Bonsoir rico25
D'abord merci de m'avoir répondu et pardon de ne réapparaitre que maitenant, j'étais pris toute la journée.
J'ai fait comme vous m'avez demandé pour Flash_disinfector ainsi que pour RSIT.exe.
Voici le contenu de log.txt:
Logfile of random's system information tool 1.05 (written by random/random)
Run by ML at 2009-03-24 20:01:04
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 32 GB (81%) free of 40 GB
Total RAM: 1014 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:01:26, on 24/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\X'nBeep 1.1\XnBeep.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\GPS Pathfinder Office 3.10\conmgr.exe
C:\Program Files\GPS Pathfinder Office 3.10\pfpjchgr.exe
C:\Program Files\Larousse\Petit Larousse 2008\bin\Hyperappel.exe
C:\PROGRA~1\FICHIE~1\Trimble\REMOTE~1\TRDMU.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\ML\Bureau\RSIT.exe
C:\Program Files\trend micro\ML.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EoBho - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PFO Check Settings] pfochk.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnnivJ] "C:\Program Files\AnnivJ\AnnivJ.exe" -s
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
O4 - HKCU\..\Run: [HPersonalOrganizer] "C:\Program Files\Hyperpractical\The Hyperpractical Personal Organizer\Hyperpratical.PersonalOrganizer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: GPS Pathfinder Office Connection Manager.lnk = C:\Program Files\GPS Pathfinder Office 3.10\conmgr.exe
O4 - Global Startup: GPS Pathfinder Office Project Changer.lnk = C:\Program Files\GPS Pathfinder Office 3.10\pfpjchgr.exe
O4 - Global Startup: Hyperappel du Petit Larousse 2008.lnk = C:\Program Files\Larousse\Petit Larousse 2008\bin\Hyperappel.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: SmarThru4 Capture Selection - C:\Program Files\SmarThru 4\WebCapture.dll2.htm
O8 - Extra context menu item: SmarThru4 Enregistrer au format HTML - C:\Program Files\SmarThru 4\WebCapture.dll1.htm
O8 - Extra context menu item: SmarThru4 Enregistrer le texte sélectionné - C:\Program Files\SmarThru 4\WebCapture.dll.htm
O8 - Extra context menu item: SmarThru4 Save as HTML - C:\Program Files\SmarThru 4\WebCapture.dll1.htm
O8 - Extra context menu item: SmarThru4 Save Selected Text - C:\Program Files\SmarThru 4\WebCapture.dll.htm
O8 - Extra context menu item: SmarThru4 Sélection par capture - C:\Program Files\SmarThru 4\WebCapture.dll2.htm
O8 - Extra context menu item: SmarThru4 Web Capture - C:\Program Files\SmarThru 4\WebCapture.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: SmarThru4 Web Capture - {5941A0E4-56C1-4a49-9B18-05762CAC5F9B} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Web Capture - {5941A0E4-56C1-4a49-9B18-05762CAC5F9B} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra button: SmarThru4 Sélection par capture - {A07BFEF7-DD11-4937-B23B-E70C11D2EDF4} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Sélection par capture - {A07BFEF7-DD11-4937-B23B-E70C11D2EDF4} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra button: SmarThru4 Enregistrer au format HTML - {E753A93F-2367-4978-BFA0-83048C1E61CB} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Enregistrer au format HTML - {E753A93F-2367-4978-BFA0-83048C1E61CB} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra button: SmarThru4 Enregistrer le texte sélectionné - {F1F53366-3E11-47ab-BF84-580C94F9C9AD} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: SmarThru4 Enregistrer le texte sélectionné - {F1F53366-3E11-47ab-BF84-580C94F9C9AD} - C:\Program Files\SmarThru 4\WebCapture.dll (HKCU)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3B15DC6-4B0A-4BFA-BD38-5A88D904BAEF}: NameServer = 208.67.222.222 193.55.10.102
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
End of file - 8021 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GlaryInitialize.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2007-08-03 1826816]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-06-13 142104]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-06-13 162584]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-06-13 138008]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"PFO Check Settings"=C:\WINDOWS\pfochk.exe [2005-04-17 57344]
"Samsung PanelMgr"=C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe [2008-04-16 536576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"AnnivJ"=C:\Program Files\AnnivJ\AnnivJ.exe [2008-12-18 94208]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2005-04-22 1196032]
"X'nBeep"=C:\Program Files\X'nBeep 1.1\XnBeep.exe [2007-01-06 1067520]
"HPersonalOrganizer"=C:\Program Files\Hyperpractical\The Hyperpractical Personal Organizer\Hyperpratical.PersonalOrganizer.exe [2009-02-06 798720]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
GPS Pathfinder Office Connection Manager.lnk - C:\Program Files\GPS Pathfinder Office 3.10\conmgr.exe
GPS Pathfinder Office Project Changer.lnk - C:\Program Files\GPS Pathfinder Office 3.10\pfpjchgr.exe
Hyperappel du Petit Larousse 2008.lnk - C:\Program Files\Larousse\Petit Larousse 2008\bin\Hyperappel.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-06-05 204800]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=36
"NoDriveAutoRun"=FFFFFFFF
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a66b1cb4-001e-11de-9f90-0022682e87e8}]
shell\AutoRun\command - H:\cv22.cmd
shell\open\command - H:\cv22.cmd
======List of files/folders created in the last 1 months======
2009-03-24 20:01:04 ----D---- C:\rsit
2009-03-23 10:26:10 ----D---- C:\Documents and Settings\ML\Application Data\Macromedia
2009-03-22 18:14:06 ----D---- C:\Program Files\Larousse
2009-03-22 18:13:49 ----D---- C:\Program Files\MSXML 4.0
2009-03-22 16:20:15 ----D---- C:\Documents and Settings\ML\Application Data\Bullzip
2009-03-22 16:17:56 ----A---- C:\WINDOWS\system32\msxml6r.dll
2009-03-22 16:17:56 ----A---- C:\WINDOWS\system32\msxml6.dll
2009-03-22 16:13:03 ----D---- C:\Program Files\PDFTK Builder
2009-03-22 14:11:46 ----D---- C:\Program Files\Hyperpractical
2009-03-22 14:11:46 ----D---- C:\Documents and Settings\ML\Application Data\Hyperpractical
2009-03-12 14:17:52 ----D---- C:\Program Files\iColorFolder
2009-03-12 13:57:59 ----D---- C:\Program Files\X'nBeep 1.1
2009-03-11 21:47:01 ----D---- C:\Documents and Settings\ML\Application Data\SmarThru4
2009-03-11 21:46:51 ----N---- C:\WINDOWS\system32\SecSNMP.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\LTRPR13n.DLL
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\LTRIO13N.DLL
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\LTR13N.DLL
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lfpsd13s.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\LFPNM13s.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lfitg13s.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lfitg13n.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lfimg13s.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lfimg13n.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lfiff13s.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lfiff13n.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lffax13s.dll
2009-03-11 21:46:50 ----A---- C:\WINDOWS\system32\lffax13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\PCDLIB32.DLL
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lttwn13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LTTLB13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\Ltpnt13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\ltpdg13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LTOCR13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\ltefx13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LTCLR13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\ltbar13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lftif13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lftif13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfpsd13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LFPNM13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\Lfpng13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\Lfpng13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfpcx13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfpcx13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfpcd13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfpcd13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfmsp13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfjbg13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LFJ2K13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LFJ2K13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfeps13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfeps13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LFCMP13s.DLL
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\LFCMP13n.DLL
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfclp13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfclp13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfbmp13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfavi13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfavi13n.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfani13s.dll
2009-03-11 21:46:49 ----A---- C:\WINDOWS\system32\lfani13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\Mfcoleui.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\Ltwvc13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\lttmb13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\ltlst13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\ltkrn13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\ltimg13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\ltfil13n.DLL
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\ltdlg13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\LTDIS13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\lfmsp13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\lfjbg13n.dll
2009-03-11 21:46:48 ----A---- C:\WINDOWS\system32\lfbmp13n.dll
2009-03-11 21:46:47 ----D---- C:\Program Files\Fichiers communs\SRC Shared
2009-03-11 21:46:44 ----A---- C:\WINDOWS\Readiris.ini
2009-03-11 21:46:42 ----A---- C:\WINDOWS\system32\irisco32.dll
2009-03-11 21:46:12 ----D---- C:\Program Files\Readiris10
2009-03-11 21:46:04 ----D---- C:\Program Files\SmarThru 4
2009-03-11 21:45:46 ----A---- C:\WINDOWS\ssndii.exe
2009-03-11 21:45:45 ----D---- C:\WINDOWS\Samsung
2009-03-11 21:45:16 ----A---- C:\WINDOWS\system32\sse1ml3.dll
2009-03-11 21:45:15 ----A---- C:\WINDOWS\system32\sse1mci.exe
2009-03-11 21:45:15 ----A---- C:\WINDOWS\system32\sse1mci.dll
2009-03-11 21:44:45 ----RA---- C:\WINDOWS\WiaInst.exe
2009-03-11 21:44:44 ----RA---- C:\WINDOWS\system32\WIASTIIO.dll
2009-03-11 21:44:44 ----RA---- C:\WINDOWS\system32\Ssusbpn.dll
2009-03-11 21:44:44 ----RA---- C:\WINDOWS\system32\Ssuiext.dll
2009-03-11 21:44:44 ----RA---- C:\WINDOWS\system32\Ssdevm.dll
2009-03-11 21:44:43 ----RA---- C:\WINDOWS\system32\WIAIPH.dll
2009-03-11 21:44:43 ----RA---- C:\WINDOWS\system32\WIAEH.dll
2009-03-11 21:44:43 ----RA---- C:\WINDOWS\system32\Sswiadrv.dll
2009-03-11 21:44:25 ----D---- C:\Program Files\Samsung
2009-03-11 13:12:24 ----D---- C:\Documents and Settings\ML\Application Data\vlc
2009-03-07 21:09:33 ----D---- C:\Documents and Settings\ML\Application Data\AdobeUM
2009-03-07 20:58:33 ----D---- C:\WINDOWS\system32\LogFiles
2009-03-07 20:48:20 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-03-07 20:48:19 ----HDC---- C:\WINDOWS\$NtUninstallKB890927$
2009-03-07 20:48:09 ----D---- C:\Program Files\Microsoft ActiveSync
2009-03-07 20:46:52 ----D---- C:\WINDOWS\Downloaded Installations
2009-03-07 20:45:33 ----A---- C:\WINDOWS\Export.INI
2009-03-07 20:14:18 ----A---- C:\WINDOWS\TRIMSURV.INI
2009-03-07 20:14:14 ----A---- C:\WINDOWS\timezone.ini
2009-03-07 20:14:14 ----A---- C:\WINDOWS\pfochk.exe
2009-03-07 20:14:08 ----D---- C:\Pfdata
2009-03-07 20:12:47 ----A---- C:\WINDOWS\system32\Roboex32.dll
2009-03-07 20:12:47 ----A---- C:\WINDOWS\system32\Inetwh32.dll
2009-03-07 20:12:44 ----D---- C:\Program Files\GPS Pathfinder Office 3.10
2009-03-07 20:12:44 ----D---- C:\Program Files\Fichiers communs\Trimble
2009-03-07 20:03:31 ----D---- C:\WINDOWS\Cache
2009-03-07 17:21:06 ----A---- C:\WINDOWS\uninst.exe
2009-03-07 16:50:38 ----D---- C:\Documents and Settings\ML\Application Data\Help
2009-03-02 16:30:04 ----D---- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2009-03-02 16:28:38 ----D---- C:\Program Files\NCH Software
2009-03-02 16:28:36 ----D---- C:\Program Files\NCH Swift Sound
2009-03-01 15:40:58 ----D---- C:\Program Files\MSECache
2009-02-28 08:43:33 ----D---- C:\Program Files\Frozen-Bubble
2009-02-28 08:40:44 ----D---- C:\Documents and Settings\ML\Application Data\Wallpaper
2009-02-28 08:36:33 ----D---- C:\Program Files\LED
2009-02-28 08:36:33 ----A---- C:\WINDOWS\system32\LedCommon.dll
2009-02-27 17:39:10 ----D---- C:\Program Files\AnnivJ
2009-02-27 17:39:10 ----D---- C:\Documents and Settings\ML\Application Data\AnnivJ
2009-02-27 17:35:13 ----D---- C:\Program Files\Common Files
2009-02-27 17:35:12 ----D---- C:\Program Files\AssosCompteScriptHp
2009-02-27 17:35:01 ----A---- C:\WINDOWS\unin040c.exe
2009-02-27 17:25:32 ----D---- C:\Program Files\Axon Data
2009-02-27 17:23:17 ----D---- C:\Program Files\Flexbyte Software
2009-02-27 17:23:17 ----D---- C:\Documents and Settings\ML\Application Data\Handy Uninstaller
2009-02-27 17:18:04 ----D---- C:\Program Files\kd11
2009-02-27 11:44:25 ----D---- C:\Program Files\a-squared Free
======List of files/folders modified in the last 1 months======
2009-03-24 20:01:26 ----D---- C:\Program Files\Trend Micro
2009-03-24 20:01:11 ----D---- C:\WINDOWS\Prefetch
2009-03-24 19:57:22 ----A---- C:\WINDOWS\DHO.INI
2009-03-24 19:56:57 ----D---- C:\WINDOWS\Temp
2009-03-24 19:56:57 ----A---- C:\WINDOWS\win.ini
2009-03-24 19:02:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-03-24 16:06:14 ----D---- C:\Documents and Settings\ML\Application Data\dvdcss
2009-03-23 08:38:11 ----D---- C:\WINDOWS
2009-03-22 21:55:22 ----D---- C:\WINDOWS\system32\CatRoot2
2009-03-22 20:30:52 ----RD---- C:\Program Files
2009-03-22 20:30:52 ----D---- C:\WINDOWS\system32
2009-03-22 18:16:30 ----SHD---- C:\WINDOWS\Installer
2009-03-22 18:16:20 ----D---- C:\Program Files\Fichiers communs\InstallShield
2009-03-22 18:16:09 ----RSD---- C:\WINDOWS\Fonts
2009-03-22 18:14:11 ----HD---- C:\WINDOWS\inf
2009-03-22 18:14:05 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-22 18:13:50 ----D---- C:\WINDOWS\WinSxS
2009-03-11 21:47:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-03-11 21:47:10 ----D---- C:\WINDOWS\system32\drivers
2009-03-11 21:46:47 ----D---- C:\Program Files\Fichiers communs
2009-03-11 21:44:39 ----D---- C:\WINDOWS\twain_32
2009-03-11 21:22:33 ----SD---- C:\Documents and Settings\ML\Application Data\Microsoft
2009-03-11 10:22:29 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-03-07 21:41:04 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-07 20:48:10 ----D---- C:\WINDOWS\Help
2009-03-07 16:48:55 ----D---- C:\Temp
2009-03-05 21:52:48 ----D---- C:\WINDOWS\SoftwareDistribution
2009-03-02 08:34:31 ----D---- C:\WINDOWS\system32\wbem
2009-03-01 15:43:44 ----D---- C:\Program Files\Microsoft Office
2009-02-27 19:02:01 ----SHD---- C:\RECYCLER
2009-02-27 18:59:59 ----D---- C:\Documents and Settings
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 40320]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
R2 DgiVecp;DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys []
R2 irda;Protocole IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-02-05 23152]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-06-05 5761728]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 irsir;Pilote série infrarouge Microsoft; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 FXDrv32;FXDrv32; \??\E:\FXDrv32.sys []
S3 usb_rndisx;Carte ISDN USB; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-01-27 12800]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2009-01-27 421496]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
et voici le cotenu de info.txt:
info.txt logfile of random's system information tool 1.05 2009-03-24 20:01:27
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}
Adobe Reader 7.0.7-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70700000002}
ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
Analyseur et SDK MSXML 4.0 SP2-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
AnnivJ 2.0.0-->C:\Program Files\AnnivJ\uninst.exe
a-squared Free 4.0-->"C:\Program Files\a-squared Free\unins000.exe"
AssosCompteScriptHp-->C:\WINDOWS\unin040c.exe -f"C:\Program Files\AssosCompteScriptHp\DeIsL1.isu" -c"C:\Program Files\AssosCompteScriptHp\_ISREG32.DLL"
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AxCrypt (Désinstaller uniquement)-->"C:\Program Files\Axon Data\AxCrypt\AxCryptU.exe"
ESET Online Scanner-->C:\WINDOWS\system32\OnlineScannerUninstaller.exe
EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
Express Rip-->C:\Program Files\NCH Swift Sound\ExpressRip\uninst.exe
Free Billiards 2008-->"D:\Free Billiards 2008\unins000.exe"
Glary Utilities 2.11.0.638-->"C:\Program Files\Glary Utilities\unins000.exe"
GPS Pathfinder Office 3.10-->C:\WINDOWS\UNINST.EXE -f"C:\Program Files\GPS Pathfinder Office 3.10\DeIsL1.isu" -c"C:\PROGRA~1\GPSPAT~1.10\PFUninst.dll
Handy Uninstaller 1.1-->"C:\Program Files\Flexbyte Software\Handy Uninstaller\unins000.exe"
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB890927)-->"C:\WINDOWS\$NtUninstallKB890927$\spuninst\spuninst.exe"
iColorFolder-->C:\Program Files\iColorFolder\uninstall.exe
Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
Microsoft ActiveSync 4.0-->MsiExec.exe /I{B208806F-A231-4FA0-AB3F-5C1B8979223E}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office Word Viewer 2003-->MsiExec.exe /I{9085040C-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
PDFTK Builder 3.5.3-->"C:\Program Files\PDFTK Builder\unins000.exe"
Petit Larousse 2008-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{422FADA9-FED2-41D7-B5FA-472BB98B7784}\Setup.exe" -l0x40c
Readiris Pro 10-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14D08502-FEE4-40E5-90D3-8A967A1D8BA2}\setup.exe" -l0x40c
REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\Setup.exe -runfromtemp -l0x040c -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
SADDR v 0.9-->MsiExec.exe /X{FCD69ACA-14F8-4045-8148-248762DC6463}
Samsung SCX-4300 Series-->C:\Program Files\Samsung\Samsung SCX-4300 Series\Install\Setup.exe /R
SmarThru 4-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{90F1943D-EA4A-4460-B59F-30023F3BA69A}\Setup.exe" -l0x40c uninstall -l040c
Sudoku 03.03.2006-->"C:\Program Files\Logiciels Sebastien GRENIER\Sudoku\uninstall.exe"
The Hyper-practical Personal Organizer (L'Organisateur Personne-->"C:\Program Files\Hyperpractical\The Hyperpractical Personal Organizer\unins000.exe"
TomCat Soft : Le Pendu-->"D:\Le Pendu\unins000.exe"
VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
X'nBeep 1.1-->"C:\Program Files\X'nBeep 1.1\unins000.exe"
======Security center information======
AV: avast! antivirus 4.8.1335 [VPS 090323-0]
System event log
Computer Name: USER-8385C99097
Event Code: 15007
Message: La réservation de l'espace de nom identifié par le préfixe d'URL *:2869/ a été correctement ajoutée.
Record Number: 5
Source Name: HTTP
Time Written: 20090221093948.000000+060
Event Type: Informations
User:
Computer Name: USER-8385C99097
Event Code: 6011
Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers USER-8385C99097.
Record Number: 4
Source Name: EventLog
Time Written: 20090221093651.000000+060
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 2
Message: Pendant la validation de \Device\Serial0 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée.
Record Number: 3
Source Name: Serial
Time Written: 20090221102234.000000+060
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6005
Message: Le service d'Enregistrement d'événement a démarré.
Record Number: 2
Source Name: EventLog
Time Written: 20090221102212.000000+060
Event Type: Informations
User:
Computer Name: MACHINENAME
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.
Record Number: 1
Source Name: EventLog
Time Written: 20090221102212.000000+060
Event Type: Informations
User:
Application event log
Computer Name: USER-8385C99097
Event Code: 1000
Message: Les compteurs de performances pour le service MSDTC (MSDTC) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.
Record Number: 5
Source Name: LoadPerf
Time Written: 20090221093808.000000+060
Event Type: Informations
User:
Computer Name: USER-8385C99097
Event Code: 1000
Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.
Record Number: 4
Source Name: LoadPerf
Time Written: 20090221093806.000000+060
Event Type: Informations
User:
Computer Name: USER-8385C99097
Event Code: 1000
Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.
Record Number: 3
Source Name: LoadPerf
Time Written: 20090221093713.000000+060
Event Type: Informations
User:
Computer Name: USER-8385C99097
Event Code: 1000
Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.
Record Number: 2
Source Name: LoadPerf
Time Written: 20090221093658.000000+060
Event Type: Informations
User:
Computer Name: USER-8385C99097
Event Code: 1000
Message: Les compteurs de performances pour le service RSVP (QoS RSVP) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.
Record Number: 1
Source Name: LoadPerf
Time Written: 20090221093657.000000+060
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ESTsoft\ALZip\;C:\Program Files\GPS Pathfinder Office 3.10
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------