Rechercher : dans
Par :

Infecté par TR/agent

Dernière réponse le 4 fév 2009 à 18:20:03 tribord44, le 30 jan 2009 à 12:02:42 
 Signaler ce message aux modérateurs

Bonjour,
âpres avoir suivit la procédure conseillée dans le forum (c.cleaner, anti malware ,scan en ligne avec betdefender ,puis
scan avec hijackthis); je suis toujours infecté avec un trojant "TR/agent".
Quelqu'un peut il me conseiller ?
voici le rapport de l'anti malware ,en l'occurrence "malwarebytes"

Version de la base de données: 1698
Windows 5.1.2600 Service Pack 2

29/01/2009 21:19:28
mbam-log-2009-01-29 (21-19-28).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 166688
Temps écoulé: 2 hour(s), 11 minute(s), 34 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

Celui de betdefender:
Statistics

Time


01:45:46

Files


423897

Folders


9385

Boot Sectors


0

Archives


9301

Packed Files


18799







Results

Identified Viruses


3

Infected Files


3

Suspect Files


0

Warnings


0

Disinfected


0

Deleted Files


3







Engines Info

Virus Definitions


2617776

Engine build


AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

Scan plugins


17

Archive plugins


45

Unpack plugins


7

E-mail plugins


6

System plugins


4







Scan Settings

First Action


Disinfect

Second Action


Delete

Heuristics


Yes

Enable Warnings


Yes

Scanned Extensions


*;

Exclude Extensions




Scan Emails


Yes

Scan Archives


Yes

Scan Packed


Yes

Scan Files


Yes

Scan Boot


Yes








Scanned File


Status

C:\Documents and Settings\\Local Settings\Application Data\Identities\{CAD5B7C9-756D-44DE-83DE-EB12DF98E55B}\Microsoft\Outlook Express\GAGS.dbx=>(message 65): TR :=>[Subject: TR : TR :][Date: Thu, 6 May 2004 14:56:55 +0200]=>(MIME part)=>Post-it.zip=>Post-it.exe


Detected with: Application.Joke.Miracle.B

C:\Documents and Settings\\Local Settings\Application Data\Identities\{CAD5B7C9-756D-44DE-83DE-EB12DF98E55B}\Microsoft\Outlook Express\GAGS.dbx=>(message 65): TR :=>[Subject: TR : TR :][Date: Thu, 6 May 2004 14:56:55 +0200]=>(MIME part)=>Post-it.zip=>Post-it.exe


Disinfection failed

C:\Documents and Settings\\Local Settings\Application Data\Identities\{CAD5B7C9-756D-44DE-83DE-EB12DF98E55B}\Microsoft\Outlook Express\GAGS.dbx=>(message 65): TR :=>[Subject: TR : TR :][Date: Thu, 6 May 2004 14:56:55 +0200]=>(MIME part)=>Post-it.zip=>Post-it.exe


Deleted

C:\Documents and Settings\\Local Settings\Application Data\Identities\{CAD5B7C9-756D-44DE-83DE-EB12DF98E55B}\Microsoft\Outlook Express\GAGS.dbx=>(message 65): TR :=>[Subject: TR : TR :][Date: Thu, 6 May 2004 14:56:55 +0200]=>(MIME part)=>Post-it.zip


Updated

C:\Documents and Settings\\Local Settings\Application Data\Identities\{CAD5B7C9-756D-44DE-83DE-EB12DF98E55B}\Microsoft\Outlook Express\GAGS.dbx=>(message 65): TR :=>[Subject: TR : TR :][Date: Thu, 6 May 2004 14:56:55 +0200]=>(MIME part)


Updated

C:\Documents and Settings\\Local Settings\Application Data\Identities\{CAD5B7C9-756D-44DE-83DE-EB12DF98E55B}\Microsoft\Outlook Express\GAGS.dbx=>(message 65): TR :


Updated

C:\Documents and Settings\\Local Settings\Application Data\Identities\{CAD5B7C9-756D-44DE-83DE-EB12DF98E55B}\Microsoft\Outlook Express\GAGS.dbx


Updated

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe=>wise0010


Detected with: Application.Claria.AL

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe=>wise0010


Disinfection failed

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe=>wise0010


Deleted

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe


Update failed

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe=>wise0013


Detected with: Application.Claria.Precision.Time.A

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe=>wise0013


Disinfection failed

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe=>wise0013


Deleted

C:\unzipped\precisiontime2102\InstallPrecisionTime.exe


Update failed

Et le rapport hijackthis:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:59:16, on 29/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Pack Securite\Common\FSM32.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\SECURE~1\secp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Pack Securite\Common\FSMA32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Pack Securite\Common\FSMB32.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Pack Securite\Common\FCH32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Pack Securite\Common\FAMEH32.EXE
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Pack Securite\FSGUI\fsguidll.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Pack Securite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Pack Securite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [mobiswing] C:\PROGRA~1\SECURE~1\secp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [DriverCure] C:\Program Files\ParetoLogic\DriverCure\DriverCure.exe -scan
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 25163 bytes

Configuration: Windows XP sp2
Firefox 3.0.5

1

sKe69, le 30 jan 2009 à 12:11:42

Salut,

Infecté ....


Dans l'ordre :



A- Tu as deux Antivirus actifs sur ton PC ( F-Sécure et AntiVir ) : c'est 1 de trop ! Ralentissement et instabilité du système + conflit entre les AV + grosse faille de sécurité ...

Donc je te conseille de supprimmer F-secure ( si tu ne payes pas de licence chez eux ) ainsi :
télécharge ce-ci sur ton bureau :

ftp://ftp.f-secure.com/support/tools/uitool/UITool3-380.zip

Clique droit sur le .zip et choisis " extraire tout " sur ton bureau .

Démarrer en mode sans echec .

/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

Comment aller en Mode sans échec :
1) Redémarre ton ordi .
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
4) Choisis la première option : Sans Échec , et valide en tapant sur [Entrée] .
5) Choisis ton compte habituel ( et pas Administrateur ).
attention : pas de connexion possible en mode sans échec , donc copie ou imprime bien la manipe pour éviter les erreurs ...

Lance " uninstallationTool.exe " et laisse toi guider ...


une fois finit , redémarre ton PC ( retour mode normal ) .


( Pour AntiVir : en mode sans échec, via pannaeu de config / "ajout et suppression de prg " ) .

=======================

2- Télécharge ToolBar S&D ( de Eric_71/Team IDN ) sur ton bureau :
http://eric.71.mespages.googlepages.com/ToolBarSD.exe

( Tuto : http://toolbarsd.googlepages.com/aideenimages )

!! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!

* Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
--> Tapes directement sur 2 ( option " suppression " ) puis tape sur [Entrée].

Le nettoyage commence .

! ne touche à rien lors de la suppression !

Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse
accompagné d'un nouveau rapport hijackthis pour analyse ...

( le rapport est en outre sauvegardé ici -> C:\TB.txt )





"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

2

tribord44, le 30 jan 2009 à 13:53:27

Salut et merci de ta réponse ,
Bien suivi les différentes étapes
Le rapport toolbar
-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(TM) XP 2600+ )
BIOS : Award Modular BIOS v6.0
USER : M V ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:114 Go (Free:13 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
G:\ (USB)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 30/01/2009|13:33 )

-----------\\ SUPPRESSION

Supprime! - C:\DOCUME~1\MV~1\APPLIC~1\Adssite Advanced Toolbar\selected.xml
Supprime! - C:\Program Files\Adssite Advanced Toolbar\buttons.xml
Supprime! - C:\Program Files\Adssite Advanced Toolbar\search.xml
Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG
Supprime! - C:\DOCUME~1\MV~1\APPLIC~1\Adssite Advanced Toolbar
Supprime! - C:\Program Files\Adssite Advanced Toolbar
Supprime! - C:\Program Files\Multi_Media_France

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ Extensions

(M V) - {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} => forecastfox
(M V) - {0545b830-f0aa-4d7e-8820-50a4629a56fe} => clrtabs
(M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb-2.0-tb
(M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb-2.0-tb
(M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb__45_2.0__45_tb


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://go.microsoft.com/fwlink/?linkid=677"
"Start Page_bak"="http://www.coolsearch.biz/"
"Search Page"="http://home.microsoft.com/access/allinone.asp"
"Search Bar"="http://g.msn.fr/0SEFRFR/SAOS02"
"SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.msn.com/"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"


--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\MV~1\Application Data\Microsoft\Office\R‚cents\Auto FX Software DreamSuite Gel Series 1.18 CRACK.lnk
C:\DOCUME~1\MV~1\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar



1 - "C:\ToolBar SD\TB_1.txt" - 30/01/2009|13:38 - Option : [2]

-----------\\ Fin du rapport a 13:38:29,00

et le rapport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:41:29, on 30/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\SECURE~1\secp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [mobiswing] C:\PROGRA~1\SECURE~1\secp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24273 bytes

Répondre à tribord44

3

sKe69, le 30 jan 2009 à 14:14:26

Bien ....


on continue :

Télécharge SDFix sur ton bureau :
ici http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.
ou ici http://download.bleepingcomputer.com/andymanchesta/SDFix.exe­
ou ici http://sdfix.net/SDFix.exe

--> Double-clique sur SDFix.exe et choisis "Install" .

( tuto ici : http://www.malekal.com/tutorial_SDFix.php )

Puis une fois l'installe faite ,

Impératif : Démarrer en mode sans echec .

/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

Comment aller en Mode sans échec :
1) Redémarre ton ordi .
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
4) Choisis la première option : Sans Échec , et valide en tapant sur [Entrée] .
5) Choisis ton compte habituel ( et pas Administrateur ).
attention : pas de connexion possible en mode sans échec , donc copie ou imprime bien la manipe pour éviter les erreurs ...


Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double-clique sur RunThis.bat pour lancer l'outil .
-->Tapes Y pour lancer le script ...
Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
presses une touche pour redémarrer quand il te le sera demandé .

Le PC va mettre du temps avant de démarrer ( c'est normale ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier
C:\SDFix sous le nom "Report.txt".

Poste ce dernier dans ta prochaine réponse accompagné d'un nouveau rapport Hijakcthis pour analyse ...


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

4

tribord44, le 30 jan 2009 à 15:06:31

Ok ,
le rapport sdfix
[b]SDFix: Version 1.240 /b
Run by M V on 30/01/2009 at 14:38

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services /b:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files /b:

Trojan Files Found:

C:\DOCUME~1\MV~1\LOCALS~1\Temp\tmpFD.tmp - Deleted





Removing Temp Files

[b]ADS Check /b:



[b]Final Check /b:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 14:50:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services /b:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[b]Remaining Files /b:


File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes /b:

Sun 28 Oct 2007 5,903,928 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Sun 16 Mar 2008 11,690 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Tue 8 Mar 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 14 Mar 2005 299,008 A..H. --- "C:\Program Files\Canon\MP Navigator 2.0\Maint.exe"
Mon 25 Apr 2005 61,440 A..H. --- "C:\Program Files\Canon\MP Navigator 2.0\uinstrsc.dll"
Thu 2 Nov 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Sun 15 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\326d1a08fc685e3efad9e9a5b059ebfb\BIT26.tmp"
Sun 15 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5b6da8fb69b176ee583a3734e2af76e6\BIT27.tmp"
Sun 15 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\60f98441524da959e4cfd96533bfcea5\BIT2D.tmp"
Sun 15 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\7333946973f87a4fdf879a85eeae256b\BIT28.tmp"
Sun 15 Jun 2008 10,092,048 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8b3179d71e82d8085d960408b16ae5bf\BIT2A.tmp"
Sun 15 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9526baba4c0a42975f8fabcda9ca8dc3\BIT2B.tmp"
Sun 15 Jun 2008 1,229,688 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\bc7043d60e692448b548f03d568309ab\BIT29.tmp"
Sun 15 Jun 2008 4,856,848 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f3fd033e4d9140ea4bb2ff5810443583\BIT2C.tmp"

[b]Finished!/b

et le nouveau rapport hijakthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:58:46, on 30/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\SECURE~1\secp.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [mobiswing] C:\PROGRA~1\SECURE~1\secp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24329 bytes

Répondre à tribord44

5

sKe69, le 30 jan 2009 à 15:17:50

Oki ...



1- CCleaner :

Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

---> Utilisation:
! déconnecte toi et ferme toutes applications en cours !
* va dans "nettoyeur" : fais -analyse- puis -nettoyage-
* va dans "registre" : fais -chercher les erreurs- et -réparer toutes les erreurs-
( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )




2- On va appronfondir Hijackthis avec ceci :

Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

-> http://images.malwareremoval.com/random/RSIT.exe

! Ferme bien toutes tes applications en cours !

Double-clique sur " RSIT.exe " pour le lancer .

-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

* Devant l'option "List files/folders created ..." , tu choisis : 2 months

* clique ensuite sur " Continue " pour lancer l'analyse ...


( Note : Si la dernière version de HijackThis n'est pas détectée sur ton PC, RSIT le téléchargera et te demandera d'accepter la licence.)


-> laisse faire le scan et ne touche pas au PC ...


Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

Important : poste un rapport, puis l'autre dans la réponse suivante ... si tu essaies de poster les deux en même temps,
cela risque d'être trop long pour le forum ...
Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ...

( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

6

tribord44, le 30 jan 2009 à 15:40:54

le 1er

Logfile of random's system information tool 1.05 (written by random/random)
Run by M V at 2009-01-30 15:35:05
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 13 GB (11%) free of 117 GB
Total RAM: 2048 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:35:09, on 30/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\SECURE~1\secp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Documents and Settings\M VOILLET\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\M V.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [mobiswing] C:\PROGRA~1\SECURE~1\secp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24358 bytes

Répondre à tribord44

7

tribord44, le 30 jan 2009 à 15:45:32

et le 2 ième

info.txt logfile of random's system information tool 1.05 2009-01-30 15:35:10

======Uninstall list======

-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
150 000 Cliparts Volume 1-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5CE69F36-35FD-4552-81EC-198F5A3F532B}
Active GIF Creator 2.18-->"C:\Program Files\Active GIF Creator 2.18\uninstall.exe"
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator 10-->"C:\Program Files\InstallShield Installation Information\{412033BC-44CF-48D9-B813-4B835101F4D3}\setup.exe"
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe SVG Viewer 3.0-->C:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Install.log
Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AFPL Ghostscript 8.50-->C:\gs\uninstgs.exe "C:\gs\gs8.50\uninstal.txt"
AFPL Ghostscript Fonts-->C:\gs\uninstgs.exe "C:\gs\fonts\uninstal.txt"
ALCATEL PC Suite V6.2.8-->"C:\Program Files\ALCATEL PC Suite\unins000.exe"
AMI-CW52 V.92 PCI Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F01&SUBSYS_900616EF\HXFSETUP.EXE -U -IVEN_14F1&DEV_2F01&SUBSYS_900616EF
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
ArtRage 2-->MsiExec.exe /X{53DEAAB0-0A05-4C41-AE59-305B188CE6FB}
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Bamboo Scribe Shared Files-->MsiExec.exe /X{08581E23-EC5B-4AEC-8DB9-F186D751129F}
Bamboo Scribe-->"C:\Program Files\Bamboo Scribe\unins000.exe"
Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
BufferZone-->MsiExec.exe /X{793CFFC9-A72F-431D-9C74-2E9361E67D04}
Canon Camera Window for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A29EA741-24F7-4C07-9B2C-06CB6491BE4A}
Canon EOS 20D Pilote WIA -->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{ED9775A0-383E-4EAA-8DA5-8CC6860D60A3}
Canon Internet Library for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6A0DBAA6-4FEC-41B7-858E-99EF59B9173C}
Canon MP Navigator 2.0-->"C:\Program Files\Canon\MP Navigator 2.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator 2.0\uninst.ini
Canon MP500-->"C:\WINDOWS\system32\CanonMP Uninstaller Information\{BA4DF4C3-196E-4128-969A-00996B5A46F8}\DelDrv.exe" /U:{BA4DF4C3-196E-4128-969A-00996B5A46F8} /L0x000c
Canon PhotoRecord-->MsiExec.exe /X{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D}
Canon RAW Image Task for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{D076E06B-F74B-454F-A56E-7510D7B6C9F0}
Canon RemoteCapture Task for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{822586CA-0B15-428C-859A-64B3728F28E7}
Canon Utilities Digital Photo Professional 3.4-->"C:\Program Files\Fichiers communs\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\Digital Photo Professional\Uninst.ini"
Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
Canon Utilities EOS Capture 1.2-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{74BE7519-41A7-45A8-8AA6-78C7907A4808}
Canon Utilities EOS Viewer Utility 1.2-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{73516B79-4518-4064-A328-28593D14E5A7}
Canon Utilities RemoteCapture 2.7-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}
Canon Utilities ZoomBrowser EX-->MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
Cartoonist 1.2-->"C:\Program Files\Cartoonist\unins000.exe"
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CDex 1.50 [Extraction Audio]-->"C:\Program Files\CDex\uninstall.exe"
CD-LabelPrint-->"C:\Program Files\Canon\CD-LabelPrint\Uninstal.exe" Canon.CDLabelPrint.Application
Classic PhoneTools-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3436EE2-D5CB-4249-840B-3A0140CC34C3}\setup.exe" -l0x40c ControlPanel
Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
Disney Tarzan, Atelier de Jeux-->C:\WINDOWS\IsUn040c.exe -fC:\PROGRA~1\DISNEY~1\DISNEY~1\DeIsL1.isu
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DreamSuite Series2-->C:\WINDOWS\unvise32.exe C:\DS2Uninstall.log
DShot TWAIN Driver ver1.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{298B02FF-B4E7-460E-8BF6-95E8579C3EDC}\setup.exe"
DVD to VCD AVI DivX Converter v3.2 (build 069)-->C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
Easy-WebPrint-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
EBP Comptes Bancaires 2004-->"C:\Program Files\EBP\Comptes Bancaires\unins000.exe"
eMule-->"C:\Program Files\eMule\Uninstall.exe"
Environnement d'exécution Java 2, Standard Edition v1.3.1_02-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\JavaSoft\JRE\1.3.1_02\Uninst.isu"
Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
Google Earth-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hollywood FX Pack 26 - Extra FX-->C:\WINDOWS\unvise32.exe C:\WINDOWS\unextrafx.log
InterActual Player-->C:\Program Files\InterActual\InterActual Player\inuninst.exe
J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
jp2IE 1.0-->C:\WINDOWS\unins001.exe
Lame ACM MP3 Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
Le Fabuleux Voyage de l'Oncle Ernest-->C:\emme\Voyage\Desinst.exe
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
Logitech QuickCam-->MsiExec.exe /I{0496D9E9-224B-4AFA-8F37-23B98D52F1EB}
Make a Movie-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{70C002F0-5308-42D8-A65A-91436B90255C}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
Microsoft ActiveSync 3.8-->"C:\WINDOWS\ISUN040C.EXE" -f"C:\Program Files\Microsoft ActiveSync\DeIsL1.isu" -c"C:\Program Files\Microsoft ActiveSync\ceuninst.dll"
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669-->C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Excel Viewer-->MsiExec.exe /I{95120000-003F-0409-0000-0000000FF1CE}
Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.19)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
Mulan FTH-->C:\WINDOWS\unin040c.exe -fC:\PROGRA~1\DISNEY~1\MULANF~1\DeIsL1.isu
My DShot Camera Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5E54A963-5088-4C7E-8253-D06BCFFA8A46}\setup.exe"
Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\setupx.exe /uninstall ExtraUninstallID=""
NeroVision Express Content-->C:\WINDOWS\UNNVEContent.exe /UNINSTALL
OmniPage SE-->MsiExec.exe /I{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}
OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{6D7F8D4B-D1A4-402A-973E-31E90940E585}
OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Pen Tablet-->C:\Program Files\Tablet\Pen\Remove.exe /u
Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
Pinnacle Hollywood FX 5
-->C:\WINDOWS\unvise32.exe C:\Program Files\Pinnacle\Hollywood FX 5\uninstal.log
Pinnacle Hollywood FX Pack0 - Extra FX-->C:\WINDOWS\unvise32.exe C:\WINDOWS\unhfxpack0.log
Pinnacle PCI Performance Enhancer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3E5A81BA-4702-490A-B729-0BFF6E7CBF96}\setup.exe" -l0x40c
Pinnacle Systems PCI Performance Enhancer-->C:\PROGRA~1\Pinnacle\PPE\UNWISE.EXE C:\PROGRA~1\Pinnacle\PPE\INSTALL.LOG
PRODUCT_NAME_REF PRODUCT_VERSION-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8A367C28-423C-48E2-8C76-EBA1171F932A}\apxp.ex_" -l0x40c
Profound effect Generic Cam recorder-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{81BB044C-3CDD-441C-9A71-EDE87E4DA4C9}\setup.exe" -l0x40c
Profound effect Hi end Cam recorder-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48299665-C4D7-4A89-9AD8-2EE4A014F4C6}\setup.exe" -l0x40c
Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
Quick Zip 3.06.3-->"C:\Program Files\QuickZip\unins000.exe"
QuickTime for Windows (32-bit)-->C:\WINDOWS\QTW32DEL.EXE
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
RescuePRO -->MsiExec.exe /X{B215D967-5524-4722-917D-A1457A57FF30}
Ri4m v5.0.1d-->C:\Program Files\Ripp-it_AM\Ri4m_Uninstal.exe
SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\setup.exe" -l0x40c
Secured eMule Toolbar-->C:\PROGRA~1\SECURE~2\UNWISE.EXE C:\PROGRA~1\SECURE~2\INSTALL.LOG
Secured eMule-->C:\PROGRA~1\SECURE~1\UNWISE.EXE C:\PROGRA~1\SECURE~1\INSTALL.LOG
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
SFR - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
SoundMAX-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
Studio 9.1 Patch-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{16E217EA-C3E0-402D-8D4F-6189DB74497A}\Setup.exe" -l0x40c UNINSTALL
Studio 9-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E491AB7-4589-48CA-9CBB-874CB2788391}\Setup.exe" -l0x40c UNINSTALL
Studio Content DVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B67624DE-75CE-4FAD-9F29-5C115773CE61}\Setup.exe" -l0x40c
torrent_search Toolbar-->C:\PROGRA~1\TORREN~1\UNWISE.EXE C:\PROGRA~1\TORREN~1\INSTALL.LOG
Uninstall AutoEye-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\AutoEye\AutoEye Uninstall.log
Uninstall DreamSuite Bonus-->C:\WINDOWS\unvise32.exe C:\PROGRAM FILES\ADOBE\ADOBE PHOTOSHOP CS3\MODULES EXTERNES\DreamSuite Bonus\DreamSuite Bonus Uninstall.log
Uninstall DreamSuite-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\DreamSuite\DreamSuite Uninstall.log
Uninstall Mystical-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\Mystical\Mystical Uninstall.log
Uninstall MysticalTTC-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\MysticalTTC\MysticalTTC Uninstall.log
ViaMichelin Navigation X-930-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47FF921C-E834-47A6-8CE4-F0A99CDE347F}\setup.exe" -l0x40c
VideoLAN VLC media player 0.8.6b-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
Windows Live Toolbar-->MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Search 4.0-->"C:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WONswap-->C:\Program Files\WON\WONswap\WONswapUninstall.exe
XnView 1.90.2-->"C:\Program Files\XnView\unins000.exe"
Xvid 1.1.2 final uninstall-->"C:\Program Files\XviD\unins001.exe"

======Hosts File======

127.0.0.1 localhost

======Security center information======

AV: Avira AntiVir PersonalEdition

System event log

Computer Name: V
Event Code: 7036
Message: Le service Acquisition d'image Windows (WIA) est entré dans l'état : en cours d'exécution.

Record Number: 17740
Source Name: Service Control Manager
Time Written: 20081230223055.000000+060
Event Type: Informations
User:

Computer Name: V
Event Code: 7036
Message: Le service FLEXnet Licensing Service est entré dans l'état : arrêté.

Record Number: 17739
Source Name: Service Control Manager
Time Written: 20081230211650.000000+060
Event Type: Informations
User:

Computer Name: V
Event Code: 7036
Message: Le service FLEXnet Licensing Service est entré dans l'état : en cours d'exécution.

Record Number: 17738
Source Name: Service Control Manager
Time Written: 20081230205952.000000+060
Event Type: Informations
User:

Computer Name: V
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service FLEXnet Licensing Service.

Record Number: 17737
Source Name: Service Control Manager
Time Written: 20081230205952.000000+060
Event Type: Informations
User: VOILLET\M V

Computer Name: V
Event Code: 10010
Message: Le serveur {E60687F7-01A1-40AA-86AC-DB1CBF673334} ne s'est pas enregistré sur DCOM avant la fin du temps imparti.

Record Number: 17736
Source Name: DCOM
Time Written: 20081230205800.000000+060
Event Type: erreur
User: AUTORITE NT\SYSTEM

Application event log

Computer Name: V
Event Code: 1517
Message: Windows a sauvegardé le Registre utilisateur VOILLET\M VOILLET alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.


Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

Record Number: 11914
Source Name: Userenv
Time Written: 20080320223739.000000+060
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: V
Event Code: 4137
Message: CI a démarré pour le catalogue c:\system volume information\catalog.wci.

Record Number: 11913
Source Name: Ci
Time Written: 20080320161159.000000+060
Event Type: Informations
User:

Computer Name: V
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.

Record Number: 11912
Source Name: SecurityCenter
Time Written: 20080320160451.000000+060
Event Type: Informations
User:

Computer Name: V
Event Code: 4096
Message: The AntiVir service has been started successfully!

Record Number: 11911
Source Name: H+BEDV AntiVir
Time Written: 20080320160442.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: V
Event Code: 1517
Message: Windows a sauvegardé le Registre utilisateur V\M V alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.


Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

Record Number: 11910
Source Name: Userenv
Time Written: 20080320001758.000000+060
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Security event log

Computer Name: V
Event Code: 576
Message: Privilèges spéciaux assignés à la nouvelle session :

Utilisateur :

Domaine :

Id. de la session : (0x0,0x3E5)

Privilèges : SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege

Record Number: 458875
Source Name: Security
Time Written: 20090126083011.000000+060
Event Type: Succès de l'audit
User: AUTORITE NT\SERVICE LOCAL

Computer Name: V
Event Code: 528
Message: Ouverture de session réseau réussie :

Utilisateur : SERVICE LOCAL

Domaine : AUTORITE NT

Id. de la session : (0x0,0x3E5)

Type de session : 5

Processus de session : Advapi

Package d'authentification : Negotiate

Station de travail :

GUID d'ouv. de session : {00000000-0000-0000-0000-000000000000}

Record Number: 458874
Source Name: Security
Time Written: 20090126083011.000000+060
Event Type: Succès de l'audit
User: AUTORITE NT\SERVICE LOCAL

Computer Name: V
Event Code: 576
Message: Privilèges spéciaux assignés à la nouvelle session :

Utilisateur : SERVICE RÉSEAU

Domaine : AUTORITE NT

Id. de la session : (0x0,0x3E4)

Privilèges : SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege

Record Number: 458873
Source Name: Security
Time Written: 20090126083011.000000+060
Event Type: Succès de l'audit
User: AUTORITE NT\SERVICE RÉSEAU

Computer Name: V
Event Code: 528
Message: Ouverture de session réseau réussie :

Utilisateur : SERVICE RÉSEAU

Domaine : AUTORITE NT

Id. de la session : (0x0,0x3E4)

Type de session : 5

Processus de session : Advapi

Package d'authentification : Negotiate

Station de travail :

GUID d'ouv. de session : {00000000-0000-0000-0000-000000000000}

Record Number: 458872
Source Name: Security
Time Written: 20090126083011.000000+060
Event Type: Succès de l'audit
User: AUTORITE NT\SERVICE RÉSEAU

Computer Name: V
Event Code: 576
Message: Privilèges spéciaux assignés à la nouvelle session :

Utilisateur :

Domaine :

Id. de la session : (0x0,0x10E0C)

Privilèges : SeChangeNotifyPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege

Record Number: 458871
Source Name: Security
Time Written: 20090126083010.000000+060
Event Type: Succès de l'audit
User: VOILLET\M VOILLET

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=0a00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------

Répondre à tribord44

8

sKe69, le 30 jan 2009 à 15:49:57

Re,

le "log.txt" ( le 1er ) n'est pas complet ! Poste moi le en entier stp ... ^^

"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

9

tribord44, le 30 jan 2009 à 15:56:01

Excuse,

Logfile of random's system information tool 1.05 (written by random/random)
Run by M V at 2009-01-30 15:35:05
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 13 GB (11%) free of 117 GB
Total RAM: 2048 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:35:09, on 30/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\SECURE~1\secp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Documents and Settings\M VOILLET\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\M V.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [mobiswing] C:\PROGRA~1\SECURE~1\secp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24358 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\ParetoLogic Registration.job
C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
Secured_eMule Toolbar - C:\Program Files\Secured_eMule\tbSec1.dll [2008-06-09 1470488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-04 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-04 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - Secured_eMule Toolbar - C:\Program Files\Secured_eMule\tbSec1.dll [2008-06-09 1470488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CapFax"=C:\Program Files\Classic PhoneTools\CapFax.EXE [2001-12-10 20739]
"PCLEPCI"=C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE [2003-09-23 32768]
"adiras"=adiras.exe []
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-05-21 221184]
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2004-06-01 458752]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2004-06-01 217088]
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2005-02-01 180269]
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe [2004-03-10 406016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-04 136600]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"OpwareSE2"=C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [2003-05-08 49152]
"OPSE reminder"=C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe [2003-07-07 729088]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-07-17 266497]
"mobiswing"=C:\PROGRA~1\SECURE~1\secp.exe [2008-05-04 53760]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2004-06-01 196608]
"LDM"=\Program\ []
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-20 15360]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE [2005-01-19 405583]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Documents and Settings\M VOILLET\Menu Démarrer\Programmes\Démarrage
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-01-30 15:35:05 ----D---- C:\rsit
2009-01-30 14:49:36 ----D---- C:\Documents and Settings\M V\Application Data\WinRAR
2009-01-30 14:33:03 ----D---- C:\WINDOWS\ERUNT
2009-01-30 14:17:43 ----D---- C:\SDFix
2009-01-30 13:33:55 ----A---- C:\TB.txt
2009-01-30 13:32:59 ----D---- C:\ToolBar SD
2009-01-29 23:58:53 ----D---- C:\Program Files\Trend Micro
2009-01-29 18:06:35 ----D---- C:\WINDOWS\BDOSCAN8
2009-01-29 14:45:50 ----D---- C:\Documents and Settings\M V\Application Data\Windows Search
2009-01-29 11:33:09 ----D---- C:\Documents and Settings\M V\Application Data\Windows Desktop Search
2009-01-29 11:32:05 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2009-01-28 10:55:33 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-01-27 13:42:26 ----D---- C:\Documents and Settings\M V\Application Data\Malwarebytes
2009-01-27 13:42:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-27 13:42:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-26 20:48:51 ----D---- C:\Documents and Settings\M V\Application Data\DriverCure
2009-01-26 20:48:32 ----D---- C:\Documents and Settings\All Users\Application Data\DriverCure
2009-01-26 20:47:48 ----D---- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2009-01-07 18:39:54 ----A---- C:\WINDOWS\cPVAS.INI
2009-01-07 18:39:54 ----A---- C:\pvas.txt

======List of files/folders modified in the last 1 months======

2009-01-30 15:35:08 ----D---- C:\WINDOWS\Prefetch
2009-01-30 15:33:57 ----D---- C:\Program Files\Mozilla Firefox
2009-01-30 15:31:09 ----D---- C:\WINDOWS\Temp
2009-01-30 15:31:09 ----D---- C:\WINDOWS
2009-01-30 14:45:41 ----D---- C:\Documents and Settings\M V\Application Data\WTablet
2009-01-30 14:45:15 ----D---- C:\WINDOWS\system32\drivers
2009-01-30 14:45:14 ----D---- C:\Program Files\BufferZone
2009-01-30 13:36:14 ----AD---- C:\Program Files
2009-01-30 08:22:13 ----D---- C:\Program Files\Mozilla Thunderbird
2009-01-29 20:06:43 ----D---- C:\Program Files\BitTorrent Fastest Tool
2009-01-29 18:06:38 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-29 18:06:34 ----HD---- C:\WINDOWS\inf
2009-01-29 18:06:29 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-29 14:41:59 ----D---- C:\WINDOWS\system32
2009-01-29 14:38:59 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-29 14:38:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-01-29 14:34:27 ----D---- C:\WINDOWS\WinSxS
2009-01-29 14:33:45 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-29 14:10:17 ----D---- C:\Program Files\Internet Explorer
2009-01-29 14:09:40 ----D---- C:\WINDOWS\ie7updates
2009-01-29 11:35:12 ----ASD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-29 11:34:34 ----D---- C:\WINDOWS\system32\en-us
2009-01-29 11:34:34 ----D---- C:\Program Files\Windows Desktop Search
2009-01-29 11:33:02 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-29 11:32:52 ----D---- C:\WINDOWS\system32\fr-fr
2009-01-29 11:32:46 ----D---- C:\WINDOWS\system32\wbem
2009-01-29 07:25:26 ----D---- C:\Documents and Settings\M V\Application Data\XnView
2009-01-29 07:24:21 ----A---- C:\WINDOWS\clarity.ini
2009-01-28 20:51:29 ----D---- C:\Documents and Settings\M V\Application Data\LimeWire
2009-01-28 20:39:26 ----D---- C:\Program Files\eMule
2009-01-28 10:52:03 ----SHD---- C:\WINDOWS\Installer
2009-01-28 10:52:03 ----D---- C:\Config.Msi
2009-01-28 10:49:21 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-28 10:49:19 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-28 10:49:03 ----D---- C:\Program Files\VS Revo Group
2009-01-28 10:46:49 ----D---- C:\WINDOWS\Minidump
2009-01-27 20:22:57 ----D---- C:\Program Files\torrent_search
2009-01-26 20:52:28 ----D---- C:\Program Files\Fichiers communs
2009-01-26 20:52:18 ----SD---- C:\WINDOWS\Tasks
2009-01-26 20:39:38 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-26 20:39:29 ----RSD---- C:\WINDOWS\assembly
2009-01-26 20:39:28 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-01-26 20:31:48 ----SD---- C:\Documents and Settings\M V\Application Data\Microsoft
2009-01-26 08:48:11 ----RSD---- C:\WINDOWS\Fonts
2009-01-26 08:47:25 ----D---- C:\Program Files\MSECache
2009-01-18 10:26:09 ----A---- C:\WINDOWS\NeroDigital.ini
2009-01-14 16:21:30 ----D---- C:\Documents and Settings\All Users\Application Data\fssg
2009-01-07 18:41:56 ----A---- C:\mpeg.txt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2004-08-19 41600]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-11-25 75072]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-20 14848]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 Cnxtdiag;Cnxtdiag; C:\WINDOWS\System32\DRIVERS\cnxtdiag.sys [2001-07-03 17776]
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\fallback.sys [2001-07-12 310739]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\fsksnt.sys [2001-06-14 127405]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\k56nt.sys [2001-07-12 427167]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\faxnt.sys [2001-06-14 216987]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\tonesnt.sys [2001-06-14 56639]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\v124nt.sys [2001-07-12 534605]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 ASAPIW2k;ASAPIW2K; C:\WINDOWS\system32\drivers\ASAPIW2k.sys [2004-03-10 11264]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\basic2.sys [2001-07-12 77426]
R3 catchme;catchme; \??\C:\DOCUME~1\MV~1\LOCALS~1\Temp\catchme.sys []
R3 FETNDIS;Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-05-27 19968]
R3 MODEMCSA;Périphérique de filtrage de flux Unimodem; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 pfc;Padus ASPI Shell; \??\C:\WINDOWS\system32\drivers\pfc.sys []
R3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2004-05-21 471232]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\rksample.sys [2001-06-14 67622]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2003-04-24 5888]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 578368]
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Pilote miniport de contrôleur hôte amélioré USB 2.0 Microsoft; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
R3 usbscan;Pilote de scanneur USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-04 15104]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2002-11-13 10496]
R3 wacommousefilter;Wacom Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
R3 wacomvhid;Wacom Virtual Hid Driver; C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 12848]
R3 WacomVKHid;Virtual Keyboard Driver; C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-16 11440]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2001-07-12 584304]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2003-07-17 46167]
S3 61883;Pilote d'unité 61883; C:\WINDOWS\System32\DRIVERS\61883.sys [2004-08-04 48128]
S3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\System32\DRIVERS\adiusbaw.sys [2003-03-27 127145]
S3 Avc;Périphérique AVC; C:\WINDOWS\System32\DRIVERS\avc.sys [2004-08-04 38912]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 DCamUSBSvis;Oregon Scientific Stream Driver; C:\WINDOWS\system32\DRIVERS\svstream.sys [2001-07-18 91480]
S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\System32\DRIVERS\msdv.sys [2004-08-04 51328]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 scsiscan;Pilote de scanneur SCSI; C:\WINDOWS\System32\DRIVERS\scsiscan.sys [2001-08-17 10880]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 StillCam;Pilote d'appareil photo numérique série; C:\WINDOWS\System32\DRIVERS\serscan.sys [2001-08-23 6912]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbser;USB Serial emulation modem driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2004-08-04 25600]
S3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2002-10-24 6912]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2003-09-01 104064]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-24 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Avira AntiVir Personal – Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-23 68865]
R2 AntiVirService;Avira AntiVir Personal – Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-23 151297]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 BufferZoneSvc;BufferZone Service; C:\Program Files\BufferZone\CLNTSVC.EXE [2007-08-06 777712]
R2 BZDcomLaunch;BufferZone DCOM Helper; C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE [2007-08-06 61440]
R2 BZRpcSs;BufferZone RPC Helper; C:\Program Files\BufferZone\BZRPCSS.EXE [2007-08-06 57344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-04 152984]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 TabletServicePen;TabletServicePen; C:\WINDOWS\system32\Pen_Tablet.exe [2007-09-07 1373480]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-20 14336]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2006-09-10 72704]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-31 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-10 138168]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 918016]
S4 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Répondre à tribord44

10

sKe69, le 30 jan 2009 à 16:05:29

Bien ...

on continue :


1-Va dans panneau de config/ajout et suppression de prg .
Regarde dans la liste si tu trouves un prg comme : " CID Help ", "Circle Developement" ou
"Adverts" --->si ils s'y trouvent , supprime les .


2-Télécharge Lop S&D :
http://eric.71.mespages.googlepages.com/LopSD.exe

Déconnecte toi et ferme toutes tes applications en cours .

Double-clique sur sur l'.exe que tu viens de télécharger pour lancer l'installe .

Une fois l'installation faite, clique sur le raccourci pour lancer l'outil .

Là,laisses toi guider:
--->choisis l'option 1 (recherche) et valides.

(Tu ne fais pas l'option de nettoyage ( 2 ou 3) ).

Une fois le scan terminer ,le Bloc-Notes contenant le rapport va s'ouvrir.
Poste ce rapport dans ta prochaine réponse pour analyse .

Tuto : http://eric.71.mespages.googlepages.com/lop.sd.exe
"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

11

tribord44, le 30 jan 2009 à 16:24:30

Depuis qq temps dans la fenetre ajout/supp prog. je n'ai plus aucune liste qui s'affiche ,je passe donc par c.cleaner pour désinstaller; je n'ai rien trouver dans la liste de c.leaner qui y ressemble.

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(TM) XP 2600+ )
BIOS : Award Modular BIOS v6.0
USER : M V ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:114 Go (Free:13 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
G:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 30/01/2009|16:11 )

--------------------\\ Listing des dossiers dans APPLIC~1

[13/01/2004|18:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[08/03/2005|19:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
[30/12/2008|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[10/09/2006|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
[05/03/2006|21:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[03/11/2008|18:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[03/11/2008|18:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[01/05/2008|08:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[14/05/2008|16:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BufferZone
[26/12/2007|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[26/01/2009|20:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[26/01/2009|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DriverCure
[29/10/2008|18:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
[14/01/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[31/10/2008|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[10/01/2007|19:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[27/01/2009|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[12/04/2007|17:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[29/01/2009|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[24/01/2004|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[20/09/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[26/08/2005|16:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PACE Anti-Piracy
[21/12/2008|20:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PicturesToExe
[01/10/2004|16:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[20/03/2005|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[29/11/2006|20:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[28/01/2009|10:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[30/10/2006|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanAppDataDir
[08/07/2006|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanWizard
[13/04/2004|23:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[22/03/2005|02:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[02/10/2005|17:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[11/11/2007|12:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[15/06/2008|11:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[09/12/2007|21:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ZoomBrowser

[13/01/2004|18:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[11/02/2006|17:21] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[05/10/2005|19:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Macromedia
[30/12/2008|18:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[01/01/2006|18:06] C:\DOCUME~1\LOCALS~1\APPLIC~1\Mozilla
[15/01/2009|16:13] C:\DOCUME~1\LOCALS~1\APPLIC~1\WTablet

[08/03/2005|19:54] C:\DOCUME~1\MVOILL~1\APPLIC~1\ACD Systems
[30/12/2008|18:08] C:\DOCUME~1\MVOILL~1\APPLIC~1\Adobe
[10/05/2008|07:54] C:\DOCUME~1\MVOILL~1\APPLIC~1\AdobeUM
[18/12/2008|08:06] C:\DOCUME~1\MVOILL~1\APPLIC~1\Ahead
[23/01/2006|20:52] C:\DOCUME~1\MVOILL~1\APPLIC~1\Ambient Design
[10/03/2005|17:38] C:\DOCUME~1\MVOILL~1\APPLIC~1\Apple Computer
[30/12/2008|22:40] C:\DOCUME~1\MVOILL~1\APPLIC~1\Bamboo Scribe
[29/11/2008|16:11] C:\DOCUME~1\MVOILL~1\APPLIC~1\Canon
[20/11/2005|17:38] C:\DOCUME~1\MVOILL~1\APPLIC~1\Corel
[26/01/2009|20:49] C:\DOCUME~1\MVOILL~1\APPLIC~1\DriverCure
[30/12/2008|18:55] C:\DOCUME~1\MVOILL~1\APPLIC~1\Ergo
[28/12/2004|16:14] C:\DOCUME~1\MVOILL~1\APPLIC~1\FotoWire
[21/12/2005|19:09] C:\DOCUME~1\MVOILL~1\APPLIC~1\Google
[17/01/2004|16:41] C:\DOCUME~1\MVOILL~1\APPLIC~1\Help
[12/04/2004|16:16] C:\DOCUME~1\MVOILL~1\APPLIC~1\Hemera
[13/01/2004|18:24] C:\DOCUME~1\MVOILL~1\APPLIC~1\Identities
[28/01/2009|20:51] C:\DOCUME~1\MVOILL~1\APPLIC~1\LimeWire
[13/02/2008|09:03] C:\DOCUME~1\MVOILL~1\APPLIC~1\Macromedia
[27/01/2009|13:42] C:\DOCUME~1\MVOILL~1\APPLIC~1\Malwarebytes
[26/01/2009|20:31] C:\DOCUME~1\MVOILL~1\APPLIC~1\Microsoft
[14/01/2004|09:21] C:\DOCUME~1\MVOILL~1\APPLIC~1\Microsoft Web Folders
[28/08/2008|17:29] C:\DOCUME~1\MVOILL~1\APPLIC~1\Mozilla
[15/06/2008|14:48] C:\DOCUME~1\MVOILL~1\APPLIC~1\MSN6
[10/09/2006|13:05] C:\DOCUME~1\MVOILL~1\APPLIC~1\Opera
[26/08/2005|16:08] C:\DOCUME~1\MVOILL~1\APPLIC~1\PACE Anti-Piracy
[10/02/2007|17:38] C:\DOCUME~1\MVOILL~1\APPLIC~1\PicturesToExe
[28/03/2008|18:48] C:\DOCUME~1\MVOILL~1\APPLIC~1\Real
[25/03/2005|00:56] C:\DOCUME~1\MVOILL~1\APPLIC~1\Sail Simulator
[08/07/2006|11:00] C:\DOCUME~1\MVOILL~1\APPLIC~1\ScanSoft
[04/11/2005|18:59] C:\DOCUME~1\MVOILL~1\APPLIC~1\Sun
[14/01/2004|09:28] C:\DOCUME~1\MVOILL~1\APPLIC~1\Symantec
[28/10/2005|15:42] C:\DOCUME~1\MVOILL~1\APPLIC~1\Talkback
[09/06/2008|17:34] C:\DOCUME~1\MVOILL~1\APPLIC~1\TaoUSign
[27/11/2007|23:26] C:\DOCUME~1\MVOILL~1\APPLIC~1\Thinstall
[29/09/2007|09:13] C:\DOCUME~1\MVOILL~1\APPLIC~1\Thunderbird
[29/08/2007|18:15] C:\DOCUME~1\MVOILL~1\APPLIC~1\vlc
[29/01/2009|11:33] C:\DOCUME~1\MVOILL~1\APPLIC~1\Windows Desktop Search
[29/01/2009|14:45] C:\DOCUME~1\MVOILL~1\APPLIC~1\Windows Search
[30/01/2009|14:49] C:\DOCUME~1\MVOILL~1\APPLIC~1\WinRAR
[30/01/2009|14:45] C:\DOCUME~1\MVOILL~1\APPLIC~1\WTablet
[29/01/2009|07:25] C:\DOCUME~1\MVOILL~1\APPLIC~1\XnView
[09/12/2007|21:53] C:\DOCUME~1\MVOILL~1\APPLIC~1\ZoomBrowser EX

[13/01/2004|18:18] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[29/01/2009 18:00][--a------] C:\WINDOWS\tasks\ParetoLogic Registration.job
[26/01/2009 13:30][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[30/01/2009 15:58][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[30/01/2009 14:45][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/04/2003 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[10/10/2004|10:36] C:\Program Files\Active GIF Creator 2.18
[09/02/2006|18:15] C:\Program Files\Activision
[31/10/2008|13:11] C:\Program Files\Adobe
[25/05/2006|08:32] C:\Program Files\Ahead
[18/07/2008|14:22] C:\Program Files\ALCATEL PC Suite
[30/12/2008|20:00] C:\Program Files\Ambient Design
[13/01/2004|18:32] C:\Program Files\Analog Devices
[12/04/2004|16:16] C:\Program Files\Anuman Interactive
[03/11/2008|18:06] C:\Program Files\Apple Software Update
[17/07/2007|15:12] C:\Program Files\AvantGo Connect
[01/05/2008|08:56] C:\Program Files\Avira
[04/01/2007|20:07] C:\Program Files\AviSynth 2.5
[30/12/2008|22:38] C:\Program Files\Bamboo Scribe
[29/01/2009|20:06] C:\Program Files\BitTorrent Fastest Tool
[31/10/2008|13:06] C:\Program Files\Bonjour
[30/01/2009|14:45] C:\Program Files\BufferZone
[02/06/2008|22:04] C:\Program Files\Canon
[15/11/2008|15:52] C:\Program Files\Cartoonist
[31/10/2008|11:50] C:\Program Files\CCleaner
[23/01/2005|20:25] C:\Program Files\CDex
[06/09/2006|13:17] C:\Program Files\Classic PhoneTools
[27/02/2005|11:36] C:\Program Files\Common Files
[14/01/2004|09:15] C:\Program Files\CONEXANT
[26/11/2006|09:22] C:\Program Files\CyberLink
[16/03/2005|08:35] C:\Program Files\directx
[20/09/2004|08:55] C:\Program Files\Disney Interactive
[07/02/2007|11:40] C:\Program Files\DivX
[22/01/2004|13:56] C:\Program Files\Dreamworks
[10/02/2004|17:19] C:\Program Files\EBP
[28/01/2009|20:39] C:\Program Files\eMule
[13/11/2004|11:16] C:\Program Files\Extensis
[26/01/2009|20:52] C:\Program Files\Fichiers communs
[24/01/2005|18:24] C:\Program Files\Ganymede
[31/10/2008|11:36] C:\Program Files\Google
[03/11/2005|21:16] C:\Program Files\HbTools(2)
[02/10/2005|17:25] C:\Program Files\HighMAT CD Writing Wizard
[26/01/2009|20:39] C:\Program Files\InstallShield Installation Information
[21/01/2004|16:30] C:\Program Files\InterActual
[16/12/2004|20:09] C:\Program Files\InterMute
[29/01/2009|14:10] C:\Program Files\Internet Explorer
[04/12/2008|20:56] C:\Program Files\Java
[07/01/2005|22:29] C:\Program Files\JavaSoft
[30/09/2008|14:40] C:\Program Files\LimeWire
[28/12/2004|16:14] C:\Program Files\Logitech
[06/03/2005|15:16] C:\Program Files\MagicDVDRipper
[27/01/2009|13:42] C:\Program Files\Malwarebytes' Anti-Malware
[21/08/2008|21:57] C:\Program Files\Messenger
[09/12/2007|13:46] C:\Program Files\Microsoft ActiveSync
[09/12/2007|13:42] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/11/2007|18:41] C:\Program Files\microsoft frontpage
[09/12/2007|13:46] C:\Program Files\Microsoft Office
[30/12/2008|18:51] C:\Program Files\Microsoft SQL Server Compact Edition
[31/01/2004|11:24] C:\Program Files\Mindscape
[15/07/2008|17:29] C:\Program Files\Movie Maker
[30/01/2009|15:37] C:\Program Files\Mozilla Firefox
[30/01/2009|08:22] C:\Program Files\Mozilla Thunderbird
[30/12/2008|18:40] C:\Program Files\MSBuild
[26/01/2009|08:47] C:\Program Files\MSECache
[15/06/2008|14:48] C:\Program Files\MSN
[13/01/2004|18:15] C:\Program Files\MSN Gaming Zone
[15/07/2008|17:26] C:\Program Files\MSN Messenger
[18/11/2006|23:57] C:\Program Files\MSXML 4.0
[15/07/2008|17:29] C:\Program Files\NetMeeting
[25/08/2007|09:37] C:\Program Files\Neuf
[20/09/2008|16:04] C:\Program Files\NOS
[15/07/2008|17:29] C:\Program Files\Outlook Express
[30/12/2008|18:02] C:\Program Files\PenLauncher
[25/03/2005|07:04] C:\Program Files\pfoc
[28/10/2007|22:37] C:\Program Files\Picasa2
[10/10/2004|10:54] C:\Program Files\Pinnacle
[30/12/2004|18:01] C:\Program Files\Pinnacle Systems
[03/11/2008|18:07] C:\Program Files\QuickTime
[11/09/2004|08:50] C:\Program Files\QuickZip
[28/05/2004|11:21] C:\Program Files\R 8.86232638731599E-0003
[28/05/2004|11:21] C:\Program Files\RA 2.43921865476295E-0001
[01/02/2005|18:01] C:\Program Files\Real
[30/12/2008|18:35] C:\Program Files\Reference Assemblies
[17/12/2007|18:06] C:\Program Files\RegCleaner
[12/12/2004|15:35] C:\Program Files\RescuePRO
[16/03/2008|15:29] C:\Program Files\Ripp-it_AM
[28/09/2007|17:52] C:\Program Files\SAGEM
[08/07/2006|11:00] C:\Program Files\ScanSoft
[14/05/2008|16:15] C:\Program Files\Secured eMule
[28/05/2008|17:09] C:\Program Files\Secured_eMule
[13/01/2004|18:17] C:\Program Files\Services en ligne
[11/09/2005|17:07] C:\Program Files\Sierra On-Line
[28/01/2009|10:49] C:\Program Files\Spybot - Search & Destroy
[05/10/2008|08:07] C:\Program Files\Sun
[30/12/2008|17:16] C:\Program Files\Tablet
[27/01/2009|20:22] C:\Program Files\torrent_search
[29/01/2009|23:58] C:\Program Files\Trend Micro
[28/09/2004|19:17] C:\Program Files\Uninstall Information
[22/12/2007|16:47] C:\Program Files\Unlocker
[13/01/2004|18:36] C:\Program Files\VIA Technologies, Inc
[17/07/2007|15:08] C:\Program Files\ViaMichelin
[29/08/2007|18:13] C:\Program Files\VideoLAN
[07/03/2005|20:22] C:\Program Files\Viewpoint
[28/01/2009|10:49] C:\Program Files\VS Revo Group
[30/12/2008|18:52] C:\Program Files\Wacom
[15/11/2008|15:53] C:\Program Files\Web Photo Album
[29/01/2009|11:34] C:\Program Files\Windows Desktop Search
[15/06/2008|11:22] C:\Program Files\Windows Live
[10/12/2007|00:21] C:\Program Files\Windows Live Favorites
[10/12/2007|00:21] C:\Program Files\Windows Live Toolbar
[02/11/2006|17:25] C:\Program Files\Windows Media Connect 2
[15/07/2008|17:29] C:\Program Files\Windows Media Player
[15/07/2008|17:29] C:\Program Files\Windows NT
[04/09/2004|13:46] C:\Program Files\WindowsUpdate
[09/03/2005|21:26] C:\Program Files\WinRAR
[08/09/2004|16:17] C:\Program Files\WinZip
[11/09/2005|17:04] C:\Program Files\WON
[13/01/2004|18:18] C:\Program Files\xerox
[09/02/2007|14:46] C:\Program Files\XnView
[05/10/2008|14:08] C:\Program Files\XviD

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[31/10/2008|13:06] C:\Program Files\Fichiers communs\Adobe
[30/12/2008|18:04] C:\Program Files\Fichiers communs\Adobe AIR
[10/09/2006|12:06] C:\Program Files\Fichiers communs\Adobe Systems Shared
[25/05/2006|08:29] C:\Program Files\Fichiers communs\Ahead
[03/11/2008|18:07] C:\Program Files\Fichiers communs\Apple
[30/03/2007|16:07] C:\Program Files\Fichiers communs\Canon
[09/12/2007|13:46] C:\Program Files\Fichiers communs\Designer
[28/12/2004|16:14] C:\Program Files\Fichiers communs\FotoWire
[12/03/2005|14:36] C:\Program Files\Fichiers communs\InstallShield
[01/11/2005|17:13] C:\Program Files\Fichiers communs\Java
[28/12/2004|16:12] C:\Program Files\Fichiers communs\Logitech
[31/10/2008|12:44] C:\Program Files\Fichiers communs\Macrovision Shared
[26/01/2009|20:39] C:\Program Files\Fichiers communs\Microsoft Shared
[13/01/2004|18:16] C:\Program Files\Fichiers communs\MSSoap
[01/03/2006|18:56] C:\Program Files\Fichiers communs\Nero
[13/01/2004|18:06] C:\Program Files\Fichiers communs\ODBC
[26/08/2005|16:07] C:\Program Files\Fichiers communs\PACE Anti-Piracy
[01/04/2008|17:29] C:\Program Files\Fichiers communs\Real
[26/12/2007|21:33] C:\Program Files\Fichiers communs\ScanSoft Shared
[13/01/2004|18:16] C:\Program Files\Fichiers communs\Services
[13/01/2004|18:06] C:\Program Files\Fichiers communs\SpeechEngines
[09/04/2005|17:43] C:\Program Files\Fichiers communs\Stentec Shared
[15/07/2008|17:29] C:\Program Files\Fichiers communs\System
[03/04/2005|14:21] C:\Program Files\Fichiers communs\Vbox
[15/06/2008|11:23] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[01/04/2008|17:29] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 48 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\Program Files\BitTorrent Fastest Tool
C:\Program Files\BitTorrent Fastest Tool\3wPlayer-2.0.0.0-setup.exe
C:\Program Files\BitTorrent Fastest Tool\INSTALL.LOG
C:\Program Files\BitTorrent Fastest Tool\Multi_Media1808.exe

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 16:14:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\MVOILL~1\Application Data\Microsoft\Office\R‚cents\Auto FX Software DreamSuite Gel Series 1.18 CRACK.lnk
C:\DOCUME~1\MVOILL~1\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar


[F:2][D:1]-> C:\DOCUME~1\MVL~1\LOCALS~1\Temp
[F:1][D:0]-> C:\DOCUME~1\MVL~1\Cookies
[F:2][D:0]-> C:\DOCUME~1\MVL~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 30/01/2009|16:17 - Option : [1]

--------------------\\ Fin du rapport a 16:17:24

Répondre à tribord44

12

sKe69, le 30 jan 2009 à 18:05:46

Bien ...

tu me fera penser avant qu'on termine à régké ce petit prb "d' ajout et suppression de prg "...



la suite :


1- ! Déconnecte toi et ferme toutes tes applications en cours !

Relance Lop S&D ,

--->choisis cette fois l'option 2 ( nettoyage ) et valide ...

->ne touche à rien pendant que l'outil travail .


Une fois le scan terminer ,le Bloc-Notes contenant le rapport va s'ouvrir.
Poste ce rapport dans ta prochaine pour analyse puis fait la suite ...

================

2-Télécharge ComboFix (par sUBs) sur ton Bureau (et pas ailleurs !):

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


--------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
!! Déconnecte toi,ferme tes applications en cours ( ainsi que ton navigateur ) et DESACTIVE TOUTES TES DEFENSES (anti-virus, guarde anti spy-ware, pare-feu) le temps de la manipe :
en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
--->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
Tuto ( aide ) ici : http://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Note : pour XP, bien installer la Console de Récupération de Windows comme il est indiqué dans le tuto ci-dessus ...
---------------------------------------------------------------------------------------------------------------------------------

Ensuite :
double-clique sur l'icône "combofix.exe" pour lancer l'outil .

Appuie sur la touche Y (Yes) pour démarrer le scan .

Notes importantes :
-> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
-> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisse le faire .
-> Si l'outil t'anonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarer votre machine", tu acceptes ...
-> si un message d'erreur windows apparait à un momment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

Le rapport sera crée ici : C:\Combofix.txt

Réactive bien tes défenses .


Poste le rapport Combofix pour analyse ...
"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

13

tribord44, le 30 jan 2009 à 18:36:31

Voici le rapport de Lop S&D
je m'occupe maintenant de combofix

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(TM) XP 2600+ )
BIOS : Award Modular BIOS v6.0
USER : M V ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:114 Go (Free:12 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
G:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 30/01/2009|18:24 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\BitTorrent Fastest Tool\3wPlayer-2.0.0.0-setup.exe
Supprime! - C:\Program Files\BitTorrent Fastest Tool\INSTALL.LOG
Supprime! - C:\Program Files\BitTorrent Fastest Tool\Multi_Media1808.exe
Supprime! - C:\Program Files\BitTorrent Fastest Tool
-
[ Fichier Hosts ] .. Restaure!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[13/01/2004|18:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[08/03/2005|19:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
[30/12/2008|18:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[10/09/2006|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
[05/03/2006|21:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[03/11/2008|18:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[03/11/2008|18:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[01/05/2008|08:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[14/05/2008|16:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BufferZone
[26/12/2007|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[26/01/2009|20:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[26/01/2009|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DriverCure
[29/10/2008|18:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
[14/01/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[31/10/2008|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[10/01/2007|19:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[27/01/2009|13:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[12/04/2007|17:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[29/01/2009|11:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[24/01/2004|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
[20/09/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[26/08/2005|16:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PACE Anti-Piracy
[21/12/2008|20:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PicturesToExe
[01/10/2004|16:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[20/03/2005|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[29/11/2006|20:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[28/01/2009|10:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[30/10/2006|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanAppDataDir
[08/07/2006|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanWizard
[13/04/2004|23:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/10/2005|17:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[11/11/2007|12:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[15/06/2008|11:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[09/12/2007|21:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ZoomBrowser

[13/01/2004|18:18] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[11/02/2006|17:21] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[05/10/2005|19:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Macromedia
[30/12/2008|18:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[01/01/2006|18:06] C:\DOCUME~1\LOCALS~1\APPLIC~1\Mozilla
[15/01/2009|16:13] C:\DOCUME~1\LOCALS~1\APPLIC~1\WTablet

[08/03/2005|19:54] C:\DOCUME~1\ML~1\APPLIC~1\ACD Systems
[30/12/2008|18:08] C:\DOCUME~1\M~1\APPLIC~1\Adobe
[10/05/2008|07:54] C:\DOCUME~1\ML~1\APPLIC~1\AdobeUM
[18/12/2008|08:06] C:\DOCUME~1\ML~1\APPLIC~1\Ahead
[23/01/2006|20:52] C:\DOCUME~1\ML~1\APPLIC~1\Ambient Design
[10/03/2005|17:38] C:\DOCUME~1\M~1\APPLIC~1\Apple Computer
[30/12/2008|22:40] C:\DOCUME~1\M~1\APPLIC~1\Bamboo Scribe
[29/11/2008|16:11] C:\DOCUME~1\ML~1\APPLIC~1\Canon
[20/11/2005|17:38] C:\DOCUME~1\ML~1\APPLIC~1\Corel
[26/01/2009|20:49] C:\DOCUME~1\ML~1\APPLIC~1\DriverCure
[30/12/2008|18:55] C:\DOCUME~1\M~1\APPLIC~1\Ergo
[28/12/2004|16:14] C:\DOCUME~1\ML~1\APPLIC~1\FotoWire
[21/12/2005|19:09] C:\DOCUME~1\ML~1\APPLIC~1\Google
[17/01/2004|16:41] C:\DOCUME~1\ML~1\APPLIC~1\Help
[12/04/2004|16:16] C:\DOCUME~1\M~1\APPLIC~1\Hemera
[13/01/2004|18:24] C:\DOCUME~1\M~1\APPLIC~1\Identities
[28/01/2009|20:51] C:\DOCUME~1\ML~1\APPLIC~1\LimeWire
[13/02/2008|09:03] C:\DOCUME~1\M~1\APPLIC~1\Macromedia
[27/01/2009|13:42] C:\DOCUME~1\M~1\APPLIC~1\Malwarebytes
[26/01/2009|20:31] C:\DOCUME~1\ML~1\APPLIC~1\Microsoft
[14/01/2004|09:21] C:\DOCUME~1\ML~1\APPLIC~1\Microsoft Web Folders
[28/08/2008|17:29] C:\DOCUME~1\ML~1\APPLIC~1\Mozilla
[15/06/2008|14:48] C:\DOCUME~1\MO~1\APPLIC~1\MSN6
[10/09/2006|13:05] C:\DOCUME~1\ML~1\APPLIC~1\Opera
[26/08/2005|16:08] C:\DOCUME~1\ML~1\APPLIC~1\PACE Anti-Piracy
[10/02/2007|17:38] C:\DOCUME~1\M~1\APPLIC~1\PicturesToExe
[28/03/2008|18:48] C:\DOCUME~1\ML~1\APPLIC~1\Real
[25/03/2005|00:56] C:\DOCUME~1\ML~1\APPLIC~1\Sail Simulator
[08/07/2006|11:00] C:\DOCUME~1\ML~1\APPLIC~1\ScanSoft
[04/11/2005|18:59] C:\DOCUME~1\M~1\APPLIC~1\Sun
[14/01/2004|09:28] C:\DOCUME~1\M~1\APPLIC~1\Symantec
[28/10/2005|15:42] C:\DOCUME~1\M~1\APPLIC~1\Talkback
[09/06/2008|17:34] C:\DOCUME~1\ML~1\APPLIC~1\TaoUSign
[27/11/2007|23:26] C:\DOCUME~1\ML~1\APPLIC~1\Thinstall
[29/09/2007|09:13] C:\DOCUME~1\ML~1\APPLIC~1\Thunderbird
[29/08/2007|18:15] C:\DOCUME~1\M~1\APPLIC~1\vlc
[29/01/2009|11:33] C:\DOCUME~1\M~1\APPLIC~1\Windows Desktop Search
[29/01/2009|14:45] C:\DOCUME~1\ML~1\APPLIC~1\Windows Search
[30/01/2009|14:49] C:\DOCUME~1\M~1\APPLIC~1\WinRAR
[30/01/2009|14:45] C:\DOCUME~1\M~1\APPLIC~1\WTablet
[29/01/2009|07:25] C:\DOCUME~1\MO1\APPLIC~1\XnView
[09/12/2007|21:53] C:\DOCUME~1\M~1\APPLIC~1\ZoomBrowser EX

[13/01/2004|18:18] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[30/01/2009 18:00][--a------] C:\WINDOWS\tasks\ParetoLogic Registration.job
[26/01/2009 13:30][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[30/01/2009 17:58][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[30/01/2009 14:45][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/04/2003 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[10/10/2004|10:36] C:\Program Files\Active GIF Creator 2.18
[09/02/2006|18:15] C:\Program Files\Activision
[31/10/2008|13:11] C:\Program Files\Adobe
[25/05/2006|08:32] C:\Program Files\Ahead
[18/07/2008|14:22] C:\Program Files\ALCATEL PC Suite
[30/12/2008|20:00] C:\Program Files\Ambient Design
[13/01/2004|18:32] C:\Program Files\Analog Devices
[12/04/2004|16:16] C:\Program Files\Anuman Interactive
[03/11/2008|18:06] C:\Program Files\Apple Software Update
[17/07/2007|15:12] C:\Program Files\AvantGo Connect
[01/05/2008|08:56] C:\Program Files\Avira
[04/01/2007|20:07] C:\Program Files\AviSynth 2.5
[30/12/2008|22:38] C:\Program Files\Bamboo Scribe
[31/10/2008|13:06] C:\Program Files\Bonjour
[30/01/2009|14:45] C:\Program Files\BufferZone
[02/06/2008|22:04] C:\Program Files\Canon
[15/11/2008|15:52] C:\Program Files\Cartoonist
[31/10/2008|11:50] C:\Program Files\CCleaner
[23/01/2005|20:25] C:\Program Files\CDex
[06/09/2006|13:17] C:\Program Files\Classic PhoneTools
[27/02/2005|11:36] C:\Program Files\Common Files
[14/01/2004|09:15] C:\Program Files\CONEXANT
[26/11/2006|09:22] C:\Program Files\CyberLink
[16/03/2005|08:35] C:\Program Files\directx
[20/09/2004|08:55] C:\Program Files\Disney Interactive
[07/02/2007|11:40] C:\Program Files\DivX
[22/01/2004|13:56] C:\Program Files\Dreamworks
[10/02/2004|17:19] C:\Program Files\EBP
[28/01/2009|20:39] C:\Program Files\eMule
[13/11/2004|11:16] C:\Program Files\Extensis
[26/01/2009|20:52] C:\Program Files\Fichiers communs
[24/01/2005|18:24] C:\Program Files\Ganymede
[31/10/2008|11:36] C:\Program Files\Google
[03/11/2005|21:16] C:\Program Files\HbTools(2)
[02/10/2005|17:25] C:\Program Files\HighMAT CD Writing Wizard
[26/01/2009|20:39] C:\Program Files\InstallShield Installation Information
[21/01/2004|16:30] C:\Program Files\InterActual
[16/12/2004|20:09] C:\Program Files\InterMute
[29/01/2009|14:10] C:\Program Files\Internet Explorer
[04/12/2008|20:56] C:\Program Files\Java
[07/01/2005|22:29] C:\Program Files\JavaSoft
[30/09/2008|14:40] C:\Program Files\LimeWire
[28/12/2004|16:14] C:\Program Files\Logitech
[06/03/2005|15:16] C:\Program Files\MagicDVDRipper
[27/01/2009|13:42] C:\Program Files\Malwarebytes' Anti-Malware
[21/08/2008|21:57] C:\Program Files\Messenger
[09/12/2007|13:46] C:\Program Files\Microsoft ActiveSync
[09/12/2007|13:42] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/11/2007|18:41] C:\Program Files\microsoft frontpage
[09/12/2007|13:46] C:\Program Files\Microsoft Office
[30/12/2008|18:51] C:\Program Files\Microsoft SQL Server Compact Edition
[31/01/2004|11:24] C:\Program Files\Mindscape
[15/07/2008|17:29] C:\Program Files\Movie Maker
[30/01/2009|16:18] C:\Program Files\Mozilla Firefox
[30/01/2009|17:18] C:\Program Files\Mozilla Thunderbird
[30/12/2008|18:40] C:\Program Files\MSBuild
[26/01/2009|08:47] C:\Program Files\MSECache
[15/06/2008|14:48] C:\Program Files\MSN
[13/01/2004|18:15] C:\Program Files\MSN Gaming Zone
[15/07/2008|17:26] C:\Program Files\MSN Messenger
[18/11/2006|23:57] C:\Program Files\MSXML 4.0
[15/07/2008|17:29] C:\Program Files\NetMeeting
[25/08/2007|09:37] C:\Program Files\Neuf
[20/09/2008|16:04] C:\Program Files\NOS
[15/07/2008|17:29] C:\Program Files\Outlook Express
[30/12/2008|18:02] C:\Program Files\PenLauncher
[25/03/2005|07:04] C:\Program Files\pfoc
[28/10/2007|22:37] C:\Program Files\Picasa2
[10/10/2004|10:54] C:\Program Files\Pinnacle
[30/12/2004|18:01] C:\Program Files\Pinnacle Systems
[03/11/2008|18:07] C:\Program Files\QuickTime
[11/09/2004|08:50] C:\Program Files\QuickZip
[28/05/2004|11:21] C:\Program Files\R 8.86232638731599E-0003
[28/05/2004|11:21] C:\Program Files\RA 2.43921865476295E-0001
[01/02/2005|18:01] C:\Program Files\Real
[30/12/2008|18:35] C:\Program Files\Reference Assemblies
[17/12/2007|18:06] C:\Program Files\RegCleaner
[12/12/2004|15:35] C:\Program Files\RescuePRO
[16/03/2008|15:29] C:\Program Files\Ripp-it_AM
[28/09/2007|17:52] C:\Program Files\SAGEM
[08/07/2006|11:00] C:\Program Files\ScanSoft
[14/05/2008|16:15] C:\Program Files\Secured eMule
[28/05/2008|17:09] C:\Program Files\Secured_eMule
[13/01/2004|18:17] C:\Program Files\Services en ligne
[11/09/2005|17:07] C:\Program Files\Sierra On-Line
[28/01/2009|10:49] C:\Program Files\Spybot - Search & Destroy
[05/10/2008|08:07] C:\Program Files\Sun
[30/12/2008|17:16] C:\Program Files\Tablet
[27/01/2009|20:22] C:\Program Files\torrent_search
[29/01/2009|23:58] C:\Program Files\Trend Micro
[28/09/2004|19:17] C:\Program Files\Uninstall Information
[22/12/2007|16:47] C:\Program Files\Unlocker
[13/01/2004|18:36] C:\Program Files\VIA Technologies, Inc
[17/07/2007|15:08] C:\Program Files\ViaMichelin
[29/08/2007|18:13] C:\Program Files\VideoLAN
[28/01/2009|10:49] C:\Program Files\VS Revo Group
[30/12/2008|18:52] C:\Program Files\Wacom
[15/11/2008|15:53] C:\Program Files\Web Photo Album
[29/01/2009|11:34] C:\Program Files\Windows Desktop Search
[15/06/2008|11:22] C:\Program Files\Windows Live
[10/12/2007|00:21] C:\Program Files\Windows Live Favorites
[10/12/2007|00:21] C:\Program Files\Windows Live Toolbar
[02/11/2006|17:25] C:\Program Files\Windows Media Connect 2
[15/07/2008|17:29] C:\Program Files\Windows Media Player
[15/07/2008|17:29] C:\Program Files\Windows NT
[04/09/2004|13:46] C:\Program Files\WindowsUpdate
[09/03/2005|21:26] C:\Program Files\WinRAR
[08/09/2004|16:17] C:\Program Files\WinZip
[11/09/2005|17:04] C:\Program Files\WON
[13/01/2004|18:18] C:\Program Files\xerox
[09/02/2007|14:46] C:\Program Files\XnView
[05/10/2008|14:08] C:\Program Files\XviD

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[31/10/2008|13:06] C:\Program Files\Fichiers communs\Adobe
[30/12/2008|18:04] C:\Program Files\Fichiers communs\Adobe AIR
[10/09/2006|12:06] C:\Program Files\Fichiers communs\Adobe Systems Shared
[25/05/2006|08:29] C:\Program Files\Fichiers communs\Ahead
[03/11/2008|18:07] C:\Program Files\Fichiers communs\Apple
[30/03/2007|16:07] C:\Program Files\Fichiers communs\Canon
[09/12/2007|13:46] C:\Program Files\Fichiers communs\Designer
[28/12/2004|16:14] C:\Program Files\Fichiers communs\FotoWire
[12/03/2005|14:36] C:\Program Files\Fichiers communs\InstallShield
[01/11/2005|17:13] C:\Program Files\Fichiers communs\Java
[28/12/2004|16:12] C:\Program Files\Fichiers communs\Logitech
[31/10/2008|12:44] C:\Program Files\Fichiers communs\Macrovision Shared
[26/01/2009|20:39] C:\Program Files\Fichiers communs\Microsoft Shared
[13/01/2004|18:16] C:\Program Files\Fichiers communs\MSSoap
[01/03/2006|18:56] C:\Program Files\Fichiers communs\Nero
[13/01/2004|18:06] C:\Program Files\Fichiers communs\ODBC
[26/08/2005|16:07] C:\Program Files\Fichiers communs\PACE Anti-Piracy
[01/04/2008|17:29] C:\Program Files\Fichiers communs\Real
[26/12/2007|21:33] C:\Program Files\Fichiers communs\ScanSoft Shared
[13/01/2004|18:16] C:\Program Files\Fichiers communs\Services
[13/01/2004|18:06] C:\Program Files\Fichiers communs\SpeechEngines
[09/04/2005|17:43] C:\Program Files\Fichiers communs\Stentec Shared
[15/07/2008|17:29] C:\Program Files\Fichiers communs\System
[03/04/2005|14:21] C:\Program Files\Fichiers communs\Vbox
[15/06/2008|11:23] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[01/04/2008|17:29] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 48 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 18:26:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\M~1\Application Data\Microsoft\Office\R‚cents\Auto FX Software DreamSuite Gel Series 1.18 CRACK.lnk
C:\DOCUME~1\ML~1\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar


[F:2][D:1]-> C:\DOCUME~1\ML~1\LOCALS~1\Temp
[F:1][D:0]-> C:\DOCUME~1\ML~1\Cookies
[F:2][D:0]-> C:\DOCUME~1\ML~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 30/01/2009|16:17 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 30/01/2009|18:29 - Option : [2]

--------------------\\ Fin du rapport a 18:29:20

Répondre à tribord44

14

sKe69, le 30 jan 2009 à 18:38:42

Impec ...

la suite donc ... ^^


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

15

tribord44, le 30 jan 2009 à 19:05:25

Voici le rapport de combofix

ComboFix 09-01-21.04 - M V 2009-01-30 18:50:30.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.2048.1555 [GMT 1:00]
Lancé depuis: c:\documents and settings\M VT\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
- Mode FONCTIONNALITES REDUITES -
.
[color=purple]Les fichiers ci-dessous ont été désactivés pendant l'exécution:/color
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll


(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\mdm.exe
c:\windows\system32\window.dll

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-30 ))))))))))))))))))))))))))))))))))))
.

2009-01-30 16:11 . 2009-01-30 18:29 <REP> d-------- C:\Lop SD
2009-01-30 15:35 . 2009-01-30 15:35 <REP> d-------- C:\rsit
2009-01-30 14:33 . 2009-01-30 14:33 <REP> d-------- c:\windows\ERUNT
2009-01-30 14:17 . 2009-01-30 14:56 <REP> d-------- C:\SDFix
2009-01-30 13:32 . 2009-01-30 13:38 <REP> d-------- C:\ToolBar SD
2009-01-29 23:58 . 2009-01-29 23:58 <REP> d-------- c:\program files\Trend Micro
2009-01-29 18:06 . 2009-01-29 18:22 <REP> d-------- c:\windows\BDOSCAN8
2009-01-29 14:45 . 2009-01-29 14:45 <REP> d-------- c:\documents and settings\M V\Application Data\Windows Search
2009-01-29 11:33 . 2009-01-29 11:33 <REP> d-------- c:\documents and settings\M V\Application Data\Windows Desktop Search
2009-01-27 13:42 . 2009-01-27 13:42 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-27 13:42 . 2009-01-27 13:42 <REP> d-------- c:\documents and settings\M V\Application Data\Malwarebytes
2009-01-27 13:42 . 2009-01-27 13:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-27 13:42 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-27 13:42 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-26 20:48 . 2009-01-26 20:49 <REP> d-------- c:\documents and settings\M V\Application Data\DriverCure
2009-01-26 20:48 . 2009-01-26 20:52 <REP> d-------- c:\documents and settings\All Users\Application Data\DriverCure
2009-01-26 20:47 . 2009-01-26 20:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-01-15 16:13 . 2009-01-15 16:13 <REP> d-------- c:\documents and settings\LocalService\Application Data\WTablet
2009-01-07 18:39 . 2009-01-07 18:41 887 --a------ c:\windows\cPVAS.INI
2008-12-30 22:40 . 2008-12-30 22:40 <REP> d-------- c:\documents and settings\M V\Application Data\Bamboo Scribe
2008-12-30 22:38 . 2008-12-30 22:38 <REP> d-------- c:\program files\Bamboo Scribe
2008-12-30 20:00 . 2008-12-30 20:00 <REP> d-------- c:\program files\Ambient Design
2008-12-30 18:55 . 2008-12-30 18:55 <REP> d-------- c:\documents and settings\M V\Application Data\Ergo
2008-12-30 18:52 . 2008-12-30 18:52 <REP> d-------- c:\program files\Wacom
2008-12-30 18:51 . 2008-12-30 18:51 <REP> d-------- c:\program files\Microsoft SQL Server Compact Edition
2008-12-30 18:44 . 2009-01-29 11:34 <REP> d-------- c:\program files\Windows Desktop Search
2008-12-30 18:43 . 2008-03-07 17:56 192,000 -----c--- c:\windows\system32\dllcache\offfilt.dll
2008-12-30 18:43 . 2008-03-07 17:56 98,304 -----c--- c:\windows\system32\dllcache\nlhtml.dll
2008-12-30 18:40 . 2008-12-30 18:40 <REP> d-------- c:\program files\MSBuild
2008-12-30 18:36 . 2008-12-30 18:36 <REP> d-------- c:\windows\system32\XPSViewer
2008-12-30 18:35 . 2008-12-30 18:35 <REP> d-------- c:\program files\Reference Assemblies
2008-12-30 18:35 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2008-12-30 18:04 . 2008-12-30 18:04 <REP> d-------- c:\program files\Fichiers communs\Adobe AIR
2008-12-30 18:02 . 2008-12-30 18:02 <REP> d-------- c:\program files\PenLauncher
2008-12-30 18:02 . 2008-06-04 19:14 319 --a------ c:\windows\system32\pentabletdefaults.xml
2008-12-30 17:17 . 2009-01-30 14:45 <REP> d-------- c:\documents and settings\M VT\Application Data\WTablet
2008-12-30 17:15 . 2008-12-30 17:16 <REP> d-------- c:\program files\Tablet
2008-12-30 17:14 . 2001-08-23 17:04 12,288 --a------ c:\windows\system32\drivers\mouhid.sys
2008-12-30 17:14 . 2001-08-23 17:04 12,288 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-12-30 17:14 . 2001-08-17 22:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-12-30 17:14 . 2001-08-17 22:02 9,600 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-12-21 20:53 . 2008-12-21 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\PicturesToExe
2008-12-04 20:56 . 2008-12-04 20:56 410,984 --a------ c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 17:47 --------- d-----w c:\program files\BufferZone
2009-01-30 16:18 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-29 06:25 --------- d-----w c:\documents and settings\M V\Application Data\XnView
2009-01-28 19:51 --------- d-----w c:\documents and settings\M V\Application Data\LimeWire
2009-01-28 19:39 --------- d-----w c:\program files\eMule
2009-01-28 09:49 --------- d-----w c:\program files\VS Revo Group
2009-01-28 09:49 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-28 09:49 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-27 19:22 --------- d-----w c:\program files\torrent_search
2009-01-26 19:39 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-26 07:47 --------- d-----w c:\program files\MSECache
2009-01-14 15:21 --------- d-----w c:\documents and settings\All Users\Application Data\fssg
2008-12-18 07:06 --------- d-----w c:\documents and settings\M V\Application Data\Ahead
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-04 19:56 --------- d-----w c:\program files\Java
2008-11-29 15:11 --------- d-----w c:\documents and settings\M V\Application Data\Canon
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-03-10 16:53 73,944 -c--a-w c:\documents and settings\M V\Application Data\GDIPFONTCACHEV1.DAT
2002-06-26 12:05 8,043,520 ----a-w c:\program files\DS.exe
2008-03-16 13:56 11,690 -csha-w c:\windows\system32\KGyGaAvL.sys
2008-06-30 19:18 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008063020080701\index.dat
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}"= "c:\program files\Secured_eMule\tbSec1.dll" [2008-06-09 1470488]

[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
2008-06-09 16:28 1470488 --a------ c:\program files\Secured_eMule\tbSec1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}"= "c:\program files\Secured_eMule\tbSec1.dll" [2008-06-09 1470488]

[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{1D1B60FD-B21F-4B9A-8A5F-64E8544828D7}"= "c:\program files\Secured_eMule\tbSec1.dll" [2008-06-09 1470488]

[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzBufferZoneOverlay]
@="{37ADBD0B-11EC-4A2C-9F93-5C3ACC7994DF}"
[HKEY_CLASSES_ROOT\CLSID\{37ADBD0B-11EC-4A2C-9F93-5C3ACC7994DF}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzConfidentialOverlay]
@="{F594B094-8768-4632-8143-12852EBBD688}"
[HKEY_CLASSES_ROOT\CLSID\{F594B094-8768-4632-8143-12852EBBD688}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzForbiddenOverlay]
@="{F1A1DA12-E651-4AD0-A1A0-6214546B2F9D}"
[HKEY_CLASSES_ROOT\CLSID\{F1A1DA12-E651-4AD0-A1A0-6214546B2F9D}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzUnknownOverlay]
@="{E4FC4B31-8A4F-45E6-BDAC-28F612371FE3}"
[HKEY_CLASSES_ROOT\CLSID\{E4FC4B31-8A4F-45E6-BDAC-28F612371FE3}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program\" [X]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-20 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 405583]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CapFax"="c:\program files\Classic PhoneTools\CapFax.EXE" [2001-12-10 20739]
"PCLEPCI"="c:\progra~1\PINNAC~1\PPE\PPE.EXE" [2003-09-23 32768]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-05-21 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-02-01 180269]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-04 136600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"OPSE reminder"="c:\program files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" [2003-07-07 729088]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-20 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]

c:\documents and settings\M VOILLET\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-04-13 110592]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2004-12-14 962663]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-03-08 450560]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
"VIDC.MJPG"= mtkjpeg.dll
"VIDC.PIM1"= pclepim1.dll
"vidc.ptev"= ptevideo.dll
"MSACM.CEGSM"= mobilev.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R0 REDLIGHT;REDLIGHT;c:\windows\system32\drivers\redlight.sys [2007-08-06 2233728]
R4 BufferZoneSvc;BufferZone Service;c:\program files\BufferZone\ClntSvc.exe [2007-08-06 777712]
R4 BZDcomLaunch;BufferZone DCOM Helper;c:\program files\BufferZone\BZDcomLaunch.exe [2007-08-06 61440]
R4 BZRpcSs;BufferZone RPC Helper;c:\program files\BufferZone\BZRpcSs.exe [2007-08-06 57344]
R4 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-30 1373480]
S3 DCamUSBSvis;Oregon Scientific Stream Driver;c:\windows\system32\drivers\SvStream.sys [2006-07-13 91480]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-20 33752]
S3 scsiscan;Pilote de scanneur SCSI;c:\windows\system32\drivers\scsiscan.sys [2005-12-16 10880]

--- Autres Services/Pilotes en mémoire ---

*Deregistered* - mchInjDrv
.
Contenu du dossier 'Tâches planifiées'

2009-01-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-01-30 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Fichiers communs\ParetoLogic\UUS2\UUS.dll []

2009-01-30 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -

HKLM-Run-adiras - adiras.exe


.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = about:NavigationFailure
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Annoter avec Bamboo Link - c:\program files\Wacom\Bamboo Link\AnnotateWithErgo.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: View EXIF - c:\viewexif\EXIF.htm
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: msn.com\fr
TCP: {EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4} = 208.67.220.220,208.67.222.222
TCP: {F3CED271-D5C7-432C-BF6E-B7E600EEBA78} = 208.67.220.220,208.67.222.222
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\M VOILLET\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 18:50:42
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...


**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_USERS\S-1-5-21-448539723-823518204-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{234399AF-0FDB-9235-B859A4E3AC2ADE1B}\{19B8A235-5775-8B53-4D38DBAF8988D503}\{76727453-9A12-1EF5-D0F3E23CAC7A8CDF}*]
"KBHFJ3LOVGGHQNXKY4VGT5W5XA1"=hex:01,00,01,00,00,00,00,00,cd,90,7b,1c,04,10,89,
b4,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40886FA5-87BC-FDA7-0C1FAC01C243999B}\{19E564B2-522B-7AA8-1ACCCD0705265332}\{1F2DE655-6E2E-2DD5-8638E8D01A513D14}*]
"YVDOYALJ4U2TQACPBJNJTEIBQG1"=hex:01,00,01,00,00,00,00,00,cd,90,7b,1c,04,10,89,
b4,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,b3,23,7f,03,c6,
d8,aa,aa,2e,e8,e1,00,eb,16,2b,de,04,f7,98,0f,fa,a4,41,ca,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,96,3d,a8,da,
1c,2b,79,46,47,15,b0,92,4b,c7,ef,cd,8c,79,5e,15,ac,27,e6,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,37,24,cf,fd,14,
32,1d,8f,7a,45,05,fd,91,e8,6f,31,7d,28,ed,99,aa,c4,21,49,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,b2,92,24,18,8b,
e3,d6,95,6b,65,49,6a,7e,99,74,f7,c8,f6,8e,52,10,8e,0d,e5,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,05,94,12,36,6d,
af,1c,71,e9,02,6c,fa,fb,1d,47,57,25,56,79,b7,88,cd,a5,5d,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,70,4b,61,14,b7,
fc,b8,d6,50,93,e5,ab,ec,6a,4e,ab,6a,7b,41,fc,1d,2c,9e,69,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,63,70,41,f6,e0,
12,a9,31,97,20,4e,9a,c7,f1,35,ee,ea,de,dd,88,3b,36,09,eb,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,9c,b2,c2,7d,35,
a8,4c,50,aa,52,c6,00,84,3c,26,64,ab,a9,a1,3f,41,74,66,7f,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,b8,d8,07,49,5e,
14,90,35,b2,46,9a,e2,1b,fe,1b,94,ba,1c,0f,26,87,6d,ed,1e,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,93,3b,fd,6d,cc,
a3,01,61,37,a4,aa,c3,a6,15,56,0a,05,23,99,a2,6b,d8,b4,13,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,63,b2,40,61,d4,
6f,da,13,f8,31,0f,a9,5f,a0,ec,fb,a3,0d,f2,4e,ef,80,37,7d,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,c5,fa,05,18,a1,
1e,86,2d,05,73,21,dd,54,d8,4a,c5,fb,12,cf,66,62,0f,75,e6,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(640)
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll

- - - - - - - > 'lsass.exe'(696)
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll

- - - - - - - > 'csrss.exe'(616)
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll
.
Heure de fin: 2009-01-30 18:54:32
ComboFix-quarantined-files.txt 2009-01-30 17:53:15

Avant-CF: 13 818 798 080 octets libres
Après-CF: 13,803,835,392 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn

318 --- E O F --- 2008-08-21 20:57:34

Répondre à tribord44

16

sKe69, le 30 jan 2009 à 19:17:45

Bien ...


dis moi comment va le PC maintenant ... du mieux ? ....


Poste moi un nouveau rapport RSIT stp et attends la suite ...

"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

17

tribord44, le 30 jan 2009 à 19:40:59

Le pc tourne bien ,j'ai l'impression d'avoir gagné en vitesse , c'est pas qu'il tournait mal ,mais les MAJ windows update ne se font plus et je pensais que l'infection en était responsable.
Visiblement ça n'a pas changé dés que je me connecte à wind.upd. cela plante IE.
Quand à la fenêtre ajout/supp programme, je pensait que tout étaient liés .
voici le rapport RSIT
Logfile of random's system information tool 1.05 (written by random/random)
Run by M V at 2009-01-30 19:25:05
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 13 GB (11%) free of 117 GB
Total RAM: 2048 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:25:10, on 30/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\PROGRA~1\SECURE~1\secp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\M VOILLET\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\M VT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24085 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\ParetoLogic Registration.job
C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
Secured_eMule Toolbar - C:\Program Files\Secured_eMule\tbSec1.dll [2008-06-09 1470488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-04 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-04 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - Secured_eMule Toolbar - C:\Program Files\Secured_eMule\tbSec1.dll [2008-06-09 1470488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CapFax"=C:\Program Files\Classic PhoneTools\CapFax.EXE [2001-12-10 20739]
"PCLEPCI"=C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE [2003-09-23 32768]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-05-21 221184]
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2004-06-01 458752]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2004-06-01 217088]
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2005-02-01 180269]
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe [2004-03-10 406016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-04 136600]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"OpwareSE2"=C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [2003-05-08 49152]
"OPSE reminder"=C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe [2003-07-07 729088]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-07-17 266497]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2004-06-01 196608]
"LDM"=\Program\ []
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-20 15360]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE [2005-01-19 405583]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Documents and Settings\M VOILLET\Menu Démarrer\Programmes\Démarrage
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 2 months======

2009-01-30 18:54:34 ----A---- C:\ComboFix.txt
2009-01-30 18:49:55 ----A---- C:\Boot.bak
2009-01-30 18:49:50 ----RASHD---- C:\cmdcons
2009-01-30 18:48:54 ----A---- C:\WINDOWS\zip.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\VFIND.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\SWSC.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\SWREG.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\sed.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\grep.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\fdsv.exe
2009-01-30 18:45:52 ----D---- C:\WINDOWS\ERDNT
2009-01-30 18:45:52 ----D---- C:\Qoobox
2009-01-30 16:11:54 ----A---- C:\lopR.txt
2009-01-30 16:11:29 ----D---- C:\Lop SD
2009-01-30 15:35:05 ----D---- C:\rsit
2009-01-30 14:49:36 ----D---- C:\Documents and Settings\M V\Application Data\WinRAR
2009-01-30 14:33:03 ----D---- C:\WINDOWS\ERUNT
2009-01-30 14:17:43 ----D---- C:\SDFix
2009-01-30 13:33:55 ----A---- C:\TB.txt
2009-01-30 13:32:59 ----D---- C:\ToolBar SD
2009-01-29 23:58:53 ----D---- C:\Program Files\Trend Micro
2009-01-29 18:06:35 ----D---- C:\WINDOWS\BDOSCAN8
2009-01-29 14:45:50 ----D---- C:\Documents and Settings\M V\Application Data\Windows Search
2009-01-29 11:33:09 ----D---- C:\Documents and Settings\M V\Application Data\Windows Desktop Search
2009-01-29 11:32:05 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2009-01-28 10:55:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-27 13:42:26 ----D---- C:\Documents and Settings\M V\Application Data\Malwarebytes
2009-01-27 13:42:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-27 13:42:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-26 20:48:51 ----D---- C:\Documents and Settings\M V\Application Data\DriverCure
2009-01-26 20:48:32 ----D---- C:\Documents and Settings\All Users\Application Data\DriverCure
2009-01-26 20:47:48 ----D---- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2009-01-07 18:39:54 ----A---- C:\WINDOWS\cPVAS.INI
2009-01-07 18:39:54 ----A---- C:\pvas.txt
2008-12-30 22:40:49 ----D---- C:\Documents and Settings\M V\Application Data\Bamboo Scribe
2008-12-30 22:38:28 ----D---- C:\Program Files\Bamboo Scribe
2008-12-30 20:00:20 ----D---- C:\Program Files\Ambient Design
2008-12-30 18:55:07 ----D---- C:\Documents and Settings\M V\Application Data\Ergo
2008-12-30 18:52:09 ----D---- C:\Program Files\Wacom
2008-12-30 18:51:42 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2008-12-30 18:44:38 ----D---- C:\Program Files\Windows Desktop Search
2008-12-30 18:40:25 ----D---- C:\Program Files\MSBuild
2008-12-30 18:36:42 ----D---- C:\WINDOWS\system32\XPSViewer
2008-12-30 18:36:40 ----D---- C:\WINDOWS\system32\en-us
2008-12-30 18:35:56 ----D---- C:\Program Files\Reference Assemblies
2008-12-30 18:35:23 ----A---- C:\WINDOWS\system32\spmsg2.dll
2008-12-30 18:32:46 ----RSD---- C:\WINDOWS\assembly
2008-12-30 18:32:10 ----D---- C:\WINDOWS\Microsoft.NET
2008-12-30 18:31:23 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2008-12-30 18:04:47 ----D---- C:\Program Files\Fichiers communs\Adobe AIR
2008-12-30 18:02:52 ----D---- C:\Program Files\PenLauncher
2008-12-30 17:17:10 ----D---- C:\Documents and Settings\M V\Application Data\WTablet
2008-12-30 17:16:44 ----A---- C:\WINDOWS\system32\hidserv.dll
2008-12-30 17:16:06 ----D---- C:\WINDOWS\system32\WTablet
2008-12-30 17:16:03 ----A---- C:\WINDOWS\system32\Wintab32.dll
2008-12-30 17:16:03 ----A---- C:\WINDOWS\system32\Pen_Tablet.dll
2008-12-30 17:16:02 ----A---- C:\WINDOWS\system32\Pen_Tablet.exe
2008-12-30 17:15:57 ----D---- C:\Program Files\Tablet
2008-12-21 20:53:41 ----D---- C:\Documents and Settings\All Users\Application Data\PicturesToExe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\java.exe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\deploytk.dll

======List of files/folders modified in the last 2 months======

2009-01-30 19:24:26 ----D---- C:\WINDOWS\Temp
2009-01-30 19:01:33 ----D---- C:\Program Files\Mozilla Firefox
2009-01-30 18:54:40 ----D---- C:\WINDOWS\system32\drivers
2009-01-30 18:54:40 ----D---- C:\WINDOWS\system32
2009-01-30 18:54:39 ----D---- C:\Program Files\BufferZone
2009-01-30 18:54:38 ----D---- C:\WINDOWS
2009-01-30 18:54:34 ----D---- C:\WINDOWS\Prefetch
2009-01-30 18:51:24 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-30 18:50:43 ----A---- C:\WINDOWS\system.ini
2009-01-30 18:49:55 ----RASH---- C:\boot.ini
2009-01-30 18:24:11 ----AD---- C:\Program Files
2009-01-30 17:18:13 ----D---- C:\Program Files\Mozilla Thunderbird
2009-01-29 18:06:38 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-29 18:06:34 ----HD---- C:\WINDOWS\inf
2009-01-29 14:38:59 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-29 14:38:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-01-29 14:34:27 ----D---- C:\WINDOWS\WinSxS
2009-01-29 14:33:45 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-29 14:10:17 ----D---- C:\Program Files\Internet Explorer
2009-01-29 14:09:40 ----D---- C:\WINDOWS\ie7updates
2009-01-29 11:35:12 ----ASD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-29 11:33:02 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-29 11:32:52 ----D---- C:\WINDOWS\system32\fr-fr
2009-01-29 11:32:46 ----D---- C:\WINDOWS\system32\wbem
2009-01-29 07:25:26 ----D---- C:\Documents and Settings\M V\Application Data\XnView
2009-01-29 07:24:21 ----A---- C:\WINDOWS\clarity.ini
2009-01-28 20:51:29 ----D---- C:\Documents and Settings\M V\Application Data\LimeWire
2009-01-28 20:39:26 ----D---- C:\Program Files\eMule
2009-01-28 10:52:03 ----SHD---- C:\WINDOWS\Installer
2009-01-28 10:52:03 ----D---- C:\Config.Msi
2009-01-28 10:49:21 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-28 10:49:19 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-28 10:49:03 ----D---- C:\Program Files\VS Revo Group
2009-01-28 10:46:49 ----D---- C:\WINDOWS\Minidump
2009-01-27 20:22:57 ----D---- C:\Program Files\torrent_search
2009-01-26 20:52:28 ----D---- C:\Program Files\Fichiers communs
2009-01-26 20:52:18 ----SD---- C:\WINDOWS\Tasks
2009-01-26 20:39:38 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-26 20:39:28 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-01-26 20:31:48 ----SD---- C:\Documents and Settings\M V\Application Data\Microsoft
2009-01-26 08:48:11 ----RSD---- C:\WINDOWS\Fonts
2009-01-26 08:47:25 ----D---- C:\Program Files\MSECache
2009-01-18 10:26:09 ----A---- C:\WINDOWS\NeroDigital.ini
2009-01-14 16:21:30 ----D---- C:\Documents and Settings\All Users\Application Data\fssg
2009-01-07 18:41:56 ----A---- C:\mpeg.txt
2008-12-30 18:35:37 ----D---- C:\WINDOWS\system32\spool
2008-12-30 18:32:16 ----D---- C:\WINDOWS\system32\mui
2008-12-30 18:08:14 ----D---- C:\Documents and Settings\M V\Application Data\Adobe
2008-12-30 18:08:14 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2008-12-30 17:16:49 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-12-18 08:06:13 ----D---- C:\Documents and Settings\M V\Application Data\Ahead
2008-12-16 16:52:42 ----AC---- C:\WINDOWS\CDPlayer.ini
2008-12-04 20:56:37 ----D---- C:\Program Files\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2004-08-19 41600]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-11-25 75072]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-20 14848]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 Cnxtdiag;Cnxtdiag; C:\WINDOWS\System32\DRIVERS\cnxtdiag.sys [2001-07-03 17776]
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\fallback.sys [2001-07-12 310739]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\fsksnt.sys [2001-06-14 127405]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\k56nt.sys [2001-07-12 427167]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\faxnt.sys [2001-06-14 216987]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\tonesnt.sys [2001-06-14 56639]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\v124nt.sys [2001-07-12 534605]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 ASAPIW2k;ASAPIW2K; C:\WINDOWS\system32\drivers\ASAPIW2k.sys [2004-03-10 11264]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\basic2.sys [2001-07-12 77426]
R3 FETNDIS;Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-05-27 19968]
R3 MODEMCSA;Périphérique de filtrage de flux Unimodem; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 pfc;Padus ASPI Shell; \??\C:\WINDOWS\system32\drivers\pfc.sys []
R3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2004-05-21 471232]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\rksample.sys [2001-06-14 67622]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2003-04-24 5888]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 578368]
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Pilote miniport de contrôleur hôte amélioré USB 2.0 Microsoft; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
R3 usbscan;Pilote de scanneur USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-04 15104]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS\System32\Drivers\vulfntr.sys [2002-11-13 10496]
R3 wacommousefilter;Wacom Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
R3 wacomvhid;Wacom Virtual Hid Driver; C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 12848]
R3 WacomVKHid;Virtual Keyboard Driver; C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-16 11440]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2001-07-12 584304]
R4 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2003-07-17 46167]
S3 61883;Pilote d'unité 61883; C:\WINDOWS\System32\DRIVERS\61883.sys [2004-08-04 48128]
S3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\System32\DRIVERS\adiusbaw.sys [2003-03-27 127145]
S3 Avc;Périphérique AVC; C:\WINDOWS\System32\DRIVERS\avc.sys [2004-08-04 38912]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 DCamUSBSvis;Oregon Scientific Stream Driver; C:\WINDOWS\system32\DRIVERS\svstream.sys [2001-07-18 91480]
S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\System32\DRIVERS\msdv.sys [2004-08-04 51328]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 scsiscan;Pilote de scanneur SCSI; C:\WINDOWS\System32\DRIVERS\scsiscan.sys [2001-08-17 10880]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 StillCam;Pilote d'appareil photo numérique série; C:\WINDOWS\System32\DRIVERS\serscan.sys [2001-08-23 6912]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbser;USB Serial emulation modem driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2004-08-04 25600]
S3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS\System32\Drivers\vulfnth.sys [2002-10-24 6912]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2003-09-01 104064]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-24 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Avira AntiVir Personal – Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-23 68865]
R2 AntiVirService;Avira AntiVir Personal – Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-23 151297]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 BufferZoneSvc;BufferZone Service; C:\Program Files\BufferZone\CLNTSVC.EXE [2007-08-06 777712]
R2 BZDcomLaunch;BufferZone DCOM Helper; C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE [2007-08-06 61440]
R2 BZRpcSs;BufferZone RPC Helper; C:\Program Files\BufferZone\BZRPCSS.EXE [2007-08-06 57344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-04 152984]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 TabletServicePen;TabletServicePen; C:\WINDOWS\system32\Pen_Tablet.exe [2007-09-07 1373480]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-20 14336]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2006-09-10 72704]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-31 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-10 138168]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 918016]
S4 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Répondre à tribord44

18

sKe69, le 30 jan 2009 à 19:45:09

Bien ...

la suite :


1-Créer un doc texte sur ton bureau :
pointe ta souris sur ton bureau , clique droit : va dans "nouveau" et choisis "document texte" .

Ensuite copie/colle le texte ci-dessous ( et rien d'autre!) dans le fichier texte que tu viens de créer :


Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LDM"=-

File::
C:\PROGRA~1\SECURE~1\secp.exe



Puis va dans "fichier" et choisis "enregistrer sous ..." et tu le nommes exactement ainsi :
CFScript puis valide ...


2-Nettoyage :

!! Déconnecte toi, ferme toutes tes applications et désactive TOUTES TES DEFENSES ( tu les réactiveras après ) !!

--->Sur ton bureau, fais glisser avec ta souris le fichier CFScript sur l'icône de ComboFix.exe .

(Regarde ici : http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript.gif )

Cette manipulation va relancer combofix .
--> Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tape 1 puis valide.

Puis patiente le temps du scan.( Le Bureau va disparaître à plusieurs reprises : c'est normal!)

!! Ne touches à rien tant que le scan n'est pas terminé !!

Note : en fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

Une fois le scan achevé, un rapport va s'afficher : poste le accompagné d' un nouveau rapport RSIT pour analyse ...

( Attention : cette manipe a été fait pour ce PC . Toute réutilisation peut endommager sévèrement le système d'exploitation )
"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

19

tribord44, le 30 jan 2009 à 20:39:52

J'espère que tu prend le temps malgré tout de diner , alors bon appétit....
Donc voici le rapport de combofix:


ComboFix 09-01-21.04 - M V 2009-01-30 19:58:31.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.2048.1553 [GMT 1:00]
Lancé depuis: c:\documents and settings\M V\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\M VOILLET\Bureau\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
- Mode FONCTIONNALITES REDUITES -

FILE ::
c:\progra~1\SECURE~1\secp.exe
.
[color=purple]Les fichiers ci-dessous ont été désactivés pendant l'exécution:/color
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll


(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\progra~1\SECURE~1\secp.exe

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-30 ))))))))))))))))))))))))))))))))))))
.

2009-01-30 16:11 . 2009-01-30 18:29 <REP> d-------- C:\Lop SD
2009-01-30 15:35 . 2009-01-30 15:35 <REP> d-------- C:\rsit
2009-01-30 14:33 . 2009-01-30 14:33 <REP> d-------- c:\windows\ERUNT
2009-01-30 14:17 . 2009-01-30 14:56 <REP> d-------- C:\SDFix
2009-01-30 13:32 . 2009-01-30 13:38 <REP> d-------- C:\ToolBar SD
2009-01-29 23:58 . 2009-01-29 23:58 <REP> d-------- c:\program files\Trend Micro
2009-01-29 18:06 . 2009-01-29 18:22 <REP> d-------- c:\windows\BDOSCAN8
2009-01-29 14:45 . 2009-01-29 14:45 <REP> d-------- c:\documents and settings\M VT\Application Data\Windows Search
2009-01-29 11:33 . 2009-01-29 11:33 <REP> d-------- c:\documents and settings\M VT\Application Data\Windows Desktop Search
2009-01-27 13:42 . 2009-01-27 13:42 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-27 13:42 . 2009-01-27 13:42 <REP> d-------- c:\documents and settings\M VT\Application Data\Malwarebytes
2009-01-27 13:42 . 2009-01-27 13:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-27 13:42 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-27 13:42 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-26 20:48 . 2009-01-26 20:49 <REP> d-------- c:\documents and settings\M V\Application Data\DriverCure
2009-01-26 20:48 . 2009-01-26 20:52 <REP> d-------- c:\documents and settings\All Users\Application Data\DriverCure
2009-01-26 20:47 . 2009-01-26 20:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-01-15 16:13 . 2009-01-15 16:13 <REP> d-------- c:\documents and settings\LocalService\Application Data\WTablet
2009-01-07 18:39 . 2009-01-07 18:41 887 --a------ c:\windows\cPVAS.INI
2008-12-30 22:40 . 2008-12-30 22:40 <REP> d-------- c:\documents and settings\M V\Application Data\Bamboo Scribe
2008-12-30 22:38 . 2008-12-30 22:38 <REP> d-------- c:\program files\Bamboo Scribe
2008-12-30 20:00 . 2008-12-30 20:00 <REP> d-------- c:\program files\Ambient Design
2008-12-30 18:55 . 2008-12-30 18:55 <REP> d-------- c:\documents and settings\M V\Application Data\Ergo
2008-12-30 18:52 . 2008-12-30 18:52 <REP> d-------- c:\program files\Wacom
2008-12-30 18:51 . 2008-12-30 18:51 <REP> d-------- c:\program files\Microsoft SQL Server Compact Edition
2008-12-30 18:44 . 2009-01-29 11:34 <REP> d-------- c:\program files\Windows Desktop Search
2008-12-30 18:43 . 2008-03-07 17:56 192,000 -----c--- c:\windows\system32\dllcache\offfilt.dll
2008-12-30 18:43 . 2008-03-07 17:56 98,304 -----c--- c:\windows\system32\dllcache\nlhtml.dll
2008-12-30 18:40 . 2008-12-30 18:40 <REP> d-------- c:\program files\MSBuild
2008-12-30 18:36 . 2008-12-30 18:36 <REP> d-------- c:\windows\system32\XPSViewer
2008-12-30 18:35 . 2008-12-30 18:35 <REP> d-------- c:\program files\Reference Assemblies
2008-12-30 18:35 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2008-12-30 18:04 . 2008-12-30 18:04 <REP> d-------- c:\program files\Fichiers communs\Adobe AIR
2008-12-30 18:02 . 2008-12-30 18:02 <REP> d-------- c:\program files\PenLauncher
2008-12-30 18:02 . 2008-06-04 19:14 319 --a------ c:\windows\system32\pentabletdefaults.xml
2008-12-30 17:17 . 2009-01-30 14:45 <REP> d-------- c:\documents and settings\M V\Application Data\WTablet
2008-12-30 17:15 . 2008-12-30 17:16 <REP> d-------- c:\program files\Tablet
2008-12-30 17:14 . 2001-08-23 17:04 12,288 --a------ c:\windows\system32\drivers\mouhid.sys
2008-12-30 17:14 . 2001-08-23 17:04 12,288 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-12-30 17:14 . 2001-08-17 22:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-12-30 17:14 . 2001-08-17 22:02 9,600 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-12-21 20:53 . 2008-12-21 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\PicturesToExe
2008-12-04 20:56 . 2008-12-04 20:56 410,984 --a------ c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 18:58 --------- d-----w c:\program files\Secured eMule
2009-01-30 18:56 --------- d-----w c:\program files\BufferZone
2009-01-30 16:18 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-29 06:25 --------- d-----w c:\documents and settings\M T\Application Data\XnView
2009-01-28 19:51 --------- d-----w c:\documents and settings\M VApplication Data\LimeWire
2009-01-28 19:39 --------- d-----w c:\program files\eMule
2009-01-28 09:49 --------- d-----w c:\program files\VS Revo Group
2009-01-28 09:49 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-28 09:49 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-27 19:22 --------- d-----w c:\program files\torrent_search
2009-01-26 19:39 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-26 07:47 --------- d-----w c:\program files\MSECache
2009-01-14 15:21 --------- d-----w c:\documents and settings\All Users\Application Data\fssg
2008-12-18 07:06 --------- d-----w c:\documents and settings\M V\Application Data\Ahead
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-04 19:56 --------- d-----w c:\program files\Java
2008-11-29 15:11 --------- d-----w c:\documents and settings\M V\Application Data\Canon
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-03-10 16:53 73,944 -c--a-w c:\documents and settings\M V\Application Data\GDIPFONTCACHEV1.DAT
2002-06-26 12:05 8,043,520 ----a-w c:\program files\DS.exe
2008-03-16 13:56 11,690 -csha-w c:\windows\system32\KGyGaAvL.sys
2008-06-30 19:18 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008063020080701\index.dat
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}"= "c:\program files\Secured_eMule\tbSec1.dll" [2008-06-09 1470488]

[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
2008-06-09 16:28 1470488 --a------ c:\program files\Secured_eMule\tbSec1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}"= "c:\program files\Secured_eMule\tbSec1.dll" [2008-06-09 1470488]

[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{1D1B60FD-B21F-4B9A-8A5F-64E8544828D7}"= "c:\program files\Secured_eMule\tbSec1.dll" [2008-06-09 1470488]

[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzBufferZoneOverlay]
@="{37ADBD0B-11EC-4A2C-9F93-5C3ACC7994DF}"
[HKEY_CLASSES_ROOT\CLSID\{37ADBD0B-11EC-4A2C-9F93-5C3ACC7994DF}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzConfidentialOverlay]
@="{F594B094-8768-4632-8143-12852EBBD688}"
[HKEY_CLASSES_ROOT\CLSID\{F594B094-8768-4632-8143-12852EBBD688}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzForbiddenOverlay]
@="{F1A1DA12-E651-4AD0-A1A0-6214546B2F9D}"
[HKEY_CLASSES_ROOT\CLSID\{F1A1DA12-E651-4AD0-A1A0-6214546B2F9D}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzUnknownOverlay]
@="{E4FC4B31-8A4F-45E6-BDAC-28F612371FE3}"
[HKEY_CLASSES_ROOT\CLSID\{E4FC4B31-8A4F-45E6-BDAC-28F612371FE3}]
2007-08-06 14:20 1222576 --a------ c:\windows\system32\RlShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-20 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 405583]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CapFax"="c:\program files\Classic PhoneTools\CapFax.EXE" [2001-12-10 20739]
"PCLEPCI"="c:\progra~1\PINNAC~1\PPE\PPE.EXE" [2003-09-23 32768]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-05-21 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-02-01 180269]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-04 136600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"OPSE reminder"="c:\program files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" [2003-07-07 729088]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-20 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]

c:\documents and settings\M VOILLET\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-04-13 110592]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2004-12-14 962663]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-03-08 450560]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
"VIDC.MJPG"= mtkjpeg.dll
"VIDC.PIM1"= pclepim1.dll
"vidc.ptev"= ptevideo.dll
"MSACM.CEGSM"= mobilev.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R0 REDLIGHT;REDLIGHT;c:\windows\system32\drivers\redlight.sys [2007-08-06 2233728]
R4 BufferZoneSvc;BufferZone Service;c:\program files\BufferZone\ClntSvc.exe [2007-08-06 777712]
R4 BZDcomLaunch;BufferZone DCOM Helper;c:\program files\BufferZone\BZDcomLaunch.exe [2007-08-06 61440]
R4 BZRpcSs;BufferZone RPC Helper;c:\program files\BufferZone\BZRpcSs.exe [2007-08-06 57344]
R4 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-30 1373480]
S3 DCamUSBSvis;Oregon Scientific Stream Driver;c:\windows\system32\drivers\SvStream.sys [2006-07-13 91480]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-20 33752]
S3 scsiscan;Pilote de scanneur SCSI;c:\windows\system32\drivers\scsiscan.sys [2005-12-16 10880]

--- Autres Services/Pilotes en mémoire ---

*Deregistered* - mchInjDrv
.
Contenu du dossier 'Tâches planifiées'

2009-01-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-01-30 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Fichiers communs\ParetoLogic\UUS2\UUS.dll []

2009-01-30 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = about:NavigationFailure
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Annoter avec Bamboo Link - c:\program files\Wacom\Bamboo Link\AnnotateWithErgo.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: View EXIF - c:\viewexif\EXIF.htm
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: msn.com\fr
TCP: {EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4} = 208.67.220.220,208.67.222.222
TCP: {F3CED271-D5C7-432C-BF6E-B7E600EEBA78} = 208.67.220.220,208.67.222.222
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\M VOILLET\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 19:58:44
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_USERS\S-1-5-21-448539723-823518204-1801674531-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{234399AF-0FDB-9235-B859A4E3AC2ADE1B}\{19B8A235-5775-8B53-4D38DBAF8988D503}\{76727453-9A12-1EF5-D0F3E23CAC7A8CDF}*]
"KBHFJ3LOVGGHQNXKY4VGT5W5XA1"=hex:01,00,01,00,00,00,00,00,cd,90,7b,1c,04,10,89,
b4,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40886FA5-87BC-FDA7-0C1FAC01C243999B}\{19E564B2-522B-7AA8-1ACCCD0705265332}\{1F2DE655-6E2E-2DD5-8638E8D01A513D14}*]
"YVDOYALJ4U2TQACPBJNJTEIBQG1"=hex:01,00,01,00,00,00,00,00,cd,90,7b,1c,04,10,89,
b4,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,b3,23,7f,03,c6,
d8,aa,aa,2e,e8,e1,00,eb,16,2b,de,04,f7,98,0f,fa,a4,41,ca,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,96,3d,a8,da,
1c,2b,79,46,47,15,b0,92,4b,c7,ef,cd,8c,79,5e,15,ac,27,e6,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,37,24,cf,fd,14,
32,1d,8f,7a,45,05,fd,91,e8,6f,31,7d,28,ed,99,aa,c4,21,49,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,b2,92,24,18,8b,
e3,d6,95,6b,65,49,6a,7e,99,74,f7,c8,f6,8e,52,10,8e,0d,e5,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,05,94,12,36,6d,
af,1c,71,e9,02,6c,fa,fb,1d,47,57,25,56,79,b7,88,cd,a5,5d,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,70,4b,61,14,b7,
fc,b8,d6,50,93,e5,ab,ec,6a,4e,ab,6a,7b,41,fc,1d,2c,9e,69,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,63,70,41,f6,e0,
12,a9,31,97,20,4e,9a,c7,f1,35,ee,ea,de,dd,88,3b,36,09,eb,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,9c,b2,c2,7d,35,
a8,4c,50,aa,52,c6,00,84,3c,26,64,ab,a9,a1,3f,41,74,66,7f,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,b8,d8,07,49,5e,
14,90,35,b2,46,9a,e2,1b,fe,1b,94,ba,1c,0f,26,87,6d,ed,1e,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,93,3b,fd,6d,cc,
a3,01,61,37,a4,aa,c3,a6,15,56,0a,05,23,99,a2,6b,d8,b4,13,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,63,b2,40,61,d4,
6f,da,13,f8,31,0f,a9,5f,a0,ec,fb,a3,0d,f2,4e,ef,80,37,7d,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,c5,fa,05,18,a1,
1e,86,2d,05,73,21,dd,54,d8,4a,c5,fb,12,cf,66,62,0f,75,e6,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(640)
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll

- - - - - - - > 'lsass.exe'(696)
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll

- - - - - - - > 'csrss.exe'(616)
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll
.
Heure de fin: 2009-01-30 20:02:07
ComboFix-quarantined-files.txt 2009-01-30 19:00:55
ComboFix2.txt 2009-01-30 17:54:34

Avant-CF: 13 776 150 528 octets libres
Après-CF: 13,768,347,648 octets libres

314 --- E O F --- 2008-08-21 20:57:34

et le rapport RSTI

Logfile of random's system information tool 1.05 (written by random/random)
Run by M V at 2009-01-30 20:19:48
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 13 GB (11%) free of 117 GB
Total RAM: 2048 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:19:54, on 30/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\M VT\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\M V.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24019 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\ParetoLogic Registration.job
C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
Secured_eMule Toolbar - C:\Program Files\Secured_eMule\tbSec1.dll [2008-06-09 1470488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-04 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-04 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - Secured_eMule Toolbar - C:\Program Files\Secured_eMule\tbSec1.dll [2008-06-09 1470488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CapFax"=C:\Program Files\Classic PhoneTools\CapFax.EXE [2001-12-10 20739]
"PCLEPCI"=C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE [2003-09-23 32768]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-05-21 221184]
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2004-06-01 458752]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2004-06-01 217088]
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2005-02-01 180269]
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe [2004-03-10 406016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-04 136600]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"OpwareSE2"=C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [2003-05-08 49152]
"OPSE reminder"=C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe [2003-07-07 729088]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-07-17 266497]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2004-06-01 196608]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-20 15360]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE [2005-01-19 405583]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Documents and Settings\M VOILLET\Menu Démarrer\Programmes\Démarrage
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 2 months======

2009-01-30 20:02:08 ----A---- C:\ComboFix.txt
2009-01-30 18:49:55 ----A---- C:\Boot.bak
2009-01-30 18:49:50 ----RASHD---- C:\cmdcons
2009-01-30 18:48:54 ----A---- C:\WINDOWS\zip.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\VFIND.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\SWSC.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\SWREG.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\sed.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\grep.exe
2009-01-30 18:48:54 ----A---- C:\WINDOWS\fdsv.exe
2009-01-30 18:45:52 ----D---- C:\WINDOWS\ERDNT
2009-01-30 18:45:52 ----D---- C:\Qoobox
2009-01-30 16:11:54 ----A---- C:\lopR.txt
2009-01-30 16:11:29 ----D---- C:\Lop SD
2009-01-30 15:35:05 ----D---- C:\rsit
2009-01-30 14:49:36 ----D---- C:\Documents and Settings\M VOILLET\Application Data\WinRAR
2009-01-30 14:33:03 ----D---- C:\WINDOWS\ERUNT
2009-01-30 14:17:43 ----D---- C:\SDFix
2009-01-30 13:33:55 ----A---- C:\TB.txt
2009-01-30 13:32:59 ----D---- C:\ToolBar SD
2009-01-29 23:58:53 ----D---- C:\Program Files\Trend Micro
2009-01-29 18:06:35 ----D---- C:\WINDOWS\BDOSCAN8
2009-01-29 14:45:50 ----D---- C:\Documents and Settings\M T\Application Data\Windows Search
2009-01-29 11:33:09 ----D---- C:\Documents and Settings\M VT\Application Data\Windows Desktop Search
2009-01-29 11:32:05 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2009-01-28 10:55:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-27 13:42:26 ----D---- C:\Documents and Settings\M VT\Application Data\Malwarebytes
2009-01-27 13:42:18 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-27 13:42:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-26 20:48:51 ----D---- C:\Documents and Settings\M VT\Application Data\DriverCure
2009-01-26 20:48:32 ----D---- C:\Documents and Settings\All Users\Application Data\DriverCure
2009-01-26 20:47:48 ----D---- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2009-01-07 18:39:54 ----A---- C:\WINDOWS\cPVAS.INI
2009-01-07 18:39:54 ----A---- C:\pvas.txt
2008-12-30 22:40:49 ----D---- C:\Documents and Settings\M V\Application Data\Bamboo Scribe
2008-12-30 22:38:28 ----D---- C:\Program Files\Bamboo Scribe
2008-12-30 20:00:20 ----D---- C:\Program Files\Ambient Design
2008-12-30 18:55:07 ----D---- C:\Documents and Settings\M V\Application Data\Ergo
2008-12-30 18:52:09 ----D---- C:\Program Files\Wacom
2008-12-30 18:51:42 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2008-12-30 18:44:38 ----D---- C:\Program Files\Windows Desktop Search
2008-12-30 18:40:25 ----D---- C:\Program Files\MSBuild
2008-12-30 18:36:42 ----D---- C:\WINDOWS\system32\XPSViewer
2008-12-30 18:36:40 ----D---- C:\WINDOWS\system32\en-us
2008-12-30 18:35:56 ----D---- C:\Program Files\Reference Assemblies
2008-12-30 18:35:23 ----A---- C:\WINDOWS\system32\spmsg2.dll
2008-12-30 18:32:46 ----RSD---- C:\WINDOWS\assembly
2008-12-30 18:32:10 ----D---- C:\WINDOWS\Microsoft.NET
2008-12-30 18:31:23 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2008-12-30 18:04:47 ----D---- C:\Program Files\Fichiers communs\Adobe AIR
2008-12-30 18:02:52 ----D---- C:\Program Files\PenLauncher
2008-12-30 17:17:10 ----D---- C:\Documents and Settings\M VT\Application Data\WTablet
2008-12-30 17:16:44 ----A---- C:\WINDOWS\system32\hidserv.dll
2008-12-30 17:16:06 ----D---- C:\WINDOWS\system32\WTablet
2008-12-30 17:16:03 ----A---- C:\WINDOWS\system32\Wintab32.dll
2008-12-30 17:16:03 ----A---- C:\WINDOWS\system32\Pen_Tablet.dll
2008-12-30 17:16:02 ----A---- C:\WINDOWS\system32\Pen_Tablet.exe
2008-12-30 17:15:57 ----D---- C:\Program Files\Tablet
2008-12-21 20:53:41 ----D---- C:\Documents and Settings\All Users\Application Data\PicturesToExe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\java.exe
2008-12-04 20:56:57 ----A---- C:\WINDOWS\system32\deploytk.dll

======List of files/folders modified in the last 2 months======

2009-01-30 20:13:39 ----D---- C:\Program Files\Mozilla Firefox
2009-01-30 20:02:12 ----D---- C:\WINDOWS\system32
2009-01-30 20:02:11 ----D---- C:\Program Files\BufferZone
2009-01-30 20:02:10 ----D---- C:\WINDOWS
2009-01-30 19:58:46 ----A---- C:\WINDOWS\system.ini
2009-01-30 19:58:37 ----D---- C:\Program Files\Secured eMule
2009-01-30 19:56:38 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-30 19:55:23 ----D---- C:\WINDOWS\Temp
2009-01-30 18:54:40 ----D---- C:\WINDOWS\system32\drivers
2009-01-30 18:54:34 ----D---- C:\WINDOWS\Prefetch
2009-01-30 18:49:55 ----RASH---- C:\boot.ini
2009-01-30 18:24:11 --

Répondre à tribord44

20

sKe69, le 30 jan 2009 à 22:41:20

Bien ...

la suite dans l'ordre :


1- refais un coup de CCleaner (registre compris )

==========

2- Avoir accès aux fichiers cachés :

Va dans Menu Démarrer->Poste de travail->Outils->Options des dossiers...->Affichage
* "Afficher les fichiers et dossiers cachés" ---> coché
* "Masquer les extensions des fichiers dont le type est connu" ---> décoché
* "masquer les fichiers du système" ---> décoché
-> valide la modif ( "appliquer" puis "ok" ).
( tu remetteras les paramètres de départ une fois la désinfection terminée , pas avant ... )



3- Rends toi sur ce site :

http://www.virustotal.com/

Copies ce qui suit et colles le dans l'espace pour la recherche :
c:\windows\cPVAS.INI

Clique sur Send File ( = " Envoyer le fichier " ).

Un rapport va s'élaborer ligne à ligne.

Attends bien la fin ... Il doit comprendre la taille du fichier envoyé.

Sauvegarde le rapport avec le bloc-note.

Copie le dans ta prochaine réponse ...

( Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant )


Fais de même pour :
c:\program files\BufferZone\RLHOOK.DLL
c:\windows\system32\RLDRAGDROP.dll
c:\windows\system32\pentabletdefaults.xml
c:\windows\system32\RlShellExt.dll
c:\viewexif\EXIF.htm


Poste moi donc ces 6 rapports ( surtout le début avec le listing des AV , et en précisant bien au début de chacuns à quel fichier ils correspondent ) .


une fois ces 6 rapports postés , fais la suite :

===============

4- Télécharge GenProc (de Jean-Chretien1 et Narco4) sur ton bureau (et pas ailleur !) :
http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip

!!Déconnecte toi et ferme tes applications en cours !!

Dézippe (=extraire tout) le contenu de ce que tu viens de télécharger sur ton bureau .

Ouvre le dossier Genproc :
* double-clique sur GenProc.bat et laisse faire ...

* A la question "faites vous aidez sur un forum..." > clique sur " oui " .

-> poste le contenu du rapport qui s'ouvre ...


Aide en images ici : http://www.alt-shift-return.org/Info/GenProc-HowTo.html

IMPORTANT : poste le rapport et ne fais rien d'autre pour l'instant ( souvant il faut ajouter des consignes à la manipe indiquée pour que cela fonctionne parfaitement ) .





"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

21

tribord44, le 31 jan 2009 à 00:46:07

Ok pour les rapport
voici pour CPVAS.ini

Fichier cPVAS.INI reçu le 2009.01.31 00:03:41 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 0/39 (0%)
en train de charger les informations du serveur...
Votre fichier est dans la file d'attente, en position: 1.
L'heure estimée de démarrage est entre 42 et 60 secondes.
Ne fermez pas la fenêtre avant la fin de l'analyse.
L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
les résultats seront affichés au fur et à mesure de leur génération.
Formaté Formaté
Impression des résultats Impression des résultats
Votre fichier a expiré ou n'existe pas.
Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
Email:

Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.93 2009.01.30 -
AhnLab-V3 5.0.0.2 2009.01.30 -
AntiVir 7.9.0.60 2009.01.30 -
Authentium 5.1.0.4 2009.01.30 -
Avast 4.8.1281.0 2009.01.30 -
AVG 8.0.0.229 2009.01.30 -
BitDefender 7.2 2009.01.30 -
CAT-QuickHeal 10.00 2009.01.30 -
ClamAV 0.94.1 2009.01.30 -
Comodo 954 2009.01.30 -
DrWeb 4.44.0.09170 2009.01.30 -
eSafe 7.0.17.0 2009.01.29 -
eTrust-Vet 31.6.6335 2009.01.29 -
F-Prot 4.4.4.56 2009.01.30 -
F-Secure 8.0.14470.0 2009.01.30 -
Fortinet 3.117.0.0 2009.01.30 -
GData 19 2009.01.30 -
Ikarus T3.1.1.45.0 2009.01.30 -
K7AntiVirus 7.10.611 2009.01.30 -
Kaspersky 7.0.0.125 2009.01.30 -
McAfee 5511 2009.01.30 -
McAfee+Artemis 5511 2009.01.30 -
Microsoft 1.4306 2009.01.30 -
NOD32 3813 2009.01.30 -
Norman 6.00.02 2009.01.30 -
nProtect 2009.1.8.0 2009.01.30 -
Panda 9.5.1.2 2009.01.30 -
PCTools 4.4.2.0 2009.01.30 -
Prevx1 V2 2009.01.31 -
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.30 -
Sophos 4.38.0 2009.01.30 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.01.30 -
TheHacker 6.3.1.5.238 2009.01.30 -
TrendMicro 8.700.0.1004 2009.01.30 -
VBA32 3.12.8.12 2009.01.30 -
ViRobot 2009.1.30.1582 2009.01.30 -
VirusBuster 4.5.11.0 2009.01.30 -
Information additionnelle
File size: 887 bytes
MD5...: 53cc1b0e03c998b716597f536677c0b0
SHA1..: cb0c5a811a22662358c44c573efa768f59995ecc
SHA256: c325a78a67660569965cc1d56bef8989061ad02344b0b2eeb05a4295d4eb2d66
SHA512: f8584ffc198432135ea0e7343985e0c02560c340cf80f49bb76da04853406894
629f445da746e10676eb0db58a1d55f60aa9f1ab31ff371f30fdadb8acc2c619
ssdeep: 24:zEZ3r61KK1KdfpB9u7SkLxUkREIAA2Z5fKF:IZ32YKYdH9OykREIAA4KF
PEiD..: -
TrID..: File type identification
Generic INI configuration (100.0%)
PEInfo: -

pour buffer zonne/RLHOOK.Dll

Fichier RLHOOK.DLL reçu le 2009.01.31 00:09:42 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 1/39 (2.57%)
en train de charger les informations du serveur...
Votre fichier est dans la file d'attente, en position: ___.
L'heure estimée de démarrage est entre ___ et ___ .
Ne fermez pas la fenêtre avant la fin de l'analyse.
L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
les résultats seront affichés au fur et à mesure de leur génération.
Formaté Formaté
Impression des résultats Impression des résultats
Votre fichier a expiré ou n'existe pas.
Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
Email:

Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.93 2009.01.30 -
AhnLab-V3 5.0.0.2 2009.01.30 -
AntiVir 7.9.0.60 2009.01.30 -
Authentium 5.1.0.4 2009.01.30 -
Avast 4.8.1281.0 2009.01.30 -
AVG 8.0.0.229 2009.01.30 -
BitDefender 7.2 2009.01.30 -
CAT-QuickHeal 10.00 2009.01.30 -
ClamAV 0.94.1 2009.01.30 -
Comodo 954 2009.01.30 -
DrWeb 4.44.0.09170 2009.01.30 -
eSafe 7.0.17.0 2009.01.29 -
eTrust-Vet 31.6.6335 2009.01.29 -
F-Prot 4.4.4.56 2009.01.30 -
F-Secure 8.0.14470.0 2009.01.30 -
Fortinet 3.117.0.0 2009.01.30 -
GData 19 2009.01.30 -
Ikarus T3.1.1.45.0 2009.01.30 -
K7AntiVirus 7.10.611 2009.01.30 -
Kaspersky 7.0.0.125 2009.01.30 -
McAfee 5511 2009.01.30 -
McAfee+Artemis 5511 2009.01.30 -
Microsoft 1.4306 2009.01.30 -
NOD32 3813 2009.01.30 -
Norman 6.00.02 2009.01.30 -
nProtect 2009.1.8.0 2009.01.30 -
Panda 9.5.1.2 2009.01.30 -
PCTools 4.4.2.0 2009.01.30 -
Prevx1 V2 2009.01.31 -
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.30 -
Sophos 4.38.0 2009.01.31 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.01.30 -
TheHacker 6.3.1.5.238 2009.01.30 -
TrendMicro 8.700.0.1004 2009.01.30 -
VBA32 3.12.8.12 2009.01.30 suspected of Win32.BrokenEmbeddedSignature (paranoid heuristics)
ViRobot 2009.1.30.1582 2009.01.30 -
VirusBuster 4.5.11.0 2009.01.30 -
Information additionnelle
File size: 139184 bytes
MD5...: 3add96d9df32c9caf1a33ffbe89034b3
SHA1..: c578ad9927be959889ef0b4fb47df6f8589831cb
SHA256: e5ef9f74c10e4ec87aaecc92174a9ead74a6c25be06d4dcefdc5388bb143cacd
SHA512: d4af913b840f5de2522db44c4ebc7d3ea62181867218ca900ab35b1df3414b61
1e4d4c820c54e81c7c9fd2fb1aea53e894545379b4e93ca85ee20d85a4023c3b
ssdeep: 3072:IDR8Gk1SUiCGtfd9yN1FDiEeRIBe8sdC0W0:1GtCofdEbFTYf
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xe3eb
timedatestamp.....: 0x46ae181a (Mon Jul 30 16:55:54 2007)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x134f0 0x14000 6.41 16fe0a574c36c2de5ea8e334ef864c0f
.rdata 0x15000 0x47d8 0x5000 4.38 f0f61f9f9d310a58baaf67dba036db02
.data 0x1a000 0x48d0 0x1000 2.28 837c294b3202b1814774d08d26bd5e36
shared 0x1f000 0x17c0 0x2000 1.31 48ff91e54ad6a90e0b766833c599e6a3
.rsrc 0x21000 0x340 0x1000 0.88 fdefb28d2ae588202b7fc06a0dcc8c71
.reloc 0x22000 0x22b0 0x3000 4.07 118aff70d9676e4ef44b55b424afb510

( 8 imports )
> MADCHOOK.DLL: HookCode, AnsiToWide, HookAPI, WideToAnsi
> WS2_32.dll: -
> KERNEL32.dll: HeapAlloc, GetProcAddress, LoadLibraryW, IsBadStringPtrW, IsBadReadPtr, GetCurrentDirectoryW, GetTickCount, MultiByteToWideChar, GetModuleFileNameW, TlsAlloc, TlsSetValue, TlsGetValue, DeleteFileW, FindNextFileW, TlsFree, GetWindowsDirectoryW, CreateDirectoryW, ResumeThread, GetTempFileNameW, CopyFileW, LocalFree, InterlockedIncrement, InterlockedDecrement, GetFileAttributesW, GetCurrentProcessId, GetSystemDirectoryW, GetModuleHandleW, GetCommandLineW, GetTempPathW, CloseHandle, SetFilePointer, WriteFile, GetCurrentThreadId, WideCharToMultiByte, FindClose, FindFirstFileW, QueryPerformanceCounter, HeapSize, LoadLibraryA, FlushFileBuffers, GetProcessHeap, HeapFree, SetLastError, GetLastError, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, SetStdHandle, GetOEMCP, FreeEnvironmentStringsA, GetModuleFileNameA, GetStartupInfoA, GetFileType, GetStdHandle, SetHandleCount, GetCurrentProcess, GetACP, TerminateProcess, GetCPInfo, GetLocaleInfoA, GetSystemInfo, VirtualProtect, GetSystemTimeAsFileTime, UnhandledExceptionFilter, GetEnvironmentStringsW, FreeEnvironmentStringsW, ExpandEnvironmentStringsW, DeviceIoControl, CreateFileA, OpenThread, RtlUnwind, HeapReAlloc, GetCommandLineA, GetVersionExA, ExitProcess, DeleteCriticalSection, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, InterlockedExchange, VirtualQuery, GetStringTypeA, GetStringTypeW, GetModuleHandleA, LCMapStringA, LCMapStringW, GetEnvironmentStrings
> USER32.dll: IsWindowUnicode, GetPropW, GetPropA, SetPropW, wsprintfW, GetForegroundWindow, GetWindowThreadProcessId, MessageBoxW, EnumWindows, GetWindowLongA, GetWindowLongW, SetWindowLongA, SetWindowLongW, RemovePropA, RemovePropW, SetPropA
> ADVAPI32.dll: RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, CloseServiceHandle, RegQueryValueExW, RegOpenKeyW, RegQueryValueW, RegCloseKey
> SHELL32.dll: SHGetPathFromIDListW, DragAcceptFiles, FindExecutableW, CommandLineToArgvW, SHGetMalloc
> ole32.dll: StringFromCLSID, CoTaskMemFree, CoCreateInstance
> RPCRT4.dll: RpcRaiseException, RpcStringBindingParseW, RpcServerUseProtseqEpW, RpcBindingToStringBindingW, RpcStringFreeW

( 1 exports )
_Refresh@0

ATENTION ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

Pour systeme32/RLDRAGDROP

Fichier RLDRAGDROP.dll reçu le 2009.01.31 00:19:04 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 1/39 (2.57%)
en train de charger les informations du serveur...
Votre fichier est dans la file d'attente, en position: 2.
L'heure estimée de démarrage est entre 49 et 70 secondes.
Ne fermez pas la fenêtre avant la fin de l'analyse.
L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
les résultats seront affichés au fur et à mesure de leur génération.
Formaté Formaté
Impression des résultats Impression des résultats
Votre fichier a expiré ou n'existe pas.
Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
Email:

Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.93 2009.01.30 -
AhnLab-V3 5.0.0.2 2009.01.30 -
AntiVir 7.9.0.60 2009.01.30 -
Authentium 5.1.0.4 2009.01.30 -
Avast 4.8.1281.0 2009.01.30 -
AVG 8.0.0.229 2009.01.30 -
BitDefender 7.2 2009.01.30 -
CAT-QuickHeal 10.00 2009.01.30 -
ClamAV 0.94.1 2009.01.30 -
Comodo 954 2009.01.30 -
DrWeb 4.44.0.09170 2009.01.30 -
eSafe 7.0.17.0 2009.01.29 -
eTrust-Vet 31.6.6335 2009.01.29 -
F-Prot 4.4.4.56 2009.01.30 -
F-Secure 8.0.14470.0 2009.01.30 -
Fortinet 3.117.0.0 2009.01.30 -
GData 19 2009.01.30 -
Ikarus T3.1.1.45.0 2009.01.30 -
K7AntiVirus 7.10.611 2009.01.30 -
Kaspersky 7.0.0.125 2009.01.30 -
McAfee 5511 2009.01.30 -
McAfee+Artemis 5511 2009.01.30 -
Microsoft 1.4306 2009.01.30 -
NOD32 3813 2009.01.30 -
Norman 6.00.02 2009.01.30 -
nProtect 2009.1.8.0 2009.01.30 -
Panda 9.5.1.2 2009.01.30 -
PCTools 4.4.2.0 2009.01.30 -
Prevx1 V2 2009.01.31 -
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.30 -
Sophos 4.38.0 2009.01.31 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.01.31 -
TheHacker 6.3.1.5.238 2009.01.30 -
TrendMicro 8.700.0.1004 2009.01.30 -
VBA32 3.12.8.12 2009.01.30 suspected of Win32.BrokenEmbeddedSignature (paranoid heuristics)
ViRobot 2009.1.30.1582 2009.01.30 -
VirusBuster 4.5.11.0 2009.01.30 -
Information additionnelle
File size: 73648 bytes
MD5...: 6a9579aa6f0170ab4768ffa980d4f5ca
SHA1..: c5f3efb8e50044a15219a39562d8b525d136c65d
SHA256: 1af618f24d82a06c4e98a4da2ae195bf0c8fbe04f6580f526338206fc4ec5b2e
SHA512: 9b0a18758ef7294628cd5d4f4753754ddadc0373a7bdb3e35497239ee8f2cb91
ff174ec3480296dcaca93609bff949310594fd36d8ad912d3a6dda0b18321d96
ssdeep: 1536:080faG3Mr9d5Rs+bj+LPE3xcwJlMnv1scgg/MMsd:080faGkzvkP+98nv1s
cg6B
PEiD..: -
TrID..: File type identification
DirectShow filter (58.4%)
Win64 Executable Generic (24.8%)
Win32 Executable MS Visual C++ (generic) (10.9%)
Win32 Executable Generic (2.4%)
Win32 Dynamic Link Library (generic) (2.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x3851
timedatestamp.....: 0x46ae17ee (Mon Jul 30 16:55:10 2007)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x842b 0x9000 6.27 a9dc33ee039ad742077d16b96866c556
.rdata 0xa000 0x2213 0x3000 3.89 07b8f99ab9dcea50bce62626f68db85b
.data 0xd000 0x16e0 0x1000 1.56 cae75619bac414198114fc084c010879
.rsrc 0xf000 0x440 0x1000 1.07 0034672bdd0527cf5ab4f978c728723c
.reloc 0x10000 0x1110 0x2000 2.65 10254f2b272fc4bec484f9be6c5f4749

( 4 imports )
> KERNEL32.dll: GlobalAlloc, WideCharToMultiByte, GetModuleFileNameW, GetProcessHeap, HeapFree, GlobalFree, InterlockedDecrement, GetLastError, GetFileAttributesW, GetTickCount, GetCurrentProcessId, MultiByteToWideChar, SetLastError, DeviceIoControl, CreateFileA, RtlUnwind, ExitProcess, HeapAlloc, GetCurrentThreadId, GetCommandLineA, GetVersionExA, HeapReAlloc, TlsAlloc, TlsFree, TlsSetValue, TlsGetValue, GetProcAddress, GetModuleHandleA, QueryPerformanceCounter, GetSystemTimeAsFileTime, GetModuleFileNameA, TerminateProcess, GetCurrentProcess, HeapSize, HeapDestroy, HeapCreate, VirtualFree, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, IsBadWritePtr, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, UnhandledExceptionFilter, WriteFile, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, SetUnhandledExceptionFilter, IsBadReadPtr, IsBadCodePtr, GetACP, GetOEMCP, GetCPInfo, LoadLibraryA, InterlockedExchange, VirtualQuery, InitializeCriticalSection, GetLocaleInfoA, VirtualProtect, GetSystemInfo, InterlockedIncrement
> USER32.dll: MessageBoxW, wsprintfW, GetCursorPos, GetKeyboardState, SetWindowLongW, RemovePropA, RemovePropW, GetPropA, GetPropW, CallWindowProcA, CallWindowProcW, IsWindowUnicode, SetWindowLongA
> ADVAPI32.dll: RegOpenKeyExW, RegDeleteKeyW, RegOpenKeyW, RegCreateKeyW, RegSetValueW, RegSetValueExW, RegCloseKey, RegQueryValueExW
> SHELL32.dll: DragQueryFileW, DragAcceptFiles, DragFinish

( 6 exports )
DllCanUnloadNow, DllGetClassObject, DllMain, DllRegisterServer, DllUnregisterServer, DragDropWndProc

Répondre à tribord44

22

tribord44, le 31 jan 2009 à 00:51:17

Je continue avec les 3 derniers
systeme 32\pentabledefauts

Fichier pentabletdefaults.xml reçu le 2009.01.31 00:24:17 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 0/38 (0%)
en train de charger les informations du serveur...
Votre fichier est dans la file d'attente, en position: ___.
L'heure estimée de démarrage est entre ___ et ___ .
Ne fermez pas la fenêtre avant la fin de l'analyse.
L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
les résultats seront affichés au fur et à mesure de leur génération.
Formaté Formaté
Impression des résultats Impression des résultats
Votre fichier a expiré ou n'existe pas.
Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
Email:

Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.93 2009.01.30 -
AhnLab-V3 5.0.0.2 2009.01.30 -
AntiVir 7.9.0.60 2009.01.30 -
Authentium 5.1.0.4 2009.01.30 -
Avast 4.8.1281.0 2009.01.30 -
AVG 8.0.0.229 2009.01.30 -
BitDefender 7.2 2009.01.30 -
CAT-QuickHeal 10.00 2009.01.30 -
ClamAV 0.94.1 2009.01.30 -
Comodo 954 2009.01.30 -
DrWeb 4.44.0.09170 2009.01.30 -
eSafe 7.0.17.0 2009.01.29 -
eTrust-Vet 31.6.6335 2009.01.29 -
F-Prot 4.4.4.56 2009.01.30 -
F-Secure 8.0.14470.0 2009.01.30 -
Fortinet 3.117.0.0 2009.01.30 -
GData 19 2009.01.31 -
Ikarus T3.1.1.45.0 2009.01.30 -
K7AntiVirus 7.10.611 2009.01.30 -
Kaspersky 7.0.0.125 2009.01.31 -
McAfee 5511 2009.01.30 -
McAfee+Artemis 5511 2009.01.30 -
Microsoft 1.4306 2009.01.30 -
NOD32 3813 2009.01.30 -
Norman 6.00.02 2009.01.30 -
nProtect 2009.1.8.0 2009.01.30 -
Panda 9.5.1.2 2009.01.30 -
PCTools 4.4.2.0 2009.01.30 -
Prevx1 V2 2009.01.31 -
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.30 -
Sophos 4.38.0 2009.01.31 -
Sunbelt 3.2.1835.2 2009.01.16 -
TheHacker 6.3.1.5.238 2009.01.30 -
TrendMicro 8.700.0.1004 2009.01.30 -
VBA32 3.12.8.12 2009.01.30 -
ViRobot 2009.1.30.1582 2009.01.30 -
VirusBuster 4.5.11.0 2009.01.30 -
Information additionnelle
File size: 319 bytes
MD5...: daa9239cade44d1377b1c03a96866b51
SHA1..: 4650dea2791eadbeb9341b83a4de475157481ca1
SHA256: 0ca78d560d4d3d7e2192fed26aa26cdc1d82ceb19c6c1f3d9f10c9912ee44f88
SHA512: a610e8354009929512e091169d09714852525b2bd118a136a11935169a043c6a
0bb618d07f6239942fcd64fe10e36a79f9aabd0ba2611b035cc832f51fc9f8fc
ssdeep: 6:JiMVBduhK5AjU/4RZYKm+Ne3cWR6uXKYEI/4cW6YyX0VfgNAjUT:MMHduhK5GU
/6uV+Y33XAIwsZNGUT
PEiD..: -
TrID..: File type identification
Text - UTF-8 encoded (100.0%)
PEInfo: -

Systeme32\rishellext.dll

Fichier RlShellExt.dll reçu le 2008.11.27 13:33:08 (CET)
Situation actuelle: terminé
Résultat: 1/37 (2.70%)
Formaté Formaté
Impression des résultats Impression des résultats
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.11.27.4 2008.11.27 -
AntiVir 7.9.0.35 2008.11.27 -
Authentium 5.1.0.4 2008.11.27 -
Avast 4.8.1281.0 2008.11.27 -
AVG 8.0.0.199 2008.11.27 -
BitDefender 7.2 2008.11.27 -
CAT-QuickHeal 10.00 2008.11.27 -
ClamAV 0.94.1 2008.11.27 -
DrWeb 4.44.0.09170 2008.11.27 -
eSafe 7.0.17.0 2008.11.27 -
eTrust-Vet 31.6.6233 2008.11.27 -
Ewido 4.0 2008.11.26 -
F-Prot 4.4.4.56 2008.11.26 -
F-Secure 8.0.14332.0 2008.11.27 -
Fortinet 3.117.0.0 2008.11.27 -
GData 19 2008.11.27 -
Ikarus T3.1.1.45.0 2008.11.27 -
K7AntiVirus 7.10.534 2008.11.26 -
Kaspersky 7.0.0.125 2008.11.27 -
McAfee 5446 2008.11.26 -
McAfee+Artemis 5446 2008.11.26 -
Microsoft 1.4104 2008.11.27 -
NOD32 3645 2008.11.27 -
Norman 5.80.02 2008.11.26 -
Panda 9.0.0.4 2008.11.27 -
PCTools 4.4.2.0 2008.11.27 -
Prevx1 V2 2008.11.27 -
Rising 21.05.32.00 2008.11.27 -
SecureWeb-Gateway 6.7.6 2008.11.27 -
Sophos 4.35.0 2008.11.27 -
Sunbelt 3.1.1832.2 2008.11.27 -
Symantec 10 2008.11.27 -
TheHacker 6.3.1.1.164 2008.11.27 -
TrendMicro 8.700.0.1004 2008.11.27 -
VBA32 3.12.8.9 2008.11.26 suspected of Win32.BrokenEmbeddedSignature (paranoid heuristics)
ViRobot 2008.11.27.1489 2008.11.27 -
VirusBuster 4.5.11.0 2008.11.26 -
Information additionnelle
File size: 1222576 bytes
MD5...: ef9b34bc261a009523926bbc40a43cdb
SHA1..: 2e4f8548da9a92396159cd75e3325da3af727a44
SHA256: d44a6031b620dfa2b3e93a7435d28e764a62402f3597a9da6cb66f558746946f
SHA512: 45cf778e14a52bf9b9b430f08b5537e4bfdff9ca891773d238e6e239811a6a7a
86fd9144dea264d2818c06aa8cafc5ff63bd22e7755ab0e6648a3dbc04ce6135
ssdeep: 24576:vbaVi/y+PAq5IFgxI+qo8XhzTUpaBxn44BAtuT+q2qmSez44Y2YY43Y44E
4YYaI5:zaga+wg+foitUpaDn8dNz4ANq
PEiD..: -
TrID..: File type identification
Windows OCX File (52.0%)
InstallShield setup (18.1%)
Win32 EXE PECompact compressed (generic) (17.5%)
Win32 Executable Delphi generic (6.1%)
Win32 Executable Generic (3.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4e8108
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0xe7120 0xe7200 6.56 5697c0ac28670e32dc137774046a0d94
DATA 0xe9000 0x4938 0x4a00 5.64 e2c396584dcd34b4e4e67c1b1d97e7d9
BSS 0xee000 0x1549 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0xf0000 0x2d2a 0x2e00 5.02 3d632a61e026e4e668c11d81d6c0bb97
.edata 0xf3000 0xa7 0x200 2.00 be08b27511529b2dbbe44dd059970b3a
.reloc 0xf4000 0x11f84 0x12000 6.65 43ad1bf2ca3220bb8edf90b2b8931949
.rsrc 0x106000 0x2860c 0x28800 5.90 202ea4e32eeff03c9b57ff7d9c6de959

( 21 imports )
> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, ExitThread, CreateThread, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle
> user32.dll: GetKeyboardType, LoadStringA, MessageBoxA, CharNextA
> advapi32.dll: RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> oleaut32.dll: SysFreeString, SysReAllocStringLen, SysAllocStringLen
> kernel32.dll: TlsSetValue, TlsGetValue, TlsFree, TlsAlloc, LocalFree, LocalAlloc
> user32.dll: WindowFromPoint, WinHelpA, WaitMessage, WaitForInputIdle, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCursor, SetWindowsHookExA, SetWindowTextA, SetWindowPos, SetWindowPlacement, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetMenuItemInfoA, SetMenuItemBitmaps, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClipboardData, SetClassLongA, SetCapture, SetActiveWindow, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostThreadMessageA, PostQuitMessage, PostMessageA, PeekMessageA, OpenClipboard, OffsetRect, OemToCharA, MsgWaitForMultipleObjects, MessageBoxExA, MessageBoxA, MessageBeep, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetWindowDC, GetUserObjectInformationA, GetTopWindow, GetThreadDesktop, GetSystemMetrics, GetSystemMenu, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassNameA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, EmptyClipboard, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawFocusRect, DrawEdge, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreateWindowExA, CreatePopupMenu, CreateMenu, CreateIcon, CopyImage, CopyIcon, CloseClipboard, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerBuffA, CharLowerA, CharUpperBuffA, CharUpperA, AdjustWindowRectEx, ActivateKeyboardLayout
> gdi32.dll: UnrealizeObject, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, Rectangle, RectVisible, RealizePalette, Polyline, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, LPtoDP, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsA, GetTextExtentPointA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetPixel, GetPaletteEntries, GetObjectType, GetObjectA, GetNearestPaletteIndex, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, GdiFlush, ExcludeClipRect, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, BitBlt
> kernel32.dll: lstrcpynW, lstrcpyA, WritePrivateProfileStringA, WriteFile, WaitForSingleObject, VirtualQuery, VirtualAlloc, TerminateThread, Sleep, SizeofResource, SetThreadPriority, SetThreadLocale, SetLastError, SetFilePointer, SetFileAttributesA, SetEvent, SetErrorMode, SetEndOfFile, ResumeThread, ResetEvent, ReleaseMutex, ReadFile, OpenFileMappingA, OpenEventA, MultiByteToWideChar, MulDiv, MoveFileExA, MapViewOfFile, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalSize, GlobalReAlloc, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetWindowsDirectoryA, GetVersionExA, GetVersion, GetTickCount, GetThreadLocale, GetTempPathA, GetSystemInfo, GetSystemDirectoryA, GetStringTypeExA, GetStdHandle, GetShortPathNameA, GetProcAddress, GetPrivateProfileStringA, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesW, GetFileAttributesA, GetExitCodeThread, GetExitCodeProcess, GetEnvironmentVariableA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCPInfo, GetACP, FreeResource, InterlockedIncrement, InterlockedExchange, InterlockedDecrement, FreeLibrary, FormatMessageA, FindResourceA, FindNextFileA, FindFirstFileA, FindClose, FileTimeToLocalFileTime, FileTimeToDosDateTime, ExpandEnvironmentStringsA, EnumCalendarInfoA, EnterCriticalSection, DisableThreadLibraryCalls, DeleteFileA, DeleteCriticalSection, CreateThread, CreateProcessA, CreateMutexA, CreateFileMappingA, CreateFileA, CreateEventA, CreateDirectoryA, CopyFileA, CompareStringW, CompareStringA, CloseHandle
> advapi32.dll: RegSetValueExA, RegQueryValueExA, RegQueryInfoKeyA, RegOpenKeyExA, RegOpenKeyA, RegFlushKey, RegEnumKeyExA, RegDeleteValueA, RegDeleteKeyA, RegCreateKeyExA, RegCreateKeyA, RegCloseKey, IsValidSecurityDescriptor, CreateProcessAsUserW
> oleaut32.dll: CreateErrorInfo, GetErrorInfo, SetErrorInfo, RegisterTypeLib, LoadTypeLib, SysFreeString
> ole32.dll: ReleaseStgMedium, CoTaskMemFree, CoCreateGuid, CLSIDFromString, StringFromCLSID, CoCreateInstance, CoLockObjectExternal, CoDisconnectObject, CoRevokeClassObject, CoRegisterClassObject, CoUninitialize, CoInitialize, IsEqualGUID
> ole32.dll: IsEqualGUID
> kernel32.dll: Sleep
> oleaut32.dll: SafeArrayPtrOfIndex, SafeArrayPutElement, SafeArrayGetElement, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayRedim, SafeArrayCreate, VariantChangeTypeEx, VariantCopyInd, VariantCopy, VariantClear, VariantInit
> comctl32.dll: ImageList_Duplicate, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_GetIcon, ImageList_Remove, ImageList_DrawEx, ImageList_Replace, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create, InitCommonControls
> shell32.dll: Shell_NotifyIconA, ShellExecuteExA, SHGetFileInfoA, DragQueryFileW, DragQueryFileA
> shell32.dll: SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHGetPathFromIDListA, SHGetMalloc, SHChangeNotify
> advapi32.dll: OpenServiceA, OpenSCManagerA, ControlService, CloseServiceHandle
> winmm.dll: timeGetTime
> kernel32.dll: GetVersionExA
> AM.DLL: RL_R3_SendUnprivilegedRequestToDriver, RL_R3_SetNominalTrust_FileTag, RL_R3_GetProgTrustAttributes, RL_IsTrustGroupConfined, RL_GetTrustGroupFromId

( 4 exports )
DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer

Et enfin wiewer\exif.htm

Répondre à tribord44

23

tribord44, le 31 jan 2009 à 00:54:31

Le dernier n'est pas passer ,
wiewer\exif.htm

Fichier EXIF.htm reçu le 2009.01.31 00:33:35 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 0/39 (0%)
en train de charger les informations du serveur...
Votre fichier est dans la file d'attente, en position: 4.
L'heure estimée de démarrage est entre 63 et 90 secondes.
Ne fermez pas la fenêtre avant la fin de l'analyse.
L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
les résultats seront affichés au fur et à mesure de leur génération.
Formaté Formaté
Impression des résultats Impression des résultats
Votre fichier a expiré ou n'existe pas.
Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
Email:

Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.93 2009.01.30 -
AhnLab-V3 5.0.0.2 2009.01.30 -
AntiVir 7.9.0.60 2009.01.30 -
Authentium 5.1.0.4 2009.01.30 -
Avast 4.8.1281.0 2009.01.30 -
AVG 8.0.0.229 2009.01.30 -
BitDefender 7.2 2009.01.30 -
CAT-QuickHeal 10.00 2009.01.30 -
ClamAV 0.94.1 2009.01.30 -
Comodo 954 2009.01.30 -
DrWeb 4.44.0.09170 2009.01.30 -
eSafe 7.0.17.0 2009.01.29 -
eTrust-Vet 31.6.6335 2009.01.29 -
F-Prot 4.4.4.56 2009.01.30 -
F-Secure 8.0.14470.0 2009.01.30 -
Fortinet 3.117.0.0 2009.01.30 -
GData 19 2009.01.31 -
Ikarus T3.1.1.45.0 2009.01.30 -
K7AntiVirus 7.10.611 2009.01.30 -
Kaspersky 7.0.0.125 2009.01.31 -
McAfee 5511 2009.01.30 -
McAfee+Artemis 5511 2009.01.30 -
Microsoft 1.4306 2009.01.30 -
NOD32 3813 2009.01.30 -
Norman 6.00.02 2009.01.30 -
nProtect 2009.1.8.0 2009.01.30 -
Panda 9.5.1.2 2009.01.30 -
PCTools 4.4.2.0 2009.01.30 -
Prevx1 V2 2009.01.31 -
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.30 -
Sophos 4.38.0 2009.01.31 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.01.31 -
TheHacker 6.3.1.5.238 2009.01.30 -
TrendMicro 8.700.0.1004 2009.01.30 -
VBA32 3.12.8.12 2009.01.30 -
ViRobot 2009.1.30.1582 2009.01.30 -
VirusBuster 4.5.11.0 2009.01.30 -
Information additionnelle
File size: 444 bytes
MD5...: 4ac4bb042ce43d7ac18c3697def5238f
SHA1..: 6323f88d00f451258d01d45a12767e2bd06731e8
SHA256: 7b914e07a899234e8e85a5d353e20746dc5f09db31fe708266175395f98934f4
SHA512: 21a6eee84dd16d8e2ccc52c1c1bcf13f2fd2d53de6bfd4881392427740106b81
f1f8573ba19379d88d75163ede52d1a099c48938a703766860e95d601e975727
ssdeep: 6:nXxp728TwabSQIq28CYRGabSQIwLLpPzt+TgMNwWFKJYRoHsbWj20DTJQEXQ7Q
Ds:38gjISRGgjIYPzK2uRvbWj3JQ7inTOMa
PEiD..: -
TrID..: File type identification
Unknown!
PEInfo: -

Répondre à tribord44

24

tribord44, le 31 jan 2009 à 01:06:13

Voici maintenant le rapport de genproc
et ce sera tous pour ce soir , merci de ton aide et a demain.

Rapport GenProc 2.351 [1] - 31/01/2009 - Windows XP

Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Par la suite, laisse-le avec ses réglages par défaut. C'est tout.


# Etape 1/ Télécharge :

- SDfix http://downloads.andymanchesta.com/RemovalTools/SDFix.exe (Andy Manchesta) et sauvegarde le sur ton Bureau.
Double clique sur SDFix.exe et choisis "Install" pour l'extraire dans C:\.


Redémarre en mode sans échec comme indiqué ici http://www.pcloisirs.eu/mode_sans_echec.htm ; pour retrouver le rapport, clique sur le raccourci "GenProc" sur ton bureau. Choisis ta session courante *** M VOILLET ***


# Etape 2/

Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.cmd pour lancer le script.
- Appuie sur Y pour commencer le processus de nettoyage.
- Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche
pour redémarrer, fais-le pour redémarrer le PC.
- Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
- Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.br />- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.br />- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.

# Etape 3/

Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

# Etape 4/

Redémarre normalement et poste, dans la même réponse :

- Le contenu du fichier Report.txt;
- Un nouveau rapport HijackThis http://tinyurl.com/GenProc-HijackThis ;

Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

____________________________________________________________________________________________________________

Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com

Répondre à tribord44

25

sKe69, le 31 jan 2009 à 01:07:44

BIen ... rien d'infectieux du côté de ces fichiers ...


la suite pour demain .... dans l'ordre :


1-Télécharge ToolsCleaner (de A.Rothstein) sur ton Bureau.
http://pc-system.fr/TC/ToolsCleaner2.exe

Déconnecte toi et ferme bien toutes tes applications en cours .

Lances le .
*Clique sur Recherche et laisse le scan se terminer (cela peut être long).
*Clique sur Suppression pour finaliser.
*Clique sur "quitter" pour générer un rapport ( et pas sur la croix rouge !) :
--> Poste ce rapport : il se trouve à la racine de ton disque dur -> C:\TCleaner.txt .

Note : Ce petit soft va te nettoyer tout les trucs dont on c'est servi pour la désinfection .
Supprime tout les outils , dossiers ou rapports consernant la désinfection que Toolscleaner2 n'a pas supprimé .

( garde CCleaner et Malwarebytes : très utiles ! )

======================================

2- Refais un coup de CCleaner ( registre compris ) .

======================================

3- Retélécharge et réinstalle hijackthis ( car supprimé par Toolscleaner2 ) ,

Télécharge et installe le logiciel HijackThis :

ici ftp://ftp.commentcamarche.com/download/HJTInstall.exe
ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
ou ici http://www.clubic.com/lancer-le-telechargement-51452-0-hijackthis.html

-> Clique sur le setup pour lancer l'installe : laisse toi guider et ne modifie pas les paramètres d'installation .
A la fin de l'installe , le prg ce lance automatiquement : ferme le en cliquant sur la croix rouge .
Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
"C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

( ne fais pas de scan pour le moment )

======================================

4- Important :
Purge de la restauration système
*Désactive ta restauration :
Clique droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
---> Redémarre ton PC ...

*Réactive ta restauration :
Clique droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
--->Redémarre ton PC ...

( Note : tu peux aussi y accéder via panneau de configuration->" système "->" restauration système " ).


======================================

5- Fais ce scan en ligne pour vérifier :

( ne rien faire d'autre avec le PC durant le scan ! )

Fais un scan en ligne avec Kaspersky : http://webscanner.kaspersky.fr/
- Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.
Le scan ne marche que sous Internet Explorer(et pas sous firefox ou autre...).
- On va te demander de télécharger un contôle active x, accepte .
- Dans le menu Choisissez la cible de l'analyse, sélectionne Poste de travail. Le scan va commencer.
- Sauvegarde le rapport qui sera généré, puis copie/colle le dans ta prochaine réponse pour analyse et attends la suite ...

--> tuto :
http://www.malekal.com/scan_Av_en_ligne.html#mozTocId291566

Note :
*Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.

*S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : http://www.inoculer.com/activex.php3
Rappel : le scan est à faire sous Internet Explorer !




"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

26

tribord44, le 31 jan 2009 à 08:22:46

Bonjour ske69
Je continue donc , j'ai passer toolsCleaner , tout a bien été désinstallé sauf combofix ; je l'ai donc relancé une deuxième fois ,même chose.Le rapport est donc celui du deuxième passage .
Je continue..

[ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\Documents and Settings\M V\Bureau\ComboFix.exe: trouvé !

---------------------------------
-->- Suppression:

C:\Documents and Settings\M V\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!

Répondre à tribord44

27

tribord44, le 31 jan 2009 à 08:46:46

J'en suis à l'étape 4 mais avant de purger la restauration, j'attends de savoir ce que je doit faire pour combofix.
-A propos à chaque réparation du registre avec c.cleaner je sauvegarde la modif, mais le fichier de sauvegarde est sur le bureau ; à quel endroit doit il se trouver réellement?

Répondre à tribord44

28

sKe69, le 31 jan 2009 à 08:56:58

Salut,

pour Combofix , tu supprimes manuellement ( clique droit dessus / supprimer )


A propos à chaque réparation du registre avec c.cleaner

-> tu sauvegardes où tu veux ! ^^ ... garde uniquement une sauv. ou 2 , les dernières ... c'est juste au cas ou il y est un prb ( backup ) .



donc tu peux passer à la suite .... ;)


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

29

tribord44, le 31 jan 2009 à 12:57:43

Voila qui est fait après qq problèmes avec kapersky le scan est enfin terminé mais impossible de l'éditer
je vais donc juste le recopier, mauvaise nouvelle la bestiole est toujours là.

Total fichiers analysés 103294
nombre de virus trouvés 1
nombre objet infectés 5
nombreobjet suspects 0

durée de l'analyse 02.07.49

Répondre à tribord44

30

sKe69, le 31 jan 2009 à 13:09:18

Il me faut le rapport complet !

Avec le détaille pour voir quelle bestiole et où ! ... ;)


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

31

tribord44, le 31 jan 2009 à 13:16:52

C'est tous ce que j'ai d'affiché et n'est rien qui m'indique un quelconque rapport.
avec d'afficher en bas de la fenêtre "terminé"
Je n'ai pas du tous eu la fenêtre rapport comme dans le tuto.
doit-je recommencer le scan?

Répondre à tribord44

32

sKe69, le 31 jan 2009 à 13:45:30

Malheureusemnt oui ...

il me faut absolument le détaille ...

expl d'un rapport complet ici :
http://www.commentcamarche.net/forum/affich 10693133 c resycled boot com n est pas une applicatio?page=3#77

A tout' ... ;) "Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

33

tribord44, le 31 jan 2009 à 16:03:55

Voila cette fois j'ai bien eu le rapport:

Saturday, January 31, 2009 3:58:30 PM
Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version : 5.0.84.2
Dernière mise à jour de la base antivirus Kaspersky : 31/01/2009
Enregistrements dans la base antivirus Kaspersky : 1560247
Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie vrai
Cible de l'analyse Poste de travail
A:\
C:\
D:\
E:\
Statistiques de l'analyse
Total d'objets analysés 103381
Nombre de virus trouvés 1
Nombre d'objets infectés 5 / 0
Nombre d'objets suspects 0
Durée de l'analyse 02:06:15

Nom de l'objet infecté Nom du virus Dernière action
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\S­ystemIndex\SystemIndex.3.Crwl L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\S­ystemIndex\SystemIndex.3.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010001.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010002.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010003.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010004.ci L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010004.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010004.wsb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010005.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010006.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010007.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010008.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010009.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\0001000A.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\0001000B.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\0001000C.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\0001000D.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\0001000E.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010011.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010013.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010015.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\00010016.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\0001001B.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\0001001C.wid L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\Indexer\CiFiles\INDEX.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\PropMap\CiPT0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\PropMap\Used0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\SecStore\CiST0000.000 L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\SystemIndex.chk1.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\SystemIndex.chk2.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\Sys­temIndex\SystemIndex.Ntfy2.gthr L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_6­28.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\cert8.db L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\content-prefs­.sqlite L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\cookies.sqlit­e L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\downloads.sql­ite L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\formhistory.s­qlite L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\key3.db L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\parent.lock L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\permissions.s­qlite L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\places.sqlite­ L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\places.sqlite­-journal L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\search.sqlite­ L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Thunderbird\Profiles\e75ec4mo.default\cert8.db L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Application Data\Thunderbird\Profiles\e75ec4mo.default\key3.db L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Thunderbird\Profiles\e75ec4mo.default\Mail\Local Folders\Inbox.msf L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Application Data\Thunderbird\Profiles\e75ec4mo.default\Mail\Local Folders\Trash.msf L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Thunderbird\Profiles\e75ec4mo.default\panacea.dat L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Thunderbird\Profiles\e75ec4mo.default\parent.lock L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Application Data\Thunderbird\Profiles\e75ec4mo.default\urlclassifier2.sq­lite L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\Cache\_CACHE_­001_ L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\Cache\_CACHE_­002_ L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\Cache\_CACHE_­003_ L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\Cache\_CACHE_­MAP_ L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\urlclassifier­3.sqlite L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\Application Data\Mozilla\Firefox\Profiles\3yjoftio.default\XUL.mfl L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\temp\etilqs_qN2bf9kb1lCIXiqFrbMr L'objet est verrouillé ignoré
C:\Documents and Settings\M V\Local Settings\temp\~DF57E1.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\M VT\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar/Kodak Digital GEM, GEM Airbrush, ROC, SHO Professional 2.0.0/Filtros/Azulejos.8BF Infecté : Rootkit.Win32.TDSS.eyj ignoré
C:\Documents and Settings\M V\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar/Kodak Digital GEM, GEM Airbrush, ROC, SHO Professional 2.0.0/Filtros/Onda.8BF Infecté : Rootkit.Win32.TDSS.eyj ignoré
C:\Documents and Settings\M V\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar/Kodak Digital GEM, GEM Airbrush, ROC, SHO Professional 2.0.0/PlugIns/Filtros/Azulejos.8BF Infecté : Rootkit.Win32.TDSS.eyj ignoré
C:\Documents and Settings\M V\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar/Kodak Digital GEM, GEM Airbrush, ROC, SHO Professional 2.0.0/PlugIns/Filtros/Onda.8BF Infecté : Rootkit.Win32.TDSS.eyj ignoré
C:\Documents and Settings\M VT\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar RAR: infecté - 4 ignoré
C:\Documents and Settings\M V\ntuser.dat L'objet est verrouillé ignoré
C:\Documents and Settings\M V\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\00000002.ps1 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\00000002.ps2 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\00010003.ci L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\cicat.fid L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\cicat.hsh L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiCL0001.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiP10000.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiP20000.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiPT0000.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiSL0001.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiSP0000.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiST0000.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\CiVP0000.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\INDEX.000 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\propstor.bk1 L'objet est verrouillé ignoré
C:\System Volume Information\catalog.wci\propstor.bk2 L'objet est verrouillé ignoré
C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
C:\System Volume Information\_restore{F568A057-78BA-4D59-9E67-737FA3C6BEFE}\R­P1\change.log L'objet est verrouillé ignoré
C:\WINDOWS\$_hpcst$.hpc L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\Temp\Perflib_Perfdata_704.dat L'objet est verrouillé ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
Analyse terminée.

Répondre à tribord44

34

sKe69, le 31 jan 2009 à 17:34:43
  • +1

Bien ...

un crak qui contient une des plus grosses saloperies du momment .... ^^


cela pourrai être intéressant pour des recherches ....


si cela te dérage pas , je vois avec mon entourage et donne la suite ... ;)



"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

35

sKe69, le 31 jan 2009 à 17:46:48
  • +1

Bien ...

en attendant , fait ce qui suit :


Télécharge OAD ( par !aur3n7) : http://sosvirus.changelog.fr/OAD.exe
----> Enregistre le sur ton bureau .

Double clique sur l'icone OAD pour le lancer

- nom du fichier à rechercher :
--> tape ou fais un copier coller de : TDSS

- Type de recherche : sélectionne l'option 6 puis valide ["entrée"]

OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ait terminé.
Le rapport de recherche s'affichera automatiquement à l’écran dès qu'il aura terminé.

Note : suivant la taille des disques durs cette recherche peut prendre plusieurs minutes. Sois patient ...

->Sauvegarde ce rapport sur ton Bureau et fais un copier / coller de celui-ci dans ta prochaine réponse ...


Puis recommence avec :

UAC

et

msqpdx


Poste moi les 3 rapports obtenu et attends la suite ...

"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

36

tribord44, le 31 jan 2009 à 19:05:56
  • +1

Voici le rapport pour TDSS
31/01/2009 ---- 18:57:57,21

----------------------------------
§§§§§§ [TDSS] §§§§§§
----------------------------------
[X] Registre

-------------- [ ] rapide
-- Fichier --- [ ] disque systeme
------------- [X] complete


********************
[Registre]
********************

Aucune entrée détectée

*******************
[Fichier]
*******************



*********************
[Même date]
*********************

Aucun fichier créé à la même date détecté


Outil Aide Diagnostic By !aur3n7 Version 1.1
----------------------------------
§§§§§ Fin Rapport §§§§§
----------------------------------


Pour UAC

31/01/2009 ---- 18:51:44,37

----------------------------------
§§§§§§ [UAC] §§§§§§
----------------------------------
[X] Registre

-------------- [ ] rapide
-- Fichier --- [ ] disque systeme
------------- [X] complete


********************
[Registre]
********************


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\G­emini\0.1\Preferences\PluginHandlerData\PluginInfo0]
@="{PluginFilename~Sgct23201.dll~ComponentCLSID~XQH3lPnIR1BGVIwDQtxQWiQ==}{PluginFilename~Sgct23201.dll~ComponentCLSID~Xgny3XaugdkSObWS2WDj03w==}{PluginFilename~Sgct23201.dll~ComponentCLSID~XoAeOu/I5CUOG84VLTV44Yg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Sgct23201.dll~ComponentCLSID~XxS3v8m4Xq0G3puw46Y9RJw==}{PluginFilename~Sgct23201.dll~ComponentCLSID~XbF7coL0ThEi9r552f7jDfA==}{PluginFilename~Sgct23201.dll~ComponentCLSID~XCCNMXSQkR0mmU2fzP5Mthw==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Sgema3201.dll~ComponentCLSID~XGHQWub3CeEOqDDSz+2pF3Q==}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Sgema3201.dll~ComponentCLSID~XwGi80LkJ1BGVCwDQtxAxsg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Sgema3201.dll~ComponentCLSID~XUF1EX0I71BGVdwCQJ2IV7g==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Sgemx3201.dll~ComponentCLSID~XAuwsmEQg1BGt2wDQtwd23Q==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Slocd3210.dll~ComponentCLSID~XOuo+6X5T70SIxZUtI+X6pg==}{PluginFilename~Slocd3210.dll~ComponentCLSID~XUtkdWG9Rlki+svUqznoyQw==}{PluginFilename~Slocd3210.dll~ComponentCLSID~XQcDz3NePE0GRtf/k7fE/NQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/..."

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\RealPlayer\6.0\Preferences\PluginHandlerData\PluginInfo1]
@="60.dll~ComponentCLSID~XSBEnizj/e0SMai9M0xttvg==}{PluginFilename~Spdge3260.dll~ComponentCLSID~X7+uh6tBiLU2MoazixTQDGA==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XkyCVjMQjcUCE/lunUP7wAw==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XMjR1D1k+VEmuPT75I0Y/Jg==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XP+H3V6sA10armDaPhZ4nxQ==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XPtDm50s87UGMwYaDb+F6Fw==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XTLnRn6VvSEut8o6glM21HA==}{PluginFilename~Spdge3260.dll~ComponentCLSID~X1vPFqZgTp0am43ZV3fr/sQ==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XnnyxE35uGUa/Scoat4uKWw==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XYESnXD2eFkmXNfZ7VElvHQ==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XruZ0EeUqfk+9x9l8LSoGaQ==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XR3Oq1Y9WYUykd7ZyWdqwPg==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XoV+htYhiL0eHroz0KCdYZQ==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XM2npXXRRuU2hFmhgiOEcJA==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XIEsnpsj5Uk+Qy5bPnoNIoA==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XgEpGE99GwECoXFlmirkmZg==}{PluginFilename~Spdge3260.dll~ComponentCLSID~Xw1zPyZbws02vFCqdaC4x7Q==}{PluginFilename~Spdge3260.dll~ComponentCLSID~XashVQi4uuUut/E74P4fbfw==}{PluginFilename~Spdge3260.dll~ComponentCLSID~Xx/DkPePZe0KyfCtRZgd37w==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~X49A3zGio6k2D0Bu6HLAf+A==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~XNP/S/296Mk6J2n3OGVZB/g==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~XkK9ud9qZHUy+p+W/gjcdIg==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~XIK1426CluEidsGRuiCY/XQ==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~XoC9nafprrEKZTskW+xgIhA==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~XDGYicXmpTEO1o4SRKybteg==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~X/OeeNwm53UOS0j9tBasTNw==}{PluginFilename~Spdwmdm.dll~ComponentCLSID~X+d/RJKipg02OGYKEpXxqiQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srjbc3260.dll~ComponentCLSID~XmBytOtati0OhN++SvsO/cQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srjbc3260.dll~ComponentCLSID~X92zCN4dO1UGQrwMhyd3qRA==}{PluginFilename~Srjbc3260.dll~ComponentCLSID~XRO5h/4NjKUGTIu61HzkU9g==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srjbc3260.dll~ComponentCLSID~XnrIlF+oHxE2GqRsLFACNiA==}{PluginFilename~Srjbc3260.dll~ComponentCLSID~Xmbrbbw96aUqWw22s4eMi5Q==}{PluginFilename~Srjbc3260.dll~ComponentCLSID~XMERKAJhTbkaaKxDSioA8Aw==}{PluginFilename~Srjbc3260.dll~ComponentCLSID~XSJ5j1v59l0unfPVzm0+yfg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srjbdll.dll~ComponentCLSID~XestUe5fH4EKYbS7/PbC/dg==}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srjbdll.dll~ComponentCLSID~XHYlERg0I4UarpgXQ9KcTPg==}{PluginFilename~Srjbdll.dll~ComponentCLSID~XPmjzWBzeCUer0rmiE0qMHw==}{PluginFilename~Srjbdll.dll~ComponentCLSID~XayFacM2HdE21Dt8n1hM61A==}{PluginFilename~Srjbdll.dll~ComponentCLSID~XzELQyOv7l0C8bWNWyL9hrg==}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srjbs3260.dll~ComponentCLSID~X2AZolTjB00ytpr/YMHENmQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~Xs3RTL5fZYUWCRRX5ihvOEA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~XZp0X+N6wEEiYRRq4BcuRww==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~XSPeZpO9Jh0eIgzvtc0Z2sg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~X+Fgg5xVVBUOz3jviwehu2Q==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~XysvYYzK0akGmwJ72SlKWKA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~XI7gO9txx8UKqGyUF1Hsaxw==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XiRT3Bv9DbEKU6Ux1TCelAQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpap3260.dll~ComponentCLSID~XIzecvUPgJEOoGqR7csQn1w==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XqFzhbIWh9Uid7fqzMhBqHw==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XW/fye8K2K02EFNJ085fEkA==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XswfKoCgdbUONJGSl+phlcA==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XtrTzYPxdw0yef1NP/XrD+g==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XSPWYqsyRWEGoSs+/mt4Dzg==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XcYYA5t2snkS9O1tYFLAMWA==}{PluginFilename~Srpap3260.dll~ComponentCLSID~X9jYD3CW+RkKxtXXtw5BtRw==}{PluginFilename~Srpappdemon.dll~ComponentCLSID~Xk3FTTq3it0SiNCfo8ZIVxA==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XgOZpQdC+SEWsq9SN/Op5RQ==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XFDdHvbNxHkqT4BuHjkzt+A==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XczBEpUJvU02oAvL4iVlNcw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XgqT4AiKWCk+PybAXCGifDg==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XL2RxoqZeCUeHgGP36kqTTw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XYK0zn7y88E22vsF6Byr6nA==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X8FzB82X+0hGn5gDA8DGKWQ==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XXA2J8mqqhkWpwJW26g33yw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XTIwar04ck0qIPBYr5jNMEQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X/WH7sw5ow0+A/xDfxgcPyA==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XBpDcEXSyPkiVJc4PM7umig==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XBRQiAUmJZU2lHB48kePS/Q==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XIjUyT2m3ekex63CnHUdTqw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XZhwZyHMNf067q2b4nIJnOw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X5SpD4VMbpkGeXpxiTEl/Mg==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X7KRU02R7Nk2cDmFSFg44vw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XDKRe4zjTzECcT2YRTzLr4A==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XAcANo9F01RGttgDA8ECmGg==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XNeJ5c+I/mUCVwo6BPHFqww==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X9T6V8ARhG0C7EC99zfzJag==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XFAO0kbReVE+bDCa1RKL1mQ==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XrO9TAK+y9E24XPD+e65wMQ==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XYlWJbkSupUCbHvz/ziH2qQ==}{PluginFilename~Srpcomproxy.dll~ComponentCLSID~X2qIcFVxQXEezOjUN9G5p/A==}{PluginFilename~Srpcomproxy.dll~ComponentCLSID~X4g05z8xrek2FBGMVX0aiYw==}{PluginFilename~Srpcomproxy.dll~ComponentCLSID~XoNIJGJFgnUa9hUKrg2JaWw==}{PluginFilename~Srpcomproxy.dll~ComponentCLSID~XhWryN5xzl0KOBMaslKhI1A==}{PluginFilename~Srpds3260.dll~rpplayersupportedextensions~Savi|vob|dat|divx|mid|midi|mpg|mpeg~rpplayersupportedmimetypes~Svideo/msvideo~rpplayersupportedprotocols~Sfile~rpplayersupportedtracktypes~SDVD|VCD~ComponentCLSID~X+MtPZlfg+k+1+EPeGsyQrQ==}{PluginFilename~Srpds3260.dll~ComponentCLSID~X7an57I/tbkq86wihSA4CIA==}{PluginFilename~Srpds3260.dll~ComponentCLSID~XxgJgPrysRkaz9z5brFDy6g==}{PluginFilename~Srpds3260.dll~ComponentCLSID~XT3lC6KX0uk6vnHXjcOrxOg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpgu3260.dll~ComponentCLSID~XtanxWFEX6UaOn0X+JEA4QA==}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpgu3260.dll~ComponentCLSID~XK7jUcv+oFEKADaWSakhqAA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpfindactor~PluginFilename~Srpgu3260.dll~"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\RealPlayer\6.0\Preferences\PluginHandlerData\PluginInfo2]
@="ComponentCLSID~XK8ioeCmmkk6ONeACkFWvww==}{PluginFilename~Srpgu3260.dll~ComponentCLSID~X3gQ5xsf90U+W4cCJ+TgOwQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpgu3260.dll~ComponentCLSID~Xsh/iP2RR9kKeT5PvpzY1Aw==}{PluginFilename~Srpho3260.dll~ComponentCLSID~XSerXClIa5UGgfJWMjfN48A==}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpme3260.dll~ComponentCLSID~XW0BEsXnccU+EPVTdSrIu/g==}{PluginFilename~Srpme3260.dll~ComponentCLSID~X7EeHKHE7u0WI+Xqu2l1c2Q==}{PluginFilename~Srpme3260.dll~ComponentCLSID~XQAMgPJRQakGWwe33tXz/ug==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpmn3260.dll~ComponentCLSID~XxG2tXdTZ6Em+aKDXssS7zw==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpmn3260.dll~ComponentCLSID~XMLQxPP8/4U2E5MvxvwtqLQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpms3260.dll~ComponentCLSID~XGshHOl6rs0yOPnVG7oPpBA==}{PluginFilename~Srpms3260.dll~ComponentCLSID~XILF0DZUxzU+l2cbNjFlzbg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpqt3260.dll~rpplayersupportedextensions~Smov|qt|m4p~rpplayersupportedmimetypes~Svideo/quicktime~rpplayersupportedprotocols~Sfile~rpplayersupportedtracktypes~S~ComponentCLSID~XtRwGcXOwFk6w6gu0DVQIlg==}{PluginFilename~Srpqt3260.dll~ComponentCLSID~XO+gp1VyqI06uG3mNYan8qg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~X5vxVOzgNcUqpoyl7Q7e0sw==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XLhowymlOkUO/leM+ZNYDBg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XCDDv6eb43EevaeRqMzs4cg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~X5RNh5lFrkUuwvVv3j6kayA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~X1+Ptp0tU+ESxTIvEQynMcg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~Xg/DDX94p2U6LKMuuDjbFRw==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XwahR37unTUGktUnlFpYBqg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XJUngz8UC10i3u+p68xDosg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~Xt+SFQz/Bt0ajeaWzxN28Pw==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XPsT956LGwECRvLYogoMblA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XsBhB/KkYDEO1rxLKpRCsgQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srput3260.dll~ComponentCLSID~Xv1pmZVWVxk6gxbtfEsO3cw==}{PluginFilename~Srput3260.dll~ComponentCLSID~XxluxbMl4kkyfpgkcgyX2Zw==}{PluginFilename~Srput3260.dll~ComponentCLSID~Xs8tdAIibNkyNJqUEgH9P6w==}{PluginFilename~Srput3260.dll~ComponentCLSID~XWZMlMEhe0U6hvd3KvjYchA==}{PluginFilename~Srput3260.dll~ComponentCLSID~XzTigFguAlEG2Ds3IG7VONQ==}{PluginFilename~Srput3260.dll~ComponentCLSID~X1j1AfirEbkmxjw4Y89IJoA==}{PluginFilename~Srput3260.dll~ComponentCLSID~X66z+5aHb+0mvxbIzLJAaHg==}{PluginFilename~Srput3260.dll~ComponentCLSID~XhFiqIL+6iUWZctgF/K/Keg==}{PluginFilename~Srput3260.dll~ComponentCLSID~XscQ1qEZdxUaFEGxLfCi6IA==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpwe3260.dll~ComponentCLSID~XGGW8hodC1UCNbDGV2tJyYg==}{PluginFilename~Srpwe3260.dll~ComponentCLSID~XATFzc7sL0UOZquKNwItebQ==}{PluginFilename~Srpwe3260.dll~ComponentCLSID~Xry7oYutEkU+w7/Sg9MOziQ==}{PluginFilename~Srpwe3260.dll~ComponentCLSID~X8KCvv9eA60mL4cJ5nL5rtg==}{PluginFilename~Srpwe3260.dll~ComponentCLSID~XDoCfxTdaI0qRIv3YYdL+Pg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srpwe3260.dll~ComponentCLSID~X0Qi6pmWoy0yrEt3JZ5gPug==}{PluginFilename~Srpwe3260.dll~ComponentCLSID~X4D7ttnuqUkCXx/FwBGG4yA==}{PluginFilename~Srpwe3260.dll~ComponentCLSID~XMUk8AWCpHk2ZG3jFtfjG1A==}{PluginFilename~Srpwm3260.dll~rpplayersupportedextensions~Sasf|wma|wmv|asx|wm|wax|wvx|wmx~rpplayersupportedmimetypes~Svideo/x-ms-asf|audio/x-ms-wma|audio/x-ms-wax|video/x-ms-wmv|video/x-ms-wm|video/x-ms-wmx|video/x-ms-wvx|application/x-mplayer2~rpplayersupportedprotocols~Sfile|http|mms~ComponentCLSID~X+dDoLF3uxUuiqoBLgyzS0A==}{PluginFilename~Srpwm3260.dll~ComponentCLSID~Xwmd4yQR9bkSHntMCOe50sg==}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Stmde3210.dll~ComponentCLSID~XcvLfKM+peki4cfa2G6uLpQ==}{PluginFilename~Stmde3210.dll~ComponentCLSID~Xf+jSozDPlU6YtoxZJn2ZWg==}{ComponentName~Shttp://ns.real.com/...}28872"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\PluginHandlerData\PluginInfo0]
@="{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{IRCAPreferencable~SPrefPage~PluginFilename~Sfaus3270.dll~ComponentCLSID~X9OLiGhXqhkK5x1PN5rvdkA==}{ComponentName~Shttp://ns.real.com/...}{IRCAPreferencable~SPrefPage~PluginFilename~Sfaus3270.dll~ComponentCLSID~XMGmJQyN2r0WH8nUP9+Rw7A==}{IRCAPreferencable~SChinPrefPage~PluginFilename~Sfaus3270.dll~ComponentCLSID~XMGmJQyN2r0WH8nUP9+Rw7A==}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Spnmi3270.dll~ComponentCLSID~XAIl1dDY00RGl6ABgl+V8eA==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srnms3270.dll~ComponentCLSID~XAAcAACNhUBR86gcLGANqdg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srnms3270.dll~ComponentCLSID~XcIeai85e1RGTRAACswf0Gg==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{IRCAPreferencable~SPrefPage~PluginFilename~Srnms3270.dll~ComponentCLSID~XjuFS/mAVu0mjA4fOfoKUKQ==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Srnqu3270.dll~ComponentCLSID~XQ2ZxNDHI0hGzOQDA8DGHmA==}{PluginFilename~Srnqu3270.dll~ComponentCLSID~XQAVqLjjf0xGU6ADQtyOttQ==}{PluginFilename~Srnqu3270.dll~ComponentCLSID~XQWZxNDHI0hGzOQDA8DGHmA==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{IRCAPreferencable~SPrefPage~PluginFilename~Srnup3270.dll~ComponentCLSID~XsFedKucf1RGxwQCQJ2IV7g==}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{ComponentName~Shttp://ns.real.com/...}{PluginFilename~Ssetu3270.dll~ComponentCLSID~XoNNlj+zn1BGWDQCQJ2IV7g==}{PluginFilename~Ssetu3270.dll~ComponentCLSID~XAAcAAN9h0BGd7wkBFgNQSA==}{PluginFilename~Ssetu3270.dll~ComponentCLSID~Xo9Nlj+zn1BGWDQCQJ2IV7g==}{PluginFilename~Ssetu3270.dll~ComponentCLSID~XotNlj+zn1BGWDQCQJ2IV7g==}{PluginFilename~Ssetu3270.dll~ComponentCLSID~XQJ8igqDX1BGWBwCQJ2IV7g==}{PluginFilename~Ssetu3270.dll~ComponentCLSID~XodNlj+zn1BGWDQCQJ2IV7g==}{PluginFilename~Ssetu3270.dll~ComponentCLSID~Xl7VDl0Wbl0qTJm7SIaGNxg==}{PluginFilename~Supgr3270.dll~ComponentCLSID~XsMvaIAH91BGTJAACswfx4w==}{PluginFilename~Supgr3270.dll~ComponentCLSID~XoEPvnRL20xGVQACQJ2IV7g==}{PluginFilename~Supgr3270.dll~ComponentCLSID~XwKSUKSrG1BGV+ACQJ2IV7g==}{PluginFilename~Supgr3270.dll~ComponentCLSID~XIMXcktdl1RGThAACswfx4w==}{PluginFilename~Supgr3270.dll~ComponentCLSID~X8AgrnrVs1RGTiwACswfx4w==}{PluginFilename~Supgr3270.dll~ComponentCLSID~X0JVckR1v1RGTjQACswfx4w==}8583"

"WAP_RED_ENU_x86_SFX_SETUP"="-fEIjPOLV?D-gmlifLIYNrRR-KDm6?AA~%F!ALi]L,pT!UaFDA9@D&u1rOE94dMs%g(7VAXGAk3bMIDxD,pejzePHAZWsVS&PAPg7v,=j0^Tc82QNI!y4-078H0wTmq?E?6wrB6Rc@YLhCAduZQW==gQ&QiSRHC3Hg!DyLLp4AfXwu5@26IaMHAiYdx0A=82T9aQ-fNIBGxol~oAD@g=kt1rbY]eWfCJwlDZy8sCd$0$82!BIX%=F'L`.9lID@BWg@JHtJ~Y!K?F{9*^)C@%Nw)BUUg'BwA8G?GM&$C4dy_]j1W&$mVnA?.?{p-NWb4brYm(Y${,w?S9KVU6kHqczgGa5}XG4Ad}pS_7cl-ZT%.m(_&er=2]Eyg&(KC63fWOF``p3AT'up3H{1}TMU]A*_E=i=}z0lMH,3r(Y0xlUvDQc8'1V.-i&%0cxUsjy.xr5@cdHxe5J@Vr_lMhIwWw[@ePX?X!,zAt'w4DJy%c_@Q@c[l2@Js8tBsh0*I~99@Rp@rF*F66[e!.Nnfi+=ciQO*QafMLEB1by[a@09*.d,r%4e0)Ux]wqVi][9G!L39zhyyR[}&_.=`p4A?h6we6RkX!-ZlomWQTW@frQ!&CP*9^]xq1sS`[G?pgpp_H]nn*s00fWyc+==D-c3W'}aSzVT[FCc~8J?5-C*g]lUHWjsJ_E~e&LAQ1TTCMEaT)UGfz.GOMEAwC0G-XTlAd{z-h3NPlz9hQr3Fd'z=6kL5FcJJ6q@D=8^F-[Iy)%$v6CROfF@C'8jrl2v*,A]ClPb$*e91k?NQ6YsQbUSi)8XvaY9i]'(ZQ[fn%gy5Vs8[-s9'Azm%hMfEz5Yw'^oyN==4@.=VyUv?xAfnc7olJM@w}uCwW?vrtY[T?g7wrL9O}+TW=T!XY,35NcJ2Yn87CZ@)S*Z5K3{%XoaV&'?2eb9@]hPBkr%FPJ(j^_@'2n$xS03w=24~X+p})k@0+?zax$@t=(}^BD5i.=?$PrregT4%vB,&^R,,@l9u0o$gD`+3i5W'v5ccI(A&H-=0WQDCa6mt)94QJ?AOFo%]no{CQf[DlhF'@X=TN^vd].'BJ)R@R1W^oAAd.uU4a?YY`8v],V%CMp?=]G*Y4Q7'DaZ_y^iD4r@1f9Kfpq,z-c(F3z@Zbp?+@Mx3`eP,k5uAC$U&y9=LOO1$FmjNEUsF`=io6t=RrXcd^GN&k_^wVJ_}d[Asxgj=m31ulXjh=8kHmw8Zogv1dZb{i2I]!aryx7@-=.PYJjB6hRQC`UV_&=?RLStGxY9Y?SAV33]Y$N=?*?^zyx,wUD.o].^xev8d=80+.&O5sGV?s0kl,Y@QC.{iea,6((4]q%4?ia?(k4_={0o8&YWL@Vc%_!?2`j_L7woV@w?XGN_0s.=K}G+n&tcnZtXn^'XKO[?%38_U%`iy$.O,@loUEE=(FZpPCc?6%s60?ghVvr8?B?R80T,4dWJ5~?9[fRA@^4HCL)OhkWVR]K=asw@7@PY0UsqV8J5cU%c7`K@DSAFmcrIlvS709em-ip8G.Ghx+np00eRukt[-[D@Tc2rZvoJg*Kk&AsRCyp=7yG-I[nKik?cLJI`j)y@ydvV]qU?_,k?&5&(b,j8ASu(^HF1So7ueSjwIo&=.&jEipVX,G19ykz%z?&9$kE1N^AdR,_uX8uICnl?{phr,PYXLS$UQ*M]oG'9_N5FD,U_L-ob&Ai1YJ,@Ug7jGPdRO1?!hx%v`_q?EJ`s('HE[eIQ(9)[QQK=Cod,wvI7r3CoHT2V8-O9}P%wAoaTU_HH3)_vQ-@A(YE[kEhJ8Bmox_t&sSy@vb[qrP'-K$`8r7$%E8}?~R`1`NK'm_c$rT?MBQg98Pz@OAkKwu(mWW6!fQt9lr0''yjLQup[hPEnD}x=ARvqnGc!RXQ@MqUN3laA!{eO1(61nJzBjQNRg]{=^cab][qoP0*U~f4{lrN9$)fu.pNrFxLp~e=M*yNArkBW!I}izUoxa90C2d=9r.KyaAf-`9pyb&1Uv7G@![WEQW~cte*qP&1*J3i@+Jxx$vn})1$Rb*cl]4Y?^XBh_+N,+83N8yjw=ZB@mjZ}5I=[t.fA%&S{?Ef87R82f@z5N@'W$U*7Jqm=a,cL4,NI]WN$kBP)f.89e(?sp]2*^F'-Km^&*C6@)BO*Y@zIsQc-Fd]xpre?`,Moe%pH8T"

"QuickTimeEssentials"="TD_.UDBXu9BWe%xw`*tdY(M'Oa8YX?JlP@zA]?dPU'[}?D]p_8aFZU26(O)[hD8f.KZhu?&dw?G7u'fPzfo.6e(KeAg$b)n.g0eYg!k!9TzPM@)}t+*JIz1i4z2ey8W`a?D]ELG3@5.sz{wUL^qGU9+V'pFBY167$8!_Ybs}-?.O0CEPt)N@*wdErlmYS9+*yq?_IkZ!fx]&i`tLc?e@(-c[U,Tp3xCRE$sf??9s4rg{{amEdA*0[DkQS9~j=6,?!GhQr&yS?)jd2=s4qL'&K&]DA[hddxHdg=T$[77]0RY(Pq8G!DDJ+?XUH52f{V.h@=UBE4J}W@((MkkP8^GfMqkwbm~Rq8%Xk!`%M'$Y?s]i^Eh$4=V0~{Irc5!(LSq@vvIH(?E=5m3sDcoY`5uXN,k-}?yq[nA^NJK*OU-WKewhJAW+cnwVo8~Gi?iObgW!Y@Kt%dM.{HTu4Zi4U$vly9[eA(A3zHmm$jm8[TD!C?ZGQvISNfy^e$h)4K2}]@PnN.ONtwG320p4YymJ+=^jfLO9!NbRWfNVY4!3cA-F6n2-atXtQ[[w?O[Ft?i+]O!&C?toqHQLl~S?P?&zn*j^s![%s$WU*D`[R=W%PnUfuFIs}RG*ZF5,)@O@9N@378'mg2O@l!Y!b9!DZ[LuVLHI9iRW^FgfN@4PdUWvj+jb~%VFt.4f%=$tPK_sK!J!)4b`kql0s953rb(Db`8OoWoeg,hav9vN@0AONU9qqoSpK4E[+?cvk'J6O0`zY[Ek*[Q1T=w^kOYi_KixF9C=MOE939a_]$1p?@xuaVPlpCF1E@Nn+UsCq{@UaZseyMv%z8sG!OwE~}my[MX).7a[d@aY5qk+_JqWNpHZ(lH9Y=2LXl-i26`8r~-@3x^-?Aejq]k]!~jPgbwecPOVX@Z'L4DyuKRHcc&t]%Y^i@^_.vP&W.wLdyirTVc)=93Y`}U$yuitFrQ}[%id39By3Q@M~y!WOi=FPfY_EA9QZ`?P8xTdkR6h`eE~,=qG0uHh%Ng%)=gI,4l5I?n[M=S,)Dwpyp)lWTORFAac*T8Dm(~cH@y*AJHZq@HOxJ(@]Q[R!^a{9+m}?9BOFb=]*u2)7I+!YhIfc9!n2-v,a+FL{V7'Z%c7y8z0vSlsK!L+bL8?FDBU{9weuGnz$2+$'5ht&eqVR?V~CU?f}2LL.$o'Icidl=uTWy)cI0leh231NPBSI@4^[)sMiF)&0sWB2V@{Y?]mue[,9ren.}S'iZL'y@V-M0q[rUe1HguaYEh96?@cCrhX%61u[z8UyY9.r?h%{?[U&toP+rJXaYaBm9}zHFZJ+UK&+=@Xn3S`@?8JU@H&yRnNK,ia*(4`V=sNBh^VvgOPH5U=K[j'B=V]*i%tP1wezsyDOB0?k@$jX&2o6QDOexdr3g8d6A[Y=.)%e}))=b,V^J3vh9yS{4m?nq'QYnSW5s%{w9.@,e4,oH3YQ3t]=,gS?=pDui!P@GqVUo9y'mezq8m]Lc(6!KC]GM_IZXpi3A?k_d43&.R`GX1v2c22~9tHL==-7CxDnS9ho-p.`9aHOUTrz?z0hIiWo[]_r=261Gj[YxD6A^@u_@uVIAZD+BD$!z)SV_?1(IEDS=T45Se0aP+c'r-`xlQi(@oAz!pR3[4NupQ$6YAXe8DS9e?KY[2a!5[&A%'TQAd-&9jv?D1MdiZPhdu}KAtVu7Jps+0_?.BO16H{g(FU%cD&lrLWlf~nDe[?)=Stzq8cY~vw0%UHQ}7qY?2w}=w'Q=G%D3o3+16}(A^4TeCV7ujy'4sV25e0p=x}521q-6QowCw]'C*}EA^puh2%ehcp5WpbXVg)RA1=2yE6v4Sg&%R=AUQ[l=K+cuuiz!0j7?~+?j(vl8E?qTEz.Tx,G1Ob?r~Cp@P$doi4ghrmn(O4Vy,uN@&{v%DvUXk7-XJPY7!&.?cAI~chOn481Vu]p^_do=QqW5y&MJ{'vJ3AL23@MA,s5bW5Y2iY%i_E.?^)k=ri_p[yS-BIW6po2a-wf?3`*?9}vYgDJF,vS`1}YAYNjP0?u[N)bWTkT1h*_A65@L=Z84t^{EFLWqaN[AVKS`y]@e2])1{=2!lw=?ojH3{c)TN)MH,--9pMA=gi%M+AANQggK6nR{g1q9_&7j!rQH-M^&3(w^EOI=NmCmOJm,Y%m@}lT~d*0=kd~$vG^1fEPfQ%e5iK$A*XcQY%y1wyh.d.UChVOAR7Obqb}FZgv+PtxATMr@Lykt*=H-YrRrk+Xpi-B?eeYnd60,HBmkPf5)=SV?)PiA])&d?J2ihGac3*x=cv5_OG]{QEgx}3I&Kz7?q`[lxQ~X^n2ju`]Bs(m@~0`+qU)'$Z7DuD(70J'Apk~_VKF})Fqgpl,vw@AAV^2uyk@pBe_lKEgUk6e@yWnlGICLycE%$AiZXhi?l_txx4i%ibdag$I&hda=6F-FxL-bK6MT0OdIQ5`=*,N0p9ZJIgu3oLe?[1U=t_j'Q7zPxU_(BKdS%t`8VZ]0HG[37VDIi@9XJjF=+vBY18H?T^rvUavrq]MA&BHeDMhZdm+veM512Ir9(N9$6,i+GHp'*)pfr*l8ShBxPQTs_8Tl[L9U@A29{I4FOO^{8dM*zwhbPx!A%(=kg'sSHN$W?ndJl[n=8o14.!zj_i6L}hQ%A5dAcyT!Ofdi^Vx&7Cns$8B@Ws~g8Oz%jHkQu+Aq)e59ri~?`_6K^B7oHAi2{qt@)mpP&V1p}GzI]${!T{_?$1^W-9Z}QUZl6{bq8t'Auu2R1HuL}IPO&M]}l$`?wTXq%)9zKoZ6sis-@IbA58Ic5S%jsFZa3=V?L6)AYGk,X,G=iJ+f`Kuf}5A9Mug1GQ0[RT$CixGb*Y)?&fmm%lg[)zqKeMD_^[$AyD4U2N=VJ@YJCSDLH]897gWZp.$VWdA9Pl%P,Zj@aDoj[sP?'CHwk]WW[L~=iTte+}-V(8AI9AeWtGX=TQ0j!cOr8v_vG0Zi%Gc@QNu,2C`?zRH3~,v[6c!@`1.Jcqa-h!3Dndh9OkT9bHmN3n{[sRM*KiTc{=-A6w)%33beQp&{5Bc.GkF@UJS)z.6MsRhZ-bGS?Xq@~yD.,N)dlv3xj~GjiB%ABUSJM^b85&csGiE`YbQAvw?ePa72Y=v2VU('?^~?&oupdib%CB(^_^^.IvF@ilkzW4y=(,-TKW9261s=o9IcA=z}$Q1un0wispi?mF%s63`c7yXPg+,=*A8AXUH}rb&j`RtxU28zVmq85Q[pqYkUcCu,Si^q6~==%Jm`=,+ThX^wO=T(~0UAvu4)&TsU+],?g?KwFaZ?nFdL?)C4A*L3TR`$B3CASGRTB@0D9aGgTzAMS!~@wh@gqdRFfoLog6C1RGR?sSRI,Uzqbz8'FirX&xf@{[?-O~9QZpp7$)?B*b.9)`FtH,&x~+csrIk=zbn@F-j77XQRm5O1b'!s2YL?vJZfQrhh3=*]CSk,a5~@.YeMn09xGXP,46ecBL_@!]iBcqP*ZlfgH9v^IB{?y^7X1w_LaE8KJB=x6@8?7%Cin1t])w8kn0Swh$&@[SfSPjT_ToJa&%E}%](=Qa!sv4fJA%%*rim18pg?n4(9Z)`X+Qr^glryu*_8&ZCk-r}TQ*N{tPJSqNk8{3G_6zn.{6cpp),Q+pb?m=}M_$H(!m4-xPb}$)v@iA[GciTY%YhTTOri*b{?i25l8z6xZt!$aMzHPf`AMEQ6RL[qGPb$octP3rd9ti(tb2[Kf,N]i$QH.Zq91&jfZ?Bx8v0%%X0o^dy9zCifM`A9mrIG4A*75cy?pdEM&,a1F07qC*g^yy}8,JUFM2`lkNSpgDvfa=I99VZiOJ[@'Ml}{TOA^DbAb.LG1%Qq@3iPf!C=eA]=$)l)X^6{$$1m$U36~)K@fjfgtXqJtDnUHfVv_gw=rpG15@2$IQTf1ym$D)ZAm{7)oyCjTibAwOk...0AehehCS{-zbpwX@SMO?!@CnSb)lbue6wbS[`&QjUAcq0`-jJ`iluMiZT&34i?awK^CBABTzi8Is_Ba@?=aNvO.o!P'1jaH~!`d_[8(}2M5sI4[.MMMU8L1Qz=8Kz4)ZfR@79)abwTy'F=dMwBh)`JSEmGzuTs.,P9Sq~-MxUu~?272=4LMx,?PvwO3t,16]r[07dSmQv?YBU!Y3bHK846N-lg=n_8iGW{k.E_Rmub-HL3rtu?7%{{kxnL[&mhCg?Y~n4Ah1^^0[CQ+7^GBi8vxks9B@=tAs155fBUv,p7htn9ZkW4NQx?YrSh@Ll^,D%@u0X?vLh7'VX[NDIo.0%9km@AbGgbE4!yJem20)PAhRDK8Qt7LHUl,EPQLs99-WSFkkNKmn.TvlPk{pz?i1HHi7(nnG=^JEA)tD59fUfm80s2&`CTwElwf)3?3Uip$_*UVHnRmPVq,GM=)Bj]yF)q*)GSaqL-R]_=]bZv`*3%x@zvP{3{+1q=L%`AuRQePi=~ndyH~3$?UJj28cJI2@mO*u?_@j-997JS]!u'u87hK5z7w@y?pfpHqwFe(qfz+IEV_8A?sl$(UG,-LcPrwxtmy5[@I_f{sXtEzL{N-r6qdLX8DnbqsGe?]%7$AK3}[@8=+*w=r^ER4jsoKSUX3S`?`m5exzbPH9.IIGa38yi9J-pbkLr60Wo{qmRRD,U9WRL0D1de%9IO`+.GJuI95bLa8ehp]g'JIy0eCaR?x6$!4?Z6tlaS,KY_w)29j[{{v1yWyO,,M{A61iZ@eot?&xPu=!Fh^Zc}@LT?.3v,RY&}pR7yAZzwm{e?=^^,nb]Zs,fMdXCfwRDAWktnwPcGCaj!st7.aFVAo*t%@W8u7sh~@o78o~*=HOCTdOXOW64NCJS+T@'=(zS.zD=Uy.=$V(8NPie8!S{p%mbT8B1`)W8q=9HA.8b+YOAOx&wi*U8XEPB?+Npv-=8KWK'FD,'*}f{@PuiRBwVsW({z&9ucU@B9C6r[URKZOx%Dld(,=`(@}=h24pm~HbG-FtRLYX*9^Ylq@_WE7&Zcm=9!dF=9Lle2Ycc47B6GQFdaN'p=A7JeKFD).s)X%(CV(1^?Ce+)%9G3&iw__F1.?J[@(tZDaEwb`V'(d@Fck~B=I7Q!]=H1da^erNWDsT5Ae+'BLe!E$V4I!}uh7f_@^T2[+,kScc?'([XJKU1AH?6mj[J'0@~=}D2LbwE=B9D$D=x9pz41SEl2ebi=$PZ$3s}B!GHZ]UZyNb-9jyTyE%$z9M)?SV*WH.n8}~X%?LS1efv-[d4S'oMAQhNPBgMB-R?Z)JTKZl{?aPCasfnzi+X[`g=,[pb8Ei6IdDKIlJ&tsB896L_99g'QEuG`jEbk)jlK6LU?UuBU$X.A[VzV81?LE}y?z3~1++T&M15LfrKb~8^@@k~oEhs`.4{6EGyclli?f!j8(`&TCvPes!$N@iN9Z?Ng`J7wxjF^+Yhx9tP='83=%SlTD6jJ.A*zrF.AzYlBOa2.?T]o=h+dbMO?YK^Sc-}d}_ToFy1TOZo@d4$d0)rOVN6dMSM2DJ!?2^wl+9?W8OJa+KsbOLs87ifKGWeWBeP3TTorjgm8'PL8$xg`Mw7_JOD5n%0A7~wRD&F%Weq{u%?,yrL@LT==xp-F^dQx,BCtMf4@OUc9Kse1`9BDxtUWLVH='5gcZ`sGhYlmg-*I-?[94nPtD==1@zDY3*Sfz0(9N.elWtQ$2.eO1+h85ni9lS4tU7~prNF@lvh'Lwn8-~A(%gc]6rP72~)k9$h@KM`3m0wci6]t6O_LG,7@`.S5G?jZXRJ]e_Y'tlY?'sIq7{!nN3g6q1B[T!s@HWJm6R9k,7TB%Ms+8-h?)UxeMg5o'AMvgab.0-l?,p8sBEaDtCb6l7=_mUCA$GK(VBdS*GcOu=?el$j?ZKk)MKT^pmg-vr&`Jg^@XZ.k[FPZwSYCC..}xrm=a10Bo%6sXLPZS5Ugb~1?P4(zEhQFYB8s(P&gY{99xISeXUVD*5VxrA=L8yA@cQ^@8jfw@-OmtzGmFd.A,.-2qAY}V$Kwxm]k^3b=HxFXXeeHN0.wsU!H45&A^3vL&HsKOkIYQ7lhQlf@Vv(ma=7SG9?k6!IG2u]?^8}tw+2QH@26CTB@+]d8-X&H%nhg2vrOBaPews^?)*Wv.oKtKPglDQOs7*FAi!P,vECzcnk'.5!jQry8N_Ie$^7%6nJ{cee-Ln]=ows'lZ`V,^TXzk$}Z$1?nUiO)n[FedkdA!'i[3F?a2]17u@2LJX6Lnhn0}F95PPE.oBR=sKwIW!z!zh8oL=W1XAky@JZb[v{4N_A)y}r?ZmL'bA0CH_[.Dx?f&Ed=`ZEU=Os2)$ApW7ABf`9(}sYJBP69WG(a{S=yv6F-z@X&ixcK@5.I,*ADp1vt]-u_,~o1o&}}~T?0b4~KhS'B)$H]JAnd4b8`z6,)'$!TP@Qma7bg0h?ta{Dr@[foC{EJsKCq}*@,)D9tfw($n%Z[Wme4[290g`GU(f]v=S6EMG8L[v=iccVaa3MN_~6r)=V,8EA`_7tF4'qr_zZsTA,f3F=!%sqdBRy^i9o.RO+ah2@(=.T4Q.9x,G8TG@%(Ks=+xKSteQ{m`Q0LvxKB9L=vTlp7l4}6^wu%M`Oz6-@a^tp%M6B+.li8FLHRuD@M@uA9yDi7,Yk7)NXj=!?nYJ-7BiM0??n9y=iOg~870xI%l=jWBwZIz!%vod?5PA6jeS2cJ5FG'@RBdM9K%ex[@A8v`Zhs7l)0d,APqZbPM[2*($Iw5SV0?z@oz1dE_(~Zi"

"TranslationFiles_1031"="CFG$0D+!g(3?!!!_GX=bBbxH8x=!g(3?!!!_GX=bC[I]yWq%g(&b=efb.?v`B%Bz691Gx8Q{jBqDGB(6_Aa`4CNgn8DB45@IbfZpuiP7_cs%g(&b=efb.?v`R'9VhB'E+=tz}k?ESog*ncOpl%I}r@`ZBY.-uOSQG*sAr[}0Y8mO6lN}m)D2kMrD)9fei?o0wwgL03lq*+yI6Rm5s@{$6ocakSuz~oj@_mNZUAcSrBF(HX=6Kb,.m+A?s9%=b@WUg7L4^yP$5VM`n?]6_,XZinE*%Oh)y{K4a?tm3gEyqpQJuKOA-qwPg8ug't_'Ykt?lSr8feNZ,?E`6_Xm.aQ.ufXWJhiB9?2?+2AVQEj`NCH7R%iPd8&NF*g,os]`ProofingToolsFiles_1031"

"TranslationFiles_1036"="CFG$0D+!g(3?!!!_GX=bBbxH8x=!g(3?!!!_GX=bB%Bz691Gx8Q{jBqDGB(6tiP7_cs%g(&b=efb.?v`_Aa`4CNgn8DB45@IbfZpB[I]yWq%g(&b=efb.?v`R'9VhB'E+=tz}k?ESog*ncOpl%I}r@`ZBY.-uOSQ)K(*$T5[V=5C-,Ul_(q*74q,1nAia=Aoo64%Hu}@-B_Fl-!4p9wF{24[fpa1qUfGN0btM?'2Oyf}w_uia_`WQfRy)@?bZX-5DZ=jvmKXw)mz5?}kVO4QpW-4+FAnpRTxd@v1@+K6CJW[kMrD)9fei?o0wwgL03lq*+yI6Rm5s@{$6ocakSuz~oj@_mNZUAcSrBF(HX=6Kb,.m+A?s9%=b@WUg7L4^yP$5VM`n?]6_,XZinE*%Oh)y{K4a?tm3gEyqpQJuKOA-qwPg8ug't_'Ykt?lSr8feNZ,?E`6_Xm.aQ.ooQ'cawYu8p@XzxUY8G`NCH7R%iPd8&NF*g,os]`ProofingToolsFiles_1036"

"CiceroFiles"="R'9VhB'E+=tz}k?ESog*ncOpl%I}r@`ZBY.-uOSQ)K(*$T5[V=5C-,Ul_(q*74q,1nAia=Aoo64%Hu}@-B_Fl-!4p9wF{24[fpa1qUfGN0btM?'2Oyf}w_uia_`WQfRy)@?bZX-5DZ=jvmKXw)mz5?}kVO4QpW-4+FAnpRTxd@v1@+K6CJW[kMrD)9fei?o0wwgL03lq*+yI6Rm5s@{$6ocakSuz~oj@_mNZUAcSrBF(HX=6Kb,.m+A?s9%=b@WUg7L4^yP$5VM`n?]6_,XZinE*%Oh)y{K4a?tm3gEyqpQJuKOA-qwPg8ug't_'Ykt?lSr8feNZ,?E`6_Xm.aQ.SHAREDFiles"

"TranslationFiles_1025"="CFG$0D+!g(3?!!!_GX=bBbxH8x=!g(3?!!!_GX=bV.RH-.`O0@2(gHe5Gu`gB%Bz691Gx8Q{jBqDGB(6_Aa`4CNgn8DB45@IbfZp)jP7_cs%g(&b=efb.?v`*jP7_cs%g(&b=efb.?v`R'9VhB'E+=tz}k?ESog*Ge[!Ex)cHA8`Nb777h8tncOpl%I}r@`ZBY.-uOSQkMrD)9fei?o0wwgL03lq*+yI6Rm5s@{$6ocakSuz~oj@_mNZUAcSrBF(HX=6Kb,.m+A?s9%=b@WUg7L4^yP$5VM`n?]6_,XZinE*%Oh)y{K4a?tm3gEyqpQJuKOA-qwPg8ug't_'Ykt?lSr8feNZ,?E`6_Xm.aQ.NCH7R%iPd8&NF*g,os]`ProofingToolsFiles_1025"

*******************
[Fichier]
*******************



*********************
[Même date]
*********************

Aucun fichier créé à la même date détecté


Outil Aide Diagnostic By !aur3n7 Version 1.1
----------------------------------
§§§§§ Fin Rapport §§§§§
----------------------------------


Pour msqpdx

31/01/2009 ---- 18:54:24,71

----------------------------------
§§§§§§ [msqpdx] §§§§§§
----------------------------------
[X] Registre

-------------- [ ] rapide
-- Fichier --- [ ] disque systeme
------------- [X] complete


********************
[Registre]
********************

Aucune entrée détectée

*******************
[Fichier]
*******************



*********************
[Même date]
*********************

Aucun fichier créé à la même date détecté


Outil Aide Diagnostic By !aur3n7 Version 1.1
----------------------------------
§§§§§ Fin Rapport §§§§§
----------------------------------

Répondre à tribord44

37

sKe69, le 31 jan 2009 à 19:11:07
  • +1

Bon ....

je te donnerai la suite plus tard ... je doit m'absenter .... A tout' ...

"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

38

sKe69, le 31 jan 2009 à 20:58:48
  • +1

De retour ,


effectivement , le crack infecté interesserai quelque créateur d'outils comme ceux que tu viens d'utilisé ...

prb , ils ne sont par sur le net en se moment , donc je ne sais toujours pas vers qui faire remonté la bestiole ... ^^


En attendant , dis moi quelle taille fait cette archive stp ( c'est là que la vermine sommeille ... et ne t'inquiète pas, elle n'est pas active ;) )

C:\Documents and Settings\M VT\Mes documents\Photoshop Plugin Kodak Digital Gem, Gem Airbrush, Roc, Sho Professional 2.0.0 Keygen Verificate.rar


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

39

tribord44, le 31 jan 2009 à 21:29:15

C' est une archive win RAR de 26.8 Mo

Répondre à tribord44

40

sKe69, le 31 jan 2009 à 21:37:16

Dis moi si tu peux extraire uniquement ceci de cette archive ( extrait sur ton bureau ) :

Kodak Digital GEM, GEM Airbrush, ROC, SHO Professional 2.0.0

puis n 'y touche plus et dis moi la taille que cela fait ...


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

41

tribord44, le 31 jan 2009 à 21:50:33

Je ne l'ai pas encore extraite mais mais j'ai les proprietées

contients 269 fichiers
taille réeel 83 764 160
taille compressé 28 145 942

Répondre à tribord44

42

sKe69, le 31 jan 2009 à 21:57:28

écoute n 'y touche pas pour le momment ...

avec cette taille , je ne sais pas si on pourra l'uploader .... et extraire comporte le risque de se faire infecter ...


donc je répète , n'y touche pas pour le moment et refais ceci :


mets à jour Malwarebytes .

! Déconnecte toi et ferme toutes applications en cours !

* Lance Malwarebyte's .

Fais un examen dit "Rapide" .

--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date),
accompagné d'un nouveau rapport hijackthis pour analyse ...

"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

43

tribord44, le 31 jan 2009 à 22:19:24

Malwarebytes ne trouve aucun fichiers infectés ,mais j'ai analysé l'archives tout a l'heure et ni malware, ni antivir ne détectait qq choses . doit je malgrés tout passer hijakthis?
Si tu veux je peux peut etre la télécharger sur un espace de stokage (9 giga) et la mettre en partage si tu me donne une adresse mail.

Malwarebytes' Anti-Malware 1.33
Version de la base de données: 1712
Windows 5.1.2600 Service Pack 2

31/01/2009 22:05:21
mbam-log-2009-01-31 (22-05-21).txt

Type de recherche: Examen rapide
Eléments examinés: 57123
Temps écoulé: 3 minute(s), 47 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

Répondre à tribord44

44

sKe69, le 31 jan 2009 à 23:59:37

Re,

Si tu veux je peux peut etre la télécharger sur un espace de stokage (9 giga) et la mettre en partage si tu me donne une adresse mail.

c'est une possibilité ... je te tiendrais aux courant de ce côté là .... garde l'archive pour le moment ...


Tant mieux si MBAM ne trouve rien ... fais moi un topo sur les disfonctionnements que tu rencontres encore ...


Et poste moi un hijavkthis tout frai ...


A demain .... ;)

"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

45

tribord44, le 1 fév 2009 à 08:46:03

Bonjour sKe69,
les dysfonctionnements sont resté les mêmes:
-impossibilitée de se connecter à windows update et plantage systématique D'IE ; donc pas de maj
-Dans ajout /supp de programmes, aucune liste n'apparait la fenêtre est blanche .
sinon le pc semble fonctionner très bien.
le rapport hijack que je viens de faire:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:28:44, on 01/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24134 bytes

Répondre à tribord44

46

sKe69, le 1 fév 2009 à 10:25:26

Salut,


1- peux-tu me dire ce qu'est ce prg :

C:\Program Files\Wacom\Bamboo Link

t'en serts tu ?



2- restes des signes d'infections au niveau des paramètres d'Intenet Exploreur :


essayes ceci :

Téléchargez ceci (de gchris) : http://gchrisftp.free.fr/divers/Ad-Fix/Ad-Fix.zip

!! Important : désactive ton anti-virus le temps de la manipe , tu le réactiveras ensuite !!

Dézippez-le sur votre bureau (clic droit -> extraire tout).

Attention : vérifiez que vous êtes bien connecté à internet.

Dans le dossier créé, double-cliquez sur le fichier "Ad-Fix.bat" ou "Ad-fix"
Choisissez l'option 1.

Si vous avez un message de votre pare-feu qui vous demande si vous voulez autoriser le fichier "URL2FILE.EXE" à
se connecter à Internet ---> autorisez, c'est nécessaire à ad-fix pour vérifier la version.

Quand c'est finit (cela peut prendre plusieurs minutes), un rapport s'ouvre avec le bloc-notes.
Merci de faire un copier/coller ici du contenu du rapport (Ad-Fix.txt) .


"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

47

tribord44, le 1 fév 2009 à 10:49:18

Je ne comprend pas , il faut que je désactive l'antivirus tout en restant connecter?

Répondre à tribord44

48

sKe69, le 1 fév 2009 à 11:03:28

Oui ,

mais ferme ton navigateur avant bien sûr !

"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

49

tribord44, le 1 fév 2009 à 11:30:57

J'ai installer dpuis peu une tablette graphique wacom, bamboo fait parti des softs installer avec la tablette
visiblement c'est un acces direct sur un forum wacom , je suppose car le lien ne fonctionne pas.
voivi le rapport ad- fix

Ad-Fix v0.101e
by gchris


OPTION 1 (Scan) :

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Démarré à :

11:13:36,79 01/02/2009


Executé depuis :

C:\Documents and Settings\M V\Bureau\Ad-Fix


Os :

Microsoft Windows XP [version 5.1.2600]

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Recherche de fichier manquant


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Recherche de fichiers cachés (pas forcément mauvais)


Fichiers cachés à la racine du disque système :

boot.ini
Bootfont.bin
IO.SYS
MSDOS.SYS
NTDETECT.COM
ntldr
pagefile.sys
sqmdata00.sqm
sqmnoopt00.sqm
ZbThumbnail.info

Fichiers cachés dans le répertoire Windows :

WindowsShell.Manifest
winnt.bmp
winnt256.bmp

Fichiers cachés dans le répertoire System32 :

cdplayer.exe.manifest
KGyGaAvL.sys
logonui.exe.manifest
ncpa.cpl.manifest
nwc.cpl.manifest
sapi.cpl.manifest
WindowsLogon.manifest
wuaucpl.cpl.manifest
zllictbl.dat

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Analyse du registre


---------- USER AGENT -- POST PLATFORM

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Internet Settings\User Agent\Post Platform]

----------

---------- AppInit_DLLs

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

----------
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Détecté !


Complete!

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Recherche de fichiers et dossiers


C:\WINDOWS\nem???.dll Détecté !




»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Terminé à 11:18:50,46

Répondre à tribord44

50

sKe69, le 1 fév 2009 à 11:35:31

J'ai installer dpuis peu une tablette graphique wacom, bamboo fait parti des softs installer avec la tablette
visiblement c'est un acces direct sur un forum wacom , je suppose car le lien ne fonctionne pas.


> donc on peut le virer ?


fait la suite :

Nettoyage Ad-fix :

Impératif : Démarrer en mode sans echec .

/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

Comment aller en Mode sans échec :
1) Redémarre ton ordi .
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
4) Choisis la première option : Sans Échec , et valide en tapant sur [Entrée] .
5) Choisis ton compte habituel ( et pas Administrateur ).
attention : pas de connexion possible en mode sans échec , donc copie ou imprime bien la manipe pour éviter les erreurs ...

--->Lancez de nouveau Ad-fix

Choisissez l'option 2
(Le bureau ou les icônes vont disparaître, c'est normal.)
Quand c'est terminé, pressez la touche [entrée] pour redémarrer l'ordinateur.

Copiez/collez ici, le contenu du nouveau rapport générer (le sauvegarder de façon à le retrouver), accompagné d'un nouveau rapport hijackthis ( celui-ci fais en mode normal ) pour analyse ...



"Baby, I'm going on an airplane, And I don't know if I'll be back again"
IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne 
vous l'a pas dit !

Répondre à sKe69

51

tribord44, le 1 fév 2009 à 12:11:33

Ok, pour le dossier wacom\bamboo link ,oui je pense qu'on peut le supp
le rapport ad-fix:

Ad-Fix v0.101e
by gchris


OPTION 2 (Fix) :

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Démarré à :

11:52:10,96 01/02/2009
en mode sans échec


Executé depuis :

C:\Documents and Settings\M V\Bureau\Ad-Fix


Os :

Microsoft Windows XP [version 5.1.2600]

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Recherche de fichier manquant


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Nettoyage du registre

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Supprimé !


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»


»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Suppression des fichiers

C:\WINDOWS\nem???.dll Supprimé !

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»­»»»»

Terminé à 11:57:34,98


Redémarrage effectué

et le rapport hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:16, on 01/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\Program Files\BufferZone\BZRPCSS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.coolsearch.biz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Annoter avec Bamboo Link - C:\Program Files\Wacom\Bamboo Link\AnnotateWithErgo.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://fr.msn.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: bw+0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {D474EA06-473B-4376-8AE7-BA24DFEDD8CF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
End of file - 24097 bytes

Répondre à tribord44