Quel galere mon pc m'ouvre un peu les liens qui lui convient... , j'ai pas reussi avec ton lien de diaghelp non plus mais j'ai reussi à le trouver ailleurs .
voila le rapport
DiagHelp version v1.4 -
http://www.malekal.com
excute le 23/10/2008 à 1:04:52,25
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->23/10/2008 01:04:09
C:\WINDOWS\prefetch\NTVDM.EXE-1A10A423.pf -->23/10/2008 01:03:11
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->23/10/2008 01:03:02
C:\WINDOWS\prefetch\FIND.EXE-0EC32F1E.pf -->23/10/2008 01:02:39
C:\WINDOWS\prefetch\AVGCMGR.EXE-1D29CBA8.pf -->23/10/2008 01:00:00
C:\WINDOWS\prefetch\EXPLORER.EXE-082F38A9.pf -->23/10/2008 00:57:48
C:\WINDOWS\prefetch\WINZIP32.EXE-335422C1.pf -->23/10/2008 00:57:35
C:\WINDOWS\prefetch\FIREFOX.EXE-28641590.pf -->23/10/2008 00:53:53
C:\WINDOWS\prefetch\NOTEPAD.EXE-336351A9.pf -->22/10/2008 23:48:55
C:\WINDOWS\prefetch\WMIPRVSE.EXE-28F301A9.pf -->22/10/2008 23:46:16
C:\WINDOWS\System32\drivers\avgtdix.sys -->22/10/2008 13:39:43
C:\WINDOWS\System32\drivers\avgldx86.sys -->22/10/2008 13:39:38
C:\WINDOWS\System32\drivers\avgmfx86.sys -->22/10/2008 13:39:36
C:\WINDOWS\System32\drivers\GEARAspiWDM.sys -->17/04/2008 13:12:54
C:\WINDOWS\System32\drivers\pxhelp20.sys -->23/02/2008 04:38:33
C:\WINDOWS\System32\drivers\cdralw2k.sys -->05/10/2006 04:42:42
C:\WINDOWS\System32\drivers\cdr4_xp.sys -->05/10/2006 04:42:42
C:\WINDOWS\System32\tmp.txt -->22/10/2008 23:32:52
C:\WINDOWS\System32\tmp.reg -->22/10/2008 23:32:52
C:\WINDOWS\System32\avgrsstx.dll -->22/10/2008 13:39:44
C:\WINDOWS\System32\CONFIG.NT -->22/10/2008 12:19:28
C:\WINDOWS\System32\delself.bat -->19/10/2008 19:33:48
C:\WINDOWS\System32\wpa.dbl -->19/10/2008 13:31:02
C:\WINDOWS\System32\o4Patch.exe -->10/10/2008 08:58:08
C:\WINDOWS\System32\IEDFix.C.exe -->10/10/2008 08:58:08
C:\WINDOWS\System32\FNTCACHE.DAT -->06/10/2008 11:58:18
C:\WINDOWS\System32\Thumbs.db -->05/10/2008 21:52:07
C:\WINDOWS\System32\VACFix.exe -->01/10/2008 15:51:40
C:\WINDOWS\System32\h323log.txt -->16/09/2008 14:40:47
C:\WINDOWS\System32\PerfStringBackup.INI -->16/09/2008 13:38:21
C:\WINDOWS\System32\perfh00C.dat -->16/09/2008 13:38:21
C:\WINDOWS\System32\perfh009.dat -->16/09/2008 13:38:21
C:\WINDOWS\System32\perfc00C.dat -->16/09/2008 13:38:21
C:\WINDOWS\System32\perfc009.dat -->16/09/2008 13:38:21
C:\WINDOWS\System32\YourCPLconfig.txt -->16/09/2008 13:07:51
C:\WINDOWS\System32\jupdate-1.5.0_07-b03.log -->16/09/2008 13:07:15
C:\WINDOWS\System32\nscompat.tlb -->16/09/2008 13:02:54
C:\WINDOWS\System32\amcompat.tlb -->16/09/2008 13:02:54
C:\WINDOWS\System32\$winnt$.inf -->16/09/2008 12:51:49
C:\WINDOWS\System32\WindowsLogon.manifest -->16/09/2008 12:45:40
C:\WINDOWS\System32\logonui.exe.manifest -->16/09/2008 12:45:40
C:\WINDOWS\System32\wuaucpl.cpl.manifest -->16/09/2008 12:45:33
C:\WINDOWS\setupapi.log -->23/10/2008 00:59:46
C:\WINDOWS\WindowsUpdate.log -->22/10/2008 23:35:39
C:\WINDOWS\wiadebug.log -->22/10/2008 23:35:38
C:\WINDOWS\wiaservc.log -->22/10/2008 23:35:37
C:\WINDOWS\bootstat.dat -->22/10/2008 23:35:16
C:\WINDOWS\SchedLgU.Txt -->22/10/2008 23:23:01
C:\WINDOWS\nsreg.dat -->20/10/2008 17:37:01
C:\WINDOWS\CDE DX4400DEFGIPS.ini -->06/10/2008 17:45:39
C:\WINDOWS\Sti_Trace.log -->16/09/2008 15:42:57
C:\WINDOWS\system.ini -->16/09/2008 14:34:39
C:\WINDOWS\ODBC.INI -->16/09/2008 13:46:43
C:\WINDOWS\RTHDCPL_DB.dbt -->16/09/2008 13:31:59
C:\WINDOWS\REGLOCS.OLD -->16/09/2008 12:52:59
C:\WINDOWS\WMSysPr9.prx -->16/09/2008 12:47:53
C:\WINDOWS\win.ini -->16/09/2008 12:47:01
winlogon.exe
svchost.exe
ws2_32.dll
user32.dll
tcpip.sys
ndis.sys
null.sys
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1544
Command line: C:\WINDOWS\Explorer.EXE
Base Size Version Path
0x10000000 0x5000 8.00.0000.0134 C:\WINDOWS\system32\avgrsstx.dll
0x58b50000 0x9a000 5.82.2900.2649 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
0x745e0000 0x2c6000 3.01.4000.2435 C:\WINDOWS\system32\msi.dll
0x017b0000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x013d0000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x01900000 0x29000 C:\Program Files\WinRAR\rarext.dll
0x01380000 0x13000 1.01.0000.0000 C:\Program Files\EPSON\Creativity Suite\Easy Photo Print\EPPShell.dll
0x73d20000 0xfe000 6.02.4131.0000 C:\WINDOWS\system32\MFC42.DLL
0x61d70000 0xe000 6.00.8665.0000 C:\WINDOWS\system32\MFC42LOC.DLL
0x621a0000 0x1b000 8.00.0000.0134 C:\Program Files\AVG\AVG8\avgse.dll
0x7c420000 0x87000 8.00.50727.0762 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll
0x78130000 0x9b000 8.00.50727.0762 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
0x01940000 0x1c000 7.00.0000.0000 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
0x01d50000 0x5b000 1.01.0000.0000 C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
0x325c0000 0x12000 11.00.5510.0000 C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 760
Command line: winlogon.exe
Base Size Version Path
0x01000000 0x81000 \??\C:\WINDOWS\system32\winlogon.exe
0x10000000 0x5000 8.00.0000.0134 C:\WINDOWS\system32\avgrsstx.dll
0x58b50000 0x9a000 5.82.2900.2649 C:\WINDOWS\system32\COMCTL32.dll
0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x73d50000 0x3000 1.05.0532.0000 C:\WINDOWS\system32\WgaLogon.dll
0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 0457-D984
Répertoire de C:\WINDOWS\system32
19/08/2004 16:09 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 52 270 014 464 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 0457-D984
Répertoire de C:\WINDOWS\Downloaded Program Files
06/10/2008 17:53 <REP> .
06/10/2008 17:53 <REP> ..
16/09/2008 12:45 65 desktop.ini
25/07/2002 17:13 24 576 dwusplay.dll
25/07/2002 17:13 196 608 dwusplay.exe
24/03/2008 19:33 1 527 056 FP_AX_CAB_INSTALLER.exe
25/07/2002 17:05 172 032 isusweb.dll
24/03/2008 19:18 247 swflash.inf
6 fichier(s) 1 920 584 octets
Total des fichiers listés :
6 fichier(s) 1 920 584 octets
2 Rép(s) 52 270 014 464 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
Export de la clef SharedTaskScheduler
exports des policies
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-23 01:05:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden services & system hive ...
disk error: C:\WINDOWS\system32\config\system, 0
scanning hidden registry entries ...
disk error: C:\WINDOWS\system32\config\software, 0
disk error: C:\Documents and Settings\Mel\ntuser.dat, 0
scanning hidden files ...
disk error: C:\
please note that you need administrator rights to perform deep scan
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
148 - E_FATICAE.EXE
488 - AppleMobileDevi
504 - avgwdsvc.exe
544 - mDNSResponder.e
736 - csrss.exe
816 - services.exe
828 - lsass.exe
972 - svchost.exe
1040 - svchost.exe
1076 - svchost.exe
1236 - svchost.exe
1544 - explorer.exe
1656 - spoolsv.exe
1700 - msnmsgr.exe
1836 - RTHDCPL.EXE
1876 - hkcmd.exe
1892 - igfxpers.exe
1920 - iTunesHelper.ex
1936 - HiYo.exe
1948 - EoEngine.exe
1960 - avgtray.exe
2024 - btdna.exe
2108 - cmd.exe
2112 - avgemc.exe
2456 - iPodService.exe
2748 - alg.exe
2836 - jucheck.exe
3272 - svchost.exe
Total number of processes = 29
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntkrnlpa.exe
806CE000 - \WINDOWS\system32\hal.dll
F8974000 - \WINDOWS\system32\KDCOM.DLL
F8884000 - \WINDOWS\system32\BOOTVID.dll
F8344000 - ACPI.sys
F8976000 - \WINDOWS\system32\DRIVERS\WMILIB.SYS
F8333000 - pci.sys
F8474000 - isapnp.sys
F8484000 - ohci1394.sys
F8494000 - \WINDOWS\system32\DRIVERS\1394BUS.SYS
F8888000 - compbatt.sys
F888C000 - \WINDOWS\system32\DRIVERS\BATTC.SYS
F8A3C000 - pciide.sys
F86F4000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F8978000 - intelide.sys
F8315000 - pcmcia.sys
F84A4000 - MountMgr.sys
F82F6000 - ftdisk.sys
F897A000 - dmload.sys
F82D0000 - dmio.sys
F8890000 - ACPIEC.sys
F8A3D000 - \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
F86FC000 - PartMgr.sys
F84B4000 - VolSnap.sys
F82B8000 - atapi.sys
F84C4000 - disk.sys
F84D4000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F8299000 - fltMgr.sys
F8287000 - sr.sys
F84E4000 - PxHelp20.sys
F8270000 - KSecDD.sys
F81E3000 - Ntfs.sys
F81B6000 - NDIS.sys
F819C000 - Mup.sys
F8504000 - \SystemRoot\system32\DRIVERS\nic1394.sys
F85F4000 - \SystemRoot\system32\DRIVERS\intelppm.sys
F8934000 - \SystemRoot\system32\DRIVERS\CmBatt.sys
F8031000 - \SystemRoot\system32\DRIVERS\ialmnt5.sys
F801D000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
F7FF7000 - \SystemRoot\system32\DRIVERS\HDAudBus.sys
F8754000 - \SystemRoot\system32\DRIVERS\usbuhci.sys
F7FD4000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
F875C000 - \SystemRoot\system32\DRIVERS\usbehci.sys
F7FB7000 - \SystemRoot\system32\drivers\tifmsony.sys
F7F1E000 - \SystemRoot\system32\DRIVERS\e100b325.sys
F8764000 - \SystemRoot\system32\DRIVERS\SonyNC.sys
F8604000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
F876C000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
F8774000 - \SystemRoot\system32\DRIVERS\mouclass.sys
F8614000 - \SystemRoot\system32\DRIVERS\imapi.sys
F8624000 - \SystemRoot\system32\DRIVERS\cdrom.sys
F8634000 - \SystemRoot\system32\DRIVERS\redbook.sys
F7EFB000 - \SystemRoot\system32\DRIVERS\ks.sys
F8938000 - \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
F8B68000 - \SystemRoot\system32\DRIVERS\audstub.sys
F8644000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
F8940000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
F7EBC000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
F8654000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
F8664000 - \SystemRoot\system32\DRIVERS\raspptp.sys
F877C000 - \SystemRoot\system32\DRIVERS\TDI.SYS
F7EAB000 - \SystemRoot\system32\DRIVERS\psched.sys
F8674000 - \SystemRoot\system32\DRIVERS\msgpc.sys
F8784000 - \SystemRoot\system32\DRIVERS\ptilink.sys
F878C000 - \SystemRoot\system32\DRIVERS\raspti.sys
F7E7A000 - \SystemRoot\system32\DRIVERS\rdpdr.sys
F8684000 - \SystemRoot\system32\DRIVERS\termdd.sys
F898E000 - \SystemRoot\system32\DRIVERS\swenum.sys
F7E46000 - \SystemRoot\system32\DRIVERS\update.sys
F895C000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
F8694000 - \SystemRoot\System32\Drivers\NDProxy.SYS
AAC9D000 - \SystemRoot\system32\drivers\RtkHDAud.sys
AAC7B000 - \SystemRoot\system32\drivers\portcls.sys
F86B4000 - \SystemRoot\system32\drivers\drmk.sys
AAC49000 - \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
AAB55000 - \SystemRoot\system32\DRIVERS\HSF_DPV.sys
AAAA4000 - \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
F8794000 - \SystemRoot\System32\Drivers\Modem.SYS
F86D4000 - \SystemRoot\system32\DRIVERS\usbhub.sys
F8992000 - \SystemRoot\system32\DRIVERS\USBD.SYS
F8994000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F8A6D000 - \SystemRoot\System32\Drivers\Null.SYS
F87B4000 - \SystemRoot\System32\drivers\vga.sys
F8996000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F8998000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F87BC000 - \SystemRoot\System32\Drivers\Msfs.SYS
F87C4000 - \SystemRoot\System32\Drivers\Npfs.SYS
F814B000 - \SystemRoot\system32\DRIVERS\rasacd.sys
AAA49000 - \SystemRoot\system32\DRIVERS\ipsec.sys
AA9F1000 - \SystemRoot\system32\DRIVERS\tcpip.sys
AA9C9000 - \SystemRoot\system32\DRIVERS\netbt.sys
AA9A7000 - \SystemRoot\System32\drivers\afd.sys
F8514000 - \SystemRoot\system32\DRIVERS\netbios.sys
AA96A000 - \SystemRoot\system32\DRIVERS\rdbss.sys
AA8FB000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
F8524000 - \SystemRoot\System32\Drivers\Fips.SYS
AA8DA000 - \SystemRoot\system32\DRIVERS\ipnat.sys
F8534000 - \SystemRoot\system32\DRIVERS\wanarp.sys
F8544000 - \SystemRoot\system32\DRIVERS\arp1394.sys
F87DC000 - \SystemRoot\System32\Drivers\avgmfx86.sys
AA8C3000 - \SystemRoot\System32\Drivers\avgldx86.sys
F8574000 - \SystemRoot\System32\Drivers\Cdfs.SYS
BF800000 - \SystemRoot\System32\win32k.sys
F7ED7000 - \SystemRoot\System32\drivers\Dxapi.sys
F87FC000 - \SystemRoot\System32\watchdog.sys
BF9C2000 - \SystemRoot\System32\drivers\dxg.sys
F8B00000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9E2000 - \SystemRoot\System32\ialmdnt5.dll
BF9D4000 - \SystemRoot\System32\ialmrnt5.dll
BFA03000 - \SystemRoot\System32\ialmdev5.DLL
BFA37000 - \SystemRoot\System32\ialmdd5.DLL
AA6FF000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
AA44E000 - \SystemRoot\system32\drivers\wdmaud.sys
F7DBD000 - \SystemRoot\system32\drivers\sysaudio.sys
A9F7C000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
A9F43000 - \SystemRoot\System32\Drivers\avgtdix.sys
A9FDD000 - \SystemRoot\system32\DRIVERS\mdmxsdk.sys
A9EC9000 - \SystemRoot\system32\DRIVERS\srv.sys
A9B18000 - \SystemRoot\System32\Drivers\HTTP.sys
F8B6D000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 120
Liste des programmes installes
Adobe Flash Player ActiveX
Adobe Reader 7.0.8 - Français
Apple Mobile Device Support
Apple Software Update
Archiveur WinRAR
Assistant de connexion Windows Live
AVG Free 8.0
Bonjour
Camera RAW Plug-In for EPSON Creativity Suite
CCleaner (remove only)
Codeur Windows Media Série 9
Codeur Windows Media Série 9
Correctif Windows XP - KB867282
Correctif Windows XP - KB885894
CX4300_5500_DX4400 Manuel
eoEngine 7.1
EPSON Attach To Email
EPSON Attach To Email
EPSON Copy Utility 3
EPSON Easy Photo Print
EPSON File Manager
EPSON Logiciel imprimante
EPSON Scan
EPSON Scan Assistant
EPSON Web-To-Page
Exstora Pro 2.3
HDAUDIO SoftV92 Data Fax Modem with SmartCP
High Definition Audio Driver Package - KB835221
HiYo
HiYo
Hotfix for Windows Media Format SDK (KB902344)
Intel(R) Graphics Media Accelerator Driver for Mobile
Intel(R) PRO Network Connections Drivers
iTunes
J2SE Runtime Environment 5.0 Update 7
Lecteur Windows Media 10
Macromedia Flash Player 8 Plugin
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Language Pack - FRA
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Media Video 9 VCM
Mise à jour de logiciel pour les Dossiers Web
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)
Mise à jour de sécurité pour Windows XP (KB913433)
Mise à jour de sécurité pour Windows XP (KB916281)
Mise à jour de sécurité pour Windows XP (KB917953)
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
Photorécit 3 pour Windows
Picasa 2
QuickTime
Realtek High Definition Audio Driver
Visionneuse Journal Windows Microsoft
VLC media player 0.9.2
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Live installer
Windows Live Messenger
Windows Media Connect
Windows Media Format Runtime
Windows Media Player 10 Hotfix - KB888656
Windows Messenger 5.1
WinZip 12.0
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 0457-D984
Répertoire de C:\Program Files
23/10/2008 01:00 <REP> .
23/10/2008 01:00 <REP> ..
16/09/2008 13:04 <REP> Adobe
16/09/2008 15:00 <REP> Apple Software Update
22/10/2008 13:39 <REP> AVG
16/09/2008 17:02 <REP> BitTorrent
16/09/2008 15:01 <REP> Bonjour
23/10/2008 00:15 <REP> CCleaner
16/09/2008 12:43 <REP> ComPlus Applications
16/09/2008 13:28 <REP> CONEXANT
16/09/2008 17:02 <REP> DNA
22/10/2008 11:30 <REP> EoRezo
06/10/2008 17:51 <REP> epson
19/10/2008 15:33 <REP> Exstora Pro
16/09/2008 15:38 <REP> Fichiers communs
21/09/2008 21:53 <REP> Google
03/10/2008 13:23 <REP> HiYo
16/09/2008 13:29 <REP> Intel
16/09/2008 12:57 <REP> Internet Explorer
16/09/2008 15:01 <REP> iPod
16/09/2008 15:02 <REP> iTunes
16/09/2008 13:07 <REP> Java
16/09/2008 12:54 <REP> JEUX
16/09/2008 13:04 <REP> Messenger
16/09/2008 12:48 <REP> microsoft frontpage
16/09/2008 13:45 <REP> Microsoft Office
16/09/2008 13:45 <REP> Microsoft.NET
16/09/2008 12:44 <REP> Movie Maker
23/10/2008 00:53 <REP> Mozilla Firefox
16/09/2008 12:42 <REP> MSN Gaming Zone
16/09/2008 12:44 <REP> NetMeeting
16/09/2008 12:44 <REP> Outlook Express
16/09/2008 13:04 <REP> Photo Story 3 for Windows
23/09/2008 11:00 <REP> Picasa2
16/09/2008 15:01 <REP> QuickTime
16/09/2008 13:24 <REP> Realtek
22/10/2008 21:36 <REP> Trend Micro
16/09/2008 12:54 <REP> UTILS
16/09/2008 14:54 <REP> VideoLAN
16/09/2008 13:02 <REP> Windows Journal Viewer
16/09/2008 15:38 <REP> Windows Live
16/09/2008 13:03 <REP> Windows Media Components
16/09/2008 12:47 <REP> Windows Media Connect 2
16/09/2008 13:03 <REP> Windows Media Player
16/09/2008 12:42 <REP> Windows NT
16/09/2008 13:12 <REP> WinRAR
05/10/2008 21:56 <REP> WinZip
16/09/2008 13:03 <REP> WMV9_VCM
16/09/2008 12:48 <REP> xerox
0 fichier(s) 0 octets
49 Rép(s) 52 270 006 272 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 0457-D984
Répertoire de C:\Program Files\fichiers communs
16/09/2008 15:38 <REP> .
16/09/2008 15:38 <REP> ..
16/09/2008 13:05 <REP> Adobe
16/09/2008 15:01 <REP> Apple
16/09/2008 13:45 <REP> DESIGNER
06/10/2008 17:53 <REP> InstallShield
16/09/2008 13:06 <REP> Java
22/10/2008 13:39 <REP> Microsoft Shared
16/09/2008 12:44 <REP> MSSoap
16/09/2008 14:34 <REP> ODBC
16/09/2008 12:44 <REP> Services
16/09/2008 14:34 <REP> SpeechEngines
16/09/2008 12:44 <REP> System
0 fichier(s) 0 octets
13 Rép(s) 52 270 002 176 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 0457-D984
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
16/09/2008 13:08 <REP> .
16/09/2008 13:08 <REP> ..
16/09/2008 13:45 <REP> 1033
16/09/2008 13:45 <REP> 1036
17/09/2004 14:43 1 293 008 msonsext.dll
15/07/2003 06:52 35 896 MSOSV.DLL
03/06/1999 12:09 122 937 MSOWS409.DLL
07/03/2001 07:00 127 033 MSOWS40c.DLL
17/09/2004 14:43 80 448 pkmws.dll
5 fichier(s) 1 659 322 octets
4 Rép(s) 52 270 002 176 octets libres
c:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.0.0.35\SetupAdmin.exe
c:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
c:\Documents and Settings\Mel\Application Data\Microsoft\Installer\{E3D278BD-FC97-4F87-BB1F-689AE0CB9122}\ARPPRODUCTICON.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\catchme.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\diff.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\dumphive.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\find2.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\Fport.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\grep.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\gzip.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\KProcCheck.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\LFiles.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\md5sums.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\pslist.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\sigcheck.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\streams.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\swreg.exe
c:\Documents and Settings\Mel\Bureau\DiagHelp\tar.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\A appliquer en fonction de votre quantité de mémoire\WCPUID\wcpuclk.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\A appliquer en fonction de votre quantité de mémoire\WCPUID\wcpuid.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Firefox - Plugins Macromedia\Firefox_Flash.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Firefox - Plugins Macromedia\Firefox_Shockwave.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\ChCfg.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\RtlUpd.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\RtlUpd64.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\SetCDfmt.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\Setup.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\Config\AzMixerSel.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\WDM\Alcmtr.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\WDM\AlcWzrd.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\WDM\MicCal.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\WDM\RTHDCPL.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\WDM\RTLCPL.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\Audio\WDM\SoundMan.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Audio\UAA High Definition Audio Class driver\kb835221.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\ChipSet\Setup.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Modem\HXFSetup.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Network\PROUnstl.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Pointing\ApntEx.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Pointing\Apoint.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Pointing\Apvfb.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Pointing\Ezcapt.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Pointing\Uninstap.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\USBMouse\Setup.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\USBMouse\SetupNT.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\hkcmd.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\ialmudlg.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\igfxcfg.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\igfxext.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\igfxpers.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\igfxsrvc.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\igfxtray.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\Video\igfxzoom.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\WirelessLAN1\Setup.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\WirelessLAN2\Instmsiw.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Pilotes du portable\WirelessLAN2\iProInst.exe
c:\Documents and Settings\Mel\Bureau\OPTIONS\Si vous utilisez l'outil de gravure intégré à Windows\KB831240_HighMAT.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\404Fix.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\AntiXPVSTFix.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\dumphive.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\exit.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\GenericRenosFix.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\HostsChk.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\IEDFix.C.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\IEDFix.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\o4Patch.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\Policies.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\Process.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\Reboot.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\restart.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\SmiUpdate.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\SrchSTS.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\swreg.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\swsc.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\swxcacls.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\UIFix.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\unzip.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\VACFix.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\VCCLSID.exe
c:\Documents and Settings\Mel\Bureau\SmitfraudFix\WS2Fix.exe
c:\Documents and Settings\Mel\Local Settings\Temp\7zS1.tmp\avgsetup.exe
c:\Documents and Settings\Mel\Mes documents\Mes images\Mes images\Fond decran\EmoticonesAnimaux.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
c:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DIFxAPI.dll
c:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspi.dll
c:\Documents and Settings\Mel\Application Data\Microsoft\IdentityCRL\Production\ppcrlconfig.dll
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_MELANIE.tar.gz a l'adresse
http://upload.malekal.com
Que dois je faire stp ?
Merci d'avance
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:03:56, on 22/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\HiYo\bin\HiYo.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE
C:\WINDOWS\system32\drivers\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\monjack.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\E_SA7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\msagent" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_07] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:03:56, on 22/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\HiYo\bin\HiYo.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE
C:\WINDOWS\system32\drivers\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\monjack.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\E_SA7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\msagent" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_07] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe