Rechercher : dans
Par :

Infection Toj. Generic.DIT

Dernière réponse le 25 nov 2009 à 09:09:39 phoenixgirl, le 13 oct 2009 à 22:16:07 
 Signaler ce message aux modérateurs

Bonjour,

Pourriez-vous m'aider SVP

Mes logiciels de sécurité ne cessent de détecter des TRACKING COOKIES lors des analyses quotidiennes... Je ne sais pas s'il y a un virus ou quoi mais mon ordi est très lent et il bogue souvent. Quelqu'un pourrait-il m'aider à vérifier tout ca et à me débarrasser de ces cookies une fois pour toutes (pcq je les supprimes, mais ils reviennent sans arrêt).

Merci beaucoup de votre aide!!!

Je poste les rapports...

Logfile of random's system information tool 1.06 (written by random/random)
Run by HP_Administrator at 2009-10-13 12:14:32
Microsoft Windows XP Professional Service Pack 3
System drive C: has 161 GB (88%) free of 183 GB
Total RAM: 503 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:01, on 2009-10-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\HP_Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\HP_Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.gamenext.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: SVIEBHO Class - {B3C54716-9D0A-4666-A81A-6072A6325A5A} - C:\Program Files\SelectView\svie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: SelectView - {16D60F96-2FF6-40b2-96D3-C32170E45A01} - C:\Program Files\SelectView\svie.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BFD90062-6B5E-4F8F-87B1-5F022C14E32F} (ActiveReceiver Control) - http://www.meetstream.com/activex/28014/activereceiver.cab
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - (no file)
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
End of file - 14950 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Connexion facile à Internet.job
C:\WINDOWS\tasks\Norton Security Scan for HP_Administrator.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{14A18F9C-8275-4067-B3CB-617437F4508B}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-11-22 399352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\ctbr.dll [2009-06-26 1215488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
Click-to-Call BHO - C:\Program Files\Windows Live\Messenger\wlchtc.dll [2009-02-06 73072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9AA2F14F-E956-44B8-8694-A5B615CDF341}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar4.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll [2008-08-11 734704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3C54716-9D0A-4666-A81A-6072A6325A5A}]
SVIEBHO Class - C:\Program Files\SelectView\svie.dll [2007-06-06 720896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-07 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e0007d18-baa4-4573-ae78-8bea0958c610}]
P2P Max DE Toolbar - C:\Program Files\P2P_Max_DE\tbP2P1.dll [2009-08-23 2215960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-07 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-11-22 399352]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{e0007d18-baa4-4573-ae78-8bea0958c610} - P2P Max DE Toolbar - C:\Program Files\P2P_Max_DE\tbP2P1.dll [2009-08-23 2215960]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Barre d'outils &Crawler - C:\PROGRA~1\Crawler\ctbr.dll [2009-06-26 1215488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2004-08-10 59392]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-08 61952]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-06-08 77824]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2005-06-08 114688]
"HPBootOp"=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2005-02-26 245760]
"LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2005-05-10 253952]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPwuSchd2.exe [2005-05-12 49152]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2006-09-11 218032]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-11 86960]
"PS2"=C:\WINDOWS\system32\ps2.exe [2004-10-25 90112]
"Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2008-04-13 143360]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2008-09-07 1783808]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-10-01 111936]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
""= []
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-08-16 236016]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe [2007-03-16 63712]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-07 149280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-11 68856]
"MessengerPlus3"=C:\Program Files\MessengerPlus! 3\MsgPlus.exe [2008-09-01 190024]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-09-11 218032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
C:\Program Files\Picasa2\PicasaMediaDetector.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
C:\DOCUME~1\DAPHNE~1\Desktop\Photo\LimeWire\LimeWire.exe []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
Desktop Manager.lnk - C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Updates from HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe
Outil de notification Live Search.lnk - C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-06-08 131072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"C:\WINDOWS\system32\ntvdm.exe"="C:\WINDOWS\system32\ntvdm.exe:*:Enabled:NTVDM.EXE"
"C:\Documents and Settings\DA PH N EE\Desktop\Photo\LimeWire\LimeWire.exe"="C:\Documents and Settings\DA PH N EE\Desktop\Photo\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Documents and Settings\DA PH N EE\Local Settings\Temp\ImInstaller\incredimail_installer.exe"="C:\Documents and Settings\DA PH N EE\Local Settings\Temp\ImInstaller\incredimail_installer.exe:*:Enabled:IncrediMail Installer"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\1215660015\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1215660015\EE\AOLServiceHost.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\1165105190\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1165105190\EE\AOLServiceHost.exe:*:Disabled:AOL"
"C:\Program Files\AOL 9.0a\waol.exe"="C:\Program Files\AOL 9.0a\waol.exe:*:Disabled:AOL"
"C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Disabled:AOL"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Disabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Disabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Disabled:AOLTsMon"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\iTunes\iTunes.exe"="%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

======List of files/folders created in the last 3 months======

2009-10-12 16:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\java.exe
2009-10-07 13:52:05 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-10-02 16:13:19 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
2009-10-02 16:13:10 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-02 16:13:10 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-10-02 15:39:26 ----D---- C:\rsit
2009-09-30 22:17:06 ----D---- C:\Program Files\PhotoScape
2009-09-30 17:41:51 ----D---- C:\Program Files\Common Files\Adobe
2009-09-11 18:20:01 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-09-09 16:20:01 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-09-09 16:19:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-09-09 16:14:40 ----HDC---- C:\WINDOWS\$NtUninstallKB973768$
2009-09-08 23:40:22 ----D---- C:\Program Files\Photosynth
2009-09-08 23:07:26 ----D---- C:\Documents and Settings\All Users\Application Data\Team MediaPortal
2009-09-08 23:06:14 ----D---- C:\Program Files\Team MediaPortal
2009-09-08 22:55:54 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2009-09-08 22:55:54 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2009-09-08 22:55:53 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2009-09-08 22:55:52 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2009-09-08 22:55:52 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2009-09-08 22:55:51 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2009-09-08 22:55:50 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2009-09-08 22:55:50 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2009-09-08 22:55:49 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2009-09-08 22:55:49 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2009-09-08 22:55:48 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2009-09-08 22:55:48 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2009-09-08 22:55:47 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2009-09-08 22:55:43 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2009-09-08 22:55:42 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2009-09-08 22:55:42 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2009-09-08 22:55:41 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2009-09-08 22:55:41 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2009-09-08 22:55:41 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2009-09-08 22:55:40 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2009-09-08 22:55:38 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2009-09-08 22:55:38 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2009-09-08 22:55:36 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2009-09-08 22:55:34 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2009-09-08 22:55:33 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2009-09-08 22:55:33 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2009-09-08 22:55:31 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2009-09-08 22:55:30 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2009-09-08 22:55:30 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2009-09-08 22:55:29 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2009-09-08 22:55:29 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2009-09-08 22:55:26 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2009-09-08 22:55:25 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2009-09-08 22:55:23 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2009-09-08 22:55:22 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2009-09-08 22:55:22 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2009-09-08 22:55:17 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2009-09-08 22:55:16 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2009-09-08 22:55:16 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2009-09-08 22:55:12 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2009-09-08 22:55:12 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2009-09-08 22:55:10 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2009-09-08 22:55:07 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2009-09-08 22:55:06 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2009-09-08 22:55:05 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2009-09-08 22:55:04 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-09-08 22:54:56 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2009-09-08 22:54:23 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-09-08 22:54:22 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2009-09-08 22:54:22 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2009-09-08 22:54:19 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-09-08 22:54:16 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-09-08 22:54:14 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-09-08 22:54:14 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-09-08 22:54:13 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-09-08 22:54:12 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-09-08 22:54:03 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-09-08 22:52:51 ----D---- C:\WINDOWS\Logs
2009-09-08 21:36:56 ----D---- C:\Program Files\Bonjour
2009-09-07 01:45:08 ----D---- C:\Program Files\Norton Security Scan
2009-09-07 01:45:08 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
2009-09-07 01:45:01 ----D---- C:\Program Files\NortonInstaller
2009-09-07 01:45:01 ----D---- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2009-09-06 22:40:24 ----D---- C:\WINDOWS\system32\Adobe
2009-09-05 16:40:39 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-09-05 16:39:41 ----D---- C:\Documents and Settings\All Users\Application Data\Oberon Media
2009-09-05 16:32:38 ----D---- C:\Program Files\Oberon Media
2009-09-05 16:32:38 ----D---- C:\Program Files\Gamenext
2009-09-05 16:32:38 ----D---- C:\Program Files\Common Files\Oberon Media
2009-08-27 16:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
2009-08-20 16:01:47 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2009-08-19 02:16:18 ----D---- C:\Program Files\Microsoft Silverlight
2009-08-19 02:15:08 ----D---- C:\Program Files\Microsoft Sync Framework
2009-08-19 02:13:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954708$
2009-08-19 02:11:06 ----D---- C:\Program Files\Windows Live SkyDrive
2009-08-19 01:35:46 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Roxio
2009-08-19 01:27:35 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Research In Motion
2009-08-19 01:27:06 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\InstallShield
2009-08-19 01:13:55 ----D---- C:\Documents and Settings\All Users\Application Data\Roxio
2009-08-19 01:13:48 ----D---- C:\Program Files\Roxio
2009-08-19 01:13:35 ----D---- C:\Program Files\Common Files\Roxio Shared
2009-08-19 01:01:37 ----D---- C:\Program Files\Common Files\Research In Motion
2009-08-19 01:01:10 ----D---- C:\Program Files\Research In Motion
2009-08-15 13:07:58 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-08-15 12:31:53 ----D---- C:\Program Files\Avira
2009-08-15 12:31:53 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-08-14 16:08:33 ----D---- C:\WINDOWS\system32\XPSViewer
2009-08-14 16:08:27 ----D---- C:\Program Files\MSBuild
2009-08-14 16:08:15 ----D---- C:\Program Files\Reference Assemblies
2009-08-14 16:07:19 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-08-14 16:07:18 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-08-14 16:07:18 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-08-14 16:07:18 ----D---- C:\9a75388fceff2697814682
2009-08-13 18:21:29 ----D---- C:\WINDOWS\ie8updates
2009-08-13 18:18:16 ----HDC---- C:\WINDOWS\ie8
2009-08-13 13:42:02 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-08-13 13:41:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-08-13 13:41:48 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-08-13 13:41:41 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2009-08-13 13:41:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-08-13 13:41:24 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-08-13 13:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-08-13 13:41:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2009-08-13 13:38:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-08-05 15:21:54 ----D---- C:\Program Files\Crawler
2009-08-03 09:39:03 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2009-08-02 22:35:26 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-08-02 22:35:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-08-02 22:34:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-08-02 16:05:14 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-08-02 16:04:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-08-02 16:04:42 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-08-02 16:04:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-08-02 16:03:40 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-08-02 16:03:31 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-08-02 16:03:20 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-08-02 16:01:17 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-08-02 16:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-08-02 11:23:56 ----N---- C:\WINDOWS\system32\xpsp4res.dll

======List of files/folders modified in the last 3 months======

2009-10-13 12:14:38 ----D---- C:\Program Files\Trend Micro
2009-10-13 12:14:26 ----D---- C:\WINDOWS\Prefetch
2009-10-13 12:09:40 ----D---- C:\Program Files\Mozilla Firefox
2009-10-13 12:07:34 ----SHD---- C:\WINDOWS\Installer
2009-10-13 12:07:07 ----D---- C:\WINDOWS\Temp
2009-10-13 12:06:13 ----D---- C:\WINDOWS
2009-10-13 12:05:45 ----HD---- C:\WINDOWS\system32\CatRoot2
2009-10-13 12:05:40 ----D---- C:\WINDOWS\Registration
2009-10-13 11:17:01 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-10-13 11:15:17 ----D---- C:\Program Files\Spyware Terminator
2009-10-13 11:15:17 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2009-10-13 11:00:50 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Spyware Terminator
2009-10-13 07:59:27 ----HD---- C:\Config.Msi
2009-10-13 07:47:01 ----HD---- C:\WINDOWS\system32
2009-10-12 16:01:41 ----HD---- C:\WINDOWS\inf
2009-10-12 16:01:32 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-10-12 16:01:30 ----HD---- C:\WINDOWS\system32\drivers
2009-10-12 15:55:57 ----A---- C:\WINDOWS\WORDPAD.INI
2009-10-12 15:42:19 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-08 15:27:02 ----SHD---- C:\WINDOWS\CSC
2009-10-07 13:51:29 ----D---- C:\Program Files\Java
2009-10-07 08:15:48 ----D---- C:\Program Files\SelectView
2009-10-02 16:25:20 ----D---- C:\Program Files
2009-10-02 16:06:10 ----D---- C:\WINDOWS\Minidump
2009-10-02 16:06:10 ----D---- C:\WINDOWS\Debug
2009-09-30 22:44:40 ----D---- C:\Program Files\PhotoFiltre
2009-09-30 17:42:32 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Adobe
2009-09-30 17:41:53 ----RSD---- C:\WINDOWS\Fonts
2009-09-30 17:41:51 ----D---- C:\Program Files\Common Files
2009-09-30 17:41:51 ----D---- C:\Program Files\Adobe
2009-09-30 17:41:51 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-09-30 17:41:15 ----D---- C:\WINDOWS\Downloaded Installations
2009-09-21 19:10:50 ----D---- C:\Program Files\WinClamAVShield
2009-09-14 16:12:19 ----A---- C:\WINDOWS\win.ini
2009-09-09 17:37:34 ----HD---- C:\WINDOWS\system32\Macromed
2009-09-09 16:14:46 ----D---- C:\WINDOWS\ehome
2009-09-09 00:26:33 ----A---- C:\WINDOWS\ULead32.ini
2009-09-08 23:40:22 ----D---- C:\WINDOWS\WinSxS
2009-09-08 23:23:27 ----SHD---- C:\System Volume Information
2009-09-08 22:55:56 ----HD---- C:\WINDOWS\system32\DirectX
2009-09-08 22:54:55 ----RSD---- C:\WINDOWS\assembly
2009-09-08 22:54:27 ----D---- C:\WINDOWS\Microsoft.NET
2009-09-07 01:45:20 ----SD---- C:\WINDOWS\Tasks
2009-09-07 01:45:08 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-09-05 16:33:30 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-08-31 14:00:06 ----D---- C:\hegames
2009-08-28 17:38:20 ----A---- C:\WINDOWS\system32\MRT.exe
2009-08-23 15:30:46 ----D---- C:\WINDOWS\network diagnostic
2009-08-23 14:18:15 ----D---- C:\Program Files\P2P_Max_DE
2009-08-20 16:55:06 ----D---- C:\Program Files\Internet Explorer
2009-08-19 18:13:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-08-19 12:54:16 ----D---- C:\Program Files\Messenger Plus! Live
2009-08-19 12:52:29 ----SD---- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
2009-08-19 02:16:08 ----HDC---- C:\WINDOWS\system32\DRVSTORE
2009-08-19 02:15:29 ----D---- C:\Program Files\Windows Live Toolbar
2009-08-19 02:14:20 ----D---- C:\Program Files\Windows Live
2009-08-19 02:11:50 ----D---- C:\Program Files\MSN Messenger
2009-08-19 01:19:08 ----D---- C:\Documents and Settings\All Users\Application Data\Sonic
2009-08-19 01:18:26 ----D---- C:\Program Files\Common Files\Sonic Shared
2009-08-19 01:16:30 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-08-19 01:07:22 ----D---- C:\temp
2009-08-19 01:03:47 ----HD---- C:\WINDOWS\system32\ReinstallBackups
2009-08-15 17:00:29 ----D---- C:\Program Files\Circle Developement
2009-08-15 15:23:10 ----D---- C:\Program Files\LimeWire
2009-08-15 13:08:12 ----HD---- C:\WINDOWS\system32\CatRoot
2009-08-14 16:08:29 ----HD---- C:\WINDOWS\system32\en-US
2009-08-14 16:07:47 ----HD---- C:\WINDOWS\system32\spool
2009-08-13 18:43:05 ----D---- C:\WINDOWS\Media
2009-08-13 18:43:05 ----D---- C:\WINDOWS\Help
2009-08-13 13:41:19 ----D---- C:\Program Files\Outlook Express
2009-08-05 05:01:48 ----AH---- C:\WINDOWS\system32\mswebdvd.dll
2009-08-02 23:47:30 ----HD---- C:\WINDOWS\system32\wbem
2009-08-02 22:35:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-08-02 16:11:26 ----D---- C:\WINDOWS\AppPatch
2009-07-19 18:48:58 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-07-19 09:18:59 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-07-17 15:01:06 ----AH---- C:\WINDOWS\system32\atl.dll
2009-07-14 07:03:14 ----H---- C:\WINDOWS\system32\tzchange.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 sdcplh;sdcplh; C:\WINDOWS\System32\drivers\sdcplh.sys [2005-09-15 40576]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-08-15 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-08-18 55656]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-10 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-10 55936]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-12-15 1038208]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2004-12-15 220928]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-06-08 1050140]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-06-08 3160576]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2004-12-06 10368]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2001-06-04 14112]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-10 5888]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-12-15 703232]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 ATWPKT2;ATWPKT2; \??\C:\Program Files\Common Files\AOL\ACS\ATWPKT2.SYS []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-08 145920]
S3 HidBatt;HID UPS Battery Driver; C:\WINDOWS\system32\DRIVERS\HidBatt.sys [2008-04-13 20352]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-04 606684]
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\15.tmp []
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 RimUsb;Téléphone intelligent BlackBerry ; C:\WINDOWS\System32\Drivers\RimUsb.sys [2007-05-31 22656]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SNPP106;PC Camera (6029 CIF); C:\WINDOWS\system32\DRIVERS\snpp106.sys [2003-04-09 227200]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-10 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-08-15 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-18 185089]
R2 APC UPS Service;APC UPS Service; C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe [2004-07-21 176241]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2004-09-28 195584]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2004-08-10 102912]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-07 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-06-21 53248]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 NWCWorkstation;Client Service for NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 NwSapAgent;SAP Agent; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-09-07 570880]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-07-24 358896]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2007-08-16 309744]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-08-16 166384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-05 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-07-24 88560]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-08-16 1092080]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 2896
Windows 5.1.2600 Service Pack 3

2009-10-13 12:53:17
mbam-log-2009-10-13 (12-53-17).txt

Type de recherche: Examen rapide
Eléments examinés: 118071
Temps écoulé: 7 minute(s), 19 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)


Aussi, Trend Micro m'a trouvé un trojan Generic.DIT mais je ne sais pas comment avoir le rapport de l'analyse en ligne...

Merci pour votre aide!!!

Configuration: Windows XP
Firefox 3.5.3

Meilleures réponses pour « infection Toj. Generic.DIT » dans :
[Virus] Que faire quand on est infecté ? VoirSi vous savez ou vous pensez être infecté par un virus Si vous savez ou vous pensez être infecté par un virus, il faut s'en occuper le plus rapidement possible car l'infection peut inviter d'autres infections dans votre PC et votre système risque...
Infection Navipromo / Magic.Control / Instant Access / EgdAccess VoirQue faire en cas d'infection Navipromo/Magic.Control/Instant Access/EgdAccess ? Navipromo est une infection qui affiche des fenêtres publicitaires intempestives. Les programmes suivants installent cette infection : Funky Emoticons Games...

1

kduc, le 13 oct 2009 à 22:59:25

Salut,

Supprime ce programme -> P2P_Max_DE en allant dans :

1/ Démarrer > Panneau de Config. > Ajout/suppres… des progr.

2/ Démarrer > Poste de travail > C:\Program Files\...

---
Lis ce qui suit :

http://forum.malekal.com/danger-des-cracks-t893.html

Ensuite, ...

Télécharge Toolbar S&D (Team IDN) sur ton Bureau : http://eric.71.mespages.googlepages.com/ToolBarSD.exe

Lance l'installation du programme en exécutant le fichier téléchargé.
Double-clique maintenant sur le raccourci de Toolbar-S&D.
Sélectionne la langue de ton choix puis, valide avec la touche "Entrée".
Ensuite, choisis l'option 1 (Recherche).
Patiente jusqu'à la fin de la recherche.
Le contenu du rapport est situé dans : C:\TB.txt
Poste-le.

Puis, télécharge Genproc : http://www.genproc.com/GenProc.exe ;
puis, double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre.

Répondre à kduc

2

phoenixgirl, le 22 oct 2009 à 21:33:30

Merci pour ton aide et désolée de ne pas avoir répondu plus tôt... Je fais ça pour l'ordinateur de ma mère alors, je n'y viens pas tous les jours... Si tu es toujours disposé à m'aider, j'en serais bien ravie! Aussi, je voudrais ajouter qu'une amie a fait un grand ménage dans les programmes et fichiers, alors je ne sais pas si une nouvelle analyse serait de mise.... Tu me diras ce que tu en penses... Quoi qu'il en soit;
Je te poste le rapport que tu m'a demandé du logiciel toolbar...

-----------\\ ToolBar S&D 1.2.9 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 2.93GHz )
BIOS : BIOS Date: 09/06/05 17:46:49 Ver: 08.00.10
USER : HP_Administrator ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091021-0] 4.8.1356 (Activated)
C:\ (Local Disk) - NTFS - Total:178 Go (Free:156 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [1] ( 2009-10-22|15:14 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\KaZaA
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml

-----------\\ Extensions

(HP_Administrator) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://ca.msn.com/defaultf.aspx"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
"SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68928"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68929"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "C:\ToolBar SD\TB_1.txt" - 2009-10-22|15:15 - Option : [1]

-----------\\ Fin du rapport a 15:15:30,70



Et l'autre rapport:

Rapport GenProc 2.640 [1] - 2009-10-22 à 15:25:39
@ Windows XP Service Pack 3 - Mode normal
@ Internet Explorer (8.0.6001.18702) [Navigateur par défaut]

Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures" ; par la suite, laisse-le avec ses réglages par défaut. C'est tout.

# Etape 1/ Télécharge :

- Lop S&D http://eric.71.mespages.googlepages.com/LopSD.exe (Eric 71 & Angeldark) sur ton Bureau.

- Toolbar-S&D http://eric.71.mespages.googlepages.com/ToolBarSD.exe (Team IDN) sur ton Bureau.


Redémarre en mode sans échec comme indiqué ici http://www.pcloisirs.eu/mode_sans_echec.htm ; Choisis ta session courante *** HP_Administrator *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).


# Etape 2/

Lance Toolbar-S&D situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

# Etape 3/

Double-clique sur Lop S&D pour lancer l'installation, séléctionne la langue souhaitée, puis choisis l'Option 2 - Suppression - et patiente jusqu'à ce qu'il ait terminé.

# Etape 4/

Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

# Etape 5/

Redémarre normalement et poste, dans la même réponse :

- Le contenu du rapport TB.txt situé dans C:\ ;
- Le contenu du rapport lopR.txt situé dans C:\ ;
- Un nouveau rapport HijackThis http://forums.cnetfrance.fr/index.php?showtopic=796 ;
- Un nouveau rapport GenProc ;

Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

~~ Arguments de la procédure ~~


# Détections [1] GenProc 2.640 2009-10-22 à 15:26:01
Lop:le 2009-10-22 à 15:27:10 "C:\Program Files\Circle Developement"
Toolbar:le 2009-10-22 à 15:27:12 "C:\Program Files\KaZaA"

----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------

~~ Fin à 15:27:56 ~~

Merci encore!!!

PS Dis-moi est-ce que je dois suivre les étapes qui sont inscrites dans le rapport????

Répondre à phoenixgirl

3

kduc, le 22 oct 2009 à 23:12:24

Salut phoenixgirl,

Suis les étapes de la procédure Genproc (ou tu retrouveras la suite de Toolbar S&D) et poste les rapports.

Répondre à kduc

4

phoenixgirl, le 25 oct 2009 à 23:29:15

-----------\\ ToolBar S&D 1.2.9 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 2.93GHz )
BIOS : BIOS Date: 09/06/05 17:46:49 Ver: 08.00.10
USER : HP_Administrator ( Administrator )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091025-0] 4.8.1356 (Activated)
C:\ (Local Disk) - NTFS - Total:178 Go (Free:157 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [2] ( 2009-10-25|18:07 )

-----------\\ SUPPRESSION

Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\KaZaA

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ Extensions

(HP_Administrator) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(HP_Administrator) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://ca.msn.com/defaultf.aspx"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
"SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68928"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68929"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://www.msn.com/"


--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\HP_ADM~1\Local Settings\Temporary Internet Files\Content.IE5\NNKD1NCJ\crackyfred_1237318629[1].jpg



1 - "C:\ToolBar SD\TB_1.txt" - 2009-10-22|15:15 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 2009-10-25|18:09 - Option : [2]

-----------\\ Fin du rapport a 18:09:37,51


lop rapport:


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 2.93GHz )
BIOS : BIOS Date: 09/06/05 17:46:49 Ver: 08.00.10
USER : HP_Administrator ( Administrator )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091025-0] 4.8.1356 (Activated)
C:\ (Local Disk) - NTFS - Total:178 Go (Free:157 Go)
D:\ (Local Disk) - FAT32 - Total:8 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 2009-10-25|18:10 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\Circle Developement

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[2005-09-09|22:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[2005-06-10|13:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[2009-10-14|14:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[2005-09-09|22:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
[2005-09-09|22:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
[2005-09-09|22:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec

[2008-11-08|13:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009-09-30|17:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2008-09-06|16:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[2008-08-12|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2008-08-12|19:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2009-10-14|14:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
[2008-08-25|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[2009-10-14|13:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-09-09|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[2005-09-09|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
[2005-09-09|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[2005-09-09|22:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[2005-09-09|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intuit
[2008-09-06|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak
[2008-09-04|21:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[2009-10-02|16:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[2006-09-26|18:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[2009-09-05|16:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2005-11-15|20:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSScanAppDataDir
[2005-12-27|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
[2008-09-06|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Netscape Internet Service
[2008-11-07|20:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NokiaMusic
[2009-10-14|13:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Norton
[2009-09-07|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NortonInstaller
[2008-09-12|14:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[2009-09-05|16:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Media
[2005-12-27|21:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Otto
[2005-10-15|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[2009-10-14|14:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Roxio
[2005-09-09|21:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[2009-08-19|01:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[2009-10-14|13:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2008-09-11|09:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
[2009-09-07|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2009-09-08|23:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Team MediaPortal
[2009-09-05|17:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2006-08-02|21:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-12-29|19:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[2008-12-29|18:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-02-11|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[2009-10-14|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom


[2005-09-09|22:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Apple Computer
[2005-06-10|13:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[2005-09-09|22:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Intuit
[2005-09-09|22:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2005-09-09|22:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[2005-09-09|22:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[2005-09-09|22:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec

[2007-08-15|12:15] C:\DOCUME~1\Guest\APPLIC~1\AOL
[2005-09-09|22:28] C:\DOCUME~1\Guest\APPLIC~1\Apple Computer
[2008-03-06|22:48] C:\DOCUME~1\Guest\APPLIC~1\Google
[2008-03-06|22:58] C:\DOCUME~1\Guest\APPLIC~1\HP
[2005-06-10|13:02] C:\DOCUME~1\Guest\APPLIC~1\Identities
[2005-09-09|22:32] C:\DOCUME~1\Guest\APPLIC~1\Intuit
[2009-10-14|14:52] C:\DOCUME~1\Guest\APPLIC~1\Microsoft
[2005-09-09|22:12] C:\DOCUME~1\Guest\APPLIC~1\Real
[2005-09-09|22:33] C:\DOCUME~1\Guest\APPLIC~1\SampleView
[2007-12-30|02:27] C:\DOCUME~1\Guest\APPLIC~1\SlipStream
[2005-09-09|22:48] C:\DOCUME~1\Guest\APPLIC~1\Symantec

[2008-11-08|11:19] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ActiveState
[2009-09-30|17:42] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Adobe
[2008-11-01|17:36] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Apple Computer
[2008-08-25|09:52] C:\DOCUME~1\HP_ADM~1\APPLIC~1\AVS4YOU
[2008-09-09|13:13] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Google
[2008-09-09|11:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Grisoft
[2008-09-14|11:59] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Help
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Hewlett-Packard
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\HP
[2008-09-14|14:01] C:\DOCUME~1\HP_ADM~1\APPLIC~1\HPQ
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Identities
[2008-12-23|23:30] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Image Zone Express
[2009-08-19|01:27] C:\DOCUME~1\HP_ADM~1\APPLIC~1\InstallShield
[2005-10-19|02:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\InterVideo
[2005-09-09|22:32] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Intuit
[2005-10-21|00:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Leadertech
[2008-09-06|17:44] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Macromedia
[2009-10-02|16:13] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Malwarebytes
[2009-10-14|14:52] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Microsoft
[2008-09-06|17:18] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Mozilla
[2005-12-27|21:30] C:\DOCUME~1\HP_ADM~1\APPLIC~1\muvee Technologies
[2008-08-31|18:12] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Netscape
[2005-12-27|21:28] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Otto
[2008-11-07|19:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Real
[2009-08-19|01:35] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Roxio
[2008-09-08|09:47] C:\DOCUME~1\HP_ADM~1\APPLIC~1\SampleView
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\SlipStream
[2005-10-21|00:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Sonic
[2008-09-06|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Sun
[2005-10-14|22:07] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Symantec
[2005-10-15|11:42] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Template
[2008-09-06|15:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Uniblue
[2005-11-30|23:06] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Verbatim Software
[2005-11-30|23:05] C:\DOCUME~1\HP_ADM~1\APPLIC~1\V-Safe
[2006-12-02|20:20] C:\DOCUME~1\HP_ADM~1\APPLIC~1\You've Got Pictures Screensaver

[2009-10-14|14:52] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2009-08-19|01:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Roxio

[2009-10-14|14:52] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[2005-10-16|01:41] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[2009-10-25 15:45][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{14A18F9C-8275-4067-B3CB-617437F4508B}.job
[2008-09-29 17:53][--a------] C:\WINDOWS\tasks\Connexion facile … Internet.job
[2009-10-25 18:02][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-10 22:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ MsgPlus SPONSOR INSTALLED !

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"SponsorInstalled"=dword:00000000


--------------------\\ Listing des dossiers dans C:\Program Files

[2009-09-30|17:41] C:\Program Files\Adobe
[2006-03-05|21:11] C:\Program Files\Alwil Software
[2008-08-30|15:46] C:\Program Files\AVG
[2008-09-06|17:18] C:\Program Files\AVS4YOU
[2009-10-14|15:05] C:\Program Files\CCleaner
[2006-06-07|17:12] C:\Program Files\CDS
[2009-10-14|14:08] C:\Program Files\Common Files
[2005-06-08|12:59] C:\Program Files\ComPlus Applications
[2009-10-14|15:31] C:\Program Files\CONEXANT
[2008-01-16|18:39] C:\Program Files\dat
[2008-08-04|14:53] C:\Program Files\Easy Internet signup
[2007-10-28|20:31] C:\Program Files\EnglishOtto
[2008-01-16|18:39] C:\Program Files\fnt
[2009-09-09|07:39] C:\Program Files\Gamenext
[2007-10-28|20:31] C:\Program Files\GemMaster
[2009-10-14|13:33] C:\Program Files\Google
[2005-09-09|22:56] C:\Program Files\Hewlett-Packard
[2005-11-15|20:53] C:\Program Files\HP
[2009-10-14|13:47] C:\Program Files\InstallShield Installation Information
[2007-10-28|20:31] C:\Program Files\IntelliMover Data Transfer Demo
[2008-09-06|17:23] C:\Program Files\InterActual
[2009-10-15|17:58] C:\Program Files\Internet Explorer
[2005-09-09|22:21] C:\Program Files\InterVideo
[2008-11-08|13:54] C:\Program Files\iPod
[2008-11-08|13:55] C:\Program Files\iTunes
[2009-10-07|13:51] C:\Program Files\Java
[2008-12-28|18:03] C:\Program Files\Jeune Styliste 2
[2008-09-06|16:53] C:\Program Files\Kodak
[2009-08-15|15:23] C:\Program Files\LimeWire
[2008-09-04|15:05] C:\Program Files\Messenger
[2009-08-19|12:54] C:\Program Files\Messenger Plus! Live
[2008-09-01|12:35] C:\Program Files\MessengerPlus! 3
[2008-11-23|20:35] C:\Program Files\Microsoft
[2008-08-05|16:12] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2005-06-10|13:04] C:\Program Files\microsoft frontpage
[2007-08-21|19:48] C:\Program Files\Microsoft Games
[2008-04-22|20:55] C:\Program Files\Microsoft Money 2005
[2006-01-09|19:54] C:\Program Files\Microsoft Office
[2005-09-09|22:23] C:\Program Files\Microsoft Plus! Dancer LE
[2005-09-09|22:23] C:\Program Files\Microsoft Plus! Digital Media Edition
[2005-09-09|22:23] C:\Program Files\Microsoft Plus! Photo Story 2 LE
[2009-09-09|19:08] C:\Program Files\Microsoft Silverlight
[2008-08-05|11:22] C:\Program Files\Microsoft SQL Server Compact Edition
[2009-08-19|02:15] C:\Program Files\Microsoft Sync Framework
[2005-09-09|22:26] C:\Program Files\Microsoft Visual Studio
[2007-10-28|20:31] C:\Program Files\Microsoft Works
[2008-01-16|18:39] C:\Program Files\mid
[2008-09-04|14:46] C:\Program Files\Movie Maker
[2009-10-25|18:06] C:\Program Files\Mozilla Firefox
[2009-08-14|16:08] C:\Program Files\MSBuild
[2008-12-29|17:42] C:\Program Files\MSECACHE
[2005-10-20|20:16] C:\Program Files\MSN
[2007-10-28|20:31] C:\Program Files\MSN Encarta Standard
[2006-01-16|15:36] C:\Program Files\MSN Games
[2005-06-10|13:04] C:\Program Files\MSN Gaming Zone
[2009-08-19|02:11] C:\Program Files\MSN Messenger
[2008-08-05|16:03] C:\Program Files\MSXML 4.0
[2005-09-09|22:31] C:\Program Files\muvee Technologies
[2008-09-04|14:41] C:\Program Files\NetMeeting
[2006-08-18|16:33] C:\Program Files\Netscape
[2008-09-06|17:13] C:\Program Files\Netscape Internet Service
[2008-09-12|14:50] C:\Program Files\NOS
[2009-09-05|16:32] C:\Program Files\Oberon Media
[2005-09-09|22:44] C:\Program Files\Online Services
[2009-08-13|13:41] C:\Program Files\Outlook Express
[2007-10-28|20:31] C:\Program Files\PC-Doctor 5 for Windows
[2005-09-09|22:40] C:\Program Files\PC-Doctor for DOS
[2008-01-16|18:39] C:\Program Files\Pcx
[2009-09-30|22:44] C:\Program Files\PhotoFiltre
[2009-09-30|22:44] C:\Program Files\PhotoScape
[2009-09-08|23:40] C:\Program Files\Photosynth
[2009-10-15|15:02] C:\Program Files\QUAD Utilities
[2009-10-14|13:35] C:\Program Files\Quicken
[2008-11-08|13:49] C:\Program Files\QuickTime
[2008-11-07|19:36] C:\Program Files\Real
[2009-08-14|16:08] C:\Program Files\Reference Assemblies
[2009-08-19|01:01] C:\Program Files\Research In Motion
[2009-10-21|13:14] C:\Program Files\SelectView
[2008-01-16|18:39] C:\Program Files\snd
[2009-10-14|13:57] C:\Program Files\Sonic
[2008-09-14|11:48] C:\Program Files\Sophos
[2008-01-16|18:39] C:\Program Files\spr
[2009-10-14|13:41] C:\Program Files\Spybot - Search & Destroy
[2008-05-05|17:12] C:\Program Files\Styliste2
[2006-03-06|10:25] C:\Program Files\Symantec
[2009-09-08|23:06] C:\Program Files\Team MediaPortal
[2008-12-28|18:03] C:\Program Files\TMNT
[2009-10-13|12:14] C:\Program Files\Trend Micro
[2007-09-28|16:55] C:\Program Files\ubisoft
[2006-04-30|19:34] C:\Program Files\Ulead Systems
[2005-06-08|12:59] C:\Program Files\Uninstall Information
[2008-12-17|22:39] C:\Program Files\WildTangent
[2008-12-29|17:42] C:\Program Files\Windows Installer Clean Up
[2009-08-19|02:14] C:\Program Files\Windows Live
[2008-08-05|11:36] C:\Program Files\Windows Live Favorites
[2008-09-16|09:03] C:\Program Files\Windows Live Safety Center
[2009-08-19|02:11] C:\Program Files\Windows Live SkyDrive
[2009-08-19|02:15] C:\Program Files\Windows Live Toolbar
[2008-11-08|15:41] C:\Program Files\Windows Media Player
[2008-09-04|14:41] C:\Program Files\Windows NT
[2005-06-10|13:05] C:\Program Files\Windows Plus
[2005-06-08|13:00] C:\Program Files\WindowsUpdate
[2005-06-10|13:05] C:\Program Files\xerox
[2006-02-11|12:10] C:\Program Files\Yahoo!
[2008-03-06|22:33] C:\Program Files\Zuma Deluxe

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[2009-09-30|17:41] C:\Program Files\Common Files\Adobe
[2008-09-06|17:26] C:\Program Files\Common Files\AOL
[2008-11-08|13:47] C:\Program Files\Common Files\Apple
[2008-09-06|17:17] C:\Program Files\Common Files\AVSMedia
[2005-09-09|22:07] C:\Program Files\Common Files\Hewlett-Packard
[2005-09-09|22:04] C:\Program Files\Common Files\HP
[2005-09-09|22:30] C:\Program Files\Common Files\InstallShield
[2005-09-09|22:21] C:\Program Files\Common Files\InterVideo
[2008-09-12|13:58] C:\Program Files\Common Files\Java
[2005-09-09|22:20] C:\Program Files\Common Files\LightScribe
[2009-08-02|22:35] C:\Program Files\Common Files\Microsoft Shared
[2005-06-10|13:03] C:\Program Files\Common Files\MSSoap
[2005-09-09|22:30] C:\Program Files\Common Files\muvee Technologies
[2006-12-02|20:20] C:\Program Files\Common Files\Nullsoft
[2009-09-05|16:32] C:\Program Files\Common Files\Oberon Media
[2005-06-10|13:03] C:\Program Files\Common Files\ODBC
[2008-11-07|19:38] C:\Program Files\Common Files\Real
[2009-10-14|14:16] C:\Program Files\Common Files\Roxio Shared
[2005-06-10|13:03] C:\Program Files\Common Files\Services
[2006-05-09|19:07] C:\Program Files\Common Files\snpp106
[2009-10-14|14:16] C:\Program Files\Common Files\Sonic Shared
[2005-06-10|13:03] C:\Program Files\Common Files\SpeechEngines
[2007-05-15|16:59] C:\Program Files\Common Files\SWF Studio
[2009-10-14|13:31] C:\Program Files\Common Files\Symantec Shared
[2008-09-04|14:41] C:\Program Files\Common Files\System
[2005-10-22|04:30] C:\Program Files\Common Files\Totem Shared
[2008-11-23|20:02] C:\Program Files\Common Files\Windows Live
[2008-08-05|11:12] C:\Program Files\Common Files\WindowsLiveInstaller

--------------------\\ Process

( 15 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-25 18:12:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\HP_ADM~1\Local Settings\Temporary Internet Files\Content.IE5\NNKD1NCJ\crackyfred_1237318629[1].jpg


[F:49][D:5]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
[F:30][D:0]-> C:\DOCUME~1\HP_ADM~1\Cookies
[F:2894][D:6]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 2009-10-25|18:14 - Option : [2]

--------------------\\ Fin du rapport a 18:14:06

Répondre à phoenixgirl

5

kduc, le 26 oct 2009 à 00:06:20

Salut,

Tu as, semble-t'il, des restes de Norton/Symantec sur le PC !

Peut-être une version pré-installée à l' achat ; pour supprimer cet antivirus, utilise cet outil :

http://service1.symantec.com/...

---
Redémarre le PC en mode sans échec ...
http://www.pcastuces.com/pratique/windows/mode_sans_echec/pa­ge2.html
(méthode F8 de préférence)

--------------------------------------------
Tu n' auras pas accès à Internet pendant le "mode sans échec".
Aussi, copie/colle la procédure dans un fichier texte (word) et mets-la
sur le "bureau" pour l' avoir à ta disposition.
--------------------------------------------

Ferme toutes les fenêtres et applications.
Relance HijackThis et clique sur > Do a system scan only puis, coche
les cases devant les lignes qui suivent (et uniquement ces lignes), si tjrs présentes :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.gamenext.com
R3 - URLSearchHook: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
O2 - BHO: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O3 - Toolbar: P2P Max DE Toolbar - {e0007d18-baa4-4573-ae78-8bea0958c610} - C:\Program Files\P2P_Max_DE\tbP2P1.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu

Ensuite, clique sur > Fix checked et valide par "Yes". Referme HijackThis.

Affiche les fichiers et dossiers cachés
Pour ce faire, tu vas dans un dossier, par ex. "Mes Images".
Ensuite, clique sur > Outils > Options des dossiers ...
clique sur l' onglet « Affichage » et ...
coche --> Afficher les fichiers et dossiers cachés
décoche > Masquer les extensions des fichiers dont le type est connu
décoche > Masquer les fichiers protégés du système d' exploitation (recommandé).
« Appliquer » et « OK ».

Rends-toi dans > Démarrer > Panneau de config. > Ajout/suppres… de programmes

Supprime, si tu le(s) trouves > WildTangent, QUAD Utilities, P2P_Max_DE et Crawler

Ensuite, va dans > Démarrer > Poste de travail > C:\

et supprime le(s) programme(s)/ fichier(s) en gras, ci-dessous, si tu le(s) trouves.

C:\PROGRA~1\Crawler <-
C:\Program Files\WildTangent <-
C:\Program Files\QUAD Utilities <-
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM <-

Remet les fichiers et dossiers cachés comme tu les as trouvés !

Lance CCleaner ...
Clique sur > Analyser > Nettoyer, puis sur OK dans la fenêtre qui s' affiche.
(re)Lance le nettoyage et (re)confirme par OK.

Redémarre le PC en mode normal ...

Télécharge Ad-Remover : http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe (de Cyrildu17 / C_XX) sur ton Bureau.
http://pagesperso-orange.fr/NosTools/ad_remover.html

! Déconnecte-toi du net et ferme toutes applications en cours.

1. Double-clique sur le programme d'installation ; laisse-le
s’ installer par défaut (C:\Program files).
2. Double-clique sur l'icône AD-Remover située sur ton Bureau.
(Pour Vista : clique droit > "Exécuter en tant qu'administrateur")
3. Au menu principal, choisis l'option L.
L’ outil débute sa recherche … Laisse-le travailler !
Le scan achevé, une fenêtre va s’ afficher.
4. Poste (copie-colle) le rapport qui apparaît à la fin.

PS : tu trouveras aussi le rapport sous C:\Ad-report(date).log)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

Note : "Process.exe", une composante de l'outil peut être
détecté par certains antivirus comme une infection ; donc, ne pas en tenir compte : il s'agit d'un faux positif.

Répondre à kduc

6

phoenixgirl, le 5 nov 2009 à 23:12:54

.
======= LOGFILE OF AD-REMOVER 1.1.4.6_A | ONLY XP/VISTA/7 =======
.
Updated by C_XX on 18.10.2009 at 19:05
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Launch at: 16:58:44, 2009-11-05 | Normal Boot | Option: CLEAN
Executed from: C:\Program Files\Ad-Remover\
Operating system: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Computer Name: PAM_ALEX | Current user: HP_Administrator
.
============== NEUTRALIZED ELEMENT(S) ==============
.

HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A­0AADCD-3A72-4B5F-900F-E3BB5A838E2A}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC­4FFE41-DE9F-46fa-B455-AAD49B9F9938}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE­E6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE­E6C35C-6118-11DC-9C72-001320C79847}
HKCU\Software\SWEETIE
HKCU\Software\SweetIM
HKLM\Software\SweetIM
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BC4FFE41-DE9F-46FA-B455-AAD49B­9F9938}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F­3D3542}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320­C79847}
HKLM\software\microsoft\windows\currentversion\installer\use­rdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\software\microsoft\windows\currentversion\installer\use­rdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\DOCUME~1\HP_ADM~1\APPLIC~1\Mozilla\Firefox\Profiles\iw3l1­4e0.default\searchplugins\sweetim.xml

(!) -- Temp files deleted.

.
============== Added scan ==============
.
.
* Mozilla FireFox Version 3.5.4 [fr] *
.
ProfilePath: iw3l14e0.default (HP_Administrator)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Google");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://search.live.com/results.aspx?FORM=IEFM1&q=");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.4");
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Start Page: hxxp://fr.msn.com/
Search Page: hxxp://www.google.com
Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchAssistant:
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
3072 Byte(s) - C:\Ad-Report-CLEAN[1].log
.
1 File(s) - C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
3 File(s) - C:\WINDOWS\Temp
.
18 File(s) - C:\Program Files\Ad-Remover\BACKUP
1 File(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
End at: 17:08:35 | 2009-11-05 - CLEAN[1]
.
============== E.O.F ==============
.

Répondre à phoenixgirl

7

kduc, le 5 nov 2009 à 23:32:46

Salut,

"Mes logiciels de sécurité ne cessent de détecter des TRACKING COOKIES lors des analyses quotidiennes...
Je ne sais pas s'il y a un virus ou quoi mais mon ordi est très lent et il bogue souvent
."

C' est tjrs d' actualité ?

---
Fais un clic droit sur le lien pour installer SDFix (par AndyManchesta) :
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Choisis "Enregistrer sous" (dans IE c'est "Enregistrer la cible/le lien sous..")
et sauvegarde-le (Enregistrer dans) sur le Bureau.

Important : dans "Nom du fichier" enregistre (renomme) "sdfix" ou "SdFix.exe" en sd-fix.exe

Redémarre en mode sans échec ...
http://www.pcastuces.com/pratique/windows/mode_sans_echec/page2.htm
(de préférence par F8 au démarrage).

--------------------------------------------
Tu n' auras pas accès à Internet pendant le "mode sans échec".
Aussi, copie/colle la procédure dans un fichier texte (word) et mets-la
sur le "bureau" pour l' avoir à ta disposition.
--------------------------------------------

Sur le bureau, double-clique sur sd-fix.exe et choisis Install pour l'extraire sur le Bureau.
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur
RunThis.cmd (ou RunThis.bat) pour lancer le script.

Appuie sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre des trojans trouvés puis te
demandera d'appuyer sur une touche pour redémarrer. Fais-le.

Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va
continuer à s'exécuter et supprimer des fichiers.

Après le chargement du Bureau, l'outil terminera son travail et affichera "Finished".
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.

Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera
aussi dans le dossier SDFix sous le nom Report.txt.

Copie/colle le contenu du fichier Report.txt dans ta prochaine réponse.

Tuto : http://www.malekal.com/tutorial_SDFix.php

Ensuite, ...

Télécharge, installe et mets à jour Malwarebytes Anti-Malwares
http://forum.telecharger.01net.com/... puis, lance un scan COMPLET et poste le rapport.

PS : si MalwareByte's a détecté des infections, clique sur Afficher les résultats,
puis sur Supprimer la sélection.

Répondre à kduc

8

phoenixgirl, le 24 nov 2009 à 22:42:40

Ca ne fonctionne pas!! Lorsque j'exécute SdFix, une fenêtre bleue s'ouvre et je tappe Y, mais ca ne se lance pas... Je ne comprends...... : (

Répondre à phoenixgirl

9

 kduc, le 25 nov 2009 à 09:09:39

Salut,

OK.

Alors, enchaîne avec Malwarebytes.

Répondre à kduc