Is not a valid Win32 application

Solved
Hello,

I am trying to launch the latest MSN I downloaded from 01net. But when I do, it says "[...] is not a valid win32 application."
I searched through discussions for people who have had this problem, but I couldn't find a solution.
It seems there may be a virus on the computer.

Thank you for guiding me please. Thanks.

164 answers

  1. Security Contributor
    Hello,

    you downloaded a crack.

    Remove it. Otherwise, the infection will restart.

    Go to this site:
    http://www.zonavirus.com/datos/descargas/95/elibagla.asp
    at the bottom of this page, you will find a tool
    to download, click on "escargar Elibagla" (the version number changes with updates)
    install this file on the Desktop.
    then double-click on Elibagla.exe
    >leave the "eliminar ficheros automaticamente" box checked
    >click on "explorar"
    >let it work
    >post the final report which will be in c:\infosat.txt
    --

    @+
    Never accept disinfection via PM.
    3
    1. Security Contributor
      Re,

      Chiquitine, leave this temp file which is legitimate.

      Go see posts 2 to 24 and check the ThreatExpert report associated with the VirusTotal report.

      This file generates legitimate files from Trend Micro.

      It's something you need to know. It helps to keep this AV "alive" even when the malware tries to kill it.
      --

      @+
      Never accept disinfection by PM.
      1
      1. Thank you very much, I will do what you told me right away.
        0
        1. Here is the report:

          Mon Jul 21 17:25:38 2008
          EliBagle v11.61 (c)2008 S.G.H. / Satinfo S.L. (Updated on July 18, 2008)
          ----------------------------------------------
          Action List (by Scan):
          Scanning Unit C:\

          Total Number of Directories: 3910
          Total Number of Files: 46697
          Number of Analyzed Files: 12260
          Number of Infected Files: 0
          Number of Cleaned Files: 0
          0
          1. Security Contributor
            Hi,

            did the tool go all the way?

            Did you post the entire report?

            What version of Windows are you on?

            --

            See you later
            Never accept disinfection via DM.
            0
            1. Yes, it went all the way, I posted the entire report.
              I am using Windows XP Professional Version 2002 Service Pack 2
              0
              1. Security Contributor
                Re,

                Ok, let's switch tools.

                Download ComboFix (by sUBs) here:

                http://download.bleepingcomputer.com/sUBs/ComboFix.exe (use Internet Explorer)

                and save it as nonabagle on the Desktop. Change the name in the window when prompted, not after it’s on the Desktop. If you rename it too late, upon execution, you'll have "invalid Win32 application". If that’s the case, delete ComboFix and start again.

                Disconnect from the internet and close all your applications.

                Disable your protections (antivirus, firewall, real-time spyware guard)

                Double-click on combofix.exe and follow the instructions

                At the end, it will produce a report C:\ComboFix.txt

                Re-enable your firewall, antivirus, and spyware guard

                Copy/paste the report C:\ComboFix.txt in your next response.

                Be careful, do not use your mouse or keyboard (or any other pointing device) while the program is running. This could freeze the computer.

                You have a complete tutorial here:

                https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                --

                @+
                Never accept disinfection via PM.
                0
                1. ComboFix 08-07-21.1 - Administrator 2008-07-21 18:48:05.2 - NTFSx86
                  Location: C:\Documents and Settings\Administrator\Desktop\nonabagle.exe
                  * Creating a new restore point

                  [color=red][b]WARNING - THE RECOVERY CONSOLE IS NOT INSTALLED ON THIS MACHINE !![/b][/color]
                  .

                  (((((((((((((((((((((((((((((((((((( Other deletions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  C:\InfoSat.txt

                  .
                  ((((((((((((((((((((((((((((( Files created 2008-06-21 to 2008-07-21 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-07-21 13:33 . 2008-07-21 13:55 <REP> d-------- C:\Program Files\RegistryQuick
                  2008-07-17 17:25 . 2008-07-17 17:28 <REP> d-------- C:\Combo-Fix
                  2008-06-25 16:59 . 2008-06-25 16:59 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
                  2008-06-21 14:52 . 2008-06-14 13:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
                  2008-06-21 13:28 . 2008-06-21 13:55 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
                  2008-06-21 13:27 . 2008-07-21 16:56 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

                  .
                  (((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-07-17 04:04 --------- d-----w C:\Program Files\Microsoft Works
                  2008-07-16 01:14 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MSN6
                  2008-07-16 01:14 --------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\MSN6
                  2008-06-30 15:04 --------- d-----w C:\Program Files\Bac_v7
                  2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
                  2008-06-02 20:39 --------- d--h--r C:\Documents and Settings\Administrator\Application Data\SecuROM
                  2008-06-02 20:39 --------- d--h--r C:\DOCUME~1\ADMINI~1\APPLIC~1\SecuROM
                  2008-06-02 20:29 --------- d-----w C:\Program Files\Common Files\MainConcept
                  2008-06-02 20:28 --------- d-----w C:\Program Files\Micro Application
                  2008-05-31 15:21 --------- d-----w C:\Program Files\OrgangeFrance
                  .

                  ((((((((((((((((((((((((((((( snapshot@2008-07-17_16.44.52.12 )))))))))))))))))))))))))))))))))))))))))
                  .
                  - 2008-06-03 13:59:49 63,522 ----a-w C:\WINDOWS\system32\perfc009.dat
                  + 2008-07-17 22:03:51 63,522 ----a-w C:\WINDOWS\system32\perfc009.dat
                  - 2008-06-03 13:59:49 76,582 ----a-w C:\WINDOWS\system32\perfc00C.dat
                  + 2008-07-17 22:03:51 76,582 ----a-w C:\WINDOWS\system32\perfc00C.dat
                  - 2008-06-03 13:59:49 404,302 ----a-w C:\WINDOWS\system32\perfh009.dat
                  + 2008-07-17 22:03:51 404,302 ----a-w C:\WINDOWS\system32\perfh009.dat
                  - 2008-06-03 13:59:49 471,484 ----a-w C:\WINDOWS\system32\perfh00C.dat
                  + 2008-07-17 22:03:51 471,484 ----a-w C:\WINDOWS\system32\perfh00C.dat
                  + 2008-07-21 17:48:56 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_b0c.dat
                  .
                  ((((((((((((((((((((((((((((((((( Reg loading point )))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Note* empty items & legitimate initial items are not listed

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 19:09 15360]
                  "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-15 12:19 65536]
                  "DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 19:29 39264]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-04-06 20:19 155648]
                  "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-06 20:07 114688]
                  "00THotkey"="C:\WINDOWS\System32\[u]0[/u]0THotkey.exe" [2003-05-23 09:20 253952]
                  "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-07-17 13:38 159744]
                  "TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2003-03-11 08:58 122880]
                  "PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [2003-11-24 06:51 1019904]
                  "ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 06:29 40960]
                  "DkAutoReg.exe"="C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe" [2002-07-24 20:09 241664]
                  "DkStartup"="C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe" [2002-07-24 20:12 217088]
                  "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2007-05-08 00:43 702072]
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
                  "000StTHK"="000StTHK.exe" [2001-06-23 15:28 24576 C:\WINDOWS\system32\[u]0[/u]00StTHK.exe]
                  "LTSMMSG"="LTSMMSG.exe" [2003-04-18 06:06 32768 C:\WINDOWS\ltsmmsg.exe]
                  "TFNF5"="TFNF5.exe" [2003-10-15 12:03 73728 C:\WINDOWS\system32\TFNF5.exe]
                  "TPSMain"="TPSMain.exe" [2003-12-01 07:09 266240 C:\WINDOWS\system32\TPSMain.exe]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 19:09 15360]

                  C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\DMARRA~1\
                  Quick launch of Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
                  Orange Caraibes.lnk - C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe [2008-01-14 14:01:50 872448]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                  "vidc.mpg4"= C:\WINDOWS\mpg4c32.dll
                  "vidc.mpg2"= C:\WINDOWS\mpg4c32.dll
                  "vidc.mpg3"= C:\WINDOWS\mpg4c32.dll
                  "vidc.GEOX"= C:\WINDOWS\system32\GeoCodec.dll

                  [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quick launch of Microsoft Office OneNote 2003.lnk]
                  path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quick launch of Microsoft Office OneNote 2003.lnk
                  backup=C:\WINDOWS\pss\Quick launch of Microsoft Office OneNote 2003.lnkCommon Startup

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n Drop CD+DVD]
                  --------- 2003-08-08 18:54 1175552 C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "C:\\Program Files\\Messenger\\msmsgs.exe"=

                  R3 GT72NDISIPXP;GT 72 IP NDIS;C:\WINDOWS\system32\DRIVERS\Gt51Ip.sys [2007-07-09 14:17]
                  R3 GT72UBUS;GT 72 U BUS;C:\WINDOWS\system32\DRIVERS\gt72ubus.sys [2007-06-26 13:38]
                  R3 GTPTSER;GT PT SER;C:\WINDOWS\system32\DRIVERS\gtptser.sys [2007-03-30 13:38]
                  R3 iKeyEnum;Rainbow iKey Enumerator;C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 03:04]
                  R3 iKeyIFD;Rainbow iKey Virtual Reader;C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 03:04]
                  S3 PAMScan;PAMScan;C:\WINDOWS\System32\DRIVERS\PAMScan.SYS [2003-09-06 10:22]
                  S3 RnbToken;Rainbow iKey Token Service;C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 03:04]

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c138b72-2f24-11dd-a5a2-00080ddf4fdb}]
                  \Shell\AutoRun\command - E:\setup.exe AUTORUN=1

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{caaa0ed6-8975-11dc-a55f-00080ddf4fdb}]
                  \Shell\AutoRun\command - RavMon.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5cd7da8-da49-11dc-a580-00080ddf4fdb}]
                  \Shell\AutoRun\command - RavMon.exe
                  .
                  - - - - ORPHANS REMOVED - - - -

                  HKLM-Run-RegistryQuick.exe - C:\Program Files\RegistryQuick\RegistryQuick.exe

                  .
                  ------- Supplementary Scan -------
                  .
                  R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
                  O8 -: E&xporter to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

                  O16 -: {1856D980-6604-4504-AE2E-6EEE0235FCF5} - hxxp://www.certeurope.fr/files/activesign/1.2.0.2/ActiveSign.CAB
                  C:\WINDOWS\Downloaded Program Files\ActiveSign.INF
                  C:\WINDOWS\System32\OLEAUT32.DLL
                  C:\WINDOWS\System32\OLEPRO32.DLL
                  C:\WINDOWS\System32\ASYCFILT.DLL
                  C:\WINDOWS\System32\STDOLE2.TLB
                  C:\WINDOWS\System32\COMCAT.DLL
                  C:\WINDOWS\System32\msvbvm60.dll
                  C:\WINDOWS\Downloaded Program Files\ActiveSign.dll

                  O16 -: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} - hxxp://213.16.24.101:8080/cab/OCXChecker_6110.cab
                  C:\WINDOWS\Downloaded Program Files\OCXDownloadChecker.inf
                  C:\WINDOWS\Downloaded Program Files\OCXDownloadChecker_6110.ocx

                  O16 -: {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} - hxxp://213.16.24.101:8080/cab/DownloadFile_7000.cab
                  C:\WINDOWS\Downloaded Program Files\Download.inf
                  C:\WINDOWS\Downloaded Program Files\Download_7000.ocx

                  **************************************************************************

                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-07-21 18:52:36
                  Windows 5.1.2600 Service Pack 2 NTFS

                  Scanning hidden processes ...

                  Scanning hidden autostart entries ...

                  Scanning hidden files ...

                  Scan completed successfully
                  Hidden files: 0

                  **************************************************************************
                  .
                  Completion time: 2008-07-21 18:56:54
                  ComboFix-quarantined-files.txt 2008-07-21 22:56:43
                  ComboFix2.txt 2008-07-17 20:46:26

                  Pre-Run: 26,707,017,728 bytes free
                  Post-Run: 26,794,024,960 bytes free

                  141 --- E O F --- 2008-07-17 04:07:11
                  0
                  1. Security Contributor
                    Hello,

                    why did you download Combofix on July 17?

                    Click on this link
                    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
                    to download the HijackThis installation file.

                    Save HJTInstall.exe on your desktop.

                    Double-click on HJTInstall.exe to launch the program

                    By default, it will install here:
                    C:\Program Files\Trend Micro\HijackThis

                    Accept the license by clicking on the "I Accept" button

                    Close Hijackthis by clicking on the red cross.

                    Download DSS (Deckard's System Scanner by Deckard) to your Desktop from this link:

                    http://www.techsupportforum.com/sectools/Deckard/dss.exe

                    Choose "Save" and "Desktop" as the location.

                    Close all running applications (very important, or the computer might crash).

                    Double-click on DSS.exe to run the tool.

                    If it does not find HijackThis, click Yes.

                    Click OK whenever prompted.

                    When the scan is finished, a text file will appear. Post its content in your reply.

                    The report is located here: C:\Deckard\System Scanner\main.txt.
                    --

                    See you later
                    Never accept a disinfection via private message.
                    0
                    1. I downloaded it because I thought the issue that some people had was the same as mine, so I followed the instructions they were given, without bothering anyone to guide me for the same problem. I didn't want to waste your time by having you repeat the same thing.
                      0
                      1. Deckard's System Scanner v20071014.68
                        Exécuté par Administrateur le 2008-07-22 08:04:58
                        L’ordinateur est en mode normal.
                        --------------------------------------------------------------------------------

                        -- Restauration du système --------------------------------------------------------------

                        Point de restauration de Deckard's System Scanner créé avec succès.

                        -- 5 derniers points de restauration --
                        39 : 2008-07-22 12:05:16 UTC - RP205 - Point de restauration de Deckard's System Scanner
                        38 : 2008-07-21 22:46:29 UTC - RP204 - Point de restauration créé par ComboFix
                        37 : 2008-07-21 21:40:07 UTC - RP203 - Windows Live installer supprimé
                        36 : 2008-07-21 20:57:28 UTC - RP202 - Windows Live installé
                        35 : 2008-07-19 01:35:05 UTC - RP201 - Windows Live installé

                        -- Premier point de restauration --
                        1 : 2008-04-05 13:37:39 UTC - RP167 - Bac_v7 installé

                        Sauvegarde des cellules de registre.
                        Nettoyage des disques effectué.

                        [color=red]Mémoire physique totale : 239 MiB (512 MiB recommandé)./color

                        -- HijackThis (exécuté en tant qu'Administrateur.exe) --------------------------------------

                        Fichier journal de Trend Micro HijackThis v2.0.2
                        Analyse sauvegardée à 08:06:25, le 22/07/2008
                        Plateforme : Windows XP SP2 (WinNT 5.01.2600)
                        MSIE : Internet Explorer v7.00 (7.00.6000.16674)
                        Mode de démarrage : Normal

                        Processus en cours d’exécution :
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                        C:\WINDOWS\System32\DkLog.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                        C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
                        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
                        C:\WINDOWS\System32\dkcktkn.exe
                        C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\System32\igfxtray.exe
                        C:\WINDOWS\System32\hkcmd.exe
                        C:\WINDOWS\System32\00THotkey.exe
                        C:\WINDOWS\LTSMMSG.exe
                        C:\Program Files\Apoint2K\Apoint.exe
                        C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
                        C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
                        C:\WINDOWS\system32\TFNF5.exe
                        C:\WINDOWS\system32\TPSMain.exe
                        C:\WINDOWS\System32\ezSP_Px.exe
                        C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
                        C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
                        C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                        C:\WINDOWS\system32\TPSBattM.exe
                        C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
                        C:\Program Files\Apoint2K\Apntex.exe
                        C:\WINDOWS\TEMP\AOC6B0.EXE
                        C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
                        C:\Documents and Settings\Administrateur\Bureau\dss.exe
                        C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrateur.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                        O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
                        O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
                        O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
                        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                        O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
                        O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
                        O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
                        O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
                        O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
                        O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
                        O4 - HKLM\..\Run: [DkStartup] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe
                        O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SYSTÈME')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'Utilisateur par défaut')
                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: Orange Caraibes.lnk = C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
                        O8 - Élément de menu contextuel supplémentaire : E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O9 - Bouton supplémentaire : (aucun nom) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O9 - Éléments de menu 'Outils' supplémentaires : Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O9 - Bouton supplémentaire : Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Bouton supplémentaire : (aucun nom) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Éléments de menu 'Outils' supplémentaires : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Bouton supplémentaire : Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Éléments de menu 'Outils' supplémentaires : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O14 - IERESET.INF : START_PAGE_URL=file:///C:\Program Files\TOSHIBA\Free Update Service\splash.html
                        O16 - DPF : {1856D980-6604-4504-AE2E-6EEE0235FCF5} (ActiveSign.CapicomInterface) - http://www.certeurope.fr/fichiers/activesign/1.2.0.2/ActiveSign.CAB
                        O16 - DPF : {1DB93715-3B60-43EE-93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://213.16.24.101:8080/cab/OCXChecker_6110.cab
                        O16 - DPF : {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} (DownloadFile Control) - http://213.16.24.101:8080/cab/DownloadFile_7000.cab
                        O17 - HKLM\System\CCS\Services\Tcpip\Parameters : Domaine = vauclin.sud
                        O17 - HKLM\Software\..\Telephony : DomainName = vauclin.sud
                        O17 - HKLM\System\CS1\Services\Tcpip\Parameters : Domaine = vauclin.sud
                        O17 - HKLM\System\CS2\Services\Tcpip\Parameters : Domaine = vauclin.sud
                        O23 - Service : ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                        O23 - Service : Service de journalisation de Datakey (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
                        O23 - Service : Service de jeton de Datakey (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
                        O23 - Service : Analyse en temps réel OfficeScanNT (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
                        O23 - Service : Service d'agent SoundMAX (Service par défaut) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                        O23 - Service : Écouteur OfficeScan NT (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
                        O23 - Service : Pare-feu OfficeScan NT (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
                        O23 - Service : Service Proxy OfficeScan NT (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe

                        --
                        Fin du fichier - 7587 octets

                        -- Associations de fichiers -----------------------------------------------------------

                        Toutes les associations sont correctes.

                        -- Pilotes : 0-Démarrage, 1-Système, 2-Automatique, 3-Demande, 4-Désactivé ---------------------

                        R0 TVALZ (Pilote de périphérique logique et général à valeur ajoutée basé sur ACPI TOSHIBA) - c:\windows\system32\drivers\tvalz.sys <Non vérifié ; TOSHIBA Corporation ; Modules communs TOSHIBA>
                        R2 Netdevio (Protocole I/O en mode utilisateur de périphérique réseau TOSHIBA) - c:\windows\system32\drivers\netdevio.sys <Non vérifié ; TOSHIBA Corporation. ; Protocole I/O en mode utilisateur de périphérique réseau TOSHIBA>
                        R2 tossmbnt - c:\windows\system32\drivers\tossmbnt.sys

                        S3 PAMScan - c:\windows\system32\drivers\pamscan.sys <Non vérifié ; Licencié pour OCTOPUS PYTHEAS. ; PAMScan>
                        S3 tsdhd (Pilote de contrôleur d'hôte de carte SD TOSHIBA) - c:\windows\system32\drivers\tsdhd.sys <Non vérifié ; TOSHIBA Corporation ; Ensemble de pilotes de carte SD>

                        -- Services : 0-Démarrage, 1-Système, 2-Automatique, 3-Demande, 4-Désactivé --------------------

                        R2 CFSvcs (Service ConfigFree) - c:\program files\toshiba\configfree\cfsvcs.exe <Non vérifié ; TOSHIBA CORPORATION ; ConfigFree(TM)>
                        R2 DkLogger (Service de journalisation de Datakey) - c:\windows\system32\dklog.exe <Non vérifié ; Datakey, Inc. ; Service de journalisation de Datakey pour NT>
                        R2 DkTknSrv (Service de jeton de Datakey) - c:\windows\system32\dkcktkn.exe <Non vérifié ; Datakey, Inc. ; Service de jeton de Datakey>

                        -- Gestionnaire de périphériques : Désactivé ----------------------------------------------------

                        Aucun périphérique désactivé trouvé.

                        -- Fichiers créés entre 2008-06-22 et 2008-07-22 -----------------------------

                        2008-07-21 13:33:16 0 d-------- C:\Program Files\RegistryQuick
                        2008-07-17 17:25:39 0 d-------- C:\Combo-Fix
                        2008-07-17 14:49:20 0 d-------- C:\Documents and Settings\Administrateur\Menu Démarrer
                        2008-07-16 23:42:04 68096 --a------ C:\WINDOWS\zip.exe
                        2008-07-16 23:42:04 49152 --a------ C:\WINDOWS\VFind.exe
                        2008-07-16 23:42:04 161792 --a------ C:\WINDOWS\swreg.exe <Non vérifié ; SteelWerX ; Éditeur de registre SteelWerX>
                        2008-07-16 23:42:04 98816 --a------ C:\WINDOWS\sed.exe
                        2008-07-16 23:42:04 80412 --a------ C:\WINDOWS\grep.exe
                        2008-07-16 23:42:04 89504 --a------ C:\WINDOWS\fdsv.exe <Non vérifié ; Smallfrogs Studio; >
                        2008-07-16 23:42:03 212480 --a------ C:\WINDOWS\swxcacls.exe <Non vérifié ; SteelWerX ; Configurateur étendu SteelWerX ACLists>
                        2008-07-16 23:42:03 136704 --a------ C:\WINDOWS\swsc.exe <Non vérifié ; SteelWerX ; Contrôleur de service SteelWerX>
                        2008-06-25 16:59:30 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2

                        -- Rapport Find3M ---------------------------------------------------------------

                        2008-07-22 08:01:37 0 d-------- C:\Program Files\Trend Micro
                        2008-07-17 18:03:51 471484 --a------ C:\WINDOWS\system32\perfh00C.dat
                        2008-07-17 18:03:51 76582 --a------ C:\WINDOWS\system32\perfc00C.dat
                        2008-07-17 00:04:03 0 d-------- C:\Program Files\Microsoft Works
                        2008-07-15 21:14:43 0 d-------- C:\Documents and Settings\Administrateur\Application Data\MSN6
                        2008-06-30 11:04:13 0 d-------- C:\Program Files\Bac_v7
                        2008-06-21 13:55:02 0 d--hs--c- C:\Program Files\Fichiers communs\WindowsLiveInstaller
                        2008-06-21 13:28:44 0 d-------- C:\Program Files\Fichiers communs
                        2008-06-02 16:39:52 0 dr-h----- C:\Documents and Settings\Administrateur\Application Data\SecuROM
                        2008-06-02 16:29:50 0 d-------- C:\Program Files\Fichiers communs\MainConcept
                        2008-06-02 16:28:57 0 d-------- C:\Program Files\Micro Application
                        2008-05-31 11:21:29 0 d-------- C:\Program Files\OrgangeFrance
                        2008-05-25 20:10:39 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Google

                        -- Exportation de registre ---------------------------------------------------------------

                        *Remarque* Les entrées vides et les entrées par défaut légitimes ne sont pas affichées

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [06/04/2003 20:19]
                        "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [06/04/2003 20:07]
                        "00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [23/05/2003 09:20]
                        "000StTHK"="000StTHK.exe" [23/06/2001 15:28 C:\WINDOWS\system32\000StTHK.exe]
                        "LTSMMSG"="LTSMMSG.exe" [18/04/2003 06:06 C:\WINDOWS\ltsmmsg.exe]
                        "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [17/07/2003 13:38]
                        "TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [11/03/2003 08:58]
                        "PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [24/11/2003 06:51]
                        "TFNF5"="TFNF5.exe" [15/10/2003 12:03 C:\WINDOWS\system32\TFNF5.exe]
                        "TPSMain"="TPSMain.exe" [01/12/2003 07:09 C:\WINDOWS\system32\TPSMain.exe]
                        "ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [20/08/2002 06:29]
                        "DkAutoReg.exe"="C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe" [24/07/2002 20:09]
                        "DkStartup"="C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe" [24/07/2002 20:12]
                        "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [08/05/2007 00:43]
                        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [14/03/2007 03:43]

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [19/08/2004 19:09]
                        "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [15/09/2003 12:19]

                        C:\Documents and Settings\Tous les utilisateurs\Menu Démarrer\Programmes\Démarrage\
                        Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 22:05:26]
                        Orange Caraibes.lnk - C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe [14/01/2008 14:01:50]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                        "DisableRegistryTools"=0 (0x0)
                        "HideLegacyLogonScripts"=0 (0x0)
                        "HideLogoffScripts"=0 (0x0)
                        "RunLogonScriptSync"=1 (0x1)
                        "RunStartupScriptSync"=0 (0x0)
                        "HideStartupScripts"=0 (0x0)

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
                        "HideLegacyLogonScripts"=0 (0x0)
                        "HideLogoffScripts"=0 (0x0)
                        "RunLogonScriptSync"=1 (0x1)
                        "RunStartupScriptSync"=0 (0x0)
                        "HideStartupScripts"=0 (0x0)

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
                        @="Service"

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
                        @="Volume shadow copy"

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Tous les utilisateurs^Menu Démarrer^Programmes^Démarrage^Lancement rapide de Microsoft Office OneNote 2003.lnk]
                        path=C:\Documents and Settings\Tous les utilisateurs\Menu Démarrer\Programmes\Démarrage\Lancement rapide de Microsoft Office OneNote 2003.lnk
                        backup=C:\WINDOWS\pss\Lancement rapide de Microsoft Office OneNote 2003.lnkCommon Startup

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n Drop CD+DVD]
                        C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c138b72-2f24-11dd-a5a2-00080ddf4fdb}]
                        AutoRun\command- E:\setup.exe AUTORUN=1

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{caaa0ed6-8975-11dc-a55f-00080ddf4fdb}]
                        AutoRun\command- RavMon.exe

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5cd7da8-da49-11dc-a580-00080ddf4fdb}]
                        AutoRun\command- RavMon.exe

                        -- Fin de Deckard's System Scanner : terminé le 2008-07-22 08:07:16 ------------
                        0
                        1. Security Contributor
                          Hello,

                          I'll check that out tonight.

                          By the way, do you know Domain = vauclin.sud?
                          --

                          Talk to you later
                          Never accept a disinfection via MP.
                          0
                          1. No. It was a work laptop for administrative tasks. Vauclin is the town, and it is located in the south.
                            0
                            1. Security Contributor
                              Hi,

                              Do you mean that you no longer need this domain to connect to the Net?

                              2 files to check.

                              Go to this site:

                              https://www.virustotal.com/gui/

                              Click on browse and search for this file: C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe

                              Click on Send File.

                              A report will be generated line by line.

                              Wait for it to finish. It should include the size of the file sent.

                              Save the report with Notepad.

                              Copy it into your reply.

                              If VirusTotal indicates that the file has already been analyzed, click on the button Reanalyze the file now

                              Repeat with: C:\WINDOWS\TEMP\AOC6B0.EXE
                              --

                              See you later
                              Never accept disinfection via PM.
                              0
                              1. File Orange_Caraibes.exe received on 2008.07.23 03:58:06 (CET)
                                Current situation: loading ... queued awaiting analysis finished NOT FOUND STOPPED

                                Result: 0/34 (0%)
                                loading server information...
                                Your file is in the queue, in position: ___.
                                Estimated start time is between ___ and ___.
                                Do not close the window before the analysis is complete.
                                The analyzer that was processing your file is currently stopped, we will wait a few seconds to attempt to retrieve your results.
                                If you have been waiting for more than five minutes, you need to resubmit your file.
                                Your file is currently being analyzed by VirusTotal,
                                results will be displayed as they are generated.
                                Formatted Print Results
                                Your file has expired or does not exist.
                                The service is currently stopped, your file has been waiting to be analyzed (position: ) for an indefinite period.

                                You can wait for a response from the Web (automatic reload) or enter your email in the form below and click "Request" for the system to send you a notification when the analysis is complete.
                                Email:

                                Antivirus Version Last updated Result
                                AhnLab-V3 2008.7.23.0 2008.07.22 -
                                AntiVir 7.8.1.11 2008.07.22 -
                                Authentium 5.1.0.4 2008.07.22 -
                                Avast 4.8.1195.0 2008.07.22 -
                                AVG 8.0.0.130 2008.07.22 -
                                BitDefender 7.2 2008.07.23 -
                                CAT-QuickHeal 9.50 2008.07.22 -
                                ClamAV 0.93.1 2008.07.23 -
                                DrWeb 4.44.0.09170 2008.07.22 -
                                eSafe 7.0.17.0 2008.07.22 -
                                eTrust-Vet 31.6.5975 2008.07.22 -
                                Ewido 4.0 2008.07.22 -
                                F-Prot 4.4.4.56 2008.07.22 -
                                F-Secure 7.60.13501.0 2008.07.22 -
                                Fortinet 3.14.0.0 2008.07.23 -
                                GData 2.0.7306.1023 2008.07.22 -
                                Ikarus T3.1.1.34.0 2008.07.23 -
                                Kaspersky 7.0.0.125 2008.07.23 -
                                McAfee 5344 2008.07.22 -
                                Microsoft 1.3704 2008.07.23 -
                                NOD32v2 3289 2008.07.22 -
                                Norman 5.80.02 2008.07.22 -
                                Panda 9.0.0.4 2008.07.23 -
                                PCTools 4.4.2.0 2008.07.22 -
                                Prevx1 V2 2008.07.23 -
                                Rising 20.54.12.00 2008.07.22 -
                                Sophos 4.31.0 2008.07.23 -
                                Sunbelt 3.1.1536.1 2008.07.18 -
                                Symantec 10 2008.07.23 -
                                TheHacker 6.2.96.385 2008.07.20 -
                                TrendMicro 8.700.0.1004 2008.07.22 -
                                VBA32 3.12.8.1 2008.07.22 -
                                VirusBuster 4.5.11.0 2008.07.22 -
                                Webwasher-Gateway 6.6.2 2008.07.22 -
                                Additional information
                                File size: 872448 bytes
                                MD5...: 6119d1766aeb4b4fa170e80462ab0101
                                SHA1..: e63844aa12cf56c9de52af48ab621b5352c8e91c
                                SHA256: 4cbebbd848a7672009686b9d91abf9e68ebe3ca3ebacd10388f89bba6962a773
                                SHA512: 703021da8a288cf28a6ee085053179c3e8280e1366e44716160caa2a0a62a2d8
                                9e5f165ffc34a6d6304bf537c38ff9a96d3fc7236859aca1bc3dc051a90c8510
                                PEiD..: -
                                PEInfo: PE Structure information

                                ( base data )
                                entrypointaddress.: 0x44265c
                                timedatestamp.....: 0x478b5d38 (Mon Jan 14 13:01:44 2008)
                                machinetype.......: 0x14c (I386)

                                ( 4 sections )
                                name viradd virsiz rawdsiz ntrpy md5
                                .text 0x1000 0x63161 0x64000 6.60 c338e1a536c6a3f9ba9d7a683d3a85ab
                                .rdata 0x65000 0x26210 0x27000 4.28 1b25600530d38ba7b03ef12f06488d9f
                                .data 0x8c000 0xf678 0x4000 3.74 40c6f7e347d59aedb9ac09e159c7610d
                                .rsrc 0x9c000 0x44478 0x45000 5.99 cbb725f7f44e09df949a44a903e64b5d

                                ( 16 imports )
                                > iphlpapi.dll: GetIfEntry, GetIpAddrTable, GetAdaptersInfo, GetIfTable
                                > KERNEL32.dll: WritePrivateProfileStringW, SetFilePointer, FlushFileBuffers, SetErrorMode, HeapFree, HeapAlloc, GetProcessHeap, GetStartupInfoW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlUnwind, RaiseException, HeapReAlloc, ExitProcess, ExitThread, HeapSize, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetThreadLocale, GetCommandLineA, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetSystemTimeAsFileTime, GetCPInfo, GetACP, GetOEMCP, VirtualAlloc, LCMapStringA, LCMapStringW, GetTimeZoneInformation, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, SetEnvironmentVariableA, lstrlenA, InterlockedIncrement, TlsFree, LocalReAlloc, TlsSetValue, TlsAlloc, OpenEventW, GlobalHandle, GlobalReAlloc, TlsGetValue, GlobalFlags, GetCurrentProcessId, InterlockedDecrement, SuspendThread, ResumeThread, GetCurrentThread, ConvertDefaultLocale, GetVersion, EnumResourceLanguagesW, lstrcmpA, GetLocaleInfoW, CompareStringA, InterlockedExchange, GlobalFree, FormatMessageW, FreeResource, GlobalAddAtomW, GlobalFindAtomW, GlobalDeleteAtom, CompareStringW, LoadLibraryA, lstrcmpW, GetVersionExA, MulDiv, GetModuleHandleA, CreateThread, ResetEvent, LocalFileTimeToFileTime, SystemTimeToFileTime, PurgeComm, ReadFile, GetOverlappedResult, ReleaseMutex, WaitForMultipleObjects, WaitCommEvent, SetEvent, SetCommMask, SetCommTimeouts, GetCommTimeouts, SetCommState, GetCommState, CreateEventW, DeviceIoControl, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, Sleep, IsValidCodePage, LocalFree, lstrcpyW, GetCurrentProcess, LocalAlloc, ExpandEnvironmentStringsW, GetTempPathW, GetModuleFileNameW, IsBadStringPtrW, lstrlenW, OutputDebugStringW, FreeLibrary, MultiByteToWideChar, GetTimeFormatW, GetDateFormatW, FileTimeToSystemTime, FileTimeToLocalFileTime, GlobalUnlock, GlobalLock, GlobalAlloc, GetProcAddress, GetModuleHandleW, GetUserDefaultUILanguage, LoadLibraryW, SetLastError, WideCharToMultiByte, TerminateProcess, WaitForSingleObject, OpenProcess, WriteFile, GetTickCount, GetCurrentThreadId, CreateFileW, GetVersionExW, GetLocalTime, CloseHandle, CreateMutexW, FindResourceW, LoadResource, LockResource, SizeofResource, GetLastError, GetEnvironmentStringsW
                                > USER32.dll: PostQuitMessage, GetMenuState, GetMenuStringW, RegisterWindowMessageW, LoadIconW, SendDlgItemMessageA, WinHelpW, IsChild, GetCapture, SetWindowsHookExW, CallNextHookEx, GetClassLongW, GetClassNameW, SetPropW, GetPropW, RemovePropW, GetLastActivePopup, SetActiveWindow, DispatchMessageW, BeginDeferWindowPos, EndDeferWindowPos, GetTopWindow, UnhookWindowsHookEx, GetMessageTime, GetMessagePos, MapWindowPoints, TrackPopupMenu, GetKeyState, UpdateWindow, GetMenu, GetMenuItemID, GetMenuItemCount, MessageBoxW, GetClassInfoExW, AdjustWindowRectEx, EqualRect, DeferWindowPos, CallWindowProcW, IntersectRect, SystemParametersInfoA, ValidateRect, GetSysColor, EndPaint, BeginPaint, ClientToScreen, ScreenToClient, GrayStringW, DrawTextExW, DrawTextW, TabbedTextOutW, IsWindowEnabled, ShowWindow, MoveWindow, SetWindowLongW, SetWindowTextW, GetWindowLongW, IsDialogMessageW, IsZoomed, SetRectEmpty, DestroyMenu, SetDlgItemTextW, SendDlgItemMessageW, DefWindowProcW, UnregisterDeviceNotification, RegisterDeviceNotificationW, DestroyWindow, CreateWindowExW, GetDlgItem, GetWindowTextLengthW, GetWindowTextW, ReleaseDC, SetMenuDefaultItem, GetSubMenu, LoadMenuW, LoadStringW, GetClipboardData, FrameRect, AppendMenuW, SetFocus, TranslateMessage, GetMessageW, CheckMenuItem, GetMenuCheckMarkDimensions, SetMenuItemBitmaps, GetFocus, GetSystemMenu, EnableMenuItem, EndDialog, GetNextDlgTabItem, CreateDialogIndirectParamW, GetDesktopWindow, WindowFromPoint, GetWindowPlacement, GetSysColorBrush, SetParent, SetCapture, LockWindowUpdate, GetDCEx, ReleaseCapture, UnregisterClassA, GetActiveWindow, ModifyMenuW, PostThreadMessageW, DrawIcon, GetCursorPos, GetDoubleClickTime, LoadImageW, IsWindowVisible, IsWindow, EmptyClipboard, OpenClipboard, CloseClipboard, SetClipboardData, LoadBitmapW, GetParent, GetSystemMetrics, BringWindowToTop, IsIconic, SetForegroundWindow, AttachThreadInput, GetForegroundWindow, GetWindow, OffsetRect, GetClientRect, SetWindowPos, GetDlgCtrlID, PeekMessageW, SystemParametersInfoW, KillTimer, SetTimer, SetCursor, LoadCursorW, EnableWindow, DrawFocusRect, InflateRect, FillRect, CopyRect, InvalidateRect, GetWindowThreadProcessId, PostMessageW, FindWindowW, UnregisterClassW, RegisterClassW, GetClassInfoW, GetWindowRect, UnionRect, SetRect, GetDC, GetWindowDC, SendMessageW, PtInRect
                                > GDI32.dll: PatBlt, GetTextMetricsW, GetCharWidthW, CreateFontW, StretchDIBits, CreateCompatibleBitmap, CreateRectRgnIndirect, SetRectRgn, CombineRgn, OffsetViewportOrgEx, SetViewportOrgEx, SetViewportExtEx, DeleteDC, ScaleWindowExtEx, SetWindowExtEx, CreateFontIndirectW, SelectObject, CreateCompatibleDC, GetBkColor, GetTextExtentPoint32W, Escape, ExtTextOutW, TextOutW, RectVisible, PtVisible, CreateRectRgn, SelectClipRgn, IntersectClipRect, ExcludeClipRect, GetClipBox, SetMapMode, SetTextColor, SetBkMode, SetBkColor, RestoreDC, SaveDC, GetDeviceCaps, CreateBitmap, CreatePatternBrush, SetBrushOrgEx, CreateSolidBrush, DeleteObject, GetObjectW, GetStockObject, ScaleViewportExtEx
                                > MSIMG32.dll: TransparentBlt
                                > WINSPOOL.DRV: OpenPrinterW, DocumentPropertiesW, ClosePrinter
                                > ADVAPI32.dll: SetSecurityDescriptorDacl, RegQueryValueW, RegEnumKeyW, RegOpenKeyW, RegDeleteKeyW, RegQueryInfoKeyW, RegEnumKeyExW, InitializeSecurityDescriptor, RegSetKeySecurity, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey
                                > SHELL32.dll: Shell_NotifyIconW
                                > COMCTL32.dll: InitCommonControlsEx, ImageList_Create
                                > SHLWAPI.dll: PathFindFileNameW, PathFindExtensionW
                                > ole32.dll: CoUninitialize, CoInitializeEx, CoWaitForMultipleHandles
                                > OLEAUT32.dll: -, -, -, -
                                > VERSION.dll: GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
                                > SETUPAPI.dll: SetupDiDestroyDeviceInfoList, CM_Get_Device_IDW, CM_Get_DevNode_Status, CM_Get_Parent, SetupDiGetDeviceRegistryPropertyA, SetupDiDestroyDriverInfoList, SetupDiEnumDriverInfoW, SetupDiBuildDriverInfoList, SetupDiOpenDeviceInfoW, SetupDiCreateDeviceInfoList, SetupDiEnumDeviceInfo, SetupDiGetClassDevsA, SetupDiOpenDevRegKey, CM_Get_Sibling, CM_Get_Child_Ex
                                > WS2_32.dll: -
                                > RASAPI32.dll: RasSetEntryPropertiesW, RasGetConnectionStatistics, RasHangUpW, RasDeleteEntryW, RasValidateEntryNameW, RasGetProjectionInfoW, RasGetConnectStatusW, RasDialW, RasGetEntryPropertiesW

                                ( 0 exports )
                                0
                                1. That's what happens when you don't download from the publisher's site ..

                                  Not so complicated after all.
                                  0
                                  1. Security Contributor
                                    Hello,

                                    the VirusTotal analysis of C:\WINDOWS\TEMP\AOC6B0.EXE?
                                    --

                                    @+
                                    Never accept disinfection via DM.
                                    0
                                    1. Hello,
                                      I don't have a file AOC6B0.EXE in Temp,
                                      but I have HN3258.EXE; I'm not sure if there's a connection. It's an icon with a little dog.
                                      0
                                      1. Security Contributor
                                        Hello,

                                        run DSS again and post the report.

                                        Don’t close the computer (don’t restart it either).
                                        --

                                        See you later
                                        Never accept disinfection via private message.
                                        0
                                        1. Deckard's System Scanner v20071014.68
                                          Exécuté par Administrateur le 2008-07-23 08:56:06
                                          L'ordinateur est en mode normal.
                                          --------------------------------------------------------------------------------

                                          [color=red]Mémoire physique totale : 239 MiB (512 MiB recommandé)./color

                                          -- HijackThis (exécuté en tant qu'Administrateur.exe) --------------------------------------

                                          Fichier journal de Trend Micro HijackThis v2.0.2
                                          Analyse sauvegardée à 08:56:27, le 23/07/2008
                                          Plateforme : Windows XP SP2 (WinNT 5.01.2600)
                                          MSIE : Internet Explorer v7.00 (7.00.6000.16674)
                                          Mode de démarrage : Normal

                                          Processus en cours :
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                          C:\WINDOWS\System32\DkLog.exe
                                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                                          C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
                                          C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
                                          C:\WINDOWS\System32\dkcktkn.exe
                                          C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\System32\igfxtray.exe
                                          C:\WINDOWS\System32\hkcmd.exe
                                          C:\WINDOWS\System32\00THotkey.exe
                                          C:\WINDOWS\LTSMMSG.exe
                                          C:\Program Files\Apoint2K\Apoint.exe
                                          C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
                                          C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
                                          C:\WINDOWS\system32\TFNF5.exe
                                          C:\WINDOWS\system32\TPSMain.exe
                                          C:\WINDOWS\System32\ezSP_Px.exe
                                          C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
                                          C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
                                          C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                                          C:\WINDOWS\system32\ctfmon.exe
                                          C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                                          C:\WINDOWS\system32\TPSBattM.exe
                                          C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
                                          C:\Program Files\Apoint2K\Apntex.exe
                                          C:\WINDOWS\system32\wuauclt.exe
                                          C:\WINDOWS\TEMP\NREE8B.EXE
                                          C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
                                          C:\Program Files\Messenger\msmsgs.exe
                                          C:\Program Files\Internet Explorer\iexplore.exe
                                          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                          C:\Documents and Settings\Administrateur\Bureau\dss.exe
                                          C:\PROGRA~1\TRENDM~1\HIJACK~1\ADMINI~1.EXE

                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Page de démarrage = https://www.google.fr/?gws_rd=ssl
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,URL de la page par défaut = https://www.msn.com/fr-fr/?ocid=iehp
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,URL de recherche par défaut = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Page de recherche = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Page de démarrage = https://www.msn.com/fr-fr/?ocid=iehp
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,Nom du dossier Liens = Liens
                                          O2 - BHO : Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                          O2 - BHO : SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                          O2 - BHO : Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                          O4 - HKLM\..\Run : [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                                          O4 - HKLM\..\Run : [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                                          O4 - HKLM\..\Run : [00THotkey] C:\WINDOWS\System32\00THotkey.exe
                                          O4 - HKLM\..\Run : [000StTHK] 000StTHK.exe
                                          O4 - HKLM\..\Run : [LTSMMSG] LTSMMSG.exe
                                          O4 - HKLM\..\Run : [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                          O4 - HKLM\..\Run : [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
                                          O4 - HKLM\..\Run : [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
                                          O4 - HKLM\..\Run : [TFNF5] TFNF5.exe
                                          O4 - HKLM\..\Run : [TPSMain] TPSMain.exe
                                          O4 - HKLM\..\Run : [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
                                          O4 - HKLM\..\Run : [DkAutoReg.exe] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe
                                          O4 - HKLM\..\Run : [DkStartup] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe
                                          O4 - HKLM\..\Run : [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
                                          O4 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                                          O4 - HKCU\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                          O4 - HKCU\..\Run : [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                                          O4 - HKUS\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE LOCAL')
                                          O4 - HKUS\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SERVICE RÉSEAU')
                                          O4 - HKUS\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'SYSTEME')
                                          O4 - HKUS\.DEFAULT\..\Run : [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (Utilisateur 'Utilisateur par défaut')
                                          O4 - Démarrage global : Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                          O4 - Démarrage global : Orange Caraibes.lnk = C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe
                                          O8 - Élément de menu contextuel supplémentaire : E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                          O9 - Bouton supplémentaire : (sans nom) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                          O9 - Élément de menu 'Outils' supplémentaire : Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                          O9 - Bouton supplémentaire : Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                          O9 - Bouton supplémentaire : (sans nom) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Élément de menu 'Outils' supplémentaire : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Bouton supplémentaire : Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O9 - Élément de menu 'Outils' supplémentaire : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O14 - IERESET.INF : START_PAGE_URL=file:///C:\Program Files\TOSHIBA\Free Update Service\splash.html
                                          O16 - DPF : {1856D980-6604-4504-AE2E-6EEE0235FCF5} (ActiveSign.CapicomInterface) - http://www.certeurope.fr/fichiers/activesign/1.2.0.2/ActiveSign.CAB
                                          O16 - DPF : {1DB93715-3B60-43EE-93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://213.16.24.101:8080/cab/OCXChecker_6110.cab
                                          O16 - DPF : {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} (DownloadFile Control) - http://213.16.24.101:8080/cab/DownloadFile_7000.cab
                                          O17 - HKLM\System\CCS\Services\Tcpip\Parameters : Domaine = vauclin.sud
                                          O17 - HKLM\Software\..\Telephony : DomainName = vauclin.sud
                                          O17 - HKLM\System\CS1\Services\Tcpip\Parameters : Domaine = vauclin.sud
                                          O17 - HKLM\System\CS2\Services\Tcpip\Parameters : Domaine = vauclin.sud
                                          O23 - Service : ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                          O23 - Service : Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
                                          O23 - Service : Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
                                          O23 - Service : OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
                                          O23 - Service : SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                          O23 - Service : OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
                                          O23 - Service : OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
                                          O23 - Service : OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe

                                          --
                                          Fin du fichier - 7757 octets

                                          -- Fichiers créés entre le 2008-06-23 et le 2008-07-23 -----------------------------

                                          2008-07-21 13:33:16 0 d-------- C:\Program Files\RegistryQuick
                                          2008-07-17 17:25:39 0 d-------- C:\Combo-Fix
                                          2008-07-17 14:49:20 0 d-------- C:\Documents and Settings\Administrateur\Menu Démarrer
                                          2008-07-16 23:42:04 68096 --a------ C:\WINDOWS\zip.exe
                                          2008-07-16 23:42:04 49152 --a------ C:\WINDOWS\VFind.exe
                                          2008-07-16 23:42:04 161792 --a------ C:\WINDOWS\swreg.exe <Non vérifié ; SteelWerX ; Éditeur de registre SteelWerX>
                                          2008-07-16 23:42:04 98816 --a------ C:\WINDOWS\sed.exe
                                          2008-07-16 23:42:04 80412 --a------ C:\WINDOWS\grep.exe
                                          2008-07-16 23:42:04 89504 --a------ C:\WINDOWS\fdsv.exe <Non vérifié ; Smallfrogs Studio; >
                                          2008-07-16 23:42:03 212480 --a------ C:\WINDOWS\swxcacls.exe <Non vérifié ; SteelWerX ; Configurateur étendu SteelWerX ACLists>
                                          2008-07-16 23:42:03 136704 --a------ C:\WINDOWS\swsc.exe <Non vérifié ; SteelWerX ; Contrôleur de service SteelWerX>
                                          2008-06-25 16:59:30 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2

                                          -- Rapport Find3M ---------------------------------------------------------------

                                          2008-07-22 08:01:37 0 d-------- C:\Program Files\Trend Micro
                                          2008-07-17 18:03:51 471484 --a------ C:\WINDOWS\system32\perfh00C.dat
                                          2008-07-17 18:03:51 76582 --a------ C:\WINDOWS\system32\perfc00C.dat
                                          2008-07-17 00:04:03 0 d-------- C:\Program Files\Microsoft Works
                                          2008-07-15 21:14:43 0 d-------- C:\Documents and Settings\Administrateur\AppData\MSN6
                                          2008-06-30 11:04:13 0 d-------- C:\Program Files\Bac_v7
                                          2008-06-21 13:55:02 0 d--hs--c- C:\Program Files\Fichiers communs\WindowsLiveInstaller
                                          2008-06-21 13:28:44 0 d-------- C:\Program Files\Fichiers communs
                                          2008-06-02 16:39:52 0 dr-h----- C:\Documents and Settings\Administrateur\AppData\SecuROM
                                          2008-06-02 16:29:50 0 d-------- C:\Program Files\Fichiers communs\MainConcept
                                          2008-06-02 16:28:57 0 d-------- C:\Program Files\Micro Application
                                          2008-05-31 11:21:29 0 d-------- C:\Program Files\OrgangeFrance
                                          2008-05-25 20:10:39 0 d-------- C:\Documents and Settings\Administrateur\AppData\Google

                                          -- Dump du registre ---------------------------------------------------------------

                                          *Remarque* les entrées vides et les entrées par défaut légitimes ne sont pas montrées

                                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [06/04/2003 20:19]
                                          "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [06/04/2003 20:07]
                                          "00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [23/05/2003 09:20]
                                          "000StTHK"="000StTHK.exe" [23/06/2001 15:28 C:\WINDOWS\system32\000StTHK.exe]
                                          "LTSMMSG"="LTSMMSG.exe" [18/04/2003 06:06 C:\WINDOWS\ltsmmsg.exe]
                                          "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [17/07/2003 13:38]
                                          "TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [11/03/2003 08:58]
                                          "PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [24/11/2003 06:51]
                                          "TFNF5"="TFNF5.exe" [15/10/2003 12:03 C:\WINDOWS\system32\TFNF5.exe]
                                          "TPSMain"="TPSMain.exe" [01/12/2003 07:09 C:\WINDOWS\system32\TPSMain.exe]
                                          "ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [20/08/2002 06:29]
                                          "DkAutoReg.exe"="C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe" [24/07/2002 20:09]
                                          "DkStartup"="C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe" [24/07/2002 20:12]
                                          "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [08/05/2007 00:43]
                                          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [14/03/2007 03:43]

                                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [19/08/2004 19:09]
                                          "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [15/09/2003 12:19]

                                          C:\Documents and Settings\Tous les utilisateurs\Menu Démarrer\Programmes\Démarrage\
                                          Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 22:05:26]
                                          Orange Caraibes.lnk - C:\Program Files\OrgangeFrance\Orange Caraibes\Orange Caraibes.exe [14/01/2008 14:01:50]

                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                          "DisableRegistryTools"=0 (0x0)
                                          "HideLegacyLogonScripts"=0 (0x0)
                                          "HideLogoffScripts"=0 (0x0)
                                          "RunLogonScriptSync"=1 (0x1)
                                          "RunStartupScriptSync"=0 (0x0)
                                          "HideStartupScripts"=0 (0x0)

                                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
                                          "HideLegacyLogonScripts"=0 (0x0)
                                          "HideLogoffScripts"=0 (0x0)
                                          "RunLogonScriptSync"=1 (0x1)
                                          "RunStartupScriptSync"=0 (0x0)
                                          "HideStartupScripts"=0 (0x0)

                                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
                                          @="Service"

                                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
                                          @="Volume shadow copy"

                                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide de Microsoft Office OneNote 2003.lnk]
                                          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide de Microsoft Office OneNote 2003.lnk
                                          backup=C:\WINDOWS\pss\Lancement rapide de Microsoft Office OneNote 2003.lnkDémarrage commun

                                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n Drop CD+DVD]
                                          C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp

                                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c138b72-2f24-11dd-a5a2-00080ddf4fdb}]
                                          AutoRun\command- E:\setup.exe AUTORUN=1

                                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{caaa0ed6-8975-11dc-a55f-00080ddf4fdb}]
                                          AutoRun\command- RavMon.exe

                                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5cd7da8-da49-11dc-a580-00080ddf4fdb}]
                                          AutoRun\command- RavMon.exe

                                          -- Fin du scanner du système de Deckard : terminé le 2008-07-23 08:56:52 ------------
                                          0
                                          • 1
                                          • 2
                                          • 3
                                          • 4
                                          • 5
                                          • 6
                                          • 7
                                          • 8
                                          • 9