Rechercher : dans
Par :

VBS:Malware-gen,VBS: Solow

Dernière réponse le 25 oct 2008 à 19:10:03 nigga_nigga, le 4 oct 2008 à 11:57:48 
 Signaler ce message aux modérateurs

Bonjour,
j'ai chopé les virus suivants VBS:Malware-gen & VBS: Solow.
Avast me les detecte mais ne peut pas me les supprimer. En recherchant sur divers tuto & forums,beaucoup conseille le logiciel hijack pour la suppression
Je l'ai telecharger et suivi la mise en oeuvre et ai recuperer un fichier en .txt bourrée d'information qui me depassent !!! :(
La marche a suivre est de copier ces informations dans un forum mais dans quel but ???
Quelqu'un peut il m'expliquer ?
Merci d avance


Voici le resultat :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:04:41, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Avast4\ashDisp.exe
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\WINDOWS\system32\wscript.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] "D:\Program Files\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MS32DLL] D:\WINDOWS\.MS32DLL.dll.vbs
O4 - HKLM\..\Run: [winboot] wscript.exe /E:vbs D:\WINDOWS\boot.ini
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 9419 bytes

Configuration: Windows XP
Internet Explorer 7.0

1

sKe69, le 4 oct 2008 à 12:00:44

Salut,

fais ceci stp :

Télécharges ToolBar S&D ( de Eric_71/Team IDN ) :
http://eric.71.mespages.googlepages.com/ToolBarSD.exe

( Tuto : http://toolbarsd.googlepages.com/aideenimages )

!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

* double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
* Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
* Choisis l'option 1 ( "recherche") et tapes "entrée" .
* Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
de son contenu dans ta prochaine réponse ...
( le rapport est en outre sauvegardé ici -> C:\TB.txt )
Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

3

nigga_nigga, le 4 oct 2008 à 12:30:40

Merci beaucoup
Je vais essayer de ce pas pour voir si ca marche!
Je te tiens au courant !

:)

Répondre à nigga_nigga

2

toptitbal, le 4 oct 2008 à 12:02:15

Bonjour

Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
http://eric.71.mespages.googlepages.com/ToolBarSD.exe

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
 

Répondre à toptitbal

4

nigga_nigga, le 4 oct 2008 à 12:31:33

Merci du conseil je vais essayer
A toute .....

Répondre à nigga_nigga

5

sKe69, le 4 oct 2008 à 12:34:32

merci du conseil je vais essayer

--> essayer ? Non, il faut le faire ...et il y aura pas mal de chose qui viendrons derrière car tu as plusieurs infections ! ... ^^ Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

6

nigga_nigga, le 4 oct 2008 à 12:46:48

Je viens de finir la recherche....
Voici le rapport a l'issue :


-----------\\ ToolBar S&D 1.2.1 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
BIOS : Award Medallion BIOS v6.00PG
USER : Did ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081004-0] 4.8.1229 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 83 Go Free : 37 Go
D:\ (Local Disk) - NTFS - Total : 37 Go Free : 30 Go
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (Local Disk) - NTFS - Total : 65 Go Free : 40 Go
J:\ (CD or DVD)
K:\ (CD or DVD) - CDFS - Total : 4 Go Free : 0 Go
M:\ (CD or DVD)
O:\ (Local Disk) - NTFS - Total : 74 Go Free : 10 Go

"D:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
Option : [1] ( 04/10/2008|12:43 )

-----------\\ Recherche de Fichiers / Dossiers ...

D:\Program Files\DAEMON Tools Toolbar
D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
D:\Program Files\DAEMON Tools Toolbar\Resources
D:\Program Files\DAEMON Tools Toolbar\uninst.exe
D:\Program Files\DAEMON Tools Toolbar\_DTLite.xml

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://www.google.fr"
"Local Page"="D:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://www.orange.fr/"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "D:\ToolBar SD\TB_1.txt" - 04/10/2008|12:44 - Option : [1]

-----------\\ Fin du rapport a 12:44:17,64

Je fais toutes ces manip sans trop capter ce que je fais....

Répondre à nigga_nigga

7

sKe69, le 4 oct 2008 à 12:51:00

Bien ...

Nettoyage avec ToolBar S&D :

!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

Relances Toolbar-S&D en double-cliquant sur le raccourci.
-->Tapes sur l'option 2 ( "nettoyage" ) puis tapes sur "Entrée".
Note : ne touches à rien lors de la suppression !
Un rapport sera généré à la fin du processus : postes son contenu dans ta prochaine réponse
accompagné d'un nouveau rapport hijackthis pour analyse ...
Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

8

nigga_nigga, le 4 oct 2008 à 13:16:41

Ca y est....
Je te poste le rapport de tool bar....

-----------\\ ToolBar S&D 1.2.1 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
BIOS : Award Medallion BIOS v6.00PG
USER : Did ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081004-0] 4.8.1229 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 83 Go Free : 38 Go
D:\ (Local Disk) - NTFS - Total : 37 Go Free : 30 Go
E:\ (USB)
F:\ (USB)
G:\ (USB) - FAT - Total : 971 Mo Free : 0 Go
H:\ (USB)
I:\ (Local Disk) - NTFS - Total : 65 Go Free : 40 Go
J:\ (CD or DVD)
K:\ (CD or DVD) - CDFS - Total : 4 Go Free : 0 Go
M:\ (CD or DVD)
O:\ (Local Disk) - NTFS - Total : 74 Go Free : 10 Go

"D:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
Option : [2] ( 04/10/2008|13:09 )

-----------\\ SUPPRESSION

Supprime! - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
Supprime! - D:\Program Files\DAEMON Tools Toolbar\Resources
Supprime! - D:\Program Files\DAEMON Tools Toolbar\uninst.exe
Supprime! - D:\Program Files\DAEMON Tools Toolbar\_DTLite.xml
Supprime! - D:\Program Files\DAEMON Tools Toolbar

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://www.google.fr"
"Local Page"="D:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://www.orange.fr/"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.msn.com/"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "D:\ToolBar SD\TB_1.txt" - 04/10/2008|12:44 - Option : [1]
2 - "D:\ToolBar SD\TB_2.txt" - 04/10/2008|13:10 - Option : [2]

-----------\\ Fin du rapport a 13:10:03,14

comme tu me la indiqué,j ai relancé hijack dont voici le rapport :


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:10:37, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Avast4\ashDisp.exe
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\WINDOWS\system32\wscript.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] "D:\Program Files\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winboot] wscript.exe /E:vbs D:\WINDOWS\boot.ini
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 9200 bytes



petite precision :

je suis obligé de laisser la fenetre d avertissement de avast ouverte car sinon les messages d erreur n'arretent pas d apparaitre !
De plus si je veux aller sur mes disques durs,je suis obliger de passer par le menu contextuel pour y acceder ...

Répondre à nigga_nigga

9

sKe69, le 4 oct 2008 à 13:19:08

Bien ... maintenant on va s'attaquer au vif du sujet ... ^^

mais tout d'abors , fais ceci :


1- Télécharges : - CCleaner
http://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

---> Utilisation:
! déconnectes toi et fermes toutes applications en cours !
* vas dans "nettoyeur" : fait analyse puis nettoyage
* vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )



2- Télécharges Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

-> http://images.malwareremoval.com/random/RSIT.exe

! Déconnecte toi et fermes toutes tes applications en cours !

Double-clique sur " RSIT.exe " pour le lancer .

-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

* Devant l'option "List files/folders created ..." , tu choisis : 3 months

* cliques ensuite sur " Continue " pour lancer l'analyse ...


( Note : Si la dernière version de HijackThis n'est pas détectée sur ton PC, RSIT le téléchargera et te demandera d'accepter la licence.)


-> laisses faire le scan et ne touche pas au PC ...


Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

Postes le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

10

nigga_nigga, le 4 oct 2008 à 13:54:30

C fait !


rapport fichier log.txt


Logfile of random's system information tool 1.04 (written by random/random)
Run by Did at 2008-10-04 13:51:56
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 31 GB (80%) free of 39 GB
Total RAM: 1023 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:52:04, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Avast4\ashDisp.exe
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\WINDOWS\system32\wscript.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Documents and Settings\Administrateur\Bureau\Utilitaires II\Random System Information Tool.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Trend Micro\HijackThis\Did.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] "D:\Program Files\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winboot] wscript.exe /E:vbs D:\WINDOWS\boot.ini
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 9224 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Maintenance en 1 clic.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}]
D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - d:\program files\google\googletoolbar1.dll [2008-08-22 2582136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll [2008-08-22 651760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17}
{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2005-06-29 14720000]
"Alcmtr"=D:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2006-06-01 7618560]
"avast!"=D:\Program Files\Avast4\ashDisp.exe [2008-07-19 78008]
"LVCOMSX"=D:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
"rkfree"=D:\WINDOWS\Winreveal\rkfree.exe [2008-08-26 66048]
"QuickTime Task"=D:\WINDOWS\system32\qttask.exe [2008-08-24 98304]
"winboot"=wscript.exe /E:vbs D:\WINDOWS\boot.ini []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=D:\Program Files\SuperCopier2\SuperCopier2.exe [2005-03-14 1057280]
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-22 39408]
"H/PC Connection Agent"=D:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"RoboForm"=D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2008-09-28 160592]

D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\GigaTribe\gigatribe.exe"="D:\Program Files\GigaTribe\gigatribe.exe:*:Enabled:gigatribe"
"D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Azureus\Azureus.exe"="D:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Messenger\msmsgs.exe"="D:\Program Files\Messenger\msmsgs.exe:*:Enabled:Messenger"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="D:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"D:\Program Files\eMule\emule.exe"="D:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4925ecd7-7061-11dd-aec1-001485770dc9}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6328119d-7064-11dd-9985-806d6172696f}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6328119e-7064-11dd-9985-806d6172696f}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{632811a1-7064-11dd-9985-806d6172696f}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68874f40-7504-11dd-aee0-001485770dc9}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80c191e0-7281-11dd-aed9-001485770dc9}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs


======List of files/folders created in the last 3 months======

2008-10-04 13:51:56 ----D---- D:\rsit
2008-10-04 13:29:01 ----D---- D:\Program Files\CCleaner
2008-10-04 13:10:18 ----A---- D:\TB II.txt
2008-10-04 12:43:23 ----A---- D:\TB.txt
2008-10-04 12:41:46 ----D---- D:\ToolBar SD
2008-10-04 09:47:20 ----D---- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:47:17 ----D---- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:16:54 ----A---- D:\.MS32DLL.dll.vbs
2008-10-04 09:16:06 ----D---- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03:49 ----D---- D:\Program Files\Trend Micro
2008-10-04 08:15:26 ----RASH---- D:\WINDOWS\boot.ini
2008-09-13 22:53:25 ----HDC---- D:\WINDOWS\$NtUninstallKB938464$
2008-09-13 22:53:16 ----HDC---- D:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-05 15:41:37 ----HD---- D:\WINDOWS\system32\GroupPolicy
2008-09-01 00:57:18 ----D---- D:\Documents and Settings\Administrateur\Application Data\Help
2008-08-31 16:15:50 ----D---- D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 16:14:48 ----D---- D:\Program Files\Siber Systems
2008-08-29 19:59:20 ----D---- D:\Program Files\La Marmite du Chef
2008-08-29 08:43:55 ----D---- D:\Program Files\SuperCopier2
2008-08-26 10:50:02 ----AD---- D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 10:49:50 ----D---- D:\WINDOWS\Winreveal
2008-08-26 10:49:39 ----D---- D:\Nouveau dossier
2008-08-26 08:33:15 ----D---- D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 08:31:54 ----D---- D:\WINDOWS\system32\CatRoot_bak
2008-08-25 16:59:20 ----D---- D:\Program Files\MappySynchro
2008-08-25 16:53:14 ----D---- D:\WINDOWS\LastGood
2008-08-25 16:50:24 ----HDC---- D:\WINDOWS\$NtUninstallKB909394$
2008-08-25 16:50:07 ----D---- D:\Program Files\Microsoft ActiveSync
2008-08-25 11:15:08 ----D---- D:\WINDOWS\LastGood.Tmp
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\muweb.dll
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll.mui
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll
2008-08-24 14:43:17 ----HD---- D:\WINDOWS\Icons
2008-08-24 12:50:02 ----D---- D:\Documents and Settings\Administrateur\Application Data\Real
2008-08-24 09:38:14 ----A---- D:\WINDOWS\system32\qttask.exe
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\rmoc3260.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5032.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5016.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pncrt.dll
2008-08-24 09:36:44 ----D---- D:\WINDOWS\system32\QuickTime
2008-08-24 09:36:43 ----A---- D:\WINDOWS\mmtvmj.ini
2008-08-24 09:36:43 ----A---- D:\WINDOWS\m3jp2k.ini
2008-08-24 09:36:42 ----A---- D:\WINDOWS\m3jpeg.ini
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvpx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvm6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplva6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplapx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplam6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaa6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\cpuinf32.dll
2008-08-24 09:36:37 ----A---- D:\WINDOWS\system32\unrar.dll
2008-08-24 09:36:35 ----A---- D:\WINDOWS\system32\xvidcore.dll
2008-08-24 09:36:31 ----D---- D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 09:18:47 ----D---- D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-24 09:02:18 ----D---- D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 09:01:45 ----D---- D:\Program Files\Fichiers communs\HP
2008-08-24 09:00:39 ----D---- D:\Program Files\Hewlett-Packard
2008-08-24 09:00:19 ----D---- D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-24 08:59:43 ----RA---- D:\WINDOWS\system32\HPZIDS01.dll
2008-08-24 08:59:42 ----A---- D:\WINDOWS\system32\hpzll054.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZisn12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipt12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipm12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZinw12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZidr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\IsUninst.exe
2008-08-24 08:57:44 ----D---- D:\Program Files\HP
2008-08-24 08:56:41 ----HD---- D:\Config.Msi
2008-08-23 23:23:09 ----HDC---- D:\WINDOWS\$NtUninstallKB941569$
2008-08-23 23:22:54 ----HDC---- D:\WINDOWS\$NtUninstallKB929399$
2008-08-23 23:22:19 ----HDC---- D:\WINDOWS\$NtUninstallKB939683$
2008-08-23 23:22:04 ----D---- D:\WINDOWS\ie7updates
2008-08-23 23:22:00 ----HDC---- D:\WINDOWS\$NtUninstallKB932823-v3$
2008-08-23 23:21:55 ----D---- D:\Program Files\MSXML 4.0
2008-08-23 23:21:50 ----A---- D:\WINDOWS\system32\wmpns.dll
2008-08-23 23:21:42 ----HDC---- D:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2RC.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.ini
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcodec2.dll
2008-08-23 09:40:29 ----A---- D:\WINDOWS\IsUn040c.exe
2008-08-23 09:35:51 ----A---- D:\WINDOWS\system32\capicom.dll
2008-08-23 09:35:14 ----RA---- D:\WINDOWS\system32\InstMed.exe
2008-08-23 09:34:48 ----D---- D:\Program Files\Fichiers communs\Logitech
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\Lvkrn12n.dll
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\LCamCpl.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71u.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71KOR.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71JPN.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ITA.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ESP.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ENU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71DEU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71CHT.DLL
2008-08-23 09:34:28 ----A---- D:\WINDOWS\system32\MFC71CHS.DLL
2008-08-23 09:34:26 ----A---- D:\WINDOWS\system32\atl71.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\QCUI2.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\Ltwvc12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltkrn12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltimg12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltfil12n.DLL
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltefx12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\LTDIS12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lftif12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lffax12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\LFCMP12n.DLL
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lfbmp12n.dll
2008-08-23 09:34:21 ----A---- D:\WINDOWS\system32\LQCUI2.dll
2008-08-23 09:34:20 ----D---- D:\Program Files\Logitech
2008-08-23 09:34:07 ----R---- D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 08:38:37 ----HDC---- D:\WINDOWS\$NtUninstallKB915865$
2008-08-23 08:38:26 ----N---- D:\WINDOWS\system32\xmllite.dll
2008-08-23 08:02:58 ----D---- D:\Program Files\Sony Corporation
2008-08-23 08:02:50 ----N---- D:\WINDOWS\snymsico.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBUI.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CddbLangFR.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBControl.dll
2008-08-23 08:02:16 ----D---- D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 07:56:49 ----D---- D:\Program Files\Sony
2008-08-23 07:56:14 ----D---- D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 07:56:14 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-23 07:37:31 ----D---- D:\WINDOWS\Sun
2008-08-23 07:37:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sun
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaws.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaw.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\java.exe
2008-08-23 07:36:29 ----D---- D:\Program Files\Java
2008-08-23 07:36:20 ----A---- D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 07:36:12 ----D---- D:\Program Files\Messenger
2008-08-23 07:36:03 ----D---- D:\Program Files\Fichiers communs\Java
2008-08-22 21:26:55 ----D---- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 21:26:01 ----D---- D:\Program Files\Windows Live
2008-08-22 21:25:59 ----D---- D:\Program Files\Messenger Plus! Live
2008-08-22 21:24:53 ----D---- D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 21:24:48 ----D---- D:\Program Files\MSN Pictures Displayer
2008-08-22 21:19:10 ----DC---- D:\WINDOWS\system32\DRVSTORE
2008-08-22 21:19:05 ----D---- D:\Program Files\MSN Messenger
2008-08-22 21:07:06 ----D---- D:\Documents and Settings\Administrateur\Application Data\Macromedia
2008-08-22 21:07:05 ----D---- D:\Documents and Settings\Administrateur\Application Data\Adobe
2008-08-22 21:00:43 ----D---- D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 21:00:41 ----D---- D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-08-22 21:00:00 ----D---- D:\Program Files\Azureus
2008-08-22 19:51:26 ----D---- D:\Documents and Settings\Administrateur\Application Data\Google
2008-08-22 19:51:22 ----D---- D:\Documents and Settings\All Users\Application Data\Google
2008-08-22 19:51:11 ----D---- D:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-22 19:51:10 ----D---- D:\Program Files\Google
2008-08-22 19:31:41 ----N---- D:\WINDOWS\system32\normaliz.dll
2008-08-22 19:30:36 ----D---- D:\WINDOWS\WBEM
2008-08-22 19:30:35 ----D---- D:\WINDOWS\system32\fr-fr
2008-08-22 19:30:28 ----D---- D:\WINDOWS\%DownloadedProgramFiles%
2008-08-22 19:29:47 ----HDC---- D:\WINDOWS\ie7
2008-08-22 19:02:57 ----D---- D:\Program Files\Microsoft Works
2008-08-22 19:02:40 ----D---- D:\Program Files\Microsoft Visual Studio
2008-08-22 19:02:39 ----D---- D:\Program Files\Fichiers communs\DESIGNER
2008-08-22 19:00:09 ----D---- D:\WINDOWS\SHELLNEW
2008-08-22 18:59:49 ----D---- D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 18:59:48 ----D---- D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 18:59:31 ----RHD---- D:\MSOCache
2008-08-22 18:57:42 ----D---- D:\Documents and Settings\All Users\Application Data\Adobe
2008-08-22 18:57:34 ----D---- D:\Program Files\Fichiers communs\Adobe
2008-08-22 18:51:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-22 18:51:11 ----HDC---- D:\WINDOWS\$NtUninstallKB952954$
2008-08-22 18:51:06 ----HDC---- D:\WINDOWS\$NtUninstallKB953839$
2008-08-22 18:51:02 ----HDC---- D:\WINDOWS\$NtUninstallKB935448$
2008-08-22 18:50:57 ----HDC---- D:\WINDOWS\$NtUninstallKB950974$
2008-08-22 18:50:52 ----HDC---- D:\WINDOWS\$NtUninstallKB951698$
2008-08-22 18:50:25 ----A---- D:\WINDOWS\system32\MRT.exe
2008-08-22 18:50:19 ----HDC---- D:\WINDOWS\$NtUninstallKB950762$
2008-08-22 18:50:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-22 18:50:09 ----HDC---- D:\WINDOWS\$NtUninstallKB952287$
2008-08-22 18:50:04 ----HDC---- D:\WINDOWS\$NtUninstallKB951066$
2008-08-22 18:49:52 ----HDC---- D:\WINDOWS\$NtUninstallKB953838$
2008-08-22 18:49:43 ----HDC---- D:\WINDOWS\$NtUninstallKB951748$
2008-08-22 18:49:34 ----HDC---- D:\WINDOWS\$NtUninstallKB950749$
2008-08-22 18:49:23 ----N---- D:\WINDOWS\system32\spmsg.dll
2008-08-22 18:49:22 ----HDC---- D:\WINDOWS\$NtUninstallKB944338-v2$
2008-08-22 18:44:30 ----HDC---- D:\WINDOWS\$NtUninstallWMFDist11$
2008-08-22 18:43:40 ----D---- D:\Program Files\Windows Media Connect 2
2008-08-22 18:43:32 ----HDC---- D:\WINDOWS\$NtUninstallwmp11$
2008-08-22 18:40:13 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-08-22 18:36:35 ----A---- D:\WINDOWS\system32\BASSMOD.dll
2008-08-22 18:35:34 ----D---- D:\Program Files\WinRAR
2008-08-22 18:33:31 ----D---- D:\Program Files\QuickTime
2008-08-22 18:33:31 ----D---- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 18:33:21 ----D---- D:\Program Files\Apple Software Update
2008-08-22 18:33:21 ----D---- D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 18:28:48 ----A---- D:\WINDOWS\system32\h323log.txt
2008-08-22 18:28:21 ----A---- D:\WINDOWS\system32\ksuser.dll
2008-08-22 18:27:12 ----A---- D:\WINDOWS\system32\usbui.dll
2008-08-22 18:26:10 ----SHD---- D:\WINDOWS\Installer
2008-08-22 18:26:10 ----D---- D:\Program Files\Fichiers communs\ODBC
2008-08-22 18:26:10 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2008-08-22 18:26:10 ----A---- D:\WINDOWS\ODBCINST.INI
2008-08-22 18:26:07 ----D---- D:\Program Files\Fichiers communs\SpeechEngines
2008-08-22 18:26:06 ----RD---- D:\Program Files
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs\Microsoft Shared
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuq.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuf.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdazel.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdycc.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbduzb.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdur.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdtat.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru1.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdmon.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkyr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkaz.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdbu.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdblr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdaze.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhept.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela3.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela2.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe319.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe220.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdgkl.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdest.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdycl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdro.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz2.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcr.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\KBDAL.DLL
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\spxcoins.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\irclass.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\EqnClass.Dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgsetup.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgrpsetu.dll
2008-08-22 18:25:52 ----N---- D:\WINDOWS\system32\CONFIG.TMP
2008-08-22 18:25:52 ----A---- D:\WINDOWS\TASKMAN.EXE
2008-08-22 18:25:51 ----A---- D:\WINDOWS\system32\batt.dll
2008-08-22 18:25:51 ----A---- D:\WINDOWS\NOTEPAD.EXE
2008-08-22 18:25:50 ----A---- D:\WINDOWS\system32\storprop.dll
2008-08-22 18:25:43 ----ASH---- D:\Documents and Settings\All Users\Application Data\desktop.ini
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot2
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot
2008-08-22 18:25:23 ----SD---- D:\Documents and Settings\All Users\Application Data\Microsoft
2008-08-22 18:25:03 ----D---- D:\Documents and Settings
2008-08-22 18:24:02 ----SHD---- D:\System Volume Information
2008-08-22 18:23:58 ----D---- D:\INSTALL
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\vxblock.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxwave.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxsfs.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxmas.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxinsa64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxhpinst.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxdrv.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxcpya64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxafs.dll
2008-08-22 18:23:23 ----D---- D:\Program Files\Winamp
2008-08-22 18:23:23 ----D---- D:\Documents and Settings\Administrateur\Application Data\Winamp
2008-08-22 18:22:00 ----A---- D:\WINDOWS\NeroDigital.ini
2008-08-22 18:21:42 ----D---- D:\Documents and Settings\Administrateur\Application Data\vlc
2008-08-22 18:21:10 ----D---- D:\Program Files\VideoLAN
2008-08-22 18:20:01 ----RSHDC---- D:\WINDOWS\system32\dllcache
2008-08-22 18:20:01 ----RSD---- D:\WINDOWS\Fonts
2008-08-22 18:20:01 ----RD---- D:\WINDOWS\Web
2008-08-22 18:20:01 ----HD---- D:\WINDOWS\inf
2008-08-22 18:20:01 ----D---- D:\WINDOWS\WinSxS
2008-08-22 18:20:01 ----D---- D:\WINDOWS\twain_32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Temp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wins
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wbem
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\usmt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\spool
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ShellExt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\Setup
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ras
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\oobe
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\npp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\inetsrv
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\IME
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\icsxml
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ias
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\export
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\drivers
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\dhcp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3com_dmi
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3076
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\2052
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1054
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1042
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1041
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1037
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1036
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1033
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1031
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1028
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1025
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system
2008-08-22 18:20:01 ----D---- D:\WINDOWS\security
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Resources
2008-08-22 18:20:01 ----D---- D:\WINDOWS\repair
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Provisioning
2008-08-22 18:20:01 ----D---- D:\WINDOWS\PeerNet
2008-08-22 18:20:01 ----D---- D:\WINDOWS\pchealth
2008-08-22 18:20:01 ----D---- D:\WINDOWS\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msapps
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msagent
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Media
2008-08-22 18:20:01 ----D---- D:\WINDOWS\java
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ime
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Help
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ehome
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Driver Cache
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Debug
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Cursors
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Connection Wizard
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\AppPatch
2008-08-22 18:20:01 ----D---- D:\WINDOWS\addins
2008-08-22 18:20:01 ----D---- D:\WINDOWS
2008-08-22 18:19:35 ----D---- D:\WINDOWS\system32\PreInstall
2008-08-22 18:19:33 ----HDC---- D:\WINDOWS\$NtUninstallKB898461$
2008-08-22 18:19:33 ----HD---- D:\WINDOWS\$hf_mig$
2008-08-22 18:14:58 ----D---- D:\Documents and Settings\Administrateur\Application Data\Nero
2008-08-22 18:14:45 ----A---- D:\WINDOWS\system32\MsiExec.exe.log
2008-08-22 18:13:28 ----D---- D:\Program Files\Nero
2008-08-22 18:13:28 ----D---- D:\Program Files\Fichiers communs\Nero
2008-08-22 18:13:28 ----D---- D:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 18:10:42 ----A---- D:\WINDOWS\system32\d3dx9_30.dll
2008-08-22 18:10:41 ----A---- D:\WINDOWS\system32\d3dx9_28.dll
2008-08-22 18:08:08 ----D---- D:\Documents and Settings\Administrateur\Application Data\GigaTribe
2008-08-22 18:06:10 ----D---- D:\WINDOWS\RegisteredPackages
2008-08-22 18:03:25 ----D---- D:\Program Files\eMule
2008-08-22 18:02:50 ----D---- D:\Program Files\GigaTribe
2008-08-22 17:59:21 ----D---- D:\Temp
2008-08-22 17:59:07 ----D---- D:\Documents and Settings\Administrateur\Application Data\Syntrillium
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmvdmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmod.dll
2008-08-22 17:58:52 ----A---- D:\WINDOWS\system32\wmvcore2.dll
2008-08-22 17:57:28 ----D---- D:\Program Files\Cool Edit Pro 2.1
2008-08-22 17:54:03 ----D---- D:\Program Files\Adobe
2008-08-22 17:49:14 ----D---- D:\Program Files\Virtual Dj 3.2
2008-08-22 17:46:10 ----D---- D:\WINDOWS\system32\SoftwareDistribution
2008-08-22 17:45:03 ----D---- D:\Program Files\DAEMON Tools Lite
2008-08-22 17:43:01 ----D---- D:\Documents and Settings\Administrateur\Application Data\DAEMON Tools
2008-08-22 17:40:58 ----A---- D:\WINDOWS\system32\TUKernel.exe
2008-08-22 17:23:05 ----A---- D:\WINDOWS\system32\uxtuneup.dll
2008-08-22 17:23:04 ----D---- D:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-08-22 17:23:04 ----A---- D:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-22 17:22:52 ----D---- D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-22 17:22:50 ----D---- D:\Program Files\TuneUp Utilities 2008
2008-08-22 17:22:38 ----D---- D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-22 17:11:51 ----SHD---- D:\RECYCLER
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\msvcp71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\MFC71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\aswBoot.exe
2008-08-22 17:09:57 ----D---- D:\Program Files\Avast4
2008-08-22 17:04:39 ----A---- D:\WINDOWS\system32\PsisDecd.dll
2008-08-22 17:04:38 ----A---- D:\WINDOWS\system32\vfwwdm32.dll
2008-08-22 17:04:08 ----A---- D:\WINDOWS\system32\hidserv.dll
2008-08-22 17:04:02 ----D---- D:\Program Files\X10 Hardware
2008-08-22 17:04:02 ----D---- D:\Program Files\Common Files
2008-08-22 17:04:02 ----A---- D:\WINDOWS\Unwise.exe
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr71.dll
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr70.dll
2008-08-22 17:03:49 ----D---- D:\Program Files\Intel
2008-08-22 17:03:19 ----HD---- D:\Program Files\InstallShield Installation Information
2008-08-22 16:56:28 ----D---- D:\WINDOWS\nview
2008-08-22 16:56:27 ----A---- D:\WINDOWS\system32\nvudisp.exe
2008-08-22 16:56:21 ----A---- D:\WINDOWS\system32\NVUNINST.EXE
2008-08-22 16:56:18 ----D---- D:\Program Files\Fichiers communs\InstallShield
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nwiz.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwssr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwss.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszht.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszhc.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrstr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssv.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssk.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsru.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsptb.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspt.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsno.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsnl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsko.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsja.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvsvc32.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvdspsch.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcplui.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcolor.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvappbar.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\keystone.exe
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsit.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshu.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshe.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsesm.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrses.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrseng.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsel.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsde.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsda.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrscs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsar.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwimg.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwdmcpl.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwddi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvsr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvshell.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszht.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszhc.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrstr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssv.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssk.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsru.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsptb.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspt.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsno.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsnl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsko.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsja.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsit.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshu.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshe.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfi.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsesm.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrses.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrseng.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsel.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsde.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsda.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrscs.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsar.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvoglnt.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvnt4cpl.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmoblsr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmobls.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmctray.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccssr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccss.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccsrs.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccs.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nview.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvhwvid.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgamesr.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgames.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvexpbar.dll
2008-08-22 16:56:11 ----A---- D:\WINDOWS\system32\nvdispsr.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvdisps.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvcpluir.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcpl.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcodins.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcod.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvapi.dll
2008-08-22 16:56:08 ----A---- D:\WINDOWS\system32\nv4_disp.dll
2008-08-22 16:46:13 ----D---- D:\WINDOWS\system32\Lang
2008-08-22 16:44:30 ----D---- D:\WINDOWS\system32\RTCOM
2008-08-22 16:44:27 ----D---- D:\WINDOWS\system32\ReinstallBackups
2008-08-22 16:44:12 ----A---- D:\WINDOWS\system32\spupdsvc.exe
2008-08-22 16:44:11 ----HDC---- D:\WINDOWS\$NtUninstallKB888111WXPSP2$
2008-08-22 16:43:50 ----D---- D:\pnp
2008-08-22 16:38:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Identities
2008-08-22 16:38:30 ----HD---- D:\Program Files\Uninstall Information
2008-08-22 16:36:20 ----ASH---- D:\Documents and Settings\Administrateur\Application Data\desktop.ini
2008-08-22 16:36:19 ----SD---- D:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-08-22 16:36:14 ----D---- D:\WINDOWS\SoftwareDistribution
2008-08-22 16:36:11 ----SD---- D:\WINDOWS\system32\Microsoft
2008-08-22 16:36:11 ----N---- D:\WINDOWS\SchedLgU.Txt
2008-08-22 16:36:11 ----D---- D:\WINDOWS\Prefetch
2008-08-22 16:33:18 ----D---- D:\WINDOWS\system32\xircom
2008-08-22 16:33:18 ----D---- D:\Program Files\xerox
2008-08-22 16:33:18 ----D---- D:\Program Files\msn gaming zone
2008-08-22 16:33:18 ----D---- D:\Program Files\movie maker
2008-08-22 16:33:18 ----D---- D:\Program Files\microsoft frontpage
2008-08-22 16:33:01 ----A---- D:\WINDOWS\control.ini
2008-08-22 16:32:47 ----A---- D:\WINDOWS\system32\mapi32.dll
2008-08-22 16:32:04 ----SD---- D:\WINDOWS\Downloaded Program Files
2008-08-22 16:32:04 ----RD---- D:\WINDOWS\Offline Web Pages
2008-08-22 16:32:04 ----RAH---- D:\WINDOWS\system32\logonui.exe.manifest
2008-08-22 16:31:58 ----RAH---- D:\WINDOWS\system32\cdplayer.exe.manifest
2008-08-22 16:31:54 ----HD---- D:\Program Files\WindowsUpdate
2008-08-22 16:31:52 ----D---- D:\Program Files\Services en ligne
2008-08-22 16:31:38 ----D---- D:\WINDOWS\system32\DirectX
2008-08-22 16:31:19 ----A---- D:\WINDOWS\system32\atrace.dll
2008-08-22 16:31:17 ----A---- D:\WINDOWS\system32\desktop.ini
2008-08-22 16:31:17 ----A---- D:\WINDOWS\desktop.ini
2008-08-22 16:31:11 ----A---- D:\WINDOWS\system32\nmevtmsg.dll
2008-08-22 16:31:10 ----A---- D:\WINDOWS\system32\acctres.dll
2008-08-22 16:31:09 ----D---- D:\Program Files\Fichiers communs\Services
2008-08-22 16:31:07 ----SD---- D:\WINDOWS\Tasks
2008-08-22 16:31:07 ----A---- D:\WINDOWS\system32\icfgnt5.dll
2008-08-22 16:31:06 ----D---- D:\Program Files\Fichiers communs\MSSoap
2008-08-22 16:31:02 ----D---- D:\WINDOWS\system32\Macromed
2008-08-22 16:31:02 ----D---- D:\WINDOWS\srchasst
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuweb.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wucltui.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuauserv.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuaueng1.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wups.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuaueng.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt1.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuapi.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgrprxy.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgr.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx3.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx2.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrslv.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrdm.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrcdlg.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\racpldlg.dll
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltMc.exe
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltlib.dll
2008-08-22 16:30:50 ----D---- D:\WINDOWS\system32\Restore
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srsvc.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srrstr.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srclient.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\nmmkcert.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\msconf.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmsrvc.exe
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmdd.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\isrdbg32.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\ils.dll
2008-08-22 16:30:46 ----D---- D:\Program Files\NetMeeting
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoert2.dll
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoeacct.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetres.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetcomm.dll
2008-08-22 16:30:44 ----D---- D:\Program Files\Outlook Express
2008-08-22 16:30:44 ----A---- D:\WINDOWS\system32\schedsvc.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstinit.exe
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstask.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\isign32.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\inetcfg.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwphbk.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwdial.dll
2008-08-22 16:30:38 ----D---- D:\Program Files\Fichiers communs\System
2008-08-22 16:30:37 ----D---- D:\Program Files\Internet Explorer
2008-08-22 16:30:09 ----D---- D:\Program Files\ComPlus Applications
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vbaddin.ini
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vb.ini
2008-08-22 16:30:04 ----D---- D:\WINDOWS\Registration
2008-08-22 16:29:58 ----D---- D:\Program Files\Windows Media Player
2008-08-22 16:29:55 ----A---- D:\WINDOWS\system32\write.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\sndvol32.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\hticons.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\winchat.exe
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avwav.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avtapi.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avmeter.dll
2008-08-22 16:29:43 ----A---- D:\WINDOWS\system32\getuname.dll
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\usrlogon.cmd
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsshutdn.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tslabels.ini
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tskill.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsdiscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\shadow.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\reset.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\charmap.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\calc.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\regini.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rdpcfgex.dll
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qappsrv.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msg.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msdtcprf.ini
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\logoff.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\cdmodem.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\stclient.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxlegih.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxex.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxdm.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\dcomcnfg.exe
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comrepl.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comaddin.dll
2008-08-22 16:29:39 ----A---- D:\WINDOWS\system32\comsnap.dll
2008-08-22 16:29:35 ----A---- D:\WINDOWS\system32\wmimgmt.msc
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\sndrec32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\mplay32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\accwiz.exe
2008-08-22 16:29:33 ----D---- D:\Program Files\Windows NT
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\mspaint.exe
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\hypertrm.dll
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\clipbrd.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\tscfgwmi.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\sessmgr.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\remotepg.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdshost.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdsaddin.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstscax.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstsc.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\tscupgrd.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\termsrv.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpwsx.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpsnd.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpclip.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdchost.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\qprocess.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\icaapi.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\cfgbkend.dll
2008-08-22 16:29:30 ----D---- D:\WINDOWS\system32\MsDtc
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\xolehlp.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\mtxoci.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcuiu.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtctm.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcprx.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtclog.dll
2008-08-22 1

Répondre à nigga_nigga

11

nigga_nigga, le 4 oct 2008 à 14:40:29

Fichier log


Logfile of random's system information tool 1.04 (written by random/random)
Run by Did at 2008-10-04 13:51:56
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 31 GB (80%) free of 39 GB
Total RAM: 1023 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:52:04, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Avast4\ashDisp.exe
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\WINDOWS\system32\wscript.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Documents and Settings\Administrateur\Bureau\Utilitaires II\Random System Information Tool.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Trend Micro\HijackThis\Did.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] "D:\Program Files\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winboot] wscript.exe /E:vbs D:\WINDOWS\boot.ini
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 9224 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Maintenance en 1 clic.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}]
D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - d:\program files\google\googletoolbar1.dll [2008-08-22 2582136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll [2008-08-22 651760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17}
{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2005-06-29 14720000]
"Alcmtr"=D:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2006-06-01 7618560]
"avast!"=D:\Program Files\Avast4\ashDisp.exe [2008-07-19 78008]
"LVCOMSX"=D:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
"rkfree"=D:\WINDOWS\Winreveal\rkfree.exe [2008-08-26 66048]
"QuickTime Task"=D:\WINDOWS\system32\qttask.exe [2008-08-24 98304]
"winboot"=wscript.exe /E:vbs D:\WINDOWS\boot.ini []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=D:\Program Files\SuperCopier2\SuperCopier2.exe [2005-03-14 1057280]
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-22 39408]
"H/PC Connection Agent"=D:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"RoboForm"=D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2008-09-28 160592]

D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\GigaTribe\gigatribe.exe"="D:\Program Files\GigaTribe\gigatribe.exe:*:Enabled:gigatribe"
"D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Azureus\Azureus.exe"="D:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Messenger\msmsgs.exe"="D:\Program Files\Messenger\msmsgs.exe:*:Enabled:Messenger"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="D:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"D:\Program Files\eMule\emule.exe"="D:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4925ecd7-7061-11dd-aec1-001485770dc9}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6328119d-7064-11dd-9985-806d6172696f}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6328119e-7064-11dd-9985-806d6172696f}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{632811a1-7064-11dd-9985-806d6172696f}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68874f40-7504-11dd-aee0-001485770dc9}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80c191e0-7281-11dd-aed9-001485770dc9}]
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs


======List of files/folders created in the last 3 months======

2008-10-04 13:51:56 ----D---- D:\rsit
2008-10-04 13:29:01 ----D---- D:\Program Files\CCleaner
2008-10-04 13:10:18 ----A---- D:\TB II.txt
2008-10-04 12:43:23 ----A---- D:\TB.txt
2008-10-04 12:41:46 ----D---- D:\ToolBar SD
2008-10-04 09:47:20 ----D---- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:47:17 ----D---- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:16:54 ----A---- D:\.MS32DLL.dll.vbs
2008-10-04 09:16:06 ----D---- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03:49 ----D---- D:\Program Files\Trend Micro
2008-10-04 08:15:26 ----RASH---- D:\WINDOWS\boot.ini
2008-09-13 22:53:25 ----HDC---- D:\WINDOWS\$NtUninstallKB938464$
2008-09-13 22:53:16 ----HDC---- D:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-05 15:41:37 ----HD---- D:\WINDOWS\system32\GroupPolicy
2008-09-01 00:57:18 ----D---- D:\Documents and Settings\Administrateur\Application Data\Help
2008-08-31 16:15:50 ----D---- D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 16:14:48 ----D---- D:\Program Files\Siber Systems
2008-08-29 19:59:20 ----D---- D:\Program Files\La Marmite du Chef
2008-08-29 08:43:55 ----D---- D:\Program Files\SuperCopier2
2008-08-26 10:50:02 ----AD---- D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 10:49:50 ----D---- D:\WINDOWS\Winreveal
2008-08-26 10:49:39 ----D---- D:\Nouveau dossier
2008-08-26 08:33:15 ----D---- D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 08:31:54 ----D---- D:\WINDOWS\system32\CatRoot_bak
2008-08-25 16:59:20 ----D---- D:\Program Files\MappySynchro
2008-08-25 16:53:14 ----D---- D:\WINDOWS\LastGood
2008-08-25 16:50:24 ----HDC---- D:\WINDOWS\$NtUninstallKB909394$
2008-08-25 16:50:07 ----D---- D:\Program Files\Microsoft ActiveSync
2008-08-25 11:15:08 ----D---- D:\WINDOWS\LastGood.Tmp
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\muweb.dll
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll.mui
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll
2008-08-24 14:43:17 ----HD---- D:\WINDOWS\Icons
2008-08-24 12:50:02 ----D---- D:\Documents and Settings\Administrateur\Application Data\Real
2008-08-24 09:38:14 ----A---- D:\WINDOWS\system32\qttask.exe
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\rmoc3260.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5032.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5016.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pncrt.dll
2008-08-24 09:36:44 ----D---- D:\WINDOWS\system32\QuickTime
2008-08-24 09:36:43 ----A---- D:\WINDOWS\mmtvmj.ini
2008-08-24 09:36:43 ----A---- D:\WINDOWS\m3jp2k.ini
2008-08-24 09:36:42 ----A---- D:\WINDOWS\m3jpeg.ini
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvpx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvm6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplva6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplapx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplam6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaa6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\cpuinf32.dll
2008-08-24 09:36:37 ----A---- D:\WINDOWS\system32\unrar.dll
2008-08-24 09:36:35 ----A---- D:\WINDOWS\system32\xvidcore.dll
2008-08-24 09:36:31 ----D---- D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 09:18:47 ----D---- D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-24 09:02:18 ----D---- D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 09:01:45 ----D---- D:\Program Files\Fichiers communs\HP
2008-08-24 09:00:39 ----D---- D:\Program Files\Hewlett-Packard
2008-08-24 09:00:19 ----D---- D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-24 08:59:43 ----RA---- D:\WINDOWS\system32\HPZIDS01.dll
2008-08-24 08:59:42 ----A---- D:\WINDOWS\system32\hpzll054.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZisn12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipt12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipm12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZinw12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZidr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\IsUninst.exe
2008-08-24 08:57:44 ----D---- D:\Program Files\HP
2008-08-24 08:56:41 ----HD---- D:\Config.Msi
2008-08-23 23:23:09 ----HDC---- D:\WINDOWS\$NtUninstallKB941569$
2008-08-23 23:22:54 ----HDC---- D:\WINDOWS\$NtUninstallKB929399$
2008-08-23 23:22:19 ----HDC---- D:\WINDOWS\$NtUninstallKB939683$
2008-08-23 23:22:04 ----D---- D:\WINDOWS\ie7updates
2008-08-23 23:22:00 ----HDC---- D:\WINDOWS\$NtUninstallKB932823-v3$
2008-08-23 23:21:55 ----D---- D:\Program Files\MSXML 4.0
2008-08-23 23:21:50 ----A---- D:\WINDOWS\system32\wmpns.dll
2008-08-23 23:21:42 ----HDC---- D:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2RC.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.ini
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcodec2.dll
2008-08-23 09:40:29 ----A---- D:\WINDOWS\IsUn040c.exe
2008-08-23 09:35:51 ----A---- D:\WINDOWS\system32\capicom.dll
2008-08-23 09:35:14 ----RA---- D:\WINDOWS\system32\InstMed.exe
2008-08-23 09:34:48 ----D---- D:\Program Files\Fichiers communs\Logitech
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\Lvkrn12n.dll
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\LCamCpl.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71u.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71KOR.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71JPN.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ITA.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ESP.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ENU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71DEU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71CHT.DLL
2008-08-23 09:34:28 ----A---- D:\WINDOWS\system32\MFC71CHS.DLL
2008-08-23 09:34:26 ----A---- D:\WINDOWS\system32\atl71.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\QCUI2.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\Ltwvc12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltkrn12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltimg12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltfil12n.DLL
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltefx12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\LTDIS12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lftif12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lffax12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\LFCMP12n.DLL
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lfbmp12n.dll
2008-08-23 09:34:21 ----A---- D:\WINDOWS\system32\LQCUI2.dll
2008-08-23 09:34:20 ----D---- D:\Program Files\Logitech
2008-08-23 09:34:07 ----R---- D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 08:38:37 ----HDC---- D:\WINDOWS\$NtUninstallKB915865$
2008-08-23 08:38:26 ----N---- D:\WINDOWS\system32\xmllite.dll
2008-08-23 08:02:58 ----D---- D:\Program Files\Sony Corporation
2008-08-23 08:02:50 ----N---- D:\WINDOWS\snymsico.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBUI.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CddbLangFR.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBControl.dll
2008-08-23 08:02:16 ----D---- D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 07:56:49 ----D---- D:\Program Files\Sony
2008-08-23 07:56:14 ----D---- D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 07:56:14 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-23 07:37:31 ----D---- D:\WINDOWS\Sun
2008-08-23 07:37:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sun
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaws.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaw.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\java.exe
2008-08-23 07:36:29 ----D---- D:\Program Files\Java
2008-08-23 07:36:20 ----A---- D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 07:36:12 ----D---- D:\Program Files\Messenger
2008-08-23 07:36:03 ----D---- D:\Program Files\Fichiers communs\Java
2008-08-22 21:26:55 ----D---- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 21:26:01 ----D---- D:\Program Files\Windows Live
2008-08-22 21:25:59 ----D---- D:\Program Files\Messenger Plus! Live
2008-08-22 21:24:53 ----D---- D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 21:24:48 ----D---- D:\Program Files\MSN Pictures Displayer
2008-08-22 21:19:10 ----DC---- D:\WINDOWS\system32\DRVSTORE
2008-08-22 21:19:05 ----D---- D:\Program Files\MSN Messenger
2008-08-22 21:07:06 ----D---- D:\Documents and Settings\Administrateur\Application Data\Macromedia
2008-08-22 21:07:05 ----D---- D:\Documents and Settings\Administrateur\Application Data\Adobe
2008-08-22 21:00:43 ----D---- D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 21:00:41 ----D---- D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-08-22 21:00:00 ----D---- D:\Program Files\Azureus
2008-08-22 19:51:26 ----D---- D:\Documents and Settings\Administrateur\Application Data\Google
2008-08-22 19:51:22 ----D---- D:\Documents and Settings\All Users\Application Data\Google
2008-08-22 19:51:11 ----D---- D:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-22 19:51:10 ----D---- D:\Program Files\Google
2008-08-22 19:31:41 ----N---- D:\WINDOWS\system32\normaliz.dll
2008-08-22 19:30:36 ----D---- D:\WINDOWS\WBEM
2008-08-22 19:30:35 ----D---- D:\WINDOWS\system32\fr-fr
2008-08-22 19:30:28 ----D---- D:\WINDOWS\%DownloadedProgramFiles%
2008-08-22 19:29:47 ----HDC---- D:\WINDOWS\ie7
2008-08-22 19:02:57 ----D---- D:\Program Files\Microsoft Works
2008-08-22 19:02:40 ----D---- D:\Program Files\Microsoft Visual Studio
2008-08-22 19:02:39 ----D---- D:\Program Files\Fichiers communs\DESIGNER
2008-08-22 19:00:09 ----D---- D:\WINDOWS\SHELLNEW
2008-08-22 18:59:49 ----D---- D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 18:59:48 ----D---- D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 18:59:31 ----RHD---- D:\MSOCache
2008-08-22 18:57:42 ----D---- D:\Documents and Settings\All Users\Application Data\Adobe
2008-08-22 18:57:34 ----D---- D:\Program Files\Fichiers communs\Adobe
2008-08-22 18:51:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-22 18:51:11 ----HDC---- D:\WINDOWS\$NtUninstallKB952954$
2008-08-22 18:51:06 ----HDC---- D:\WINDOWS\$NtUninstallKB953839$
2008-08-22 18:51:02 ----HDC---- D:\WINDOWS\$NtUninstallKB935448$
2008-08-22 18:50:57 ----HDC---- D:\WINDOWS\$NtUninstallKB950974$
2008-08-22 18:50:52 ----HDC---- D:\WINDOWS\$NtUninstallKB951698$
2008-08-22 18:50:25 ----A---- D:\WINDOWS\system32\MRT.exe
2008-08-22 18:50:19 ----HDC---- D:\WINDOWS\$NtUninstallKB950762$
2008-08-22 18:50:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-22 18:50:09 ----HDC---- D:\WINDOWS\$NtUninstallKB952287$
2008-08-22 18:50:04 ----HDC---- D:\WINDOWS\$NtUninstallKB951066$
2008-08-22 18:49:52 ----HDC---- D:\WINDOWS\$NtUninstallKB953838$
2008-08-22 18:49:43 ----HDC---- D:\WINDOWS\$NtUninstallKB951748$
2008-08-22 18:49:34 ----HDC---- D:\WINDOWS\$NtUninstallKB950749$
2008-08-22 18:49:23 ----N---- D:\WINDOWS\system32\spmsg.dll
2008-08-22 18:49:22 ----HDC---- D:\WINDOWS\$NtUninstallKB944338-v2$
2008-08-22 18:44:30 ----HDC---- D:\WINDOWS\$NtUninstallWMFDist11$
2008-08-22 18:43:40 ----D---- D:\Program Files\Windows Media Connect 2
2008-08-22 18:43:32 ----HDC---- D:\WINDOWS\$NtUninstallwmp11$
2008-08-22 18:40:13 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-08-22 18:36:35 ----A---- D:\WINDOWS\system32\BASSMOD.dll
2008-08-22 18:35:34 ----D---- D:\Program Files\WinRAR
2008-08-22 18:33:31 ----D---- D:\Program Files\QuickTime
2008-08-22 18:33:31 ----D---- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 18:33:21 ----D---- D:\Program Files\Apple Software Update
2008-08-22 18:33:21 ----D---- D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 18:28:48 ----A---- D:\WINDOWS\system32\h323log.txt
2008-08-22 18:28:21 ----A---- D:\WINDOWS\system32\ksuser.dll
2008-08-22 18:27:12 ----A---- D:\WINDOWS\system32\usbui.dll
2008-08-22 18:26:10 ----SHD---- D:\WINDOWS\Installer
2008-08-22 18:26:10 ----D---- D:\Program Files\Fichiers communs\ODBC
2008-08-22 18:26:10 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2008-08-22 18:26:10 ----A---- D:\WINDOWS\ODBCINST.INI
2008-08-22 18:26:07 ----D---- D:\Program Files\Fichiers communs\SpeechEngines
2008-08-22 18:26:06 ----RD---- D:\Program Files
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs\Microsoft Shared
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuq.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuf.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdazel.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdycc.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbduzb.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdur.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdtat.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru1.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdmon.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkyr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkaz.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdbu.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdblr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdaze.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhept.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela3.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela2.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe319.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe220.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdgkl.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdest.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdycl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdro.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz2.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcr.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\KBDAL.DLL
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\spxcoins.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\irclass.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\EqnClass.Dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgsetup.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgrpsetu.dll
2008-08-22 18:25:52 ----N---- D:\WINDOWS\system32\CONFIG.TMP
2008-08-22 18:25:52 ----A---- D:\WINDOWS\TASKMAN.EXE
2008-08-22 18:25:51 ----A---- D:\WINDOWS\system32\batt.dll
2008-08-22 18:25:51 ----A---- D:\WINDOWS\NOTEPAD.EXE
2008-08-22 18:25:50 ----A---- D:\WINDOWS\system32\storprop.dll
2008-08-22 18:25:43 ----ASH---- D:\Documents and Settings\All Users\Application Data\desktop.ini
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot2
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot
2008-08-22 18:25:23 ----SD---- D:\Documents and Settings\All Users\Application Data\Microsoft
2008-08-22 18:25:03 ----D---- D:\Documents and Settings
2008-08-22 18:24:02 ----SHD---- D:\System Volume Information
2008-08-22 18:23:58 ----D---- D:\INSTALL
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\vxblock.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxwave.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxsfs.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxmas.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxinsa64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxhpinst.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxdrv.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxcpya64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxafs.dll
2008-08-22 18:23:23 ----D---- D:\Program Files\Winamp
2008-08-22 18:23:23 ----D---- D:\Documents and Settings\Administrateur\Application Data\Winamp
2008-08-22 18:22:00 ----A---- D:\WINDOWS\NeroDigital.ini
2008-08-22 18:21:42 ----D---- D:\Documents and Settings\Administrateur\Application Data\vlc
2008-08-22 18:21:10 ----D---- D:\Program Files\VideoLAN
2008-08-22 18:20:01 ----RSHDC---- D:\WINDOWS\system32\dllcache
2008-08-22 18:20:01 ----RSD---- D:\WINDOWS\Fonts
2008-08-22 18:20:01 ----RD---- D:\WINDOWS\Web
2008-08-22 18:20:01 ----HD---- D:\WINDOWS\inf
2008-08-22 18:20:01 ----D---- D:\WINDOWS\WinSxS
2008-08-22 18:20:01 ----D---- D:\WINDOWS\twain_32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Temp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wins
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wbem
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\usmt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\spool
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ShellExt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\Setup
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ras
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\oobe
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\npp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\inetsrv
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\IME
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\icsxml
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ias
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\export
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\drivers
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\dhcp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3com_dmi
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3076
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\2052
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1054
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1042
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1041
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1037
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1036
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1033
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1031
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1028
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1025
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system
2008-08-22 18:20:01 ----D---- D:\WINDOWS\security
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Resources
2008-08-22 18:20:01 ----D---- D:\WINDOWS\repair
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Provisioning
2008-08-22 18:20:01 ----D---- D:\WINDOWS\PeerNet
2008-08-22 18:20:01 ----D---- D:\WINDOWS\pchealth
2008-08-22 18:20:01 ----D---- D:\WINDOWS\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msapps
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msagent
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Media
2008-08-22 18:20:01 ----D---- D:\WINDOWS\java
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ime
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Help
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ehome
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Driver Cache
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Debug
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Cursors
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Connection Wizard
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\AppPatch
2008-08-22 18:20:01 ----D---- D:\WINDOWS\addins
2008-08-22 18:20:01 ----D---- D:\WINDOWS
2008-08-22 18:19:35 ----D---- D:\WINDOWS\system32\PreInstall
2008-08-22 18:19:33 ----HDC---- D:\WINDOWS\$NtUninstallKB898461$
2008-08-22 18:19:33 ----HD---- D:\WINDOWS\$hf_mig$
2008-08-22 18:14:58 ----D---- D:\Documents and Settings\Administrateur\Application Data\Nero
2008-08-22 18:14:45 ----A---- D:\WINDOWS\system32\MsiExec.exe.log
2008-08-22 18:13:28 ----D---- D:\Program Files\Nero
2008-08-22 18:13:28 ----D---- D:\Program Files\Fichiers communs\Nero
2008-08-22 18:13:28 ----D---- D:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 18:10:42 ----A---- D:\WINDOWS\system32\d3dx9_30.dll
2008-08-22 18:10:41 ----A---- D:\WINDOWS\system32\d3dx9_28.dll
2008-08-22 18:08:08 ----D---- D:\Documents and Settings\Administrateur\Application Data\GigaTribe
2008-08-22 18:06:10 ----D---- D:\WINDOWS\RegisteredPackages
2008-08-22 18:03:25 ----D---- D:\Program Files\eMule
2008-08-22 18:02:50 ----D---- D:\Program Files\GigaTribe
2008-08-22 17:59:21 ----D---- D:\Temp
2008-08-22 17:59:07 ----D---- D:\Documents and Settings\Administrateur\Application Data\Syntrillium
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmvdmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmod.dll
2008-08-22 17:58:52 ----A---- D:\WINDOWS\system32\wmvcore2.dll
2008-08-22 17:57:28 ----D---- D:\Program Files\Cool Edit Pro 2.1
2008-08-22 17:54:03 ----D---- D:\Program Files\Adobe
2008-08-22 17:49:14 ----D---- D:\Program Files\Virtual Dj 3.2
2008-08-22 17:46:10 ----D---- D:\WINDOWS\system32\SoftwareDistribution
2008-08-22 17:45:03 ----D---- D:\Program Files\DAEMON Tools Lite
2008-08-22 17:43:01 ----D---- D:\Documents and Settings\Administrateur\Application Data\DAEMON Tools
2008-08-22 17:40:58 ----A---- D:\WINDOWS\system32\TUKernel.exe
2008-08-22 17:23:05 ----A---- D:\WINDOWS\system32\uxtuneup.dll
2008-08-22 17:23:04 ----D---- D:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-08-22 17:23:04 ----A---- D:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-22 17:22:52 ----D---- D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-22 17:22:50 ----D---- D:\Program Files\TuneUp Utilities 2008
2008-08-22 17:22:38 ----D---- D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-22 17:11:51 ----SHD---- D:\RECYCLER
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\msvcp71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\MFC71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\aswBoot.exe
2008-08-22 17:09:57 ----D---- D:\Program Files\Avast4
2008-08-22 17:04:39 ----A---- D:\WINDOWS\system32\PsisDecd.dll
2008-08-22 17:04:38 ----A---- D:\WINDOWS\system32\vfwwdm32.dll
2008-08-22 17:04:08 ----A---- D:\WINDOWS\system32\hidserv.dll
2008-08-22 17:04:02 ----D---- D:\Program Files\X10 Hardware
2008-08-22 17:04:02 ----D---- D:\Program Files\Common Files
2008-08-22 17:04:02 ----A---- D:\WINDOWS\Unwise.exe
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr71.dll
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr70.dll
2008-08-22 17:03:49 ----D---- D:\Program Files\Intel
2008-08-22 17:03:19 ----HD---- D:\Program Files\InstallShield Installation Information
2008-08-22 16:56:28 ----D---- D:\WINDOWS\nview
2008-08-22 16:56:27 ----A---- D:\WINDOWS\system32\nvudisp.exe
2008-08-22 16:56:21 ----A---- D:\WINDOWS\system32\NVUNINST.EXE
2008-08-22 16:56:18 ----D---- D:\Program Files\Fichiers communs\InstallShield
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nwiz.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwssr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwss.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszht.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszhc.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrstr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssv.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssk.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsru.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsptb.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspt.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsno.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsnl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsko.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsja.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvsvc32.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvdspsch.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcplui.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcolor.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvappbar.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\keystone.exe
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsit.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshu.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshe.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsesm.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrses.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrseng.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsel.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsde.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsda.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrscs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsar.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwimg.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwdmcpl.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwddi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvsr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvshell.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszht.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszhc.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrstr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssv.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssk.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsru.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsptb.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspt.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsno.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsnl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsko.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsja.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsit.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshu.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshe.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfi.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsesm.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrses.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrseng.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsel.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsde.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsda.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrscs.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsar.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvoglnt.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvnt4cpl.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmoblsr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmobls.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmctray.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccssr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccss.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccsrs.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccs.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nview.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvhwvid.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgamesr.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgames.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvexpbar.dll
2008-08-22 16:56:11 ----A---- D:\WINDOWS\system32\nvdispsr.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvdisps.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvcpluir.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcpl.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcodins.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcod.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvapi.dll
2008-08-22 16:56:08 ----A---- D:\WINDOWS\system32\nv4_disp.dll
2008-08-22 16:46:13 ----D---- D:\WINDOWS\system32\Lang
2008-08-22 16:44:30 ----D---- D:\WINDOWS\system32\RTCOM
2008-08-22 16:44:27 ----D---- D:\WINDOWS\system32\ReinstallBackups
2008-08-22 16:44:12 ----A---- D:\WINDOWS\system32\spupdsvc.exe
2008-08-22 16:44:11 ----HDC---- D:\WINDOWS\$NtUninstallKB888111WXPSP2$
2008-08-22 16:43:50 ----D---- D:\pnp
2008-08-22 16:38:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Identities
2008-08-22 16:38:30 ----HD---- D:\Program Files\Uninstall Information
2008-08-22 16:36:20 ----ASH---- D:\Documents and Settings\Administrateur\Application Data\desktop.ini
2008-08-22 16:36:19 ----SD---- D:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-08-22 16:36:14 ----D---- D:\WINDOWS\SoftwareDistribution
2008-08-22 16:36:11 ----SD---- D:\WINDOWS\system32\Microsoft
2008-08-22 16:36:11 ----N---- D:\WINDOWS\SchedLgU.Txt
2008-08-22 16:36:11 ----D---- D:\WINDOWS\Prefetch
2008-08-22 16:33:18 ----D---- D:\WINDOWS\system32\xircom
2008-08-22 16:33:18 ----D---- D:\Program Files\xerox
2008-08-22 16:33:18 ----D---- D:\Program Files\msn gaming zone
2008-08-22 16:33:18 ----D---- D:\Program Files\movie maker
2008-08-22 16:33:18 ----D---- D:\Program Files\microsoft frontpage
2008-08-22 16:33:01 ----A---- D:\WINDOWS\control.ini
2008-08-22 16:32:47 ----A---- D:\WINDOWS\system32\mapi32.dll
2008-08-22 16:32:04 ----SD---- D:\WINDOWS\Downloaded Program Files
2008-08-22 16:32:04 ----RD---- D:\WINDOWS\Offline Web Pages
2008-08-22 16:32:04 ----RAH---- D:\WINDOWS\system32\logonui.exe.manifest
2008-08-22 16:31:58 ----RAH---- D:\WINDOWS\system32\cdplayer.exe.manifest
2008-08-22 16:31:54 ----HD---- D:\Program Files\WindowsUpdate
2008-08-22 16:31:52 ----D---- D:\Program Files\Services en ligne
2008-08-22 16:31:38 ----D---- D:\WINDOWS\system32\DirectX
2008-08-22 16:31:19 ----A---- D:\WINDOWS\system32\atrace.dll
2008-08-22 16:31:17 ----A---- D:\WINDOWS\system32\desktop.ini
2008-08-22 16:31:17 ----A---- D:\WINDOWS\desktop.ini
2008-08-22 16:31:11 ----A---- D:\WINDOWS\system32\nmevtmsg.dll
2008-08-22 16:31:10 ----A---- D:\WINDOWS\system32\acctres.dll
2008-08-22 16:31:09 ----D---- D:\Program Files\Fichiers communs\Services
2008-08-22 16:31:07 ----SD---- D:\WINDOWS\Tasks
2008-08-22 16:31:07 ----A---- D:\WINDOWS\system32\icfgnt5.dll
2008-08-22 16:31:06 ----D---- D:\Program Files\Fichiers communs\MSSoap
2008-08-22 16:31:02 ----D---- D:\WINDOWS\system32\Macromed
2008-08-22 16:31:02 ----D---- D:\WINDOWS\srchasst
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuweb.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wucltui.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuauserv.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuaueng1.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wups.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuaueng.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt1.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuapi.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgrprxy.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgr.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx3.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx2.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrslv.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrdm.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrcdlg.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\racpldlg.dll
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltMc.exe
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltlib.dll
2008-08-22 16:30:50 ----D---- D:\WINDOWS\system32\Restore
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srsvc.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srrstr.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srclient.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\nmmkcert.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\msconf.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmsrvc.exe
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmdd.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\isrdbg32.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\ils.dll
2008-08-22 16:30:46 ----D---- D:\Program Files\NetMeeting
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoert2.dll
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoeacct.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetres.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetcomm.dll
2008-08-22 16:30:44 ----D---- D:\Program Files\Outlook Express
2008-08-22 16:30:44 ----A---- D:\WINDOWS\system32\schedsvc.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstinit.exe
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstask.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\isign32.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\inetcfg.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwphbk.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwdial.dll
2008-08-22 16:30:38 ----D---- D:\Program Files\Fichiers communs\System
2008-08-22 16:30:37 ----D---- D:\Program Files\Internet Explorer
2008-08-22 16:30:09 ----D---- D:\Program Files\ComPlus Applications
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vbaddin.ini
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vb.ini
2008-08-22 16:30:04 ----D---- D:\WINDOWS\Registration
2008-08-22 16:29:58 ----D---- D:\Program Files\Windows Media Player
2008-08-22 16:29:55 ----A---- D:\WINDOWS\system32\write.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\sndvol32.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\hticons.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\winchat.exe
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avwav.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avtapi.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avmeter.dll
2008-08-22 16:29:43 ----A---- D:\WINDOWS\system32\getuname.dll
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\usrlogon.cmd
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsshutdn.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tslabels.ini
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tskill.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsdiscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\shadow.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\reset.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\charmap.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\calc.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\regini.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rdpcfgex.dll
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qappsrv.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msg.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msdtcprf.ini
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\logoff.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\cdmodem.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\stclient.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxlegih.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxex.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxdm.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\dcomcnfg.exe
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comrepl.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comaddin.dll
2008-08-22 16:29:39 ----A---- D:\WINDOWS\system32\comsnap.dll
2008-08-22 16:29:35 ----A---- D:\WINDOWS\system32\wmimgmt.msc
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\sndrec32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\mplay32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\accwiz.exe
2008-08-22 16:29:33 ----D---- D:\Program Files\Windows NT
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\mspaint.exe
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\hypertrm.dll
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\clipbrd.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\tscfgwmi.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\sessmgr.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\remotepg.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdshost.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdsaddin.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstscax.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstsc.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\tscupgrd.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\termsrv.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpwsx.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpsnd.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpclip.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdchost.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\qprocess.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\icaapi.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\cfgbkend.dll
2008-08-22 16:29:30 ----D---- D:\WINDOWS\system32\MsDtc
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\xolehlp.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\mtxoci.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcuiu.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtctm.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcprx.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtclog.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtc.

Répondre à nigga_nigga

12

sKe69, le 4 oct 2008 à 16:18:06

Bien ,

1- Que toutes tes unités externes ( DD externes, clé USB, flash disques , ect ) soient branchées au PC . Tu ne les débrancheras que lorsque je te le dirai ...


2- Avoir accès aux fichiers cachés :

Vas dans Menu Démarrer->Poste de travail->Outils->Options des dossiers...->Affichage
* "Afficher les fichiers et dossiers cachés" ---> coché
* "Masquer les extensions des fichiers dont le type est connu" ---> décoché
* "masquer les fichiers du système" ---> décoché
-> valides la modif ( "appliquer" puis "ok" ).
( tu remetteras les paramètres de départ une fois la désinfection terminée , pas avant ... )


3- Rends toi sur ce site :

http://www.virustotal.com/

Copies ce qui suit et colles le dans l'espace pour la recherche :
D:\WINDOWS\boot.ini

Cliques sur Send File ( = " Envoyer le fichier " ).

Un rapport va s'élaborer ligne à ligne.

Attends bien la fin ... Il doit comprendre la taille du fichier envoyé.

Sauvegarde le rapport avec le bloc-note.

Copies le dans ta prochaine réponse ...

( Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant )


Fais de même pour :
D:\.MS32DLL.dll.vbs

postes moi donc ces 2 rapports ( surtout le début avec le listing des AV , et en précisant bien au début de chacuns à quel fichier ils correspondent ) et attends la suite ...
Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

13

nigga_nigga, le 4 oct 2008 à 17:12:06

Pour le D:\WINDOWS\boot.ini,le rapport est le suivant

Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.10.3.2 2008.10.03 VBS/Solow.Gen
AntiVir 7.8.1.34 2008.10.04 HTML/Rce.Gen
Authentium 5.1.0.4 2008.10.04 VBS/Solow.A
Avast 4.8.1248.0 2008.10.04 VBS:Solow
AVG 8.0.0.161 2008.10.04 VBS/Small
BitDefender 7.2 2008.10.04 Generic.ScriptWorm.EE5BBFA8
CAT-QuickHeal 9.50 2008.10.04 VBS/Sasan.A
ClamAV 0.93.1 2008.10.04 VBS.Flesh-1
DrWeb 4.44.0.09170 2008.10.04 VBS.Generic.548
eSafe 7.0.17.0 2008.10.02 -
eTrust-Vet 31.6.6129 2008.10.04 VBS/Slogod.B
Ewido 4.0 2008.10.04 -
F-Prot 4.4.4.56 2008.10.03 VBS/Solow.A
F-Secure 8.0.14332.0 2008.10.04 Worm.VBS.Sasan.a
Fortinet 3.113.0.0 2008.10.04 -
GData 19 2008.10.04 Generic.ScriptWorm.EE5BBFA8
Ikarus T3.1.1.34.0 2008.10.04 Worm.VBS.Sasan.a
K7AntiVirus 7.10.484 2008.10.04 Worm.VBS.Sasan.a
Kaspersky 7.0.0.125 2008.10.04 Worm.VBS.Sasan.a
McAfee 5398 2008.10.04 VBS/Pica.worm.gen
Microsoft 1.4005 2008.10.04 Worm:VBS/Slows.A
NOD32 3494 2008.10.03 VBS/Pica.NAA
Norman 5.80.02 2008.10.03 VBS/Solow.I
Panda 9.0.0.4 2008.10.04 VBS/Sasan.A.worm
PCTools 4.4.2.0 2008.10.04 Worm.VBS.Sasan.A
Prevx1 V2 2008.10.04 -
Rising 20.63.62.00 2008.09.28 VBS.NoExp
SecureWeb-Gateway 6.7.6 2008.10.04 Heuristic.Script.Rce
Sophos 4.34.0 2008.10.04 VBS/Sasan-C
Sunbelt 3.1.1675.1 2008.09.27 -
Symantec 10 2008.10.04 VBS.Solow
TheHacker 6.3.1.0.100 2008.10.03 -
TrendMicro 8.700.0.1004 2008.10.03 VBS_SASAN.A
VBA32 3.12.8.6 2008.10.03 -
ViRobot 2008.10.4.1406 2008.10.04 VBS.Sasan.7790
VirusBuster 4.5.11.0 2008.10.04 Worm.VBS.Sasan.A
Information additionnelle
File size: 91796 bytes
MD5...: b8be75d5ebc0b1f4b2665d5a32c1a3b8
SHA1..: 120f97071db33d5bb88fe4f5a62a9c44c938990c
SHA256: a1b0e6962386bf11f8adc77ff39e4080f8716c4a024b9b927bb9ce6b197f­8e1d
SHA512: ca03817783718cbc238abe583e11b61869733c8c45d2a4b440f56650722a­313e
8e1e50d5128e579349e8a751eb9790c7bc986cb3156c6a832932526d76a3­a74b
PEiD..: -
TrID..: File type identification
Text - UTF-16 (LE) encoded (64.4%)
MP3 audio (32.2%)
Lumena CEL bitmap (2.0%)
Corel Photo Paint (1.3%)
PEInfo: -
packers (F-Prot): Unicode
packers (Authentium): Unicode




pour le D:\.MS32DLL.dll.vbs le rapport est le suivant:

0 bytes size received / Se ha recibido un archivo vacio


par contre,lorsque j'ai decoché "masquer les fichiers du système" ca m'a mis un msg d avertissement...dans le genre que ca pouvait mettre en peril l ordi et qu il ne pourrait ne plus fonctionner correctement !!!
neanmoins j ai suivi tes conseils !
qu est ce que je peux risquer en faisant ca ?

Répondre à nigga_nigga

14

sKe69, le 4 oct 2008 à 17:45:31

Re,

qu est ce que je peux risquer en faisant --> rien tant que tu ne touches pas aux fichiers dont l'apparence est légèrement blanchatre ...

fais exactement ce qui suit :

Télécharges ComboFix (par sUBs) sur ton Bureau (et pas ailleurs !):

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


--------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
!! Déconnectes toi,fermes tes applications en cours et DESACTIVES TOUTES TES DEFENSES (anti-virus, guardes anti spy-ware, pare-feu) le temps de la manipe :
en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
--->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
Tuto ( aide ) ici : http://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

---------------------------------------------------------------------------------------------------------------------------------

Ensuite :
double-cliques sur l'icône "combofix.exe" pour lancer l'outil .

Appuyes sur la touche Y (Yes) pour démarrer le scan .

Notes importantes :
-> n'utilises pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
-> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisses le faire .
-> Si l'outil t'anonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarer votre machine", tu acceptes ...
-> si un message d'erreur windows apparait à un momment : cliques sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

Le rapport sera crée dans: C:\Combofix.txt

Postes le rapport Combofix accompagné d'un nouveau rapport hijackthis pour analyse ...

Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

15

nigga_nigga, le 4 oct 2008 à 18:21:50

J ai bien suivi tes instructions et ca a l'air d'avoir bien fonctionné a priori....

Rapport combo fix:

ComboFix 08-10-03.06 - Did 2008-10-04 18:11:31.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.647 [GMT 2:00]
Lancé depuis: D:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé

[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\.MS32DLL.dll.vbs
C:\Autorun.inf
D:\.MS32DLL.dll.vbs
D:\autorun.inf
D:\Documents and Settings\Administrateur\Cookies\did@ad.yieldmanager[1].txt
D:\Documents and Settings\Aurore\Cookies\aurore@bluestreak[1].txt
D:\Documents and Settings\Aurore\Cookies\aurore@ems6[1].txt
D:\Documents and Settings\Aurore\Cookies\aurore@linternaute[1].txt
D:\Documents and Settings\Aurore\Cookies\aurore@metaffiliation[1].txt
D:\Documents and Settings\Aurore\Cookies\aurore@reussissonsensemble[2].txt
D:\Documents and Settings\Aurore\Cookies\aurore@tradedoubler[1].txt
D:\Documents and Settings\Aurore\Cookies\aurore@www.etreenceinte[1].txt
D:\install\install.exe
D:\WINDOWS\.MS32DLL.dll.vbs
D:\WINDOWS\boot.ini
D:\WINDOWS\system32\rtl60.bpl
G:\.MS32DLL.dll.vbs
G:\autorun.inf
I:\Autorun.inf
O:\.MS32DLL.dll.vbs
O:\Autorun.inf
shellexecute=wscript.exe .MS32DLL.dll.vbsI:\.MS32DLL.dll.vbs

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MCHINJDRV
-------\Service_mchInjDrv


((((((((((((((((((((((((((((( Fichiers créés du 2008-09-04 au 2008-10-04 ))))))))))))))))))))))))))))))))))))
.

2008-10-04 13:51 . 2008-10-04 13:52 <REP> d-------- D:\rsit
2008-10-04 13:29 . 2008-10-04 13:29 <REP> d-------- D:\Program Files\CCleaner
2008-10-04 12:43 . 2008-10-04 13:09 1,944 --a------ D:\Documents and Settings\Orph.egd
2008-10-04 12:41 . 2008-10-04 13:10 <REP> d-------- D:\ToolBar SD
2008-10-04 09:47 . 2008-10-04 09:47 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:47 . 2008-10-04 09:47 <REP> d-------- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:16 . 2008-10-04 12:34 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03 . 2008-10-04 09:03 <REP> d-------- D:\Program Files\Trend Micro
2008-09-05 15:41 . 2008-09-05 15:41 <REP> d--h----- D:\WINDOWS\system32\GroupPolicy

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-04 10:26 --------- d-----w D:\Program Files\eMule
2008-10-04 06:40 --------- d-----w D:\Program Files\Avast4
2008-10-03 21:55 --------- d-----w D:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-03 16:22 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-09-28 16:39 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\GigaTribe
2008-09-25 08:16 --------- d-----w D:\Program Files\MSN Messenger
2008-09-25 08:16 --------- d-----w D:\Program Files\Messenger Plus! Live
2008-09-14 14:53 --------- d-----w D:\Program Files\TuneUp Utilities 2008
2008-08-31 14:15 --------- d-----w D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 14:14 --------- d-----w D:\Program Files\Siber Systems
2008-08-31 08:01 --------- d-----w D:\Program Files\GigaTribe
2008-08-31 07:24 2,290,176 ----a-w D:\WINDOWS\system32\TUKernel.exe
2008-08-29 17:59 --------- d-----w D:\Program Files\La Marmite du Chef
2008-08-29 06:44 --------- d-----w D:\Program Files\SuperCopier2
2008-08-28 14:38 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Winamp
2008-08-26 08:50 --------- d---a-w D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 06:33 --------- d-----w D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 06:29 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-25 15:22 --------- d-----w D:\Program Files\MappySynchro
2008-08-25 14:50 --------- d-----w D:\Program Files\Microsoft ActiveSync
2008-08-24 13:17 --------- d-----w D:\Documents and Settings\Aurore\Application Data\MSN Pictures Displayer
2008-08-24 07:48 --------- d-----w D:\Documents and Settings\Aurore\Application Data\Nero
2008-08-24 07:47 --------- d-----w D:\Documents and Settings\Aurore\Application Data\HP
2008-08-24 07:38 98,304 ----a-w D:\WINDOWS\system32\qttask.exe
2008-08-24 07:38 --------- d-----w D:\Program Files\QuickTime
2008-08-24 07:37 --------- d-----w D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 07:26 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-24 07:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 07:01 --------- d-----w D:\Program Files\HP
2008-08-24 07:01 --------- d-----w D:\Program Files\Fichiers communs\HP
2008-08-24 07:00 --------- d-----w D:\Program Files\Hewlett-Packard
2008-08-24 07:00 --------- d-----w D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-23 21:21 --------- d-----w D:\Program Files\MSXML 4.0
2008-08-23 07:34 81,920 ------r D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 07:34 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-08-23 07:34 --------- d-----w D:\Program Files\Logitech
2008-08-23 07:34 --------- d-----w D:\Program Files\Fichiers communs\Logitech
2008-08-23 07:24 --------- d-----w D:\Program Files\Azureus
2008-08-23 06:22 --------- d-----w D:\Documents and Settings\Aurore\Application Data\vlc
2008-08-23 06:03 --------- d-----w D:\Program Files\Sony
2008-08-23 06:03 --------- d-----w D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 06:02 --------- d-----w D:\Program Files\Sony Corporation
2008-08-23 06:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 05:56 --------- d-----w D:\Program Files\Fichiers communs\InstallShield
2008-08-23 05:38 --------- d-----w D:\Program Files\MSN Pictures Displayer
2008-08-23 05:36 446,976 ----a-w D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 05:36 --------- d-----w D:\Program Files\Java
2008-08-23 05:36 --------- d-----w D:\Program Files\Fichiers communs\Java
2008-08-22 19:26 --------- d-----w D:\Program Files\Windows Live
2008-08-22 19:26 --------- d-----w D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 19:24 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 19:00 --------- d-----w D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 17:58 --------- d-----w D:\Program Files\Google
2008-08-22 17:42 --------- d-----w D:\Documents and Settings\Aurore\Application Data\TuneUp Software
2008-08-22 17:31 20,480 ------w D:\WINDOWS\system32\normaliz.dll
2008-08-22 17:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 17:02 --------- d-----w D:\Program Files\Microsoft Works
2008-08-22 17:02 --------- d-----w D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 16:57 --------- d-----w D:\Program Files\Fichiers communs\Adobe
2008-08-22 16:43 --------- d-----w D:\Program Files\Windows Media Connect 2
2008-08-22 16:33 --------- d-----w D:\Program Files\Apple Software Update
2008-08-22 16:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 16:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 16:25 --------- d-----w D:\Program Files\Winamp
2008-08-22 16:21 --------- d-----w D:\Program Files\VideoLAN
2008-08-22 16:21 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\vlc
2008-08-22 16:14 --------- d-----w D:\Program Files\Fichiers communs\Nero
2008-08-22 16:14 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Nero
2008-08-22 16:13 --------- d-----w D:\Program Files\Nero
2008-08-22 16:13 --------- d-----w D:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 16:07 --------- d-----w D:\Program Files\DAEMON Tools Lite
2008-08-22 16:02 --------- d-----w D:\Program Files\Cool Edit Pro 2.1
2008-08-22 15:59 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Syntrillium
2008-08-22 15:52 --------- d-----w D:\Program Files\Virtual Dj 3.2
2008-08-22 15:43 717,296 ----a-w D:\WINDOWS\system32\drivers\sptd.sys
2008-08-22 15:43 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\DAEMON Tools
2008-08-22 15:24 355,584 ----a-w D:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-22 15:23 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-08-22 15:22 --------- d-----w D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-22 15:22 --------- d-----w D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-22 15:05 --------- d-----w D:\Documents and Settings\LocalService\Application Data\X10 Commander
2008-08-22 15:04 --------- d-----w D:\Program Files\X10 Hardware
2008-08-22 15:04 --------- d-----w D:\Program Files\Common Files
2008-08-22 15:03 --------- d-----w D:\Program Files\Intel
2008-08-22 14:33 --------- d-----w D:\Program Files\microsoft frontpage
2008-08-22 14:31 --------- d-----w D:\Program Files\Services en ligne
2008-07-18 20:10 94,920 ----a-w D:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w D:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w D:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w D:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w D:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w D:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w D:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w D:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w D:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w D:\WINDOWS\system32\muweb.dll
2008-07-07 20:31 253,952 ----a-w D:\WINDOWS\system32\es.dll
.

------- Sigcheck -------

2004-08-23 00:35 1036288 998f3f568f6074a35ab08cd3395a9dc2 D:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="D:\Program Files\SuperCopier2\SuperCopier2.exe" [2005-03-14 1057280]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-22 39408]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"RoboForm"="D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2006-06-01 7618560]
"LVCOMSX"="D:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"rkfree"="D:\WINDOWS\Winreveal\rkfree.exe" [2008-08-26 66048]
"QuickTime Task"="D:\WINDOWS\system32\qttask.exe" [2008-08-24 98304]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-29 D:\WINDOWS\RTHDCPL.EXE]

D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="D:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\iac25_32.ax
"vidc.avrn"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avidavicodec.dll
"vidc.advj"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avidavicodec.dll
"vidc.mszh"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avimszh.dll
"vidc.zlib"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avizlib.dll
"msacm.lameacm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\lameacm.acm
"vidc.asv1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv1.dll
"vidc.asv2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv2.dll
"vidc.asvx"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv2.dll
"vidc.div3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.div5"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.mpg3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.div4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.div6"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.ap41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.dvx4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\divx4.dll
"vidc.divx"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivX520.dll
"msacm.divxa32"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\divxa32.acm
"vidc.i263"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\i263_32.drv
"vidc.iv30"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv31"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv32"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv33"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv34"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv35"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv36"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv37"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv38"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv39"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv40"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv42"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv43"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv44"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv45"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv46"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv47"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv48"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv49"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv50"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir50_32.dll
"vidc.iyuv"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\Iyvu9_32.dll
"vidc.ir21"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IR21_R.DLL
"vidc.rt21"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IR21_R.DLL
"msacm.imc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IMC32.ACM
"vidc.dv25"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.dv50"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.msmc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mmjp"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx5"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx6"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx7"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx8"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx9"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mmes"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"msacm.msadpcm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msadp32.acm
"msacm.imaadpcm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\imaadp32.acm
"msacm.msg711"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msg711.acm
"msacm.msg723"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msg723.acm
"msacm.msgsm610"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msgsm32.acm
"vidc.m261"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh261.drv
"vidc.m263"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh263.drv
"vidc.i420"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh263.drv
"vidc.mrle"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msrle32.dll
"vidc.uyvy"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.yuy2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.yvyu"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.msvc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msvidc32.dll
"vidc.cram"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msvidc32.dll
"vidc.mpg4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp42"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp43"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp4s"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp4v"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.wmv3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\WMV9VCM.dll
"msacm.msaudio1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msaud32.acm
"msacm.vorbis"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\OGG\vorbis.acm
"vidc.pdvc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Panasonic\idvcodec.dll
"vidc.ipdv"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Panasonic\idvcodec.dll
"vidc.miro"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\mirodv2avi.dll
"vidc.dcap"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\mirodv2avi.dll
"vidc.mjpa"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\rtmjpgcdc.dll
"vidc.gpjm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\rtmjpgcdc.dll
"vidc.pim1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\pclepim1.dll
"vidc.xvid"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\XviD\xvidvfw.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\GigaTribe\\gigatribe.exe"=
"D:\\Program Files\\Microsoft Office Professional Plus 2007\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Azureus\\Azureus.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"= D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"= D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;D:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 UxTuneUp;TuneUp Extension de thème;D:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 3xHybrid;3xHybrid service;D:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
R3 X10Hid;X10 Hid Device;D:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 7040]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;D:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-22 355584]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - MCHINJDRV
.
Contenu du dossier 'Tâches planifiées'

2008-10-04 D:\WINDOWS\Tasks\Maintenance en 1 clic.job
- D:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:23]
.
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.orange.fr/
R0 -: HKLM-Main,Window Title =
R1 -: HKCU-Internet Settings,ProxyOverride = localhost
O8 -: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 -: E&xporter vers Microsoft Excel - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 -: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 -: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 -: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O17 -: HKLM\CCS\Interface\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 -: HKLM\CCS\Interface\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 18:14:59
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp"
.
------------------------ Autres processus actifs ------------------------
.
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\PROGRA~1\Common Files\X10\Common\X10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Heure de fin: 2008-10-04 18:16:03 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-04 16:15:58

Avant-CF: 32 334 778 368 octets libres
Après-CF: 32,442,576,896 octets libres

352 --- E O F --- 2008-09-13 20:54:16



rapport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:17, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\notepad.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 8777 bytes



NB: je me suis aperçu avant d utiliser combo... que mes icones avast (presde l horloge) avait disparues...j ai pu quand meme desactiver l'AV...

Répondre à nigga_nigga

16

sKe69, le 4 oct 2008 à 18:31:49

Bien ... La suite dans l'ordre :


1- pour l'icône d'Avast :

vas dans "C:\program files", puis recherche le dossier "alwil" (Avast) .
Tu rentres dedans et recherches " ashDisp.exe " -> tu cliques dessus ---> l´icone d´avast devrait réaparaitre ...


2- refais un coup de CCleaner ( registre compris ) .


3- débranches toutes tes unités externes du PC ( gardes les sous la mains , tu vas devoir les rebranchées par la suite ) .


4- Télécharges Flash_Disinfector de sUBs ici :

http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe

Enregistres le sur ton bureau.

Double cliques sur Flash_Disinfector.exe pour le lancer ...

Quand le message : "Plug in yours flash drive & clic Ok to begin disinfection" apparaitra :
->connectes toutes tes clés USB et périphériques USB externes susceptibles d'avoir été infectés .

Puis clique sur Ok .

Les icônes sur le bureau vont disparaitre jusqu'à l'apparition du message: " Done!! "

Appuye sur "Ok", pour faire réapparaitre le bureau ...


5 -refais un scan RSIT et postes moi le nouveau rapport pour analyse ....
Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

17

nigga_nigga, le 4 oct 2008 à 18:44:12

Rapport scan rsit


Logfile of random's system information tool 1.04 (written by random/random)
Run by Did at 2008-10-04 18:40:45
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 31 GB (80%) free of 39 GB
Total RAM: 1023 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:40, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\Program Files\Avast4\ashDisp.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\WINDOWS\explorer.exe
D:\Documents and Settings\Administrateur\Bureau\Utilitaires II\Random System Information Tool.exe
D:\Program Files\Trend Micro\HijackThis\Did.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 8840 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Maintenance en 1 clic.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}]
D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - d:\program files\google\googletoolbar1.dll [2008-08-22 2582136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll [2008-08-22 651760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2005-06-29 14720000]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2006-06-01 7618560]
"LVCOMSX"=D:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
"rkfree"=D:\WINDOWS\Winreveal\rkfree.exe [2008-08-26 66048]
"QuickTime Task"=D:\WINDOWS\system32\qttask.exe [2008-08-24 98304]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=D:\Program Files\SuperCopier2\SuperCopier2.exe [2005-03-14 1057280]
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-22 39408]
"H/PC Connection Agent"=D:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"RoboForm"=D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2008-09-28 160592]

D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=FFFFFFFF
"NoDriveTypeAutoRun"=36

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\GigaTribe\gigatribe.exe"="D:\Program Files\GigaTribe\gigatribe.exe:*:Enabled:gigatribe"
"D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Azureus\Azureus.exe"="D:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Messenger\msmsgs.exe"="D:\Program Files\Messenger\msmsgs.exe:*:Enabled:Messenger"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="D:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======List of files/folders created in the last 3 months======

2008-10-04 18:39:58 ----RASHD---- D:\autorun.inf
2008-10-04 18:36:17 ----SHD---- D:\RECYCLER
2008-10-04 18:16:04 ----A---- D:\ComboFix.txt
2008-10-04 18:11:15 ----D---- D:\WINDOWS\erdnt
2008-10-04 18:10:56 ----D---- D:\QooBox
2008-10-04 18:10:54 ----A---- D:\WINDOWS\zip.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\VFind.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\swxcacls.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\SWSC.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\SWREG.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\sed.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\Nircmd.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\grep.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\fdsv.exe
2008-10-04 13:51:56 ----D---- D:\rsit
2008-10-04 13:29:01 ----D---- D:\Program Files\CCleaner
2008-10-04 13:10:18 ----A---- D:\TB II.txt
2008-10-04 12:43:23 ----A---- D:\TB.txt
2008-10-04 12:41:46 ----D---- D:\ToolBar SD
2008-10-04 09:47:20 ----D---- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:47:17 ----D---- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:16:06 ----D---- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03:49 ----D---- D:\Program Files\Trend Micro
2008-09-13 22:53:25 ----HDC---- D:\WINDOWS\$NtUninstallKB938464$
2008-09-13 22:53:16 ----HDC---- D:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-05 15:41:37 ----HD---- D:\WINDOWS\system32\GroupPolicy
2008-09-01 00:57:18 ----D---- D:\Documents and Settings\Administrateur\Application Data\Help
2008-08-31 16:15:50 ----D---- D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 16:14:48 ----D---- D:\Program Files\Siber Systems
2008-08-29 19:59:20 ----D---- D:\Program Files\La Marmite du Chef
2008-08-29 08:43:55 ----D---- D:\Program Files\SuperCopier2
2008-08-26 10:50:02 ----AD---- D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 10:49:50 ----D---- D:\WINDOWS\Winreveal
2008-08-26 10:49:39 ----D---- D:\Nouveau dossier
2008-08-26 08:33:15 ----D---- D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 08:31:54 ----D---- D:\WINDOWS\system32\CatRoot_bak
2008-08-25 16:59:20 ----D---- D:\Program Files\MappySynchro
2008-08-25 16:53:14 ----D---- D:\WINDOWS\LastGood
2008-08-25 16:50:24 ----HDC---- D:\WINDOWS\$NtUninstallKB909394$
2008-08-25 16:50:07 ----D---- D:\Program Files\Microsoft ActiveSync
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\muweb.dll
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll.mui
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll
2008-08-24 14:43:17 ----HD---- D:\WINDOWS\Icons
2008-08-24 12:50:02 ----D---- D:\Documents and Settings\Administrateur\Application Data\Real
2008-08-24 09:38:14 ----A---- D:\WINDOWS\system32\qttask.exe
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\rmoc3260.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5032.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5016.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pncrt.dll
2008-08-24 09:36:44 ----D---- D:\WINDOWS\system32\QuickTime
2008-08-24 09:36:43 ----A---- D:\WINDOWS\mmtvmj.ini
2008-08-24 09:36:43 ----A---- D:\WINDOWS\m3jp2k.ini
2008-08-24 09:36:42 ----A---- D:\WINDOWS\m3jpeg.ini
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvpx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvm6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplva6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplapx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplam6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaa6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\cpuinf32.dll
2008-08-24 09:36:37 ----A---- D:\WINDOWS\system32\unrar.dll
2008-08-24 09:36:35 ----A---- D:\WINDOWS\system32\xvidcore.dll
2008-08-24 09:36:31 ----D---- D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 09:18:47 ----D---- D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-24 09:02:18 ----D---- D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 09:01:45 ----D---- D:\Program Files\Fichiers communs\HP
2008-08-24 09:00:39 ----D---- D:\Program Files\Hewlett-Packard
2008-08-24 09:00:19 ----D---- D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-24 08:59:43 ----RA---- D:\WINDOWS\system32\HPZIDS01.dll
2008-08-24 08:59:42 ----A---- D:\WINDOWS\system32\hpzll054.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZisn12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipt12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipm12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZinw12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZidr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\IsUninst.exe
2008-08-24 08:57:44 ----D---- D:\Program Files\HP
2008-08-24 08:56:41 ----HD---- D:\Config.Msi
2008-08-23 23:23:09 ----HDC---- D:\WINDOWS\$NtUninstallKB941569$
2008-08-23 23:22:54 ----HDC---- D:\WINDOWS\$NtUninstallKB929399$
2008-08-23 23:22:19 ----HDC---- D:\WINDOWS\$NtUninstallKB939683$
2008-08-23 23:22:04 ----D---- D:\WINDOWS\ie7updates
2008-08-23 23:22:00 ----HDC---- D:\WINDOWS\$NtUninstallKB932823-v3$
2008-08-23 23:21:55 ----D---- D:\Program Files\MSXML 4.0
2008-08-23 23:21:50 ----A---- D:\WINDOWS\system32\wmpns.dll
2008-08-23 23:21:42 ----HDC---- D:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2RC.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.ini
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcodec2.dll
2008-08-23 09:40:29 ----A---- D:\WINDOWS\IsUn040c.exe
2008-08-23 09:35:51 ----A---- D:\WINDOWS\system32\capicom.dll
2008-08-23 09:35:14 ----RA---- D:\WINDOWS\system32\InstMed.exe
2008-08-23 09:34:48 ----D---- D:\Program Files\Fichiers communs\Logitech
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\Lvkrn12n.dll
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\LCamCpl.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71u.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71KOR.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71JPN.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ITA.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ESP.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ENU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71DEU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71CHT.DLL
2008-08-23 09:34:28 ----A---- D:\WINDOWS\system32\MFC71CHS.DLL
2008-08-23 09:34:26 ----A---- D:\WINDOWS\system32\atl71.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\QCUI2.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\Ltwvc12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltkrn12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltimg12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltfil12n.DLL
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltefx12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\LTDIS12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lftif12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lffax12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\LFCMP12n.DLL
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lfbmp12n.dll
2008-08-23 09:34:21 ----A---- D:\WINDOWS\system32\LQCUI2.dll
2008-08-23 09:34:20 ----D---- D:\Program Files\Logitech
2008-08-23 09:34:07 ----R---- D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 08:38:37 ----HDC---- D:\WINDOWS\$NtUninstallKB915865$
2008-08-23 08:38:26 ----N---- D:\WINDOWS\system32\xmllite.dll
2008-08-23 08:02:58 ----D---- D:\Program Files\Sony Corporation
2008-08-23 08:02:50 ----N---- D:\WINDOWS\snymsico.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBUI.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CddbLangFR.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBControl.dll
2008-08-23 08:02:16 ----D---- D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 07:56:49 ----D---- D:\Program Files\Sony
2008-08-23 07:56:14 ----D---- D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 07:56:14 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-23 07:37:31 ----D---- D:\WINDOWS\Sun
2008-08-23 07:37:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sun
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaws.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaw.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\java.exe
2008-08-23 07:36:29 ----D---- D:\Program Files\Java
2008-08-23 07:36:20 ----A---- D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 07:36:12 ----D---- D:\Program Files\Messenger
2008-08-23 07:36:03 ----D---- D:\Program Files\Fichiers communs\Java
2008-08-22 21:26:55 ----D---- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 21:26:01 ----D---- D:\Program Files\Windows Live
2008-08-22 21:25:59 ----D---- D:\Program Files\Messenger Plus! Live
2008-08-22 21:24:53 ----D---- D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 21:24:48 ----D---- D:\Program Files\MSN Pictures Displayer
2008-08-22 21:19:10 ----DC---- D:\WINDOWS\system32\DRVSTORE
2008-08-22 21:19:05 ----D---- D:\Program Files\MSN Messenger
2008-08-22 21:07:06 ----D---- D:\Documents and Settings\Administrateur\Application Data\Macromedia
2008-08-22 21:07:05 ----D---- D:\Documents and Settings\Administrateur\Application Data\Adobe
2008-08-22 21:00:43 ----D---- D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 21:00:41 ----D---- D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-08-22 21:00:00 ----D---- D:\Program Files\Azureus
2008-08-22 19:51:26 ----D---- D:\Documents and Settings\Administrateur\Application Data\Google
2008-08-22 19:51:22 ----D---- D:\Documents and Settings\All Users\Application Data\Google
2008-08-22 19:51:11 ----D---- D:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-22 19:51:10 ----D---- D:\Program Files\Google
2008-08-22 19:31:41 ----N---- D:\WINDOWS\system32\normaliz.dll
2008-08-22 19:30:36 ----D---- D:\WINDOWS\WBEM
2008-08-22 19:30:35 ----D---- D:\WINDOWS\system32\fr-fr
2008-08-22 19:30:28 ----D---- D:\WINDOWS\%DownloadedProgramFiles%
2008-08-22 19:29:47 ----HDC---- D:\WINDOWS\ie7
2008-08-22 19:02:57 ----D---- D:\Program Files\Microsoft Works
2008-08-22 19:02:40 ----D---- D:\Program Files\Microsoft Visual Studio
2008-08-22 19:02:39 ----D---- D:\Program Files\Fichiers communs\DESIGNER
2008-08-22 19:00:09 ----D---- D:\WINDOWS\SHELLNEW
2008-08-22 18:59:49 ----D---- D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 18:59:48 ----D---- D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 18:59:31 ----RHD---- D:\MSOCache
2008-08-22 18:57:42 ----D---- D:\Documents and Settings\All Users\Application Data\Adobe
2008-08-22 18:57:34 ----D---- D:\Program Files\Fichiers communs\Adobe
2008-08-22 18:51:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-22 18:51:11 ----HDC---- D:\WINDOWS\$NtUninstallKB952954$
2008-08-22 18:51:06 ----HDC---- D:\WINDOWS\$NtUninstallKB953839$
2008-08-22 18:51:02 ----HDC---- D:\WINDOWS\$NtUninstallKB935448$
2008-08-22 18:50:57 ----HDC---- D:\WINDOWS\$NtUninstallKB950974$
2008-08-22 18:50:52 ----HDC---- D:\WINDOWS\$NtUninstallKB951698$
2008-08-22 18:50:25 ----A---- D:\WINDOWS\system32\MRT.exe
2008-08-22 18:50:19 ----HDC---- D:\WINDOWS\$NtUninstallKB950762$
2008-08-22 18:50:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-22 18:50:09 ----HDC---- D:\WINDOWS\$NtUninstallKB952287$
2008-08-22 18:50:04 ----HDC---- D:\WINDOWS\$NtUninstallKB951066$
2008-08-22 18:49:52 ----HDC---- D:\WINDOWS\$NtUninstallKB953838$
2008-08-22 18:49:43 ----HDC---- D:\WINDOWS\$NtUninstallKB951748$
2008-08-22 18:49:34 ----HDC---- D:\WINDOWS\$NtUninstallKB950749$
2008-08-22 18:49:23 ----N---- D:\WINDOWS\system32\spmsg.dll
2008-08-22 18:49:22 ----HDC---- D:\WINDOWS\$NtUninstallKB944338-v2$
2008-08-22 18:44:30 ----HDC---- D:\WINDOWS\$NtUninstallWMFDist11$
2008-08-22 18:43:40 ----D---- D:\Program Files\Windows Media Connect 2
2008-08-22 18:43:32 ----HDC---- D:\WINDOWS\$NtUninstallwmp11$
2008-08-22 18:40:13 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-08-22 18:36:35 ----A---- D:\WINDOWS\system32\BASSMOD.dll
2008-08-22 18:35:34 ----D---- D:\Program Files\WinRAR
2008-08-22 18:33:31 ----D---- D:\Program Files\QuickTime
2008-08-22 18:33:31 ----D---- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 18:33:21 ----D---- D:\Program Files\Apple Software Update
2008-08-22 18:33:21 ----D---- D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 18:28:48 ----A---- D:\WINDOWS\system32\h323log.txt
2008-08-22 18:28:21 ----A---- D:\WINDOWS\system32\ksuser.dll
2008-08-22 18:27:12 ----A---- D:\WINDOWS\system32\usbui.dll
2008-08-22 18:26:10 ----SHD---- D:\WINDOWS\Installer
2008-08-22 18:26:10 ----D---- D:\Program Files\Fichiers communs\ODBC
2008-08-22 18:26:10 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2008-08-22 18:26:10 ----A---- D:\WINDOWS\ODBCINST.INI
2008-08-22 18:26:07 ----D---- D:\Program Files\Fichiers communs\SpeechEngines
2008-08-22 18:26:06 ----RD---- D:\Program Files
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs\Microsoft Shared
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuq.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuf.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdazel.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdycc.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbduzb.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdur.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdtat.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru1.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdmon.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkyr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkaz.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdbu.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdblr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdaze.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhept.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela3.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela2.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe319.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe220.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdgkl.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdest.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdycl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdro.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz2.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcr.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\KBDAL.DLL
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\spxcoins.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\irclass.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\EqnClass.Dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgsetup.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgrpsetu.dll
2008-08-22 18:25:52 ----N---- D:\WINDOWS\system32\CONFIG.TMP
2008-08-22 18:25:52 ----A---- D:\WINDOWS\TASKMAN.EXE
2008-08-22 18:25:51 ----A---- D:\WINDOWS\system32\batt.dll
2008-08-22 18:25:51 ----A---- D:\WINDOWS\NOTEPAD.EXE
2008-08-22 18:25:50 ----A---- D:\WINDOWS\system32\storprop.dll
2008-08-22 18:25:43 ----ASH---- D:\Documents and Settings\All Users\Application Data\desktop.ini
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot2
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot
2008-08-22 18:25:23 ----SD---- D:\Documents and Settings\All Users\Application Data\Microsoft
2008-08-22 18:25:03 ----D---- D:\Documents and Settings
2008-08-22 18:24:02 ----SHD---- D:\System Volume Information
2008-08-22 18:23:58 ----D---- D:\INSTALL
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\vxblock.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxwave.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxsfs.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxmas.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxinsa64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxhpinst.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxdrv.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxcpya64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxafs.dll
2008-08-22 18:23:23 ----D---- D:\Program Files\Winamp
2008-08-22 18:23:23 ----D---- D:\Documents and Settings\Administrateur\Application Data\Winamp
2008-08-22 18:22:00 ----A---- D:\WINDOWS\NeroDigital.ini
2008-08-22 18:21:42 ----D---- D:\Documents and Settings\Administrateur\Application Data\vlc
2008-08-22 18:21:10 ----D---- D:\Program Files\VideoLAN
2008-08-22 18:20:01 ----RSHDC---- D:\WINDOWS\system32\dllcache
2008-08-22 18:20:01 ----RSD---- D:\WINDOWS\Fonts
2008-08-22 18:20:01 ----RD---- D:\WINDOWS\Web
2008-08-22 18:20:01 ----HD---- D:\WINDOWS\inf
2008-08-22 18:20:01 ----D---- D:\WINDOWS\WinSxS
2008-08-22 18:20:01 ----D---- D:\WINDOWS\twain_32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Temp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wins
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wbem
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\usmt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\spool
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ShellExt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\Setup
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ras
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\oobe
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\npp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\inetsrv
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\IME
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\icsxml
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ias
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\export
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\drivers
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\dhcp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3com_dmi
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3076
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\2052
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1054
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1042
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1041
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1037
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1036
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1033
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1031
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1028
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1025
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system
2008-08-22 18:20:01 ----D---- D:\WINDOWS\security
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Resources
2008-08-22 18:20:01 ----D---- D:\WINDOWS\repair
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Provisioning
2008-08-22 18:20:01 ----D---- D:\WINDOWS\PeerNet
2008-08-22 18:20:01 ----D---- D:\WINDOWS\pchealth
2008-08-22 18:20:01 ----D---- D:\WINDOWS\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msapps
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msagent
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Media
2008-08-22 18:20:01 ----D---- D:\WINDOWS\java
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ime
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Help
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ehome
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Driver Cache
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Debug
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Cursors
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Connection Wizard
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\AppPatch
2008-08-22 18:20:01 ----D---- D:\WINDOWS\addins
2008-08-22 18:20:01 ----D---- D:\WINDOWS
2008-08-22 18:19:35 ----D---- D:\WINDOWS\system32\PreInstall
2008-08-22 18:19:33 ----HDC---- D:\WINDOWS\$NtUninstallKB898461$
2008-08-22 18:19:33 ----HD---- D:\WINDOWS\$hf_mig$
2008-08-22 18:14:58 ----D---- D:\Documents and Settings\Administrateur\Application Data\Nero
2008-08-22 18:14:45 ----A---- D:\WINDOWS\system32\MsiExec.exe.log
2008-08-22 18:13:28 ----D---- D:\Program Files\Nero
2008-08-22 18:13:28 ----D---- D:\Program Files\Fichiers communs\Nero
2008-08-22 18:13:28 ----D---- D:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 18:10:42 ----A---- D:\WINDOWS\system32\d3dx9_30.dll
2008-08-22 18:10:41 ----A---- D:\WINDOWS\system32\d3dx9_28.dll
2008-08-22 18:08:08 ----D---- D:\Documents and Settings\Administrateur\Application Data\GigaTribe
2008-08-22 18:06:10 ----D---- D:\WINDOWS\RegisteredPackages
2008-08-22 18:03:25 ----D---- D:\Program Files\eMule
2008-08-22 18:02:50 ----D---- D:\Program Files\GigaTribe
2008-08-22 17:59:21 ----D---- D:\Temp
2008-08-22 17:59:07 ----D---- D:\Documents and Settings\Administrateur\Application Data\Syntrillium
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmvdmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmod.dll
2008-08-22 17:58:52 ----A---- D:\WINDOWS\system32\wmvcore2.dll
2008-08-22 17:57:28 ----D---- D:\Program Files\Cool Edit Pro 2.1
2008-08-22 17:54:03 ----D---- D:\Program Files\Adobe
2008-08-22 17:49:14 ----D---- D:\Program Files\Virtual Dj 3.2
2008-08-22 17:46:10 ----D---- D:\WINDOWS\system32\SoftwareDistribution
2008-08-22 17:45:03 ----D---- D:\Program Files\DAEMON Tools Lite
2008-08-22 17:43:01 ----D---- D:\Documents and Settings\Administrateur\Application Data\DAEMON Tools
2008-08-22 17:40:58 ----A---- D:\WINDOWS\system32\TUKernel.exe
2008-08-22 17:23:05 ----A---- D:\WINDOWS\system32\uxtuneup.dll
2008-08-22 17:23:04 ----D---- D:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-08-22 17:23:04 ----A---- D:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-22 17:22:52 ----D---- D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-22 17:22:50 ----D---- D:\Program Files\TuneUp Utilities 2008
2008-08-22 17:22:38 ----D---- D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\msvcp71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\MFC71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\aswBoot.exe
2008-08-22 17:09:57 ----D---- D:\Program Files\Avast4
2008-08-22 17:04:39 ----A---- D:\WINDOWS\system32\PsisDecd.dll
2008-08-22 17:04:38 ----A---- D:\WINDOWS\system32\vfwwdm32.dll
2008-08-22 17:04:08 ----A---- D:\WINDOWS\system32\hidserv.dll
2008-08-22 17:04:02 ----D---- D:\Program Files\X10 Hardware
2008-08-22 17:04:02 ----D---- D:\Program Files\Common Files
2008-08-22 17:04:02 ----A---- D:\WINDOWS\Unwise.exe
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr71.dll
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr70.dll
2008-08-22 17:03:49 ----D---- D:\Program Files\Intel
2008-08-22 17:03:19 ----HD---- D:\Program Files\InstallShield Installation Information
2008-08-22 16:56:28 ----D---- D:\WINDOWS\nview
2008-08-22 16:56:27 ----A---- D:\WINDOWS\system32\nvudisp.exe
2008-08-22 16:56:21 ----A---- D:\WINDOWS\system32\NVUNINST.EXE
2008-08-22 16:56:18 ----D---- D:\Program Files\Fichiers communs\InstallShield
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nwiz.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwssr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwss.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszht.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszhc.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrstr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssv.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssk.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsru.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsptb.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspt.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsno.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsnl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsko.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsja.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvsvc32.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvdspsch.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcplui.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcolor.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvappbar.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\keystone.exe
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsit.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshu.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshe.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsesm.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrses.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrseng.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsel.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsde.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsda.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrscs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsar.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwimg.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwdmcpl.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwddi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvsr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvshell.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszht.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszhc.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrstr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssv.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssk.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsru.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsptb.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspt.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsno.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsnl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsko.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsja.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsit.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshu.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshe.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfi.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsesm.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrses.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrseng.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsel.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsde.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsda.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrscs.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsar.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvoglnt.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvnt4cpl.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmoblsr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmobls.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmctray.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccssr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccss.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccsrs.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccs.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nview.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvhwvid.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgamesr.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgames.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvexpbar.dll
2008-08-22 16:56:11 ----A---- D:\WINDOWS\system32\nvdispsr.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvdisps.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvcpluir.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcpl.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcodins.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcod.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvapi.dll
2008-08-22 16:56:08 ----A---- D:\WINDOWS\system32\nv4_disp.dll
2008-08-22 16:46:13 ----D---- D:\WINDOWS\system32\Lang
2008-08-22 16:44:30 ----D---- D:\WINDOWS\system32\RTCOM
2008-08-22 16:44:27 ----D---- D:\WINDOWS\system32\ReinstallBackups
2008-08-22 16:44:12 ----A---- D:\WINDOWS\system32\spupdsvc.exe
2008-08-22 16:44:11 ----HDC---- D:\WINDOWS\$NtUninstallKB888111WXPSP2$
2008-08-22 16:43:50 ----D---- D:\pnp
2008-08-22 16:38:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Identities
2008-08-22 16:38:30 ----HD---- D:\Program Files\Uninstall Information
2008-08-22 16:36:20 ----ASH---- D:\Documents and Settings\Administrateur\Application Data\desktop.ini
2008-08-22 16:36:19 ----SD---- D:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-08-22 16:36:14 ----D---- D:\WINDOWS\SoftwareDistribution
2008-08-22 16:36:11 ----SD---- D:\WINDOWS\system32\Microsoft
2008-08-22 16:36:11 ----N---- D:\WINDOWS\SchedLgU.Txt
2008-08-22 16:36:11 ----D---- D:\WINDOWS\Prefetch
2008-08-22 16:33:18 ----D---- D:\WINDOWS\system32\xircom
2008-08-22 16:33:18 ----D---- D:\Program Files\xerox
2008-08-22 16:33:18 ----D---- D:\Program Files\msn gaming zone
2008-08-22 16:33:18 ----D---- D:\Program Files\movie maker
2008-08-22 16:33:18 ----D---- D:\Program Files\microsoft frontpage
2008-08-22 16:33:01 ----A---- D:\WINDOWS\control.ini
2008-08-22 16:32:47 ----A---- D:\WINDOWS\system32\mapi32.dll
2008-08-22 16:32:04 ----SD---- D:\WINDOWS\Downloaded Program Files
2008-08-22 16:32:04 ----RD---- D:\WINDOWS\Offline Web Pages
2008-08-22 16:32:04 ----RAH---- D:\WINDOWS\system32\logonui.exe.manifest
2008-08-22 16:31:58 ----RAH---- D:\WINDOWS\system32\cdplayer.exe.manifest
2008-08-22 16:31:54 ----HD---- D:\Program Files\WindowsUpdate
2008-08-22 16:31:52 ----D---- D:\Program Files\Services en ligne
2008-08-22 16:31:38 ----D---- D:\WINDOWS\system32\DirectX
2008-08-22 16:31:19 ----A---- D:\WINDOWS\system32\atrace.dll
2008-08-22 16:31:17 ----A---- D:\WINDOWS\system32\desktop.ini
2008-08-22 16:31:17 ----A---- D:\WINDOWS\desktop.ini
2008-08-22 16:31:11 ----A---- D:\WINDOWS\system32\nmevtmsg.dll
2008-08-22 16:31:10 ----A---- D:\WINDOWS\system32\acctres.dll
2008-08-22 16:31:09 ----D---- D:\Program Files\Fichiers communs\Services
2008-08-22 16:31:07 ----SD---- D:\WINDOWS\Tasks
2008-08-22 16:31:07 ----A---- D:\WINDOWS\system32\icfgnt5.dll
2008-08-22 16:31:06 ----D---- D:\Program Files\Fichiers communs\MSSoap
2008-08-22 16:31:02 ----D---- D:\WINDOWS\system32\Macromed
2008-08-22 16:31:02 ----D---- D:\WINDOWS\srchasst
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuweb.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wucltui.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuauserv.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuaueng1.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wups.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuaueng.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt1.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuapi.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgrprxy.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgr.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx3.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx2.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrslv.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrdm.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrcdlg.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\racpldlg.dll
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltMc.exe
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltlib.dll
2008-08-22 16:30:50 ----D---- D:\WINDOWS\system32\Restore
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srsvc.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srrstr.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srclient.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\nmmkcert.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\msconf.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmsrvc.exe
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmdd.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\isrdbg32.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\ils.dll
2008-08-22 16:30:46 ----D---- D:\Program Files\NetMeeting
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoert2.dll
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoeacct.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetres.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetcomm.dll
2008-08-22 16:30:44 ----D---- D:\Program Files\Outlook Express
2008-08-22 16:30:44 ----A---- D:\WINDOWS\system32\schedsvc.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstinit.exe
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstask.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\isign32.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\inetcfg.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwphbk.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwdial.dll
2008-08-22 16:30:38 ----D---- D:\Program Files\Fichiers communs\System
2008-08-22 16:30:37 ----D---- D:\Program Files\Internet Explorer
2008-08-22 16:30:09 ----D---- D:\Program Files\ComPlus Applications
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vbaddin.ini
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vb.ini
2008-08-22 16:30:04 ----D---- D:\WINDOWS\Registration
2008-08-22 16:29:58 ----D---- D:\Program Files\Windows Media Player
2008-08-22 16:29:55 ----A---- D:\WINDOWS\system32\write.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\sndvol32.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\hticons.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\winchat.exe
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avwav.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avtapi.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avmeter.dll
2008-08-22 16:29:43 ----A---- D:\WINDOWS\system32\getuname.dll
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\usrlogon.cmd
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsshutdn.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tslabels.ini
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tskill.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsdiscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\shadow.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\reset.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\charmap.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\calc.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\regini.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rdpcfgex.dll
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qappsrv.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msg.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msdtcprf.ini
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\logoff.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\cdmodem.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\stclient.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxlegih.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxex.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxdm.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\dcomcnfg.exe
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comrepl.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comaddin.dll
2008-08-22 16:29:39 ----A---- D:\WINDOWS\system32\comsnap.dll
2008-08-22 16:29:35 ----A---- D:\WINDOWS\system32\wmimgmt.msc
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\sndrec32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\mplay32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\accwiz.exe
2008-08-22 16:29:33 ----D---- D:\Program Files\Windows NT
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\mspaint.exe
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\hypertrm.dll
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\clipbrd.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\tscfgwmi.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\sessmgr.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\remotepg.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdshost.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdsaddin.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstscax.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstsc.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\tscupgrd.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\termsrv.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpwsx.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpsnd.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpclip.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdchost.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\qprocess.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\icaapi.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\cfgbkend.dll
2008-08-22 16:29:30 ----D---- D:\WINDOWS\system32\MsDtc
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\xolehlp.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\mtxoci.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcuiu.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtctm.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcprx.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtclog.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtc.exe
2008-08-22 16:29:29 ----D---- D:\WINDOWS\system32\Com
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\colbact.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\clbcatex.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\catsrvut.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\catsrvps.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\catsrv.dll
2008-08-22 16:29:28 ----A---- D:\WINDOWS\system32\comuid.dll
2008-08-22 16:29:28 ----A---- D:\WINDOWS\system32\comsvcs.dll
2008-08-22 16:29:28 ----A---- D:\WINDOWS\system32\clbcatq.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\servdeps.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\mmfutil.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\licwmi.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\cmprops.dll
2008-07-14 13:09:18 ----N---- D:\WINDOWS\system32\tzchange.exe

======List of files/folders modified in the last 3 months======

2008-10-04 18:14:54 ----A---- D:\WINDOWS\system.ini
2008-09-27 21:36:06 ----A---- D:\WINDOWS\win.ini
2008-07-18 22:10:48 ----A---- D:\WINDOWS\system32\cdm.dll
2008-07-18 22:10:40 ----A---- D:\WINDOWS\system32\wups2.dll
2008-07-18 22:10:36 ----A---- D:\WINDOWS\system32\wucltui.dll.mui
2008-07-18 22:09:14 ----A---- D:\WINDOWS\system32\wuapi.dll.mui
2008-07-18 22:09:06 ----A---- D:\WINDOWS\system32\wuaueng.dll.mui
2008-07-07 22:31:48 ----A---- D:\WINDOWS\system32\es.dll

======List of dr

Répondre à nigga_nigga

18

sKe69, le 4 oct 2008 à 18:49:35

Re,

peux-tu me poster la fin du rapport stp ... du chappitre :

======List of files/folders modified in the last 3 months======


à la fin ... merci ... =) Rien ne sert de courir .... Non, ça sert à rien ...    ---sK­e---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

19

nigga_nigga, le 4 oct 2008 à 18:57:13

======List of files/folders modified in the last 3 months======

2008-10-04 18:14:54 ----A---- D:\WINDOWS\system.ini
2008-09-27 21:36:06 ----A---- D:\WINDOWS\win.ini
2008-07-18 22:10:48 ----A---- D:\WINDOWS\system32\cdm.dll
2008-07-18 22:10:40 ----A---- D:\WINDOWS\system32\wups2.dll
2008-07-18 22:10:36 ----A---- D:\WINDOWS\system32\wucltui.dll.mui
2008-07-18 22:09:14 ----A---- D:\WINDOWS\system32\wuapi.dll.mui
2008-07-18 22:09:06 ----A---- D:\WINDOWS\system32\wuaueng.dll.mui
2008-07-07 22:31:48 ----A---- D:\WINDOWS\system32\es.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
R1 aswSP;avast! Self Protection; D:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
R1 intelppm;Pilote de processeur Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 40320]
R1 kbdhid;Pilote HID de clavier; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
R3 3xHybrid;3xHybrid service; D:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
R3 Arp1394;Protocole client ARP 1394; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 aswRdr;aswRdr; D:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Pilote de classe HID Microsoft; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-24 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-06-29 3173888]
R3 LVUSBSta;Logitech USB Monitor Filter; D:\WINDOWS\system32\drivers\lvusbsta.sys [2005-05-27 22016]
R3 mouhid;Pilote HID de souris; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-24 12288]
R3 NIC1394;Pilote réseau 1394; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-06-01 3925920]
R3 pepifilter;Volume Adapter; D:\WINDOWS\system32\DRIVERS\lv302af.sys [2005-05-27 7136]
R3 PID_08A0;QuickCam IM(PID_08A0); D:\WINDOWS\system32\DRIVERS\LV302AV.SYS [2005-05-27 913280]
R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); D:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 usbaudio;Pilote USB audio (WDM); D:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Concentrateur USB2; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Pilote de stockage de masse USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 X10Hid;X10 Hid Device; D:\WINDOWS\System32\Drivers\x10hid.sys [2005-11-28 7040]
S3 a2c4r172;a2c4r172; D:\WINDOWS\system32\drivers\a2c4r172.sys []
S3 catchme;catchme; \??\D:\ComboFix\catchme.sys []
S3 CCDECODE;Décodeur sous-titre fermé; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; D:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; D:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; D:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; D:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 MPE;Filtre BDA MPE; D:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;Détrameur décalage BDA; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Classe d'imprimantes USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 wceusbsh;Windows CE USB Serial Host Driver; D:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Codec Teletext standard; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; D:\Program Files\Avast4\aswUpdSv.exe [2008-07-19 16056]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\Avast4\ashServ.exe [2008-07-19 147640]
R2 gusvc;Google Updater Service; D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-22 137200]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2006-06-01 155715]
R2 UxTuneUp;TuneUp Extension de thème; D:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 x10nets;X10 Device Network Service; D:\PROGRA~1\Common Files\X10\Common\x10nets.exe [2001-11-12 20480]
R3 avast! Mail Scanner;avast! Mail Scanner; D:\Program Files\Avast4\ashMaiSv.exe [2008-07-19 250040]
R3 avast! Web Scanner;avast! Web Scanner; D:\Program Files\Avast4\ashWebSv.exe [2008-07-23 348344]
S2 Pml Driver HPZ12;Pml Driver HPZ12; D:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
S3 NMIndexingService;NMIndexingService; D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PACSPTISVR;PACSPTISVR; D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe [2004-10-29 53337]
S3 SPTISRV;Sony SPTI Service; D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe [2004-10-29 69718]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; D:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-22 355584]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; D:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; D:\Program Files\Windows Media Player\wmpnetwk.exe [2006-10-24 918016]

-----------------EOF-----------------

Répondre à nigga_nigga

20

sKe69, le 4 oct 2008 à 19:05:36

Bon ... on continue :

1-Crées un doc texte sur ton bureau :
pointes ta souris sur ton bureau , cliques droit : vas dans "nouveau" et choisis "document texte" .

Ensuite copie/colle le texte ci-dessous ( et rien d'autre!) dans le fichier texte que tu viens de créer :

File::
D:\WINDOWS\system32\drivers\a2c4r172.sys

Service::
a2c4r172



Puis vas dans "fichier" et choisis "enregistrer sous ..." et tu le nommes exactement ainsi :
CFScript puis valides ...


2-Nettoyage :

!! Déconnectes toi, fermes toutes tes applications et désactives TOUTES TES DEFENSES ( tu les réactiveras après ) !!

--->Sur ton bureau, fais un glissé avec ta souris le fichier CFScript sur l'icône de ComboFix.exe .

(Regarde ici : http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript.gif )

Cette manipulation va relancer combofix .
--> Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tapes 1 puis valide.

Puis patientes le temps du scan.( Le Bureau va disparaître à plusieurs reprises : c'est normal!)

!! Ne touches à rien tant que le scan n'est pas terminé !!

Note : en fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisses-le faire.

Une fois le scan achevé, un rapport va s'afficher : Postes le accompagné d' un nouveau rapport RSIT ( et surtout la fin ;) ) pour analyse ...


( Attention : cette manipe a été fait pour ce PC . Toute réutilisation peut endommager sévèrement le système d'exploitation ) Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

21

nigga_nigga, le 4 oct 2008 à 19:29:39

Rapport combofix





ComboFix 08-10-04.01 - Did 2008-10-04 19:18:46.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.623 [GMT 2:00]
Lancé depuis: D:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: D:\Documents and Settings\Administrateur\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé

[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR

FILE ::
D:\WINDOWS\system32\drivers\a2c4r172.sys
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MCHINJDRV


((((((((((((((((((((((((((((( Fichiers créés du 2008-09-04 au 2008-10-04 ))))))))))))))))))))))))))))))))))))
.

2008-10-04 13:51 . 2008-10-04 13:52 <REP> d-------- D:\rsit
2008-10-04 13:29 . 2008-10-04 13:29 <REP> d-------- D:\Program Files\CCleaner
2008-10-04 12:43 . 2008-10-04 13:09 1,944 --a------ D:\Documents and Settings\Orph.egd
2008-10-04 12:41 . 2008-10-04 13:10 <REP> d-------- D:\ToolBar SD
2008-10-04 09:47 . 2008-10-04 09:47 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:47 . 2008-10-04 09:47 <REP> d-------- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:16 . 2008-10-04 12:34 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03 . 2008-10-04 09:03 <REP> d-------- D:\Program Files\Trend Micro
2008-09-05 15:41 . 2008-09-05 15:41 <REP> d--h----- D:\WINDOWS\system32\GroupPolicy

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-04 10:26 --------- d-----w D:\Program Files\eMule
2008-10-04 06:40 --------- d-----w D:\Program Files\Avast4
2008-10-03 21:55 --------- d-----w D:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-03 16:22 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-09-28 16:39 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\GigaTribe
2008-09-25 08:16 --------- d-----w D:\Program Files\MSN Messenger
2008-09-25 08:16 --------- d-----w D:\Program Files\Messenger Plus! Live
2008-09-14 14:53 --------- d-----w D:\Program Files\TuneUp Utilities 2008
2008-08-31 14:15 --------- d-----w D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 14:14 --------- d-----w D:\Program Files\Siber Systems
2008-08-31 08:01 --------- d-----w D:\Program Files\GigaTribe
2008-08-31 07:24 2,290,176 ----a-w D:\WINDOWS\system32\TUKernel.exe
2008-08-29 17:59 --------- d-----w D:\Program Files\La Marmite du Chef
2008-08-29 06:44 --------- d-----w D:\Program Files\SuperCopier2
2008-08-28 14:38 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Winamp
2008-08-26 08:50 --------- d---a-w D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 06:33 --------- d-----w D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 06:29 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-25 15:22 --------- d-----w D:\Program Files\MappySynchro
2008-08-25 14:50 --------- d-----w D:\Program Files\Microsoft ActiveSync
2008-08-24 13:17 --------- d-----w D:\Documents and Settings\Aurore\Application Data\MSN Pictures Displayer
2008-08-24 07:48 --------- d-----w D:\Documents and Settings\Aurore\Application Data\Nero
2008-08-24 07:47 --------- d-----w D:\Documents and Settings\Aurore\Application Data\HP
2008-08-24 07:38 98,304 ----a-w D:\WINDOWS\system32\qttask.exe
2008-08-24 07:38 --------- d-----w D:\Program Files\QuickTime
2008-08-24 07:37 --------- d-----w D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 07:26 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-24 07:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 07:01 --------- d-----w D:\Program Files\HP
2008-08-24 07:01 --------- d-----w D:\Program Files\Fichiers communs\HP
2008-08-24 07:00 --------- d-----w D:\Program Files\Hewlett-Packard
2008-08-24 07:00 --------- d-----w D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-23 21:21 --------- d-----w D:\Program Files\MSXML 4.0
2008-08-23 07:34 81,920 ------r D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 07:34 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-08-23 07:34 --------- d-----w D:\Program Files\Logitech
2008-08-23 07:34 --------- d-----w D:\Program Files\Fichiers communs\Logitech
2008-08-23 07:24 --------- d-----w D:\Program Files\Azureus
2008-08-23 06:22 --------- d-----w D:\Documents and Settings\Aurore\Application Data\vlc
2008-08-23 06:03 --------- d-----w D:\Program Files\Sony
2008-08-23 06:03 --------- d-----w D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 06:02 --------- d-----w D:\Program Files\Sony Corporation
2008-08-23 06:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 05:56 --------- d-----w D:\Program Files\Fichiers communs\InstallShield
2008-08-23 05:38 --------- d-----w D:\Program Files\MSN Pictures Displayer
2008-08-23 05:36 446,976 ----a-w D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 05:36 --------- d-----w D:\Program Files\Java
2008-08-23 05:36 --------- d-----w D:\Program Files\Fichiers communs\Java
2008-08-22 19:26 --------- d-----w D:\Program Files\Windows Live
2008-08-22 19:26 --------- d-----w D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 19:24 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 19:00 --------- d-----w D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 17:58 --------- d-----w D:\Program Files\Google
2008-08-22 17:42 --------- d-----w D:\Documents and Settings\Aurore\Application Data\TuneUp Software
2008-08-22 17:31 20,480 ------w D:\WINDOWS\system32\normaliz.dll
2008-08-22 17:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 17:02 --------- d-----w D:\Program Files\Microsoft Works
2008-08-22 17:02 --------- d-----w D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 16:57 --------- d-----w D:\Program Files\Fichiers communs\Adobe
2008-08-22 16:43 --------- d-----w D:\Program Files\Windows Media Connect 2
2008-08-22 16:33 --------- d-----w D:\Program Files\Apple Software Update
2008-08-22 16:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 16:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 16:25 --------- d-----w D:\Program Files\Winamp
2008-08-22 16:21 --------- d-----w D:\Program Files\VideoLAN
2008-08-22 16:21 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\vlc
2008-08-22 16:14 --------- d-----w D:\Program Files\Fichiers communs\Nero
2008-08-22 16:14 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Nero
2008-08-22 16:13 --------- d-----w D:\Program Files\Nero
2008-08-22 16:13 --------- d-----w D:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 16:07 --------- d-----w D:\Program Files\DAEMON Tools Lite
2008-08-22 16:02 --------- d-----w D:\Program Files\Cool Edit Pro 2.1
2008-08-22 15:59 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Syntrillium
2008-08-22 15:52 --------- d-----w D:\Program Files\Virtual Dj 3.2
2008-08-22 15:43 717,296 ----a-w D:\WINDOWS\system32\drivers\sptd.sys
2008-08-22 15:43 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\DAEMON Tools
2008-08-22 15:24 355,584 ----a-w D:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-22 15:23 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-08-22 15:22 --------- d-----w D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-22 15:22 --------- d-----w D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-22 15:05 --------- d-----w D:\Documents and Settings\LocalService\Application Data\X10 Commander
2008-08-22 15:04 --------- d-----w D:\Program Files\X10 Hardware
2008-08-22 15:04 --------- d-----w D:\Program Files\Common Files
2008-08-22 15:03 --------- d-----w D:\Program Files\Intel
2008-08-22 14:33 --------- d-----w D:\Program Files\microsoft frontpage
2008-08-22 14:31 --------- d-----w D:\Program Files\Services en ligne
2008-07-18 20:10 94,920 ----a-w D:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w D:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w D:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w D:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w D:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w D:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w D:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w D:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w D:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w D:\WINDOWS\system32\muweb.dll
2008-07-07 20:31 253,952 ----a-w D:\WINDOWS\system32\es.dll
.

------- Sigcheck -------

2004-08-23 00:35 1036288 998f3f568f6074a35ab08cd3395a9dc2 D:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-10-04_18.15.30.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-04 17:22:00 16,384 ----atw D:\WINDOWS\Temp\Perflib_Perfdata_498.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="D:\Program Files\SuperCopier2\SuperCopier2.exe" [2005-03-14 1057280]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-22 39408]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"RoboForm"="D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2006-06-01 7618560]
"LVCOMSX"="D:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"rkfree"="D:\WINDOWS\Winreveal\rkfree.exe" [2008-08-26 66048]
"QuickTime Task"="D:\WINDOWS\system32\qttask.exe" [2008-08-24 98304]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-29 D:\WINDOWS\RTHDCPL.EXE]

D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="D:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\iac25_32.ax
"vidc.avrn"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avidavicodec.dll
"vidc.advj"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avidavicodec.dll
"vidc.mszh"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avimszh.dll
"vidc.zlib"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avizlib.dll
"msacm.lameacm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\lameacm.acm
"vidc.asv1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv1.dll
"vidc.asv2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv2.dll
"vidc.asvx"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv2.dll
"vidc.div3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.div5"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.mpg3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.div4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.div6"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.ap41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.dvx4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\divx4.dll
"vidc.divx"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivX520.dll
"msacm.divxa32"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\divxa32.acm
"vidc.i263"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\i263_32.drv
"vidc.iv30"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv31"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv32"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv33"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv34"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv35"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv36"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv37"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv38"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv39"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv40"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv42"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv43"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv44"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv45"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv46"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv47"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv48"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv49"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv50"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir50_32.dll
"vidc.iyuv"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\Iyvu9_32.dll
"vidc.ir21"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IR21_R.DLL
"vidc.rt21"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IR21_R.DLL
"msacm.imc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IMC32.ACM
"vidc.dv25"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.dv50"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.msmc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mmjp"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx5"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx6"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx7"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx8"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx9"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mmes"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"msacm.msadpcm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msadp32.acm
"msacm.imaadpcm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\imaadp32.acm
"msacm.msg711"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msg711.acm
"msacm.msg723"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msg723.acm
"msacm.msgsm610"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msgsm32.acm
"vidc.m261"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh261.drv
"vidc.m263"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh263.drv
"vidc.i420"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh263.drv
"vidc.mrle"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msrle32.dll
"vidc.uyvy"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.yuy2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.yvyu"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.msvc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msvidc32.dll
"vidc.cram"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msvidc32.dll
"vidc.mpg4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp42"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp43"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp4s"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp4v"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.wmv3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\WMV9VCM.dll
"msacm.msaudio1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msaud32.acm
"msacm.vorbis"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\OGG\vorbis.acm
"vidc.pdvc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Panasonic\idvcodec.dll
"vidc.ipdv"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Panasonic\idvcodec.dll
"vidc.miro"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\mirodv2avi.dll
"vidc.dcap"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\mirodv2avi.dll
"vidc.mjpa"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\rtmjpgcdc.dll
"vidc.gpjm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\rtmjpgcdc.dll
"vidc.pim1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\pclepim1.dll
"vidc.xvid"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\XviD\xvidvfw.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\GigaTribe\\gigatribe.exe"=
"D:\\Program Files\\Microsoft Office Professional Plus 2007\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Azureus\\Azureus.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"= D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"= D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;D:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 UxTuneUp;TuneUp Extension de thème;D:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 3xHybrid;3xHybrid service;D:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
R3 X10Hid;X10 Hid Device;D:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 7040]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;D:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-22 355584]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - MCHINJDRV
.
Contenu du dossier 'Tâches planifiées'

2008-10-04 D:\WINDOWS\Tasks\Maintenance en 1 clic.job
- D:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:23]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 19:22:30
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp"
.
------------------------ Autres processus actifs ------------------------
.
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\PROGRA~1\Common Files\X10\Common\X10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
D:\ComboFix\pv.cfexe
.
**************************************************************************
.
Heure de fin: 2008-10-04 19:23:34 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-04 17:23:29
ComboFix2.txt 2008-10-04 16:16:04

Avant-CF: 32 414 650 368 octets libres
Après-CF: 32,406,106,112 octets libres

324 --- E O F --- 2008-09-13 20:54:16








rapport RSIT




Logfile of random's system information tool 1.04 (written by random/random)
Run by Did at 2008-10-04 19:26:56
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 31 GB (80%) free of 39 GB
Total RAM: 1023 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:27, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Avast4\ashDisp.exe
D:\Documents and Settings\Administrateur\Bureau\Utilitaires II\Random System Information Tool.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Trend Micro\HijackThis\Did.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 8873 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Maintenance en 1 clic.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}]
D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - d:\program files\google\googletoolbar1.dll [2008-08-22 2582136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll [2008-08-22 651760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2005-06-29 14720000]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2006-06-01 7618560]
"LVCOMSX"=D:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
"rkfree"=D:\WINDOWS\Winreveal\rkfree.exe [2008-08-26 66048]
"QuickTime Task"=D:\WINDOWS\system32\qttask.exe [2008-08-24 98304]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=D:\Program Files\SuperCopier2\SuperCopier2.exe [2005-03-14 1057280]
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-22 39408]
"H/PC Connection Agent"=D:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"RoboForm"=D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2008-09-28 160592]

D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\GigaTribe\gigatribe.exe"="D:\Program Files\GigaTribe\gigatribe.exe:*:Enabled:gigatribe"
"D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Azureus\Azureus.exe"="D:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Messenger\msmsgs.exe"="D:\Program Files\Messenger\msmsgs.exe:*:Enabled:Messenger"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="D:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======List of files/folders created in the last 3 months======

2008-10-04 19:26:50 ----SHD---- D:\RECYCLER
2008-10-04 19:23:36 ----A---- D:\ComboFix.txt
2008-10-04 18:39:58 ----RASHD---- D:\autorun.inf
2008-10-04 18:11:15 ----D---- D:\WINDOWS\erdnt
2008-10-04 18:10:56 ----D---- D:\QooBox
2008-10-04 18:10:54 ----A---- D:\WINDOWS\zip.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\VFind.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\swxcacls.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\SWSC.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\SWREG.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\sed.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\Nircmd.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\grep.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\fdsv.exe
2008-10-04 13:51:56 ----D---- D:\rsit
2008-10-04 13:29:01 ----D---- D:\Program Files\CCleaner
2008-10-04 12:41:46 ----D---- D:\ToolBar SD
2008-10-04 09:47:20 ----D---- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:47:17 ----D---- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:16:06 ----D---- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03:49 ----D---- D:\Program Files\Trend Micro
2008-09-13 22:53:25 ----HDC---- D:\WINDOWS\$NtUninstallKB938464$
2008-09-13 22:53:16 ----HDC---- D:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-05 15:41:37 ----HD---- D:\WINDOWS\system32\GroupPolicy
2008-09-01 00:57:18 ----D---- D:\Documents and Settings\Administrateur\Application Data\Help
2008-08-31 16:15:50 ----D---- D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 16:14:48 ----D---- D:\Program Files\Siber Systems
2008-08-29 19:59:20 ----D---- D:\Program Files\La Marmite du Chef
2008-08-29 08:43:55 ----D---- D:\Program Files\SuperCopier2
2008-08-26 10:50:02 ----AD---- D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 10:49:50 ----D---- D:\WINDOWS\Winreveal
2008-08-26 10:49:39 ----D---- D:\Nouveau dossier
2008-08-26 08:33:15 ----D---- D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 08:31:54 ----D---- D:\WINDOWS\system32\CatRoot_bak
2008-08-25 16:59:20 ----D---- D:\Program Files\MappySynchro
2008-08-25 16:50:24 ----HDC---- D:\WINDOWS\$NtUninstallKB909394$
2008-08-25 16:50:07 ----D---- D:\Program Files\Microsoft ActiveSync
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\muweb.dll
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll.mui
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll
2008-08-24 14:43:17 ----HD---- D:\WINDOWS\Icons
2008-08-24 12:50:02 ----D---- D:\Documents and Settings\Administrateur\Application Data\Real
2008-08-24 09:38:14 ----A---- D:\WINDOWS\system32\qttask.exe
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\rmoc3260.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5032.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5016.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pncrt.dll
2008-08-24 09:36:44 ----D---- D:\WINDOWS\system32\QuickTime
2008-08-24 09:36:43 ----A---- D:\WINDOWS\mmtvmj.ini
2008-08-24 09:36:43 ----A---- D:\WINDOWS\m3jp2k.ini
2008-08-24 09:36:42 ----A---- D:\WINDOWS\m3jpeg.ini
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvpx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvm6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplva6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplapx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplam6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaa6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\cpuinf32.dll
2008-08-24 09:36:37 ----A---- D:\WINDOWS\system32\unrar.dll
2008-08-24 09:36:35 ----A---- D:\WINDOWS\system32\xvidcore.dll
2008-08-24 09:36:31 ----D---- D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 09:18:47 ----D---- D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-24 09:02:18 ----D---- D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 09:01:45 ----D---- D:\Program Files\Fichiers communs\HP
2008-08-24 09:00:39 ----D---- D:\Program Files\Hewlett-Packard
2008-08-24 09:00:19 ----D---- D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-24 08:59:43 ----RA---- D:\WINDOWS\system32\HPZIDS01.dll
2008-08-24 08:59:42 ----A---- D:\WINDOWS\system32\hpzll054.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZisn12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipt12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipm12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZinw12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZidr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\IsUninst.exe
2008-08-24 08:57:44 ----D---- D:\Program Files\HP
2008-08-24 08:56:41 ----HD---- D:\Config.Msi
2008-08-23 23:23:09 ----HDC---- D:\WINDOWS\$NtUninstallKB941569$
2008-08-23 23:22:54 ----HDC---- D:\WINDOWS\$NtUninstallKB929399$
2008-08-23 23:22:19 ----HDC---- D:\WINDOWS\$NtUninstallKB939683$
2008-08-23 23:22:04 ----D---- D:\WINDOWS\ie7updates
2008-08-23 23:22:00 ----HDC---- D:\WINDOWS\$NtUninstallKB932823-v3$
2008-08-23 23:21:55 ----D---- D:\Program Files\MSXML 4.0
2008-08-23 23:21:50 ----A---- D:\WINDOWS\system32\wmpns.dll
2008-08-23 23:21:42 ----HDC---- D:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2RC.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.ini
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcodec2.dll
2008-08-23 09:40:29 ----A---- D:\WINDOWS\IsUn040c.exe
2008-08-23 09:35:51 ----A---- D:\WINDOWS\system32\capicom.dll
2008-08-23 09:35:14 ----RA---- D:\WINDOWS\system32\InstMed.exe
2008-08-23 09:34:48 ----D---- D:\Program Files\Fichiers communs\Logitech
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\Lvkrn12n.dll
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\LCamCpl.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71u.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71KOR.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71JPN.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ITA.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ESP.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ENU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71DEU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71CHT.DLL
2008-08-23 09:34:28 ----A---- D:\WINDOWS\system32\MFC71CHS.DLL
2008-08-23 09:34:26 ----A---- D:\WINDOWS\system32\atl71.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\QCUI2.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\Ltwvc12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltkrn12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltimg12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltfil12n.DLL
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltefx12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\LTDIS12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lftif12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lffax12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\LFCMP12n.DLL
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lfbmp12n.dll
2008-08-23 09:34:21 ----A---- D:\WINDOWS\system32\LQCUI2.dll
2008-08-23 09:34:20 ----D---- D:\Program Files\Logitech
2008-08-23 09:34:07 ----R---- D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 08:38:37 ----HDC---- D:\WINDOWS\$NtUninstallKB915865$
2008-08-23 08:38:26 ----N---- D:\WINDOWS\system32\xmllite.dll
2008-08-23 08:02:58 ----D---- D:\Program Files\Sony Corporation
2008-08-23 08:02:50 ----N---- D:\WINDOWS\snymsico.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBUI.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CddbLangFR.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBControl.dll
2008-08-23 08:02:16 ----D---- D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 07:56:49 ----D---- D:\Program Files\Sony
2008-08-23 07:56:14 ----D---- D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 07:56:14 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-23 07:37:31 ----D---- D:\WINDOWS\Sun
2008-08-23 07:37:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sun
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaws.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaw.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\java.exe
2008-08-23 07:36:29 ----D---- D:\Program Files\Java
2008-08-23 07:36:20 ----A---- D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 07:36:12 ----D---- D:\Program Files\Messenger
2008-08-23 07:36:03 ----D---- D:\Program Files\Fichiers communs\Java
2008-08-22 21:26:55 ----D---- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 21:26:01 ----D---- D:\Program Files\Windows Live
2008-08-22 21:25:59 ----D---- D:\Program Files\Messenger Plus! Live
2008-08-22 21:24:53 ----D---- D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 21:24:48 ----D---- D:\Program Files\MSN Pictures Displayer
2008-08-22 21:19:10 ----DC---- D:\WINDOWS\system32\DRVSTORE
2008-08-22 21:19:05 ----D---- D:\Program Files\MSN Messenger
2008-08-22 21:07:06 ----D---- D:\Documents and Settings\Administrateur\Application Data\Macromedia
2008-08-22 21:07:05 ----D---- D:\Documents and Settings\Administrateur\Application Data\Adobe
2008-08-22 21:00:43 ----D---- D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 21:00:41 ----D---- D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-08-22 21:00:00 ----D---- D:\Program Files\Azureus
2008-08-22 19:51:26 ----D---- D:\Documents and Settings\Administrateur\Application Data\Google
2008-08-22 19:51:22 ----D---- D:\Documents and Settings\All Users\Application Data\Google
2008-08-22 19:51:11 ----D---- D:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-22 19:51:10 ----D---- D:\Program Files\Google
2008-08-22 19:31:41 ----N---- D:\WINDOWS\system32\normaliz.dll
2008-08-22 19:30:36 ----D---- D:\WINDOWS\WBEM
2008-08-22 19:30:35 ----D---- D:\WINDOWS\system32\fr-fr
2008-08-22 19:30:28 ----D---- D:\WINDOWS\%DownloadedProgramFiles%
2008-08-22 19:29:47 ----HDC---- D:\WINDOWS\ie7
2008-08-22 19:02:57 ----D---- D:\Program Files\Microsoft Works
2008-08-22 19:02:40 ----D---- D:\Program Files\Microsoft Visual Studio
2008-08-22 19:02:39 ----D---- D:\Program Files\Fichiers communs\DESIGNER
2008-08-22 19:00:09 ----D---- D:\WINDOWS\SHELLNEW
2008-08-22 18:59:49 ----D---- D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 18:59:48 ----D---- D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 18:59:31 ----RHD---- D:\MSOCache
2008-08-22 18:57:42 ----D---- D:\Documents and Settings\All Users\Application Data\Adobe
2008-08-22 18:57:34 ----D---- D:\Program Files\Fichiers communs\Adobe
2008-08-22 18:51:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-22 18:51:11 ----HDC---- D:\WINDOWS\$NtUninstallKB952954$
2008-08-22 18:51:06 ----HDC---- D:\WINDOWS\$NtUninstallKB953839$
2008-08-22 18:51:02 ----HDC---- D:\WINDOWS\$NtUninstallKB935448$
2008-08-22 18:50:57 ----HDC---- D:\WINDOWS\$NtUninstallKB950974$
2008-08-22 18:50:52 ----HDC---- D:\WINDOWS\$NtUninstallKB951698$
2008-08-22 18:50:25 ----A---- D:\WINDOWS\system32\MRT.exe
2008-08-22 18:50:19 ----HDC---- D:\WINDOWS\$NtUninstallKB950762$
2008-08-22 18:50:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-22 18:50:09 ----HDC---- D:\WINDOWS\$NtUninstallKB952287$
2008-08-22 18:50:04 ----HDC---- D:\WINDOWS\$NtUninstallKB951066$
2008-08-22 18:49:52 ----HDC---- D:\WINDOWS\$NtUninstallKB953838$
2008-08-22 18:49:43 ----HDC---- D:\WINDOWS\$NtUninstallKB951748$
2008-08-22 18:49:34 ----HDC---- D:\WINDOWS\$NtUninstallKB950749$
2008-08-22 18:49:23 ----N---- D:\WINDOWS\system32\spmsg.dll
2008-08-22 18:49:22 ----HDC---- D:\WINDOWS\$NtUninstallKB944338-v2$
2008-08-22 18:44:30 ----HDC---- D:\WINDOWS\$NtUninstallWMFDist11$
2008-08-22 18:43:40 ----D---- D:\Program Files\Windows Media Connect 2
2008-08-22 18:43:32 ----HDC---- D:\WINDOWS\$NtUninstallwmp11$
2008-08-22 18:40:13 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-08-22 18:36:35 ----A---- D:\WINDOWS\system32\BASSMOD.dll
2008-08-22 18:35:34 ----D---- D:\Program Files\WinRAR
2008-08-22 18:33:31 ----D---- D:\Program Files\QuickTime
2008-08-22 18:33:31 ----D---- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 18:33:21 ----D---- D:\Program Files\Apple Software Update
2008-08-22 18:33:21 ----D---- D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 18:28:48 ----A---- D:\WINDOWS\system32\h323log.txt
2008-08-22 18:28:21 ----A---- D:\WINDOWS\system32\ksuser.dll
2008-08-22 18:27:12 ----A---- D:\WINDOWS\system32\usbui.dll
2008-08-22 18:26:10 ----SHD---- D:\WINDOWS\Installer
2008-08-22 18:26:10 ----D---- D:\Program Files\Fichiers communs\ODBC
2008-08-22 18:26:10 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2008-08-22 18:26:10 ----A---- D:\WINDOWS\ODBCINST.INI
2008-08-22 18:26:07 ----D---- D:\Program Files\Fichiers communs\SpeechEngines
2008-08-22 18:26:06 ----RD---- D:\Program Files
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs\Microsoft Shared
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuq.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuf.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdazel.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdycc.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbduzb.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdur.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdtat.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru1.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdmon.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkyr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkaz.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdbu.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdblr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdaze.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhept.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela3.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela2.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe319.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe220.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdgkl.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdest.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdycl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdro.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz2.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcr.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\KBDAL.DLL
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\spxcoins.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\irclass.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\EqnClass.Dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgsetup.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgrpsetu.dll
2008-08-22 18:25:52 ----N---- D:\WINDOWS\system32\CONFIG.TMP
2008-08-22 18:25:52 ----A---- D:\WINDOWS\TASKMAN.EXE
2008-08-22 18:25:51 ----A---- D:\WINDOWS\system32\batt.dll
2008-08-22 18:25:51 ----A---- D:\WINDOWS\NOTEPAD.EXE
2008-08-22 18:25:50 ----A---- D:\WINDOWS\system32\storprop.dll
2008-08-22 18:25:43 ----ASH---- D:\Documents and Settings\All Users\Application Data\desktop.ini
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot2
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot
2008-08-22 18:25:23 ----SD---- D:\Documents and Settings\All Users\Application Data\Microsoft
2008-08-22 18:25:03 ----D---- D:\Documents and Settings
2008-08-22 18:24:02 ----SHD---- D:\System Volume Information
2008-08-22 18:23:58 ----D---- D:\INSTALL
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\vxblock.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxwave.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxsfs.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxmas.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxinsa64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxhpinst.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxdrv.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxcpya64.ex

Répondre à nigga_nigga

22

sKe69, le 4 oct 2008 à 19:33:25

Re , il me faut la fin comme tout à l'heure stp ... ;)


Dis moi aussi comment va le PC maintenant ... du mieux ? ... Rien ne sert de courir .... Non, ça sert à rien ...    ---sK­e---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

23

nigga_nigga, le 4 oct 2008 à 19:37:38

Logfile of random's system information tool 1.04 (written by random/random)
Run by Did at 2008-10-04 19:26:56
Microsoft Windows XP Professionnel Service Pack 2
System drive D: has 31 GB (80%) free of 39 GB
Total RAM: 1023 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:27, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
D:\Program Files\Avast4\ashMaiSv.exe
D:\Program Files\Avast4\ashWebSv.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\LVCOMSX.EXE
D:\WINDOWS\Winreveal\rkfree.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Avast4\ashDisp.exe
D:\Documents and Settings\Administrateur\Bureau\Utilitaires II\Random System Information Tool.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Trend Micro\HijackThis\Did.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [rkfree] D:\WINDOWS\Winreveal\rkfree.exe /b
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Barre RoboForm - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office Professional Plus 2007\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95C6242A-DEB9-4592-8A28-E08E44FC4411}: NameServer = 80.10.246.2,80.10.246.129
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA47A746-1915-40DA-B7A5-3D56B0C9A5C6}: NameServer = 80.10.246.2,80.10.246.129
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - D:\PROGRA~1\Common Files\X10\Common\x10nets.exe
End of file - 8873 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Maintenance en 1 clic.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}]
D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - d:\program files\google\googletoolbar1.dll [2008-08-22 2582136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll [2008-08-22 651760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2008-09-28 5759816]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2005-06-29 14720000]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2006-06-01 7618560]
"LVCOMSX"=D:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
"rkfree"=D:\WINDOWS\Winreveal\rkfree.exe [2008-08-26 66048]
"QuickTime Task"=D:\WINDOWS\system32\qttask.exe [2008-08-24 98304]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"=D:\Program Files\SuperCopier2\SuperCopier2.exe [2005-03-14 1057280]
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-08-22 39408]
"H/PC Connection Agent"=D:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"RoboForm"=D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2008-09-28 160592]

D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\GigaTribe\gigatribe.exe"="D:\Program Files\GigaTribe\gigatribe.exe:*:Enabled:gigatribe"
"D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office Professional Plus 2007\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Azureus\Azureus.exe"="D:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Messenger\msmsgs.exe"="D:\Program Files\Messenger\msmsgs.exe:*:Enabled:Messenger"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:Logitech Desktop Messenger"
"D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"D:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="D:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\MSN Messenger\msnmsgr.exe"="D:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"D:\Program Files\MSN Messenger\livecall.exe"="D:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======List of files/folders created in the last 3 months======

2008-10-04 19:26:50 ----SHD---- D:\RECYCLER
2008-10-04 19:23:36 ----A---- D:\ComboFix.txt
2008-10-04 18:39:58 ----RASHD---- D:\autorun.inf
2008-10-04 18:11:15 ----D---- D:\WINDOWS\erdnt
2008-10-04 18:10:56 ----D---- D:\QooBox
2008-10-04 18:10:54 ----A---- D:\WINDOWS\zip.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\VFind.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\swxcacls.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\SWSC.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\SWREG.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\sed.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\Nircmd.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\grep.exe
2008-10-04 18:10:54 ----A---- D:\WINDOWS\fdsv.exe
2008-10-04 13:51:56 ----D---- D:\rsit
2008-10-04 13:29:01 ----D---- D:\Program Files\CCleaner
2008-10-04 12:41:46 ----D---- D:\ToolBar SD
2008-10-04 09:47:20 ----D---- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:47:17 ----D---- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:16:06 ----D---- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03:49 ----D---- D:\Program Files\Trend Micro
2008-09-13 22:53:25 ----HDC---- D:\WINDOWS\$NtUninstallKB938464$
2008-09-13 22:53:16 ----HDC---- D:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-05 15:41:37 ----HD---- D:\WINDOWS\system32\GroupPolicy
2008-09-01 00:57:18 ----D---- D:\Documents and Settings\Administrateur\Application Data\Help
2008-08-31 16:15:50 ----D---- D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 16:14:48 ----D---- D:\Program Files\Siber Systems
2008-08-29 19:59:20 ----D---- D:\Program Files\La Marmite du Chef
2008-08-29 08:43:55 ----D---- D:\Program Files\SuperCopier2
2008-08-26 10:50:02 ----AD---- D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 10:49:50 ----D---- D:\WINDOWS\Winreveal
2008-08-26 10:49:39 ----D---- D:\Nouveau dossier
2008-08-26 08:33:15 ----D---- D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 08:31:54 ----D---- D:\WINDOWS\system32\CatRoot_bak
2008-08-25 16:59:20 ----D---- D:\Program Files\MappySynchro
2008-08-25 16:50:24 ----HDC---- D:\WINDOWS\$NtUninstallKB909394$
2008-08-25 16:50:07 ----D---- D:\Program Files\Microsoft ActiveSync
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\muweb.dll
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll.mui
2008-08-25 11:15:08 ----A---- D:\WINDOWS\system32\mucltui.dll
2008-08-24 14:43:17 ----HD---- D:\WINDOWS\Icons
2008-08-24 12:50:02 ----D---- D:\Documents and Settings\Administrateur\Application Data\Real
2008-08-24 09:38:14 ----A---- D:\WINDOWS\system32\qttask.exe
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\rmoc3260.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5032.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pndx5016.dll
2008-08-24 09:36:49 ----A---- D:\WINDOWS\system32\pncrt.dll
2008-08-24 09:36:44 ----D---- D:\WINDOWS\system32\QuickTime
2008-08-24 09:36:43 ----A---- D:\WINDOWS\mmtvmj.ini
2008-08-24 09:36:43 ----A---- D:\WINDOWS\m3jp2k.ini
2008-08-24 09:36:42 ----A---- D:\WINDOWS\m3jpeg.ini
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvpx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplvm6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplva6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaw7.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplapx.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplam6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\mplaa6.dll
2008-08-24 09:36:38 ----A---- D:\WINDOWS\system32\cpuinf32.dll
2008-08-24 09:36:37 ----A---- D:\WINDOWS\system32\unrar.dll
2008-08-24 09:36:35 ----A---- D:\WINDOWS\system32\xvidcore.dll
2008-08-24 09:36:31 ----D---- D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 09:18:47 ----D---- D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-24 09:02:18 ----D---- D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 09:01:45 ----D---- D:\Program Files\Fichiers communs\HP
2008-08-24 09:00:39 ----D---- D:\Program Files\Hewlett-Packard
2008-08-24 09:00:19 ----D---- D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-24 08:59:43 ----RA---- D:\WINDOWS\system32\HPZIDS01.dll
2008-08-24 08:59:42 ----A---- D:\WINDOWS\system32\hpzll054.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZisn12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipt12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZipm12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZinw12.exe
2008-08-24 08:58:34 ----A---- D:\WINDOWS\system32\HPZidr12.dll
2008-08-24 08:58:34 ----A---- D:\WINDOWS\IsUninst.exe
2008-08-24 08:57:44 ----D---- D:\Program Files\HP
2008-08-24 08:56:41 ----HD---- D:\Config.Msi
2008-08-23 23:23:09 ----HDC---- D:\WINDOWS\$NtUninstallKB941569$
2008-08-23 23:22:54 ----HDC---- D:\WINDOWS\$NtUninstallKB929399$
2008-08-23 23:22:19 ----HDC---- D:\WINDOWS\$NtUninstallKB939683$
2008-08-23 23:22:04 ----D---- D:\WINDOWS\ie7updates
2008-08-23 23:22:00 ----HDC---- D:\WINDOWS\$NtUninstallKB932823-v3$
2008-08-23 23:21:55 ----D---- D:\Program Files\MSXML 4.0
2008-08-23 23:21:50 ----A---- D:\WINDOWS\system32\wmpns.dll
2008-08-23 23:21:42 ----HDC---- D:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2RC.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\LVUI2.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.ini
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcoinst.dll
2008-08-23 09:44:40 ----RA---- D:\WINDOWS\system32\lvcodec2.dll
2008-08-23 09:40:29 ----A---- D:\WINDOWS\IsUn040c.exe
2008-08-23 09:35:51 ----A---- D:\WINDOWS\system32\capicom.dll
2008-08-23 09:35:14 ----RA---- D:\WINDOWS\system32\InstMed.exe
2008-08-23 09:34:48 ----D---- D:\Program Files\Fichiers communs\Logitech
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\Lvkrn12n.dll
2008-08-23 09:34:32 ----A---- D:\WINDOWS\system32\LCamCpl.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71u.dll
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71KOR.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71JPN.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ITA.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ESP.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71ENU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71DEU.DLL
2008-08-23 09:34:29 ----A---- D:\WINDOWS\system32\MFC71CHT.DLL
2008-08-23 09:34:28 ----A---- D:\WINDOWS\system32\MFC71CHS.DLL
2008-08-23 09:34:26 ----A---- D:\WINDOWS\system32\atl71.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\QCUI2.dll
2008-08-23 09:34:25 ----A---- D:\WINDOWS\system32\Ltwvc12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltkrn12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltimg12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltfil12n.DLL
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\ltefx12n.dll
2008-08-23 09:34:24 ----A---- D:\WINDOWS\system32\LTDIS12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lftif12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lffax12n.dll
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\LFCMP12n.DLL
2008-08-23 09:34:23 ----A---- D:\WINDOWS\system32\lfbmp12n.dll
2008-08-23 09:34:21 ----A---- D:\WINDOWS\system32\LQCUI2.dll
2008-08-23 09:34:20 ----D---- D:\Program Files\Logitech
2008-08-23 09:34:07 ----R---- D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 08:38:37 ----HDC---- D:\WINDOWS\$NtUninstallKB915865$
2008-08-23 08:38:26 ----N---- D:\WINDOWS\system32\xmllite.dll
2008-08-23 08:02:58 ----D---- D:\Program Files\Sony Corporation
2008-08-23 08:02:50 ----N---- D:\WINDOWS\snymsico.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBUI.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CddbLangFR.dll
2008-08-23 08:02:41 ----A---- D:\WINDOWS\system32\CDDBControl.dll
2008-08-23 08:02:16 ----D---- D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 07:56:49 ----D---- D:\Program Files\Sony
2008-08-23 07:56:14 ----D---- D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 07:56:14 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-23 07:37:31 ----D---- D:\WINDOWS\Sun
2008-08-23 07:37:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Sun
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaws.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\javaw.exe
2008-08-23 07:36:57 ----A---- D:\WINDOWS\system32\java.exe
2008-08-23 07:36:29 ----D---- D:\Program Files\Java
2008-08-23 07:36:20 ----A---- D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 07:36:12 ----D---- D:\Program Files\Messenger
2008-08-23 07:36:03 ----D---- D:\Program Files\Fichiers communs\Java
2008-08-22 21:26:55 ----D---- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 21:26:01 ----D---- D:\Program Files\Windows Live
2008-08-22 21:25:59 ----D---- D:\Program Files\Messenger Plus! Live
2008-08-22 21:24:53 ----D---- D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 21:24:48 ----D---- D:\Program Files\MSN Pictures Displayer
2008-08-22 21:19:10 ----DC---- D:\WINDOWS\system32\DRVSTORE
2008-08-22 21:19:05 ----D---- D:\Program Files\MSN Messenger
2008-08-22 21:07:06 ----D---- D:\Documents and Settings\Administrateur\Application Data\Macromedia
2008-08-22 21:07:05 ----D---- D:\Documents and Settings\Administrateur\Application Data\Adobe
2008-08-22 21:00:43 ----D---- D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 21:00:41 ----D---- D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-08-22 21:00:00 ----D---- D:\Program Files\Azureus
2008-08-22 19:51:26 ----D---- D:\Documents and Settings\Administrateur\Application Data\Google
2008-08-22 19:51:22 ----D---- D:\Documents and Settings\All Users\Application Data\Google
2008-08-22 19:51:11 ----D---- D:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-22 19:51:10 ----D---- D:\Program Files\Google
2008-08-22 19:31:41 ----N---- D:\WINDOWS\system32\normaliz.dll
2008-08-22 19:30:36 ----D---- D:\WINDOWS\WBEM
2008-08-22 19:30:35 ----D---- D:\WINDOWS\system32\fr-fr
2008-08-22 19:30:28 ----D---- D:\WINDOWS\%DownloadedProgramFiles%
2008-08-22 19:29:47 ----HDC---- D:\WINDOWS\ie7
2008-08-22 19:02:57 ----D---- D:\Program Files\Microsoft Works
2008-08-22 19:02:40 ----D---- D:\Program Files\Microsoft Visual Studio
2008-08-22 19:02:39 ----D---- D:\Program Files\Fichiers communs\DESIGNER
2008-08-22 19:00:09 ----D---- D:\WINDOWS\SHELLNEW
2008-08-22 18:59:49 ----D---- D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 18:59:48 ----D---- D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 18:59:31 ----RHD---- D:\MSOCache
2008-08-22 18:57:42 ----D---- D:\Documents and Settings\All Users\Application Data\Adobe
2008-08-22 18:57:34 ----D---- D:\Program Files\Fichiers communs\Adobe
2008-08-22 18:51:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-22 18:51:11 ----HDC---- D:\WINDOWS\$NtUninstallKB952954$
2008-08-22 18:51:06 ----HDC---- D:\WINDOWS\$NtUninstallKB953839$
2008-08-22 18:51:02 ----HDC---- D:\WINDOWS\$NtUninstallKB935448$
2008-08-22 18:50:57 ----HDC---- D:\WINDOWS\$NtUninstallKB950974$
2008-08-22 18:50:52 ----HDC---- D:\WINDOWS\$NtUninstallKB951698$
2008-08-22 18:50:25 ----A---- D:\WINDOWS\system32\MRT.exe
2008-08-22 18:50:19 ----HDC---- D:\WINDOWS\$NtUninstallKB950762$
2008-08-22 18:50:15 ----HDC---- D:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-22 18:50:09 ----HDC---- D:\WINDOWS\$NtUninstallKB952287$
2008-08-22 18:50:04 ----HDC---- D:\WINDOWS\$NtUninstallKB951066$
2008-08-22 18:49:52 ----HDC---- D:\WINDOWS\$NtUninstallKB953838$
2008-08-22 18:49:43 ----HDC---- D:\WINDOWS\$NtUninstallKB951748$
2008-08-22 18:49:34 ----HDC---- D:\WINDOWS\$NtUninstallKB950749$
2008-08-22 18:49:23 ----N---- D:\WINDOWS\system32\spmsg.dll
2008-08-22 18:49:22 ----HDC---- D:\WINDOWS\$NtUninstallKB944338-v2$
2008-08-22 18:44:30 ----HDC---- D:\WINDOWS\$NtUninstallWMFDist11$
2008-08-22 18:43:40 ----D---- D:\Program Files\Windows Media Connect 2
2008-08-22 18:43:32 ----HDC---- D:\WINDOWS\$NtUninstallwmp11$
2008-08-22 18:40:13 ----D---- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-08-22 18:36:35 ----A---- D:\WINDOWS\system32\BASSMOD.dll
2008-08-22 18:35:34 ----D---- D:\Program Files\WinRAR
2008-08-22 18:33:31 ----D---- D:\Program Files\QuickTime
2008-08-22 18:33:31 ----D---- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 18:33:21 ----D---- D:\Program Files\Apple Software Update
2008-08-22 18:33:21 ----D---- D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 18:28:48 ----A---- D:\WINDOWS\system32\h323log.txt
2008-08-22 18:28:21 ----A---- D:\WINDOWS\system32\ksuser.dll
2008-08-22 18:27:12 ----A---- D:\WINDOWS\system32\usbui.dll
2008-08-22 18:26:10 ----SHD---- D:\WINDOWS\Installer
2008-08-22 18:26:10 ----D---- D:\Program Files\Fichiers communs\ODBC
2008-08-22 18:26:10 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2008-08-22 18:26:10 ----A---- D:\WINDOWS\ODBCINST.INI
2008-08-22 18:26:07 ----D---- D:\Program Files\Fichiers communs\SpeechEngines
2008-08-22 18:26:06 ----RD---- D:\Program Files
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs\Microsoft Shared
2008-08-22 18:26:06 ----D---- D:\Program Files\Fichiers communs
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuq.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdtuf.dll
2008-08-22 18:26:04 ----RA---- D:\WINDOWS\system32\kbdazel.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdycc.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbduzb.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdur.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdtat.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru1.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdru.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdmon.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkyr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdkaz.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdbu.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdblr.dll
2008-08-22 18:26:02 ----RA---- D:\WINDOWS\system32\kbdaze.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhept.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela3.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhela2.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe319.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe220.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdhe.dll
2008-08-22 18:26:00 ----RA---- D:\WINDOWS\system32\kbdgkl.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlv.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt1.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdlt.dll
2008-08-22 18:25:59 ----RA---- D:\WINDOWS\system32\kbdest.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdycl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdsl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdro.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdpl.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdhu.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz2.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz1.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcz.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\kbdcr.dll
2008-08-22 18:25:57 ----RA---- D:\WINDOWS\system32\KBDAL.DLL
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\spxcoins.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\irclass.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\EqnClass.Dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgsetup.dll
2008-08-22 18:25:54 ----A---- D:\WINDOWS\system32\dgrpsetu.dll
2008-08-22 18:25:52 ----N---- D:\WINDOWS\system32\CONFIG.TMP
2008-08-22 18:25:52 ----A---- D:\WINDOWS\TASKMAN.EXE
2008-08-22 18:25:51 ----A---- D:\WINDOWS\system32\batt.dll
2008-08-22 18:25:51 ----A---- D:\WINDOWS\NOTEPAD.EXE
2008-08-22 18:25:50 ----A---- D:\WINDOWS\system32\storprop.dll
2008-08-22 18:25:43 ----ASH---- D:\Documents and Settings\All Users\Application Data\desktop.ini
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot2
2008-08-22 18:25:29 ----D---- D:\WINDOWS\system32\CatRoot
2008-08-22 18:25:23 ----SD---- D:\Documents and Settings\All Users\Application Data\Microsoft
2008-08-22 18:25:03 ----D---- D:\Documents and Settings
2008-08-22 18:24:02 ----SHD---- D:\System Volume Information
2008-08-22 18:23:58 ----D---- D:\INSTALL
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\vxblock.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxwave.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxsfs.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxmas.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxinsa64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxhpinst.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxdrv.dll
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxcpya64.exe
2008-08-22 18:23:26 ----N---- D:\WINDOWS\system32\pxafs.dll
2008-08-22 18:23:23 ----D---- D:\Program Files\Winamp
2008-08-22 18:23:23 ----D---- D:\Documents and Settings\Administrateur\Application Data\Winamp
2008-08-22 18:22:00 ----A---- D:\WINDOWS\NeroDigital.ini
2008-08-22 18:21:42 ----D---- D:\Documents and Settings\Administrateur\Application Data\vlc
2008-08-22 18:21:10 ----D---- D:\Program Files\VideoLAN
2008-08-22 18:20:01 ----RSHDC---- D:\WINDOWS\system32\dllcache
2008-08-22 18:20:01 ----RSD---- D:\WINDOWS\Fonts
2008-08-22 18:20:01 ----RD---- D:\WINDOWS\Web
2008-08-22 18:20:01 ----HD---- D:\WINDOWS\inf
2008-08-22 18:20:01 ----D---- D:\WINDOWS\WinSxS
2008-08-22 18:20:01 ----D---- D:\WINDOWS\twain_32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Temp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wins
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\wbem
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\usmt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\spool
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ShellExt
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\Setup
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ras
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\oobe
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\npp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\inetsrv
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\IME
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\icsxml
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\ias
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\export
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\drivers
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\dhcp
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3com_dmi
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\3076
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\2052
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1054
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1042
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1041
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1037
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1036
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1033
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1031
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1028
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32\1025
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system32
2008-08-22 18:20:01 ----D---- D:\WINDOWS\system
2008-08-22 18:20:01 ----D---- D:\WINDOWS\security
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Resources
2008-08-22 18:20:01 ----D---- D:\WINDOWS\repair
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Provisioning
2008-08-22 18:20:01 ----D---- D:\WINDOWS\PeerNet
2008-08-22 18:20:01 ----D---- D:\WINDOWS\pchealth
2008-08-22 18:20:01 ----D---- D:\WINDOWS\mui
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msapps
2008-08-22 18:20:01 ----D---- D:\WINDOWS\msagent
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Media
2008-08-22 18:20:01 ----D---- D:\WINDOWS\java
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ime
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Help
2008-08-22 18:20:01 ----D---- D:\WINDOWS\ehome
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Driver Cache
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Debug
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Cursors
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Connection Wizard
2008-08-22 18:20:01 ----D---- D:\WINDOWS\Config
2008-08-22 18:20:01 ----D---- D:\WINDOWS\AppPatch
2008-08-22 18:20:01 ----D---- D:\WINDOWS\addins
2008-08-22 18:20:01 ----D---- D:\WINDOWS
2008-08-22 18:19:35 ----D---- D:\WINDOWS\system32\PreInstall
2008-08-22 18:19:33 ----HDC---- D:\WINDOWS\$NtUninstallKB898461$
2008-08-22 18:19:33 ----HD---- D:\WINDOWS\$hf_mig$
2008-08-22 18:14:58 ----D---- D:\Documents and Settings\Administrateur\Application Data\Nero
2008-08-22 18:14:45 ----A---- D:\WINDOWS\system32\MsiExec.exe.log
2008-08-22 18:13:28 ----D---- D:\Program Files\Nero
2008-08-22 18:13:28 ----D---- D:\Program Files\Fichiers communs\Nero
2008-08-22 18:13:28 ----D---- D:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 18:10:42 ----A---- D:\WINDOWS\system32\d3dx9_30.dll
2008-08-22 18:10:41 ----A---- D:\WINDOWS\system32\d3dx9_28.dll
2008-08-22 18:08:08 ----D---- D:\Documents and Settings\Administrateur\Application Data\GigaTribe
2008-08-22 18:06:10 ----D---- D:\WINDOWS\RegisteredPackages
2008-08-22 18:03:25 ----D---- D:\Program Files\eMule
2008-08-22 18:02:50 ----D---- D:\Program Files\GigaTribe
2008-08-22 17:59:21 ----D---- D:\Temp
2008-08-22 17:59:07 ----D---- D:\Documents and Settings\Administrateur\Application Data\Syntrillium
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmvdmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmoe.dll
2008-08-22 17:58:53 ----A---- D:\WINDOWS\system32\wmv8dmod.dll
2008-08-22 17:58:52 ----A---- D:\WINDOWS\system32\wmvcore2.dll
2008-08-22 17:57:28 ----D---- D:\Program Files\Cool Edit Pro 2.1
2008-08-22 17:54:03 ----D---- D:\Program Files\Adobe
2008-08-22 17:49:14 ----D---- D:\Program Files\Virtual Dj 3.2
2008-08-22 17:46:10 ----D---- D:\WINDOWS\system32\SoftwareDistribution
2008-08-22 17:45:03 ----D---- D:\Program Files\DAEMON Tools Lite
2008-08-22 17:43:01 ----D---- D:\Documents and Settings\Administrateur\Application Data\DAEMON Tools
2008-08-22 17:40:58 ----A---- D:\WINDOWS\system32\TUKernel.exe
2008-08-22 17:23:05 ----A---- D:\WINDOWS\system32\uxtuneup.dll
2008-08-22 17:23:04 ----D---- D:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-08-22 17:23:04 ----A---- D:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-22 17:22:52 ----D---- D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-22 17:22:50 ----D---- D:\Program Files\TuneUp Utilities 2008
2008-08-22 17:22:38 ----D---- D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\msvcp71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\MFC71.dll
2008-08-22 17:10:02 ----A---- D:\WINDOWS\system32\aswBoot.exe
2008-08-22 17:09:57 ----D---- D:\Program Files\Avast4
2008-08-22 17:04:39 ----A---- D:\WINDOWS\system32\PsisDecd.dll
2008-08-22 17:04:38 ----A---- D:\WINDOWS\system32\vfwwdm32.dll
2008-08-22 17:04:08 ----A---- D:\WINDOWS\system32\hidserv.dll
2008-08-22 17:04:02 ----D---- D:\Program Files\X10 Hardware
2008-08-22 17:04:02 ----D---- D:\Program Files\Common Files
2008-08-22 17:04:02 ----A---- D:\WINDOWS\Unwise.exe
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr71.dll
2008-08-22 17:04:02 ----A---- D:\WINDOWS\system32\msvcr70.dll
2008-08-22 17:03:49 ----D---- D:\Program Files\Intel
2008-08-22 17:03:19 ----HD---- D:\Program Files\InstallShield Installation Information
2008-08-22 16:56:28 ----D---- D:\WINDOWS\nview
2008-08-22 16:56:27 ----A---- D:\WINDOWS\system32\nvudisp.exe
2008-08-22 16:56:21 ----A---- D:\WINDOWS\system32\NVUNINST.EXE
2008-08-22 16:56:18 ----D---- D:\Program Files\Fichiers communs\InstallShield
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nwiz.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwssr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwss.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszht.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrszhc.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrstr.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssv.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrssk.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsru.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsptb.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspt.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrspl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsno.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsnl.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsko.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvwrsja.dll
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvsvc32.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvdspsch.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcplui.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvcolor.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\nvappbar.exe
2008-08-22 16:56:16 ----A---- D:\WINDOWS\system32\keystone.exe
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsit.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshu.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrshe.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsfi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsesm.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrses.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrseng.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsel.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsde.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsda.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrscs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwrsar.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwimg.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwdmcpl.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvwddi.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvsr.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvvitvs.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvshell.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszht.dll
2008-08-22 16:56:15 ----A---- D:\WINDOWS\system32\nvrszhc.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrstr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssv.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrssk.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsru.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsptb.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspt.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrspl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsno.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsnl.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsko.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsja.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsit.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshu.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrshe.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfr.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsfi.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsesm.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrses.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrseng.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsel.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsde.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsda.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrscs.dll
2008-08-22 16:56:14 ----A---- D:\WINDOWS\system32\nvrsar.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvoglnt.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvnt4cpl.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmoblsr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmobls.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmctray.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccssr.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccss.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccsrs.dll
2008-08-22 16:56:13 ----A---- D:\WINDOWS\system32\nvmccs.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nview.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvhwvid.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgamesr.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvgames.dll
2008-08-22 16:56:12 ----A---- D:\WINDOWS\system32\nvexpbar.dll
2008-08-22 16:56:11 ----A---- D:\WINDOWS\system32\nvdispsr.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvdisps.dll
2008-08-22 16:56:10 ----A---- D:\WINDOWS\system32\nvcpluir.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcpl.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcodins.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvcod.dll
2008-08-22 16:56:09 ----A---- D:\WINDOWS\system32\nvapi.dll
2008-08-22 16:56:08 ----A---- D:\WINDOWS\system32\nv4_disp.dll
2008-08-22 16:46:13 ----D---- D:\WINDOWS\system32\Lang
2008-08-22 16:44:30 ----D---- D:\WINDOWS\system32\RTCOM
2008-08-22 16:44:27 ----D---- D:\WINDOWS\system32\ReinstallBackups
2008-08-22 16:44:12 ----A---- D:\WINDOWS\system32\spupdsvc.exe
2008-08-22 16:44:11 ----HDC---- D:\WINDOWS\$NtUninstallKB888111WXPSP2$
2008-08-22 16:43:50 ----D---- D:\pnp
2008-08-22 16:38:31 ----D---- D:\Documents and Settings\Administrateur\Application Data\Identities
2008-08-22 16:38:30 ----HD---- D:\Program Files\Uninstall Information
2008-08-22 16:36:20 ----ASH---- D:\Documents and Settings\Administrateur\Application Data\desktop.ini
2008-08-22 16:36:19 ----SD---- D:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-08-22 16:36:14 ----D---- D:\WINDOWS\SoftwareDistribution
2008-08-22 16:36:11 ----SD---- D:\WINDOWS\system32\Microsoft
2008-08-22 16:36:11 ----D---- D:\WINDOWS\Prefetch
2008-08-22 16:36:11 ----A---- D:\WINDOWS\SchedLgU.Txt
2008-08-22 16:33:18 ----D---- D:\WINDOWS\system32\xircom
2008-08-22 16:33:18 ----D---- D:\Program Files\xerox
2008-08-22 16:33:18 ----D---- D:\Program Files\msn gaming zone
2008-08-22 16:33:18 ----D---- D:\Program Files\movie maker
2008-08-22 16:33:18 ----D---- D:\Program Files\microsoft frontpage
2008-08-22 16:33:01 ----A---- D:\WINDOWS\control.ini
2008-08-22 16:32:47 ----A---- D:\WINDOWS\system32\mapi32.dll
2008-08-22 16:32:04 ----SD---- D:\WINDOWS\Downloaded Program Files
2008-08-22 16:32:04 ----RD---- D:\WINDOWS\Offline Web Pages
2008-08-22 16:32:04 ----RAH---- D:\WINDOWS\system32\logonui.exe.manifest
2008-08-22 16:31:58 ----RAH---- D:\WINDOWS\system32\cdplayer.exe.manifest
2008-08-22 16:31:54 ----HD---- D:\Program Files\WindowsUpdate
2008-08-22 16:31:52 ----D---- D:\Program Files\Services en ligne
2008-08-22 16:31:38 ----D---- D:\WINDOWS\system32\DirectX
2008-08-22 16:31:19 ----A---- D:\WINDOWS\system32\atrace.dll
2008-08-22 16:31:17 ----A---- D:\WINDOWS\system32\desktop.ini
2008-08-22 16:31:17 ----A---- D:\WINDOWS\desktop.ini
2008-08-22 16:31:11 ----A---- D:\WINDOWS\system32\nmevtmsg.dll
2008-08-22 16:31:10 ----A---- D:\WINDOWS\system32\acctres.dll
2008-08-22 16:31:09 ----D---- D:\Program Files\Fichiers communs\Services
2008-08-22 16:31:07 ----SD---- D:\WINDOWS\Tasks
2008-08-22 16:31:07 ----A---- D:\WINDOWS\system32\icfgnt5.dll
2008-08-22 16:31:06 ----D---- D:\Program Files\Fichiers communs\MSSoap
2008-08-22 16:31:02 ----D---- D:\WINDOWS\system32\Macromed
2008-08-22 16:31:02 ----D---- D:\WINDOWS\srchasst
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuweb.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wucltui.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuauserv.dll
2008-08-22 16:30:59 ----A---- D:\WINDOWS\system32\wuaueng1.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wups.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuaueng.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt1.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuauclt.exe
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\wuapi.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgrprxy.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\qmgr.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx3.dll
2008-08-22 16:30:58 ----A---- D:\WINDOWS\system32\bitsprx2.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrslv.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrdm.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\safrcdlg.dll
2008-08-22 16:30:54 ----A---- D:\WINDOWS\system32\racpldlg.dll
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltMc.exe
2008-08-22 16:30:51 ----A---- D:\WINDOWS\system32\fltlib.dll
2008-08-22 16:30:50 ----D---- D:\WINDOWS\system32\Restore
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srsvc.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srrstr.dll
2008-08-22 16:30:50 ----A---- D:\WINDOWS\system32\srclient.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\nmmkcert.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\msconf.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmsrvc.exe
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\mnmdd.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\isrdbg32.dll
2008-08-22 16:30:49 ----A---- D:\WINDOWS\system32\ils.dll
2008-08-22 16:30:46 ----D---- D:\Program Files\NetMeeting
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoert2.dll
2008-08-22 16:30:46 ----A---- D:\WINDOWS\system32\msoeacct.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetres.dll
2008-08-22 16:30:45 ----A---- D:\WINDOWS\system32\inetcomm.dll
2008-08-22 16:30:44 ----D---- D:\Program Files\Outlook Express
2008-08-22 16:30:44 ----A---- D:\WINDOWS\system32\schedsvc.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstinit.exe
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\mstask.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\isign32.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\inetcfg.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwphbk.dll
2008-08-22 16:30:43 ----A---- D:\WINDOWS\system32\icwdial.dll
2008-08-22 16:30:38 ----D---- D:\Program Files\Fichiers communs\System
2008-08-22 16:30:37 ----D---- D:\Program Files\Internet Explorer
2008-08-22 16:30:09 ----D---- D:\Program Files\ComPlus Applications
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vbaddin.ini
2008-08-22 16:30:07 ----A---- D:\WINDOWS\vb.ini
2008-08-22 16:30:04 ----D---- D:\WINDOWS\Registration
2008-08-22 16:29:58 ----D---- D:\Program Files\Windows Media Player
2008-08-22 16:29:55 ----A---- D:\WINDOWS\system32\write.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\sndvol32.exe
2008-08-22 16:29:50 ----A---- D:\WINDOWS\system32\hticons.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\winchat.exe
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avwav.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avtapi.dll
2008-08-22 16:29:49 ----A---- D:\WINDOWS\system32\avmeter.dll
2008-08-22 16:29:43 ----A---- D:\WINDOWS\system32\getuname.dll
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\usrlogon.cmd
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsshutdn.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tslabels.ini
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tskill.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tsdiscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\tscon.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\shadow.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\reset.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\charmap.exe
2008-08-22 16:29:42 ----A---- D:\WINDOWS\system32\calc.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\regini.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\rdpcfgex.dll
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qwinsta.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\qappsrv.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msg.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\msdtcprf.ini
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\logoff.exe
2008-08-22 16:29:41 ----A---- D:\WINDOWS\system32\cdmodem.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\stclient.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxlegih.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxex.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\mtxdm.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\dcomcnfg.exe
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comrepl.dll
2008-08-22 16:29:40 ----A---- D:\WINDOWS\system32\comaddin.dll
2008-08-22 16:29:39 ----A---- D:\WINDOWS\system32\comsnap.dll
2008-08-22 16:29:35 ----A---- D:\WINDOWS\system32\wmimgmt.msc
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\sndrec32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\mplay32.exe
2008-08-22 16:29:34 ----A---- D:\WINDOWS\system32\accwiz.exe
2008-08-22 16:29:33 ----D---- D:\Program Files\Windows NT
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\mspaint.exe
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\hypertrm.dll
2008-08-22 16:29:33 ----A---- D:\WINDOWS\system32\clipbrd.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\tscfgwmi.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\sessmgr.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\remotepg.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdshost.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\rdsaddin.exe
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstscax.dll
2008-08-22 16:29:32 ----A---- D:\WINDOWS\system32\mstsc.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\tscupgrd.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\termsrv.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpwsx.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpsnd.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdpclip.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\rdchost.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\qprocess.exe
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\icaapi.dll
2008-08-22 16:29:31 ----A---- D:\WINDOWS\system32\cfgbkend.dll
2008-08-22 16:29:30 ----D---- D:\WINDOWS\system32\MsDtc
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\xolehlp.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\mtxoci.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcuiu.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtctm.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtcprx.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtclog.dll
2008-08-22 16:29:30 ----A---- D:\WINDOWS\system32\msdtc.exe
2008-08-22 16:29:29 ----D---- D:\WINDOWS\system32\Com
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\colbact.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\clbcatex.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\catsrvut.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\catsrvps.dll
2008-08-22 16:29:29 ----A---- D:\WINDOWS\system32\catsrv.dll
2008-08-22 16:29:28 ----A---- D:\WINDOWS\system32\comuid.dll
2008-08-22 16:29:28 ----A---- D:\WINDOWS\system32\comsvcs.dll
2008-08-22 16:29:28 ----A---- D:\WINDOWS\system32\clbcatq.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\servdeps.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\mmfutil.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\licwmi.dll
2008-08-22 16:29:22 ----A---- D:\WINDOWS\system32\cmprops.dll
2008-07-14 13:09:18 ----N---- D:\WINDOWS\system32\tzchange.exe

======List of files/folders modified in the last 3 months======

2008-10-04 19:22:22 ----A---- D:\WINDOWS\system.ini
2008-09-27 21:36:06 ----A---- D:\WINDOWS\win.ini
2008-07-18 22:10:48 ----A---- D:\WINDOWS\system32\cdm.dll
2008-07-18 22:10:40 ----A---- D:\WINDOWS\system32\wups2.dll
2008-07-18 22:10:36 ----A---- D:\WINDOWS\system32\wucltui.dll.mui
2008-07-18 22:09:14 ----A---- D:\WINDOWS\system32\wuapi.dll.mui
2008-07-18 22:09:06 ----A---- D:\WINDOWS\system32\wuaueng.dll.mui
2008-07-07 22:31:48 ----A---- D:\WINDOWS\system32\es.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
R1 aswSP;avast! Self Protect

Répondre à nigga_nigga

24

sKe69, le 4 oct 2008 à 19:42:40

Presque mais il en manque encore ... :))))

de ce chapitre à la fin :

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======


merci ...=)
Rien ne sert de courir .... Non, ça sert à rien ...    ---sK­e---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

25

nigga_nigga, le 4 oct 2008 à 19:52:25

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
R1 aswSP;avast! Self Protection; D:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
R1 intelppm;Pilote de processeur Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 40320]
R1 kbdhid;Pilote HID de clavier; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
R3 3xHybrid;3xHybrid service; D:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
R3 Arp1394;Protocole client ARP 1394; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 aswRdr;aswRdr; D:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
R3 catchme;catchme; \??\D:\ComboFix\catchme.sys []
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Pilote de classe HID Microsoft; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-24 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-06-29 3173888]
R3 LVUSBSta;Logitech USB Monitor Filter; D:\WINDOWS\system32\drivers\lvusbsta.sys [2005-05-27 22016]
R3 mouhid;Pilote HID de souris; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-24 12288]
R3 NIC1394;Pilote réseau 1394; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-06-01 3925920]
R3 pepifilter;Volume Adapter; D:\WINDOWS\system32\DRIVERS\lv302af.sys [2005-05-27 7136]
R3 PID_08A0;QuickCam IM(PID_08A0); D:\WINDOWS\system32\DRIVERS\LV302AV.SYS [2005-05-27 913280]
R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); D:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 usbaudio;Pilote USB audio (WDM); D:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Concentrateur USB2; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Pilote de stockage de masse USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 X10Hid;X10 Hid Device; D:\WINDOWS\System32\Drivers\x10hid.sys [2005-11-28 7040]
S3 a2nsniok;a2nsniok; D:\WINDOWS\system32\drivers\a2nsniok.sys []
S3 CCDECODE;Décodeur sous-titre fermé; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; D:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; D:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; D:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; D:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 MPE;Filtre BDA MPE; D:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;Détrameur décalage BDA; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Classe d'imprimantes USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 wceusbsh;Windows CE USB Serial Host Driver; D:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Codec Teletext standard; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 mchInjDrv;mchInjDrv; \??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; D:\Program Files\Avast4\aswUpdSv.exe [2008-07-19 16056]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\Avast4\ashServ.exe [2008-07-19 147640]
R2 gusvc;Google Updater Service; D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-22 137200]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2006-06-01 155715]
R2 UxTuneUp;TuneUp Extension de thème; D:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 x10nets;X10 Device Network Service; D:\PROGRA~1\Common Files\X10\Common\x10nets.exe [2001-11-12 20480]
R3 avast! Mail Scanner;avast! Mail Scanner; D:\Program Files\Avast4\ashMaiSv.exe [2008-07-19 250040]
R3 avast! Web Scanner;avast! Web Scanner; D:\Program Files\Avast4\ashWebSv.exe [2008-07-23 348344]
S2 Pml Driver HPZ12;Pml Driver HPZ12; D:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
S3 NMIndexingService;NMIndexingService; D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PACSPTISVR;PACSPTISVR; D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe [2004-10-29 53337]
S3 SPTISRV;Sony SPTI Service; D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe [2004-10-29 69718]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; D:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-22 355584]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; D:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; D:\Program Files\Windows Media Player\wmpnetwk.exe [2006-10-24 918016]

-----------------EOF-----------------

Répondre à nigga_nigga

26

sKe69, le 4 oct 2008 à 20:01:32

Hic ... il faut refaire la manipe ....

1-Crées un doc texte sur ton bureau :
pointes ta souris sur ton bureau , cliques droit : vas dans "nouveau" et choisis "document texte" .

Ensuite copie/colle le texte ci-dessous ( et rien d'autre!) dans le fichier texte que tu viens de créer :

driver::
mchInjDrv
a2nsniok



Puis vas dans "fichier" et choisis "enregistrer sous ..." et tu le nommes exactement ainsi :
CFScript puis valides ...


2-Nettoyage :

!! Déconnectes toi, fermes toutes tes applications et désactives TOUTES TES DEFENSES ( tu les réactiveras après ) !!

--->Sur ton bureau, fais un glissé avec ta souris le fichier CFScript sur l'icône de ComboFix.exe .

(Regarde ici : http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript.gif )

Cette manipulation va relancer combofix .
--> Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tapes 1 puis valide.

Puis patientes le temps du scan.( Le Bureau va disparaître à plusieurs reprises : c'est normal!)

!! Ne touches à rien tant que le scan n'est pas terminé !!

Note : en fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisses-le faire.

Une fois le scan achevé, un rapport va s'afficher : Postes le accompagné d' un nouveau rapport RSIT ( les deux derniers chapitres seulement ! ) pour analyse ...

( Attention : cette manipe a été fait pour ce PC . Toute réutilisation peut endommager sévèrement le système d'exploitation ) Rien ne sert de courir .... Non, ça sert à rien ...    ---sKe---
"Baby, I'm going on an airplane, And I don't know if I'll be back again."
IMPORTANT : ne vous croyez pas tiré d'affaire
tant qu'on ne vous l'a pas dit !

Répondre à sKe69

27

nigga_nigga, le 4 oct 2008 à 20:23:33

ComboFix 08-10-04.01 - Did 2008-10-04 20:09:39.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.638 [GMT 2:00]
Lancé depuis: D:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: D:\Documents and Settings\Administrateur\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé

[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MCHINJDRV
-------\Service_a2nsniok
-------\Service_mchInjDrv


((((((((((((((((((((((((((((( Fichiers créés du 2008-09-04 au 2008-10-04 ))))))))))))))))))))))))))))))))))))
.

2008-10-04 13:51 . 2008-10-04 13:52 <REP> d-------- D:\rsit
2008-10-04 13:29 . 2008-10-04 13:29 <REP> d-------- D:\Program Files\CCleaner
2008-10-04 12:43 . 2008-10-04 13:09 1,944 --a------ D:\Documents and Settings\Orph.egd
2008-10-04 12:41 . 2008-10-04 19:26 <REP> d-------- D:\ToolBar SD
2008-10-04 09:47 . 2008-10-04 09:47 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 09:47 . 2008-10-04 09:47 <REP> d-------- D:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-04 09:16 . 2008-10-04 12:34 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-04 09:03 . 2008-10-04 09:03 <REP> d-------- D:\Program Files\Trend Micro
2008-09-05 15:41 . 2008-09-05 15:41 <REP> d--h----- D:\WINDOWS\system32\GroupPolicy

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-04 10:26 --------- d-----w D:\Program Files\eMule
2008-10-04 06:40 --------- d-----w D:\Program Files\Avast4
2008-10-03 21:55 --------- d-----w D:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-03 16:22 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Azureus
2008-09-28 16:39 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\GigaTribe
2008-09-25 08:16 --------- d-----w D:\Program Files\MSN Messenger
2008-09-25 08:16 --------- d-----w D:\Program Files\Messenger Plus! Live
2008-09-14 14:53 --------- d-----w D:\Program Files\TuneUp Utilities 2008
2008-08-31 14:15 --------- d-----w D:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-31 14:14 --------- d-----w D:\Program Files\Siber Systems
2008-08-31 08:01 --------- d-----w D:\Program Files\GigaTribe
2008-08-31 07:24 2,290,176 ----a-w D:\WINDOWS\system32\TUKernel.exe
2008-08-29 17:59 --------- d-----w D:\Program Files\La Marmite du Chef
2008-08-29 06:44 --------- d-----w D:\Program Files\SuperCopier2
2008-08-28 14:38 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Winamp
2008-08-26 08:50 --------- d---a-w D:\Documents and Settings\All Users\Application Data\rkfree
2008-08-26 06:33 --------- d-----w D:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-26 06:29 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\HP
2008-08-25 15:22 --------- d-----w D:\Program Files\MappySynchro
2008-08-25 14:50 --------- d-----w D:\Program Files\Microsoft ActiveSync
2008-08-24 13:17 --------- d-----w D:\Documents and Settings\Aurore\Application Data\MSN Pictures Displayer
2008-08-24 07:48 --------- d-----w D:\Documents and Settings\Aurore\Application Data\Nero
2008-08-24 07:47 --------- d-----w D:\Documents and Settings\Aurore\Application Data\HP
2008-08-24 07:38 98,304 ----a-w D:\WINDOWS\system32\qttask.exe
2008-08-24 07:38 --------- d-----w D:\Program Files\QuickTime
2008-08-24 07:37 --------- d-----w D:\Program Files\ACE Mega CoDecS Pack
2008-08-24 07:26 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Sony Corporation
2008-08-24 07:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\HP
2008-08-24 07:01 --------- d-----w D:\Program Files\HP
2008-08-24 07:01 --------- d-----w D:\Program Files\Fichiers communs\HP
2008-08-24 07:00 --------- d-----w D:\Program Files\Hewlett-Packard
2008-08-24 07:00 --------- d-----w D:\Program Files\Fichiers communs\Hewlett-Packard
2008-08-23 21:21 --------- d-----w D:\Program Files\MSXML 4.0
2008-08-23 07:34 81,920 ------r D:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2008-08-23 07:34 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-08-23 07:34 --------- d-----w D:\Program Files\Logitech
2008-08-23 07:34 --------- d-----w D:\Program Files\Fichiers communs\Logitech
2008-08-23 07:24 --------- d-----w D:\Program Files\Azureus
2008-08-23 06:22 --------- d-----w D:\Documents and Settings\Aurore\Application Data\vlc
2008-08-23 06:03 --------- d-----w D:\Program Files\Sony
2008-08-23 06:03 --------- d-----w D:\Program Files\Fichiers communs\Sony Shared
2008-08-23 06:02 --------- d-----w D:\Program Files\Sony Corporation
2008-08-23 06:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 05:56 --------- d-----w D:\Program Files\Fichiers communs\InstallShield
2008-08-23 05:38 --------- d-----w D:\Program Files\MSN Pictures Displayer
2008-08-23 05:36 446,976 ----a-w D:\WINDOWS\system32\ShellMPD.dll
2008-08-23 05:36 --------- d-----w D:\Program Files\Java
2008-08-23 05:36 --------- d-----w D:\Program Files\Fichiers communs\Java
2008-08-22 19:26 --------- d-----w D:\Program Files\Windows Live
2008-08-22 19:26 --------- d-----w D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-22 19:24 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\MSN Pictures Displayer
2008-08-22 19:00 --------- d-----w D:\Documents and Settings\All Users\Application Data\Azureus
2008-08-22 17:58 --------- d-----w D:\Program Files\Google
2008-08-22 17:42 --------- d-----w D:\Documents and Settings\Aurore\Application Data\TuneUp Software
2008-08-22 17:31 20,480 ------w D:\WINDOWS\system32\normaliz.dll
2008-08-22 17:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-22 17:02 --------- d-----w D:\Program Files\Microsoft Works
2008-08-22 17:02 --------- d-----w D:\Program Files\Microsoft Office Professional Plus 2007
2008-08-22 16:57 --------- d-----w D:\Program Files\Fichiers communs\Adobe
2008-08-22 16:43 --------- d-----w D:\Program Files\Windows Media Connect 2
2008-08-22 16:33 --------- d-----w D:\Program Files\Apple Software Update
2008-08-22 16:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-22 16:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple
2008-08-22 16:25 --------- d-----w D:\Program Files\Winamp
2008-08-22 16:21 --------- d-----w D:\Program Files\VideoLAN
2008-08-22 16:21 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\vlc
2008-08-22 16:14 --------- d-----w D:\Program Files\Fichiers communs\Nero
2008-08-22 16:14 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Nero
2008-08-22 16:13 --------- d-----w D:\Program Files\Nero
2008-08-22 16:13 --------- d-----w D:\Documents and Settings\All Users\Application Data\Nero
2008-08-22 16:07 --------- d-----w D:\Program Files\DAEMON Tools Lite
2008-08-22 16:02 --------- d-----w D:\Program Files\Cool Edit Pro 2.1
2008-08-22 15:59 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\Syntrillium
2008-08-22 15:52 --------- d-----w D:\Program Files\Virtual Dj 3.2
2008-08-22 15:43 717,296 ----a-w D:\WINDOWS\system32\drivers\sptd.sys
2008-08-22 15:43 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\DAEMON Tools
2008-08-22 15:24 355,584 ----a-w D:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-22 15:23 --------- d-----w D:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-08-22 15:22 --------- d-----w D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-22 15:22 --------- d-----w D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-22 15:05 --------- d-----w D:\Documents and Settings\LocalService\Application Data\X10 Commander
2008-08-22 15:04 --------- d-----w D:\Program Files\X10 Hardware
2008-08-22 15:04 --------- d-----w D:\Program Files\Common Files
2008-08-22 15:03 --------- d-----w D:\Program Files\Intel
2008-08-22 14:33 --------- d-----w D:\Program Files\microsoft frontpage
2008-08-22 14:31 --------- d-----w D:\Program Files\Services en ligne
2008-07-18 20:10 94,920 ----a-w D:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w D:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w D:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w D:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w D:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w D:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w D:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w D:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w D:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w D:\WINDOWS\system32\muweb.dll
2008-07-07 20:31 253,952 ----a-w D:\WINDOWS\system32\es.dll
.

------- Sigcheck -------

2004-08-23 00:35 1036288 998f3f568f6074a35ab08cd3395a9dc2 D:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-10-04_18.15.30.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-04 18:12:18 16,384 ----atw D:\WINDOWS\Temp\Perflib_Perfdata_4a0.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="D:\Program Files\SuperCopier2\SuperCopier2.exe" [2005-03-14 1057280]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-22 39408]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"RoboForm"="D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-09-28 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2006-06-01 7618560]
"LVCOMSX"="D:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"rkfree"="D:\WINDOWS\Winreveal\rkfree.exe" [2008-08-26 66048]
"QuickTime Task"="D:\WINDOWS\system32\qttask.exe" [2008-08-24 98304]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-29 D:\WINDOWS\RTHDCPL.EXE]

D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="D:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\iac25_32.ax
"vidc.avrn"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avidavicodec.dll
"vidc.advj"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avidavicodec.dll
"vidc.mszh"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avimszh.dll
"vidc.zlib"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\avizlib.dll
"msacm.lameacm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\lameacm.acm
"vidc.asv1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv1.dll
"vidc.asv2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv2.dll
"vidc.asvx"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\ASUS\asusasv2.dll
"vidc.div3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.div5"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.mpg3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32.dll
"vidc.div4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.div6"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.ap41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivXc32f.dll
"vidc.dvx4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\divx4.dll
"vidc.divx"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\DivX520.dll
"msacm.divxa32"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\DivX\divxa32.acm
"vidc.i263"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\i263_32.drv
"vidc.iv30"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv31"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv32"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv33"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv34"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv35"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv36"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv37"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv38"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv39"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir32_32.dll
"vidc.iv40"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv42"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv43"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv44"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv45"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv46"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv47"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv48"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv49"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir41_32.dll
"vidc.iv50"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\ir50_32.dll
"vidc.iyuv"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\Iyvu9_32.dll
"vidc.ir21"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IR21_R.DLL
"vidc.rt21"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IR21_R.DLL
"msacm.imc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Intel\IMC32.ACM
"vidc.dv25"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.dv50"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.msmc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mmjp"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx5"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx6"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx7"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx8"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mtx9"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"vidc.mmes"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Matrox\DigiVCap.dll
"msacm.msadpcm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msadp32.acm
"msacm.imaadpcm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\imaadp32.acm
"msacm.msg711"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msg711.acm
"msacm.msg723"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msg723.acm
"msacm.msgsm610"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msgsm32.acm
"vidc.m261"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh261.drv
"vidc.m263"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh263.drv
"vidc.i420"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msh263.drv
"vidc.mrle"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msrle32.dll
"vidc.uyvy"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.yuy2"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.yvyu"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msyuv.dll
"vidc.msvc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msvidc32.dll
"vidc.cram"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msvidc32.dll
"vidc.mpg4"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp41"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp42"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp43"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp4s"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.mp4v"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\mpg4c32.dll
"vidc.wmv3"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\WMV9VCM.dll
"msacm.msaudio1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Microsoft\msaud32.acm
"msacm.vorbis"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\OGG\vorbis.acm
"vidc.pdvc"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Panasonic\idvcodec.dll
"vidc.ipdv"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Panasonic\idvcodec.dll
"vidc.miro"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\mirodv2avi.dll
"vidc.dcap"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\mirodv2avi.dll
"vidc.mjpa"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\rtmjpgcdc.dll
"vidc.gpjm"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\rtmjpgcdc.dll
"vidc.pim1"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\Pinnacle\pclepim1.dll
"vidc.xvid"= D:\PROGRA~1\ACE Mega CoDecS Pack\SystemS\XviD\xvidvfw.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
"swg"=D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\GigaTribe\\gigatribe.exe"=
"D:\\Program Files\\Microsoft Office Professional Plus 2007\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Azureus\\Azureus.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"D:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"= D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"= D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;D:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 UxTuneUp;TuneUp Extension de thème;D:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 3xHybrid;3xHybrid service;D:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
R3 X10Hid;X10 Hid Device;D:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 7040]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;D:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-22 355584]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - MCHINJDRV
.
Contenu du dossier 'Tâches planifiées'

2008-10-04 D:\WINDOWS\Tasks\Maintenance en 1 clic.job
- D:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:23]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 20:20:03
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp"
.
------------------------ Autres processus actifs ------------------------
.
D:\Program Files\Avast4\aswUpdSv.exe
D:\Program Files\Avast4\ashServ.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\PROGRA~1\Common Files\X10\Common\X10nets.exe
D:\WINDOWS\system32\wscntfy.exe
D:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
D:\ComboFix\pv.cfexe
.
**************************************************************************
.
Heure de fin: 2008-10-04 20:21:01 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-04 18:20:57
ComboFix2.txt 2008-10-04 17:23:36
ComboFix3.txt 2008-10-04 16:16:04

Avant-CF: 32 383 950 848 octets libres
Après-CF: 32,374,177,792 octets libres

324 --- E O F --- 2008-09-13 20:54:16

Répondre à nigga_nigga

28

nigga_nigga, le 4 oct 2008 à 20:25:06

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswSP;avast! Self Protection; D:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
R1 intelppm;Pilote de processeur Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 40320]
R1 kbdhid;Pilote HID de clavier; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
R3 3xHybrid;3xHybrid service; D:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
R3 Arp1394;Protocole client ARP 1394; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 catchme;catchme; \??\D:\ComboFix\catchme.sys []
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Pilote de classe HID Microsoft; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-24 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-06-29 3173888]
R3 LVUSBSta;Logitech USB Monitor Filter; D:\WINDOWS\system32\drivers\lvusbsta.sys [2005-05-27 22016]
R3 mouhid;Pilote HID de souris; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-24 12288]
R3 NIC1394;Pilote réseau 1394; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-06-01 3925920]
R3 pepifilter;Volume Adapter; D:\WINDOWS\system32\DRIVERS\lv302af.sys [2005-05-27 7136]
R3 PID_08A0;QuickCam IM(PID_08A0); D:\WINDOWS\system32\DRIVERS\LV302AV.SYS [2005-05-27 913280]
R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); D:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 usbaudio;Pilote USB audio (WDM); D:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Concentrateur USB2; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbstor;Pilote de stockage de masse USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 X10Hid;X10 Hid Device; D:\WINDOWS\System32\Drivers\x10hid.sys [2005-11-28 7040]
S3 aswRdr;aswRdr; D:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
S3 axk9zko3;axk9zko3; D:\WINDOWS\system32\drivers\axk9zko3.sys []
S3 CCDECODE;Décodeur sous-titre fermé; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; D:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; D:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; D:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; D:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 MPE;Filtre BDA MPE; D:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;Détrameur décalage BDA; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Classe d'imprimantes USB Microsoft; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 wceusbsh;Windows CE USB Serial Host Driver; D:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Codec Teletext standard; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; D:\Program Files\Avast4\aswUpdSv.exe [2008-07-19 16056]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\Avast4\ashServ.exe [2008-07-19 147640]
R2 gusvc;Google Updater Service; D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-22 137200]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2006-06-01 155715]
R2 UxTuneUp;TuneUp Extension de thème; D:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 x10nets;X10 Device Network Service; D:\PROGRA~1\Common Files\X10\Common\x10nets.exe [2001-11-12 20480]
S2 Pml Driver HPZ12;Pml Driver HPZ12; D:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
S3 avast! Mail Scanner;avast! Mail Scanner; D:\Program Files\Avast4\ashMaiSv.exe [2008-07-19 250040]
S3 avast! Web Scanner;avast! Web Scanner; D:\Program Files\Avast4\ashWebSv.exe [2008-07-23 348344]
S3 NMIndexingService;NMIndexingService; D:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PACSPTISVR;PACSPTISVR; D:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe [2004-10-29 53337]
S3 SPTISRV;Sony SPTI Service; D:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe [2004-10-29 69718]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; D:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-22 355584]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; D:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; D:\Program Files\Windows Media Player\wmpnetwk.exe [2006-10-24 918016]

-----------------EOF-----------------

Répondre à nigga_nigga