Rechercher : dans
Par :

VIRUS anti-antivirus sous vista, HELP!

Dernière réponse le 24 nov 2008 à 15:54:45 jimmy, le 24 nov 2008 à 12:01:23 
 Signaler ce message aux modérateurs

Bonjour,
je vais essayer de décrire mon problème clairement...

tout a commencé lorsque j'ai décompressé un .rar d'un certain Burn4Free (logiciel de gravure) trouvé sur Emule. J'ai lancé le .exe. M'attendant à une installation standard, je clique sans trop réfléchir sur le seul bouton disponible "process". Et là, écran bleu, plantage. je redémarre, de nouveau écran bleu plantage (2fois seulement). Impossible de choisir "redémarrage en mode sans échec" car mon clavier est (étrangement) inactif avant l'ouverture de windows, donc "redémarrage de windows normalement" obligé après les 20sec d'attente.

Désormais, mon ordinateur s'allume et s'éteint normalement, mais mon antivirus a disparu (Antivir) de la barre windows, il est impossible de le lancer (lui ou tout autre antivirus, j'ai essayé Avast) que ce soit par des raccourcis ou lorsque je navigue dans ses dossiers (j'ai rarement le temps d'atteindre le dossier avant que la fenêtre ne réponde plus.)
Lorsque j'arrive à en lancer un, on me dit que ce ne sont pas des applications Win32 valides! on me dit également ça lorsque j'essaye d'accéder à mon disque dur externe! de plus, les capacités de mon ordinateurs sont lourdement parasités (des pointes régulières à 30%de CU utilisée) et d'autres programmes (le logiciel de la carte son creative fatal1ty par exemple) sont mis hors jeu exactement comme les antivirus.

Tout ceci me broie majestueusement les couilles si vous me permettez l'expression, et j'ai vraiment besoin d'aide. J'ai apparement choppé une saloperie de virus anti-antivirus et il faut vraiment que je m'en débarrasse car l'utilisation de mon dde m'est indispensable.

Je vous remercie d'avance :)

Configuration: Windows Vista
Internet Explorer 7.0

Meilleures réponses pour « VIRUS anti antivirus sous vista, HELP! » dans :
Quel est le meilleur antivirus gratuit ? VoirLe choix d'un anti-virus reste une décision personnelle, en fonction des goûts de chacun. Voici ci-dessous une sélection des meilleurs antivirus gratuits. 1. Antivir Personal Edition 2. Avast Home 3. AVG 4. Microsoft Security Essentials 5....
Virus - Introduction aux virus VoirVirus Un virus est un petit programme informatique situé dans le corps d'un autre, qui, lorsqu'on l'exécute, se charge en mémoire et exécute les instructions que son auteur a programmé. La définition d'un virus pourrait être la suivante : « Tout...

1

Destrio5, le 24 nov 2008 à 12:03:51
  • +1

Salut,

Tu as gagné l'infection Bagle.

---> Désactive l'UAC le temps de la désinfection :
http://www.commentcamarche.net/faq/sujet 8343 vista desactiver l uac

--> Télécharge FindyKill (par Chiquitine29) sur ton Bureau :
http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

--> Lance l'installation avec les paramètres par défaut.

--> Clique droit sur le raccourci FindyKill situé sur ton Bureau et choisis Exécuter en tant qu'administrateur.

--> Choisis F pour Français et valide.

--> Au menu principal, choisis l'option 1 (Recherche).

--> Poste le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.

Répondre à Destrio5

3

jimmy, le 24 nov 2008 à 12:17:23

vous etes rapides les mecs! :) voici donc le rapport findkill:



----------------- FindyKill V4.705 ------------------

* User : Jimmy - PC-DE-JIMMY
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 17/11/08 par Chiquitine29
* Recherche effectuée à 12:13:52 le 24/11/2008
* Windows Vista - Internet Explorer 7.0.6001.18000

((((((((((((((((( *** Recherche *** ))))))))))))))))))


--------------- [ Processus actifs ] ----------------


C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Windows\System32\CTHELPER.EXE
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\explorer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe

--------------- [ Fichiers/Dossiers infectieux ] ----------------


»»»» Presence des fichiers dans C:

Found ! [24/11/2008 00:18] - C:\InfoSat.txt

»»»» Presence des fichiers dans C:\Windows


»»»» Presence des fichiers dans C:\Windows\Prefetch

Found ! - C:\Windows\prefetch\6640619.EXE-F33026B6.pf
Found ! - C:\Windows\prefetch\6648809.EXE-44E3674B.pf
Found ! - C:\Windows\prefetch\6653770.EXE-82328ED8.pf
Found ! - C:\Windows\prefetch\FLEC006.EXE-D021030F.pf
Found ! - C:\Windows\prefetch\MDELK.EXE-74B0283C.pf
Found ! - C:\Windows\prefetch\WINFILSE.EXE-48314F7F.pf
Found ! - C:\Windows\prefetch\WINTEMS.EXE-9889BB0E.pf

»»»» Presence des fichiers dans C:\Windows\system32

Found ! [24/11/2008 08:13] - C:\Windows\system32\mdelk.exe
Found ! [24/11/2008 08:13] - C:\Windows\system32\wintems.exe
Found ! [24/11/2008 09:15] - C:\Windows\system32\ban_list.txt

»»»» Presence des fichiers dans C:\Windows\system32\drivers

Found ! [23/11/2008 23:52] - C:\Windows\system32\drivers\srosa.sys
Found ! [23/11/2008 23:52] - C:\Windows\system32\drivers\srosa2.sys
Found ! [06/10/2005 09:10] - C:\Windows\system32\drivers\winfilse.exe
Found ! [24/11/2008 08:20] - "C:\Windows\system32\drivers\downld"
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\105643.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\108826.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\135986.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\141508.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15150707.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15186510.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15192157.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15210206.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15379592.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15505298.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15639537.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\15654591.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\175547.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\177513.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\209946.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\213643.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\214532.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\244547.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\251848.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30150032.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30157411.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30159064.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30174961.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30181076.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30319324.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30323739.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30493577.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30582576.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\30601592.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\353373.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\356321.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\360284.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\364839.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\476021.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\604332.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\622896.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\6615206.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\6617094.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\6640619.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\6648809.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\6653770.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\72680.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\73538.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\78484.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\84131.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\86970.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\87766.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\89731.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\90652.exe
Found ! [24/11/2008 08:20] - C:\Windows\system32\drivers\downld\92009.exe

»»»» Presence des fichiers dans C:\Users\Jimmy\AppData\Roaming

Found ! [24/11/2008 08:13] - "C:\Users\Jimmy\AppData\Roaming\m\flec006.exe"
Found ! [24/11/2008 08:14] - "C:\Users\Jimmy\AppData\Roaming\m\list.oct"
Found ! [24/11/2008 08:14] - "C:\Users\Jimmy\AppData\Roaming\m\data.oct"
Found ! [24/11/2008 08:14] - "C:\Users\Jimmy\AppData\Roaming\m\srvlist.oct"
Found ! [24/11/2008 10:03] - "C:\Users\Jimmy\AppData\Roaming\m\shared"
Found ! [24/11/2008 04:04] - "C:\Users\Jimmy\AppData\Roaming\m"

»»»» Presence des fichiers dans C:\Users\Jimmy\AppData\Local\Temp


»»»» Presence des fichiers dans C:\Users\Jimmy\Local Settings\Temporary Internet Files\Content.IE5

Found ! [23/11/2008 23:27] - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UR628QG\b64_3[1].jpg
Found ! [23/11/2008 23:41] - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO3IAN4\b64[2].jpg
Found ! [23/11/2008 23:44] - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO3IAN4\b64_2[1].jpg
Found ! [23/11/2008 23:44] - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XT730OEU\b64_1[1].jpg
Found ! [23/11/2008 23:42] - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XT730OEU\WMPdd237293-cc04-4af7-8be5-78b647551c37[1]..jpg
Found ! [23/11/2008 23:41] - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y1CXCKZH\b64_2[1].jpg
Found ! [26/02/2007 17:45] - C:\Users\Jimmy\Desktop\MUSIQUE\Citizen Cope\The Clarence Greenwood Recordings\AlbumArt_{4C2779C1-1E02-4B64-9F35-9B9096DE2FD5}_Large.jpg
Found ! [26/02/2007 17:45] - C:\Users\Jimmy\Desktop\MUSIQUE\Citizen Cope\The Clarence Greenwood Recordings\AlbumArt_{4C2779C1-1E02-4B64-9F35-9B9096DE2FD5}_Small.jpg

--------------- [ Registre / Startup ] ----------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

filehippo.com="C:\Program Files\filehippo.com\UpdateChecker.exe" /background
DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
Orb="C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
eMuleAutoStart=C:\Program Files\eMule\emule.exe -AutoStart
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater=
<NO NAME>=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
RCSystem="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
AudioDrvEmulator="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
VolPanel="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
CTHelper=CTHELPER.EXE
UpdReg=C:\Windows\UpdReg.EXE
avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
StartCCC="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
CTxfiHlp=CTXFIHLP.EXE
SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
Logitech Hardware Abstraction Layer=KHALMNPR.EXE
Acrobat Assistant 8.0="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
<NO NAME>=
Adobe_ID0EYTHM=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
WinampAgent="C:\Program Files\Winamp\winampa.exe"
Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=

--------------- [ Registre / Clés infectieuses ] ----------------


Found ! - HKEY_USERS\S-1-5-21-1290542435-382262474-971793042-1000\Software\Local AppWizard-Generated Applications\winfilse
Found ! - HKEY_USERS\S-1-5-21-1290542435-382262474-971793042-1000\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-1290542435-382262474-971793042-1000\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-1290542435-382262474-971793042-1000\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-1290542435-382262474-971793042-1000\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - HKEY_CURRENT_USER\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\FFC
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s

--------------- [ Etat / Services ] ----------------



+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

/!\ Ndisuio - Type de démarrage = 4

EapHost - Type de démarrage = 3

Wlansvc - Type de démarrage = 3

SharedAccess - Type de démarrage = 2

wuauserv - Type de démarrage = 2

/!\ wscsvc - Type de démarrage = 4

/!\ WinDefend - Type de démarrage = 4



--------------- [ Recherche dans supports amovibles] ----------------


+- Informations :

C: - Lecteur fixe
E: - Lecteur fixe

+- Contenu de l'autorun : E:\autorun.inf

[autorun]
open=Launch.exe
icon=Launch.exe


+- presence des fichiers :

Found ! [02/07/2007 07:34][--a------] - E:\autorun.inf


--------------- [ Registre / Mountpoint2 ] ----------------


-> Not found !


------------------- ! Fin du rapport ! --------------------

Répondre à jimmy

2

totobetourne, le 24 nov 2008 à 12:05:09

Bonjour

surement infection bagle.fait les differents points dans l ordre.


1)pour vista si infection.

Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection: IMPORTANT A NE SURTOUT PAS OUBLIER):

- Va dans démarrer puis panneau de configuration
- Double Clique sur l'icône "Comptes d'utilisateurs"
- Clique ensuite sur désactiver et valide.

http://www.laboratoire-microsoft.org/tips-23933-desactiver-uac-vista.html




2) Télécharges FindyKill de Chiquitine29

Fais un clique droit sur le lien et choisis "enregistrer la cible sous ...." , destination le bureau .

http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe


Note importante : si tu as le prg Elibagla sur ton PC , supprimes le ( risque de conflit entre les deux outils ) .

--> Entre dans le dossier " FindyKill "

Double clic sur " FindyKill.bat " (et pas sur autre chose!) pour lancer l'outil .

->choisis l'option 1 . Puis laisses travailler ...

Une fois terminé, postes le rapport FindyKill.txt qui est généré ...

( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

Répondre à totobetourne

4

Destrio5, le 24 nov 2008 à 12:19:19
  • +1

--> Supprime tes cracks et keygens.

--> Branche tes disques amovibles à ton PC (clefs USB, disque dur externe, etc...) sans les ouvrir.

--> Clique droit sur le raccourci FindyKill situé sur ton Bureau et choisis Exécuter en tant qu'administrateur.

--> Choisis F pour Français puis valide.

--> Au menu principal, choisis l'option 2 (Suppression).

/!\ Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\

--> Ensuite, poste le rapport FindyKill.txt

Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.

Répondre à Destrio5

5

jimmy, le 24 nov 2008 à 12:42:08

Voilà le rapport, je n'ai encore pas testé voir si ça a réglé le problème? guidez moi :)
vous gérez les mecs
voici le rapport :




----------------- FindyKill V4.705 ------------------

* User : Jimmy - PC-DE-JIMMY
* executed from : C:\Program Files\FindyKill
* Update on 17/11/08 par Chiquitine29
* Start at 12:36:21 the 24/11/2008
* Windows Vista - Internet Explorer 7.0.6001.18000


((((((((((((((( *** deleting *** ))))))))))))))))))


--------------- [ Active Processes ] ----------------


C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\conime.exe

--------------- [ Infected files / folders ] ----------------


»»»» Supression files in C:

Deleted ! - C:\InfoSat.txt

»»»» Supression files in C:\Windows


»»»» Supression files in C:\Windows\Prefetch

Deleted ! - C:\Windows\prefetch\6640619.EXE-F33026B6.pf
Deleted ! - C:\Windows\prefetch\6648809.EXE-44E3674B.pf
Deleted ! - C:\Windows\prefetch\6653770.EXE-82328ED8.pf
Deleted ! - C:\Windows\prefetch\FLEC006.EXE-D021030F.pf
Deleted ! - C:\Windows\prefetch\MDELK.EXE-74B0283C.pf
Deleted ! - C:\Windows\prefetch\WINFILSE.EXE-48314F7F.pf
Deleted ! - C:\Windows\prefetch\WINTEMS.EXE-9889BB0E.pf

»»»» Supression files in C:\Windows\system32

Deleted ! - C:\Windows\system32\mdelk.exe
Deleted ! - C:\Windows\system32\wintems.exe
Deleted ! - C:\Windows\system32\ban_list.txt

»»»» Supression files in C:\Windows\system32\drivers

Deleted ! - C:\Windows\system32\drivers\srosa.sys
Deleted ! - C:\Windows\system32\drivers\srosa2.sys
Deleted ! - C:\Windows\system32\drivers\winfilse.exe
Deleted ! - C:\Windows\system32\drivers\downld\105643.exe
Deleted ! - C:\Windows\system32\drivers\downld\108826.exe
Deleted ! - C:\Windows\system32\drivers\downld\135986.exe
Deleted ! - C:\Windows\system32\drivers\downld\141508.exe
Deleted ! - C:\Windows\system32\drivers\downld\15150707.exe
Deleted ! - C:\Windows\system32\drivers\downld\15186510.exe
Deleted ! - C:\Windows\system32\drivers\downld\15192157.exe
Deleted ! - C:\Windows\system32\drivers\downld\15210206.exe
Deleted ! - C:\Windows\system32\drivers\downld\15379592.exe
Deleted ! - C:\Windows\system32\drivers\downld\15505298.exe
Deleted ! - C:\Windows\system32\drivers\downld\15639537.exe
Deleted ! - C:\Windows\system32\drivers\downld\15654591.exe
Deleted ! - C:\Windows\system32\drivers\downld\175547.exe
Deleted ! - C:\Windows\system32\drivers\downld\177513.exe
Deleted ! - C:\Windows\system32\drivers\downld\209946.exe
Deleted ! - C:\Windows\system32\drivers\downld\213643.exe
Deleted ! - C:\Windows\system32\drivers\downld\214532.exe
Deleted ! - C:\Windows\system32\drivers\downld\244547.exe
Deleted ! - C:\Windows\system32\drivers\downld\251848.exe
Deleted ! - C:\Windows\system32\drivers\downld\30150032.exe
Deleted ! - C:\Windows\system32\drivers\downld\30157411.exe
Deleted ! - C:\Windows\system32\drivers\downld\30159064.exe
Deleted ! - C:\Windows\system32\drivers\downld\30174961.exe
Deleted ! - C:\Windows\system32\drivers\downld\30181076.exe
Deleted ! - C:\Windows\system32\drivers\downld\30319324.exe
Deleted ! - C:\Windows\system32\drivers\downld\30323739.exe
Deleted ! - C:\Windows\system32\drivers\downld\30493577.exe
Deleted ! - C:\Windows\system32\drivers\downld\30582576.exe
Deleted ! - C:\Windows\system32\drivers\downld\30601592.exe
Deleted ! - C:\Windows\system32\drivers\downld\353373.exe
Deleted ! - C:\Windows\system32\drivers\downld\356321.exe
Deleted ! - C:\Windows\system32\drivers\downld\360284.exe
Deleted ! - C:\Windows\system32\drivers\downld\364839.exe
Deleted ! - C:\Windows\system32\drivers\downld\476021.exe
Deleted ! - C:\Windows\system32\drivers\downld\604332.exe
Deleted ! - C:\Windows\system32\drivers\downld\622896.exe
Deleted ! - C:\Windows\system32\drivers\downld\6615206.exe
Deleted ! - C:\Windows\system32\drivers\downld\6617094.exe
Deleted ! - C:\Windows\system32\drivers\downld\6640619.exe
Deleted ! - C:\Windows\system32\drivers\downld\6648809.exe
Deleted ! - C:\Windows\system32\drivers\downld\6653770.exe
Deleted ! - C:\Windows\system32\drivers\downld\72680.exe
Deleted ! - C:\Windows\system32\drivers\downld\73538.exe
Deleted ! - C:\Windows\system32\drivers\downld\78484.exe
Deleted ! - C:\Windows\system32\drivers\downld\84131.exe
Deleted ! - C:\Windows\system32\drivers\downld\86970.exe
Deleted ! - C:\Windows\system32\drivers\downld\87766.exe
Deleted ! - C:\Windows\system32\drivers\downld\89731.exe
Deleted ! - C:\Windows\system32\drivers\downld\90652.exe
Deleted ! - C:\Windows\system32\drivers\downld\92009.exe
Deleted ! - "C:\Windows\system32\drivers\downld"

»»»» Supression files in C:\Users\Jimmy\AppData\Roaming

Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\flec006.exe"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\list.oct"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\data.oct"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\srvlist.oct"
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\001_Joiner_and_Splitter_Pro_2.1.4.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\1-abc.net_Folder-To-TXT_1.01.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ABSYNTH_4.0.1.007.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ActivePrint_UltraLight_4.7.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AD Picture Viewer 3.9.1.311.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AD_Three_Bears_5.07.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Age of Mythology The Titans Aurum Athina map.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Allok_Video_Joiner_3.2.0807.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Amazing Places - Austria 1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Amazon.com Searchbar 2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Anonymity_Gateway_2.5_(Patch).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AudioTools Pro 4.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Avira.AntiVir.PersonalEdition.Premium.7.+.Key_01_10_2006.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AVI_Toolbox_1.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AVS Video Editor 3.5.1.355.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Barcode_Components_1.0.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Belltech Label Maker Pro 2.1.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Bix_Photo_Book_2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Blat PHP Example 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\BloodRayne 1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Body_Account_1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Body_Account_1.1_(Patch).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Cabbage Soup Diet 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\CD MP3 Terminator 2.07.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Celebrity_Magnet_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Clicktionary_English-Japanese_3.2.2_[Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Coin Collector Professional 7.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ColorMaker 3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\CommuniCrypt File Encryption Tools 1.01.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\CPU-Control_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Crazy Mouse 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Create Floor Schedules for Your Agents 3.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Delicioius Diabetic Recipes 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Delivery_Waitress_1.0_[Key+Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Desert_Combat_(Battlefield_1942) -_Baghdad_Intl_Airport_map_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Diablo II Screensaver 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Drop_Menu_II_Applet_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\DVD-fx 2.3.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Ease CD Ripper 1.50.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Easy Auction Creator 1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\EasyFP 2.3 [KeyGen].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Easy_Login_1.1.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\eBookGuard Document Protection 3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\EBSQ Art of the Day 0.1.2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\EGPicJpgDBF 1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Elite_Helisquad_1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Employee_Expense_Organizer_Deluxe_2.8_[Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\F-Prot Antivirus 6.0.9.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Fastcrop 1.03.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Fast_Port_Scanner_1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Find My Heart 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Flash Retriever 1.2.0.41.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\FLASH-Album Author 1.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\FTP_Client_Engine_for_FoxPro_2.6.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Goldfish Aquarium 2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\GoldFish0009 ScreenMate.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\How_to_Study_Ebook_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ImageExtractor_2003.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\IrisSkin_3.41_(Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Jazz Globals 1.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Kaspersky.5.0.121.personal.fr.+.manuel.+.clǸ.key.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Kernel_FAT-NTFS_-_Windows_Data_Recovery_4.03_(Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Kitchen_Design_Secrets_1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\LabelWidget_1.1.4.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Leithauser_Research_EBook_Reader_-_15000_Useful_Phrases_1.0_[Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Madcrosoft File Encrypter 2.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Magic Polyphonic Ringtone 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Mail_Merge_Pro_(OS_X)_2.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Michelangelo Art 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Monkey Beach Demo Screensaver 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Mouz 1.00.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\MyTVPal_Player_5.3.152.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Nasser Exe2Swf 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Network Ping 1.0.0.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\NetworkGazer 1.0.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Nick Video Jigsaw Jam 1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\No One Lives Forever 2 A Spy in H.A.R.M.'s Way map pack 2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\One_Smart_Cookie_1.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PassKeeper_2.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Peaceful_Rain_Demo_Screensaver_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Peacock Screensaver1 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PEBundle 3.0.17.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Personal_Finance_1.1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Pic-Matic_1.0_(Key+Serial).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PL.NOD32.2.51.30.PL.+.key.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Plexis_Serial_Barcode_Wedge_2.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Plugin Commander Light 1.52 Rev4.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Power_Phone_Book_Personal_Edition_1.61_[Crack].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PQ_DVD_to_iPhone_Video_Converter_Suite_1.0_Build_01_[Cracked].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Primasoft Text 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Proactive_System_Password_Recovery_4.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ProCon Latte 1.7.9.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Professional Renamer 2.45.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Recovozaur_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\RegView_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Richlaur Backgammon 1.0.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ScreenWorks 3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SDE for JDeveloper (CE) for Windows 3.3 Community Edition.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SecureBlackbox (VCL) 6.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Send2_for_Outlook_1.20.0456.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SNRemove_1.00.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Sophos.Enterprise.Console.v2.0.0.&.EM.Library.v1.3.0-ARN-Shared.by.koolman.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SpaceObServer 2.3.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Speed Reader 2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Spider_3D_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Sporting Life 4 Screensaver.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SpyStudio_0.8.2b.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\StatsNET 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\STL WebMail Server 1.4.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SweetMail_2.2r6.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\TakeItEasy 1.5.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\TeamTrax_Lite_1.1_(Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Terrasoft_CRM_2.8.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\The Journal 4.0.0.127 (Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\The_Complete_Guide_to_Internet_Marketing_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\The_Leaf_Writer_2006.1_build_29.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Traylook_1.6.5_(Key+Serial).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\TriviaFrog 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Tunebounce_1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\uCertify_PrepKit_-_C220-601_A+_Essentials_8.00.05.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\UpdateIP_JumpGate_0.4.55_Beta.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\VirusScan.-.McAfee.-.VirusScan.2006.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Visendo_FaxServer_Standard_3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Wallpaper_Wrangler_1.0.1.15.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\WebThumb 2005 release 5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\WickedOrange Notes 0.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\WinContentFilter_2005_2.0.37.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Word_Finder_Pro_1.0.zip
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\shared"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m"

»»»» Supression files in C:\Users\Jimmy\AppData\Local\Temp


»»»» Supression files in C:\Users\Jimmy\Local Settings\Temporary Internet Files\Content.IE5

Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UR628QG\b64_3[1].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO3IAN4\b64[2].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO3IAN4\b64_2[1].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XT730OEU\b64_1[1].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XT730OEU\WMPdd237293-cc04-4af7-8be5-78b647551c37[1]..jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y1CXCKZH\b64_2[1].jpg
Deleted ! - C:\Users\Jimmy\Desktop\MUSIQUE\Citizen Cope\The Clarence Greenwood Recordings\AlbumArt_{4C2779C1-1E02-4B64-9F35-9B9096DE2FD5}_Large.jpg
Deleted ! - C:\Users\Jimmy\Desktop\MUSIQUE\Citizen Cope\The Clarence Greenwood Recordings\AlbumArt_{4C2779C1-1E02-4B64-9F35-9B9096DE2FD5}_Small.jpg

--------------- [ Registry / Infected keys ] ----------------

Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-1290542435-382262474-971793042-1000\Software\Local AppWizard-Generated Applications\winfilse

--------------- [ States / Restarting of services ] ----------------



+- Services : [ Auto=2 / Request=3 / Disable=4 ]

Ndisuio - Type of startup = 3

EapHost - Type of startup = 2

Wlansvc - Type of startup = 2

SharedAccess - Type of startup = 2

wuauserv - Type of startup = 2

wscsvc - Type of startup = 2

WinDefend - Type of startup = 2


--------------- [ Cleaning removable drives ] ----------------

+- Informations :

C: - Lecteur fixe
E: - Lecteur fixe

+- deleting files :

Deleted ! - E:\autorun.inf

--------------- [ Registry / Mountpoint2 ] ----------------


-> Not found !


--------------- [ Searching Cracks / Keygen ] ----------------

C:\Users\Jimmy\Desktop\MUSIQUE\David Bowie\1983 - Ziggy Stardust The Motion Picture\09 - Cracked Actor.mp3
C:\Users\Jimmy\Desktop\MUSIQUE\David Bowie\1989 - Tin Machine\04 - Crack City.mp3


---------------- ! End of report ! ------------------

Répondre à jimmy

6

jimmy, le 24 nov 2008 à 12:42:10

Voilà le rapport, je n'ai encore pas testé voir si ça a réglé le problème? guidez moi :)
vous gérez les mecs
voici le rapport :




----------------- FindyKill V4.705 ------------------

* User : Jimmy - PC-DE-JIMMY
* executed from : C:\Program Files\FindyKill
* Update on 17/11/08 par Chiquitine29
* Start at 12:36:21 the 24/11/2008
* Windows Vista - Internet Explorer 7.0.6001.18000


((((((((((((((( *** deleting *** ))))))))))))))))))


--------------- [ Active Processes ] ----------------


C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\conime.exe

--------------- [ Infected files / folders ] ----------------


»»»» Supression files in C:

Deleted ! - C:\InfoSat.txt

»»»» Supression files in C:\Windows


»»»» Supression files in C:\Windows\Prefetch

Deleted ! - C:\Windows\prefetch\6640619.EXE-F33026B6.pf
Deleted ! - C:\Windows\prefetch\6648809.EXE-44E3674B.pf
Deleted ! - C:\Windows\prefetch\6653770.EXE-82328ED8.pf
Deleted ! - C:\Windows\prefetch\FLEC006.EXE-D021030F.pf
Deleted ! - C:\Windows\prefetch\MDELK.EXE-74B0283C.pf
Deleted ! - C:\Windows\prefetch\WINFILSE.EXE-48314F7F.pf
Deleted ! - C:\Windows\prefetch\WINTEMS.EXE-9889BB0E.pf

»»»» Supression files in C:\Windows\system32

Deleted ! - C:\Windows\system32\mdelk.exe
Deleted ! - C:\Windows\system32\wintems.exe
Deleted ! - C:\Windows\system32\ban_list.txt

»»»» Supression files in C:\Windows\system32\drivers

Deleted ! - C:\Windows\system32\drivers\srosa.sys
Deleted ! - C:\Windows\system32\drivers\srosa2.sys
Deleted ! - C:\Windows\system32\drivers\winfilse.exe
Deleted ! - C:\Windows\system32\drivers\downld\105643.exe
Deleted ! - C:\Windows\system32\drivers\downld\108826.exe
Deleted ! - C:\Windows\system32\drivers\downld\135986.exe
Deleted ! - C:\Windows\system32\drivers\downld\141508.exe
Deleted ! - C:\Windows\system32\drivers\downld\15150707.exe
Deleted ! - C:\Windows\system32\drivers\downld\15186510.exe
Deleted ! - C:\Windows\system32\drivers\downld\15192157.exe
Deleted ! - C:\Windows\system32\drivers\downld\15210206.exe
Deleted ! - C:\Windows\system32\drivers\downld\15379592.exe
Deleted ! - C:\Windows\system32\drivers\downld\15505298.exe
Deleted ! - C:\Windows\system32\drivers\downld\15639537.exe
Deleted ! - C:\Windows\system32\drivers\downld\15654591.exe
Deleted ! - C:\Windows\system32\drivers\downld\175547.exe
Deleted ! - C:\Windows\system32\drivers\downld\177513.exe
Deleted ! - C:\Windows\system32\drivers\downld\209946.exe
Deleted ! - C:\Windows\system32\drivers\downld\213643.exe
Deleted ! - C:\Windows\system32\drivers\downld\214532.exe
Deleted ! - C:\Windows\system32\drivers\downld\244547.exe
Deleted ! - C:\Windows\system32\drivers\downld\251848.exe
Deleted ! - C:\Windows\system32\drivers\downld\30150032.exe
Deleted ! - C:\Windows\system32\drivers\downld\30157411.exe
Deleted ! - C:\Windows\system32\drivers\downld\30159064.exe
Deleted ! - C:\Windows\system32\drivers\downld\30174961.exe
Deleted ! - C:\Windows\system32\drivers\downld\30181076.exe
Deleted ! - C:\Windows\system32\drivers\downld\30319324.exe
Deleted ! - C:\Windows\system32\drivers\downld\30323739.exe
Deleted ! - C:\Windows\system32\drivers\downld\30493577.exe
Deleted ! - C:\Windows\system32\drivers\downld\30582576.exe
Deleted ! - C:\Windows\system32\drivers\downld\30601592.exe
Deleted ! - C:\Windows\system32\drivers\downld\353373.exe
Deleted ! - C:\Windows\system32\drivers\downld\356321.exe
Deleted ! - C:\Windows\system32\drivers\downld\360284.exe
Deleted ! - C:\Windows\system32\drivers\downld\364839.exe
Deleted ! - C:\Windows\system32\drivers\downld\476021.exe
Deleted ! - C:\Windows\system32\drivers\downld\604332.exe
Deleted ! - C:\Windows\system32\drivers\downld\622896.exe
Deleted ! - C:\Windows\system32\drivers\downld\6615206.exe
Deleted ! - C:\Windows\system32\drivers\downld\6617094.exe
Deleted ! - C:\Windows\system32\drivers\downld\6640619.exe
Deleted ! - C:\Windows\system32\drivers\downld\6648809.exe
Deleted ! - C:\Windows\system32\drivers\downld\6653770.exe
Deleted ! - C:\Windows\system32\drivers\downld\72680.exe
Deleted ! - C:\Windows\system32\drivers\downld\73538.exe
Deleted ! - C:\Windows\system32\drivers\downld\78484.exe
Deleted ! - C:\Windows\system32\drivers\downld\84131.exe
Deleted ! - C:\Windows\system32\drivers\downld\86970.exe
Deleted ! - C:\Windows\system32\drivers\downld\87766.exe
Deleted ! - C:\Windows\system32\drivers\downld\89731.exe
Deleted ! - C:\Windows\system32\drivers\downld\90652.exe
Deleted ! - C:\Windows\system32\drivers\downld\92009.exe
Deleted ! - "C:\Windows\system32\drivers\downld"

»»»» Supression files in C:\Users\Jimmy\AppData\Roaming

Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\flec006.exe"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\list.oct"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\data.oct"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\srvlist.oct"
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\001_Joiner_and_Splitter_Pro_2.1.4.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\1-abc.net_Folder-To-TXT_1.01.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ABSYNTH_4.0.1.007.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ActivePrint_UltraLight_4.7.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AD Picture Viewer 3.9.1.311.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AD_Three_Bears_5.07.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Age of Mythology The Titans Aurum Athina map.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Allok_Video_Joiner_3.2.0807.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Amazing Places - Austria 1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Amazon.com Searchbar 2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Anonymity_Gateway_2.5_(Patch).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AudioTools Pro 4.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Avira.AntiVir.PersonalEdition.Premium.7.+.Key_01_10_2006.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AVI_Toolbox_1.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\AVS Video Editor 3.5.1.355.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Barcode_Components_1.0.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Belltech Label Maker Pro 2.1.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Bix_Photo_Book_2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Blat PHP Example 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\BloodRayne 1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Body_Account_1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Body_Account_1.1_(Patch).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Cabbage Soup Diet 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\CD MP3 Terminator 2.07.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Celebrity_Magnet_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Clicktionary_English-Japanese_3.2.2_[Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Coin Collector Professional 7.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ColorMaker 3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\CommuniCrypt File Encryption Tools 1.01.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\CPU-Control_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Crazy Mouse 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Create Floor Schedules for Your Agents 3.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Delicioius Diabetic Recipes 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Delivery_Waitress_1.0_[Key+Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Desert_Combat_(Battlefield_1942) -_Baghdad_Intl_Airport_map_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Diablo II Screensaver 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Drop_Menu_II_Applet_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\DVD-fx 2.3.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Ease CD Ripper 1.50.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Easy Auction Creator 1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\EasyFP 2.3 [KeyGen].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Easy_Login_1.1.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\eBookGuard Document Protection 3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\EBSQ Art of the Day 0.1.2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\EGPicJpgDBF 1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Elite_Helisquad_1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Employee_Expense_Organizer_Deluxe_2.8_[Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\F-Prot Antivirus 6.0.9.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Fastcrop 1.03.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Fast_Port_Scanner_1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Find My Heart 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Flash Retriever 1.2.0.41.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\FLASH-Album Author 1.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\FTP_Client_Engine_for_FoxPro_2.6.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Goldfish Aquarium 2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\GoldFish0009 ScreenMate.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\How_to_Study_Ebook_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ImageExtractor_2003.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\IrisSkin_3.41_(Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Jazz Globals 1.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Kaspersky.5.0.121.personal.fr.+.manuel.+.clǸ.key.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Kernel_FAT-NTFS_-_Windows_Data_Recovery_4.03_(Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Kitchen_Design_Secrets_1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\LabelWidget_1.1.4.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Leithauser_Research_EBook_Reader_-_15000_Useful_Phrases_1.0_[Serial].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Madcrosoft File Encrypter 2.5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Magic Polyphonic Ringtone 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Mail_Merge_Pro_(OS_X)_2.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Michelangelo Art 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Monkey Beach Demo Screensaver 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Mouz 1.00.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\MyTVPal_Player_5.3.152.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Nasser Exe2Swf 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Network Ping 1.0.0.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\NetworkGazer 1.0.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Nick Video Jigsaw Jam 1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\No One Lives Forever 2 A Spy in H.A.R.M.'s Way map pack 2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\One_Smart_Cookie_1.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PassKeeper_2.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Peaceful_Rain_Demo_Screensaver_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Peacock Screensaver1 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PEBundle 3.0.17.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Personal_Finance_1.1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Pic-Matic_1.0_(Key+Serial).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PL.NOD32.2.51.30.PL.+.key.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Plexis_Serial_Barcode_Wedge_2.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Plugin Commander Light 1.52 Rev4.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Power_Phone_Book_Personal_Edition_1.61_[Crack].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\PQ_DVD_to_iPhone_Video_Converter_Suite_1.0_Build_01_[Cracked].zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Primasoft Text 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Proactive_System_Password_Recovery_4.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ProCon Latte 1.7.9.2.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Professional Renamer 2.45.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Recovozaur_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\RegView_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Richlaur Backgammon 1.0.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\ScreenWorks 3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SDE for JDeveloper (CE) for Windows 3.3 Community Edition.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SecureBlackbox (VCL) 6.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Send2_for_Outlook_1.20.0456.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SNRemove_1.00.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Sophos.Enterprise.Console.v2.0.0.&.EM.Library.v1.3.0-ARN-Shared.by.koolman.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SpaceObServer 2.3.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Speed Reader 2.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Spider_3D_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Sporting Life 4 Screensaver.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SpyStudio_0.8.2b.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\StatsNET 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\STL WebMail Server 1.4.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\SweetMail_2.2r6.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\TakeItEasy 1.5.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\TeamTrax_Lite_1.1_(Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Terrasoft_CRM_2.8.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\The Journal 4.0.0.127 (Crack).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\The_Complete_Guide_to_Internet_Marketing_1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\The_Leaf_Writer_2006.1_build_29.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Traylook_1.6.5_(Key+Serial).zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\TriviaFrog 1.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Tunebounce_1.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\uCertify_PrepKit_-_C220-601_A+_Essentials_8.00.05.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\UpdateIP_JumpGate_0.4.55_Beta.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\VirusScan.-.McAfee.-.VirusScan.2006.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Visendo_FaxServer_Standard_3.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Wallpaper_Wrangler_1.0.1.15.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\WebThumb 2005 release 5.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\WickedOrange Notes 0.1.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\WinContentFilter_2005_2.0.37.0.zip
Deleted ! - C:\Users\Jimmy\AppData\Roaming\m\shared\Word_Finder_Pro_1.0.zip
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m\shared"
Deleted ! - "C:\Users\Jimmy\AppData\Roaming\m"

»»»» Supression files in C:\Users\Jimmy\AppData\Local\Temp


»»»» Supression files in C:\Users\Jimmy\Local Settings\Temporary Internet Files\Content.IE5

Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1UR628QG\b64_3[1].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO3IAN4\b64[2].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO3IAN4\b64_2[1].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XT730OEU\b64_1[1].jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XT730OEU\WMPdd237293-cc04-4af7-8be5-78b647551c37[1]..jpg
Deleted ! - C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y1CXCKZH\b64_2[1].jpg
Deleted ! - C:\Users\Jimmy\Desktop\MUSIQUE\Citizen Cope\The Clarence Greenwood Recordings\AlbumArt_{4C2779C1-1E02-4B64-9F35-9B9096DE2FD5}_Large.jpg
Deleted ! - C:\Users\Jimmy\Desktop\MUSIQUE\Citizen Cope\The Clarence Greenwood Recordings\AlbumArt_{4C2779C1-1E02-4B64-9F35-9B9096DE2FD5}_Small.jpg

--------------- [ Registry / Infected keys ] ----------------

Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_CONFIG\System\CurrentControlSet\Enum\ROOT\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_USERS\S-1-5-21-1290542435-382262474-971793042-1000\Software\Local AppWizard-Generated Applications\winfilse

--------------- [ States / Restarting of services ] ----------------



+- Services : [ Auto=2 / Request=3 / Disable=4 ]

Ndisuio - Type of startup = 3

EapHost - Type of startup = 2

Wlansvc - Type of startup = 2

SharedAccess - Type of startup = 2

wuauserv - Type of startup = 2

wscsvc - Type of startup = 2

WinDefend - Type of startup = 2


--------------- [ Cleaning removable drives ] ----------------

+- Informations :

C: - Lecteur fixe
E: - Lecteur fixe

+- deleting files :

Deleted ! - E:\autorun.inf

--------------- [ Registry / Mountpoint2 ] ----------------


-> Not found !


--------------- [ Searching Cracks / Keygen ] ----------------

C:\Users\Jimmy\Desktop\MUSIQUE\David Bowie\1983 - Ziggy Stardust The Motion Picture\09 - Cracked Actor.mp3
C:\Users\Jimmy\Desktop\MUSIQUE\David Bowie\1989 - Tin Machine\04 - Crack City.mp3


---------------- ! End of report ! ------------------

Répondre à jimmy

7

Destrio5, le 24 nov 2008 à 12:46:48

---> Réinstalle tes applications infectées (Message d'erreur win32).

- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

- Double-clique sur RSIT.exe afin de lancer le programme.

- Clique sur Continue à l'écran Disclaimer.

- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

Note : Les rapports sont sauvegardés dans le dossier C:\rsit.

Répondre à Destrio5

8

jimmy, le 24 nov 2008 à 12:59:33

mon logo créative est réapparu dans la barre des taches et j'ai accés à mon dde, vous etes des chefs! :
voici les .txt, log puis info


Logfile of random's system information tool 1.04 (written by random/random)
Run by Jimmy at 2008-11-24 12:57:14
Microsoft® Windows Vista™ Professionnel Service Pack 1
System drive C: has 310 GB (65%) free of 477 GB
Total RAM: 2046 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:57:27, on 24/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\System32\CTHELPER.EXE
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y80NKQN\RSIT[1].exe
C:\Program Files\trend micro\Jimmy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O13 - Gopher Prefix:
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
End of file - 9781 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2008-06-11 61816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll [2007-03-16 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-10-14 863688]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22 321120]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll [2007-03-16 118784]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-11-23 1008184]
"RCSystem"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2006-11-22 57344]
"AudioDrvEmulator"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2006-11-22 57344]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [2006-12-06 180224]
"CTHelper"=C:\Windows\system32\CTHELPER.EXE [2007-03-05 19456]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-01 61440]
"CTxfiHlp"=C:\Windows\system32\CTXFIHLP.EXE [2008-07-11 19968]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"Logitech Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2007-04-11 56080]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2006-10-22 620152]
""= []
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [2007-03-20 1884160]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"filehippo.com"=C:\Program Files\filehippo.com\UpdateChecker.exe [2005-10-06 860168]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]
"Orb"=C:\Program Files\Winamp Remote\bin\OrbTray.exe [2008-04-01 507904]
"eMuleAutoStart"=C:\Program Files\eMule\emule.exe [2008-08-01 5480448]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=95000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{698d7ea2-b99c-11dd-b249-001fd0264aca}]
shell\AutoRun\command - E:\Launch.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccbcbf81-a637-11dd-8034-806e6f6e6963}]
shell\AutoRun\command - D:\livebox.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e11c7a95-ab61-11dd-a5fb-001fd0264aca}]
shell\AutoRun\command - F:\AutoRunCD.exe


======List of files/folders created in the last 1 months======

2008-11-24 12:57:14 ----D---- C:\rsit
2008-11-24 12:57:14 ----D---- C:\Program Files\trend micro
2008-11-24 12:36:21 ----A---- C:\FindyKill.txt
2008-11-24 12:12:44 ----D---- C:\Program Files\FindyKill
2008-11-23 23:36:06 ----D---- C:\Program Files\Alwil Software
2008-11-23 23:16:22 ----A---- C:\Windows\Filzip.ini
2008-11-23 23:15:46 ----D---- C:\Windows\Minidump
2008-11-23 21:32:02 ----D---- C:\Windows\Downloaded Installations
2008-11-21 16:13:15 ----D---- C:\Crytek
2008-11-20 14:15:22 ----D---- C:\Program Files\Filzip
2008-11-18 23:42:35 ----D---- C:\ProgramData\eMule
2008-11-18 23:41:54 ----D---- C:\Program Files\eMule
2008-11-18 19:05:06 ----D---- C:\Windows\system32\appmgmt
2008-11-18 19:01:56 ----D---- C:\Users\Jimmy\AppData\Roaming\AdobeUM
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wups2.dll
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wucltux.dll
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wuaueng.dll
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wuauclt.exe
2008-11-18 11:22:52 ----A---- C:\Windows\system32\wups.dll
2008-11-18 11:22:52 ----A---- C:\Windows\system32\wudriver.dll
2008-11-18 11:22:52 ----A---- C:\Windows\system32\wuapi.dll
2008-11-18 11:22:46 ----A---- C:\Windows\system32\wuwebv.dll
2008-11-18 11:22:46 ----A---- C:\Windows\system32\wuapp.exe
2008-11-16 06:19:12 ----RHD---- C:\Users\Jimmy\AppData\Roaming\SecuROM
2008-11-15 19:15:42 ----D---- C:\Program Files\Audacity
2008-11-15 01:57:05 ----A---- C:\Windows\system32\REX Shared Library.dll
2008-11-15 01:57:04 ----A---- C:\Windows\system32\ReWire.dll
2008-11-15 01:52:43 ----D---- C:\Users\Jimmy\AppData\Roaming\Propellerhead Software
2008-11-15 01:52:43 ----D---- C:\ProgramData\Propellerhead Software
2008-11-15 01:51:08 ----D---- C:\Program Files\Propellerhead
2008-11-12 09:47:59 ----A---- C:\Windows\system32\msxml3.dll
2008-11-12 09:47:57 ----A---- C:\Windows\system32\msxml6.dll
2008-11-11 23:28:53 ----D---- C:\Program Files\GameSpy
2008-11-11 23:27:10 ----D---- C:\Windows\system32\URTTEMP
2008-11-11 23:19:14 ----A---- C:\Windows\system32\PnkBstrB.exe
2008-11-11 23:19:11 ----A---- C:\Windows\system32\PnkBstrA.exe
2008-11-11 23:19:10 ----A---- C:\Windows\system32\pbsvc.exe
2008-11-11 23:10:55 ----D---- C:\Program Files\Sierra Entertainment
2008-11-08 20:25:17 ----D---- C:\Program Files\Common Files\Digidesign
2008-11-08 20:25:17 ----A---- C:\Program Files\Jupiter-8V.dll
2008-11-08 20:25:14 ----D---- C:\Program Files\Arturia
2008-11-07 19:56:33 ----D---- C:\Users\Jimmy\AppData\Roaming\dvdcss
2008-11-07 03:00:42 ----D---- C:\Program Files\MSXML 4.0
2008-11-06 01:40:48 ----D---- C:\Users\Jimmy\AppData\Roaming\vlc
2008-11-06 01:40:00 ----D---- C:\Program Files\VideoLAN
2008-11-06 01:23:54 ----D---- C:\ProgramData\OrbNetworks
2008-11-06 01:23:54 ----D---- C:\Program Files\Winamp Remote
2008-11-06 01:23:13 ----N---- C:\Windows\system32\vxblock.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxwave.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxsfs.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxmas.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxinsa64.exe
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxhpinst.exe
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxdrv.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxcpya64.exe
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxafs.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\px.dll
2008-11-06 01:23:12 ----D---- C:\Program Files\Winamp
2008-11-06 01:11:55 ----D---- C:\ProgramData\FLEXnet
2008-11-05 21:09:25 ----D---- C:\ProgramData\Adobe Systems
2008-11-05 21:01:04 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2008-11-05 20:59:57 ----A---- C:\Windows\system32\msxml4r.dll
2008-11-05 19:29:59 ----D---- C:\ProgramData\ALM
2008-11-05 19:26:49 ----D---- C:\Program Files\QuickTime
2008-11-05 19:22:54 ----A---- C:\Windows\system32\NPSWF32_FlashUtil.exe
2008-11-05 19:22:54 ----A---- C:\Windows\system32\NPSWF32.dll
2008-11-05 19:21:21 ----D---- C:\ProgramData\Adobe
2008-11-05 19:19:23 ----D---- C:\Program Files\Bonjour
2008-11-05 19:16:24 ----D---- C:\Program Files\Common Files\Macrovision Shared
2008-11-05 19:04:30 ----D---- C:\Program Files\TransMac
2008-11-05 18:49:27 ----D---- C:\Program Files\DAEMON Tools Toolbar
2008-11-05 18:48:54 ----D---- C:\Program Files\DAEMON Tools Lite
2008-11-05 18:46:08 ----D---- C:\Users\Jimmy\AppData\Roaming\DAEMON Tools
2008-11-04 20:22:02 ----D---- C:\Program Files\Common Files\Adobe
2008-11-04 20:22:02 ----D---- C:\Program Files\Adobe
2008-11-04 20:20:50 ----A---- C:\Windows\IsUn040c.exe
2008-11-03 23:24:29 ----D---- C:\Windows\PCHEALTH
2008-11-03 23:24:29 ----D---- C:\Program Files\MSN Messenger
2008-11-03 23:24:18 ----HD---- C:\Config.Msi
2008-11-03 23:20:33 ----D---- C:\Users\Jimmy\AppData\Roaming\HP
2008-11-03 22:40:11 ----D---- C:\ProgramData\Creative Labs
2008-11-03 22:21:19 ----D---- C:\Program Files\Orange HSS
2008-11-03 22:21:10 ----A---- C:\Windows\system32\MSVCR71.dll
2008-11-03 22:21:10 ----A---- C:\Windows\system32\msvcp71.dll
2008-11-03 22:21:10 ----A---- C:\Windows\system32\MFC71.dll
2008-11-03 22:21:10 ----A---- C:\Windows\system32\atl71.dll
2008-11-03 22:18:22 ----D---- C:\Program Files\SAGEM
2008-11-03 21:58:30 ----D---- C:\Program Files\Common Files\logishrd
2008-11-03 21:53:18 ----D---- C:\Users\Jimmy\AppData\Roaming\Logitech
2008-11-03 21:53:07 ----R---- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-11-03 21:50:57 ----A---- C:\Windows\system32\KemXML.dll
2008-11-03 21:50:57 ----A---- C:\Windows\system32\KemWnd.dll
2008-11-03 21:50:57 ----A---- C:\Windows\system32\KemUtil.dll
2008-11-03 21:50:57 ----A---- C:\Windows\system32\kemutb.dll
2008-11-03 21:50:43 ----D---- C:\ProgramData\Logitech
2008-11-03 21:50:42 ----D---- C:\Program Files\Logitech
2008-11-03 21:50:40 ----D---- C:\Program Files\Common Files\Logitech
2008-11-03 21:49:09 ----D---- C:\ProgramData\LogiShrd
2008-11-03 02:06:34 ----D---- C:\Program Files\Bohemia Interactive
2008-11-02 18:12:36 ----A---- C:\Windows\system32\CmdLineExt.dll
2008-11-02 17:59:00 ----D---- C:\Program Files\Bethesda Softworks
2008-11-02 17:59:00 ----A---- C:\Windows\system32\XAudio2_1.dll
2008-11-02 17:59:00 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2008-11-02 17:59:00 ----A---- C:\Windows\system32\xactengine3_1.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\XAudio2_0.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\xactengine3_0.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DX9_38.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DX9_37.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\d3dx10_38.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\d3dx10_37.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\xactengine2_9.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\xactengine2_10.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\d3dx9_36.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\d3dx10_36.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\d3dx10_35.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\xactengine2_8.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\d3dx9_35.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\d3dx9_34.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\d3dx10_34.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2008-11-02 17:58:56 ----A---- C:\Windows\system32\xactengine2_7.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\xactengine2_6.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\xactengine2_5.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\xactengine2_4.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\x3daudio1_1.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\d3dx9_32.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\d3dx10.dll
2008-11-02 17:58:53 ----A---- C:\Windows\system32\xinput1_2.dll
2008-11-02 17:58:53 ----A---- C:\Windows\system32\xactengine2_3.dll
2008-11-02 17:58:53 ----A---- C:\Windows\system32\d3dx9_31.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\xinput1_3.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\d3dx9_33.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\d3dx10_33.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2008-11-02 17:57:17 ----D---- C:\Windows\system32\xlive
2008-11-01 23:34:05 ----D---- C:\Program Files\OCCT
2008-11-01 21:43:32 ----D---- C:\Users\Jimmy\AppData\Roaming\OpenOffice.org
2008-11-01 13:44:34 ----D---- C:\Program Files\JRE
2008-11-01 13:44:29 ----D---- C:\Program Files\OpenOffice.org 3
2008-11-01 13:44:10 ----A---- C:\Windows\system32\javaws.exe
2008-11-01 13:44:10 ----A---- C:\Windows\system32\javaw.exe
2008-11-01 13:44:10 ----A---- C:\Windows\system32\java.exe
2008-11-01 13:43:24 ----D---- C:\Program Files\Java
2008-11-01 13:43:24 ----D---- C:\Program Files\Common Files\Java
2008-10-31 21:49:39 ----D---- C:\Program Files\Yahoo!
2008-10-31 21:49:34 ----D---- C:\Program Files\CCleaner
2008-10-31 21:39:53 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2008-10-31 21:39:51 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2008-10-31 21:39:45 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2008-10-31 21:17:18 ----D---- C:\Users\Jimmy\AppData\Roaming\Macromedia
2008-10-31 21:17:18 ----D---- C:\Users\Jimmy\AppData\Roaming\Adobe
2008-10-31 20:43:24 ----D---- C:\Program Files\filehippo.com
2008-10-31 20:19:50 ----D---- C:\Program Files\Lavalys
2008-10-31 20:13:49 ----D---- C:\Program Files\Common Files\Creative Labs Shared
2008-10-31 20:12:28 ----A---- C:\Windows\system32\cttele32.dll
2008-10-31 20:08:07 ----A---- C:\Windows\system32\AppSetup.exe
2008-10-31 19:55:22 ----D---- C:\ProgramData\ATI
2008-10-31 19:49:17 ----D---- C:\ATI
2008-10-31 19:45:37 ----D---- C:\ProgramData\ma-config.com
2008-10-31 19:45:37 ----D---- C:\Program Files\ma-config.com
2008-10-31 19:28:32 ----D---- C:\Users\Jimmy\AppData\Roaming\Mozilla
2008-10-31 19:28:26 ----D---- C:\Program Files\Mozilla Firefox
2008-10-31 19:16:30 ----A---- C:\Windows\system32\shell32.dll
2008-10-31 19:16:10 ----A---- C:\Windows\system32\es.dll
2008-10-31 19:16:05 ----A---- C:\Windows\system32\IPSECSVC.DLL
2008-10-31 19:15:58 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-10-31 19:15:58 ----A---- C:\Windows\system32\gameux.dll
2008-10-31 19:15:58 ----A---- C:\Windows\system32\Apphlpdm.dll
2008-10-31 19:15:54 ----A---- C:\Windows\system32\rpcrt4.dll
2008-10-31 19:15:51 ----A---- C:\Windows\system32\pacerprf.dll
2008-10-31 19:15:48 ----A---- C:\Windows\system32\wmpeffects.dll
2008-10-31 19:10:37 ----A---- C:\Windows\system32\winresume.exe
2008-10-31 19:10:37 ----A---- C:\Windows\system32\winload.exe
2008-10-31 19:10:37 ----A---- C:\Windows\system32\kd1394.dll
2008-10-31 19:10:37 ----A---- C:\Windows\system32\ci.dll
2008-10-31 19:10:36 ----A---- C:\Windows\system32\srcore.dll
2008-10-31 19:10:36 ----A---- C:\Windows\system32\setbcdlocale.dll
2008-10-31 19:10:35 ----A---- C:\Windows\system32\srdelayed.exe
2008-10-31 19:10:35 ----A---- C:\Windows\system32\srclient.dll
2008-10-31 19:10:35 ----A---- C:\Windows\system32\rstrui.exe
2008-10-31 19:10:35 ----A---- C:\Windows\system32\kbd106n.dll
2008-10-31 19:10:25 ----A---- C:\Windows\system32\emdmgmt.dll
2008-10-31 19:10:24 ----A---- C:\Windows\system32\dataclen.dll
2008-10-31 19:10:24 ----A---- C:\Windows\system32\cdd.dll
2008-10-31 19:10:22 ----A---- C:\Windows\system32\gdi32.dll
2008-10-31 19:10:20 ----A---- C:\Windows\system32\win32spl.dll
2008-10-31 19:10:16 ----A---- C:\Windows\system32\wersvc.dll
2008-10-31 19:10:16 ----A---- C:\Windows\system32\Faultrep.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\wshext.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\wscript.exe
2008-10-31 19:10:13 ----A---- C:\Windows\system32\vbscript.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\scrrun.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\scrobj.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\jscript.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\cscript.exe
2008-10-31 19:10:11 ----A---- C:\Windows\system32\inetcomm.dll
2008-10-31 19:10:09 ----A---- C:\Windows\system32\quartz.dll
2008-10-31 19:10:06 ----A---- C:\Windows\system32\ntoskrnl.exe
2008-10-31 19:10:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
2008-10-31 19:09:54 ----A---- C:\Windows\system32\tzres.dll
2008-10-31 19:09:54 ----A---- C:\Windows\system32\mshtml.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\wininet.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\urlmon.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\mstime.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\jsproxy.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\iertutil.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\ieframe.dll
2008-10-31 19:09:23 ----A---- C:\Windows\system32\msshooks.dll
2008-10-31 19:09:22 ----A---- C:\Windows\system32\msscb.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\thawbrkr.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\srchadmin.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\SearchFilterHost.exe
2008-10-31 19:09:19 ----A---- C:\Windows\system32\propsys.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\propdefs.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\msstrc.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\mssprxy.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\mssitlb.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\msshsq.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\korwbrkr.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\xmlfilter.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\wsepno.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\tquery.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2008-10-31 19:09:18 ----A---- C:\Windows\system32\SearchIndexer.exe
2008-10-31 19:09:18 ----A---- C:\Windows\system32\rtffilt.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\offfilt.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\nlhtml.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssvp.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssrch.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssphtb.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssph.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\msscntrs.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mimefilt.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\chtbrkr.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\chsbrkr.dll
2008-10-31 19:05:59 ----A---- C:\Windows\system32\netapi32.dll
2008-10-31 19:04:45 ----A---- C:\Windows\Kit.ini
2008-10-31 19:04:44 ----D---- C:\Program Files\Wanadoo
2008-10-31 19:01:11 ----D---- C:\Program Files\Securitoo
2008-10-31 19:01:03 ----D---- C:\Program Files\Inventel
2008-10-31 13:21:24 ----N---- C:\Windows\Ctregrun.exe
2008-10-31 13:20:05 ----D---- C:\Program Files\Common Files\Creative
2008-10-31 13:20:04 ----HD---- C:\Program Files\Creative Installation Information
2008-10-31 13:13:08 ----N---- C:\Windows\Updreg.EXE
2008-10-31 13:12:46 ----D---- C:\ProgramData\Creative
2008-10-31 13:05:04 ----D---- C:\Program Files\OpenAL
2008-10-31 13:05:04 ----A---- C:\Windows\system32\wrap_oal.dll
2008-10-31 13:05:04 ----A---- C:\Windows\system32\OpenAL32.dll
2008-10-31 13:04:37 ----D---- C:\Windows\system32\Data
2008-10-31 13:04:37 ----A---- C:\Windows\CTXFIFRN.DLL
2008-10-31 13:04:37 ----A---- C:\Windows\CTDCRFRN.DLL
2008-10-31 13:03:46 ----A---- C:\Windows\system32\CmdRtr.DLL
2008-10-31 13:03:46 ----A---- C:\Windows\system32\APOMngr.DLL
2008-10-31 13:02:22 ----D---- C:\Users\Jimmy\AppData\Roaming\Creative
2008-10-31 13:01:04 ----D---- C:\Program Files\Creative
2008-10-30 23:22:27 ----D---- C:\Windows\system32\Macromed
2008-10-30 23:22:20 ----A---- C:\Windows\system32\xinput1_1.dll
2008-10-30 23:22:20 ----A---- C:\Windows\system32\xactengine2_2.dll
2008-10-30 23:22:20 ----A---- C:\Windows\system32\xactengine2_1.dll
2008-10-30 23:22:18 ----A---- C:\Windows\system32\xactengine2_0.dll
2008-10-30 23:22:18 ----A---- C:\Windows\system32\x3daudio1_0.dll
2008-10-30 23:22:18 ----A---- C:\Windows\system32\d3dx9_30.dll
2008-10-30 23:22:17 ----A---- C:\Windows\system32\d3dx9_29.dll
2008-10-30 23:22:17 ----A---- C:\Windows\system32\d3dx9_28.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_27.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_26.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_25.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_24.dll
2008-10-30 22:46:45 ----D---- C:\Users\Jimmy\AppData\Roaming\ATI
2008-10-30 22:43:33 ----D---- C:\Program Files\Common Files\ATI Technologies
2008-10-30 22:42:29 ----SHD---- C:\Windows\Installer
2008-10-30 22:41:51 ----D---- C:\Program Files\ATI Technologies
2008-10-30 22:41:49 ----D---- C:\Program Files\ATI
2008-10-30 22:26:35 ----D---- C:\Users\Jimmy\AppData\Roaming\InstallShield
2008-10-30 22:24:38 ----D---- C:\Windows\system32\RTCOM
2008-10-30 22:24:18 ----A---- C:\Windows\DIFxAPI.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\WavesLib.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSWOW.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSTSXT.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSTSHD.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSHP360.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkPgExt.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkCoInst.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkApoApi.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkAPO.dll
2008-10-30 22:24:16 ----A---- C:\Windows\SkyTel.exe
2008-10-30 22:24:16 ----A---- C:\Windows\RtlUpd.exe
2008-10-30 22:24:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2008-10-30 22:24:15 ----A---- C:\Windows\RtHDVCpl.exe
2008-10-30 22:24:14 ----D---- C:\Program Files\Realtek
2008-10-30 22:24:14 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2008-10-30 22:24:14 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2008-10-30 22:24:14 ----A---- C:\Windows\system32\FMAPO.dll
2008-10-30 22:24:13 ----A---- C:\Windows\HideWin.exe
2008-10-30 22:20:41 ----RA---- C:\Windows\system32\CSVer.dll
2008-10-30 22:20:41 ----D---- C:\Program Files\Intel
2008-10-30 22:20:33 ----D---- C:\Intel
2008-10-30 22:20:21 ----D---- C:\Program Files\GIGABYTE
2008-10-30 22:20:20 ----HD---- C:\Program Files\InstallShield Installation Information
2008-10-30 22:20:14 ----D---- C:\Program Files\Common Files\InstallShield
2008-10-30 22:19:43 ----A---- C:\Windows\GSetup.ini
2008-10-30 22:17:38 ----D---- C:\Users\Jimmy\AppData\Roaming\Identities
2008-10-30 22:17:31 ----SD---- C:\Users\Jimmy\AppData\Roaming\Microsoft
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Modèles
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Menu Démarrer
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Favoris
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Bureau
2008-10-30 22:15:17 ----SHD---- C:\Program Files\Fichiers communs
2008-10-30 05:11:52 ----D---- C:\Windows\Debug
2008-10-30 05:06:43 ----D---- C:\Windows\SoftwareDistribution
2008-10-30 05:05:31 ----D---- C:\Windows\CSC
2008-10-30 05:04:20 ----D---- C:\Windows\Prefetch
2008-10-30 05:04:13 ----SHD---- C:\System Volume Information
2008-10-30 05:03:20 ----D---- C:\Windows\Panther
2008-10-30 05:03:05 ----RAS---- C:\BOOTSECT.BAK
2008-10-30 05:03:04 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 months======

2008-11-24 12:57:17 ----D---- C:\Windows\Temp
2008-11-24 12:57:14 ----RD---- C:\Program Files
2008-11-24 12:53:24 ----D---- C:\Windows\System32
2008-11-24 12:49:50 ----HD---- C:\Windows\system32\drivers
2008-11-24 12:49:50 ----HD---- C:\ProgramData
2008-11-24 12:41:14 ----D---- C:\Windows\inf
2008-11-24 12:41:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2008-11-24 12:37:54 ----D---- C:\Windows\system32\WDI
2008-11-23 23:51:14 ----D---- C:\Windows
2008-11-23 23:12:39 ----D---- C:\Windows\system32\Tasks
2008-11-23 21:15:55 ----RSD---- C:\Windows\Fonts
2008-11-20 17:43:38 ----D---- C:\Windows\system32\NDF
2008-11-20 17:27:02 ----D---- C:\Windows\system32\catroot2
2008-11-18 17:34:00 ----D---- C:\Windows\rescache
2008-11-18 17:12:05 ----D---- C:\Windows\system32\fr-FR
2008-11-18 13:04:04 ----D---- C:\Windows\winsxs
2008-11-18 11:23:42 ----D---- C:\Windows\PolicyDefinitions
2008-11-18 11:23:23 ----D---- C:\Windows\system32\catroot
2008-11-13 03:02:53 ----D---- C:\Windows\Registration
2008-11-13 03:02:08 ----D---- C:\Program Files\Internet Explorer
2008-11-11 23:27:59 ----RSD---- C:\Windows\assembly
2008-11-11 23:19:06 ----D---- C:\Windows\system32\LogFiles
2008-11-08 20:25:17 ----D---- C:\Program Files\Common Files
2008-11-08 18:42:48 ----HD---- C:\Windows\system32\GroupPolicy
2008-11-04 01:10:25 ----A---- C:\Windows\system32\mrt.exe
2008-11-03 23:24:30 ----D---- C:\Program Files\Common Files\microsoft shared
2008-11-03 23:21:58 ----SD---- C:\ProgramData\Microsoft
2008-11-03 21:58:31 ----D---- C:\Windows\twain_32
2008-11-02 19:52:50 ----D---- C:\Windows\Logs
2008-10-31 21:12:54 ----D---- C:\Windows\AppPatch
2008-10-31 21:12:52 ----D---- C:\Program Files\Windows Mail
2008-10-31 21:12:49 ----D---- C:\Windows\system32\Boot
2008-10-31 21:12:43 ----D---- C:\Windows\system32\migration
2008-10-31 13:04:42 ----D---- C:\Windows\system
2008-10-30 23:22:18 ----D---- C:\Windows\Microsoft.NET
2008-10-30 22:20:15 ----D---- C:\Windows\system32\restore
2008-10-30 22:17:48 ----SHD---- C:\$Recycle.Bin
2008-10-30 22:17:31 ----RD---- C:\Users
2008-10-30 22:15:17 ----D---- C:\Program Files\Windows NT

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-01-21 350720]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-09-24 3976192]
R3 CT20XUT.DLL;CT20XUT.DLL; C:\Windows\system32\CT20XUT.DLL [2008-07-15 170520]
R3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2008-07-15 511000]
R3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2008-07-15 527384]
R3 CTEDSPSY.DLL;CTEDSPSY.DLL; C:\Windows\system32\CTEDSPSY.DLL [2007-03-05 329528]
R3 CTEXFIFX.DLL;CTEXFIFX.DLL; C:\Windows\system32\CTEXFIFX.DLL [2008-07-15 1323544]
R3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys [2008-07-15 14360]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys [2008-07-15 157208]
R3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys [2008-07-15 92696]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2008-11-24 16608]
R3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys [2008-07-15 1173016]
R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\Windows\system32\DRIVERS\L8042mou.Sys [2007-04-11 63248]
R3 LMouKE;SetPoint Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouKE.Sys [2007-04-11 79376]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\DRIVERS\LVUSBSta.sys [2007-10-12 41752]
R3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys [2008-07-15 127000]
R3 PID_0928;Logitech QuickCam Express(PID_0928); C:\Windows\system32\DRIVERS\LV561AV.SYS [2007-10-12 490776]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-02-14 118784]
S3 ay1p4t7a;ay1p4t7a; C:\Windows\system32\drivers\ay1p4t7a.sys []
S3 COMMONFX.DLL;COMMONFX.DLL; C:\Windows\system32\COMMONFX.DLL [2007-03-05 98616]
S3 CTAUDFX.DLL;CTAUDFX.DLL; C:\Windows\system32\CTAUDFX.DLL [2007-03-05 552248]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\Windows\system32\drivers\ctdvda2k.sys [2008-07-15 347080]
S3 CTEAPSFX.DLL;CTEAPSFX.DLL; C:\Windows\system32\CTEAPSFX.DLL [2007-03-05 174392]
S3 CTEDSPFX.DLL;CTEDSPFX.DLL; C:\Windows\system32\CTEDSPFX.DLL [2007-03-05 286520]
S3 CTEDSPIO.DLL;CTEDSPIO.DLL; C:\Windows\system32\CTEDSPIO.DLL [2007-03-05 134968]
S3 CTERFXFX.DLL;CTERFXFX.DLL; C:\Windows\system32\CTERFXFX.DLL [2007-03-05 101176]
S3 CTHWIUT.DLL;CTHWIUT.DLL; C:\Windows\system32\CTHWIUT.DLL [2008-07-15 72728]
S3 CTSBLFX.DLL;CTSBLFX.DLL; C:\Windows\system32\CTSBLFX.DLL [2007-03-05 566584]
S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2008-10-28 15360]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-05-07 2134424]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
S3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-21 73088]
S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-09-24 704512]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-04-30 417792]
R2 GEST Service;GEST Service for program management.; C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-05-13 80392]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2008-11-11 66872]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-11-05 654848]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-11-05 72704]
S3 Adobe Version Cue CS3;Adobe Version Cue CS3; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe [2007-03-20 153792]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 aspnet_state;Service d'état ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-01-21 33800]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-10-31 79360]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-21 523776]
S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2008-10-28 195752]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-01-21 917504]

-----------------EOF-----------------


info.txt logfile of random's system information tool 1.04 2008-11-24 12:57:28

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative\Sound Blaster X-Fi\Program\SETUP.EXE" /S /U /W /L:FRN
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{06E3E953-0570-4DFF-A7B5-46114C390228}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{06E3E953-0570-4DFF-A7B5-46114C390228}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1EF644C7-1A0D-4B94-9AF5-AD04702094A4}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1EF644C7-1A0D-4B94-9AF5-AD04702094A4}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7AB55EC6-1158-41EF-B87D-90555A8F5C92}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B026740-A400-48FF-8F6B-B37C4F61C937}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B026740-A400-48FF-8F6B-B37C4F61C937}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CAAE8EC2-2340-4D6E-A74D-07814046A11B}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CAAE8EC2-2340-4D6E-A74D-07814046A11B}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEC86016-B796-4348-B93B-36C5EDEB85E1}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEC86016-B796-4348-B93B-36C5EDEB85E1}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DCCC08BD-FC52-4AEB-ACF8-6A5C06550468}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DCCC08BD-FC52-4AEB-ACF8-6A5C06550468}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3C64B-2A22-48C5-857B-E952D7BE64F5}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3C64B-2A22-48C5-857B-E952D7BE64F5}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x40c /remove
Add or Remove Adobe Creative Suite 3 Web Premium-->C:\Program Files\Common Files\Adobe\Installers\247961ef275e20c5cb073c36394ac32\Setup.exe
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe BridgeTalk Plugin CS3-->MsiExec.exe /I{B7F560B3-6EFF-4026-A982-843895A41149}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Contribute CS3-->MsiExec.exe /I{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}
Adobe Creative Suite 3 Web Premium-->MsiExec.exe /I{C347D234-93D8-4595-BDAA-C04638B23B48}
Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Extension Manager CS3-->MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
Adobe Flash CS3-->MsiExec.exe /I{6B52140A-F189-4945-BFFC-DB3F00B8C589}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
Adobe Flash Player 9 Plugin-->MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
Adobe Flash Video Encoder-->MsiExec.exe /I{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}
Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator CS3-->MsiExec.exe /I{F08E8D2E-F132-4742-9C87-D5FF223A016A}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe MotionPicture Color Files-->MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Photoshop CS3-->MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Adobe Setup-->MsiExec.exe /I{6A5D1A94-624A-4D20-B178-3A283B500370}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe Version Cue CS3 Server-->MsiExec.exe /I{1D58229F-C505-45CA-8223-F35F3A34B963}
Adobe WAS CS3-->MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AHV content for Acrobat and Flash-->MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
ArmA Queen's Gambit Uninstall-->C:\Program files\Bohemia Interactive\ArmA\UnInstallQG.exe
ArmA Uninstall-->C:\Program files\Bohemia Interactive\ArmA\UnInstall.exe
ATI AVIVO Codecs-->MsiExec.exe /I{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}
Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
BattlEye Uninstall-->C:\Program files\Bohemia Interactive\ArmA\BattlEye\UnInstallBE.exe
Catalyst Control Center - Branding-->MsiExec.exe /I{FA3A247D-437A-455E-A88F-7EB6E5F9E799}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CDDRV_Installer-->MsiExec.exe /I{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}
Creative Audio Console-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x40c /remove
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x40c /remove
Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8

Répondre à jimmy

9

Destrio5, le 24 nov 2008 à 13:15:35

--> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

--> Lance l'installation avec les paramètres par défaut.

--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

--> Clique droit sur le raccourci UsbFix situé sur ton Bureau et choisis Exécuter en tant qu'administrateur.

--> Choisis l'option 1 (Nettoyage).

--> Le PC va redémarrer.

--> Après redémarrage, poste le rapport UsbFix.txt

Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)

Répondre à Destrio5

10

jimmy, le 24 nov 2008 à 13:27:08

Je vais faire ça cher destrio5 mais je pense que nous pouvons considérer le problème résolu! j'ai réinstallé AntiVir et il me scanne tout tranquilement... je suis super content vous êtes des chefs! la bise
(je poste mon rapport usbFix très bientot)

Répondre à jimmy

11

Destrio5, le 24 nov 2008 à 13:31:42

Pour moi, retirer juste Bagle ne suffit pas.

Répondre à Destrio5

12

jimmy, le 24 nov 2008 à 15:10:06

J'ai fait le scan usbfix, voici le rapport. dis moi si il y'a encore un risque :) encore merci




-------------- UsbFix V2.413 ---------------

* User : Jimmy - PC-DE-JIMMY
* Outils mis a jours le 23/11/2008 par Chiquitine29 et Chimay8
* Recherche effectuée à 15:06:22 le 24/11/2008
* Windows Vista - Internet Explorer 7.0.6001.18000


--------------- [ Processus actifs ] ----------------


C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Jimmy\AppData\Local\Temp\E436.tmp\b2e.exe
C:\Windows\system32\conime.exe

--------------- [ Informations lecteurs ] ----------------

C: - Lecteur fixe
E: - Lecteur fixe

--------------- [ Lecteur C ] ----------------

C: - Lecteur fixe

+- Listing des fichiers présents :

[18/09/2006 22:43][--a------] C:\autoexec.bat
[24/11/2008 12:38][--a------] C:\FindyKill.txt
[24/11/2008 12:38][--a------] C:\UsbFix.txt
[18/09/2006 22:43][--a------] C:\config.sys
[18/09/2006 22:43][--a------] C:\hiberfil.sys
[18/09/2006 22:43][--a------] C:\pagefile.sys

--------------- [ Lecteur E ] ----------------

E: - Lecteur fixe

+- Listing des fichiers présents :


--------------- [ Registre / Startup ] ----------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion­\run]

filehippo.com="C:\Program Files\filehippo.com\UpdateChecker.exe" /background
DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
Orb="C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
eMuleAutoStart=C:\Program Files\eMule\emule.exe -AutoStart
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater=
<NO NAME>=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
RCSystem="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
AudioDrvEmulator="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
VolPanel="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
CTHelper=CTHELPER.EXE
UpdReg=C:\Windows\UpdReg.EXE
StartCCC="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
CTxfiHlp=CTXFIHLP.EXE
SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
Logitech Hardware Abstraction Layer=KHALMNPR.EXE
Acrobat Assistant 8.0="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
<NO NAME>=
Adobe_ID0EYTHM=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
WinampAgent="C:\Program Files\Winamp\winampa.exe"
Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=

--------------- [ Registre / Mountpoint2 ] ----------------

Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{698d7ea2-b99c-11dd-b249-001fd0264aca}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b9681b6a-ba23-11dd-8f59-001fd0264aca}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ccbcbf81-a637-11dd-8034-806e6f6e6963}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e11c7a95-ab61-11dd-a5fb-001fd0264aca}\Shell\AutoRun\command

--------------- [ Nettoyage des disques ] ----------------


--------------- [ Resumé ] ----------------

-> /!\ Le resultat doit etre interprété par un spécialiste /!\

[18/09/2006 22:43][--a------] C:\autoexec.bat

--------------- ! Fin du rapport ! ----------------

Répondre à jimmy

13

Destrio5, le 24 nov 2008 à 15:12:37

Reposte le rapport info de RSIT car il a bogué ;)

Répondre à Destrio5

14

jimmy, le 24 nov 2008 à 15:14:55

Info.txt logfile of random's system information tool 1.04 2008-11-24 12:57:28

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative\Sound Blaster X-Fi\Program\SETUP.EXE" /S /U /W /L:FRN
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{06E3E953-0570-4DFF-A7B5-46114C390228}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{06E3E953-0570-4DFF-A7B5-46114C390228}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1EF644C7-1A0D-4B94-9AF5-AD04702094A4}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1EF644C7-1A0D-4B94-9AF5-AD04702094A4}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7AB55EC6-1158-41EF-B87D-90555A8F5C92}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B026740-A400-48FF-8F6B-B37C4F61C937}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B026740-A400-48FF-8F6B-B37C4F61C937}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CAAE8EC2-2340-4D6E-A74D-07814046A11B}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CAAE8EC2-2340-4D6E-A74D-07814046A11B}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC3D3A93-C433-4329-AC3A-7EFC52A332C2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEC86016-B796-4348-B93B-36C5EDEB85E1}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEC86016-B796-4348-B93B-36C5EDEB85E1}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DCCC08BD-FC52-4AEB-ACF8-6A5C06550468}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DCCC08BD-FC52-4AEB-ACF8-6A5C06550468}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3C64B-2A22-48C5-857B-E952D7BE64F5}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3C64B-2A22-48C5-857B-E952D7BE64F5}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x40c /remove
Add or Remove Adobe Creative Suite 3 Web Premium-->C:\Program Files\Common Files\Adobe\Installers\247961ef275e20c5cb073c36394ac32\Setup.exe
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe BridgeTalk Plugin CS3-->MsiExec.exe /I{B7F560B3-6EFF-4026-A982-843895A41149}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Contribute CS3-->MsiExec.exe /I{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}
Adobe Creative Suite 3 Web Premium-->MsiExec.exe /I{C347D234-93D8-4595-BDAA-C04638B23B48}
Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Extension Manager CS3-->MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
Adobe Flash CS3-->MsiExec.exe /I{6B52140A-F189-4945-BFFC-DB3F00B8C589}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
Adobe Flash Player 9 Plugin-->MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
Adobe Flash Video Encoder-->MsiExec.exe /I{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}
Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator CS3-->MsiExec.exe /I{F08E8D2E-F132-4742-9C87-D5FF223A016A}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe MotionPicture Color Files-->MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Photoshop CS3-->MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Adobe Setup-->MsiExec.exe /I{6A5D1A94-624A-4D20-B178-3A283B500370}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe Version Cue CS3 Server-->MsiExec.exe /I{1D58229F-C505-45CA-8223-F35F3A34B963}
Adobe WAS CS3-->MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AHV content for Acrobat and Flash-->MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
ArmA Queen's Gambit Uninstall-->C:\Program files\Bohemia Interactive\ArmA\UnInstallQG.exe
ArmA Uninstall-->C:\Program files\Bohemia Interactive\ArmA\UnInstall.exe
ATI AVIVO Codecs-->MsiExec.exe /I{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}
Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
BattlEye Uninstall-->C:\Program files\Bohemia Interactive\ArmA\BattlEye\UnInstallBE.exe
Catalyst Control Center - Branding-->MsiExec.exe /I{FA3A247D-437A-455E-A88F-7EB6E5F9E799}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CDDRV_Installer-->MsiExec.exe /I{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}
Creative Audio Console-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x40c /remove
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x40c /remove
Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c /remove
Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
eMule-->"C:\Program Files\eMule\Uninstall.exe"
Energy Saver Advance B8.0610.1-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7ED169D4-5053-4166-93DF-53B12AE6C539}\setup.exe" -l0x9 -removeonly
Fallout 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{974C4B12-4D02-4879-85E0-61C95CC63E9E}\setup.exe" -l0x40c -removeonly
FEAR Perseus Mandate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5B15759F-B7A0-400C-9A5E-634C9D0871CE}\setup.exe" -l0x40c -removeonly
filehippo.com Update Checker-->"C:\Program Files\filehippo.com\uninstall.exe"
Filzip 3.06-->"C:\Program Files\Filzip\unins000.exe"
FindyKill-->C:\Program Files\FindyKill\Uninstal.exe
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
HydraVision-->MsiExec.exe /X{A434533D-989F-0440-1D1F-A784F64E15F3}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jupiter-8V Demo 1.1-->"C:\Program Files\Arturia\Jupiter-8V\unins000.exe"
KhalInstallWrapper-->MsiExec.exe /I{56918C0C-0D87-4CA6-92BF-4975A43AC719}
livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x40c UNINSTALL
Logitech SetPoint-->C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe -runfromtemp -l0x040c -removeonly
Ma-Config.com-->MsiExec.exe /X{49C3F7D7-215F-47D7-A93B-E9FC772A5E96}
Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Mozilla Firefox (2.0.0.18)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Propriétés de Creative Sound Blaster-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7AB55EC6-1158-41EF-B87D-90555A8F5C92}\setup.exe" -l0x40c /remove
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\SETUP.EXE -runfromtemp -l0x040c -removeonly
Reason 4.0-->"C:\Program Files\Propellerhead\Reason\Uninstall Reason\unins000.exe"
Sound Blaster X-Fi-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18F11181-EA1A-42AE-AF89-4867C7F7A6FA}\SETUP.EXE" -l0x40c /remove
TransMac version 8.1-->"C:\Program Files\TransMac\unins000.exe"
VLC media player 0.9.4-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp Remote-->"C:\Program Files\Winamp Remote\uninstall.exe"
Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
World of Warcraft FREE Trial-->MsiExec.exe /X{02EBDBB9-4600-41D3-B566-40CB861511D2}

======Security center information======

AS: Avira AntiVir PersonalEdition (outdated)
AS: Windows Defender

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE

-----------------EOF-----------------


Logfile of random's system information tool 1.04 (written by random/random)
Run by Jimmy at 2008-11-24 12:57:14
Microsoft® Windows Vista™ Professionnel Service Pack 1
System drive C: has 310 GB (65%) free of 477 GB
Total RAM: 2046 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:57:27, on 24/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\System32\CTHELPER.EXE
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Windows\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4Y80NKQN\RSIT[1].exe
C:\Program Files\trend micro\Jimmy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O13 - Gopher Prefix:
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
End of file - 9781 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2008-06-11 61816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll [2007-03-16 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-10-14 863688]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22 321120]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll [2007-03-16 118784]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-11-23 1008184]
"RCSystem"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2006-11-22 57344]
"AudioDrvEmulator"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2006-11-22 57344]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [2006-12-06 180224]
"CTHelper"=C:\Windows\system32\CTHELPER.EXE [2007-03-05 19456]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-01 61440]
"CTxfiHlp"=C:\Windows\system32\CTXFIHLP.EXE [2008-07-11 19968]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"Logitech Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2007-04-11 56080]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2006-10-22 620152]
""= []
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [2007-03-20 1884160]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"filehippo.com"=C:\Program Files\filehippo.com\UpdateChecker.exe [2005-10-06 860168]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]
"Orb"=C:\Program Files\Winamp Remote\bin\OrbTray.exe [2008-04-01 507904]
"eMuleAutoStart"=C:\Program Files\eMule\emule.exe [2008-08-01 5480448]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=95000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{698d7ea2-b99c-11dd-b249-001fd0264aca}]
shell\AutoRun\command - E:\Launch.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccbcbf81-a637-11dd-8034-806e6f6e6963}]
shell\AutoRun\command - D:\livebox.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e11c7a95-ab61-11dd-a5fb-001fd0264aca}]
shell\AutoRun\command - F:\AutoRunCD.exe


======List of files/folders created in the last 1 months======

2008-11-24 12:57:14 ----D---- C:\rsit
2008-11-24 12:57:14 ----D---- C:\Program Files\trend micro
2008-11-24 12:36:21 ----A---- C:\FindyKill.txt
2008-11-24 12:12:44 ----D---- C:\Program Files\FindyKill
2008-11-23 23:36:06 ----D---- C:\Program Files\Alwil Software
2008-11-23 23:16:22 ----A---- C:\Windows\Filzip.ini
2008-11-23 23:15:46 ----D---- C:\Windows\Minidump
2008-11-23 21:32:02 ----D---- C:\Windows\Downloaded Installations
2008-11-21 16:13:15 ----D---- C:\Crytek
2008-11-20 14:15:22 ----D---- C:\Program Files\Filzip
2008-11-18 23:42:35 ----D---- C:\ProgramData\eMule
2008-11-18 23:41:54 ----D---- C:\Program Files\eMule
2008-11-18 19:05:06 ----D---- C:\Windows\system32\appmgmt
2008-11-18 19:01:56 ----D---- C:\Users\Jimmy\AppData\Roaming\AdobeUM
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wups2.dll
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wucltux.dll
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wuaueng.dll
2008-11-18 11:23:08 ----A---- C:\Windows\system32\wuauclt.exe
2008-11-18 11:22:52 ----A---- C:\Windows\system32\wups.dll
2008-11-18 11:22:52 ----A---- C:\Windows\system32\wudriver.dll
2008-11-18 11:22:52 ----A---- C:\Windows\system32\wuapi.dll
2008-11-18 11:22:46 ----A---- C:\Windows\system32\wuwebv.dll
2008-11-18 11:22:46 ----A---- C:\Windows\system32\wuapp.exe
2008-11-16 06:19:12 ----RHD---- C:\Users\Jimmy\AppData\Roaming\SecuROM
2008-11-15 19:15:42 ----D---- C:\Program Files\Audacity
2008-11-15 01:57:05 ----A---- C:\Windows\system32\REX Shared Library.dll
2008-11-15 01:57:04 ----A---- C:\Windows\system32\ReWire.dll
2008-11-15 01:52:43 ----D---- C:\Users\Jimmy\AppData\Roaming\Propellerhead Software
2008-11-15 01:52:43 ----D---- C:\ProgramData\Propellerhead Software
2008-11-15 01:51:08 ----D---- C:\Program Files\Propellerhead
2008-11-12 09:47:59 ----A---- C:\Windows\system32\msxml3.dll
2008-11-12 09:47:57 ----A---- C:\Windows\system32\msxml6.dll
2008-11-11 23:28:53 ----D---- C:\Program Files\GameSpy
2008-11-11 23:27:10 ----D---- C:\Windows\system32\URTTEMP
2008-11-11 23:19:14 ----A---- C:\Windows\system32\PnkBstrB.exe
2008-11-11 23:19:11 ----A---- C:\Windows\system32\PnkBstrA.exe
2008-11-11 23:19:10 ----A---- C:\Windows\system32\pbsvc.exe
2008-11-11 23:10:55 ----D---- C:\Program Files\Sierra Entertainment
2008-11-08 20:25:17 ----D---- C:\Program Files\Common Files\Digidesign
2008-11-08 20:25:17 ----A---- C:\Program Files\Jupiter-8V.dll
2008-11-08 20:25:14 ----D---- C:\Program Files\Arturia
2008-11-07 19:56:33 ----D---- C:\Users\Jimmy\AppData\Roaming\dvdcss
2008-11-07 03:00:42 ----D---- C:\Program Files\MSXML 4.0
2008-11-06 01:40:48 ----D---- C:\Users\Jimmy\AppData\Roaming\vlc
2008-11-06 01:40:00 ----D---- C:\Program Files\VideoLAN
2008-11-06 01:23:54 ----D---- C:\ProgramData\OrbNetworks
2008-11-06 01:23:54 ----D---- C:\Program Files\Winamp Remote
2008-11-06 01:23:13 ----N---- C:\Windows\system32\vxblock.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxwave.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxsfs.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxmas.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxinsa64.exe
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxhpinst.exe
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxdrv.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxcpya64.exe
2008-11-06 01:23:13 ----N---- C:\Windows\system32\pxafs.dll
2008-11-06 01:23:13 ----N---- C:\Windows\system32\px.dll
2008-11-06 01:23:12 ----D---- C:\Program Files\Winamp
2008-11-06 01:11:55 ----D---- C:\ProgramData\FLEXnet
2008-11-05 21:09:25 ----D---- C:\ProgramData\Adobe Systems
2008-11-05 21:01:04 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2008-11-05 20:59:57 ----A---- C:\Windows\system32\msxml4r.dll
2008-11-05 19:29:59 ----D---- C:\ProgramData\ALM
2008-11-05 19:26:49 ----D---- C:\Program Files\QuickTime
2008-11-05 19:22:54 ----A---- C:\Windows\system32\NPSWF32_FlashUtil.exe
2008-11-05 19:22:54 ----A---- C:\Windows\system32\NPSWF32.dll
2008-11-05 19:21:21 ----D---- C:\ProgramData\Adobe
2008-11-05 19:19:23 ----D---- C:\Program Files\Bonjour
2008-11-05 19:16:24 ----D---- C:\Program Files\Common Files\Macrovision Shared
2008-11-05 19:04:30 ----D---- C:\Program Files\TransMac
2008-11-05 18:49:27 ----D---- C:\Program Files\DAEMON Tools Toolbar
2008-11-05 18:48:54 ----D---- C:\Program Files\DAEMON Tools Lite
2008-11-05 18:46:08 ----D---- C:\Users\Jimmy\AppData\Roaming\DAEMON Tools
2008-11-04 20:22:02 ----D---- C:\Program Files\Common Files\Adobe
2008-11-04 20:22:02 ----D---- C:\Program Files\Adobe
2008-11-04 20:20:50 ----A---- C:\Windows\IsUn040c.exe
2008-11-03 23:24:29 ----D---- C:\Windows\PCHEALTH
2008-11-03 23:24:29 ----D---- C:\Program Files\MSN Messenger
2008-11-03 23:24:18 ----HD---- C:\Config.Msi
2008-11-03 23:20:33 ----D---- C:\Users\Jimmy\AppData\Roaming\HP
2008-11-03 22:40:11 ----D---- C:\ProgramData\Creative Labs
2008-11-03 22:21:19 ----D---- C:\Program Files\Orange HSS
2008-11-03 22:21:10 ----A---- C:\Windows\system32\MSVCR71.dll
2008-11-03 22:21:10 ----A---- C:\Windows\system32\msvcp71.dll
2008-11-03 22:21:10 ----A---- C:\Windows\system32\MFC71.dll
2008-11-03 22:21:10 ----A---- C:\Windows\system32\atl71.dll
2008-11-03 22:18:22 ----D---- C:\Program Files\SAGEM
2008-11-03 21:58:30 ----D---- C:\Program Files\Common Files\logishrd
2008-11-03 21:53:18 ----D---- C:\Users\Jimmy\AppData\Roaming\Logitech
2008-11-03 21:53:07 ----R---- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-11-03 21:50:57 ----A---- C:\Windows\system32\KemXML.dll
2008-11-03 21:50:57 ----A---- C:\Windows\system32\KemWnd.dll
2008-11-03 21:50:57 ----A---- C:\Windows\system32\KemUtil.dll
2008-11-03 21:50:57 ----A---- C:\Windows\system32\kemutb.dll
2008-11-03 21:50:43 ----D---- C:\ProgramData\Logitech
2008-11-03 21:50:42 ----D---- C:\Program Files\Logitech
2008-11-03 21:50:40 ----D---- C:\Program Files\Common Files\Logitech
2008-11-03 21:49:09 ----D---- C:\ProgramData\LogiShrd
2008-11-03 02:06:34 ----D---- C:\Program Files\Bohemia Interactive
2008-11-02 18:12:36 ----A---- C:\Windows\system32\CmdLineExt.dll
2008-11-02 17:59:00 ----D---- C:\Program Files\Bethesda Softworks
2008-11-02 17:59:00 ----A---- C:\Windows\system32\XAudio2_1.dll
2008-11-02 17:59:00 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2008-11-02 17:59:00 ----A---- C:\Windows\system32\xactengine3_1.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\XAudio2_0.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\xactengine3_0.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DX9_38.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DX9_37.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\d3dx10_38.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\d3dx10_37.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2008-11-02 17:58:59 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\xactengine2_9.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\xactengine2_10.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\d3dx9_36.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\d3dx10_36.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\d3dx10_35.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2008-11-02 17:58:58 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\xactengine2_8.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\d3dx9_35.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\d3dx9_34.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\d3dx10_34.dll
2008-11-02 17:58:57 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2008-11-02 17:58:56 ----A---- C:\Windows\system32\xactengine2_7.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\xactengine2_6.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\xactengine2_5.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\xactengine2_4.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\x3daudio1_1.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\d3dx9_32.dll
2008-11-02 17:58:54 ----A---- C:\Windows\system32\d3dx10.dll
2008-11-02 17:58:53 ----A---- C:\Windows\system32\xinput1_2.dll
2008-11-02 17:58:53 ----A---- C:\Windows\system32\xactengine2_3.dll
2008-11-02 17:58:53 ----A---- C:\Windows\system32\d3dx9_31.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\xinput1_3.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\d3dx9_33.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\d3dx10_33.dll
2008-11-02 17:57:36 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2008-11-02 17:57:17 ----D---- C:\Windows\system32\xlive
2008-11-01 23:34:05 ----D---- C:\Program Files\OCCT
2008-11-01 21:43:32 ----D---- C:\Users\Jimmy\AppData\Roaming\OpenOffice.org
2008-11-01 13:44:34 ----D---- C:\Program Files\JRE
2008-11-01 13:44:29 ----D---- C:\Program Files\OpenOffice.org 3
2008-11-01 13:44:10 ----A---- C:\Windows\system32\javaws.exe
2008-11-01 13:44:10 ----A---- C:\Windows\system32\javaw.exe
2008-11-01 13:44:10 ----A---- C:\Windows\system32\java.exe
2008-11-01 13:43:24 ----D---- C:\Program Files\Java
2008-11-01 13:43:24 ----D---- C:\Program Files\Common Files\Java
2008-10-31 21:49:39 ----D---- C:\Program Files\Yahoo!
2008-10-31 21:49:34 ----D---- C:\Program Files\CCleaner
2008-10-31 21:39:53 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2008-10-31 21:39:51 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2008-10-31 21:39:45 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2008-10-31 21:17:18 ----D---- C:\Users\Jimmy\AppData\Roaming\Macromedia
2008-10-31 21:17:18 ----D---- C:\Users\Jimmy\AppData\Roaming\Adobe
2008-10-31 20:43:24 ----D---- C:\Program Files\filehippo.com
2008-10-31 20:19:50 ----D---- C:\Program Files\Lavalys
2008-10-31 20:13:49 ----D---- C:\Program Files\Common Files\Creative Labs Shared
2008-10-31 20:12:28 ----A---- C:\Windows\system32\cttele32.dll
2008-10-31 20:08:07 ----A---- C:\Windows\system32\AppSetup.exe
2008-10-31 19:55:22 ----D---- C:\ProgramData\ATI
2008-10-31 19:49:17 ----D---- C:\ATI
2008-10-31 19:45:37 ----D---- C:\ProgramData\ma-config.com
2008-10-31 19:45:37 ----D---- C:\Program Files\ma-config.com
2008-10-31 19:28:32 ----D---- C:\Users\Jimmy\AppData\Roaming\Mozilla
2008-10-31 19:28:26 ----D---- C:\Program Files\Mozilla Firefox
2008-10-31 19:16:30 ----A---- C:\Windows\system32\shell32.dll
2008-10-31 19:16:10 ----A---- C:\Windows\system32\es.dll
2008-10-31 19:16:05 ----A---- C:\Windows\system32\IPSECSVC.DLL
2008-10-31 19:15:58 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-10-31 19:15:58 ----A---- C:\Windows\system32\gameux.dll
2008-10-31 19:15:58 ----A---- C:\Windows\system32\Apphlpdm.dll
2008-10-31 19:15:54 ----A---- C:\Windows\system32\rpcrt4.dll
2008-10-31 19:15:51 ----A---- C:\Windows\system32\pacerprf.dll
2008-10-31 19:15:48 ----A---- C:\Windows\system32\wmpeffects.dll
2008-10-31 19:10:37 ----A---- C:\Windows\system32\winresume.exe
2008-10-31 19:10:37 ----A---- C:\Windows\system32\winload.exe
2008-10-31 19:10:37 ----A---- C:\Windows\system32\kd1394.dll
2008-10-31 19:10:37 ----A---- C:\Windows\system32\ci.dll
2008-10-31 19:10:36 ----A---- C:\Windows\system32\srcore.dll
2008-10-31 19:10:36 ----A---- C:\Windows\system32\setbcdlocale.dll
2008-10-31 19:10:35 ----A---- C:\Windows\system32\srdelayed.exe
2008-10-31 19:10:35 ----A---- C:\Windows\system32\srclient.dll
2008-10-31 19:10:35 ----A---- C:\Windows\system32\rstrui.exe
2008-10-31 19:10:35 ----A---- C:\Windows\system32\kbd106n.dll
2008-10-31 19:10:25 ----A---- C:\Windows\system32\emdmgmt.dll
2008-10-31 19:10:24 ----A---- C:\Windows\system32\dataclen.dll
2008-10-31 19:10:24 ----A---- C:\Windows\system32\cdd.dll
2008-10-31 19:10:22 ----A---- C:\Windows\system32\gdi32.dll
2008-10-31 19:10:20 ----A---- C:\Windows\system32\win32spl.dll
2008-10-31 19:10:16 ----A---- C:\Windows\system32\wersvc.dll
2008-10-31 19:10:16 ----A---- C:\Windows\system32\Faultrep.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\wshext.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\wscript.exe
2008-10-31 19:10:13 ----A---- C:\Windows\system32\vbscript.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\scrrun.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\scrobj.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\jscript.dll
2008-10-31 19:10:13 ----A---- C:\Windows\system32\cscript.exe
2008-10-31 19:10:11 ----A---- C:\Windows\system32\inetcomm.dll
2008-10-31 19:10:09 ----A---- C:\Windows\system32\quartz.dll
2008-10-31 19:10:06 ----A---- C:\Windows\system32\ntoskrnl.exe
2008-10-31 19:10:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
2008-10-31 19:09:54 ----A---- C:\Windows\system32\tzres.dll
2008-10-31 19:09:54 ----A---- C:\Windows\system32\mshtml.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\wininet.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\urlmon.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\mstime.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\jsproxy.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\iertutil.dll
2008-10-31 19:09:53 ----A---- C:\Windows\system32\ieframe.dll
2008-10-31 19:09:23 ----A---- C:\Windows\system32\msshooks.dll
2008-10-31 19:09:22 ----A---- C:\Windows\system32\msscb.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\thawbrkr.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\srchadmin.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\SearchFilterHost.exe
2008-10-31 19:09:19 ----A---- C:\Windows\system32\propsys.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\propdefs.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\msstrc.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\mssprxy.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\mssitlb.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\msshsq.dll
2008-10-31 19:09:19 ----A---- C:\Windows\system32\korwbrkr.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\xmlfilter.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\wsepno.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\tquery.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2008-10-31 19:09:18 ----A---- C:\Windows\system32\SearchIndexer.exe
2008-10-31 19:09:18 ----A---- C:\Windows\system32\rtffilt.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\offfilt.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\nlhtml.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssvp.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssrch.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssphtb.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mssph.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\msscntrs.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\mimefilt.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\chtbrkr.dll
2008-10-31 19:09:18 ----A---- C:\Windows\system32\chsbrkr.dll
2008-10-31 19:05:59 ----A---- C:\Windows\system32\netapi32.dll
2008-10-31 19:04:45 ----A---- C:\Windows\Kit.ini
2008-10-31 19:04:44 ----D---- C:\Program Files\Wanadoo
2008-10-31 19:01:11 ----D---- C:\Program Files\Securitoo
2008-10-31 19:01:03 ----D---- C:\Program Files\Inventel
2008-10-31 13:21:24 ----N---- C:\Windows\Ctregrun.exe
2008-10-31 13:20:05 ----D---- C:\Program Files\Common Files\Creative
2008-10-31 13:20:04 ----HD---- C:\Program Files\Creative Installation Information
2008-10-31 13:13:08 ----N---- C:\Windows\Updreg.EXE
2008-10-31 13:12:46 ----D---- C:\ProgramData\Creative
2008-10-31 13:05:04 ----D---- C:\Program Files\OpenAL
2008-10-31 13:05:04 ----A---- C:\Windows\system32\wrap_oal.dll
2008-10-31 13:05:04 ----A---- C:\Windows\system32\OpenAL32.dll
2008-10-31 13:04:37 ----D---- C:\Windows\system32\Data
2008-10-31 13:04:37 ----A---- C:\Windows\CTXFIFRN.DLL
2008-10-31 13:04:37 ----A---- C:\Windows\CTDCRFRN.DLL
2008-10-31 13:03:46 ----A---- C:\Windows\system32\CmdRtr.DLL
2008-10-31 13:03:46 ----A---- C:\Windows\system32\APOMngr.DLL
2008-10-31 13:02:22 ----D---- C:\Users\Jimmy\AppData\Roaming\Creative
2008-10-31 13:01:04 ----D---- C:\Program Files\Creative
2008-10-30 23:22:27 ----D---- C:\Windows\system32\Macromed
2008-10-30 23:22:20 ----A---- C:\Windows\system32\xinput1_1.dll
2008-10-30 23:22:20 ----A---- C:\Windows\system32\xactengine2_2.dll
2008-10-30 23:22:20 ----A---- C:\Windows\system32\xactengine2_1.dll
2008-10-30 23:22:18 ----A---- C:\Windows\system32\xactengine2_0.dll
2008-10-30 23:22:18 ----A---- C:\Windows\system32\x3daudio1_0.dll
2008-10-30 23:22:18 ----A---- C:\Windows\system32\d3dx9_30.dll
2008-10-30 23:22:17 ----A---- C:\Windows\system32\d3dx9_29.dll
2008-10-30 23:22:17 ----A---- C:\Windows\system32\d3dx9_28.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_27.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_26.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_25.dll
2008-10-30 23:22:16 ----A---- C:\Windows\system32\d3dx9_24.dll
2008-10-30 22:46:45 ----D---- C:\Users\Jimmy\AppData\Roaming\ATI
2008-10-30 22:43:33 ----D---- C:\Program Files\Common Files\ATI Technologies
2008-10-30 22:42:29 ----SHD---- C:\Windows\Installer
2008-10-30 22:41:51 ----D---- C:\Program Files\ATI Technologies
2008-10-30 22:41:49 ----D---- C:\Program Files\ATI
2008-10-30 22:26:35 ----D---- C:\Users\Jimmy\AppData\Roaming\InstallShield
2008-10-30 22:24:38 ----D---- C:\Windows\system32\RTCOM
2008-10-30 22:24:18 ----A---- C:\Windows\DIFxAPI.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\WavesLib.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSWOW.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSTSXT.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSTSHD.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\SRSHP360.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkPgExt.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkCoInst.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkApoApi.dll
2008-10-30 22:24:16 ----A---- C:\Windows\system32\RtkAPO.dll
2008-10-30 22:24:16 ----A---- C:\Windows\SkyTel.exe
2008-10-30 22:24:16 ----A---- C:\Windows\RtlUpd.exe
2008-10-30 22:24:15 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2008-10-30 22:24:15 ----A---- C:\Windows\RtHDVCpl.exe
2008-10-30 22:24:14 ----D---- C:\Program Files\Realtek
2008-10-30 22:24:14 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2008-10-30 22:24:14 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2008-10-30 22:24:14 ----A---- C:\Windows\system32\FMAPO.dll
2008-10-30 22:24:13 ----A---- C:\Windows\HideWin.exe
2008-10-30 22:20:41 ----RA---- C:\Windows\system32\CSVer.dll
2008-10-30 22:20:41 ----D---- C:\Program Files\Intel
2008-10-30 22:20:33 ----D---- C:\Intel
2008-10-30 22:20:21 ----D---- C:\Program Files\GIGABYTE
2008-10-30 22:20:20 ----HD---- C:\Program Files\InstallShield Installation Information
2008-10-30 22:20:14 ----D---- C:\Program Files\Common Files\InstallShield
2008-10-30 22:19:43 ----A---- C:\Windows\GSetup.ini
2008-10-30 22:17:38 ----D---- C:\Users\Jimmy\AppData\Roaming\Identities
2008-10-30 22:17:31 ----SD---- C:\Users\Jimmy\AppData\Roaming\Microsoft
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Modèles
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Menu Démarrer
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Favoris
2008-10-30 22:15:17 ----SHD---- C:\ProgramData\Bureau
2008-10-30 22:15:17 ----SHD---- C:\Program Files\Fichiers communs
2008-10-30 05:11:52 ----D---- C:\Windows\Debug
2008-10-30 05:06:43 ----D---- C:\Windows\SoftwareDistribution
2008-10-30 05:05:31 ----D---- C:\Windows\CSC
2008-10-30 05:04:20 ----D---- C:\Windows\Prefetch
2008-10-30 05:04:13 ----SHD---- C:\System Volume Information
2008-10-30 05:03:20 ----D---- C:\Windows\Panther
2008-10-30 05:03:05 ----RAS---- C:\BOOTSECT.BAK
2008-10-30 05:03:04 ----SHD---- C:\Boot

======List of files/folders modified in the last 1 months======

2008-11-24 12:57:17 ----D---- C:\Windows\Temp
2008-11-24 12:57:14 ----RD---- C:\Program Files
2008-11-24 12:53:24 ----D---- C:\Windows\System32
2008-11-24 12:49:50 ----HD---- C:\Windows\system32\drivers
2008-11-24 12:49:50 ----HD---- C:\ProgramData
2008-11-24 12:41:14 ----D---- C:\Windows\inf
2008-11-24 12:41:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2008-11-24 12:37:54 ----D---- C:\Windows\system32\WDI
2008-11-23 23:51:14 ----D---- C:\Windows
2008-11-23 23:12:39 ----D---- C:\Windows\system32\Tasks
2008-11-23 21:15:55 ----RSD---- C:\Windows\Fonts
2008-11-20 17:43:38 ----D---- C:\Windows\system32\NDF
2008-11-20 17:27:02 ----D---- C:\Windows\system32\catroot2
2008-11-18 17:34:00 ----D---- C:\Windows\rescache
2008-11-18 17:12:05 ----D---- C:\Windows\system32\fr-FR
2008-11-18 13:04:04 ----D---- C:\Windows\winsxs
2008-11-18 11:23:42 ----D---- C:\Windows\PolicyDefinitions
2008-11-18 11:23:23 ----D---- C:\Windows\system32\catroot
2008-11-13 03:02:53 ----D---- C:\Windows\Registration
2008-11-13 03:02:08 ----D---- C:\Program Files\Internet Explorer
2008-11-11 23:27:59 ----RSD---- C:\Windows\assembly
2008-11-11 23:19:06 ----D---- C:\Windows\system32\LogFiles
2008-11-08 20:25:17 ----D---- C:\Program Files\Common Files
2008-11-08 18:42:48 ----HD---- C:\Windows\system32\GroupPolicy
2008-11-04 01:10:25 ----A---- C:\Windows\system32\mrt.exe
2008-11-03 23:24:30 ----D---- C:\Program Files\Common Files\microsoft shared
2008-11-03 23:21:58 ----SD---- C:\ProgramData\Microsoft
2008-11-03 21:58:31 ----D---- C:\Windows\twain_32
2008-11-02 19:52:50 ----D---- C:\Windows\Logs
2008-10-31 21:12:54 ----D---- C:\Windows\AppPatch
2008-10-31 21:12:52 ----D---- C:\Program Files\Windows Mail
2008-10-31 21:12:49 ----D---- C:\Windows\system32\Boot
2008-10-31 21:12:43 ----D---- C:\Windows\system32\migration
2008-10-31 13:04:42 ----D---- C:\Windows\system
2008-10-30 23:22:18 ----D---- C:\Windows\Microsoft.NET
2008-10-30 22:20:15 ----D---- C:\Windows\system32\restore
2008-10-30 22:17:48 ----SHD---- C:\$Recycle.Bin
2008-10-30 22:17:31 ----RD---- C:\Users
2008-10-30 22:15:17 ----D---- C:\Program Files\Windows NT

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-01-21 350720]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-09-24 3976192]
R3 CT20XUT.DLL;CT20XUT.DLL; C:\Windows\system32\CT20XUT.DLL [2008-07-15 170520]
R3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2008-07-15 511000]
R3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2008-07-15 527384]
R3 CTEDSPSY.DLL;CTEDSPSY.DLL; C:\Windows\system32\CTEDSPSY.DLL [2007-03-05 329528]
R3 CTEXFIFX.DLL;CTEXFIFX.DLL; C:\Windows\system32\CTEXFIFX.DLL [2008-07-15 1323544]
R3 c

Répondre à jimmy

15

Destrio5, le 24 nov 2008 à 15:21:27

1/

- eMule

---> Par rapport au P2P :
http://www.libellules.ch/...


2/

---> Désinstalle les programmes suivants :
- DAEMON Tools Toolbar
- FindyKill
- Java 6 Update 7
- UsbFix

---> Mets à jour Java :
http://www.java.com/fr/download/manual.jsp


3/

---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.

A la fin de l'analyse, un message s'affiche :

L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.

Répondre à Destrio5

17

jimmy, le 24 nov 2008 à 15:36:59

merci pour les infos sur P2P mais je télécharge que très rarement^^
voici le rapport de Malwarebytes, il me semble cool:


Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1419
Windows 6.0.6001 Service Pack 1

24/11/2008 15:34:23
mbam-log-2008-11-24 (15-34-23).txt

Type de recherche: Examen rapide
Eléments examinés: 42157
Temps écoulé: 2 minute(s), 39 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

Répondre à jimmy

18

 Destrio5, le 24 nov 2008 à 15:54:45

---> Supprime le dossier RSIT situé dans C:\

---> Refais un scan RSIT et poste les deux rapports.

Répondre à Destrio5
Collection CommentÇaMarche.net