Bonsoir,
Ci-après le contenu de main.txt :
Deckard's System Scanner v20071014.68
Run by papa on 2008-04-14 00:38:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2008-04-13 22:38:09 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-04-13 15:12:41 UTC - RP1 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
[color=red]Total Physical Memory: 511 MiB (512 MiB recommended)./color
-- HijackThis (run as papa.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:39:40, on 14/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Documents and Settings\papa.VAIOPAPA\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\papa.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [VAIO Update 3] "C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKCU\..\Run: [road draw] C:\DOCUME~1\PAPA~1.VAI\APPLIC~1\FORDER~1\DVD OPTION START.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Transfert par Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5D14BF74-84BB-4BB7-B9B7-BD25DA67C662}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7E1DC21-964E-4821-A05B-50322B584769}: NameServer = 212.27.53.252,212.27.54.252
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - D:\Program Files\Ares\chatServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
End of file - 9114 bytes
-- File Associations -----------------------------------------------------------
[COLOR=red].js - JSFile - DefaultIcon - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
R2 s24trans (Transport RLAN) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
R3 catchme - c:\docume~1\papa~1.vai\locals~1\temp\catchme.sys (file missing)
S3 PCANDIS5 (PCANDIS5 Protocol Driver) - d:\dg834g~1\pcandis5.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 McAfeeFramework (McAfee Framework Service) - c:\program files\network associates\common framework\frameworkservice.exe /servicestart <Not Verified; Network Associates, Inc.; McAfee Common Framework>
R2 McTaskManager (Network Associates Task Manager) - "c:\program files\network associates\virusscan\vstskmgr.exe" <Not Verified; Network Associates, Inc.; VirusScan Enterprise>
R2 RegSrvc - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; RegSrvc Module>
S3 AresChatServer (Ares Chatroom server) - d:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) PRO/Wireless 2200BG Network Connection
Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27538086&REV_05\4&2FA23535&0&20F0
Manufacturer: Intel(R) Corporation
Name: Intel(R) PRO/Wireless 2200BG Network Connection
PNP Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27538086&REV_05\4&2FA23535&0&20F0
Service: w29n51
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) PRO/100 VE Network Connection
Device ID: PCI\VEN_8086&DEV_1068&SUBSYS_81D0104D&REV_03\4&2FA23535&0&40F0
Manufacturer: Intel
Name: Intel(R) PRO/100 VE Network Connection
PNP Device ID: PCI\VEN_8086&DEV_1068&SUBSYS_81D0104D&REV_03\4&2FA23535&0&40F0
Service: E100B
-- Scheduled Tasks -------------------------------------------------------------
2008-04-14 00:00:00 266 --ah----- C:\WINDOWS\Tasks\AB695E05918ED581.job
-- Files created between 2008-03-14 and 2008-04-14 -----------------------------
2008-04-14 00:32:15 0 d-------- C:\Program Files\Trend Micro
2008-04-14 00:07:39 0 d-------- C:\MSNFix
2008-04-12 14:21:40 0 d--h----- C:\Documents and Settings\Default User.WINSAVE\Voisinage réseau
2008-04-12 14:21:40 0 d--h----- C:\Documents and Settings\Default User.WINSAVE\Voisinage d'impression
2008-04-12 14:21:40 0 dr-h----- C:\Documents and Settings\Default User.WINSAVE\SendTo
2008-04-12 14:21:40 0 d--h----- C:\Documents and Settings\Default User.WINSAVE\Recent
2008-04-12 14:21:40 0 d--h----- C:\Documents and Settings\Default User.WINSAVE\Modèles
2008-04-12 14:21:40 0 d-------- C:\Documents and Settings\Default User.WINSAVE\Mes documents
2008-04-12 14:21:40 0 dr------- C:\Documents and Settings\Default User.WINSAVE\Menu Démarrer
2008-04-12 14:21:40 0 dr-h----- C:\Documents and Settings\Default User.WINSAVE\Local Settings
2008-04-12 14:21:40 0 d-------- C:\Documents and Settings\Default User.WINSAVE\Favoris
2008-04-12 14:21:40 0 d---s---- C:\Documents and Settings\Default User.WINSAVE\Cookies
2008-04-12 14:21:40 0 d-------- C:\Documents and Settings\Default User.WINSAVE\Bureau
2008-04-12 14:21:40 0 d--h----- C:\Documents and Settings\All Users.WINSAVE\Modèles
2008-04-12 14:21:40 0 dr------- C:\Documents and Settings\All Users.WINSAVE\Menu Démarrer
2008-04-12 14:21:40 0 d-------- C:\Documents and Settings\All Users.WINSAVE\Favoris
2008-04-12 14:21:40 0 dr------- C:\Documents and Settings\All Users.WINSAVE\Documents
2008-04-12 14:21:40 0 d-------- C:\Documents and Settings\All Users.WINSAVE\Bureau
2008-04-12 14:21:19 0 dr-h----- C:\Documents and Settings\Default User.WINSAVE\Application Data
2008-04-12 14:21:19 0 d---s---- C:\Documents and Settings\Default User.WINSAVE\Application Data\Microsoft
2008-04-12 14:21:18 0 dr-h----- C:\Documents and Settings\All Users.WINSAVE\Application Data
2008-04-12 14:21:18 0 d---s---- C:\Documents and Settings\All Users.WINSAVE\Application Data\Microsoft
2008-04-12 14:12:21 0 d-------- C:\WINSAVE
2008-04-12 12:46:05 0 d-------- C:\Documents and Settings\papa.PORTABLE\Application Data\Identities
2008-04-12 12:45:52 0 d--h----- C:\Documents and Settings\papa.PORTABLE\Voisinage réseau
2008-04-12 12:45:52 0 d--h----- C:\Documents and Settings\papa.PORTABLE\Voisinage d'impression
2008-04-12 12:45:52 0 dr-h----- C:\Documents and Settings\papa.PORTABLE\SendTo
2008-04-12 12:45:52 0 dr-h----- C:\Documents and Settings\papa.PORTABLE\Recent
2008-04-12 12:45:52 786432 --ah----- C:\Documents and Settings\papa.PORTABLE\NTUSER.DAT
2008-04-12 12:45:52 0 d--h----- C:\Documents and Settings\papa.PORTABLE\Modèles
2008-04-12 12:45:52 0 dr------- C:\Documents and Settings\papa.PORTABLE\Mes documents
2008-04-12 12:45:52 0 dr------- C:\Documents and Settings\papa.PORTABLE\Menu Démarrer
2008-04-12 12:45:52 0 d--h----- C:\Documents and Settings\papa.PORTABLE\Local Settings
2008-04-12 12:45:52 0 dr------- C:\Documents and Settings\papa.PORTABLE\Favoris
2008-04-12 12:45:52 0 d---s---- C:\Documents and Settings\papa.PORTABLE\Cookies
2008-04-12 12:45:52 0 d-------- C:\Documents and Settings\papa.PORTABLE\Bureau
2008-04-12 12:45:52 0 dr-h----- C:\Documents and Settings\papa.PORTABLE\Application Data
2008-04-12 12:45:52 0 d---s---- C:\Documents and Settings\papa.PORTABLE\Application Data\Microsoft
2008-04-12 12:44:38 229376 --ah----- C:\Documents and Settings\LocalService.AUTORITE NT.000\NTUSER.DAT
2008-04-12 12:44:38 0 d--h----- C:\Documents and Settings\LocalService.AUTORITE NT.000\Local Settings
2008-04-12 12:44:38 0 d---s---- C:\Documents and Settings\LocalService.AUTORITE NT.000\Cookies
2008-04-12 12:44:38 0 d-------- C:\Documents and Settings\LocalService.AUTORITE NT.000\Application Data
2008-04-12 12:44:38 0 d---s---- C:\Documents and Settings\LocalService.AUTORITE NT.000\Application Data\Microsoft
2008-04-12 12:44:09 229376 --ah----- C:\Documents and Settings\NetworkService.AUTORITE NT.000\NTUSER.DAT
2008-04-12 12:44:09 0 d--h----- C:\Documents and Settings\NetworkService.AUTORITE NT.000\Local Settings
2008-04-12 12:44:09 0 d---s---- C:\Documents and Settings\NetworkService.AUTORITE NT.000\Cookies
2008-04-12 12:44:09 0 d-------- C:\Documents and Settings\NetworkService.AUTORITE NT.000\Application Data
2008-04-12 12:44:09 0 d---s---- C:\Documents and Settings\NetworkService.AUTORITE NT.000\Application Data\Microsoft
2008-04-12 12:38:49 229376 ---h----- C:\Documents and Settings\Default User.WINSAVE\NTUSER.DAT
2008-04-12 12:37:12 0 d--hs---- C:\Documents and Settings\All Users.WINSAVE\DRM
2008-04-12 10:10:55 0 d-------- C:\WINDOWS\pss
2008-04-12 10:00:29 4096 --a------ C:\WINDOWS\system32\nkyknn.exe
2008-04-12 09:58:35 0 dr-h----- C:\Documents and Settings\papa.VAIOPAPA\Recent
2008-04-12 09:09:19 0 d-------- C:\Program Files\CCleaner
2008-04-11 16:32:39 0 d--h----- C:\Documents and Settings\Administrateur\Local Settings
2008-04-11 16:32:39 0 d-------- C:\Documents and Settings\Administrateur\Favoris
2008-04-11 16:32:39 0 d--hs---- C:\Documents and Settings\Administrateur\Cookies
2008-04-11 16:32:39 0 d-------- C:\Documents and Settings\Administrateur\Bureau
2008-04-11 16:32:39 0 dr-h----- C:\Documents and Settings\Administrateur\Application Data
2008-04-11 16:32:39 0 d---s---- C:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-04-11 16:32:38 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-04-11 16:32:38 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-04-11 16:32:38 0 dr-h----- C:\Documents and Settings\Administrateur\SendTo
2008-04-11 16:32:38 0 d--h----- C:\Documents and Settings\Administrateur\Recent
2008-04-11 16:32:38 524288 --ah----- C:\Documents and Settings\Administrateur\NTUSER.DAT
2008-04-11 16:32:38 0 d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-04-11 16:32:38 0 d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-04-11 16:32:38 0 dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-04-02 16:30:55 64156 -----n--- C:\WINDOWS\system32\%%%%%.exe
-- Find3M Report ---------------------------------------------------------------
2008-04-13 20:57:25 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-04-12 12:33:44 0 d-------- C:\Program Files\Messenger
2008-04-12 09:28:45 465130 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-04-12 09:28:45 73458 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-04-07 22:53:25 0 d-------- C:\Program Files\Messenger Plus! Live
2008-04-07 22:53:24 0 d-------- C:\Program Files\MSN Messenger
2008-02-22 19:20:14 0 d-------- C:\Documents and Settings\papa.VAIOPAPA\Application Data\Adobe
2008-02-21 16:01:28 72192 --a------ C:\WINDOWS\system32\tasklist.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-02-20 08:51:00 282624 -----n--- C:\WINDOWS\system32\gdi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-02-20 07:35:05 45568 -----n--- C:\WINDOWS\system32\dnsrslvr.dll <Not Verified; Microsoft Corporation; Système d'exploitation Microsoft® Windows®>
2008-02-20 00:59:39 0 d-------- C:\Program Files\Google
2008-02-20 00:57:17 0 d-------- C:\Program Files\Java
2008-02-20 00:22:55 0 d-------- C:\Program Files\Windows Live Toolbar
2008-02-15 18:52:47 0 d-------- C:\Documents and Settings\papa.VAIOPAPA\Application Data\Ford Error Hide
2008-02-15 18:52:15 0 d-------- C:\Program Files\Ford Error Hide
2008-02-15 18:51:53 0 d-------- C:\Program Files\Circle Developement
2008-02-15 18:34:50 0 d-------- C:\Program Files\Kiwee Toolbar2
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VAIO Update 3"="C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" [25/01/2007 20:41]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [22/02/2007 11:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [15/12/2006 04:23]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [27/09/2005 07:59]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [19/10/2005 23:07]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [29/09/2003 07:10]
"RTHDCPL"="RTHDCPL.EXE" [30/01/2007 18:54 C:\WINDOWS\RTHDCPL.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [02/11/2004 20:24]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [09/06/2005 19:56]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [10/09/2003 04:11]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [20/02/2004 15:12]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [07/11/2003 19:21]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 18:43 C:\WINDOWS\Alcmtr.exe]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [24/09/2005 07:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"road draw"="C:\DOCUME~1\PAPA~1.VAI\APPLIC~1\FORDER~1\DVD OPTION START.exe" [15/02/2008 18:52]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [05/08/2004 14:00]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
C:\Documents and Settings\papa.VAIOPAPA\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [09/09/2005 03:25:50]
C:\Documents and Settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 23:05:26]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 23/09/2006 15:24 73728 C:\WINDOWS\system32\VESWinlogon.dll
-- Hosts -----------------------------------------------------------------------
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
60 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-04-14 00:40:14 ------------
Attente de votre réponse.
Cordialement