Voici le rapport log.txt
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrateur at 2009-01-20 20:54:49
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 12 GB (47%) free of 25 GB
Total RAM: 246 MB (5% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:12:17, on 20-01-2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\mmm.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\documents and settings\administrateur\local settings\application data\ggoppp.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\visualtooltips\VisualToolTip.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
C:\Program Files\trend micro\Administrateur.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\d88abfb919ee60059584a5427f9e72f7\update\update.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2095689
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz0.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [KelsPackSoft] C:\WINDOWS\system32\mmm.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iexplore] C:\WINDOWS\iexplore.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [RocketDock] "%programfiles%\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [UberIcon] "%programfiles%\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ggoppp] "c:\documents and settings\administrateur\local settings\application data\ggoppp.exe" ggoppp
O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [RocketDock] "%programfiles%\RocketDock\RocketDock.exe" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [UberIcon] "%programfiles%\UberIcon\UberIcon Manager.exe" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - .DEFAULT User Startup: VisualToolTip.lnk = C:\Program Files\visualtooltips\VisualToolTip.exe (User 'Default user')
O4 - Startup: VisualToolTip.lnk = C:\Program Files\visualtooltips\VisualToolTip.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\cryptdll32.dll,C:\WINDOWS\System32\dblstcht32.dll
O20 - Winlogon Notify: cc12cd7e517 - C:\WINDOWS\System32\cryptdll32.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
End of file - 9058 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-11-12 1377576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-15 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
Eazel-FR Toolbar - C:\Program Files\Eazel-FR\tbEaz0.dll [2008-11-23 1784856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 544032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-15 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-15 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 544032]
{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - Eazel-FR Toolbar - C:\Program Files\Eazel-FR\tbEaz0.dll [2008-11-23 1784856]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2006-08-14 98304]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2006-08-14 114688]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2006-08-14 94208]
"KelsPackSoft"=C:\WINDOWS\system32\mmm.exe [2005-07-05 828416]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
""= []
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2005-10-26 159744]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe [2005-06-23 57344]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2004-12-20 33792]
"iexplore"=C:\WINDOWS\iexplore.exe []
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"=C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe [2006-08-05 62976]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2006-05-14 344064]
"UberIcon"=C:\Program Files\UberIcon\UberIcon Manager.exe [2006-02-05 180224]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-03 15360]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"ggoppp"=c:\documents and settings\administrateur\local settings\application data\ggoppp.exe [2009-01-15 221184]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
VisualToolTip.lnk - C:\Program Files\visualtooltips\VisualToolTip.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\System32\cryptdll32.dll,C:\WINDOWS\System32\dblstcht32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cc12cd7e517]
C:\WINDOWS\System32\cryptdll32.dll [2009-01-20 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-08-14 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispCPL"=0
"NoDispAppearancePage"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1
"NoThemesTab"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceClassicControlPanel"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\wamp\Apache2\bin\httpd.exe"="C:\wamp\Apache2\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Administrateur\so7.exe"="C:\Documents and Settings\Administrateur\so7.exe:*:Enabled:so7"
"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\WINDOWS\system32\iexplore.exe"="C:\WINDOWS\system32\iexplore.exe:*:Enabled:Microsoft Internet Explorer"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9047b2f8-b61e-11dd-907c-001320b2d2f8}]
shell\AutoRun\command - F:\explorer.exe
shell\explore\command - F:\explorer.exe
shell\open\command - F:\explorer.exe
======File associations======
.bat - edit - C:\WINDOWS\system32\NOTEPAD2.EXE %1
.cmd - edit - C:\WINDOWS\system32\NOTEPAD2.EXE %1
.inf - open - C:\WINDOWS\system32\NOTEPAD2.EXE %1
.ini - open - C:\WINDOWS\system32\NOTEPAD2.EXE %1
.js - edit - C:\WINDOWS\system32\Notepad2.exe %1
.reg - edit - C:\WINDOWS\system32\NOTEPAD2.EXE %1
.txt - open - C:\WINDOWS\system32\NOTEPAD2.EXE %1
.vbs - edit - C:\WINDOWS\system32\Notepad2.exe %1
======List of files/folders created in the last 1 months======
2009-01-20 20:55:24 ----D---- C:\Program Files\trend micro
2009-01-20 20:54:49 ----D---- C:\rsit
2009-01-20 14:22:36 ----ASH---- C:\WINDOWS\system32\249.tmp
2009-01-20 13:32:45 ----D---- C:\Program Files\Lavasoft
2009-01-20 13:32:42 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-01-20 13:31:43 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2009-01-19 16:33:58 ----D---- C:\Program Files\Avira
2009-01-19 16:33:58 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-01-19 16:30:14 ----D---- C:\Documents and Settings\Administrateur\Application Data\vlc
2009-01-19 16:28:07 ----D---- C:\Program Files\VideoLAN
2009-01-19 13:57:19 ----SHD---- C:\WINDOWS\system32\GroupPolicyManifest
2009-01-19 13:52:38 ----D---- C:\Program Files\Sunbelt Software
2009-01-17 21:46:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-01-17 21:45:41 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-01-17 21:44:16 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-01-17 21:42:09 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-01-17 21:40:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2009-01-17 21:37:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-01-17 21:36:16 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-01-17 21:35:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-01-17 21:34:15 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-01-17 21:29:15 ----HDC---- C:\WINDOWS\$NtUninstallKB926251$
2009-01-17 21:27:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-01-17 21:25:25 ----D---- C:\Program Files\MSXML 6.0
2009-01-17 21:25:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-01-17 21:15:14 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-01-17 21:13:23 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-01-17 21:00:19 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-01-17 20:58:53 ----D---- C:\WINDOWS\system32\appmgmt
2009-01-17 14:48:01 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-01-17 14:43:24 ----HDC---- C:\WINDOWS\$NtUninstallKB923689$
2009-01-17 14:39:43 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-17 14:36:54 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-01-17 14:32:18 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-01-17 14:18:02 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-01-17 14:16:53 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-01-17 14:15:53 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-01-17 14:15:00 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-01-17 14:13:45 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-01-17 14:12:25 ----D---- C:\Program Files\MSXML 4.0
2009-01-17 14:06:19 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP10$
2009-01-17 13:58:56 ----A---- C:\WINDOWS\GnuHashes.ini
2009-01-15 20:44:37 ----D---- C:\Documents and Settings\Administrateur\Application Data\Google
2009-01-15 20:43:01 ----D---- C:\Program Files\Google
2009-01-15 20:34:32 ----D---- C:\Program Files\Conduit
2009-01-15 20:34:27 ----D---- C:\Program Files\Eazel-FR
2009-01-15 20:12:26 ----A---- C:\WINDOWS\system32\cryptdll32.dll
2009-01-15 20:12:26 ----A---- C:\ARK2.tmp
2009-01-15 19:54:27 ----D---- C:\WINDOWS\ie7updates
2009-01-15 19:43:40 ----D---- C:\Documents and Settings\Administrateur\Application Data\LimeWire
2009-01-15 19:41:45 ----D---- C:\WINDOWS\WBEM
2009-01-15 19:41:35 ----D---- C:\WINDOWS\system32\fr-fr
2009-01-15 19:38:11 ----HDC---- C:\WINDOWS\ie7
2009-01-15 19:35:49 ----A---- C:\WINDOWS\system32\javaws.exe
2009-01-15 19:35:49 ----A---- C:\WINDOWS\system32\javaw.exe
2009-01-15 19:35:49 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-01-15 19:35:48 ----A---- C:\WINDOWS\system32\java.exe
2009-01-15 19:33:32 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2009-01-15 19:30:22 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-01-15 19:30:20 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2009-01-15 19:28:27 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
2009-01-15 19:27:30 ----N---- C:\WINDOWS\system32\xmllite.dll
2009-01-15 19:19:27 ----D---- C:\Documents and Settings\Administrateur\Application Data\Sun
2009-01-15 19:04:28 ----N---- C:\WINDOWS\system32\tzchange.exe
2009-01-15 19:02:37 ----D---- C:\Program Files\LimeWire
2009-01-15 17:34:13 ----D---- C:\Documents and Settings\Administrateur\Application Data\Mozilla
2009-01-15 17:33:56 ----D---- C:\Program Files\Mozilla Firefox
2009-01-15 16:57:10 ----D---- C:\Program Files\InternetGameBox
======List of files/folders modified in the last 1 months======
2009-01-20 21:12:34 ----D---- C:\WINDOWS\system32
2009-01-20 21:12:16 ----D---- C:\WINDOWS
2009-01-20 21:11:43 ----D---- C:\Temp
2009-01-20 21:11:32 ----D---- C:\WINDOWS\Temp
2009-01-20 20:55:24 ----RD---- C:\Program Files
2009-01-20 18:39:06 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-20 18:37:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-20 13:33:56 ----SHD---- C:\WINDOWS\Installer
2009-01-20 13:32:45 ----D---- C:\WINDOWS\system32\drivers
2009-01-20 13:31:43 ----D---- C:\Program Files\Fichiers communs
2009-01-19 20:27:36 ----HD---- C:\WINDOWS\inf
2009-01-19 20:27:35 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-19 15:34:58 ----D---- C:\WINDOWS\Debug
2009-01-18 20:17:29 ----A---- C:\WINDOWS\winamp.ini
2009-01-17 21:48:20 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-01-17 21:46:25 ----D---- C:\WINDOWS\system32\DllCache
2009-01-17 21:46:23 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-17 21:29:18 ----D---- C:\Program Files\Windows Media Player
2009-01-17 20:48:02 ----D---- C:\Program Files\Rational
2009-01-17 20:47:45 ----RSD---- C:\WINDOWS\Fonts
2009-01-17 20:46:54 ----A---- C:\WINDOWS\vbaddin.ini
2009-01-17 20:35:16 ----D---- C:\Program Files\Winamp
2009-01-17 20:34:54 ----D---- C:\Program Files\EasyPHP 2.0b1
2009-01-17 20:34:14 ----D---- C:\JBuilder7
2009-01-17 20:31:12 ----D---- C:\wamp
2009-01-17 14:16:57 ----D---- C:\WINDOWS\WinSxS
2009-01-15 21:35:49 ----D---- C:\Program Files\Internet Explorer
2009-01-15 21:35:48 ----D---- C:\WINDOWS\Network Diagnostic
2009-01-15 21:35:48 ----D---- C:\WINDOWS\Help
2009-01-15 19:41:24 ----D---- C:\WINDOWS\Media
2009-01-15 19:33:21 ----D---- C:\Program Files\Java
2009-01-15 17:36:16 ----D---- C:\Documents and Settings\Administrateur\Application Data\Adobe
2009-01-09 17:35:30 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-09-26 40320]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2006-08-06 163328]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2006-09-26 138752]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-09-28 9600]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-11-17 1042432]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2003-11-17 212224]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2006-08-14 1109568]
R3 MODEMCSA;Périphérique de filtrage de flux Unimodem; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-09-26 12288]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2005-11-16 1047816]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2006-09-26 31744]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-04-19 30080]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-07-06 58496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-09-26 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-11-17 680704]
S1 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2006-02-25 16877]
S3 bvrp_pci;bvrp_pci; \??\C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 K320bus;Sony Ericsson K320 driver (WDM); C:\WINDOWS\system32\DRIVERS\K320bus.sys [2006-08-18 61504]
S3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\K320mdfl.sys [2006-08-18 9328]
S3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\K320mdm.sys [2006-08-18 97056]
S3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\K320mgmt.sys [2006-08-18 88560]
S3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\K320obex.sys [2006-08-18 86368]
S3 sfng32;Sonic Focus Plugin for Sigmatel HDA; C:\WINDOWS\system32\drivers\sfng32.sys [2006-08-23 41728]
S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-12-29 26368]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-01-20 611664]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-15 152984]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2006-09-27 38912]
S3 WMConnectCDS;Service Windows Media Connect; C:\Program Files\Windows Media Connect 2\wmccds.exe [2005-10-06 856064]
-----------------EOF-----------------
rapport info.txt
Event Type: Informations
User:
Computer Name: VISI0N-4812C7C6
Event Code: 100
Message: MsnMsgr (604) Le moteur de base de données 5.01.2600.2780 est démarré.
Record Number: 307
Source Name: ESENT
Time Written: 20090115135536.000000+060
Event Type: Informations
User:
Computer Name: VISI0N-4812C7C6
Event Code: 12001
Message: The Messenger Sharing USN Journal Reader service started successfully.
Record Number: 306
Source Name: usnjsvc
Time Written: 20090115135533.000000+060
Event Type:
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\Teleca Shared
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0403
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"KTD"=C:\WINDOWS\DriverPacks
-----------------EOF-----------------