Bon j'ai fait "continuer" sur les quelques messages d'erreur (celui indiqué plus haut).
Voici le rapport :
############################## | UsbFix V6.023 |
User : odewit (Administrateurs) # ODEWIT-VISTA
Update on 29/08/09 by Chiquitine29, C_XX & Chimay8
Start at: 19:00:53 | 30/08/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
AMD Turion(tm) 64 X2 Mobile Technology TL-50
Microsoft® Windows Vista™ Professionnel (6.0.6000 32-bit) #
Internet Explorer 7.0.6000.16830
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Disque fixe local # 149,05 Go (93,69 Go free) # NTFS
D:\ -> Disque CD-ROM
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local # 298,09 Go (104,7 Go free) [Wexterne] # NTFS
############################## | Processus actifs |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Multimedia Card Reader\readericon10.exe
C:\Program Files\Hotkey Management\FuncKey.exe
C:\Program Files\Power Manager\PM.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Users\odewit\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\program files\avira\antivir desktop\avcenter.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
################## | Fichiers # Dossiers infectieux |
F:\autorun.inf # -> fichier appelé : "F:\RECYCLED\INFO.exe" ( Présent ! )
Présent ! F:\.\recycled\info.exe
Présent ! F:\autorun.inf
Présent ! F:\RECYCLED\INFO.exe
################## | Suspect ! ... |
http://www.virustotal.com |
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\##odewitMacVista#Dev
shell\AutoRun\command =Z:\
shell\explore\Command =Z:\RECYCLED\INFO.exe
shell\open\Command =Z:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\F
shell\AutoRun\command =F:\
shell\explore\Command =F:\RECYCLED\INFO.exe
shell\open\Command =F:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\G
shell\AutoRun\command =G:\
shell\explore\Command =G:\RECYCLED\INFO.exe
shell\open\Command =G:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\{0a34fac2-1f9c-11de-a286-001060d2e988}
shell\AutoRun\command =F:\
shell\explore\Command =F:\RECYCLED\INFO.exe
shell\open\Command =F:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\{215ac330-2e53-11de-9739-001060d2e988}
shell\AutoRun\command =F:\
shell\explore\Command =F:\RECYCLED\INFO.exe
shell\open\Command =F:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\{3d501213-ef86-11dd-ab80-001060d2e988}
shell\AutoRun\command =G:\
shell\explore\Command =G:\RECYCLED\INFO.exe
shell\open\Command =G:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\{4d29f407-f032-11dd-a86d-001060d2e988}
shell\AutoRun\command =F:\
shell\explore\Command =F:\RECYCLED\INFO.exe
shell\open\Command =F:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\{8044eda7-9555-11de-8e53-001060d2e988}
shell\AutoRun\command =F:\
shell\explore\Command =F:\RECYCLED\INFO.exe
shell\open\Command =F:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\{9fd1ca2e-35a9-11de-80e8-001060d2e988}
shell\AutoRun\command =F:\
shell\explore\Command =F:\RECYCLED\INFO.exe
shell\open\Command =F:\RECYCLED\INFO.exe
HKCU\..\..\Explorer\MountPoints2\{9fd1ca3c-35a9-11de-80e8-001060d2e988}
shell\AutoRun\command =F:\
shell\explore\Command =F:\RECYCLED\INFO.exe
shell\open\Command =F:\RECYCLED\INFO.exe
################## | Cracks / Keygens / Serials |
################## | ! Fin du rapport # UsbFix V6.023 ! |
info.txt logfile of random's system information tool 1.06 2010-01-11 14:38:31
======Uninstall list======
-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
-->C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe /uninstall
-->C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe /uninstall
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.8 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70800000002}
Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Altiris Application Metering Agent-->MsiExec.exe /I{4A702DA1-9E48-4346-8030-26B399CCFA8C}
Altiris Carbon Copy Solution Agent -->MsiExec.exe /X{332454D8-73B0-4B4A-954C-D96089CD898A}
Altiris Carbon Copy Solution Agent 6.2-->MsiExec.exe /x {332454D8-73B0-4b4a-954C-D96089CD898A} /qf
Altiris Client Task Agent-->MsiExec.exe /I{A407490A-166A-464A-BB97-457732BDB7BD}
Altiris Power Management Agent-->MsiExec.exe /I{AD85A594-6928-4F8C-A32E-039F3670F31B}
Altiris Script Task Agent-->MsiExec.exe /I{E0AFFA7A-E135-4CA5-9836-297F042D7130}
Altiris Service Control Task Agent-->MsiExec.exe /I{D4BB3396-F72E-4074-9631-D9BBF264F8D9}
Altiris Software Delivery Solution Agent-->MsiExec.exe /X{A0A1EB01-A6FD-423A-8480-364055A7C961}
Altiris Task Synchronization Agent-->MsiExec.exe /X{2851123E-5786-41BE-A3F1-A9B21E499EEB}
Broadcom Gigabit Integrated Controller-->MsiExec.exe /X{A64A5576-D862-44F8-89DC-2B17FCC9B86E}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
e/pop 3.0 Spell Check & Thesaurus-->MsiExec.exe /I{3AF3CB05-EE06-46B0-B209-EE343BBD6A2D}
e/pop Desktop 3.1.3.605-->MsiExec.exe /I{125DAF1E-E671-405C-A4C3-E4E90FEC27FA}
Euroglot 4.5-->MsiExec.exe /I{ECD28038-9F24-4D1F-94A2-DA378597B7D5}
High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2-->"C:\DOCUME~1\CI015786\LOCALS~1\Temp\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB896344)-->"C:\WINDOWS\$NtUninstallKB896344$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
HP Install Network Printer Wizard-->MsiExec.exe /X{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}
iGraal Toolbar for Internet Explorer-->"C:\Program Files\iGraal\uninstall.exe"
Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Livelink Imaging 9.5-->MsiExec.exe /I{96538711-469D-4B19-B2F3-F1E49F4A9E0E}
LiveUpdate 3.1 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lotus Notes 7.0.2 fr-->MsiExec.exe /I{5406E11A-EB38-486E-8C9D-770B5F34F71D}
Lotus Notes Dictionary-->MsiExec.exe /I{A4C6828B-AA60-4085-8722-654A8ABADA2D}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Base Smart Card Cryptographic Service Provider Package-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office 2003 French User Interface Pack-->MsiExec.exe /I{901E040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office 2003 Proofing Tools-->MsiExec.exe /I{901F0409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Standard Edition 2003-->MsiExec.exe /I{90120409-6000-11D3-8CFE-0150048383C9}
Microsoft redistributable runtime DLLs VS2005 SP1(x86)-->MsiExec.exe /I{8E770F99-CF23-4BF9-BF4E-E3A2924FEB27}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML4.0 redistributable-->MsiExec.exe /I{44D66AD9-AE19-4AFD-BE7E-A1B44C856697}
PDF-XChange Registered Release-->MsiExec.exe /I{CBC5921A-8601-4A76-A003-0770345DA502}
Proxy Host-->MsiExec.exe /I{8B519E5C-409B-4332-9A64-CCF1836A3424}
Proxy Master-->MsiExec.exe /I{0840F8AF-756F-4E60-818F-72A3C94B9063}
SAP Business Explorer-->"C:\Program Files\SAP\SAPsetup\setup\NwSapSetup.exe" /product="SAPBI" /uninstall
SAP GUI 7.10-->"C:\Program Files\SAP\SAPsetup\setup\NwSapSetup.exe" /product="SAPGUI710" /uninstall
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Windows Media Player (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Security Update for Windows XP (KB939653)-->"C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971032)-->"C:\WINDOWS\$NtUninstallKB971032$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974455)-->"C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
SnagIt 7-->MsiExec.exe /I{4360BB46-507E-4361-8DCB-4FF9BDC9907B}
SoundMAX-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x9 -removeonly
Symantec AntiVirus-->MsiExec.exe /I{50E125D1-88E5-48CE-80AE-98EC9698E639}
Update for Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920342)-->"C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB925876)-->"C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Update for Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Hotfix - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
WinZip-->"C:\Progra~1\WinZip\WINZIP32.EXE" /uninstall
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
ZipMail V8 for Lotus Notes-->MsiExec.exe /I{EB3433D0-C17F-4D00-95DF-5BFB9E478DA1}
=====HijackThis Backups=====
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe [2010-01-11]
======Hosts File======
127.0.0.1 www.Merijn.org
127.0.0.1 www.spywareinfo.com
127.0.0.1 www.spybot.info
127.0.0.1 www.hijackthis.de
127.0.0.1 www.majorgeeks.com
127.0.0.1 www.virustotal.com
127.0.0.1 www.avg-antivirus.net
127.0.0.1 www.kaspersky-labs.com
127.0.0.1 www.bleepingcomputer.com
127.0.0.1 www.free.grisoft.com
======Security center information======
AV: Symantec AntiVirus Corporate Edition
======System event log======
Computer Name: CIZ4W286
Event Code: 7036
Message: Le service COM+ System Application est entré dans l'état : running.
Record Number: 5
Source Name: Service Control Manager
Time Written: 20091224084741.000000+000
Event Type: Informations
User:
Computer Name: CIZ4W286
Event Code: 7035
Message: Un contrôle start a correctement été envoyé au service COM+ System Application.
Record Number: 4
Source Name: Service Control Manager
Time Written: 20091224084741.000000+000
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: CIZ4W286
Event Code: 7036
Message: Le service Cryptographic Services est entré dans l'état : running.
Record Number: 3
Source Name: Service Control Manager
Time Written: 20091224084741.000000+000
Event Type: Informations
User:
Computer Name: CIZ4W286
Event Code: 7035
Message: Un contrôle start a correctement été envoyé au service Cryptographic Services.
Record Number: 2
Source Name: Service Control Manager
Time Written: 20091224084741.000000+000
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: CIZ4W286
Event Code: 7005
Message: L'appel LoadUserProfile a échoué avec l'erreur :
Le périphérique n'est pas prêt.
Record Number: 1
Source Name: Service Control Manager
Time Written: 20091224084741.000000+000
Event Type: erreur
User:
=====Application event log=====
Computer Name: CIZ4W286
Event Code: 11707
Message: Product: Altiris Patch Management Agent -- Installation operation completed successfully.
Record Number: 5
Source Name: MsiInstaller
Time Written: 20091224091923.000000+000
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: CIZ4W286
Event Code: 1000
Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.
Record Number: 4
Source Name: LoadPerf
Time Written: 20091224084949.000000+000
Event Type: Informations
User:
Computer Name: CIZ4W286
Event Code: 1001
Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été supprimés.
Les données d'enregistrement contiennent les nouvelles valeurs du dernier compteur système
et les dernières entrées du registre d'aide.
Record Number: 3
Source Name: LoadPerf
Time Written: 20091224084949.000000+000
Event Type: Informations
User:
Computer Name: CIZ4W286
Event Code: 11728
Message: Product: WebFldrs XP -- Configuration completed successfully.
Record Number: 2
Source Name: MsiInstaller
Time Written: 20091224084840.000000+000
Event Type: Informations
User: CIZ4W286\Administrator
Computer Name: CIZ4W286
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.
Record Number: 1
Source Name: SecurityCenter
Time Written: 20091224084832.000000+000
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\IXOS\bin
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by CI015786 at 2010-01-11 14:38:28
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 139 GB (91%) free of 153 GB
Total RAM: 2037 MB (65% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\CCleaner.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}]
HelperObject Class - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll [2005-10-14 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [2006-10-12 434279]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CF3C5900-BEC0-470E-AEE8-CE277C60667C}]
iGraal Module - C:\Program Files\iGraal\BHO.dll [2009-10-12 61640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll [2005-10-14 131072]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
{D01B1F7D-9D7F-46C3-8DB9-5A55819E2A7F} - iGraal Toolbar - C:\Program Files\iGraal\Toolbar.dll [2009-10-12 92872]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AeXAgentLogon"=C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe [2008-05-12 143360]
"AClntUsr"=C:\Program Files\Altiris\AClient\AClntUsr.EXE [2010-01-11 184320]
"ProxyHostTrayIcon"=C:\Program Files\Funk Software\Proxy Host\phtray.exe [2004-02-17 230544]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2006-11-21 52840]
"vptray"=C:\PROGRA~1\SYMANT~1\VPTray.exe [2007-03-14 125632]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe [2006-10-12 49263]
"CfgDownload"=C:\Program Files\IXOS\bin\CfgDownload.exe [2006-03-10 172032]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-08-01 1036288]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-06-05 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-06-05 162328]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
EPop.lnk - C:\Program Files\WiredRed\EPop\EPop.exe
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" AMINIT.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-06-05 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\system32\NavLogon.dll [2007-03-14 43712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-01-11 14:38:28 ----D---- C:\rsit
2010-01-11 14:38:28 ----D---- C:\Program Files\trend micro
2010-01-11 14:36:44 ----D---- C:\Documents and Settings\CI015786\Application Data\Mozilla
2010-01-11 14:36:43 ----D---- C:\Program Files\iGraal
2010-01-08 18:20:45 ----D---- C:\Program Files\Hewlett-Packard
2010-01-07 12:27:56 ----D---- C:\Documents and Settings\CI015786\Application Data\Malwarebytes
2010-01-07 12:27:52 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-07 12:27:52 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-01-07 12:16:19 ----D---- C:\Documents and Settings\CI015786\Application Data\Yahoo!
2010-01-07 12:16:19 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2010-01-07 12:16:18 ----D---- C:\Program Files\Yahoo!
2010-01-07 12:16:17 ----D---- C:\Program Files\CCleaner
2010-01-07 10:38:35 ----A---- C:\WINDOWS\VPC32.INI
2010-01-07 10:32:38 ----HD---- C:\WINDOWS\PIF
2010-01-07 09:34:59 ----ASH---- C:\Documents and Settings\CI015786\Application Data\desktop.ini
2010-01-07 09:34:58 ----SD---- C:\Documents and Settings\CI015786\Application Data\Microsoft
2010-01-07 09:34:58 ----D---- C:\Documents and Settings\CI015786\Application Data\Macromedia
2010-01-07 09:34:58 ----D---- C:\Documents and Settings\CI015786\Application Data\Identities
2010-01-07 09:34:58 ----D---- C:\Documents and Settings\CI015786\Application Data\Adobe
2010-01-07 08:56:15 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-01-07 08:46:29 ----D---- C:\WINDOWS\SchCache
2010-01-05 13:44:52 ----A---- C:\WINDOWS\system32\kbdkor.dll
2010-01-05 13:44:52 ----A---- C:\WINDOWS\system32\kbdjpn.dll
2010-01-05 13:44:52 ----A---- C:\WINDOWS\system32\kbd106.dll
2010-01-05 13:44:52 ----A---- C:\WINDOWS\system32\kbd103.dll
2010-01-05 13:44:52 ----A---- C:\WINDOWS\system32\kbd101c.dll
2010-01-05 13:44:50 ----A---- C:\WINDOWS\system32\kbd101b.dll
2010-01-05 13:22:06 ----A---- C:\WINDOWS\system32\igfxres.dll
2010-01-05 08:45:45 ----D---- C:\Program Files\Broadcom
2010-01-05 08:45:04 ----A---- C:\WINDOWS\system32\igfxzoom.exe
2010-01-05 08:45:03 ----D---- C:\WINDOWS\system32\Lang
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igxpun.exe
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igxprd32.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\iglicd32.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igldev32.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxtray.exe
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxress.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxpph.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxpers.exe
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxext.exe
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxexps.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxdo.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxdev.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxCoIn_v4837.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\hkcmd.exe
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\hccutils.dll
2010-01-05 08:45:03 ----A---- C:\WINDOWS\system32\difxapi.dll
2010-01-05 08:43:54 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-01-05 08:43:51 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-05 08:43:51 ----D---- C:\Program Files\Analog Devices
2010-01-05 08:43:51 ----A---- C:\WINDOWS\system32\DSndUp.exe
2010-01-05 08:43:51 ----A---- C:\WINDOWS\system32\CleanUp.exe
2010-01-05 08:43:39 ----A---- C:\WINDOWS\system32\PostProc.dll
2010-01-05 08:43:38 ----A---- C:\WINDOWS\system32\a3d.dll
2010-01-05 08:42:27 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-01-05 08:42:27 ----D---- C:\Program Files\Intel
2010-01-05 08:42:27 ----A---- C:\WINDOWS\system32\CSVer.dll
2010-01-05 08:42:20 ----D---- C:\Intel
2010-01-05 08:31:44 ----D---- C:\WINDOWS\ServicePackFiles
2010-01-05 08:27:05 ----D---- C:\Program Files\MSXML 4.0
2010-01-05 08:22:15 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-01-04 11:09:16 ----D---- C:\Program Files\IXOS
2010-01-04 11:09:08 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-04 11:08:35 ----D---- C:\Program Files\WiredRed
2010-01-04 11:07:28 ----D---- C:\WINDOWS\system32\1036
2010-01-04 11:07:28 ----A---- C:\WINDOWS\system32\WMErrFRA.dll
2010-01-04 11:06:09 ----D---- C:\Program Files\TechSmith
2010-01-04 11:05:59 ----D---- C:\Program Files\WinZip
2010-01-04 11:05:26 ----D---- C:\Program Files\Linguistic Systems
2010-01-04 11:04:49 ----D---- C:\Program Files\Common Files\Adobe
2010-01-04 11:04:47 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-01-04 11:04:43 ----D---- C:\Program Files\Adobe
2010-01-04 11:04:40 ----D---- C:\Program Files\PDF-XChange
2010-01-04 11:04:37 ----A---- C:\WINDOWS\system32\javaws.exe
2010-01-04 11:04:37 ----A---- C:\WINDOWS\system32\javaw.exe
2010-01-04 11:04:37 ----A---- C:\WINDOWS\system32\java.exe
2010-01-04 11:04:12 ----D---- C:\Program Files\Java
2010-01-04 11:04:10 ----D---- C:\Program Files\Common Files\Java
2010-01-04 11:04:08 ----A---- C:\WINDOWS\notes.ini
2010-01-04 11:03:35 ----D---- C:\lotus
2010-01-04 11:03:27 ----D---- C:\Microsoft
2010-01-04 11:03:26 ----A---- C:\WINDOWS\SAPlogon.ini
2010-01-04 11:02:51 ----A---- C:\WINDOWS\system32\icuuc34.dll
2010-01-04 11:02:51 ----A---- C:\WINDOWS\system32\icuin34.dll
2010-01-04 11:02:51 ----A---- C:\WINDOWS\system32\icu_license.txt
2010-01-04 11:02:50 ----A---- C:\WINDOWS\system32\libsapu16vc80.dll
2010-01-04 11:02:50 ----A---- C:\WINDOWS\system32\librfc32u.dll
2010-01-04 11:02:50 ----A---- C:\WINDOWS\system32\icudt34.dll
2010-01-04 11:02:47 ----A---- C:\WINDOWS\system32\grsapx32.dll
2010-01-04 11:02:47 ----A---- C:\WINDOWS\system32\grfcxl32.dll
2010-01-04 11:02:45 ----A---- C:\WINDOWS\system32\vrfc32.dll
2010-01-04 11:02:45 ----A---- C:\WINDOWS\system32\Vbar332.dll
2010-01-04 11:02:45 ----A---- C:\WINDOWS\system32\Vb5db.dll
2010-01-04 11:02:45 ----A---- C:\WINDOWS\system32\msrepl35.dll
2010-01-04 11:02:45 ----A---- C:\Program Files\Common Files\sapxlhelper.dll
2010-01-04 11:02:45 ----A---- C:\Program Files\Common Files\sapconsr3.dll
2010-01-04 11:02:45 ----A---- C:\Program Files\Common Files\sapconsaccess.dll
2010-01-04 11:02:43 ----A---- C:\WINDOWS\system32\vb40032.dll
2010-01-04 11:02:02 ----D---- C:\Program Files\Common Files\ESRI
2010-01-04 11:02:02 ----A---- C:\WINDOWS\system32\wdba.dll
2010-01-04 11:01:33 ----A---- C:\WINDOWS\system32\h5tool32.dll
2010-01-04 11:01:33 ----A---- C:\WINDOWS\system32\h5rtf32.dll
2010-01-04 11:01:33 ----A---- C:\WINDOWS\system32\h5menu32.dll
2010-01-04 11:01:33 ----A---- C:\WINDOWS\system32\h5krnl32.dll
2010-01-04 11:01:33 ----A---- C:\WINDOWS\system32\h5icon32.dll
2010-01-04 11:01:33 ----A---- C:\WINDOWS\system32\h5dlg32.dll
2010-01-04 11:01:31 ----A---- C:\WINDOWS\system32\SAPbtmp.dll
2010-01-04 11:01:30 ----D---- C:\Program Files\Common Files\SAP Shared
2010-01-04 11:01:30 ----A---- C:\WINDOWS\system32\vtssm32.dll
2010-01-04 11:01:30 ----A---- C:\WINDOWS\system32\vtssdl32.dll
2010-01-04 11:01:30 ----A---- C:\WINDOWS\system32\oc30.dll
2010-01-04 11:01:30 ----A---- C:\WINDOWS\system32\mfcans32.dll
2010-01-04 11:01:29 ----A---- C:\WINDOWS\system32\librfc32.dll
2010-01-04 11:01:12 ----A---- C:\WINDOWS\system32\tlbinf32.dll
2010-01-04 11:01:10 ----D---- C:\Program Files\SAP
2010-01-04 11:01:03 ----A---- C:\WINDOWS\ODBC.INI
2010-01-04 11:00:58 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-01-04 11:00:36 ----D---- C:\Program Files\Common Files\L&H
2010-01-04 11:00:30 ----D---- C:\Program Files\Microsoft ActiveSync
2010-01-04 11:00:27 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-04 11:00:25 ----D---- C:\Program Files\Microsoft Works
2010-01-04 11:00:21 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-04 11:00:17 ----D---- C:\WINDOWS\SHELLNEW
2010-01-04 11:00:16 ----D---- C:\Program Files\Microsoft.NET
2010-01-04 11:00:16 ----D---- C:\Program Files\Microsoft Office
2010-01-04 10:19:19 ----A---- C:\WINDOWS\system32\S32EVNT1.DLL
2010-01-04 10:19:11 ----D---- C:\Program Files\Symantec
2010-01-04 10:19:11 ----A---- C:\WINDOWS\system32\capicom.dll
2010-01-04 10:19:06 ----D---- C:\Program Files\Symantec AntiVirus
2010-01-04 10:19:06 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-01-04 10:19:06 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-12-24 10:25:15 ----A---- C:\WINDOWS\client.INI
2009-12-24 09:51:44 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-12-24 09:46:21 ----A---- C:\WINDOWS\system32\hccoin.dll
2009-12-24 09:46:19 ----A---- C:\WINDOWS\system32\usbui.dll
2009-12-24 08:47:33 ----D---- C:\WINDOWS\system32\Downloaded Installations
2009-12-24 08:47:33 ----D---- C:\Program Files\Funk Software
2009-12-24 08:47:33 ----D---- C:\Program Files\Common Files\Funk Software
======List of files/folders modified in the last 1 months======
2010-01-11 14:38:28 ----RD---- C:\Program Files
2010-01-11 14:38:14 ----D---- C:\WINDOWS\Temp
2010-01-11 14:36:44 ----D---- C:\WINDOWS\Prefetch
2010-01-11 12:01:00 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-11 10:00:09 ----SHD---- C:\WINDOWS\Installer
2010-01-11 09:05:26 ----RSD---- C:\WINDOWS\Fonts
2010-01-11 09:05:26 ----D---- C:\WINDOWS\system32\drivers
2010-01-11 09:05:26 ----D---- C:\WINDOWS\system32
2010-01-11 09:04:37 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-11 07:47:41 ----D---- C:\WINDOWS\security
2010-01-11 07:43:43 ----D---- C:\WINDOWS\Registration
2010-01-11 07:43:40 ----D---- C:\WINDOWS
2010-01-11 07:43:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-08 16:03:27 ----D---- C:\WINDOWS\system32\LogFiles
2010-01-08 16:03:26 ----D---- C:\WINDOWS\Debug
2010-01-08 16:03:16 ----SHD---- C:\RECYCLER
2010-01-08 13:27:39 ----SD---- C:\WINDOWS\Tasks
2010-01-07 10:05:28 ----HD---- C:\WINDOWS\inf
2010-01-07 09:34:57 ----D---- C:\Documents and Settings
2010-01-07 07:42:19 ----D---- C:\WINDOWS\system32\config
2010-01-05 13:44:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-05 13:23:51 ----A---- C:\WINDOWS\system.ini
2010-01-05 10:26:38 ----D---- C:\WINDOWS\system32\wbem
2010-01-05 10:26:38 ----D---- C:\WINDOWS\system32\Setup
2010-01-05 10:26:37 ----D---- C:\WINDOWS\AppPatch
2010-01-05 08:54:06 ----RSD---- C:\WINDOWS\assembly
2010-01-05 08:53:39 ----D---- C:\WINDOWS\Microsoft.NET
2010-01-05 08:46:04 ----D---- C:\Drvs
2010-01-05 08:43:55 ----D---- C:\WINDOWS\system
2010-01-05 08:39:38 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-05 08:37:59 ----D---- C:\WINDOWS\WinSxS
2010-01-05 08:33:32 ----D---- C:\Program Files\Internet Explorer
2010-01-04 11:16:28 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-01-04 11:16:18 ----D---- C:\Program Files\Common Files\System
2010-01-04 11:09:08 ----D---- C:\Program Files\Common Files
2010-01-04 11:08:30 ----D---- C:\WINDOWS\mui
2010-01-04 11:08:25 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-04 11:07:32 ----D---- C:\WINDOWS\pchealth
2010-01-04 11:07:32 ----D---- C:\WINDOWS\Help
2010-01-04 11:07:28 ----D---- C:\Program Files\Windows Media Player
2010-01-04 11:07:22 ----RD---- C:\WINDOWS\Web
2010-01-04 11:07:22 ----D---- C:\WINDOWS\system32\oobe
2010-01-04 11:01:07 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-01-04 09:57:10 ----SHD---- C:\WINDOWS\CSC
2009-12-24 11:26:10 ----D---- C:\Program Files\Altiris
2009-12-24 09:45:42 ----D---- C:\WINDOWS\repair
2009-12-24 08:47:39 ----SHD---- C:\System Volume Information
2009-12-24 08:47:39 ----D---- C:\Sysprep
2009-12-24 08:46:46 ----RASH---- C:\boot.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CCDevice;CCDevice; C:\WINDOWS\system32\drivers\CCDevice.sys [2007-05-29 9216]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 ProxyHostDriver;Proxy Host Driver; C:\WINDOWS\System32\Drivers\phw2ksys.sys [2004-02-17 61008]
R1 ProxyHostMirrorDisplay;Proxy Host Mirror Display; C:\WINDOWS\System32\Drivers\phmmini.sys [2004-02-17 11472]
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys []
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-08-03 307712]
R3 AlKernel;Altiris Kernel Driver; C:\WINDOWS\System32\Drivers\AlKernel.sys [2010-01-11 2401]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-03-19 175104]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-08-12 137728]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-06-05 5761728]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100110.017\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100110.017\navex15.sys []
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
S3 PCnet;AMD PCNET Compatable Adapter Driver; C:\WINDOWS\system32\DRIVERS\pcntpci5.sys [2001-08-17 35328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AClient;Altiris Client Service; C:\Program Files\Altiris\AClient\AClient.exe [2006-04-14 5005388]
R2 AeXNSClient;Altiris Agent; C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe [2008-05-12 1523712]
R2 CarbonCopy32;Altiris Carbon Copy; C:\WINDOWS\system32\ccsrvc.exe [2007-05-29 49152]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2006-11-21 192104]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2006-11-21 169576]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec AntiVirus\DefWatch.exe [2007-03-14 31424]
R2 Lotus Notes Single Logon;Ouverture de session unique de Lotus Notes; C:\lotus\notes\nslsvice.exe [2006-09-27 7680]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Multi-user Cleanup Service;Multi-user Cleanup Service; C:\lotus\notes\ntmulti.exe [2006-09-27 53248]
R2 ProxyHostService;Proxy Host Service; C:\Program Files\Funk Software\Proxy Host\ph32svc.exe [2004-02-17 287888]
R2 SavRoam;SAVRoam; C:\Program Files\Symantec AntiVirus\SavRoam.exe [2007-03-14 116416]
R2 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2007-01-10 1160792]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec AntiVirus\Rtvscan.exe [2007-03-14 1816768]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-09-02 2528960]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
-----------------EOF-----------------