Rechercher : dans
Par :

[Virus] Win32 Hidrag.a

Dernière réponse le 14 nov 2009 à 19:57:09 Nomak49, le 14 nov 2009 à 16:10:04 
 Signaler ce message aux modérateurs

Bonjour, comme beaucoup d'autres, j'ai été infecté par le virus Win 32 Hidrag qui infeste maintenant mon disque dur externe.
Je l'ai repéré avec Avira, et j'ai tenté de le supprimer avec USB Fix, XoftSpySE, SuperAntiSpyware..... sans résultat. Les trois quart du temps, ils ne me le repèrent même pas. J'ai du télécharger une quinzaine de logiciels mais entre ceux qu'il faut acheter, ceux qui ne fonctionnent pas sur mon pc, je galère....

Donc, je vous poste le rapport Hijack que j'obtiens en espérant que vous pourrez m'aider.
Le souci, c'est que je viens de me rendre compte qu'il n'y avait aucune mention de mon disque dur externe (G) dessus...

Logfile of HijackThis v1.99.1
Scan saved at 16:06:18, on 14/11/2009
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\XoftSpySE6\XoftSpySE.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Users\ACER\AppData\Local\Temp\RtkBtMnt.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Windows\system32\wuauclt.exe
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\OpenOffice.org 3\program\swriter.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\MpcStar\mpcstar.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\ACER\hijackthis_199\HijackThis.exe

O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\\PLFSetL.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [XoftSpySE] "C:\Program Files\XoftSpySE6\XoftSpySE.exe" -NM -hidesplash
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: XoftSpyService - ParetoLogic Inc. - C:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe

Configuration: Windows Vista 32 bits

1

Destrio5, le 14 nov 2009 à 16:13:53

Bonjour,

--> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

--> Double-clique sur RSIT.exe afin de lancer le programme.
(Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)

--> Clique sur Continue à l'écran Disclaimer.

--> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

--> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

Note : les rapports sont sauvegardés dans le dossier C:\rsit.

Répondre à Destrio5

2

Nomak49, le 14 nov 2009 à 16:34:53

Allons y, je poste d'abord le fichier log.txt

ogfile of random's system information tool 1.06 (written by random/random)
Run by ACER at 2009-11-14 16:19:50
Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
System drive C: has 14 GB (13%) free of 114 GB
Total RAM: 3070 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:20:18, on 14/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)
Boot mode: Normal

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\XoftSpySE6\XoftSpySE.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Users\ACER\AppData\Local\Temp\RtkBtMnt.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Windows\system32\wuauclt.exe
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\OpenOffice.org 3\program\swriter.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\MpcStar\mpcstar.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\conime.exe
C:\Users\ACER\Downloads\a2AntiMalwareSetup.exe
C:\Users\ACER\AppData\Local\Temp\is-2DUED.tmp\a2AntiMalwareSetup.tmp
C:\Users\ACER\Downloads\RSIT.exe
C:\Program Files\trend micro\ACER.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\\PLFSetL.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [XoftSpySE] "C:\Program Files\XoftSpySE6\XoftSpySE.exe" -NM -hidesplash
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: XoftSpyService - ParetoLogic Inc. - C:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe
End of file - 9493 bytes

======Scheduled tasks folder======

C:\Windows\tasks\McDefragTask.job
C:\Windows\tasks\McQcTask.job
C:\Windows\tasks\ParetoLogic Registration3.job
C:\Windows\tasks\ParetoLogic Update Version3.job
C:\Windows\tasks\XoftSpySE.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\PROGRA~1\mcafee\msk\mskapbho.dll [2009-10-02 246800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-01-03 312368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-02-13 150032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-11 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-05 142896]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-02-13 150032]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-12-05 4710400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2009-09-17 645328]
"eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-03-05 525360]
"eAudio"=C:\Acer\Empowering Technology\eAudio\eAudio.exe [2007-10-10 1286144]
"PCMService"=C:\Program Files\Acer\Acer Arcade\PCMService.exe [2008-01-25 155648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-03-08 40048]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2007-10-17 768520]
"PLFSetI"=C:\Windows\PLFSetI.exe [2007-10-23 200704]
"PLFSetL"=C:\Windows\\PLFSetL.exe [2007-07-05 94208]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-07-21 159744]
"eRecoveryService"= []
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-11-11 148888]
"XoftSpySE"=C:\Program Files\XoftSpySE6\XoftSpySE.exe [2009-08-28 4853016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-10 218032]
"Connexion SFR 9props.exe"=C:\Program Files\SFR\Kit\9props.exe [2009-10-15 959808]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-11-11 2001648]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ACER^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-04-16 384000]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{096fa707-80ef-11de-9cb8-00235a5af887}]
shell\AutoRun\command - RECYCLER\help.exe
shell\opEN\command - RECYCLER\help.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5d2606df-10f3-11de-95e8-806e6f6e6963}]
shell\AutoRun\command - E:\Autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0d63c6d-8258-11de-8e7d-00235a5af887}]
shell\AutoRun\command - H:\RECYCLER\help.exe
shell\opEN\command - H:\RECYCLER\help.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f215b5b0-84d9-11de-9da7-00242bd2abde}]
shell\AutoRun\command - F:\autorun.exe


======List of files/folders created in the last 1 months======

2009-11-14 16:20:07 ----D---- C:\Program Files\a-squared Anti-Malware
2009-11-14 16:19:50 ----D---- C:\rsit
2009-11-14 16:19:50 ----D---- C:\Program Files\trend micro
2009-11-14 16:14:50 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-11-14 16:14:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-11-14 15:11:43 ----A---- C:\UsbFix.txt
2009-11-14 01:11:03 ----D---- C:\UsbFix
2009-11-14 01:05:40 ----DC---- C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-14 00:28:44 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2009-11-14 00:26:29 ----D---- C:\Users\ACER\AppData\Roaming\SUPERAntiSpyware.com
2009-11-14 00:26:29 ----D---- C:\Program Files\SUPERAntiSpyware
2009-11-13 22:27:04 ----D---- C:\ProgramData\ParetoLogic
2009-11-13 22:27:01 ----D---- C:\Program Files\Common Files\ParetoLogic
2009-11-13 22:26:55 ----D---- C:\Program Files\Common Files\XoftSpySE
2009-11-13 22:26:51 ----D---- C:\ProgramData\XoftSpySE
2009-11-13 22:26:44 ----D---- C:\Program Files\XoftSpySE6
2009-11-13 22:13:03 ----D---- C:\Program Files\Lavasoft
2009-11-13 21:32:48 ----D---- C:\Program Files\CCleaner
2009-11-13 18:31:13 ----D---- C:\Windows\pss
2009-11-13 13:58:41 ----D---- C:\Windows\Sun
2009-11-11 19:56:02 ----A---- C:\Windows\system32\javaws.exe
2009-11-11 19:56:02 ----A---- C:\Windows\system32\javaw.exe
2009-11-11 19:56:02 ----A---- C:\Windows\system32\java.exe
2009-11-11 19:56:02 ----A---- C:\Windows\system32\deploytk.dll
2009-11-11 19:55:04 ----D---- C:\Program Files\Java
2009-11-11 19:54:14 ----D---- C:\Program Files\Kommute
2009-11-11 18:56:37 ----D---- C:\Program Files\VirtualDJ
2009-11-11 03:10:11 ----D---- C:\714b7ab49b3deeb8bad8
2009-11-11 01:10:15 ----A---- C:\Windows\system32\WSDApi.dll
2009-11-08 14:25:08 ----D---- C:\Users\ACER\AppData\Roaming\Ubisoft
2009-11-08 14:17:03 ----D---- C:\ProgramData\Ubisoft
2009-11-08 14:15:46 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-11-08 14:15:43 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-11-08 14:15:43 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-11-08 14:15:41 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-11-08 14:15:39 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-11-08 14:15:37 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-11-08 14:15:37 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-11-08 14:15:34 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-11-08 14:15:32 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-11-08 14:15:32 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-11-08 14:15:29 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-11-08 14:15:29 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-11-08 14:15:27 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-11-08 14:15:26 ----A---- C:\Windows\system32\xinput1_3.dll
2009-11-08 14:15:25 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-11-08 14:15:23 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-11-08 14:15:23 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-11-08 14:15:21 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-11-08 14:15:20 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-11-08 14:15:19 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-11-08 14:15:18 ----A---- C:\Windows\system32\d3dx10.dll
2009-11-08 14:15:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-11-08 14:15:15 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-11-08 14:15:15 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-11-08 14:15:13 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-11-08 14:15:12 ----A---- C:\Windows\system32\xinput1_2.dll
2009-11-08 14:15:12 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-11-08 14:15:10 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-11-08 14:15:09 ----A---- C:\Windows\system32\xinput1_1.dll
2009-11-08 14:15:08 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-11-08 14:14:36 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-11-08 14:14:33 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-11-08 14:14:33 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-11-08 14:14:31 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-11-08 14:14:28 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-11-08 14:14:26 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-11-08 14:14:24 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-11-08 14:14:22 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-11-08 14:14:19 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-11-05 21:45:09 ----D---- C:\Program Files\SiteAdvisor
2009-11-05 21:43:38 ----D---- C:\ProgramData\Avira
2009-11-05 21:43:38 ----D---- C:\Program Files\Avira
2009-11-05 21:00:02 ----D---- C:\NVIDIA
2009-11-05 19:56:12 ----D---- C:\Program Files\directx
2009-11-05 11:38:32 ----D---- C:\Program Files\SFR
2009-11-04 17:19:47 ----A---- C:\Windows\system32\mshtml.dll
2009-10-28 21:59:38 ----D---- C:\Program Files\LucasArts
2009-10-28 21:59:27 ----A---- C:\Windows\unin040c.exe
2009-10-28 21:27:11 ----AT---- C:\Windows\system32\SIntfNT.dll
2009-10-28 21:27:11 ----AT---- C:\Windows\system32\SIntf32.dll
2009-10-28 21:27:10 ----AT---- C:\Windows\system32\SIntf16.dll
2009-10-28 16:07:22 ----A---- C:\Windows\system32\wmp.dll
2009-10-28 16:07:18 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-28 16:07:10 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-27 21:03:35 ----A---- C:\Windows\system32\CmdLineExt03.dll
2009-10-27 14:29:00 ----A---- C:\Windows\system32\wups2.dll
2009-10-27 14:29:00 ----A---- C:\Windows\system32\wucltux.dll
2009-10-27 14:29:00 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-27 14:29:00 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-27 14:28:02 ----A---- C:\Windows\system32\wups.dll
2009-10-27 14:28:02 ----A---- C:\Windows\system32\wudriver.dll
2009-10-27 14:28:01 ----A---- C:\Windows\system32\wuapi.dll
2009-10-27 14:27:14 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-27 14:27:14 ----A---- C:\Windows\system32\wuapp.exe
2009-10-27 13:42:29 ----D---- C:\Program Files\GameSpy Arcade
2009-10-26 22:50:34 ----D---- C:\Windows\system32\URTTEMP
2009-10-26 22:49:44 ----A---- C:\Windows\iun6002.exe
2009-10-26 22:40:22 ----D---- C:\Program Files\QuickPar
2009-10-26 14:16:55 ----A---- C:\Windows\system32\Mfc42loc.dll
2009-10-26 12:41:52 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-26 12:41:34 ----A---- C:\Windows\system32\wininet.dll
2009-10-26 12:41:34 ----A---- C:\Windows\system32\occache.dll
2009-10-26 12:41:33 ----A---- C:\Windows\system32\urlmon.dll
2009-10-26 12:41:31 ----A---- C:\Windows\system32\ieframe.dll
2009-10-26 12:41:28 ----A---- C:\Windows\system32\ieapfltr.dll
2009-10-26 12:41:27 ----A---- C:\Windows\system32\iertutil.dll
2009-10-26 12:41:26 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-26 12:41:25 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-26 12:41:23 ----A---- C:\Windows\system32\ieaksie.dll
2009-10-26 12:41:22 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-26 12:41:21 ----A---- C:\Windows\system32\mstime.dll
2009-10-26 12:41:21 ----A---- C:\Windows\system32\ieencode.dll
2009-10-26 12:41:20 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-26 12:40:38 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-10-26 12:40:33 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-10-26 12:39:40 ----A---- C:\Windows\system32\wlanmsm.dll
2009-10-26 12:39:40 ----A---- C:\Windows\system32\L2SecHC.dll
2009-10-26 12:39:39 ----A---- C:\Windows\system32\wlansec.dll
2009-10-26 12:39:37 ----A---- C:\Windows\system32\wlansvc.dll
2009-10-26 12:31:34 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-26 12:31:32 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-26 11:42:37 ----A---- C:\Windows\system32\netiohlp.dll
2009-10-26 11:42:34 ----A---- C:\Windows\system32\NETSTAT.EXE
2009-10-26 11:42:34 ----A---- C:\Windows\system32\ARP.EXE
2009-10-26 11:42:33 ----A---- C:\Windows\system32\TCPSVCS.EXE
2009-10-26 11:42:32 ----A---- C:\Windows\system32\MRINFO.EXE
2009-10-26 11:42:32 ----A---- C:\Windows\system32\HOSTNAME.EXE
2009-10-26 11:42:32 ----A---- C:\Windows\system32\finger.exe
2009-10-26 11:42:31 ----A---- C:\Windows\system32\ROUTE.EXE
2009-10-26 11:42:27 ----A---- C:\Windows\system32\netevent.dll
2009-10-26 11:40:28 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-10-26 11:40:28 ----A---- C:\Windows\system32\mf.dll
2009-10-26 10:25:19 ----A---- C:\Windows\system32\jscript.dll
2009-10-26 10:24:09 ----A---- C:\Windows\system32\msasn1.dll
2009-10-26 10:23:13 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2009-10-21 00:03:24 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-10-21 00:03:24 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-10-21 00:03:22 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-10-21 00:03:20 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-10-21 00:03:20 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-10-21 00:03:19 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-10-21 00:03:17 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-10-21 00:03:16 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-10-21 00:03:16 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-10-21 00:03:14 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-10-21 00:03:12 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-10-21 00:03:12 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-10-21 00:03:10 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-10-21 00:03:09 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-10-21 00:03:07 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-10-21 00:03:07 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-10-21 00:03:05 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-10-21 00:03:04 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-10-21 00:03:03 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-10-21 00:03:02 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-10-19 20:13:43 ----D---- C:\Windows\85EBB28365AF4C539EBE7C0A232762F7.TMP
2009-10-19 20:13:36 ----D---- C:\ProgramData\Media Center Programs
2009-10-19 19:31:57 ----RHD---- C:\Users\ACER\AppData\Roaming\SecuROM
2009-10-19 14:17:30 ----A---- C:\Windows\IsUn040c.exe
2009-10-17 17:00:52 ----D---- C:\Users\ACER\AppData\Roaming\Mozilla
2009-10-17 16:48:50 ----D---- C:\Program Files\Mozilla Firefox

======List of files/folders modified in the last 1 months======

2009-11-14 16:20:07 ----RD---- C:\Program Files
2009-11-14 16:20:06 ----D---- C:\Windows\Prefetch
2009-11-14 16:19:59 ----D---- C:\Windows\Temp
2009-11-14 16:14:50 ----HD---- C:\ProgramData
2009-11-14 15:47:03 ----D---- C:\Users\ACER\AppData\Roaming\UseNeXT
2009-11-14 15:16:16 ----D---- C:\Windows
2009-11-14 10:01:04 ----D---- C:\Program Files\McAfee
2009-11-14 01:03:18 ----D---- C:\Windows\Minidump
2009-11-14 01:03:18 ----D---- C:\Windows\Debug
2009-11-14 00:40:43 ----SHD---- C:\System Volume Information
2009-11-14 00:32:17 ----SHD---- C:\Windows\Installer
2009-11-14 00:27:10 ----SD---- C:\Users\ACER\AppData\Roaming\Microsoft
2009-11-14 00:24:07 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-11-13 23:18:38 ----D---- C:\Windows\System32
2009-11-13 23:18:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-11-13 23:18:36 ----D---- C:\Windows\inf
2009-11-13 22:32:48 ----D---- C:\Windows\system32\Tasks
2009-11-13 22:32:47 ----D---- C:\Windows\Tasks
2009-11-13 22:27:01 ----D---- C:\Program Files\Common Files
2009-11-13 18:02:43 ----D---- C:\Windows\system32\WDI
2009-11-13 18:01:09 ----D---- C:\Windows\system32\wbem
2009-11-13 17:57:07 ----D---- C:\Windows\system32\config
2009-11-13 17:56:30 ----D---- C:\Windows\system32\spool
2009-11-13 17:56:30 ----D---- C:\Windows\system32\drivers
2009-11-13 17:56:30 ----D---- C:\Windows\system32\catroot2
2009-11-13 17:56:24 ----D---- C:\Users\ACER\AppData\Roaming\DAEMON Tools
2009-11-13 17:55:47 ----D---- C:\Windows\registration
2009-11-11 20:01:34 ----RD---- C:\Users
2009-11-11 18:58:37 ----RSD---- C:\Windows\Fonts
2009-11-11 03:57:38 ----D---- C:\Windows\winsxs
2009-11-11 03:18:48 ----D---- C:\Windows\system32\catroot
2009-11-11 03:13:58 ----D---- C:\Program Files\Windows Mail
2009-11-11 02:57:58 ----D---- C:\Users\ACER\AppData\Roaming\dvdcss
2009-11-11 02:35:10 ----D---- C:\Program Files\MpcStar
2009-11-10 02:52:30 ----D---- C:\ProgramData\McAfee
2009-11-08 14:15:08 ----RSD---- C:\Windows\assembly
2009-11-08 13:36:29 ----HD---- C:\Program Files\InstallShield Installation Information
2009-11-05 19:52:49 ----SD---- C:\Windows\Downloaded Program Files
2009-11-05 18:36:21 ----A---- C:\Windows\system32\mrt.exe
2009-10-29 19:15:14 ----AD---- C:\ProgramData\TEMP
2009-10-29 09:29:27 ----D---- C:\Windows\rescache
2009-10-29 09:11:56 ----D---- C:\Windows\system32\fr-FR
2009-10-29 09:11:56 ----D---- C:\Program Files\Windows Media Player
2009-10-29 08:55:42 ----D---- C:\Program Files\Internet Explorer
2009-10-28 03:11:36 ----D---- C:\Windows\Microsoft.NET
2009-10-28 03:05:40 ----D---- C:\Windows\AppPatch
2009-10-23 12:11:56 ----RSHD---- C:\RECYCLER
2009-10-16 18:04:00 ----D---- C:\Windows\system32\AGEIA
2009-10-16 18:04:00 ----D---- C:\Program Files\AGEIA Technologies

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [2006-11-02 20112]
R1 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys [2009-09-16 214664]
R1 MPFP;MPFP; C:\Windows\System32\Drivers\Mpfp.sys [2009-07-16 130424]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2009-11-11 9968]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2009-11-11 74480]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-11-08 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-11-08 55656]
R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2007-07-03 15392]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-01-03 16432]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-01-03 59952]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-01-30 8704]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-12-11 163376]
R3 BCM43XX;Pilote pour carte réseau Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-10-26 1044984]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-02 21264]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 32256]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-04-26 984064]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-04-26 208384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-12-05 2027032]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2009-09-16 79816]
R3 mfebopk;McAfee Inc. mfebopk; C:\Windows\system32\drivers\mfebopk.sys [2009-09-16 35272]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\Windows\system32\drivers\mfesmfk.sys [2009-09-16 40552]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-03-20 6144]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-12-05 8241984]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-11-11 7408]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-04-26 660480]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 atg8rhww;atg8rhww; C:\Windows\system32\drivers\atg8rhww.sys []
S3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-07-30 743424]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 mferkdk;McAfee Inc. mferkdk; C:\Windows\system32\drivers\mferkdk.sys [2009-09-16 34248]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-12-03 1040544]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ALaunchService;ALaunch Service; C:\Acer\ALaunch\ALaunchSvc.exe [2007-09-19 51200]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-11-08 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-11-08 185089]
R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe [2008-01-25 254059]
R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe [2008-01-25 114793]
R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe [2008-01-25 1076832]
R2 eDataSecurity Service;eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-03-05 497712]
R2 eLockService;eLock Service; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [2007-10-01 24576]
R2 eNet Service;eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [2008-06-10 131072]
R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-09-10 57344]
R2 eSettingsService;eSettings Service; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-12-19 24576]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2009-03-11 210216]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2009-09-17 865832]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2009-07-07 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2009-07-08 359952]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2009-09-16 144704]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-11-27 110592]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2009-09-15 894136]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2009-10-02 26640]
R2 WMIService;ePower$ Service; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-09-20 167936]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-01-30 386560]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2009-09-16 606736]
R3 XoftSpyService;XoftSpyService; C:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe [2009-08-28 582424]
S2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 aspnet_state;Service d'état ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-27 34312]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2009-09-16 365072]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Quel foutoir indigeste !! Bon, la suite, avec le fichier info.txt

======Uninstall list======

-->C:\Windows\IsUninst.exe -f"d:\jeux vidéos\Vampire The Masquerade\Vampire.isu"
-->MsiExec /X{45235788-142C-44BE-8A4D-DDE9A84492E5}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\setup.exe" -uninstall
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Acer Arcade-->C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe -uninstall
Acer Crystal Eye Webcam Video Class Camera -->C:\Program Files\InstallShield Installation Information\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}\setup.exe -runfromtemp -l0x040c -removeonly -u
Acer Crystal Eye Webcam-->C:\Program Files\InstallShield Installation Information\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}\setup.exe -runfromtemp -l0x040c -removeonly
Acer eAudio Management-->"C:\Program Files\InstallShield Installation Information\{57265292-228A-41FA-9AEC-4620CBCC2739}\Setup.exe" -uninstall
Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\x86\eDSnstHelper.exe -Operation UNINSTALL
Acer eLock Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}\setup.exe" -l0x40c -removeonly
Acer Empowering Technology-->"C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -runfromtemp -l0x040c -removeonly
Acer eNet Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C06554A1-2C1E-4D20-B613-EE62C79927CC}\setup.exe" -l0x40c -removeonly
Acer ePower Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\setup.exe" -l0x40c -removeonly
Acer ePresentation Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BF839132-BD43-4056-ACBF-4377F4A88E2A}\setup.exe" -l0x40c -removeonly
Acer eSettings Management-->"C:\Program Files\InstallShield Installation Information\{CE65A9A0-9686-45C6-9098-3C9543A412F0}\setup.exe" -runfromtemp -l0x040c -removeonly
Acer GameZone Console 2.0.1.1-->"C:\Program Files\Acer GameZone\GameConsole\unins000.exe"
Acer GridVista-->C:\Windows\UnInst32.exe GridV.UNI
Acer Mobility Center Plug-In-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
Agatha Christie Death on the Nile-->"C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\Uninstall.exe" "C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\install.log"
AGEIA PhysX v7.09.13-->MsiExec.exe /X{45235788-142C-44BE-8A4D-DDE9A84492E5}
Alice Greenfingers-->"C:\Program Files\Acer GameZone\Alice Greenfingers\Uninstall.exe" "C:\Program Files\Acer GameZone\Alice Greenfingers\install.log"
Aliens vs. Predator 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EF79591-BF16-4CF8-8FF0-D8AD968228B1}\SETUP.EXE"
ALPS Touch Pad Driver-->C:\Program Files\Apoint2K\Uninstap.exe ADDREMOVE
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assassin's Creed-->C:\Program Files\InstallShield Installation Information\{8CFA9151-6404-409A-AF22-4632D04582FD}\setup.exe -runfromtemp -l0x040c -removeonly
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
Azada-->"C:\Program Files\Acer GameZone\Azada\Uninstall.exe" "C:\Program Files\Acer GameZone\Azada\install.log"
Backspin Billiards-->"C:\Program Files\Acer GameZone\Backspin Billiards\Uninstall.exe" "C:\Program Files\Acer GameZone\Backspin Billiards\install.log"
Big Kahuna Reef-->"C:\Program Files\Acer GameZone\Big Kahuna Reef\Uninstall.exe" "C:\Program Files\Acer GameZone\Big Kahuna Reef\install.log"
BitComet 0.60-->D:\BitComet\uninst.exe
Bricks of Egypt-->"C:\Program Files\Acer GameZone\Bricks of Egypt\Uninstall.exe" "C:\Program Files\Acer GameZone\Bricks of Egypt\install.log"
Cake Mania-->"C:\Program Files\Acer GameZone\Cake Mania\Uninstall.exe" "C:\Program Files\Acer GameZone\Cake Mania\install.log"
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Chicken Invaders 3-->"C:\Program Files\Acer GameZone\Chicken Invaders 3\Uninstall.exe" "C:\Program Files\Acer GameZone\Chicken Invaders 3\install.log"
Clive Barker's Jericho-->"C:\Program Files\InstallShield Installation Information\{BE9A67F1-BDD3-4259-9F5C-2EFCE6B3A6C5}\Setup.exe" -runfromtemp -l0x040c -removeonly
Deus Ex-->D:\Jeux vidéos\Eidos\DeusEx\System\Setup.exe uninstall "Deus Ex"
Diner Dash Flo on the Go-->"C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\Uninstall.exe" "C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\install.log"
EPSON Logiciel imprimante-->C:\Windows\system32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
ESDX3800 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE
Fallout 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{974C4B12-4D02-4879-85E0-61C95CC63E9E}\setup.exe" -l0x40c -removeonly
Freenet-->D:\Freenet\bin\freenetuninstaller.exe
GTA2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}\Setup.exe" -l0x9
HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118\UIU32m.exe -U -IAcrZUn32z.inf
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Jewel Quest Solitaire-->"C:\Program Files\Acer GameZone\Jewel Quest Solitaire\Uninstall.exe" "C:\Program Files\Acer GameZone\Jewel Quest Solitaire\install.log"
Kick N Rush-->"C:\Program Files\Acer GameZone\Kick N Rush\Uninstall.exe" "C:\Program Files\Acer GameZone\Kick N Rush\install.log"
Launch Manager-->C:\Windows\UnInst32.exe LManager.UNI
Mahjong Escape Ancient China-->"C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\install.log"
Mahjongg Artifacts-->"C:\Program Files\Acer GameZone\Mahjongg Artifacts\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjongg Artifacts\install.log"
McAfee SecurityCenter-->C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}
Microsoft Games for Windows - LIVE-->MsiExec.exe /X{F112F66E-25CA-42DD-983C-6118EB38F606}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C}
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (3.5.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MpcStar 4.1-->C:\Program Files\MpcStar\uninst.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Mystery Case Files - Huntsville-->"C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\install.log"
Mystery Solitaire - Secret Island-->"C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\install.log"
NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
OpenOffice.org 3.1-->MsiExec.exe /I{B2E581DB-C4DD-432C-AC84-ED761AC056BC}
Orion-->MsiExec.exe /X{AC1ACE88-C471-494E-B5FA-0B7C21F22E4F}
PowerProducer-->"C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
QuickPar 0.9-->C:\Program Files\QuickPar\uninst.exe
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
RESIDENT EVIL 5-->MsiExec.exe /X{AC08BBA0-96B9-431A-A7D0-D8598E493775}
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Turbo Pizza-->"C:\Program Files\Acer GameZone\Turbo Pizza\Uninstall.exe" "C:\Program Files\Acer GameZone\Turbo Pizza\install.log"
Unreal II-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{626F32D6-007C-41D5-8157-9509AB1428BE}\Setup.exe" -l0x40c
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
UseNeXT-->"D:\UseNeXT\unins000.exe"
Vampire - The Masquerade Bloodlines-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{C4E2A4A7-B623-40CB-8EEA-72F577E49D56} /l1036
VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
XoftSpySE-->C:\Program Files\XoftSpySE6\uninstall.exe
Zuma Deluxe-->"C:\Program Files\Acer GameZone\Zuma Deluxe\Uninstall.exe" "C:\Program Files\Acer GameZone\Zuma Deluxe\install.log"

======Security center information======

AS: Spybot - Search and Destroy
AS: Windows Defender
AS: SUPERAntiSpyware

======System event log======

Computer Name: PC-de-ACER
Event Code: 1003
Message:
Record Number: 61143
Source Name: Microsoft-Windows-Dhcp-Client
Time Written: 20091114143346.000000-000
Event Type: Avertissement
User:

Computer Name: PC-de-ACER
Event Code: 1002
Message: Le bail de l'adresse IP 192.168.1.86 pour la carte réseau dont l'adresse réseau est 00242BD2ABDE a été refusé par le serveur DHCP 192.168.2.1 (celui-ci a envoyé un message DHCPNACK).
Record Number: 61144
Source Name: Microsoft-Windows-Dhcp-Client
Time Written: 20091114143346.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-ACER
Event Code: 1003
Message:
Record Number: 61148
Source Name: Microsoft-Windows-Dhcp-Client
Time Written: 20091114143445.000000-000
Event Type: Avertissement
User:

Computer Name: PC-de-ACER
Event Code: 1002
Message: Le bail de l'adresse IP 192.168.2.11 pour la carte réseau dont l'adresse réseau est 00242BD2ABDE a été refusé par le serveur DHCP 192.168.1.1 (celui-ci a envoyé un message DHCPNACK).
Record Number: 61149
Source Name: Microsoft-Windows-Dhcp-Client
Time Written: 20091114143445.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-ACER
Event Code: 52
Message: Le pilote a détecté que le périphérique \Device\Harddisk0\DR0 a prédit une défaillance. Faites immédiatement une sauvegarde de vos données et remplacez votre disque dur. Une panne est certainement imminente.
Record Number: 61153
Source Name: disk
Time Written: 20091114151505.733165-000
Event Type: Avertissement
User:

=====Application event log=====

Computer Name: PC-de-ACER
Event Code: 4113
Message: AntiVir a détecté dans le fichier G:\Jeux vidéos\Démos blizzard\Diablo\Spawn\diablo_s.exe un code suspect avec la désignation 'W32/Hidrag.a'!
Record Number: 16742
Source Name: Avira AntiVir
Time Written: 20091114144552.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-ACER
Event Code: 4113
Message: AntiVir a détecté dans le fichier G:\Jeux vidéos\Démos blizzard\Diablo II Shareware\D2VidTst.exe un code suspect avec la désignation 'W32/Hidrag.a'!
Record Number: 16743
Source Name: Avira AntiVir
Time Written: 20091114144558.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-ACER
Event Code: 4113
Message: AntiVir a détecté dans le fichier G:\Jeux vidéos\super nintendo\snes9xw.exe un code suspect avec la désignation 'W32/Hidrag.a'!
Record Number: 16744
Source Name: Avira AntiVir
Time Written: 20091114144610.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-ACER
Event Code: 4113
Message: AntiVir a détecté dans le fichier G:\Jeux vidéos\Ubisoft\Register\register.exe un code suspect avec la désignation 'W32/Hidrag.a'!
Record Number: 16745
Source Name: Avira AntiVir
Time Written: 20091114144622.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-ACER
Event Code: 4113
Message: AntiVir a détecté dans le fichier G:\Jeux vidéos\Jeux\Starcraft\BNUpdate.exe un code suspect avec la désignation 'W32/Hidrag.a'!
Record Number: 16746
Source Name: Avira AntiVir
Time Written: 20091114144640.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

=====Security event log=====

Computer Name: PC-de-ACER
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 12791
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091114152014.652165-000
Event Type: Échec de l'audit
User:

Computer Name: PC-de-ACER
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 12792
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091114152014.963165-000
Event Type: Échec de l'audit
User:

Computer Name: PC-de-ACER
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 12793
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20091114152015.175165-000
Event Type: Échec de l'audit
User:

Computer Name: PC-de-ACER
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut

Répondre à Nomak49

3

Destrio5, le 14 nov 2009 à 16:37:22

--> Télécharge UsbFix (de Chiquitine29 & C_XX) sur ton Bureau.

--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

--> Double-clique sur le programme UsbFix situé sur ton Bureau.

--> Choisis l'option 1 (Recherche).

--> Laisse travailler l'outil.

--> Poste le rapport UsbFix.txt.

Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

Répondre à Destrio5

4

Nomak49, le 14 nov 2009 à 17:12:37

Eh bien USBFix ne me trouve quedalle

################## | Fichiers # Dossiers infectieux |

G:\autorun.inf
G:\autorun.inf -> fichier appelé : "G:\RECYCLER\help.exe" ( Absent ! )

################## | Registre # Clés Run infectieuses |

[HKLM\software\microsoft\windows nt\currentversion\winlogon] "Taskman"

################## | Registre # Mountpoints2 |

HKCU\..\..\Explorer\MountPoints2\F
shell\AutoRun\command =F:\RECYCLER\help.exe
shell\opEN\CoMmanD =F:\RECYCLER\help.exe

HKCU\..\..\Explorer\MountPoints2\H
shell\AutoRun\command =H:\RECYCLER\help.exe
shell\opEN\CoMmanD =H:\RECYCLER\help.exe

HKCU\..\..\Explorer\MountPoints2\{096fa707-80ef-11de-9cb8-00235a5af887}
shell\AutoRun\command =RECYCLER\help.exe
shell\opEN\CoMmanD =RECYCLER\help.exe

HKCU\..\..\Explorer\MountPoints2\{5d2606df-10f3-11de-95e8-806e6f6e6963}
shell\AutoRun\command =E:\Autorun.exe

HKCU\..\..\Explorer\MountPoints2\{c0d63c6d-8258-11de-8e7d-00235a5af887}
shell\AutoRun\command =H:\RECYCLER\help.exe
shell\opEN\CoMmanD =H:\RECYCLER\help.exe

HKCU\..\..\Explorer\MountPoints2\{f215b5b0-84d9-11de-9da7-00242bd2abde}
shell\AutoRun\command =F:\autorun.exe

################## | Suspect | http://www.virustotal.com |

Répondre à Nomak49

5

Destrio5, le 14 nov 2009 à 17:14:23

Bah si.

--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

--> Double-clique sur UsbFix présent sur ton Bureau.

--> Choisis l'option 2 (Suppression).

--> Ton Bureau disparaîtra et le PC redémarrera.

--> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.

--> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.

Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

Répondre à Destrio5

6

Nomak49, le 14 nov 2009 à 19:28:54

Voilà le rapport, le virus est toujours là.... Je vais jamais arriver à me débarrasser de cette merde !!


################### | UsbFix V6.052 |

User : ACER (Administrateurs) # PC-DE-ACER
Update on 13/11/2009 by Chiquitine29, C_XX & Chimay8
Start at: 18:55:41 | 14/11/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

AMD Turion(tm) 64 X2 Mobile Technology TL-64
Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 7.0.6001.18000
Windows Firewall Status : Enabled

C:\ -> Disque fixe local # 111,69 Go (12,8 Go free) [ACER] # NTFS
D:\ -> Disque fixe local # 111,43 Go (17,81 Go free) [DATA] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque CD-ROM
G:\ -> Disque fixe local # 465,65 Go (17,32 Go free) [IOMEGA_HDD] # FAT32

############################## | Processus actifs |

C:\Windows\System32\smss.exe 532
C:\Windows\system32\csrss.exe 600
C:\Windows\system32\wininit.exe 652
C:\Windows\system32\csrss.exe 664
C:\Windows\system32\services.exe 716
C:\Windows\system32\lsass.exe 728
C:\Windows\system32\lsm.exe 736
C:\Windows\system32\winlogon.exe 828
C:\Windows\system32\svchost.exe 908
C:\Windows\system32\svchost.exe 988
C:\Windows\System32\svchost.exe 1084
C:\Windows\System32\svchost.exe 1116
C:\Windows\system32\svchost.exe 1148
C:\Windows\system32\SLsvc.exe 1224
C:\Windows\system32\LogonUI.exe 1260
C:\Windows\system32\svchost.exe 1296
C:\Windows\system32\svchost.exe 1424
C:\Windows\system32\WLANExt.exe 1596
C:\Windows\System32\spoolsv.exe 1708
C:\Program Files\Avira\AntiVir Desktop\sched.exe 1736
C:\Windows\system32\svchost.exe 1784
C:\Program Files\a-squared Anti-Malware\a2service.exe 2032
C:\Acer\ALaunch\ALaunchSvc.exe 392
C:\Program Files\Avira\AntiVir Desktop\avguard.exe 516
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe 544
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe 560
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 668
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe 1388
C:\Acer\Empowering Technology\eNet\eNet Service.exe 788
C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2064
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe 2092
C:\Windows\system32\rundll32.exe 2104
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe 2112
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe 2148
C:\Acer\Mobility Center\MobilityService.exe 2272
C:\Program Files\McAfee\MPF\MPFSrv.exe 2324
C:\Program Files\McAfee\MSK\MskSrver.exe 2360
C:\Windows\system32\svchost.exe 2496
C:\Windows\system32\svchost.exe 2584
C:\Windows\System32\svchost.exe 2612
C:\Windows\system32\SearchIndexer.exe 2636
C:\Windows\system32\DRIVERS\xaudio.exe 2780
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe 2816
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe 2848
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe 2888
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe 3048
C:\Windows\system32\wbem\wmiprvse.exe 3172
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 3260
C:\Windows\system32\wbem\wmiprvse.exe 3304
C:\Windows\system32\wbem\unsecapp.exe 3444
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe 3564
C:\Windows\system32\taskeng.exe 3996
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe 1344
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe 3804
C:\Windows\system32\Dwm.exe 2800
C:\Windows\Explorer.EXE 3344
C:\Windows\system32\runonce.exe 3404
c:\PROGRA~1\mcafee.com\agent\mcagent.exe 3356
C:\Windows\system32\taskeng.exe 2796

################## | Fichiers # Dossiers infectieux |


################## | Registre # Clés Run infectieuses |


################## | Registre # Mountpoints2 |

Supprimé ! HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\H\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{096fa707-80ef-11de-9cb8-00235a5af887}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{5d2606df-10f3-11de-95e8-806e6f6e6963}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{c0d63c6d-8258-11de-8e7d-00235a5af887}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{f215b5b0-84d9-11de-9da7-00242bd2abde}\Shell\AutoRun\Command

################## | Listing des fichiers présent |

[15/03/2009 01:03|--a------|90] C:\Arcade.log
[18/09/2006 22:43|--a------|24] C:\autoexec.bat
[20/03/2008 22:56|--a------|702884] C:\bknowsetup.log
[21/01/2008 03:34|-rahs----|333203] C:\bootmgr
[21/03/2008 06:18|-ra-s----|8192] C:\BOOTSECT.BAK
[18/09/2006 22:43|--a------|10] C:\config.sys
[?|?|?] C:\hiberfil.sys
[19/10/2009 14:16|-rahs----|0] C:\IO.SYS
[19/10/2009 14:16|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\pagefile.sys
[13/11/2009 22:35|--a------|4350] C:\resolve.log
[20/03/2008 22:46|--a------|426] C:\RHDSetup.log
[20/03/2008 22:56|--a------|86] C:\setup.log
[20/03/2008 23:37|--a------|162] C:\SoftDMA.log
[14/11/2009 19:00|--a------|4911] C:\UsbFix.txt
[10/11/2009 16:41|--a------|471739198] D:\Braquo.S01E01.FRENCH.HDTV.XviD-JMT.avi
[10/11/2009 16:53|--a------|471718706] D:\Braquo.S01E02.FRENCH.HDTV.XviD-JMT.avi
[20/10/2009 03:03|--a------|419022148] D:\Braquo.S01E03.FRENCH.HDTV.XviD-JMT- N›Way.avi
[20/10/2009 03:43|--a------|419190954] D:\Braquo.S01E04.FRENCH.HDTV.XviD-JMT- N›Way.avi
[27/10/2009 02:09|--a------|419141794] D:\Braquo.S01E05.FRENCH.HDTV.XviD-JMT.avi
[27/10/2009 02:39|--a------|418946058] D:\Braquo.S01E06.FRENCH.HDTV.XviD-JMT.avi
[11/11/2009 18:51|--a------|419103520] D:\Braquo.S01E07.FRENCH.DVDRip.XviD-JMT by N›Way.avi
[11/11/2009 19:01|--a------|419040938] D:\Braquo.S01E08.FiNAL.FRENCH.DVDRip.XviD-JMT by N›Way.avi
[12/11/2009 00:32|--a------|443731] D:\FlashForward.106.VOVF_v1.02.zip
[12/11/2009 00:33|--a------|217977] D:\FlashForward.1x07.ENFR.BT.zip
[27/10/2009 19:34|--a------|307714418] D:\FlashForward.S01E01.VOSTFR.Gillop.avi
[27/10/2009 20:42|--a------|335388674] D:\FlashForward.S01E02.VOSTFR.Gillop.avi
[28/10/2009 22:49|--a------|325863884] D:\FlashForward.S01E03.VOSTFR.Gillop.avi
[09/11/2009 02:37|--a------|326519116] D:\FlashForward.S01E04.VOSTFR.Gillop.avi
[25/10/2009 02:13|--a------|405031334] D:\FlashForward.S01E05.vostf.avi
[30/10/2009 02:05|--a------|367166188] D:\FlashForward.S01E06.hdtv.xvid-fever.avi
[03/11/2009 21:55|--a------|45093] D:\FlashForward.S01e06.hdtv.xvid-fever.srt
[07/11/2009 18:30|--a------|48279] D:\FlashForward.S01E07.HDTV.XviD-2HD.ass
[11/11/2009 23:11|--a------|367406344] D:\FlashForward.S01E07.HDTV.XviD-2HD.avi
[08/11/2009 19:04|--a------|45068] D:\FlashForward.S01E07.HDTV.XviD-2HD.srt
[20/05/2009 10:54|--a------|716992732] D:\Gomorra.2008[DVDrip]XviD[Ita].kitrinipapia.avi
[20/05/2009 10:41|--a------|85644] D:\Gomorra.2008[DVDrip]XviD[Ita].kitrinipapia.Fra.srt
[07/04/2009 19:51|--a------|860216606] D:\L'Ecole du Pouvoir EP2.avi
[26/10/2009 21:00|--a------|368582656] D:\Nip.Tuck.S06E01.HDTV.XviD-SYS.avi
[19/10/2009 08:14|--a------|50164] D:\Nip.Tuck.S06E01.HDTV.XviD-SYS.srt
[27/10/2009 16:44|--a------|366197158] D:\Supernatural.S04E06.HDTV.XviD-NoTV.avi
[27/10/2008 08:21|--a------|39662] D:\Supernatural.S04E06.HDTV.XviD-NoTV.srt
[10/11/2009 19:20|--a------|365594098] D:\Supernatural.S04E07.HDTV.XviD-NoTV.avi
[03/11/2008 12:11|--a------|41743] D:\Supernatural.S04E07.HDTV.XviD-NoTV.avi.srt
[12/11/2009 02:58|--a------|366092088] D:\Supernatural.S04E08.HDTV.XviD-NoTV.avi
[10/11/2008 11:45|--a------|41769] D:\Supernatural.S04E08.HDTV.XviD-NoTV.srt
[13/11/2009 19:46|--a------|366218276] D:\Supernatural.S04E09.HDTV.XviD-NoTV.avi
[12/11/2009 00:48|--a------|733976576] D:\WH13-101-102-MYOWIITUBE-DRAGONS.avi
[29/01/2009 22:19|---------|10219520] G:\Blindness.2008.DVDRIP-ZEKTORM.sub
[14/08/2008 12:44|--a------|839217152] G:\Southland Tales.avi
[01/05/2008 13:42|--a------|125759] G:\Southland Tales.srt
[06/01/2007 04:41|--a------|732956672] G:\The.Illusionist.DVDRip.FR_by.stitch[www.spacemen-team.net].avi
[06/07/2009 11:54|--a------|732727296] G:\The wrestler.avi
[13/11/2008 05:09|--a------|729040896] G:\Mariage chez les Bodins.avi
[27/10/2008 01:40|---------|727572480] G:\From Hell.avi
[25/12/2008 03:52|--a------|733452288] G:\Mad Max I (1979) French DVDrip xivd (condom be).avi
[05/05/2002 23:27|---------|104121] G:\From Hell.srt
[04/05/2008 18:19|--a------|734957568] G:\BLOODRAYNE.(2008).Vraie.VF.Divx6.French.DVDRip.ARLBOUFFIARD.avi
[11/08/2008 19:13|---------|995307520] G:\American Gangster.avi
[27/07/2008 14:08|--a------|728512512] G:\Chasseurs.De.Dragons.2008.TRUEFRENCH.R5.XviD.avi
[04/10/2008 01:29|--a------|735064064] G:\Dikkenek French Dvdrip Xvid-Others.avi
[16/08/2008 23:26|---------|175906] G:\American Gangster.srt
[10/06/2008 21:33|---------|733913088] G:\Appleseed.avi
[29/05/2007 03:02|--a------|711087616] G:\Louis.de.Funes.La soupe aux choux (DivX - Fr).avi
[30/06/2007 17:24|---------|729675007] G:\[XCT] Delicatessen (1991) [XviD AAC{FR COMM} ST{EN DE ES IT NL PT COMM} CHAP].mkv
[08/10/2007 00:07|---------|733620224] G:\Apocalypto.FRENCH.DVDRiP.XViD-.avi
[02/03/2008 20:15|---------|86447] G:\Basic Instinct 1992 Special Edition.srt
[11/10/2008 13:43|--a------|735203328] G:\Indiana Jones and the Kingdom of the crystal skull.avi
[12/02/2008 09:21|--a------|734828544] G:\La folle histoire de l'espace(Mel Brooks 1987)Fr.DVDRip.HQ.Par.Nuro.avi
[25/07/2007 05:53|--a------|733462528] G:\Lancelot, Le Premier Chevalier 1994 Sean Connery Et R Geere Fr Divx.avi
[08/09/2008 05:09|---------|730617856] G:\Blue Velvet.avi
[09/09/2008 00:20|---------|70979] G:\Blue Velvet.srt
[16/07/2007 08:42|---------|735619072] G:\Carnets de voyage.avi
[26/12/2008 18:47|---------|83992] G:\Citizen Kane.srt
[27/12/2008 03:22|---------|734382196] G:\CITIZEN KANE.divx
[05/04/2009 19:17|---hs----|348160] G:\msvcr71.dll
[31/08/2008 10:59|---------|864651264] G:\Basic Instinct 1992 Special Edition.avi
[29/01/2009 22:17|---------|197866] G:\Blindness.2008.DVDRIP-ZEKTORM.idx
[29/01/2009 23:10|---------|733933041] G:\Blindness.2008.DVDRIP-ZEKTORM.mp4

################## | Vaccination |

# C:\autorun.inf -> Dossier créé par UsbFix.
# D:\autorun.inf -> Dossier créé par UsbFix.
# G:\autorun.inf -> Dossier créé par UsbFix.

################## | Suspect | http://www.virustotal.com |


################## | Cracks / Keygens / Serials |

"D:\Jeux vid‚os\[PC] Alien VS Predator 2\Crack\AVP2.exe"
31/10/2001 23:31 |Size 5292032 |Crc32 39606af6 |Md5 4516d71e19b3b44732ba035382530873

"C:\Users\ACER\Downloads\Logiciels, patchs etc\Crack_No-CD.rar"
-> contain : daemon347.exe

"D:\Jeux vid‚os\[PC] Alien VS Predator 2\Crack\AVP2.rar"
-> contain : AVP2.exe

"G:\Applications\Crack_No-CD.rar"
-> contain : daemon347.exe


################## | ! Fin du rapport # UsbFix V6.052 ! |

Répondre à Nomak49

7

Destrio5, le 14 nov 2009 à 19:31:03

"le virus est toujours là...."

--> Comment ça ?

Répondre à Destrio5

8

Nomak49, le 14 nov 2009 à 19:40:28

Je reçois toujours des alertes de mon antivirus.

Répondre à Nomak49

9

Destrio5, le 14 nov 2009 à 19:41:29

McAfee ou AntiVir ?

D'ailleurs, il faut en désinstaller un.

Répondre à Destrio5

10

Nomak49, le 14 nov 2009 à 19:42:28

AntiVir qui s'avère incapable de s'en débarrasser.

Répondre à Nomak49

11

 Destrio5, le 14 nov 2009 à 19:57:09

--> Double-clique sur l'icône d'AntiVir (Parapluie) dans la barre des tâches.

--> Dans AntiVir, choisis Outils puis Configuration.

--> Coche Mode Expert et coche Rech. Rootkit au dém. de la recherche à droite dans Autres réglages puis valide.

--> Fais un scan complet, clique sur Tout réparer si AntiVir trouve quelque chose et poste le rapport.

Tutoriel sur AntiVir.

Répondre à Destrio5
Collection CommentÇaMarche.net