salut je te donne les infos j'espère que tu pourras m'aider à les déchiffrer parceque moi je n'y comprend rien
ComboScan v20070306.20 run by nathetfranck on 2007-03-24 at 06:12:07
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
24: 2007-03-22 22:09:20 UTC - RP130 - Windows Update
23: 2007-03-22 12:04:51 UTC - RP129 - Installed Adobe Reader 7.0.9
22: 2007-03-21 03:48:30 UTC - RP128 - Windows Update
21: 2007-03-18 17:01:32 UTC - RP127 - Installé Paint Shop Pro 7 Anniversary Edition
20: 2007-03-17 11:14:45 UTC - RP126 - Windows Update
-- First Restore Point --
1: 2007-02-18 00:53:26 UTC - RP101 - Configuré ProStroke Golf
Performed disk cleanup.
-- HijackThis (run as nathetfranck.exe) ----------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 06:13:29, on 2007-03-24
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16386)
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\MyWebSearch\bar\4.bin\M3SRCHMN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Users\nathetfranck\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\73Z25P4Q\comboscan[1].exe
C:\Windows\system32\SearchFilterHost.exe
C:\PROGRA~1\HIJACK~1\nathetfranck.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/ig?hl=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://fr.ca.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.ca.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\4.bin\MWSBAR.DLL
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\4.bin\MWSBAR.DLL
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\4.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: MSN Messenger 7.5.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZR
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -
http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) -
http://ak.exe.imgfarm.com/...
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) -
http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -
http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (ZPA_HRTZ Object) -
http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab55579.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) -
http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) -
http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
-- File Associations -----------------------------------------------------------
.bat - batfile - "%1" %*
.chm - chm.file - "%SystemRoot%\hh.exe" %1
.cmd - cmdfile - "%1" %*
.com - comfile - "%1" %*
.exe - exefile - "%1" %*
.hlp - hlpfile - %SystemRoot%\winhlp32.exe %1
.inf - inffile - %SystemRoot%\system32\NOTEPAD.EXE %1
.ini - inifile - %SystemRoot%\system32\NOTEPAD.EXE %1
.js - JSFile - %SystemRoot%\System32\WScript.exe "%1" %*
.lnk - lnkfile - {00021401-0000-0000-C000-000000000046}
.pif - piffile - "%1" %*
.reg - regfile - regedit.exe "%1"
.scr - scrfile - "%1" /S
.txt - txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1
.vbs - VBSFile - "%SystemRoot%\System32\WScript.exe" "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
1R eeCtrl (Symantec Eraser Control driver) - \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
3R EraserUtilRebootDrv - \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
3S HdAudAddService (Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio) - C:\Windows\System32\drivers\HdAudio.sys
1R IDSvix86 (Symantec Intrusion Prevention Driver) - \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20070308.001\IDSvix86.sys
2R int15 - \??\C:\Acer\Empowering Technology\eRecovery\int15.sys
3R IntcAzAudAddService (Service for Realtek HD Audio (WDM)) - C:\Windows\System32\drivers\RTKVHDA.sys
3R NAVENG - \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070323.033\NAVENG.SYS
3R NAVEX15 - \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070323.033\NAVEX15.SYS
3R NTIDrvr (Upper Class Filter Driver) - C:\Windows\System32\drivers\NTIDrvr.sys
3R nvlddmkm - C:\Windows\System32\drivers\nvlddmkm.sys
0R PSDFilter - C:\Windows\System32\drivers\psdfilter.sys
0R PSDNServ (PSDNSERVER) - C:\Windows\System32\drivers\PSDNServ.sys
0R psdvdisk - C:\Windows\System32\drivers\psdvdisk.sys
3R smserial - C:\Windows\System32\drivers\smserial.sys
1R SPBBCDrv - \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
3R SRTSP - C:\Windows\System32\drivers\srtsp.sys
3S SRTSPL - C:\Windows\System32\drivers\srtspl.sys
1R SRTSPX - C:\Windows\System32\drivers\srtspx.sys
3R SYMDNS - C:\Windows\System32\drivers\symdns.sys
3R SymEvent - \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
3R SYMFW - C:\Windows\System32\drivers\symfw.sys
3R SYMIDS - C:\Windows\System32\drivers\symids.sys
3R SYMNDISV - C:\Windows\System32\drivers\symndisv.sys
3R SYMREDRV - C:\Windows\System32\drivers\symredrv.sys
1R SYMTDI - C:\Windows\System32\drivers\symtdi.sys
0R UBHelper - C:\Windows\System32\drivers\UBHelper.sys
3S usbscan (Pilote de scanneur USB) - C:\Windows\System32\drivers\usbscan.sys
3R USBSTOR (Pilote de stockage de masse USB) - C:\Windows\System32\drivers\USBSTOR.SYS
3S WSVD - \??\C:\Windows\system32\drivers\WSVD.sys
3R yukonwlh (NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller) - C:\Windows\System32\drivers\yk60x86.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
2R AcerMemUsageCheckService (ePerformance Service) - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
2R ccEvtMgr (Symantec Event Manager) - "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
2R ccSetMgr (Symantec Settings Manager) - "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
2R CLTNetCnService (Symantec Lic NetConnect service) - "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon
3S comHost (COM Host) - "C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe"
2R eRecoveryService (eRecovery Service) - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
2R gusvc (Google Updater Service) - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
3S IDriverT (InstallDriver Table Manager) - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
3S ISPwdSvc (Symantec IS Password Validation) - "C:\Program Files\Norton Internet Security\isPwdSvc.exe"
2R LightScribeService (LightScribeService Direct Disc Labeling Service) - "C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
3S LiveUpdate - "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"
3S odserv (Microsoft Office Diagnostics Service) - "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
3S ose (Office Source Engine) - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
2R Planificateur LiveUpdate automatique - "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
2R RichVideo (Cyberlink RichVideo Service(CRVS)) - "C:\Program Files\CyberLink\Shared Files\RichVideo.exe"
3R Symantec Core LC - "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"
2R SymAppCore (Symantec AppCore Service) - "C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe"
2R W3SVC (Service de publication World Wide Web) - C:\Windows\system32\svchost.exe -k iissvcs
3R WAS (Service d'activation des processus Windows) - C:\Windows\system32\svchost.exe -k iissvcs
-- Scheduled Tasks -------------------------------------------------------------
2007-03-24 06:13:01 268 --a------ C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job<VRIFIE~1.JOB>
2007-03-23 07:22:02 538 --a------ C:\Windows\Tasks\Norton Internet Security - Analyse système complète - nathetfranck.job<NORTON~1.JOB>
-- Files created between 2007-02-24 and 2007-03-24 -----------------------------
-- Find3M Report ---------------------------------------------------------------
2007-03-23 15:22:27 0 d-------- C:\Program Files\MSN Games<MSNGAM~1>
2007-03-23 14:46:40 750878 --a------ C:\Windows\system32\perfh00C.dat
2007-03-23 14:46:40 139976 --a------ C:\Windows\system32\perfc00C.dat
2007-03-23 14:38:13 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-03-22 08:06:31 0 d-------- C:\Program Files\Common Files\Adobe
2007-03-18 13:02:13 0 d-------- C:\Program Files\Jasc Software Inc<JASCSO~1>
2007-03-16 09:32:26 69689 --a------ C:\Windows\UNZIP.DLL
2007-03-16 09:32:26 507904 --a------ C:\Windows\TMUPDATE.DLL
2007-03-16 09:32:25 286720 --a------ C:\Windows\PATCH.EXE
2007-03-14 09:36:05 414208 --a------ C:\Windows\system32\msscp.dll
2007-03-14 09:35:43 4153344 --a------ C:\Windows\system32\GameUXLegacyGDFs.dll
2007-03-14 09:35:42 1686016 --a------ C:\Windows\system32\gameux.dll
2007-03-12 09:55:44 0 d---s---- C:\Users\nathetfranck\AppData\Roaming\Microsoft<MICROS~1>
2007-03-11 20:45:54 0 d-------- C:\Program Files\MSN Messenger<MSNMES~1>
2007-03-10 08:49:15 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Adobe
2007-03-05 22:35:14 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Apple Computer<APPLEC~1>
2007-03-05 22:34:27 0 d-------- C:\Program Files\QuickTime<QUICKT~1>
2007-03-05 22:31:44 0 d-------- C:\Program Files\Apple Software Update<APPLES~1>
2007-03-05 13:48:07 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-03-05 13:38:57 0 d-------- C:\Program Files\Norton Internet Security<NORTON~1>
2007-03-05 13:38:49 0 d-------- C:\Program Files\Symantec
2007-02-18 21:26:38 0 d-------- C:\Program Files\Microsoft Games<MICROS~1>
2007-02-18 08:42:17 501798 --a------ C:\Users\nathetfranck\AppData\Roaming\UserTile.png
2007-02-18 08:25:07 0 d-------- C:\Program Files\Common Files\Intuit
2007-02-15 17:41:46 98304 --a------ C:\Windows\system32\CmdLineExt.dll<CMDLIN~1.DLL>
2007-02-15 09:41:43 0 d--h----- C:\Program Files\CanonBJ
2007-02-15 09:40:38 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Canon
2007-02-14 15:31:45 0 d-------- C:\Program Files\ValuSoft
2007-02-14 07:23:06 0 d-------- C:\Program Files\Windows Mail<WINDOW~1>
2007-02-13 11:51:05 0 d-------- C:\Program Files\MyWebSearch<MYWEBS~1>
2007-02-13 11:51:03 28672 --a------ C:\Windows\system32\f3PSSavr.scr
2007-02-13 11:45:17 0 d-------- C:\Program Files\FunWebProducts<FUNWEB~1>
2007-02-12 16:40:18 0 d-------- C:\Program Files\Yahoo!
2007-02-12 15:35:23 0 d-------- C:\Program Files\Reference Assemblies<REFERE~1>
2007-02-12 15:35:23 0 d-------- C:\Program Files\MSBuild
2007-02-11 15:34:51 0 d-------- C:\Users\nathetfranck\AppData\Roaming\7Wonders
2007-02-11 14:10:14 104448 --a------ C:\Windows\system32\DWWIN.EXE
2007-02-11 14:09:59 229888 --a------ C:\Windows\system32\msshsq.dll
2007-02-11 14:08:38 383488 --a------ C:\Windows\system32\ieapfltr.dll
2007-02-11 14:07:52 974336 --a------ C:\Windows\system32\crypt32.dll
2007-02-10 16:59:47 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Macromedia<MACROM~1>
2007-02-08 15:30:11 0 d-------- C:\Program Files\Registry Helper<REGIST~1>
2007-02-08 15:25:25 0 d-------- C:\Program Files\The Weather Channel FW<THEWEA~1>
2007-02-08 15:20:33 106716412 --a------ C:\2-8-2007--2-19-47-pm.reg<2-8-20~1.REG>
2007-02-08 15:19:34 2814872 --a------ C:\Windows\system32\RegistryHelperSetupFZ.exe<REGIST~1.EXE>
2007-02-08 15:19:02 0 d-------- C:\Program Files\Free Offers from Freeze.com<FREEOF~1.COM>
2007-02-08 15:08:34 1311335 --a------ C:\Windows\system32\aquarium.scr
2007-02-08 15:06:44 1715 --a------ C:\Windows\unins001.dat
2007-02-08 11:46:22 2878 --a------ C:\Windows\unins000.dat
2007-02-08 11:35:46 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Google
2007-02-08 11:34:26 0 d-------- C:\Program Files\Google
2007-02-08 09:35:13 97 --a------ C:\Windows\dun.bat
2007-02-06 07:04:15 0 d-------- C:\Program Files\Java
2007-02-06 06:59:00 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Sun
2007-02-05 15:50:57 0 --a------ C:\Windows\PowerReg.dat
2007-02-05 15:48:59 0 d-------- C:\Program Files\Ubi Soft<UBISOF~1>
2007-02-04 17:42:28 0 d-------- C:\Program Files\Common Files\CANON
2007-02-04 17:41:56 0 d-------- C:\Program Files\Canon
2007-02-03 21:54:40 0 d-------- C:\Program Files\Emoticons-plus.com<EMOTIC~1.COM>
2007-02-03 13:03:00 0 d-------- C:\Program Files\NevoSoft
2007-02-02 21:24:59 0 d-------- C:\Users\nathetfranck\AppData\Roaming\CyberLink<CYBERL~1>
2007-02-02 18:02:43 0 d-------- C:\Program Files\Mindscape<MINDSC~1>
2007-02-02 18:02:30 0 -rahs---- C:\MSDOS.SYS
2007-02-02 18:02:30 0 -rahs---- C:\IO.SYS
2007-02-02 08:11:42 0 d-------- C:\Users\nathetfranck\AppData\Roaming\AdobeUM
2007-02-01 21:55:33 0 d-------- C:\Users\nathetfranck\AppData\Roaming\ArcSoft
2007-02-01 20:56:01 0 d-------- C:\Program Files\Microsoft Works<MICROS~3>
2007-02-01 20:55:34 0 d-------- C:\Program Files\Microsoft.NET<MICROS~1.NET>
2007-02-01 18:23:03 0 d-------- C:\Program Files\LimeWire
2007-02-01 18:21:44 0 d-------- C:\Program Files\Common Files\Java
2007-02-01 17:57:58 0 d-------- C:\Program Files\Windows Live Toolbar<WI81E8~1>
2007-02-01 17:26:05 0 d-------- C:\Users\nathetfranck\AppData\Roaming\ScanSoft
2007-02-01 17:25:53 0 d-------- C:\Program Files\Common Files\ScanSoft Shared<SCANSO~1>
2007-02-01 17:25:11 0 d-------- C:\Program Files\ScanSoft
2007-02-01 17:23:46 0 d-------- C:\Program Files\ArcSoft
2007-02-01 17:02:13 0 d-------- C:\Users\nathetfranck\AppData\Roaming\InterTrust<INTERT~1>
2007-02-01 16:11:22 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Acer
2007-02-01 16:11:17 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Leadertech<LEADER~1>
2007-02-01 16:06:58 0 d-------- C:\Program Files\Acer Inc<ACERIN~1>
2007-02-01 16:06:55 0 d-------- C:\Program Files\Common Files\InstallShield<INSTAL~1>
2007-02-01 16:04:02 0 d-------- C:\Program Files\Acer Assist<ACERAS~1>
2007-02-01 16:02:57 0 d-------- C:\Users\nathetfranck\AppData\Roaming\Identities<IDENTI~1>
2007-02-01 15:58:14 0 d-------- C:\Program Files\Windows NT<WINDOW~2>
2007-02-01 15:58:14 0 d--hs---- C:\Program Files\Fichiers communs<FICHIE~1>
2007-01-25 11:04:52 1680 --a------ C:\Windows\rmt.dat
2007-01-07 14:51:00 1712201 --a------ C:\Windows\system32\InetClnt.dll
-- Registry Dump ---------------------------------------------------------------
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
"????r"=hex(42a000):
"ISUSPM Startup"="\"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~1\\bar\\4.bin\\mwsoemon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe AcRdB7_0_9"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Windows Defender"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,\
6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,53,41,53,43,75,69,2e,65,78,\
65,20,2d,68,69,64,65,00
"RtHDVCpl"="RtHDVCpl.exe"
"Acer Tour"=""
"eDataSecurity Loader"="C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSloader.exe"
"eRecoveryService"=""
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"Acer Assist Launcher"="C:\\Program Files\\Acer Assist\\launcher.exe"
"My Web Search Bar Search Scope Monitor"="\"C:\\PROGRA~1\\MYWEBS~1\\bar\\4.bin\\m3SrchMn.exe\" /m=0"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~1\\bar\\4.bin\\mwsoemon.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"scforceoption"=dword:00000000
"FilterAdministratorToken"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI\Clipboard]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"=dword:00000002
"DontDisplayLogonHoursWarnings"=dword:00000001
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="credssp.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AppInfo
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\KeyIso
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\NTDS
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\ProfSvc
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sacsvr
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SWPRV
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\TabletInputService
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\TBS
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\TrustedInstaller
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgr.sys
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgrx.sys
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ nsi\0lltdsvc\0SSDPSRV\0upnphost\0SCardSvr\0w32time\0EventSystem\0RemoteRegistry\0WinHttpAutoProxySvc\0lanmanworkstation\0TBS\0SLUINotify\0THREADORDER\0fdrespub\0netprofm\0fdphost\0wcncsvc\0QWAVE\0Mcx2Svc\0WebClient\0\0
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv\0UxSms\0WdiSystemHost\0Netman\0trkwks\0AudioEndpointBuilder\0WUDFSvc\0irmon\0sysmain\0IPBusEnum\0dot3svc\0PcaSvc\0EMDMgmt\0TabletInputService\0wlansvc\0WPDBusEnum\0\0
NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent\0\0
LocalServiceNoNetwork REG_MULTI_SZ PLA\0DPS\0BFE\0mpssvc\0ehstart\0\0
NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0KtmRm\0DNSCache\0NapAgent\0nlasvc\0WinRM\0WECSVC\0Tapisrv\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WerSvcGroup REG_MULTI_SZ wersvc\0\0
swprv REG_MULTI_SZ swprv\0\0
LocalServiceNetworkRestricted REG_MULTI_SZ DHCP\0eventlog\0AudioSrv\0LmHosts\0wscsvc\0p2pimsvc\0PNRPSvc\0p2psvc\0WPCSvc\0PnrpAutoReg\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
regsvc REG_MULTI_SZ RemoteRegistry\0\0
wcssvc REG_MULTI_SZ WcsPlugInService\0\0
DcomLaunch REG_MULTI_SZ PlugPlay\0DcomLaunch\0\0
wdisvc REG_MULTI_SZ WdiServiceHost\0\0
sdrsvc REG_MULTI_SZ sdrsvc\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
secsvcs REG_MULTI_SZ WinDefend\0\0
iissvcs REG_MULTI_SZ w3svc\0was\0\0
HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
AeLookupSvc
wercplsupport
CertPropSvc
SCPolicySvc
gpsvc
IKEEXT
LogonHours
PCAudit
iphlpsvc
AppInfo
msiscsi
MMCSS
ProfSvc
EapHost
SessionEnv
hkmsvc
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST
-- End of ComboScan: finished at 2007-03-24 at 06:14:09 ------------------------
merci
si tu as d'autre solution, il me ferait plaisir de les essayer