Rapport Killbox
Pocket Killbox version 2.0.0.648
Running on Windows XP as Eric(Administrator)
was started @ samedi, juin 09, 2007, 11:43 AM
Killbox Closed(Exit) @ 11:44:10 AM
__________________________________________________
Pocket Killbox version 2.0.0.648
Running on Windows XP as Eric(Administrator)
was started @ samedi, juin 09, 2007, 11:44 AM
# 1 [Delete on Reboot]
Path = c:\windows\system32\orkvienh.dll",realset
I Rebooted @ 11:45:39 AM
Killbox Closed(Exit) @ 11:45:41 AM
__________________________________________________
Pocket Killbox version 2.0.0.648
Running on Windows XP as Eric(Administrator)
was started @ samedi, juin 09, 2007, 11:51 AM
Killbox Closed(Exit) @ 11:56:15 AM
__________________________________________________
Pocket Killbox version 2.0.0.648
Running on Windows XP as Eric(Administrator)
was started @ samedi, juin 09, 2007, 1:01 PM
# 1 [Delete on Reboot]
Path = c:\windows\system32\tndvqmkv.dll",realset
PendingFileRenameOperations Registry Data has been Removed by External Process! @ 1:04:43 PM
Killbox Closed(Exit) @ 1:04:47 PM
__________________________________________________
Pocket Killbox version 2.0.0.648
Running on Windows XP as Eric(Administrator)
was started @ samedi, juin 09, 2007, 1:09 PM
Rapport VGB
[06/09/2007, 13:11:22] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Eric\Bureau\VirtumundoBeGone.exe" )
[06/09/2007, 13:11:30] - Detected System Information:
[06/09/2007, 13:11:30] - Windows Version: 5.1.2600, Service Pack 2
[06/09/2007, 13:11:30] - Current Username: Eric (Admin)
[06/09/2007, 13:11:30] - Windows is in NORMAL mode.
[06/09/2007, 13:11:30] - Searching for Browser Helper Objects:
[06/09/2007, 13:11:30] - BHO 1: {27A508E5-7A04-4C3C-9858-46D3E6282CEE} ()
[06/09/2007, 13:11:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:30] - Checking for HKLM\...\Winlogon\Notify\jkhhe
[06/09/2007, 13:11:30] - Found: HKLM\...\Winlogon\Notify\jkhhe - This is probably Virtumundo.
[06/09/2007, 13:11:30] - Assigning {27A508E5-7A04-4C3C-9858-46D3E6282CEE} MSEvents Object
[06/09/2007, 13:11:30] - BHO list has been changed! Starting over...
[06/09/2007, 13:11:30] - BHO 1: {27A508E5-7A04-4C3C-9858-46D3E6282CEE} (MSEvents Object)
[06/09/2007, 13:11:30] - ALERT: Found MSEvents Object!
[06/09/2007, 13:11:30] - BHO 2: {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} (Flashget Catch Url Class)
[06/09/2007, 13:11:30] - BHO 3: {5F53B0C0-665C-4F79-A3FA-192AFB3009E7} ()
[06/09/2007, 13:11:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:30] - Checking for HKLM\...\Winlogon\Notify\jkkji
[06/09/2007, 13:11:30] - Key not found: HKLM\...\Winlogon\Notify\jkkji, continuing.
[06/09/2007, 13:11:30] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/09/2007, 13:11:30] - BHO 5: {8A61098D-612B-4EF2-943D-64E920684061} ()
[06/09/2007, 13:11:30] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:30] - Checking for HKLM\...\Winlogon\Notify\xxyyvsr
[06/09/2007, 13:11:30] - Key not found: HKLM\...\Winlogon\Notify\xxyyvsr, continuing.
[06/09/2007, 13:11:31] - BHO 6: {92A444D2-F945-4dd9-89A1-896A6C2D8D22} ()
[06/09/2007, 13:11:31] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:31] - Checking for HKLM\...\Winlogon\Notify\airoiuqw
[06/09/2007, 13:11:31] - Key not found: HKLM\...\Winlogon\Notify\airoiuqw, continuing.
[06/09/2007, 13:11:31] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/09/2007, 13:11:31] - BHO 8: {E12BFF69-38A7-406e-A8EF-2738107A7831} ()
[06/09/2007, 13:11:31] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:31] - Checking for HKLM\...\Winlogon\Notify\bemafpru
[06/09/2007, 13:11:31] - Key not found: HKLM\...\Winlogon\Notify\bemafpru, continuing.
[06/09/2007, 13:11:31] - BHO 9: {F156768E-81EF-470C-9057-481BA8380DBA} (gFlash Class)
[06/09/2007, 13:11:31] - Finished Searching Browser Helper Objects
[06/09/2007, 13:11:31] - *** Detected MSEvents Object
[06/09/2007, 13:11:31] - Trying to remove MSEvents Object...
[06/09/2007, 13:11:32] - Terminating Process: IEXPLORE.EXE
[06/09/2007, 13:11:32] - Terminating Process: RUNDLL32.EXE
[06/09/2007, 13:11:32] - Disabling Automatic Shell Restart
[06/09/2007, 13:11:32] - Terminating Process: EXPLORER.EXE
[06/09/2007, 13:11:33] - Suspending the NT Session Manager System Service
[06/09/2007, 13:11:33] - Terminating Windows NT Logon/Logoff Manager
[06/09/2007, 13:11:33] - Re-enabling Automatic Shell Restart
[06/09/2007, 13:11:33] - File to disable: C:\WINDOWS\system32\jkhhe.dll
[06/09/2007, 13:11:33] - Renaming C:\WINDOWS\system32\jkhhe.dll -> C:\WINDOWS\system32\jkhhe.dll.vir
[06/09/2007, 13:11:33] - ! File rename was unsucessful.
[06/09/2007, 13:11:33] - Attempting to Deny Access to C:\WINDOWS\system32\jkhhe.dll
[06/09/2007, 13:11:34] - *** IMPORTANT: Delete/Rename/Move on reboot (like Killbox) MAY NOT work.
[06/09/2007, 13:11:34] - ERROR: Le mappage entre les noms de compte et les ID de sécurité n'a pas été effectué.
[06/09/2007, 13:11:34] - *** IMPORTANT: The file is disabled and will need to be deleted by the user.
[06/09/2007, 13:11:34] - Removing HKLM\...\Browser Helper Objects\{27A508E5-7A04-4C3C-9858-46D3E6282CEE}
[06/09/2007, 13:11:34] - Removing HKCR\CLSID\{27A508E5-7A04-4C3C-9858-46D3E6282CEE}
[06/09/2007, 13:11:34] - Adding Kill Bit for ActiveX for GUID: {27A508E5-7A04-4C3C-9858-46D3E6282CEE}
[06/09/2007, 13:11:34] - Deleting ATLEvents/MSEvents Registry entries
[06/09/2007, 13:11:34] - Removing HKLM\...\Winlogon\Notify\jkhhe
[06/09/2007, 13:11:34] - Searching for Browser Helper Objects:
[06/09/2007, 13:11:34] - BHO 1: {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} (Flashget Catch Url Class)
[06/09/2007, 13:11:34] - BHO 2: {5F53B0C0-665C-4F79-A3FA-192AFB3009E7} ()
[06/09/2007, 13:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:34] - Checking for HKLM\...\Winlogon\Notify\jkkji
[06/09/2007, 13:11:34] - Key not found: HKLM\...\Winlogon\Notify\jkkji, continuing.
[06/09/2007, 13:11:34] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/09/2007, 13:11:34] - BHO 4: {8A61098D-612B-4EF2-943D-64E920684061} ()
[06/09/2007, 13:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:34] - Checking for HKLM\...\Winlogon\Notify\xxyyvsr
[06/09/2007, 13:11:34] - Key not found: HKLM\...\Winlogon\Notify\xxyyvsr, continuing.
[06/09/2007, 13:11:34] - BHO 5: {92A444D2-F945-4dd9-89A1-896A6C2D8D22} ()
[06/09/2007, 13:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:34] - Checking for HKLM\...\Winlogon\Notify\airoiuqw
[06/09/2007, 13:11:34] - Key not found: HKLM\...\Winlogon\Notify\airoiuqw, continuing.
[06/09/2007, 13:11:34] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/09/2007, 13:11:34] - BHO 7: {E12BFF69-38A7-406e-A8EF-2738107A7831} ()
[06/09/2007, 13:11:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:34] - Checking for HKLM\...\Winlogon\Notify\bemafpru
[06/09/2007, 13:11:35] - Key not found: HKLM\...\Winlogon\Notify\bemafpru, continuing.
[06/09/2007, 13:11:35] - BHO 8: {E12BFF69-38A7-406e-A8EF-2738107A7831} ()
[06/09/2007, 13:11:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2007, 13:11:35] - Checking for HKLM\...\Winlogon\Notify\bemafpru
[06/09/2007, 13:11:35] - Key not found: HKLM\...\Winlogon\Notify\bemafpru, continuing.
[06/09/2007, 13:11:35] - BHO 9: {F156768E-81EF-470C-9057-481BA8380DBA} (gFlash Class)
[06/09/2007, 13:11:35] - Finished Searching Browser Helper Objects
[06/09/2007, 13:11:35] - Finishing up...
[06/09/2007, 13:11:35] - A restart is needed.
[06/09/2007, 13:11:35] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[06/09/2007, 13:11:45] - Attempting to Restart via STOP error (Blue Screen!)
Rapport Hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 13:17:10, on 09/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 82.231.144.169 apogee.lineage2.com
O1 - Hosts: 91.121.8.140 L2authd.lineage2.com
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\tndvqmkv.dll",realset
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLABR11\webserver\bin\matlabserver.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Report SDfix
SDFix: Version 1.86
Run by Eric - 09/06/2007 - 13:49:23,43
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing Security Center Service
Restoring Missing SharedAccess Service
Rebooting...
Service xpdx - Deleted after Reboot
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\Temp\win31.tmp.exe - Deleted
C:\WINDOWS\Temp\win8A.tmp.exe - Deleted
C:\WINDOWS\Temp\win8F.tmp.exe - Deleted
C:\WINDOWS\Temp\win31.tmp.exe - Deleted
C:\WINDOWS\Temp\win8A.tmp.exe - Deleted
C:\WINDOWS\Temp\win8F.tmp.exe - Deleted
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00001.dll - Deleted
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00002.dll - Deleted
C:\WINDOWS\Temp\$_2341233.TMP - Deleted
C:\WINDOWS\Temp\$_2341234.TMP - Deleted
C:\WINDOWS\Temp\$b17a2e8.tmp - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
C:\WINDOWS\system32\xpdx.sys - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
C:\DOCUME~1\Eric\LOCALS~1\Temp\win*.tmp - Deleted
Removing Temp Files...
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Checking if ADS is attached to ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%ProgramFiles%\\AOL 9.0\\aol.exe"="%ProgramFiles%\\AOL 9.0\\aol.exe:*:Enabled:AOL"
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:PANDORA"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\APPS\\Inventime\\my.exe"="C:\\APPS\\Inventime\\my.exe:*:Enabled:INVENTIME"
"C:\\Program Files\\Starcraft\\starcraft.exe"="C:\\Program Files\\Starcraft\\starcraft.exe:*:Enabled:Starcraft - Brood War"
"C:\\Program Files\\Kazaa\\kazaa.exe"="C:\\Program Files\\Kazaa\\kazaa.exe:*:Enabled:Kazaa Media Desktop"
"C:\\APPS\\skype\\phone\\Skype.exe"="C:\\APPS\\skype\\phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_NO_SSE.exe"="C:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_NO_SSE.exe:*:Enabled:Earth 2160"
"C:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_SSE.exe"="C:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_SSE.exe:*:Enabled:Earth 2160"
"C:\\Program Files\\Cyanide\\Pro Cycling Manager\\Cym2005.exe"="C:\\Program Files\\Cyanide\\Pro Cycling Manager\\Cym2005.exe:*:Enabled:Pro Cycling Manager"
"C:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe"="C:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe:*:Enabled:GameCenter"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\kaiba62@hotmail.com\\counter-strike\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\kaiba62@hotmail.com\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Phantasy Star Online\\Pso.exe"="C:\\Program Files\\Phantasy Star Online\\Pso.exe:*:Enabled:Pso"
"C:\\Program Files\\Sports Interactive\\Football Manager 2006\\fm.exe"="C:\\Program Files\\Sports Interactive\\Football Manager 2006\\fm.exe:*:Enabled:Football Manager 2006"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\kaiba62@hotmail.com\\day of defeat\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\kaiba62@hotmail.com\\day of defeat\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\hl2.exe"="D:\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\HL2\\hl2.exe"="C:\\Program Files\\HL2\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"="C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe:*:Enabled:ET"
"C:\\Program Files\\Shareaza\\Shareaza.exe"="C:\\Program Files\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza"
"C:\\Program Files\\Xolox\\XoloxEXE.exe"="C:\\Program Files\\Xolox\\XoloxEXE.exe:*:Enabled:Xolox"
"C:\\Program Files\\Xolox\\mldonkey\\mlnet.exe"="C:\\Program Files\\Xolox\\mldonkey\\mlnet.exe:*:Enabled:MLdonkey - multiuser P2P daemon"
"C:\\Documents and Settings\\Eric\\Local Settings\\Temp\\powerfootball\\PowerFootball-D3D9.exe"="C:\\Documents and Settings\\Eric\\Local Settings\\Temp\\powerfootball\\PowerFootball-D3D9.exe:*:Enabled:PowerFootball-D3D9"
"C:\\Documents and Settings\\Eric\\Local Settings\\Temp\\powerfootball\\PowerFootball-OpenGL.exe"="C:\\Documents and Settings\\Eric\\Local Settings\\Temp\\powerfootball\\PowerFootball-OpenGL.exe:*:Enabled:PowerFootball-OpenGL"
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.EXE"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.EXE:*:Enabled:Age of Empires II"
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"C:\\Program Files\\Sports Interactive\\Football Manager 2007\\fm.exe"="C:\\Program Files\\Sports Interactive\\Football Manager 2007\\fm.exe:*:Enabled:Football Manager 2007"
"C:\\Program Files\\Lineage II\\Lineage II Apog‚e.exe"="C:\\Program Files\\Lineage II\\Lineage II Apog‚e.exe:*:Enabled:Lineage II Apog‚e"
"C:\\Program Files\\Lineage II\\system\\l2.exe"="C:\\Program Files\\Lineage II\\system\\l2.exe:*:Enabled:l2"
"C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe"="C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe:*:Enabled:P2P Networking"
"C:\\Program Files\\UT2004\\System\\UT2004.exe"="C:\\Program Files\\UT2004\\System\\UT2004.exe:*:Enabled:UT2004"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\\Documents and Settings\\Eric\\Application Data\\SopCast\\adv\\SopAdver.exe"="C:\\Documents and Settings\\Eric\\Application Data\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\F-IRC\\f-irc.exe"="C:\\Program Files\\F-IRC\\f-irc.exe:*:Enabled:Client IRC"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\EA SPORTS\\NBA LIVE 07\\nbalive07.exe"="C:\\Program Files\\EA SPORTS\\NBA LIVE 07\\nbalive07.exe:*:Enabled:NBA LIVE 07"
"C:\\DOCUME~1\\Eric\\LOCALS~1\\Temp\\win8.tmp.exe"="C:\\DOCUME~1\\Eric\\LOCALS~1\\Temp\\win8.tmp.exe:*:Enabled:win8.tmp"
"C:\\WINDOWS\\TEMP\\win17.tmp.exe"="C:\\WINDOWS\\TEMP\\win17.tmp.exe:*:Enabled:win17.tmp"
"C:\\WINDOWS\\TEMP\\win83.tmp.exe"="C:\\WINDOWS\\TEMP\\win83.tmp.exe:*:Enabled:win83.tmp"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Listing Files with Hidden Attributes:
C:\Program Files\FlashGet\Torrent\Virtua Tennis 3 [English][PCDVD][WwW.GamesTorrents.CoM].torrent.bits
C:\Program Files\FlashGet\Torrent\Virtua Tennis 3 [English][PCDVD][WwW.GamesTorrents.CoM].torrent.filelist
C:\Program Files\FlashGet\Torrent\Virtua Tennis 3 [English][PCDVD][WwW.GamesTorrents.CoM].torrent.seeds
C:\Program Files\FlashGet\Torrent\Virtua Tennis 3 [English][PCDVD][WwW.GamesTorrents.CoM].torrent.~tmp
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\AS_Skins\boutons\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\AS_Skins\fond\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\AS_Skins\Form\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\AS_Skins\Form\Bg\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\AS_Skins\Form\Bouton\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\BG\Actuel\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\BG\Default\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\BG\RS\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\BG\Temp\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\BG\Temp2\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\radial.cdb
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Bleach\1\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Bleach\2\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Bleach\3\dbx-sweety-draws\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Bleach\4\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Bleach\5\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Bleach\6\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\DBZ\C18 et le ruban rouge\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\DBZ\Entrainement sp‚cial\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\DBZ\La dette\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\DBZ\Le jour d avant\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Slurt Girl\1\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike\Addons\amxmodx\configs\Slurt Girl\3\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\cstrike_french\models\player\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\overviews\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_About\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_Exit\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_Exit_2\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_Main_Opt\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_Minimize\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_misc_partie_droite\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_misc_partie_gauche\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Bouton_radio\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Controls\Cases … cocher\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Form\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Form\Bg\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Form\Bouton\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\Default\Form1\Thumbs.db
C:\Program Files\Valve\Steam\SteamApps\kaiba62@hotmail.com\counter-strike\RS_Skins\FormAuthorInfos\!! -- PRIVATE -- !!\Thumbs.db
C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll
C:\WINDOWS\system32\jkhhe.dll
C:\Program Files\AOL 9.0\aolphx.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\AOL 9.0\RBM.exe
C:\Program Files\Fichiers communs\Yazzle1162OinUninstaller.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
Listing User Accounts:
comptes d'utilisateurs de \\PORTABLE
Administrateur ASPNET Eric
HelpAssistant Invit‚ SUPPORT_388945a0
La commande s'est termin‚e correctement.
Finished
Rapport Hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 14:23:53, on 09/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Downloads\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\tndvqmkv.dll",realset
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLABR11\webserver\bin\matlabserver.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Voila, alors apparement les pubs ont disparues, ainsi que le bug qui me coupé IE. De plus, l'ordinateur semble avoir retrouvé de sa rapidité.
Merci encore une fois pour le travail ainsi que pour la rapidité.