Setupcasino enlever : impossible

Résolu/Fermé
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 - 16 févr. 2009 à 23:13
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 - 22 févr. 2009 à 20:30
Bonjour,
voilà j'ai télécharger un jeu de casino et quand je fais le "anti-spy" il me le trouve mais je n'arrive pas à l'enlever!

je vous remercie d'avance,

gabriel
A voir également:

73 réponses

seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
17 févr. 2009 à 14:14
voilà, j'ai relancé le "log.txt"!

Logfile of random's system information tool 1.05 (written by random/random)
Run by moi at 2009-02-17 14:11:59
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 150 GB (83%) free of 180 GB
Total RAM: 2046 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:12:24, on 17/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\moi\Downloads\RSIT.exe
C:\Program Files\trend micro\moi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Kaspersky Internet Security (avp) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
17 févr. 2009 à 14:33
ouh là, je crois voir que le rapport ne s'affiche pas normalement!

je te le reposte :

Logfile of random's system information tool 1.05 (written by random/random)
Run by moi at 2009-02-17 14:30:09
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 150 GB (83%) free of 180 GB
Total RAM: 2046 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:30:11, on 17/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Users\moi\Downloads\RSIT.exe
C:\Program Files\trend micro\moi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Kaspersky Internet Security (avp) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
0
Utilisateur anonyme
17 févr. 2009 à 14:46
---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :





:processes
explorer.exe

:files
C:\autorun.inf
H:\Autorun.inf

:reg
[HKEY_CUERRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/?gws_rd=ssl"

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]






---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log


0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
17 févr. 2009 à 15:17
ok,

bon voilà le rapport :

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\autorun.inf moved successfully.
File/Folder H:\Autorun.inf not found.
========== REGISTRY ==========
HKEY_CUERRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"https://www.google.fr/?gws_rd=ssl" /E :invalid edit format. No such root key.
========== COMMANDS ==========
File delete failed. C:\Users\moi\AppData\Local\Temp\~DF12EA.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\moi\AppData\Local\Temp\~DF9E9B.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02172009_150711

Files moved on Reboot...
C:\Users\moi\AppData\Local\Temp\~DF12EA.tmp moved successfully.
C:\Users\moi\AppData\Local\Temp\~DF9E9B.tmp moved successfully.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
17 févr. 2009 à 16:29
je re,

t'es là chef?
0
Utilisateur anonyme
17 févr. 2009 à 17:11
ok desole faute de frappe :

laisse branché ta clé usb et :


:processes
explorer.exe

:files
H:\Autorun.inf

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/?gws_rd=ssl"

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]


repasse ceci dans otmoveit stp
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
17 févr. 2009 à 23:20
salut,
me revoilà!

voici donc le "moveIT" (avec clé USB) :

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File move failed. H:\autorun.inf scheduled to be moved on reboot.
========== REGISTRY ==========
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"http://www.google.fr/" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\Users\moi\AppData\Local\Temp\~DFCC79.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\moi\AppData\Local\Temp\~DFDEE8.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\Windows\temp\TMP000000505E7F93E03F6ABF81 scheduled to be deleted on reboot.
Windows Temp folder emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02172009_231209

Files moved on Reboot...
File move failed. H:\autorun.inf scheduled to be moved on reboot.
C:\Users\moi\AppData\Local\Temp\~DFCC79.tmp moved successfully.
C:\Users\moi\AppData\Local\Temp\~DFDEE8.tmp moved successfully.
File C:\Windows\temp\TMP000000505E7F93E03F6ABF81 not found!
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
17 févr. 2009 à 23:39
t'es plus là?
0
Utilisateur anonyme
18 févr. 2009 à 01:20
Avis aux Moderateurs j'ai deliberement pris la responsabilite n'engageant que moi a faire passer cet outil dont je poste la reponse ici car elle m a ete adressee en MP

merci de votre comprehension afin que tout le monde s'il y a lieu d intervenir , puisse etre au courant des avancements de ce topic :

voilà le rapport,

mais j'ai l'impression qu'il y a eu problème de nettoyage de H:\

bref, tu verras :



-------------- UsbFix V2.395 ---------------

* User : moi - PC-DE-MOI
* Outils mis a jours le 26/10/2008 par Chiquitine29 et Chimay8
* Recherche effectuée à 0:56:12 le 18/02/2009
* Windows Vista - Internet Explorer 7.0.6001.18000


--------------- [ Processus actifs ] ----------------



--------------- [ Informations lecteurs ] ----------------

C: - Lecteur fixe
G: - Lecteur amovible
H: - Lecteur de CD-ROM

+- Contenu de l'autorun : G:\autorun.inf


+- Contenu de l'autorun : H:\autorun.inf

[AutoRun]
open=LaunchU3.exe -a
icon=LaunchU3.exe,0
action=Run U3 Launchpad

[Definitions]
Launchpad=LaunchPad.exe
Vtype=2

[CopyFiles]
FileNumber=1
File1=LaunchPad.zip

[Update]
URL=http://u3.sandisk.com/download/lp_installer.asp?custom=1.6.1.2&brand=PelicanBFG


[Comment]
brand=PelicanBFG
--------------- [ Registre / Startup ] ----------------


HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
ISBMgr.exe REG_SZ "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
MarketingTools REG_SZ C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
NvSvc REG_SZ RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
NvCplDaemon REG_SZ RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
NvMediaCenter REG_SZ RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
AVP REG_SZ "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Picasa Media Detector REG_SZ C:\Program Files\Picasa2\PicasaMediaDetector.exe


--------------- [ Registre / Mountpoint2 ] ----------------


-> Recherche négative.

--------------- [ Nettoyage des disques ] ----------------

Echec de la supression !! - G:\autorun.inf
Supprimé ! - G:\autorun.inf
Echec de la supression !! - H:\autorun.inf
Echec de la supression !! - H:\autorun.inf

--------------- ! Fin du rapport ! ----------------
0
Utilisateur anonyme
18 févr. 2009 à 01:27
colle ceci dans un document texte ,

:processes
explorer.exe

:files
H:\Autorun.inf

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]


et enregistre le sur le bureau

redemarre en mode sans echec et relance otmoveit et appliques la meme procedure stp(copier/coller)

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 01:40
bon me revoilà! :)

voici le poste :

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File move failed. H:\autorun.inf scheduled to be moved on reboot.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02182009_013556

Files moved on Reboot...
File move failed. H:\autorun.inf scheduled to be moved on reboot.
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 01:28
excuse-moi mais je suis un peu perdu là!

que dois-je faire?

au fait, j'ai un problème depuis quelques temps (même 2) :

1) j'ai l'impression (ou est-ce moi, mais je ne crois pas) que le démarrage et l'arrêt se fait beaucoup plus lentement

2) de temps en temps (1 fois sur 3 environ ou 4) l'ordi au démarrage ne se fait pas normalement et l'écran s'ouvre avec des "moyens" réduits (difficile à expliquer) comme si j'étais repassé au mode XP!

bref, bizare!
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 01:30
désolé, ne prends pas ce message en compte : "excuse-moi mais je suis un peu perdu là!

que dois-je faire?"

j'ai dû le poster en même temps que tu me répondais!

par contre les 2 problèmes cités après, à voir peut-être....
0
Utilisateur anonyme
18 févr. 2009 à 02:02
tu vas devoir formater ta cle usb qui est sur H:\
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 02:10
bon ok!

mais pour la lenteur?
j'ai l'impression que mon Kaspersky 2009 déconne!
je vais devoir le remettre!

bref!
je vais voir si c'est ça!
0
Utilisateur anonyme
18 févr. 2009 à 02:13
tres important !!! formate taa cle usb il est innettoyable aperemment
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 02:56
ben, la clé USB, impossible à formater!

bon, à la rigueur, c'est pas très grave pour ce qu'il y avait,

j'avais par précaution tout enregistrer sur un CD!

mais par contre, tout me semble si lent!
j'ai voulu remettre Kaspersky ac mon CD mais le lecteur ne le lisait plus du tout, il était carrément vierge!

bref! j'ai quand-même pu le télécharger via le site net!

mais tout ça ne me semble pas très bon
0
Utilisateur anonyme
18 févr. 2009 à 03:07
oui je pense qu'il y a uun gros souci mais que je n'arrive pas a discerner ...

J'aimerais que quelqu'un de plus efficace intervienne s'il a une idee de comment depatouiller notre ami
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
18 févr. 2009 à 03:31
Salut,

--> Désactive l'UAC le temps de la désinfection.

/!\ Désactive tes protections résidentes (Antivirus, etc...) /!\

--> Télécharge ComboFix (de sUBs) sur ton Bureau.
--> Clique droit sur ComboFix.exe (le .exe n'est pas forcément visible) et choisis Exécuter en tant qu'administrateur afin de le lancer.
--> Il va te demander d'installer la console de récupération : accepte.
--> Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.

Pour t'aider : Un guide et un tutoriel sur l'utilisation de ComboFix
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 04:03
eh ben!

le combo fix se bloque!
ça marche pas! j'arrive à la télécharger
mais après il envoie un message du genre "some installation files are corrupted. please download a fresh copy..."

alors, désespéré?
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 12:14
voilà, ben en passant par "intener explorer" et non mozzila
j'ai enfin pu faire le scan combofix!

voilà le rapport :

ComboFix 09-02-17.02 - moi 2009-02-18 12:06:17.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1117 [GMT 1:00]
Lancé depuis: c:\users\moi\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Un nouveau point de restauration a été créé
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-18 au 2009-02-18 ))))))))))))))))))))))))))))))))))))
.

2009-02-18 02:32 . 2009-02-18 02:42 101,287 --a------ c:\windows\System32\drivers\klin.dat
2009-02-18 02:32 . 2009-02-18 02:42 89,601 --a------ c:\windows\System32\drivers\klick.dat
2009-02-18 02:31 . 2009-02-18 11:58 <REP> d-------- c:\users\All Users\Kaspersky Lab
2009-02-18 02:31 . 2009-02-18 11:58 <REP> d-------- c:\programdata\Kaspersky Lab
2009-02-18 02:31 . 2009-02-18 02:31 <REP> d-------- c:\program files\Kaspersky Lab
2009-02-18 02:31 . 2009-02-18 04:09 3,293,728 --ahs---- c:\windows\System32\drivers\fidbox.dat
2009-02-18 02:31 . 2009-02-18 12:07 409,632 --ahs---- c:\windows\System32\drivers\fidbox2.dat
2009-02-18 02:31 . 2009-02-18 04:09 26,812 --ahs---- c:\windows\System32\drivers\fidbox.idx
2009-02-18 02:31 . 2009-02-18 12:05 2,480 --ahs---- c:\windows\System32\drivers\fidbox2.idx
2009-02-18 02:27 . 2009-02-18 02:27 <REP> d-------- c:\windows\Sun
2009-02-18 00:41 . 2009-02-18 03:21 <REP> d-------- c:\program files\UsbFix
2009-02-17 15:07 . 2009-02-17 15:07 <REP> d-------- C:\_OTMoveIt
2009-02-17 14:52 . 2009-02-17 14:52 <REP> d-------- c:\program files\JRE
2009-02-17 13:19 . 2009-02-17 13:16 132,597 --a------ C:\Flash_Disinfector.exe
2009-02-17 13:15 . 2009-02-17 13:15 <REP> d-------- c:\users\All Users\McAfee
2009-02-17 13:15 . 2009-02-17 13:15 <REP> d-------- c:\programdata\McAfee
2009-02-17 13:08 . 2009-02-17 13:30 <REP> d-------- c:\users\moi\AppData\Roaming\U3
2009-02-17 12:35 . 2009-02-17 12:35 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-02-17 11:50 . 2009-02-17 13:08 <REP> d-------- c:\program files\FindyKill
2009-02-17 11:25 . 2009-02-18 03:33 <REP> d-------- C:\rsit
2009-02-17 02:29 . 2009-02-17 02:29 <REP> d-------- c:\users\moi\AppData\Roaming\Malwarebytes
2009-02-17 02:29 . 2009-02-17 02:29 <REP> d-------- c:\users\All Users\Malwarebytes
2009-02-17 02:29 . 2009-02-17 02:29 <REP> d-------- c:\programdata\Malwarebytes
2009-02-16 23:23 . 2009-02-17 13:25 <REP> d-------- c:\program files\Ad-remover
2009-02-16 23:03 . 2009-02-18 03:33 <REP> d-------- c:\program files\Trend Micro
2009-02-15 12:38 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-15 12:38 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-15 12:38 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-15 12:38 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-15 12:38 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-14 23:41 . 2009-02-15 00:00 <REP> d-------- c:\users\moi\AppData\Roaming\skypePM
2009-02-14 23:41 . 2009-02-14 23:41 56 --ah----- c:\users\All Users\ezsidmv.dat
2009-02-14 23:41 . 2009-02-14 23:41 56 --ah----- c:\programdata\ezsidmv.dat
2009-02-14 23:40 . 2009-02-15 02:40 <REP> d-------- c:\users\moi\AppData\Roaming\Skype
2009-02-14 23:39 . 2009-02-14 23:39 <REP> dr------- c:\program files\Skype
2009-02-14 23:39 . 2009-02-14 23:39 <REP> d-------- c:\program files\Common Files\Skype
2009-02-12 17:32 . 2009-02-12 17:32 <REP> d-------- c:\users\All Users\FLEXnet
2009-02-12 17:32 . 2009-02-12 17:32 <REP> d-------- c:\programdata\FLEXnet
2009-02-11 11:54 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 11:54 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-09 22:08 . 2009-02-09 22:08 <REP> d-------- c:\program files\Common Files\Scanner
2009-02-09 22:08 . 2009-02-09 22:10 <REP> d-------- c:\program files\CA Yahoo! Anti-Spy
2009-02-04 23:39 . 2009-02-04 23:39 2,117,632 --a------ c:\windows\System32\python25.dll
2009-02-04 23:39 . 2008-09-16 17:26 1,332,197 --a------ c:\windows\System32\pythondll.zip
2009-02-04 23:39 . 2009-02-04 23:39 339,968 --a------ c:\windows\System32\pythoncom25.dll
2009-02-04 23:39 . 2009-02-04 23:39 114,688 --a------ c:\windows\System32\pywintypes25.dll
2009-02-04 23:37 . 2009-02-04 23:39 <REP> d-------- c:\program files\AGI
2009-02-03 16:09 . 2009-02-03 16:19 <REP> d-------- C:\Poker
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Videos
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Searches
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Saved Games
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Pictures
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Music
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Links
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Downloads
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Documents
2009-02-03 01:08 . 2009-02-03 01:09 <REP> d-------- C:\VAIO Entertainment
2009-02-01 01:36 . 2009-02-01 01:44 <REP> d-------- c:\users\moi\AppData\Roaming\ArcSoft
2009-02-01 01:31 . 2004-07-20 18:21 245,408 --a------ c:\windows\System32\unicows.dll
2009-02-01 01:31 . 2006-03-30 16:53 212,480 --a------ c:\windows\System32\PCDLIB32.DLL
2009-02-01 01:31 . 2007-11-10 14:10 55,808 --a------ c:\windows\System32\ArcSoftKsUFilter.dll
2009-02-01 01:31 . 2007-12-20 15:52 17,408 --a------ c:\windows\System32\drivers\ArcSoftKsUFilter.sys
2009-01-30 22:48 . 2009-01-30 22:48 <REP> d-------- c:\program files\Common Files\Macrovision Shared
2009-01-30 13:44 . 2009-01-30 13:47 <REP> d--h----- c:\users\TEMP\AppData
2009-01-30 13:44 . 2009-01-30 13:47 <REP> d-------- c:\users\TEMP
2009-01-30 12:30 . 2009-02-18 02:42 370 --a------ c:\windows\System32\%LocalXml%
2009-01-30 11:58 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-01-30 11:58 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-01-30 11:58 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-01-30 11:58 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-01-30 11:58 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-01-30 11:58 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-01-30 11:58 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-01-30 11:58 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-01-30 11:53 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-01-30 11:53 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-01-30 11:53 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-01-30 11:53 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-01-30 11:53 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-01-29 22:48 . 2009-01-29 22:48 <REP> d-------- C:\PerfLogs
2009-01-29 15:00 . 2009-01-29 15:00 <REP> d-------- c:\users\All Users\HP Product Assistant
2009-01-29 15:00 . 2009-01-29 15:00 <REP> d-------- c:\programdata\HP Product Assistant
2009-01-29 14:55 . 2009-01-29 14:56 <REP> d-------- c:\program files\Common Files\HP
2009-01-29 14:42 . 2009-01-29 14:58 148,935 --a------ c:\windows\hppins20.dat
2009-01-29 14:42 . 2007-03-01 03:21 16,655 --a------ c:\windows\hppmdl20.dat
2009-01-29 13:36 . 2005-10-24 13:55 830,464 --a------ c:\users\moi\hp_ize.exe
2009-01-29 13:32 . 2009-01-29 13:33 19,497 --a------ c:\windows\hpqins13.dat
2009-01-29 13:18 . 2009-01-29 13:18 <REP> d-------- c:\users\moi\AppData\Roaming\Printer Info Cache
2009-01-29 13:18 . 2009-02-01 03:38 <REP> d-------- c:\users\moi\AppData\Roaming\Image Zone Express
2009-01-29 13:04 . 2009-01-29 15:12 <REP> d-------- c:\users\moi\AppData\Roaming\HP
2009-01-29 13:04 . 2009-01-29 13:04 <REP> d-------- c:\users\All Users\WEBREG
2009-01-29 13:04 . 2009-01-29 14:05 <REP> d-------- c:\users\All Users\HPSSUPPLY
2009-01-29 13:04 . 2009-01-29 13:04 <REP> d-------- c:\programdata\WEBREG
2009-01-29 13:04 . 2009-01-29 14:05 <REP> d-------- c:\programdata\HPSSUPPLY
2009-01-29 12:58 . 2009-01-29 12:58 <REP> d-------- c:\users\All Users\Hewlett-Packard
2009-01-29 12:58 . 2009-01-29 12:58 <REP> d-------- c:\programdata\Hewlett-Packard
2009-01-29 12:42 . 2007-01-29 14:22 117,760 --a------ c:\windows\System32\hpz3l4v2.dll
2009-01-29 12:41 . 2007-02-01 08:14 258,048 --a------ c:\windows\System32\hpzids01.dll
2009-01-29 12:24 . 2009-01-29 14:56 <REP> d-------- c:\program files\HP
2009-01-29 12:21 . 2009-01-29 22:17 <REP> d-------- c:\users\All Users\HP
2009-01-29 12:21 . 2009-01-29 22:17 <REP> d-------- c:\programdata\HP
2009-01-28 23:02 . 2008-01-19 08:33 2,623,488 --a------ c:\windows\System32\SLsvc.exe
2009-01-28 23:02 . 2008-01-19 08:36 1,541,120 --a------ c:\windows\System32\onex.dll
2009-01-28 23:00 . 2008-01-19 08:33 8,139,264 --a------ c:\windows\System32\ssBranded.scr
2009-01-28 22:59 . 2008-01-19 08:32 5,714,432 --a------ c:\windows\System32\logon.scr
2009-01-28 22:58 . 2008-01-19 07:06 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-01-28 22:57 . 2008-01-19 08:34 305,152 --a------ c:\windows\System32\msdelta.dll
2009-01-28 22:57 . 2008-01-19 08:34 258,560 --a------ c:\windows\System32\dpx.dll
2009-01-28 22:57 . 2008-01-19 08:34 246,784 --a------ c:\windows\System32\drvstore.dll
2009-01-28 22:57 . 2008-01-19 08:35 35,328 --a------ c:\windows\System32\mspatcha.dll
2009-01-28 20:39 . 2009-01-28 20:39 <REP> d-------- c:\users\All Users\NOS
2009-01-28 20:39 . 2009-01-28 20:39 <REP> d-------- c:\programdata\NOS
2009-01-28 20:39 . 2009-01-28 20:39 <REP> d-------- c:\program files\NOS
2009-01-28 12:33 . 2009-01-28 12:33 <REP> d-------- c:\users\moi\AppData\Roaming\OpenOffice.org
2009-01-28 12:08 . 2009-01-28 12:08 <REP> d-------- c:\users\All Users\Kaspersky Lab Setup Files
2009-01-28 12:08 . 2009-01-28 12:08 <REP> d-------- c:\programdata\Kaspersky Lab Setup Files
2009-01-28 12:04 . 2009-02-17 14:51 <REP> d-------- c:\program files\OpenOffice.org 3
2009-01-28 10:24 . 2009-01-28 11:41 <REP> d-------- c:\users\moi\AppData\Roaming\OpenOffice.org2
2009-01-28 10:20 . 2009-01-28 12:04 <REP> d-------- c:\program files\OpenOffice.org 2.2
2009-01-27 23:41 . 2009-02-06 02:08 <REP> d-------- c:\program files\Defraggler
2009-01-27 23:39 . 2009-01-27 23:39 <REP> d-------- c:\program files\CCleaner
2009-01-27 23:31 . 2009-01-27 23:31 <REP> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-27 23:31 . 2009-01-27 23:31 269,312 --a------ c:\windows\System32\es.dll
2009-01-27 22:08 . 2009-01-27 22:08 <REP> d-------- c:\users\moi\AppData\Roaming\InstallShield
2009-01-27 21:57 . 2009-01-27 21:57 <REP> d-------- c:\users\moi\AppData\Roaming\DivX

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-18 11:03 --------- d-----w c:\program files\Google
2009-02-18 01:42 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-14 22:39 --------- d-----w c:\programdata\Skype
2009-02-11 11:37 --------- d-----w c:\program files\Windows Mail
2009-02-10 14:33 --------- d-----w c:\program files\Java
2009-02-03 00:08 --------- d-----w c:\programdata\Sony Corporation
2009-02-01 00:40 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-30 21:48 --------- d-----w c:\program files\Common Files\Adobe
2009-01-29 21:58 174 --sha-w c:\program files\desktop.ini
2009-01-29 21:49 --------- d-----w c:\program files\Windows Sidebar
2009-01-29 21:49 --------- d-----w c:\program files\Windows Photo Gallery
2009-01-29 21:49 --------- d-----w c:\program files\Windows Journal
2009-01-29 21:49 --------- d-----w c:\program files\Windows Defender
2009-01-29 21:49 --------- d-----w c:\program files\Windows Collaboration
2009-01-29 21:49 --------- d-----w c:\program files\Windows Calendar
2009-01-29 21:34 82,432 ----a-w c:\windows\System32\axaltocm.dll
2009-01-29 21:34 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2009-01-27 22:32 --------- d-----w c:\programdata\Microsoft Help
2009-01-27 22:27 --------- d-----w c:\program files\Microsoft Works
2009-01-27 22:00 --------- d-----w c:\program files\Sony
2009-01-27 22:00 --------- d-----w c:\program files\Common Files\Sony Shared
2009-01-27 19:21 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2009-01-27 19:21 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-27 19:21 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-27 19:21 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2009-01-27 19:21 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2009-01-27 19:21 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-27 19:12 9,847,296 ----a-w c:\windows\System32\NlsData000a.dll
2009-01-27 18:54 996,352 ----a-w c:\windows\System32\WMNetMgr.dll
2009-01-27 18:54 98,816 ----a-w c:\windows\System32\mfps.dll
2009-01-27 18:54 94,720 ----a-w c:\windows\System32\logagent.exe
2009-01-27 18:54 84,480 ----a-w c:\windows\System32\INETRES.dll
2009-01-27 18:54 738,304 ----a-w c:\windows\System32\inetcomm.dll
2009-01-27 18:54 53,248 ----a-w c:\windows\System32\rrinstaller.exe
2009-01-27 18:54 288,768 ----a-w c:\windows\system32\drivers\srv.sys
2009-01-27 18:54 24,576 ----a-w c:\windows\System32\mfpmp.exe
2009-01-27 18:54 2,868,736 ----a-w c:\windows\System32\mf.dll
2009-01-27 18:54 2,048 ----a-w c:\windows\System32\mferror.dll
2009-01-27 18:54 1,645,568 ----a-w c:\windows\System32\connect.dll
2009-01-27 18:54 1,314,816 ----a-w c:\windows\System32\quartz.dll
2009-01-27 17:15 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-01-27 17:01 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-04 23:11 308,584 ----a-w c:\windows\WLXPGSS.SCR
2008-12-02 21:37 49,480 ----a-w c:\windows\System32\sirenacm.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-12 443968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-06-10 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-09-19 311296]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-02 1838592]
"MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2007-11-02 36864]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-10-30 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-30 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-30 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-10 148888]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-18 206088]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-08-28 739880]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 20:05 98304 c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\program files\Common Files\Sony Shared\VideoLib\sonydv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{AB636B88-B70A-437A-AD96-EBCD9D37871E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{98656251-E95C-4BB3-9267-CE63813A0C49}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2C2F61F9-8DA2-44C7-A22A-68A261ABB719}"= Disabled:UDP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{AFA15B50-6C27-4075-812A-4FDB7583A6A3}"= Disabled:TCP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{3BF0911B-0DC7-4948-B237-53BD7534B6EA}"= UDP:c:\users\moi\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{C80A73FE-9302-466D-8B9A-E5A638A2B003}"= TCP:c:\users\moi\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{15627994-46BD-4860-9726-11A9471F7699}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{772D3550-9599-4D4B-99FC-659DAE740D73}"= c:\program files\HP\Digital Imaging\bin\hpqpse.exe:hpqpse.exe
"{6F006875-2CEE-4673-9D80-B56578CC0671}"= c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe:hpqphotocrm.exe
"{F513F5FA-9208-4873-B396-D1999F94760F}"= c:\program files\HP\Digital Imaging\bin\hpqsudi.exe:hpqsudi.exe
"{4C250F66-C12C-4B0E-8EE9-1DE43B4A9CFC}"= c:\program files\HP\Digital Imaging\bin\hpqpsapp.exe:hpqpsapp.exe
"{DF71B73D-5B33-44EF-B871-56447F69258C}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{E69F1DE4-F724-4F14-81E1-78EB7C670AED}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{AA619891-28E9-43DF-8D5C-9CAF37173BF3}"= c:\program files\Skype\Phone\Skype.exe:Skype

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [2008-01-29 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [2008-07-09 20496]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [2007-04-17 11032]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2009-02-01 104960]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-01-27 333088]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\System32\drivers\ArcSoftKsUFilter.sys [2009-02-01 17408]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [2008-03-13 26640]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [2007-11-02 75008]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [2007-11-02 43904]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [2007-11-02 9344]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [2007-11-02 812544]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [2007-11-02 28464]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-28 33752]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2009-01-27 436096]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [2009-01-27 745472]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2009-01-27 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2009-01-27 1089536]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2009-01-27 87328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mStart Page = about:blank
IE: Ajouter à Kaspersky Anti-Bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\users\moi\AppData\Roaming\Mozilla\Firefox\Profiles\wshfj6uk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Wikipédia (fr)
FF - prefs.js: browser.startup.homepage - hxxp://fr.yahoo.com/r/hf
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- PARAMETRES FIREFOX ----
user_pref('capability.policy.policynames', 'localfilelinks');user_pref('capability.policy.localfilelinks.sites', 'hxxp://www.webmynd.com http://www.google.com');user_pref('capability.policy.localfilelinks.checkloaduri.enabled',/... 'allAccess');.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-18 12:08:42
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'Explorer.exe'(5404)
c:\windows\system32\btmmhook.dll
.
Heure de fin: 2009-02-18 12:10:26
ComboFix-quarantined-files.txt 2009-02-18 11:10:23

Avant-CF: 153 606 766 592 octets libres
Après-CF: 153,581,486,080 octets libres

302 --- E O F --- 2009-02-15 11:39:37
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 03:46
ah tiens!
bizare, c'est toi qui est sur l'autre forum??

bref, je vais faire le truc avec plaisir!

au point où j'en suis! lol!
allez, hop!
0
Utilisateur anonyme
18 févr. 2009 à 04:26
Merci Willy :)
0
seesaw Messages postés 312 Date d'inscription dimanche 30 décembre 2007 Statut Membre Dernière intervention 12 mars 2018 8
18 févr. 2009 à 12:16
ne sachant pas si tu as reçu (ton aide est encore la bienvenue, et je t'en remercie malgré les difficultés! :)) le poste combofix que j'ai enfin pu faire je te l'envoie :

ComboFix 09-02-17.02 - moi 2009-02-18 12:06:17.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1117 [GMT 1:00]
Lancé depuis: c:\users\moi\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Un nouveau point de restauration a été créé
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-18 au 2009-02-18 ))))))))))))))))))))))))))))))))))))
.

2009-02-18 02:32 . 2009-02-18 02:42 101,287 --a------ c:\windows\System32\drivers\klin.dat
2009-02-18 02:32 . 2009-02-18 02:42 89,601 --a------ c:\windows\System32\drivers\klick.dat
2009-02-18 02:31 . 2009-02-18 11:58 <REP> d-------- c:\users\All Users\Kaspersky Lab
2009-02-18 02:31 . 2009-02-18 11:58 <REP> d-------- c:\programdata\Kaspersky Lab
2009-02-18 02:31 . 2009-02-18 02:31 <REP> d-------- c:\program files\Kaspersky Lab
2009-02-18 02:31 . 2009-02-18 04:09 3,293,728 --ahs---- c:\windows\System32\drivers\fidbox.dat
2009-02-18 02:31 . 2009-02-18 12:07 409,632 --ahs---- c:\windows\System32\drivers\fidbox2.dat
2009-02-18 02:31 . 2009-02-18 04:09 26,812 --ahs---- c:\windows\System32\drivers\fidbox.idx
2009-02-18 02:31 . 2009-02-18 12:05 2,480 --ahs---- c:\windows\System32\drivers\fidbox2.idx
2009-02-18 02:27 . 2009-02-18 02:27 <REP> d-------- c:\windows\Sun
2009-02-18 00:41 . 2009-02-18 03:21 <REP> d-------- c:\program files\UsbFix
2009-02-17 15:07 . 2009-02-17 15:07 <REP> d-------- C:\_OTMoveIt
2009-02-17 14:52 . 2009-02-17 14:52 <REP> d-------- c:\program files\JRE
2009-02-17 13:19 . 2009-02-17 13:16 132,597 --a------ C:\Flash_Disinfector.exe
2009-02-17 13:15 . 2009-02-17 13:15 <REP> d-------- c:\users\All Users\McAfee
2009-02-17 13:15 . 2009-02-17 13:15 <REP> d-------- c:\programdata\McAfee
2009-02-17 13:08 . 2009-02-17 13:30 <REP> d-------- c:\users\moi\AppData\Roaming\U3
2009-02-17 12:35 . 2009-02-17 12:35 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-02-17 11:50 . 2009-02-17 13:08 <REP> d-------- c:\program files\FindyKill
2009-02-17 11:25 . 2009-02-18 03:33 <REP> d-------- C:\rsit
2009-02-17 02:29 . 2009-02-17 02:29 <REP> d-------- c:\users\moi\AppData\Roaming\Malwarebytes
2009-02-17 02:29 . 2009-02-17 02:29 <REP> d-------- c:\users\All Users\Malwarebytes
2009-02-17 02:29 . 2009-02-17 02:29 <REP> d-------- c:\programdata\Malwarebytes
2009-02-16 23:23 . 2009-02-17 13:25 <REP> d-------- c:\program files\Ad-remover
2009-02-16 23:03 . 2009-02-18 03:33 <REP> d-------- c:\program files\Trend Micro
2009-02-15 12:38 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-15 12:38 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-15 12:38 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-15 12:38 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-15 12:38 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-14 23:41 . 2009-02-15 00:00 <REP> d-------- c:\users\moi\AppData\Roaming\skypePM
2009-02-14 23:41 . 2009-02-14 23:41 56 --ah----- c:\users\All Users\ezsidmv.dat
2009-02-14 23:41 . 2009-02-14 23:41 56 --ah----- c:\programdata\ezsidmv.dat
2009-02-14 23:40 . 2009-02-15 02:40 <REP> d-------- c:\users\moi\AppData\Roaming\Skype
2009-02-14 23:39 . 2009-02-14 23:39 <REP> dr------- c:\program files\Skype
2009-02-14 23:39 . 2009-02-14 23:39 <REP> d-------- c:\program files\Common Files\Skype
2009-02-12 17:32 . 2009-02-12 17:32 <REP> d-------- c:\users\All Users\FLEXnet
2009-02-12 17:32 . 2009-02-12 17:32 <REP> d-------- c:\programdata\FLEXnet
2009-02-11 11:54 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 11:54 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-09 22:08 . 2009-02-09 22:08 <REP> d-------- c:\program files\Common Files\Scanner
2009-02-09 22:08 . 2009-02-09 22:10 <REP> d-------- c:\program files\CA Yahoo! Anti-Spy
2009-02-04 23:39 . 2009-02-04 23:39 2,117,632 --a------ c:\windows\System32\python25.dll
2009-02-04 23:39 . 2008-09-16 17:26 1,332,197 --a------ c:\windows\System32\pythondll.zip
2009-02-04 23:39 . 2009-02-04 23:39 339,968 --a------ c:\windows\System32\pythoncom25.dll
2009-02-04 23:39 . 2009-02-04 23:39 114,688 --a------ c:\windows\System32\pywintypes25.dll
2009-02-04 23:37 . 2009-02-04 23:39 <REP> d-------- c:\program files\AGI
2009-02-03 16:09 . 2009-02-03 16:19 <REP> d-------- C:\Poker
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Videos
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Searches
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Saved Games
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Pictures
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Music
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Links
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Downloads
2009-02-03 01:08 . 2009-02-03 01:08 <REP> dr------- c:\windows\System32\config\systemprofile\Documents
2009-02-03 01:08 . 2009-02-03 01:09 <REP> d-------- C:\VAIO Entertainment
2009-02-01 01:36 . 2009-02-01 01:44 <REP> d-------- c:\users\moi\AppData\Roaming\ArcSoft
2009-02-01 01:31 . 2004-07-20 18:21 245,408 --a------ c:\windows\System32\unicows.dll
2009-02-01 01:31 . 2006-03-30 16:53 212,480 --a------ c:\windows\System32\PCDLIB32.DLL
2009-02-01 01:31 . 2007-11-10 14:10 55,808 --a------ c:\windows\System32\ArcSoftKsUFilter.dll
2009-02-01 01:31 . 2007-12-20 15:52 17,408 --a------ c:\windows\System32\drivers\ArcSoftKsUFilter.sys
2009-01-30 22:48 . 2009-01-30 22:48 <REP> d-------- c:\program files\Common Files\Macrovision Shared
2009-01-30 13:44 . 2009-01-30 13:47 <REP> d--h----- c:\users\TEMP\AppData
2009-01-30 13:44 . 2009-01-30 13:47 <REP> d-------- c:\users\TEMP
2009-01-30 12:30 . 2009-02-18 02:42 370 --a------ c:\windows\System32\%LocalXml%
2009-01-30 11:58 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-01-30 11:58 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-01-30 11:58 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-01-30 11:58 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-01-30 11:58 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-01-30 11:58 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-01-30 11:58 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-01-30 11:58 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-01-30 11:53 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-01-30 11:53 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-01-30 11:53 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-01-30 11:53 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-01-30 11:53 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-01-29 22:48 . 2009-01-29 22:48 <REP> d-------- C:\PerfLogs
2009-01-29 15:00 . 2009-01-29 15:00 <REP> d-------- c:\users\All Users\HP Product Assistant
2009-01-29 15:00 . 2009-01-29 15:00 <REP> d-------- c:\programdata\HP Product Assistant
2009-01-29 14:55 . 2009-01-29 14:56 <REP> d-------- c:\program files\Common Files\HP
2009-01-29 14:42 . 2009-01-29 14:58 148,935 --a------ c:\windows\hppins20.dat
2009-01-29 14:42 . 2007-03-01 03:21 16,655 --a------ c:\windows\hppmdl20.dat
2009-01-29 13:36 . 2005-10-24 13:55 830,464 --a------ c:\users\moi\hp_ize.exe
2009-01-29 13:32 . 2009-01-29 13:33 19,497 --a------ c:\windows\hpqins13.dat
2009-01-29 13:18 . 2009-01-29 13:18 <REP> d-------- c:\users\moi\AppData\Roaming\Printer Info Cache
2009-01-29 13:18 . 2009-02-01 03:38 <REP> d-------- c:\users\moi\AppData\Roaming\Image Zone Express
2009-01-29 13:04 . 2009-01-29 15:12 <REP> d-------- c:\users\moi\AppData\Roaming\HP
2009-01-29 13:04 . 2009-01-29 13:04 <REP> d-------- c:\users\All Users\WEBREG
2009-01-29 13:04 . 2009-01-29 14:05 <REP> d-------- c:\users\All Users\HPSSUPPLY
2009-01-29 13:04 . 2009-01-29 13:04 <REP> d-------- c:\programdata\WEBREG
2009-01-29 13:04 . 2009-01-29 14:05 <REP> d-------- c:\programdata\HPSSUPPLY
2009-01-29 12:58 . 2009-01-29 12:58 <REP> d-------- c:\users\All Users\Hewlett-Packard
2009-01-29 12:58 . 2009-01-29 12:58 <REP> d-------- c:\programdata\Hewlett-Packard
2009-01-29 12:42 . 2007-01-29 14:22 117,760 --a------ c:\windows\System32\hpz3l4v2.dll
2009-01-29 12:41 . 2007-02-01 08:14 258,048 --a------ c:\windows\System32\hpzids01.dll
2009-01-29 12:24 . 2009-01-29 14:56 <REP> d-------- c:\program files\HP
2009-01-29 12:21 . 2009-01-29 22:17 <REP> d-------- c:\users\All Users\HP
2009-01-29 12:21 . 2009-01-29 22:17 <REP> d-------- c:\programdata\HP
2009-01-28 23:02 . 2008-01-19 08:33 2,623,488 --a------ c:\windows\System32\SLsvc.exe
2009-01-28 23:02 . 2008-01-19 08:36 1,541,120 --a------ c:\windows\System32\onex.dll
2009-01-28 23:00 . 2008-01-19 08:33 8,139,264 --a------ c:\windows\System32\ssBranded.scr
2009-01-28 22:59 . 2008-01-19 08:32 5,714,432 --a------ c:\windows\System32\logon.scr
2009-01-28 22:58 . 2008-01-19 07:06 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-01-28 22:57 . 2008-01-19 08:34 305,152 --a------ c:\windows\System32\msdelta.dll
2009-01-28 22:57 . 2008-01-19 08:34 258,560 --a------ c:\windows\System32\dpx.dll
2009-01-28 22:57 . 2008-01-19 08:34 246,784 --a------ c:\windows\System32\drvstore.dll
2009-01-28 22:57 . 2008-01-19 08:35 35,328 --a------ c:\windows\System32\mspatcha.dll
2009-01-28 20:39 . 2009-01-28 20:39 <REP> d-------- c:\users\All Users\NOS
2009-01-28 20:39 . 2009-01-28 20:39 <REP> d-------- c:\programdata\NOS
2009-01-28 20:39 . 2009-01-28 20:39 <REP> d-------- c:\program files\NOS
2009-01-28 12:33 . 2009-01-28 12:33 <REP> d-------- c:\users\moi\AppData\Roaming\OpenOffice.org
2009-01-28 12:08 . 2009-01-28 12:08 <REP> d-------- c:\users\All Users\Kaspersky Lab Setup Files
2009-01-28 12:08 . 2009-01-28 12:08 <REP> d-------- c:\programdata\Kaspersky Lab Setup Files
2009-01-28 12:04 . 2009-02-17 14:51 <REP> d-------- c:\program files\OpenOffice.org 3
2009-01-28 10:24 . 2009-01-28 11:41 <REP> d-------- c:\users\moi\AppData\Roaming\OpenOffice.org2
2009-01-28 10:20 . 2009-01-28 12:04 <REP> d-------- c:\program files\OpenOffice.org 2.2
2009-01-27 23:41 . 2009-02-06 02:08 <REP> d-------- c:\program files\Defraggler
2009-01-27 23:39 . 2009-01-27 23:39 <REP> d-------- c:\program files\CCleaner
2009-01-27 23:31 . 2009-01-27 23:31 <REP> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-27 23:31 . 2009-01-27 23:31 269,312 --a------ c:\windows\System32\es.dll
2009-01-27 22:08 . 2009-01-27 22:08 <REP> d-------- c:\users\moi\AppData\Roaming\InstallShield
2009-01-27 21:57 . 2009-01-27 21:57 <REP> d-------- c:\users\moi\AppData\Roaming\DivX

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-18 11:03 --------- d-----w c:\program files\Google
2009-02-18 01:42 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-14 22:39 --------- d-----w c:\programdata\Skype
2009-02-11 11:37 --------- d-----w c:\program files\Windows Mail
2009-02-10 14:33 --------- d-----w c:\program files\Java
2009-02-03 00:08 --------- d-----w c:\programdata\Sony Corporation
2009-02-01 00:40 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-30 21:48 --------- d-----w c:\program files\Common Files\Adobe
2009-01-29 21:58 174 --sha-w c:\program files\desktop.ini
2009-01-29 21:49 --------- d-----w c:\program files\Windows Sidebar
2009-01-29 21:49 --------- d-----w c:\program files\Windows Photo Gallery
2009-01-29 21:49 --------- d-----w c:\program files\Windows Journal
2009-01-29 21:49 --------- d-----w c:\program files\Windows Defender
2009-01-29 21:49 --------- d-----w c:\program files\Windows Collaboration
2009-01-29 21:49 --------- d-----w c:\program files\Windows Calendar
2009-01-29 21:34 82,432 ----a-w c:\windows\System32\axaltocm.dll
2009-01-29 21:34 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2009-01-27 22:32 --------- d-----w c:\programdata\Microsoft Help
2009-01-27 22:27 --------- d-----w c:\program files\Microsoft Works
2009-01-27 22:00 --------- d-----w c:\program files\Sony
2009-01-27 22:00 --------- d-----w c:\program files\Common Files\Sony Shared
2009-01-27 19:21 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2009-01-27 19:21 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-27 19:21 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-27 19:21 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2009-01-27 19:21 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2009-01-27 19:21 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-27 19:12 9,847,296 ----a-w c:\windows\System32\NlsData000a.dll
2009-01-27 18:54 996,352 ----a-w c:\windows\System32\WMNetMgr.dll
2009-01-27 18:54 98,816 ----a-w c:\windows\System32\mfps.dll
2009-01-27 18:54 94,720 ----a-w c:\windows\System32\logagent.exe
2009-01-27 18:54 84,480 ----a-w c:\windows\System32\INETRES.dll
2009-01-27 18:54 738,304 ----a-w c:\windows\System32\inetcomm.dll
2009-01-27 18:54 53,248 ----a-w c:\windows\System32\rrinstaller.exe
2009-01-27 18:54 288,768 ----a-w c:\windows\system32\drivers\srv.sys
2009-01-27 18:54 24,576 ----a-w c:\windows\System32\mfpmp.exe
2009-01-27 18:54 2,868,736 ----a-w c:\windows\System32\mf.dll
2009-01-27 18:54 2,048 ----a-w c:\windows\System32\mferror.dll
2009-01-27 18:54 1,645,568 ----a-w c:\windows\System32\connect.dll
2009-01-27 18:54 1,314,816 ----a-w c:\windows\System32\quartz.dll
2009-01-27 17:15 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-01-27 17:01 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-04 23:11 308,584 ----a-w c:\windows\WLXPGSS.SCR
2008-12-02 21:37 49,480 ----a-w c:\windows\System32\sirenacm.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-12 443968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-06-10 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-09-19 311296]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-02 1838592]
"MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2007-11-02 36864]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-10-30 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-30 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-30 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-10 148888]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-18 206088]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-08-28 739880]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 20:05 98304 c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\program files\Common Files\Sony Shared\VideoLib\sonydv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{AB636B88-B70A-437A-AD96-EBCD9D37871E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{98656251-E95C-4BB3-9267-CE63813A0C49}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2C2F61F9-8DA2-44C7-A22A-68A261ABB719}"= Disabled:UDP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{AFA15B50-6C27-4075-812A-4FDB7583A6A3}"= Disabled:TCP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{3BF0911B-0DC7-4948-B237-53BD7534B6EA}"= UDP:c:\users\moi\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{C80A73FE-9302-466D-8B9A-E5A638A2B003}"= TCP:c:\users\moi\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{15627994-46BD-4860-9726-11A9471F7699}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{772D3550-9599-4D4B-99FC-659DAE740D73}"= c:\program files\HP\Digital Imaging\bin\hpqpse.exe:hpqpse.exe
"{6F006875-2CEE-4673-9D80-B56578CC0671}"= c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe:hpqphotocrm.exe
"{F513F5FA-9208-4873-B396-D1999F94760F}"= c:\program files\HP\Digital Imaging\bin\hpqsudi.exe:hpqsudi.exe
"{4C250F66-C12C-4B0E-8EE9-1DE43B4A9CFC}"= c:\program files\HP\Digital Imaging\bin\hpqpsapp.exe:hpqpsapp.exe
"{DF71B73D-5B33-44EF-B871-56447F69258C}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{E69F1DE4-F724-4F14-81E1-78EB7C670AED}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{AA619891-28E9-43DF-8D5C-9CAF37173BF3}"= c:\program files\Skype\Phone\Skype.exe:Skype

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [2008-01-29 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [2008-07-09 20496]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [2007-04-17 11032]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2009-02-01 104960]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-01-27 333088]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\System32\drivers\ArcSoftKsUFilter.sys [2009-02-01 17408]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [2008-03-13 26640]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [2007-11-02 75008]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [2007-11-02 43904]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [2007-11-02 9344]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [2007-11-02 812544]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [2007-11-02 28464]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-28 33752]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [2009-01-27 436096]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [2009-01-27 745472]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2009-01-27 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2009-01-27 1089536]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2009-01-27 87328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mStart Page = about:blank
IE: Ajouter à Kaspersky Anti-Bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\users\moi\AppData\Roaming\Mozilla\Firefox\Profiles\wshfj6uk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Wikipédia (fr)
FF - prefs.js: browser.startup.homepage - hxxp://fr.yahoo.com/r/hf
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- PARAMETRES FIREFOX ----
user_pref('capability.policy.policynames', 'localfilelinks');user_pref('capability.policy.localfilelinks.sites', 'hxxp://www.webmynd.com http://www.google.com');user_pref('capability.policy.localfilelinks.checkloaduri.enabled',/... 'allAccess');.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-18 12:08:42
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'Explorer.exe'(5404)
c:\windows\system32\btmmhook.dll
.
Heure de fin: 2009-02-18 12:10:26
ComboFix-quarantined-files.txt 2009-02-18 11:10:23

Avant-CF: 153 606 766 592 octets libres
Après-CF: 153,581,486,080 octets libres

302 --- E O F --- 2009-02-15 11:39:37
0