voici le log
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 3028
Windows 6.0.6002 Service Pack 2
25/10/2009 12:12:45
mbam-log-2009-10-25 (12-12-45).txt
Type de recherche: Examen rapide
Eléments examinés: 89061
Temps écoulé: 2 minute(s), 0 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
-
-
Pour l'AV laisse tomber...j'avais zappé ceci:
C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
Postes ton logtxt en deux fois si tu veux....
a+-
re
voici la première partie
Logfile of random's system information tool 1.06 (written by random/random)
Run by jc-joce at 2009-10-25 10:34:48
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 579 GB (95%) free of 610 GB
Total RAM: 3326 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:03, on 25/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\jc-joce\Downloads\RSIT.exe
C:\Program Files\trend micro\jc-joce.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files\RelevantKnowledge\rlservice.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
-
@michet la deuxième
et il m'a encore bloqué j'ai du réinicialiser de nouveau
2009-10-18 19:41:29 ----SHD---- C:\Program Files\Fichiers communs
2009-10-18 19:35:33 ----D---- C:\Program Files\ATI Technologies
2009-10-18 19:32:38 ----D---- C:\Program Files\ATI
2009-10-18 19:32:28 ----A---- C:\Windows\ATIDetect.txt
2009-10-18 19:30:35 ----A---- C:\Windows\system32\nvraiins.dll
2009-10-18 19:30:32 ----D---- C:\Windows\SoftwareDistribution
======List of files/folders modified in the last 1 months======
2009-10-25 11:50:42 ----D---- C:\Windows\Temp
2009-10-25 10:34:48 ----RD---- C:\Program Files
2009-10-25 10:34:23 ----D---- C:\Windows\System32
2009-10-25 10:34:23 ----D---- C:\Windows\inf
2009-10-25 10:34:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-10-25 08:32:59 ----D---- C:\Windows
2009-10-24 23:47:55 ----SHD---- C:\Windows\Installer
2009-10-24 23:47:48 ----SD---- C:\ProgramData\Microsoft
2009-10-24 23:47:48 ----D---- C:\Windows\system32\drivers
2009-10-24 22:25:39 ----D---- C:\Windows\system32\wbem
2009-10-24 22:24:59 ----D---- C:\Windows\system32\config
2009-10-24 22:24:54 ----D---- C:\Windows\Tasks
2009-10-24 22:24:54 ----D---- C:\Windows\system32\spool
2009-10-24 22:24:54 ----D---- C:\Windows\system32\Msdtc
2009-10-24 22:24:54 ----D---- C:\Windows\system32\CodeIntegrity
2009-10-24 22:24:54 ----D---- C:\Windows\system32\catroot2
2009-10-24 22:24:53 ----D---- C:\Windows\registration
2009-10-24 22:24:09 ----SHD---- C:\System Volume Information
2009-10-24 19:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-24 19:37:01 ----D---- C:\Program Files\Common Files
2009-10-24 19:29:42 ----RSD---- C:\Windows\Fonts
2009-10-24 19:29:41 ----SD---- C:\Windows\Downloaded Program Files
2009-10-24 19:29:41 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-24 19:29:29 ----HD---- C:\ProgramData
2009-10-24 18:13:34 ----D---- C:\Windows\Prefetch
2009-10-24 16:33:30 ----D---- C:\PerfLogs
2009-10-23 15:22:49 ----D---- C:\Windows\rescache
2009-10-23 15:06:04 ----D---- C:\Windows\ShellNew
2009-10-23 15:05:20 ----D---- C:\Windows\winsxs
2009-10-23 07:25:11 ----D---- C:\Windows\Logs
2009-10-22 17:28:32 ----D---- C:\Windows\system32\LogFiles
2009-10-22 06:39:42 ----D---- C:\Windows\system32\Tasks
2009-10-21 08:13:28 ----D---- C:\Windows\system32\NDF
2009-10-19 19:50:37 ----D---- C:\Windows\twain_32
2009-10-19 19:50:17 ----A---- C:\Windows\win.ini
2009-10-19 15:24:11 ----D---- C:\Windows\Microsoft.NET
2009-10-19 15:24:04 ----RSD---- C:\Windows\assembly
2009-10-19 15:14:27 ----D---- C:\Windows\system32\catroot
2009-10-19 14:41:10 ----D---- C:\ProgramData\CyberLink
2009-10-19 09:13:32 ----D---- C:\Program Files\Common Files\Adobe
2009-10-19 09:13:28 ----D---- C:\ProgramData\Adobe
2009-10-19 07:24:45 ----SHD---- C:\Boot
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Sidebar
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Media Player
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Mail
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Collaboration
2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Calendar
2009-10-19 07:20:50 ----D---- C:\Program Files\Movie Maker
2009-10-19 07:20:50 ----D---- C:\Program Files\Internet Explorer
2009-10-19 07:20:49 ----D---- C:\Program Files\Windows Photo Gallery
2009-10-19 07:20:49 ----D---- C:\Program Files\Common Files\System
2009-10-19 07:20:48 ----D---- C:\Windows\servicing
2009-10-19 07:20:48 ----D---- C:\Windows\ehome
2009-10-19 07:20:48 ----D---- C:\Program Files\Windows Defender
2009-10-19 07:20:46 ----D---- C:\Windows\system32\lv-LV
2009-10-19 07:20:46 ----D---- C:\Windows\IME
2009-10-19 07:20:45 ----D---- C:\Windows\system32\XPSViewer
2009-10-19 07:20:45 ----D---- C:\Windows\system32\sk-SK
2009-10-19 07:20:45 ----D---- C:\Windows\system32\ru-RU
2009-10-19 07:20:45 ----D---- C:\Windows\system32\oobe
2009-10-19 07:20:45 ----D---- C:\Windows\system32\migration
2009-10-19 07:20:45 ----D---- C:\Windows\system32\ko-KR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\it-IT
2009-10-19 07:20:45 ----D---- C:\Windows\system32\hr-HR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr-FR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr
2009-10-19 07:20:45 ----D---- C:\Windows\system32\et-EE
2009-10-19 07:20:45 ----D---- C:\Windows\system32\en-US
2009-10-19 07:20:45 ----D---- C:\Windows\system32\el-GR
2009-10-19 07:20:45 ----D---- C:\Windows\system32\de-DE
2009-10-19 07:20:45 ----D---- C:\Windows\system32\da-DK
2009-10-19 07:20:45 ----D---- C:\Windows\system32\AdvancedInstallers
2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-TW
2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-CN
2009-10-19 07:20:44 ----D---- C:\Windows\system32\uk-UA
2009-10-19 07:20:44 ----D---- C:\Windows\system32\th-TH
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sv-SE
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sr-Latn-CS
2009-10-19 07:20:44 ----D---- C:\Windows\system32\SLUI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\sl-SI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\setup
2009-10-19 07:20:44 ----D---- C:\Windows\system32\ro-RO
2009-10-19 07:20:44 ----D---- C:\Windows\system32\pt-PT
2009-10-19 07:20:44 ----D---- C:\Windows\system32\pl-PL
2009-10-19 07:20:44 ----D---- C:\Windows\system32\manifeststore
2009-10-19 07:20:44 ----D---- C:\Windows\system32\ja-JP
2009-10-19 07:20:44 ----D---- C:\Windows\system32\hu-HU
2009-10-19 07:20:44 ----D---- C:\Windows\system32\he-IL
2009-10-19 07:20:44 ----D---- C:\Windows\system32\fi-FI
2009-10-19 07:20:44 ----D---- C:\Windows\system32\es-ES
2009-10-19 07:20:44 ----D---- C:\Windows\system32\cs-CZ
2009-10-19 07:20:44 ----D---- C:\Windows\system32\bg-BG
2009-10-19 07:20:43 ----D---- C:\Windows\system32\tr-TR
2009-10-19 07:20:43 ----D---- C:\Windows\system32\pt-BR
2009-10-19 07:20:43 ----D---- C:\Windows\system32\nl-NL
2009-10-19 07:20:43 ----D---- C:\Windows\system32\nb-NO
2009-10-19 07:20:43 ----D---- C:\Windows\system32\migwiz
2009-10-19 07:20:43 ----D---- C:\Windows\system32\lt-LT
2009-10-19 07:20:43 ----D---- C:\Windows\system32\ar-SA
2009-10-19 07:20:37 ----D---- C:\Windows\AppPatch
2009-10-19 07:20:35 ----D---- C:\Windows\system32\Boot
2009-10-19 07:19:30 ----D---- C:\Windows\system32\RTCOM
2009-10-18 22:26:52 ----D---- C:\Windows\Debug
2009-10-18 22:06:49 ----D---- C:\Windows\system32\WDI
2009-10-18 21:50:23 ----D---- C:\ProgramData\Microsoft Help
2009-10-18 21:47:38 ----D---- C:\Program Files\Common Files\microsoft shared
2009-10-18 21:47:31 ----D---- C:\Program Files\Microsoft Works
2009-10-18 21:26:37 ----D---- C:\ACER
2009-10-18 21:21:11 ----D---- C:\Windows\PolicyDefinitions
2009-10-18 21:20:43 ----D---- C:\Windows\system32\OEM
2009-10-18 21:17:31 ----D---- C:\Windows\system
2009-10-18 19:51:46 ----D---- C:\ProgramData\SiteAdvisor
2009-10-18 19:48:11 ----D---- C:\Program Files\Acer
2009-10-18 19:44:49 ----RD---- C:\Users
2009-10-18 19:41:53 ----D---- C:\Windows\system32\restore
2009-10-18 19:41:29 ----D---- C:\Program Files\Windows NT
2009-10-18 19:36:17 ----D---- C:\Windows\Panther
2009-10-02 10:01:58 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-08-19 15392]
R2 irda;Protocole IrDA; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60464]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-10-03 3977728]
R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-04 2161496]
R3 irsir;Pilote série infrarouge Microsoft; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-21 20992]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-07 1050656]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-08-24 15872]
R3 snpstd2;Trek 310; C:\Windows\system32\DRIVERS\snpstd2.sys [2007-06-26 343808]
R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-10-03 704512]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2008-09-08 450560]
R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2008-09-08 184320]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-05-29 241734]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-19 133104]
S2 RelevantKnowledge;RelevantKnowledge; C:\Program Files\RelevantKnowledge\rlservice.exe /service []
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-18 24064]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-18 182768]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
-
- 1
- 2