Page internet qui s'ouvre seule
Forum Sécurité - Virus : Page internet qui s'ouvre seule
bonjour,
depuis quelque temps j'ai des pages d'internet explorer qui s'ouvrent seule mais sans que j'utilise internet. j'ai édité le rapport Hijackthis mais je ni comprend rien. es ce que quelqu'un peut m'aider.
merci
donc voici le rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:04:48, on 22/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\windows\sttray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Target Web ADS\TargetWebADSh.exe
C:\windows\System32\svchost.exe
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\windows\system32\svchost.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: TargetWebADS module - {8152A0B9-DEB6-476e-BC67-175B19080A8A} - C:\Program Files\Target Web ADS\TargetWebADS.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [HBlock] C:\Program Files\Target Web ADS\TargetWebADSh.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\DOCUME~1\marco\LOCALS~1\Temp\cce14F.html
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\marco\LOCALS~1\Temp\cce14D.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\marco\LOCALS~1\Temp\cce14E.html
O9 - Extra button: (no name) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Audio Service (STacSV) - Unknown owner - c:\d\s\zi\STacSV.exe (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 9016 bytes
Bonjour,
Télécharge Catchme (Przemyslaw Gmerek) sur ton Bureau.
- Double clique sur catchme.exe (le .exe n'est pas forcément visible) afin de le lancer.
- Lorsque la recherche sera terminée, poste le rapport catchme.log dans ta prochaine réponse. (Ce rapport est sur ton bureau.)
Répondre à Angeldark
voici le rapport de catchme et merci pour ton aide
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-22 15:50:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:b728168f
"s2"=dword:9494d52b
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:62,f4,ed,06,b4,0b,3e,89,1e,d2,cb,4a,d8,6d,02,a0,86,19,8c,8f,a7,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:62,f4,ed,06,b4,0b,3e,89,1e,d2,cb,4a,d8,6d,02,a0,86,19,8c,8f,a7,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Re,
Télécharge Random's System Information Tool (RSIT) (de random/random) et sauvegarde-le sur le Bureau.
- Double-clique sur RSIT.exe afin de lancer RSIT.
- Clique Continue à l'écran Disclaimer.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (qui sera affiché)
ainsi que de info.txt (qui sera réduit dans la Barre des Tâches)
- NB : Les rapports sont sauvegardés dans le dossier C:\rsit
- Veille bien à me poster l'intégralité des rapports, vérifie qu'ils soient complets une fois que tu les as postés.
Répondre à Angeldark
info.txt logfile of random's system information tool 1.06 2009-08-22 19:55:49
======Uninstall list======
-->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
Alky for Applications (Windows XP)-->MsiExec.exe /X{BB05D173-9681-4812-A7FA-BD4042A3DA00}
Ask Toolbar-->"C:\Program Files\AskBarDis\unins000.exe"
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
barre d'outils Orange-->C:\Program Files\Orange\ToolbarFR\uninst.exe
CPUID CPU-Z 1.52.1-->"C:\Program Files\CPUID\CPU-Z\unins000.exe"
CPUID HWMonitor 1.14-->"C:\Program Files\CPUID\HWMonitor\unins000.exe"
CyberLink DVD Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
EA Download Manager-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{EF7E931D-DC84-471B-8DB6-A83358095474} /l1036
Gadget Installer-->MsiExec.exe /I{3F3733A5-8322-454D-A638-3B74E1C83752}
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
HD Tune 2.55-->"C:\Program Files\HD Tune\unins000.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Deskjet All-In-One Driver Software 9.0.A Corporate Edition-->C:\Program Files\HP\Digital Imaging\{B2C61EBB-F47C-48ba-B375-27A40F8F48F7}\setup\hpzscr01.exe -datfile hposcr14.dat
Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
K-Lite Codec Pack 5.0.0 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
LG ODD Auto Firmware Update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6179550A-3E7C-499E-BCC9-9E8113E0A285}\setup.exe"
Ma-Config.com-->MsiExec.exe /X{6C4D4FC0-467B-4BD7-8D11-50E49B2770D2}
MDI viewer 0.1-->"C:\Program Files\MDIviewer\unins000.exe"
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\windows\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\windows\$NtUninstallKB956744$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\windows\$NtUninstallKB960859$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\windows\$NtUninstallKB971557$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\windows\$NtUninstallKB971657$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\windows\$NtUninstallKB973354$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\windows\$NtUninstallKB973507$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\windows\$NtUninstallKB973869$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\windows\$NtUninstallKB967715$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB973815)-->"C:\windows\$NtUninstallKB973815$\spuninst\spuninst.exe"
Mozilla Firefox (3.5.2)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Need for Speed™ Undercover-->MsiExec.exe /X{E6D22FE1-AB5F-42CA-9480-6F70B96DDD88}
Nero 8-->MsiExec.exe /X{B944FA21-81AF-4A77-8328-CE4F4CC51036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Nokia Connectivity Cable Driver-->RUNDLL32.EXE nsesetup.dll,DoNTUninst
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
On-line Help Console-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6283826F-59A2-11D9-BB04-000AE6BE6EE7}\setup.exe" -l0x9
Open Command Prompt Shell Extension (x86-32)-->regsvr32.exe /u /i /n "C:\WINDOWS\system32\ShellExt\CmdOpen.dll"
Panda ActiveScan 2.0-->C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
Pomo 6.0-->MsiExec.exe /X{B67A3190-4C93-483A-A8F4-E51F2A572E0B}
SigmaTel Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\Setup.exe" -l0x40c -remove -removeonly
SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe"
Target Web ADS-->"C:\Program Files\Target Web ADS\Uninstall.exe"
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Outlook 2007 Junk Email Filter (kb972691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {AA020E6E-E2FB-45EF-B732-2400E2296742}
VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Windows Movie Maker 2.6-->MsiExec.exe /X{B3DAF54F-DB25-4586-9EF1-96D24BB14088}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
======Security center information======
AV: AntiVir Desktop
======System event log======
Computer Name: IZI-180D41D956F
Event Code: 7036
Message: Le service PnkBstrB est entré dans l'état : arrêté.
Record Number: 318
Source Name: Service Control Manager
Time Written: 20090806123615.000000+120
Event Type: Informations
User:
Computer Name: IZI-180D41D956F
Event Code: 7036
Message: Le service PnkBstrB est entré dans l'état : en cours d'exécution.
Record Number: 317
Source Name: Service Control Manager
Time Written: 20090806123614.000000+120
Event Type: Informations
User:
Computer Name: IZI-180D41D956F
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service PnkBstrB.
Record Number: 316
Source Name: Service Control Manager
Time Written: 20090806123614.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: IZI-180D41D956F
Event Code: 7036
Message: Le service InstallDriver Table Manager est entré dans l'état : arrêté.
Record Number: 315
Source Name: Service Control Manager
Time Written: 20090806123321.000000+120
Event Type: Informations
User:
Computer Name: IZI-180D41D956F
Event Code: 7035
Message: Un contrôle Arrêter a correctement été envoyé au service InstallDriver Table Manager.
Record Number: 314
Source Name: Service Control Manager
Time Written: 20090806123321.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM
=====Application event log=====
Computer Name: IZI-180D41D956F
Event Code: 1040
Message:
Record Number: 316
Source Name: MsiInstaller
Time Written: 20090807163355.000000+120
Event Type: Informations
User: IZI-180D41D956F\marco
Computer Name: IZI-180D41D956F
Event Code: 1033
Message:
Record Number: 315
Source Name: MsiInstaller
Time Written: 20090807163355.000000+120
Event Type: Informations
User: IZI-180D41D956F\marco
Computer Name: IZI-180D41D956F
Event Code: 11708
Message:
Record Number: 314
Source Name: MsiInstaller
Time Written: 20090807163355.000000+120
Event Type: Informations
User: IZI-180D41D956F\marco
Computer Name: IZI-180D41D956F
Event Code: 4113
Message: AntiVir a détecté dans le fichier
C:\Documents and Settings\marco\Local Settings\Temp\wza3c7\Nero.9.2.6.0-Crack.exe
un code suspect avec la désignation 'WORM/Rbot.171172'!
Record Number: 313
Source Name: Avira AntiVir
Time Written: 20090807143948.000000+120
Event Type: Avertissement
User: AUTORITE NT\SYSTEM
Computer Name: IZI-180D41D956F
Event Code: 4113
Message: AntiVir a détecté dans le fichier
C:\Documents and Settings\marco\Local Settings\Temp\wz47bd\Nero.9.2.6.0-Crack.exe
un code suspect avec la désignation 'WORM/Rbot.171172'!
Record Number: 312
Source Name: Avira AntiVir
Time Written: 20090807143925.000000+120
Event Type: Avertissement
User: AUTORITE NT\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Alky for Applications\Libraries\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by marco at 2009-08-22 19:55:47
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 215 GB (45%) free of 477 GB
Total RAM: 2047 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:55:48, on 22/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\windows\sttray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\windows\System32\svchost.exe
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\windows\system32\svchost.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Target Web ADS\TargetWebADSh.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\marco\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\marco.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: TargetWebADS module - {8152A0B9-DEB6-476e-BC67-175B19080A8A} - C:\Program Files\Target Web ADS\TargetWebADS.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [HBlock] C:\Program Files\Target Web ADS\TargetWebADSh.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\DOCUME~1\marco\LOCALS~1\Temp\cce412.html
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\marco\LOCALS~1\Temp\cce410.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\marco\LOCALS~1\Temp\cce411.html
O9 - Extra button: (no name) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Audio Service (STacSV) - Unknown owner - c:\d\s\zi\STacSV.exe (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 9011 bytes
======Scheduled tasks folder======
C:\windows\tasks\Ad-Aware Update (Weekly).job
C:\windows\tasks\User_Feed_Synchronization-{6E6AA75D-281F-449D-B637-23582B1F7208}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8152A0B9-DEB6-476e-BC67-175B19080A8A}]
TargetWebADS Class - C:\Program Files\Target Web ADS\TargetWebADS.dll [2009-08-15 207364]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-06 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-08-06 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-08-16 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-06 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-08-06 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]
Locked
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-06 256112]
{D3028143-6145-4318-99D3-3EDCE54A95A9} - barre d'outils Orange - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll [2009-07-02 2268464]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-08-15 520024]
"Google Quick Search Box"=C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-08-16 122368]
"SigmatelSysTrayApp"=C:\windows\sttray.exe [2007-05-06 405504]
"LGODDFU"=C:\Program Files\lg_fwupdate\fwupdate.exe [2006-08-17 249856]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\windows\system32\ctfmon.exe [2008-04-14 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-06 39408]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2009-08-09 288048]
"HBlock"=C:\Program Files\Target Web ADS\TargetWebADSh.exe [2009-08-15 136708]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EADM\Core.exe [2008-07-22 2772992]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-08-16 122368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
C:\windows\sttray.exe [2007-05-06 405504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-08-06 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-06 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2009-08-09 288048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
C:\PROGRA~1\WinZip\WZQKPICK.EXE [2006-07-10 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\windows\system32\WgaLogon.dll [2009-03-10 239496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2009-03-27 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"legalnoticecaption"=
"legalnoticetext"=
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"ForceClassicControlPanel"=1
"NoSMHelp"=1
"NoSMConfigurePrograms"=1
"NoStartMenuPinnedList"=0
"NoResolveTrack"=1
"NoResolveSearch"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ma-config.com\maconfservice.exe"="C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======File associations======
.scr - config - "%1" /S
======List of files/folders created in the last 1 months======
2009-08-22 19:55:47 ----D---- C:\rsit
2009-08-22 15:04:17 ----D---- C:\Program Files\Trend Micro
2009-08-22 14:51:57 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-08-22 14:50:18 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-08-22 11:06:22 ----D---- C:\Program Files\Panda Security
2009-08-22 10:13:26 ----D---- C:\windows\BDOSCAN8
2009-08-21 17:50:00 ----D---- C:\Temp
2009-08-21 17:49:12 ----A---- C:\windows\lgfwup.ini
2009-08-21 17:49:09 ----A---- C:\windows\system32\Vb6stkit.dll
2009-08-21 17:49:09 ----A---- C:\windows\system32\VB6KO.DLL
2009-08-21 17:49:09 ----A---- C:\windows\system32\lgfwunis.exe
2009-08-21 17:49:08 ----D---- C:\Program Files\lg_fwupdate
2009-08-21 17:46:50 ----D---- C:\Program Files\CyberLink
2009-08-19 17:57:28 ----A---- C:\windows\ntbtlog.txt
2009-08-18 22:12:42 ----DC---- C:\windows\$NtUninstallKB968389$
2009-08-18 21:35:33 ----D---- C:\windows\Sun
2009-08-17 11:22:02 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-08-17 11:22:02 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-08-17 11:22:02 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-08-16 14:37:19 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft(2)
2009-08-16 13:58:29 ----D---- C:\Program Files\SigmaTel
2009-08-15 21:38:50 ----HDC---- C:\windows\$NtUninstallKB967715$
2009-08-15 14:12:45 ----D---- C:\Program Files\QUAD Utilities
2009-08-15 13:24:41 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-08-15 12:17:19 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-08-15 12:17:19 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-15 12:14:28 ----A---- C:\windows\system32\lsdelete.exe
2009-08-15 11:19:31 ----HDC---- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-08-15 11:19:29 ----D---- C:\Program Files\Lavasoft
2009-08-15 09:36:15 ----D---- C:\Program Files\Target Web ADS
2009-08-14 19:11:08 ----D---- C:\Program Files\Fichiers communs\Borland Shared
2009-08-14 19:11:02 ----D---- C:\Program Files\Pomo
2009-08-14 19:10:17 ----A---- C:\windows\system32\dunzip32.dll
2009-08-13 00:26:27 ----HDC---- C:\windows\$NtUninstallKB960859$
2009-08-13 00:26:24 ----HDC---- C:\windows\$NtUninstallKB971657$
2009-08-13 00:26:21 ----HDC---- C:\windows\$NtUninstallKB971557$
2009-08-13 00:26:18 ----HDC---- C:\windows\$NtUninstallKB956744$
2009-08-13 00:26:15 ----HDC---- C:\windows\$NtUninstallKB973869$
2009-08-13 00:26:01 ----HDC---- C:\windows\$NtUninstallKB973507$
2009-08-13 00:25:58 ----HDC---- C:\windows\$NtUninstallKB973354$
2009-08-13 00:25:56 ----A---- C:\windows\system32\wmpns.dll
2009-08-13 00:25:52 ----HDC---- C:\windows\$NtUninstallKB973540_WM9$
2009-08-13 00:25:11 ----HDC---- C:\windows\$NtUninstallKB973815$
2009-08-12 19:44:46 ----D---- C:\Program Files\NOS
2009-08-12 19:44:46 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-08-10 15:20:37 ----D---- C:\Program Files\MDIviewer
2009-08-10 15:20:37 ----A---- C:\windows\system32\MSPGIMME.DLL
2009-08-10 15:20:37 ----A---- C:\windows\system32\MSPCORE.DLL
2009-08-10 15:20:37 ----A---- C:\windows\system32\MDIVWCTL.DLL
2009-08-10 15:20:37 ----A---- C:\windows\system32\GDIPLUS.DLL
2009-08-10 01:47:10 ----A---- C:\windows\NeroDigital.ini
2009-08-09 10:57:08 ----D---- C:\Program Files\Mozilla Firefox
2009-08-09 10:57:08 ----D---- C:\Program Files\AskBarDis
2009-08-09 10:57:08 ----D---- C:\Documents and Settings\marco\Application Data\Mozilla
2009-08-09 10:56:53 ----D---- C:\Program Files\uTorrent
2009-08-09 10:56:25 ----D---- C:\Documents and Settings\marco\Application Data\uTorrent
2009-08-08 22:40:41 ----D---- C:\Program Files\Fichiers communs\Adobe
2009-08-08 22:40:41 ----D---- C:\Program Files\Adobe
2009-08-08 20:41:43 ----D---- C:\Documents and Settings\marco\Application Data\Nero
2009-08-08 20:41:34 ----A---- C:\windows\system32\MsiExec.exe.log
2009-08-08 20:40:35 ----D---- C:\Program Files\Nero
2009-08-08 20:40:35 ----D---- C:\Program Files\Fichiers communs\Nero
2009-08-08 20:40:35 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2009-08-07 21:31:50 ----A---- C:\windows\system32\MRT.exe
2009-08-07 20:24:34 ----D---- C:\Program Files\HD Tune
2009-08-07 19:45:17 ----D---- C:\Program Files\CPUID
2009-08-06 16:29:40 ----D---- C:\Program Files\Microsoft Works
2009-08-06 16:29:35 ----D---- C:\Program Files\MSBuild
2009-08-06 16:29:29 ----D---- C:\Program Files\Microsoft Visual Studio
2009-08-06 16:29:29 ----D---- C:\Program Files\Fichiers communs\DESIGNER
2009-08-06 16:29:08 ----D---- C:\Program Files\Microsoft.NET
2009-08-06 16:27:44 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-08-06 16:27:24 ----D---- C:\windows\SHELLNEW
2009-08-06 16:27:08 ----D---- C:\Program Files\Microsoft Office
2009-08-06 16:26:53 ----RHD---- C:\MSOCache
2009-08-06 12:36:37 ----A---- C:\windows\system32\PnkBstrA.exe
2009-08-06 12:36:14 ----A---- C:\windows\system32\PnkBstrB.exe
2009-08-06 12:33:19 ----D---- C:\Program Files\Electronic Arts
2009-08-06 12:33:18 ----D---- C:\ProgramData
2009-08-06 12:32:58 ----D---- C:\Documents and Settings\marco\Application Data\Leadertech
2009-08-06 12:28:34 ----D---- C:\windows\system32\LogFiles
2009-08-06 12:24:02 ----D---- C:\Program Files\EA Games
2009-08-06 12:13:43 ----D---- C:\Documents and Settings\marco\Application Data\Azureus
2009-08-06 12:13:15 ----A---- C:\windows\system32\javaws.exe
2009-08-06 12:13:15 ----A---- C:\windows\system32\javaw.exe
2009-08-06 12:13:15 ----A---- C:\windows\system32\java.exe
2009-08-06 12:13:15 ----A---- C:\windows\system32\deploytk.dll
2009-08-06 12:13:08 ----D---- C:\Program Files\Java
2009-08-06 12:09:45 ----D---- C:\Documents and Settings\marco\Application Data\Sun
2009-08-06 11:19:37 ----D---- C:\Program Files\Alcohol Soft
2009-08-06 10:57:26 ----A---- C:\windows\system32\hpzll64X.dll
2009-08-06 10:56:33 ----D---- C:\Program Files\Hewlett-Packard
2009-08-06 10:56:30 ----D---- C:\Program Files\Fichiers communs\Hewlett-Packard
2009-08-06 10:55:54 ----A---- C:\windows\system32\hpzll5ha.dll
2009-08-06 10:55:46 ----A---- C:\windows\system32\hpzids01.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hppldcoi.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hpowiax3.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hpovst10.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hpotscl3.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\difxapi.dll
2009-08-06 10:55:42 ----D---- C:\Program Files\HP
2009-08-06 10:50:47 ----SHD---- C:\RECYCLER
2009-08-06 10:13:36 ----A---- C:\windows\sttray.exe
2009-08-06 10:12:42 ----D---- C:\Program Files\Intel
2009-08-06 10:12:38 ----D---- C:\Intel
2009-08-06 10:12:07 ----D---- C:\Program Files\On-line Help Console
2009-08-06 10:12:06 ----HD---- C:\Program Files\InstallShield Installation Information
2009-08-06 10:11:53 ----D---- C:\windows\system32\Tools
2009-08-06 10:11:48 ----D---- C:\Program Files\Fichiers communs\InstallShield
2009-08-06 09:47:19 ----D---- C:\Program Files\ma-config.com
2009-08-06 09:41:56 ----D---- C:\Documents and Settings\marco\Application Data\Google
2009-08-06 09:41:24 ----D---- C:\Program Files\Google
2009-08-06 09:38:51 ----D---- C:\Program Files\Orange
2009-08-06 09:30:51 ----D---- C:\windows\pss
2009-08-05 22:49:22 ----D---- C:\Documents and Settings\marco\Application Data\Media Player Classic
2009-08-05 22:44:56 ----D---- C:\Program Files\SpeedFan
2009-08-05 22:44:19 ----A---- C:\windows\system32\unrar.dll
2009-08-05 22:44:19 ----A---- C:\windows\avisplitter.ini
2009-08-05 22:44:18 ----A---- C:\windows\system32\yv12vfw.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\xvidvfw.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\xvidcore.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\qt-dx331.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\dpl100.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\divx.dll
2009-08-05 22:44:17 ----A---- C:\windows\system32\ff_vfw.dll.manifest
2009-08-05 22:44:17 ----A---- C:\windows\system32\ff_vfw.dll
2009-08-05 22:44:16 ----D---- C:\Program Files\K-Lite Codec Pack
2009-08-05 22:44:16 ----A---- C:\windows\system32\msvcr71.dll
2009-08-05 22:41:37 ----A---- C:\windows\system32\h323log.txt
2009-08-05 22:41:03 ----D---- C:\Program Files\IDT
2009-08-05 22:41:03 ----A---- C:\windows\system32\stlang.dll
2009-08-05 22:41:03 ----A---- C:\windows\system32\stacsv.exe
2009-08-05 22:40:58 ----A---- C:\windows\system32\ksuser.dll
2009-08-05 22:40:49 ----A---- C:\windows\system32\hidserv.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrszht.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrszhc.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrstr.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrsth.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrssv.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrssl.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrssk.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrsru.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrsptb.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrspt.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrspl.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrszht.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrszhc.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrstr.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrsth.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrssv.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrssl.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrssk.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrsru.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrsptb.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrspt.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsno.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsnl.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsko.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsja.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsit.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrshu.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrshe.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsfr.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsfi.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsesm.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrses.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrseng.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsel.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsde.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsda.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrspl.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsno.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsnl.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsko.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsja.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsit.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrshu.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrshe.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsfr.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsfi.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsesm.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrses.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrseng.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsel.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsde.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsda.dll
2009-08-05 22:39:53 ----D---- C:\windows\nview
2009-08-05 22:39:53 ----A---- C:\windows\system32\nwiz.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwrscs.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwrsar.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwimg.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwdmcpl.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvuninst.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvudisp.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvshell.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvrscs.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvrsar.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvmccsrs.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nview.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvdspsch.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvcpluir.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvcplui.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvcolor.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvappbar.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\keystone.exe
2009-08-05 22:39:24 ----A---- C:\windows\system32\usbui.dll
2009-08-05 22:37:17 ----A---- C:\windows\imsins.BAK
2009-08-05 22:37:15 ----A---- C:\windows\system32\PerfStringBackup.INI
2009-08-05 22:37:14 ----SHD---- C:\windows\Installer
2009-08-05 22:37:14 ----RD---- C:\Program Files
2009-08-05 22:37:14 ----D---- C:\Program Files\Fichiers communs\ODBC
2009-08-05 22:37:14 ----D---- C:\Program Files\Fichiers communs
2009-08-05 22:37:14 ----A---- C:\windows\ODBCINST.INI
2009-08-05 22:37:08 ----A---- C:\windows\system32\spxcoins.dll
2009-08-05 22:37:08 ----A---- C:\windows\system32\irclass.dll
2009-08-05 22:37:08 ----A---- C:\windows\system32\dgsetup.dll
2009-08-05 22:37:08 ----A---- C:\windows\system32\dgrpsetu.dll
2009-08-05 22:37:07 ----A---- C:\windows\system32\EqnClass.Dll
2009-08-05 22:37:06 ----N---- C:\windows\system32\CONFIG.TMP
2009-08-05 22:37:06 ----A---- C:\windows\TASKMAN.EXE
2009-08-05 22:37:06 ----A---- C:\windows\system32\batt.dll
2009-08-05 22:37:05 ----A---- C:\windows\system32\storprop.dll
2009-08-05 22:37:05 ----A---- C:\windows\NOTEPAD.EXE
2009-08-05 22:36:56 ----RA---- C:\windows\SET8.tmp
2009-08-05 22:36:54 ----RA---- C:\windows\SET4.tmp
2009-08-05 22:36:52 ----RA---- C:\windows\SET3.tmp
2009-08-05 22:36:48 ----D---- C:\windows\system32\CatRoot2
2009-08-05 22:36:48 ----D---- C:\windows\system32\CatRoot
2009-08-05 22:36:30 ----A---- C:\windows\setuplog.txt
2009-08-05 22:35:55 ----A---- C:\windows\system32\staco.dll
2009-08-05 22:35:55 ----A---- C:\windows\system32\stacapi.dll
2009-08-05 22:34:45 ----A---- C:\windows\system32\RtNicProp32.dll
2009-08-05 22:34:23 ----D---- C:\Program Files\Avira
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvwssr.dll
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvwss.dll
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvwddi.dll
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvvitvsr.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvvitvs.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvoglnt.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvnt4cpl.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmoblsr.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmobls.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmctray.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmccssr.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmccss.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmccs.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvgamesr.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvgames.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvdispsr.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvdisps.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvcuda.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvsvc32.exe
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvcpl.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvcodins.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvcod.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvapi.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nv4_disp.dll
2009-08-05 22:31:45 ----SHD---- C:\System Volume Information
2009-08-05 22:31:45 ----D---- C:\Documents and Settings
2009-08-05 22:28:08 ----RSHDC---- C:\windows\system32\dllcache
2009-08-05 22:28:08 ----RSD---- C:\windows\Fonts
2009-08-05 22:28:08 ----RD---- C:\windows\Web
2009-08-05 22:28:08 ----HD---- C:\windows\inf
2009-08-05 22:28:08 ----D---- C:\windows\WinSxS
2009-08-05 22:28:08 ----D---- C:\windows\twain_32
2009-08-05 22:28:08 ----D---- C:\windows\Temp
2009-08-05 22:28:08 ----D---- C:\windows\system32\wins
2009-08-05 22:28:08 ----D---- C:\windows\system32\wbem
2009-08-05 22:28:08 ----D---- C:\windows\system32\usmt
2009-08-05 22:28:08 ----D---- C:\windows\system32\spool
2009-08-05 22:28:08 ----D---- C:\windows\system32\ShellExt
2009-08-05 22:28:08 ----D---- C:\windows\system32\Setup
2009-08-05 22:28:08 ----D---- C:\windows\system32\ras
2009-08-05 22:28:08 ----D---- C:\windows\system32\PreInstall
2009-08-05 22:28:08 ----D---- C:\windows\system32\oobe
2009-08-05 22:28:08 ----D---- C:\windows\system32\npp
2009-08-05 22:28:08 ----D---- C:\windows\system32\mui
2009-08-05 22:28:08 ----D---- C:\windows\system32\inetsrv
2009-08-05 22:28:08 ----D---- C:\windows\system32\IME
2009-08-05 22:28:08 ----D---- C:\windows\system32\icsxml
2009-08-05 22:28:08 ----D---- C:\windows\system32\ias
2009-08-05 22:28:08 ----D---- C:\windows\system32\fr-fr
2009-08-05 22:28:08 ----D---- C:\windows\system32\fr
2009-08-05 22:28:08 ----D---- C:\windows\system32\export
2009-08-05 22:28:08 ----D---- C:\windows\system32\drivers
2009-08-05 22:28:08 ----D---- C:\windows\system32\dhcp
2009-08-05 22:28:08 ----D---- C:\windows\system32\config
2009-08-05 22:28:08 ----D---- C:\windows\system32\3com_dmi
2009-08-05 22:28:08 ----D---- C:\windows\system32\3076
2009-08-05 22:28:08 ----D---- C:\windows\system32\2052
2009-08-05 22:28:08 ----D---- C:\windows\system32\1054
2009-08-05 22:28:08 ----D---- C:\windows\system32\1042
2009-08-05 22:28:08 ----D---- C:\windows\system32\1041
2009-08-05 22:28:08 ----D---- C:\windows\system32\1037
2009-08-05 22:28:08 ----D---- C:\windows\system32\1036
2009-08-05 22:28:08 ----D---- C:\windows\system32\1033
2009-08-05 22:28:08 ----D---- C:\windows\system32\1031
2009-08-05 22:28:08 ----D---- C:\windows\system32\1028
2009-08-05 22:28:08 ----D---- C:\windows\system32\1025
2009-08-05 22:28:08 ----D---- C:\windows\system32
2009-08-05 22:28:08 ----D---- C:\windows\system
2009-08-05 22:28:08 ----D---- C:\windows\SoftwareDistribution
2009-08-05 22:28:08 ----D---- C:\windows\security
2009-08-05 22:28:08 ----D---- C:\windows\Resources
2009-08-05 22:28:08 ----D---- C:\windows\repair
2009-08-05 22:28:08 ----D---- C:\windows\Provisioning
2009-08-05 22:28:08 ----D---- C:\windows\PeerNet
2009-08-05 22:28:08 ----D---- C:\windows\pchealth
2009-08-05 22:28:08 ----D---- C:\windows\Network Diagnostic
2009-08-05 22:28:08 ----D---- C:\windows\mui
2009-08-05 22:28:08 ----D---- C:\windows\msapps
2009-08-05 22:28:08 ----D---- C:\windows\msagent
2009-08-05 22:28:08 ----D---- C:\windows\Media
2009-08-05 22:28:08 ----D---- C:\windows\L2Schemas
2009-08-05 22:28:08 ----D---- C:\windows\java
2009-08-05 22:28:08 ----D---- C:\windows\ime
2009-08-05 22:28:08 ----D---- C:\windows\Help
2009-08-05 22:28:08 ----D---- C:\windows\ehome
2009-08-05 22:28:08 ----D---- C:\windows\Driver Cache
2009-08-05 22:28:08 ----D---- C:\windows\Debug
2009-08-05 22:28:08 ----D---- C:\windows\Cursors
2009-08-05 22:28:08 ----D---- C:\windows\Connection Wizard
2009-08-05 22:28:08 ----D---- C:\windows\Config
2009-08-05 22:28:08 ----D---- C:\windows\AppPatch
2009-08-05 22:28:08 ----D---- C:\windows\addins
2009-08-05 22:28:08 ----D---- C:\WINDOWS
2009-08-05 22:26:24 ----D---- C:\Program Files\WinZip
2009-08-05 22:23:38 ----D---- C:\Program Files\WinRAR
2009-08-05 22:07:29 ----HDC---- C:\windows\$NtUninstallWdf01005$
2009-08-05 22:07:20 ----D---- C:\windows\system32\ReinstallBackups
2009-08-05 22:07:17 ----HDC---- C:\windows\$NtUninstallKB973346$
2009-08-05 22:07:14 ----HDC---- C:\windows\$NtUninstallKB961501$
2009-08-05 22:07:11 ----HDC---- C:\windows\$NtUninstallKB971633$
2009-08-05 22:06:59 ----D---- C:\windows\ie8updates
2009-08-05 22:06:56 ----HDC---- C:\windows\$NtUninstallKB970238$
2009-08-05 22:06:53 ----HDC---- C:\windows\$NtUninstallKB968537$
2009-08-05 22:06:47 ----HDC---- C:\windows\$NtUninstallKB961371$
2009-08-05 22:06:47 ----HD---- C:\windows\$hf_mig$
2009-08-05 22:03:08 ----D---- C:\Documents and Settings\marco\Application Data\Macromedia
2009-08-05 22:03:08 ----D---- C:\Documents and Settings\marco\Application Data\Adobe
2009-08-05 22:01:03 ----D---- C:\Documents and Settings\marco\Application Data\Identities
2009-08-05 22:01:01 ----HD---- C:\Program Files\Uninstall Information
2009-08-05 22:00:54 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-08-05 22:00:51 ----ASH---- C:\Documents and Settings\marco\Application Data\desktop.ini
2009-08-05 22:00:50 ----SD---- C:\Documents and Settings\marco\Application Data\Microsoft
2009-08-05 20:53:57 ----D---- C:\windows\Prefetch
2009-08-05 20:53:57 ----A---- C:\windows\SchedLgU.Txt
2009-08-05 20:52:41 ----SD---- C:\windows\system32\Microsoft
2009-08-05 20:52:31 ----A---- C:\windows\system32\spupdsvc.exe
2009-08-05 20:52:31 ----A---- C:\windows\system32\spmsg.dll
2009-08-05 20:52:30 ----HDC---- C:\windows\$NtServicePackUninstallNLSDownlevelMapping$
2009-08-05 20:52:25 ----D---- C:\Program Files\Alky for Applications
2009-08-05 20:52:19 ----D---- C:\Program Files\Microsoft Silverlight
2009-08-05 20:52:13 ----D---- C:\Program Files\Movie Maker 2.6
2009-08-05 20:52:08 ----D---- C:\windows\system32\Macromed
2009-08-05 20:50:52 ----RSD---- C:\windows\assembly
2009-08-05 20:50:42 ----D---- C:\windows\Microsoft.NET
2009-08-05 20:50:13 ----A---- C:\windows\control.ini
2009-08-05 20:50:03 ----A---- C:\windows\OEWABLog.txt
2009-08-05 20:49:47 ----DC---- C:\windows\system32\DRVSTORE
2009-08-05 20:49:37 ----A---- C:\windows\system32\mapi32.dll
2009-08-05 20:48:59 ----RAH---- C:\windows\system32\logonui.exe.manifest
2009-08-05 20:48:56 ----RAH---- C:\windows\system32\cdplayer.exe.manifest
2009-08-05 20:48:52 ----HD---- C:\Program Files\WindowsUpdate
2009-08-05 20:48:48 ----D---- C:\Program Files\Services en ligne
2009-08-05 20:48:40 ----D---- C:\windows\system32\DirectX
2009-08-05 20:48:36 ----A---- C:\windows\system32\atrace.dll
2009-08-05 20:48:35 ----A---- C:\windows\system32\desktop.ini
2009-08-05 20:48:35 ----A---- C:\windows\desktop.ini
2009-08-05 20:48:30 ----A---- C:\windows\system32\acctres.dll
2009-08-05 20:48:29 ----D---- C:\Program Files\Fichiers communs\Services
2009-08-05 20:48:28 ----SD---- C:\windows\Tasks
2009-08-05 20:48:28 ----A---- C:\windows\system32\icfgnt5.dll
2009-08-05 20:48:27 ----D---- C:\Program Files\Fichiers communs\MSSoap
2009-08-05 20:48:24 ----A---- C:\windows\system32\wuweb.dll
2009-08-05 20:48:24 ----A---- C:\windows\system32\wucltui.dll
2009-08-05 20:48:24 ----A---- C:\windows\system32\wuauserv.dll
2009-08-05 20:48:24 ----A---- C:\windows\system32\wuaueng1.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\wups.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuaueng.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuauclt1.exe
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuauclt.exe
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuapi.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\qmgrprxy.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\qmgr.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\bitsprx4.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\bitsprx3.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\bitsprx2.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\safrslv.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\safrdm.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\safrcdlg.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\racpldlg.dll
2009-08-05 20:48:08 ----A---- C:\windows\system32\fltMc.exe
2009-08-05 20:48:08 ----A---- C:\windows\system32\fltlib.dll
2009-08-05 20:48:07 ----D---- C:\windows\system32\Restore
2009-08-05 20:48:07 ----A---- C:\windows\system32\srsvc.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\srrstr.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\srclient.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\msoert2.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\msoeacct.dll
2009-08-05 20:48:06 ----A---- C:\windows\system32\inetres.dll
2009-08-05 20:48:06 ----A---- C:\windows\system32\inetcomm.dll
2009-08-05 20:48:05 ----D---- C:\Program Files\Outlook Express
2009-08-05 20:48:05 ----A---- C:\windows\system32\schedsvc.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\mstinit.exe
2009-08-05 20:48:04 ----A---- C:\windows\system32\mstask.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\isign32.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\inetcfg.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\icwphbk.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\icwdial.dll
2009-08-05 20:48:00 ----D---- C:\Program Files\Fichiers communs\System
2009-08-05 20:47:22 ----D---- C:\Program Files\ComPlus Applications
2009-08-05 20:47:20 ----A---- C:\windows\vbaddin.ini
2009-08-05 20:47:20 ----A---- C:\windows\vb.ini
2009-08-05 20:47:16 ----D---- C:\windows\Registration
2009-08-05 20:46:34 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-08-05 20:46:16 ----D---- C:\Program Files\Windows Live
2009-08-05 20:46:11 ----SD---- C:\windows\Downloaded Program Files
2009-08-05 20:46:11 ----RD---- C:\windows\Offline Web Pages
2009-08-05 20:46:07 ----D---- C:\Program Files\Internet Explorer
2009-08-05 20:43:30 ----D---- C:\Program Files\Windows Sidebar
2009-08-05 20:43:25 ----D---- C:\Program Files\VistaExperience.org
2009-08-05 20:43:18 ----D---- C:\Program Files\Windows Media Player
2009-08-05 20:43:18 ----D---- C:\Program Files\Windows Media Connect 2
2009-08-05 20:43:13 ----A---- C:\windows\system32\usrlogon.cmd
2009-08-05 20:43:13 ----A---- C:\windows\system32\tsshutdn.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\tslabels.ini
2009-08-05 20:43:13 ----A---- C:\windows\system32\tskill.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\tsdiscon.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\tscon.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\reset.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\shadow.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\rwinsta.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\regini.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\rdpcfgex.dll
2009-08-05 20:43:12 ----A---- C:\windows\system32\qwinsta.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\qappsrv.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\msg.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\msdtcprf.ini
2009-08-05 20:43:12 ----A---- C:\windows\system32\logoff.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\cdmodem.dll
2009-08-05 20:43:08 ----A---- C:\windows\system32\wmimgmt.msc
2009-08-05 20:43:07 ----D---- C:\Program Files\Windows NT
2009-08-05 20:43:06 ----A---- C:\windows\system32\tsgqec.dll
2009-08-05 20:43:06 ----A---- C:\windows\system32\tscfgwmi.dll
2009-08-05 20:43:06 ----A---- C:\windows\system32\rhttpaa.dll
2009-08-05 20:43:06 ----A---- C:\windows\system32\aaclient.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\sessmgr.exe
2009-08-05 20:43:05 ----A---- C:\windows\system32\remotepg.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\rdshost.exe
2009-08-05 20:43:05 ----A---- C:\windows\system32\rdsaddin.exe
2009-08-05 20:43:05 ----A---- C:\windows\system32\rdchost.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\mstscax.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\mstsc.exe
2009-08-05 20:43:04 ----D---- C:\windows\system32\MsDtc
2009-08-05 20:43:04 ----A---- C:\windows\system32\termsrv.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\rdpwsx.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\rdpsnd.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\rdpclip.exe
2009-08-05 20:43:04 ----A---- C:\windows\system32\qprocess.exe
2009-08-05 20:43:04 ----A---- C:\windows\system32\mtxoci.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\msdtcuiu.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\icaapi.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\cfgbkend.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\xolehlp.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtctm.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtcprx.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtclog.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtc.exe
2009-08-05 20:43:02 ----D---- C:\windows\system32\Com
2009-08-05 20:43:02 ----A---- C:\windows\system32\stclient.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\mtxlegih.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\mtxex.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\mtxdm.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\dcomcnfg.exe
2009-08-05 20:43:02 ----A---- C:\windows\system32\comrepl.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\comaddin.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\colbact.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\clbcatex.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\catsrvps.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\comuid.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\comsvcs.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\comsnap.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\clbcatq.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\catsrvut.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\catsrv.dll
2009-08-05 20:42:57 ----A---- C:\windows\system32\servdeps.dll
2009-08-05 20:42:56 ----A---- C:\windows\system32\mmfutil.dll
2009-08-05 20:42:56 ----A---- C:\windows\system32\licwmi.dll
2009-08-05 20:42:56 ----A---- C:\windows\system32\cmprops.dll
======List of files/folders modified in the last 1 months======
2009-08-19 04:56:35 ----A---- C:\windows\win.ini
2009-08-19 04:56:35 ----A---- C:\windows\system.ini
2009-08-05 11:00:38 ----A---- C:\windows\system32\mswebdvd.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Pilote de processeur Intel; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 ssmdrv;ssmdrv; C:\windows\system32\DRIVERS\ssmdrv.sys [2009-08-05 28520]
R2 avgntflt;avgntflt; C:\windows\system32\DRIVERS\avgntflt.sys [2009-08-18 55656]
R2 rspndr;Répondeur de découverte de topologie de la couche de liaison; C:\windows\system32\DRIVERS\rspndr.sys [2008-05-29 62848]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Pilote de classe HID Microsoft; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\windows\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\windows\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\windows\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
R3 mouhid;Pilote HID de souris; C:\windows\system32\DRIVERS\mouhid.sys [2008-04-14 12288]
R3 NuidFltr;NUID filter driver; C:\windows\system32\DRIVERS\NuidFltr.sys [2009-05-09 14736]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\windows\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\windows\system32\drivers\sthda.sys [2007-05-06 1222840]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-24 30336]
R3 usbhub;Concentrateur USB2; C:\windows\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Classe d'imprimantes USB Microsoft; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Pilote de scanneur USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\windows\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Wdf01000; C:\windows\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 a4gsvfg2;a4gsvfg2; C:\windows\system32\drivers\a4gsvfg2.sys []
S3 cpuz132;cpuz132; \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys []
S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\windows\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 nmwcdc;Nokia USB Generic; C:\windows\system32\drivers\ccdcmbo.sys [2008-05-02 20864]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2008-05-02 8064]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-02 8064]
S3 USBSTOR;Pilote de stockage de masse USB; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\windows\system32\DRIVERS\WudfPf.sys [2009-03-27 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2009-03-27 82944]
S4 exFat;exFat; C:\windows\system32\drivers\exFat.sys [2008-09-29 133632]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-08-05 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-18 185089]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-08-06 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service;
Re,
Désinstalle :
* Ask Toolbar
Tu connais Target Web ADS ?
Télécharge OTM3 (de OldTimer). Sauvegarde-le sur ton Bureau.
Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :
:processes
|
Double clique sur OTM.exe afin de le lancer.
Colle (ou Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
Clique maintenant sur le bouton MoveIt! puis ferme OTM3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
Répondre à Angeldark
je ne sais pas supprimer ask toolbar je l'ai juste supprimé de ma barre d'outil par contre j'ai pus effectuer tout ce que tu ma demandé apres le reboot un rapport est apparu le voici
========== PROCESSES ==========
No active process named explorer.exe was found!
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}\ deleted successfully.
========== FILES ==========
C:\Program Files\AskBarDis\bar\Settings moved successfully.
C:\Program Files\AskBarDis\bar\History moved successfully.
C:\Program Files\AskBarDis\bar\Cache moved successfully.
C:\Program Files\AskBarDis\bar\bin moved successfully.
C:\Program Files\AskBarDis\bar moved successfully.
C:\Program Files\AskBarDis moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33172 bytes
User: marco
->Temp folder emptied: 1998949 bytes
->Temporary Internet Files folder emptied: 29223134 bytes
->Java cache emptied: 13489439 bytes
->FireFox cache emptied: 38806747 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
C:\windows\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 2352838 bytes
%systemroot%\System32 .tmp files removed: 3072 bytes
Windows Temp folder emptied: 2905273 bytes
RecycleBin emptied: 705897726 bytes
Total Files Cleaned = 757,96 mb
OTM by OldTimer - Version 3.0.0.6 log created on 08232009_144544
Files moved on Reboot...
Registry entries deleted on Reboot...
j'attend la suite merci
Refais un scan RSIT (je veux juste la partie log.txt).
Répondre à Angeldark
Logfile of random's system information tool 1.06 (written by random/random)
Run by marco at 2009-08-24 19:32:56
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 215 GB (45%) free of 477 GB
Total RAM: 2047 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:33:04, on 24/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\windows\System32\svchost.exe
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\windows\system32\svchost.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\windows\sttray.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\windows\system32\ctfmon.exe
C:\Documents and Settings\marco\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\windows\system32\wscntfy.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Target Web ADS\TargetWebADSh.exe
c:\program files\avira\antivir desktop\avcenter.exe
C:\Program Files\Avira\AntiVir Desktop\update.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\marco\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\marco.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tropal.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: TargetWebADS module - {8152A0B9-DEB6-476e-BC67-175B19080A8A} - C:\Program Files\Target Web ADS\TargetWebADS.dll
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [HBlock] C:\Program Files\Target Web ADS\TargetWebADSh.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\DOCUME~1\marco\LOCALS~1\Temp\cce9F4.html
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\marco\LOCALS~1\Temp\cce9F2.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\marco\LOCALS~1\Temp\cce9F3.html
O9 - Extra button: (no name) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Audio Service (STacSV) - Unknown owner - c:\d\s\zi\STacSV.exe (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 9632 bytes
======Scheduled tasks folder======
C:\windows\tasks\Ad-Aware Update (Weekly).job
C:\windows\tasks\User_Feed_Synchronization-{6E6AA75D-281F-449D-B637-23582B1F7208}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8152A0B9-DEB6-476e-BC67-175B19080A8A}]
TargetWebADS Class - C:\Program Files\Target Web ADS\TargetWebADS.dll [2009-08-15 207364]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-06 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-08-06 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-08-16 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-06 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-08-06 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
Locked
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-06 256112]
{D3028143-6145-4318-99D3-3EDCE54A95A9} - barre d'outils Orange - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll [2009-07-02 2268464]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\windows\system32\ctfmon.exe [2008-04-14 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"HBlock"=C:\Program Files\Target Web ADS\TargetWebADSh.exe [2009-08-15 136708]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-08-15 520024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EADM\Core.exe [2008-07-22 2772992]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-08-16 122368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HBlock]
C:\Program Files\Target Web ADS\TargetWebADSh.exe [2009-08-15 136708]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe [2006-08-17 249856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
C:\windows\sttray.exe [2007-05-06 405504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-08-06 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-08-06 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2009-08-09 288048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
C:\PROGRA~1\WinZip\WZQKPICK.EXE [2006-07-10 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\windows\system32\WgaLogon.dll [2009-03-10 239496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2009-03-27 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"legalnoticecaption"=
"legalnoticetext"=
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"ForceClassicControlPanel"=1
"NoSMHelp"=1
"NoSMConfigurePrograms"=1
"NoStartMenuPinnedList"=0
"NoResolveTrack"=1
"NoResolveSearch"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ma-config.com\maconfservice.exe"="C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44d4a76c-826a-11de-a234-0019213c879e}]
shell\AutoRun\command - F:\SETUP.EXE
shell\configure\command - F:\SETUP.EXE
shell\install\command - F:\SETUP.EXE
======File associations======
.scr - config - "%1" /S
======List of files/folders created in the last 1 months======
2009-08-23 23:19:43 ----D---- C:\Documents and Settings\marco\Application Data\Yahoo!
2009-08-23 23:19:43 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2009-08-23 23:19:42 ----D---- C:\Program Files\Yahoo!
2009-08-23 23:19:40 ----D---- C:\Program Files\CCleaner
2009-08-23 14:45:44 ----D---- C:\_OTM
2009-08-23 14:27:48 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-08-23 14:26:20 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-08-22 22:39:18 ----D---- C:\windows\WBEM
2009-08-22 19:55:47 ----D---- C:\rsit
2009-08-22 15:04:17 ----D---- C:\Program Files\Trend Micro
2009-08-22 11:06:22 ----D---- C:\Program Files\Panda Security
2009-08-22 10:13:26 ----D---- C:\windows\BDOSCAN8
2009-08-21 17:50:00 ----D---- C:\Temp
2009-08-21 17:49:12 ----A---- C:\windows\lgfwup.ini
2009-08-21 17:49:09 ----A---- C:\windows\system32\Vb6stkit.dll
2009-08-21 17:49:09 ----A---- C:\windows\system32\VB6KO.DLL
2009-08-21 17:49:09 ----A---- C:\windows\system32\lgfwunis.exe
2009-08-21 17:49:08 ----D---- C:\Program Files\lg_fwupdate
2009-08-21 17:46:50 ----D---- C:\Program Files\CyberLink
2009-08-18 22:12:42 ----HDC---- C:\windows\$NtUninstallKB968389$
2009-08-18 21:35:33 ----D---- C:\windows\Sun
2009-08-17 11:22:02 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-08-17 11:22:02 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-08-17 11:22:02 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-08-16 14:37:19 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft(2)
2009-08-16 13:58:29 ----D---- C:\Program Files\SigmaTel
2009-08-15 21:38:50 ----HDC---- C:\windows\$NtUninstallKB967715$
2009-08-15 13:24:41 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-08-15 12:17:19 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-08-15 12:17:19 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-15 12:14:28 ----A---- C:\windows\system32\lsdelete.exe
2009-08-15 11:19:31 ----HDC---- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-08-15 11:19:29 ----D---- C:\Program Files\Lavasoft
2009-08-15 09:36:15 ----D---- C:\Program Files\Target Web ADS
2009-08-14 19:11:08 ----D---- C:\Program Files\Fichiers communs\Borland Shared
2009-08-14 19:11:02 ----D---- C:\Program Files\Pomo
2009-08-14 19:10:17 ----A---- C:\windows\system32\dunzip32.dll
2009-08-13 00:26:27 ----HDC---- C:\windows\$NtUninstallKB960859$
2009-08-13 00:26:24 ----HDC---- C:\windows\$NtUninstallKB971657$
2009-08-13 00:26:21 ----HDC---- C:\windows\$NtUninstallKB971557$
2009-08-13 00:26:18 ----HDC---- C:\windows\$NtUninstallKB956744$
2009-08-13 00:26:15 ----HDC---- C:\windows\$NtUninstallKB973869$
2009-08-13 00:26:01 ----HDC---- C:\windows\$NtUninstallKB973507$
2009-08-13 00:25:58 ----HDC---- C:\windows\$NtUninstallKB973354$
2009-08-13 00:25:56 ----A---- C:\windows\system32\wmpns.dll
2009-08-13 00:25:52 ----HDC---- C:\windows\$NtUninstallKB973540_WM9$
2009-08-13 00:25:11 ----HDC---- C:\windows\$NtUninstallKB973815$
2009-08-12 19:44:46 ----D---- C:\Program Files\NOS
2009-08-12 19:44:46 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-08-10 15:20:37 ----D---- C:\Program Files\MDIviewer
2009-08-10 15:20:37 ----A---- C:\windows\system32\MSPGIMME.DLL
2009-08-10 15:20:37 ----A---- C:\windows\system32\MSPCORE.DLL
2009-08-10 15:20:37 ----A---- C:\windows\system32\MDIVWCTL.DLL
2009-08-10 15:20:37 ----A---- C:\windows\system32\GDIPLUS.DLL
2009-08-10 01:47:10 ----A---- C:\windows\NeroDigital.ini
2009-08-09 10:57:08 ----D---- C:\Program Files\Mozilla Firefox
2009-08-09 10:57:08 ----D---- C:\Documents and Settings\marco\Application Data\Mozilla
2009-08-09 10:56:53 ----D---- C:\Program Files\uTorrent
2009-08-09 10:56:25 ----D---- C:\Documents and Settings\marco\Application Data\uTorrent
2009-08-08 22:40:41 ----D---- C:\Program Files\Fichiers communs\Adobe
2009-08-08 22:40:41 ----D---- C:\Program Files\Adobe
2009-08-08 20:41:43 ----D---- C:\Documents and Settings\marco\Application Data\Nero
2009-08-08 20:41:34 ----A---- C:\windows\system32\MsiExec.exe.log
2009-08-08 20:40:35 ----D---- C:\Program Files\Nero
2009-08-08 20:40:35 ----D---- C:\Program Files\Fichiers communs\Nero
2009-08-08 20:40:35 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2009-08-07 21:31:50 ----A---- C:\windows\system32\MRT.exe
2009-08-07 20:24:34 ----D---- C:\Program Files\HD Tune
2009-08-07 19:45:17 ----D---- C:\Program Files\CPUID
2009-08-06 16:29:40 ----D---- C:\Program Files\Microsoft Works
2009-08-06 16:29:35 ----D---- C:\Program Files\MSBuild
2009-08-06 16:29:29 ----D---- C:\Program Files\Microsoft Visual Studio
2009-08-06 16:29:29 ----D---- C:\Program Files\Fichiers communs\DESIGNER
2009-08-06 16:29:08 ----D---- C:\Program Files\Microsoft.NET
2009-08-06 16:27:44 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-08-06 16:27:24 ----D---- C:\windows\SHELLNEW
2009-08-06 16:27:08 ----D---- C:\Program Files\Microsoft Office
2009-08-06 16:26:53 ----RHD---- C:\MSOCache
2009-08-06 12:36:37 ----A---- C:\windows\system32\PnkBstrA.exe
2009-08-06 12:36:14 ----A---- C:\windows\system32\PnkBstrB.exe
2009-08-06 12:33:19 ----D---- C:\Program Files\Electronic Arts
2009-08-06 12:33:18 ----D---- C:\ProgramData
2009-08-06 12:32:58 ----D---- C:\Documents and Settings\marco\Application Data\Leadertech
2009-08-06 12:28:34 ----D---- C:\windows\system32\LogFiles
2009-08-06 12:24:02 ----D---- C:\Program Files\EA Games
2009-08-06 12:13:43 ----D---- C:\Documents and Settings\marco\Application Data\Azureus
2009-08-06 12:13:15 ----A---- C:\windows\system32\javaws.exe
2009-08-06 12:13:15 ----A---- C:\windows\system32\javaw.exe
2009-08-06 12:13:15 ----A---- C:\windows\system32\java.exe
2009-08-06 12:13:15 ----A---- C:\windows\system32\deploytk.dll
2009-08-06 12:13:08 ----D---- C:\Program Files\Java
2009-08-06 12:09:45 ----D---- C:\Documents and Settings\marco\Application Data\Sun
2009-08-06 11:19:37 ----D---- C:\Program Files\Alcohol Soft
2009-08-06 10:57:26 ----A---- C:\windows\system32\hpzll64X.dll
2009-08-06 10:56:33 ----D---- C:\Program Files\Hewlett-Packard
2009-08-06 10:56:30 ----D---- C:\Program Files\Fichiers communs\Hewlett-Packard
2009-08-06 10:55:54 ----A---- C:\windows\system32\hpzll5ha.dll
2009-08-06 10:55:46 ----A---- C:\windows\system32\hpzids01.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hppldcoi.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hpowiax3.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hpovst10.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\hpotscl3.dll
2009-08-06 10:55:45 ----A---- C:\windows\system32\difxapi.dll
2009-08-06 10:55:42 ----D---- C:\Program Files\HP
2009-08-06 10:50:47 ----SHD---- C:\RECYCLER
2009-08-06 10:13:36 ----A---- C:\windows\sttray.exe
2009-08-06 10:12:42 ----D---- C:\Program Files\Intel
2009-08-06 10:12:38 ----D---- C:\Intel
2009-08-06 10:12:07 ----D---- C:\Program Files\On-line Help Console
2009-08-06 10:12:06 ----HD---- C:\Program Files\InstallShield Installation Information
2009-08-06 10:11:53 ----D---- C:\windows\system32\Tools
2009-08-06 10:11:48 ----D---- C:\Program Files\Fichiers communs\InstallShield
2009-08-06 09:47:19 ----D---- C:\Program Files\ma-config.com
2009-08-06 09:41:56 ----D---- C:\Documents and Settings\marco\Application Data\Google
2009-08-06 09:41:24 ----D---- C:\Program Files\Google
2009-08-06 09:38:51 ----D---- C:\Program Files\Orange
2009-08-06 09:30:51 ----D---- C:\windows\pss
2009-08-05 22:49:22 ----D---- C:\Documents and Settings\marco\Application Data\Media Player Classic
2009-08-05 22:44:56 ----D---- C:\Program Files\SpeedFan
2009-08-05 22:44:19 ----A---- C:\windows\system32\unrar.dll
2009-08-05 22:44:19 ----A---- C:\windows\avisplitter.ini
2009-08-05 22:44:18 ----A---- C:\windows\system32\yv12vfw.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\xvidvfw.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\xvidcore.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\qt-dx331.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\dpl100.dll
2009-08-05 22:44:18 ----A---- C:\windows\system32\divx.dll
2009-08-05 22:44:17 ----A---- C:\windows\system32\ff_vfw.dll.manifest
2009-08-05 22:44:17 ----A---- C:\windows\system32\ff_vfw.dll
2009-08-05 22:44:16 ----D---- C:\Program Files\K-Lite Codec Pack
2009-08-05 22:44:16 ----A---- C:\windows\system32\msvcr71.dll
2009-08-05 22:41:37 ----A---- C:\windows\system32\h323log.txt
2009-08-05 22:41:03 ----D---- C:\Program Files\IDT
2009-08-05 22:41:03 ----A---- C:\windows\system32\stlang.dll
2009-08-05 22:41:03 ----A---- C:\windows\system32\stacsv.exe
2009-08-05 22:40:58 ----A---- C:\windows\system32\ksuser.dll
2009-08-05 22:40:49 ----A---- C:\windows\system32\hidserv.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrszht.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrszhc.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrstr.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrsth.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrssv.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrssl.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrssk.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrsru.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrsptb.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrspt.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvwrspl.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrszht.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrszhc.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrstr.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrsth.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrssv.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrssl.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrssk.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrsru.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrsptb.dll
2009-08-05 22:39:55 ----A---- C:\windows\system32\nvrspt.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsno.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsnl.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsko.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsja.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsit.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrshu.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrshe.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsfr.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsfi.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsesm.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrses.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrseng.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsel.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsde.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvwrsda.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrspl.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsno.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsnl.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsko.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsja.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsit.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrshu.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrshe.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsfr.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsfi.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsesm.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrses.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrseng.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsel.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsde.dll
2009-08-05 22:39:54 ----A---- C:\windows\system32\nvrsda.dll
2009-08-05 22:39:53 ----D---- C:\windows\nview
2009-08-05 22:39:53 ----A---- C:\windows\system32\nwiz.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwrscs.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwrsar.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwimg.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvwdmcpl.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvuninst.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvudisp.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvshell.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvrscs.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvrsar.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvmccsrs.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nview.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvdspsch.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvcpluir.dll
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvcplui.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvcolor.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\nvappbar.exe
2009-08-05 22:39:53 ----A---- C:\windows\system32\keystone.exe
2009-08-05 22:39:24 ----A---- C:\windows\system32\usbui.dll
2009-08-05 22:37:15 ----A---- C:\windows\system32\PerfStringBackup.INI
2009-08-05 22:37:14 ----SHD---- C:\windows\Installer
2009-08-05 22:37:14 ----RD---- C:\Program Files
2009-08-05 22:37:14 ----D---- C:\Program Files\Fichiers communs\ODBC
2009-08-05 22:37:14 ----D---- C:\Program Files\Fichiers communs
2009-08-05 22:37:14 ----A---- C:\windows\ODBCINST.INI
2009-08-05 22:37:08 ----A---- C:\windows\system32\spxcoins.dll
2009-08-05 22:37:08 ----A---- C:\windows\system32\irclass.dll
2009-08-05 22:37:08 ----A---- C:\windows\system32\dgsetup.dll
2009-08-05 22:37:08 ----A---- C:\windows\system32\dgrpsetu.dll
2009-08-05 22:37:07 ----A---- C:\windows\system32\EqnClass.Dll
2009-08-05 22:37:06 ----A---- C:\windows\TASKMAN.EXE
2009-08-05 22:37:06 ----A---- C:\windows\system32\batt.dll
2009-08-05 22:37:05 ----A---- C:\windows\system32\storprop.dll
2009-08-05 22:37:05 ----A---- C:\windows\NOTEPAD.EXE
2009-08-05 22:36:48 ----D---- C:\windows\system32\CatRoot2
2009-08-05 22:36:48 ----D---- C:\windows\system32\CatRoot
2009-08-05 22:35:55 ----A---- C:\windows\system32\staco.dll
2009-08-05 22:35:55 ----A---- C:\windows\system32\stacapi.dll
2009-08-05 22:34:45 ----A---- C:\windows\system32\RtNicProp32.dll
2009-08-05 22:34:23 ----D---- C:\Program Files\Avira
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvwssr.dll
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvwss.dll
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvwddi.dll
2009-08-05 22:32:31 ----A---- C:\windows\system32\nvvitvsr.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvvitvs.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvoglnt.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvnt4cpl.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmoblsr.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmobls.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmctray.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmccssr.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmccss.dll
2009-08-05 22:32:30 ----A---- C:\windows\system32\nvmccs.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvgamesr.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvgames.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvdispsr.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvdisps.dll
2009-08-05 22:32:29 ----A---- C:\windows\system32\nvcuda.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvsvc32.exe
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvcpl.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvcodins.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvcod.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nvapi.dll
2009-08-05 22:32:28 ----A---- C:\windows\system32\nv4_disp.dll
2009-08-05 22:31:45 ----SHD---- C:\System Volume Information
2009-08-05 22:31:45 ----D---- C:\Documents and Settings
2009-08-05 22:28:08 ----RSHDC---- C:\windows\system32\dllcache
2009-08-05 22:28:08 ----RSD---- C:\windows\Fonts
2009-08-05 22:28:08 ----RD---- C:\windows\Web
2009-08-05 22:28:08 ----HD---- C:\windows\inf
2009-08-05 22:28:08 ----D---- C:\windows\WinSxS
2009-08-05 22:28:08 ----D---- C:\windows\twain_32
2009-08-05 22:28:08 ----D---- C:\windows\Temp
2009-08-05 22:28:08 ----D---- C:\windows\system32\wins
2009-08-05 22:28:08 ----D---- C:\windows\system32\wbem
2009-08-05 22:28:08 ----D---- C:\windows\system32\usmt
2009-08-05 22:28:08 ----D---- C:\windows\system32\spool
2009-08-05 22:28:08 ----D---- C:\windows\system32\ShellExt
2009-08-05 22:28:08 ----D---- C:\windows\system32\Setup
2009-08-05 22:28:08 ----D---- C:\windows\system32\ras
2009-08-05 22:28:08 ----D---- C:\windows\system32\PreInstall
2009-08-05 22:28:08 ----D---- C:\windows\system32\oobe
2009-08-05 22:28:08 ----D---- C:\windows\system32\npp
2009-08-05 22:28:08 ----D---- C:\windows\system32\mui
2009-08-05 22:28:08 ----D---- C:\windows\system32\inetsrv
2009-08-05 22:28:08 ----D---- C:\windows\system32\IME
2009-08-05 22:28:08 ----D---- C:\windows\system32\icsxml
2009-08-05 22:28:08 ----D---- C:\windows\system32\ias
2009-08-05 22:28:08 ----D---- C:\windows\system32\fr-fr
2009-08-05 22:28:08 ----D---- C:\windows\system32\fr
2009-08-05 22:28:08 ----D---- C:\windows\system32\export
2009-08-05 22:28:08 ----D---- C:\windows\system32\drivers
2009-08-05 22:28:08 ----D---- C:\windows\system32\dhcp
2009-08-05 22:28:08 ----D---- C:\windows\system32\config
2009-08-05 22:28:08 ----D---- C:\windows\system32\3com_dmi
2009-08-05 22:28:08 ----D---- C:\windows\system32\3076
2009-08-05 22:28:08 ----D---- C:\windows\system32\2052
2009-08-05 22:28:08 ----D---- C:\windows\system32\1054
2009-08-05 22:28:08 ----D---- C:\windows\system32\1042
2009-08-05 22:28:08 ----D---- C:\windows\system32\1041
2009-08-05 22:28:08 ----D---- C:\windows\system32\1037
2009-08-05 22:28:08 ----D---- C:\windows\system32\1036
2009-08-05 22:28:08 ----D---- C:\windows\system32\1033
2009-08-05 22:28:08 ----D---- C:\windows\system32\1031
2009-08-05 22:28:08 ----D---- C:\windows\system32\1028
2009-08-05 22:28:08 ----D---- C:\windows\system32\1025
2009-08-05 22:28:08 ----D---- C:\windows\system32
2009-08-05 22:28:08 ----D---- C:\windows\system
2009-08-05 22:28:08 ----D---- C:\windows\SoftwareDistribution
2009-08-05 22:28:08 ----D---- C:\windows\security
2009-08-05 22:28:08 ----D---- C:\windows\Resources
2009-08-05 22:28:08 ----D---- C:\windows\repair
2009-08-05 22:28:08 ----D---- C:\windows\Provisioning
2009-08-05 22:28:08 ----D---- C:\windows\PeerNet
2009-08-05 22:28:08 ----D---- C:\windows\pchealth
2009-08-05 22:28:08 ----D---- C:\windows\Network Diagnostic
2009-08-05 22:28:08 ----D---- C:\windows\mui
2009-08-05 22:28:08 ----D---- C:\windows\msapps
2009-08-05 22:28:08 ----D---- C:\windows\msagent
2009-08-05 22:28:08 ----D---- C:\windows\Media
2009-08-05 22:28:08 ----D---- C:\windows\L2Schemas
2009-08-05 22:28:08 ----D---- C:\windows\java
2009-08-05 22:28:08 ----D---- C:\windows\ime
2009-08-05 22:28:08 ----D---- C:\windows\Help
2009-08-05 22:28:08 ----D---- C:\windows\ehome
2009-08-05 22:28:08 ----D---- C:\windows\Driver Cache
2009-08-05 22:28:08 ----D---- C:\windows\Debug
2009-08-05 22:28:08 ----D---- C:\windows\Cursors
2009-08-05 22:28:08 ----D---- C:\windows\Connection Wizard
2009-08-05 22:28:08 ----D---- C:\windows\Config
2009-08-05 22:28:08 ----D---- C:\windows\AppPatch
2009-08-05 22:28:08 ----D---- C:\windows\addins
2009-08-05 22:28:08 ----D---- C:\WINDOWS
2009-08-05 22:26:24 ----D---- C:\Program Files\WinZip
2009-08-05 22:23:38 ----D---- C:\Program Files\WinRAR
2009-08-05 22:07:29 ----HDC---- C:\windows\$NtUninstallWdf01005$
2009-08-05 22:07:20 ----D---- C:\windows\system32\ReinstallBackups
2009-08-05 22:07:17 ----HDC---- C:\windows\$NtUninstallKB973346$
2009-08-05 22:07:14 ----HDC---- C:\windows\$NtUninstallKB961501$
2009-08-05 22:07:11 ----HDC---- C:\windows\$NtUninstallKB971633$
2009-08-05 22:06:59 ----D---- C:\windows\ie8updates
2009-08-05 22:06:56 ----HDC---- C:\windows\$NtUninstallKB970238$
2009-08-05 22:06:53 ----HDC---- C:\windows\$NtUninstallKB968537$
2009-08-05 22:06:47 ----HDC---- C:\windows\$NtUninstallKB961371$
2009-08-05 22:06:47 ----HD---- C:\windows\$hf_mig$
2009-08-05 22:03:08 ----D---- C:\Documents and Settings\marco\Application Data\Macromedia
2009-08-05 22:03:08 ----D---- C:\Documents and Settings\marco\Application Data\Adobe
2009-08-05 22:01:03 ----D---- C:\Documents and Settings\marco\Application Data\Identities
2009-08-05 22:01:01 ----HD---- C:\Program Files\Uninstall Information
2009-08-05 22:00:54 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-08-05 22:00:51 ----ASH---- C:\Documents and Settings\marco\Application Data\desktop.ini
2009-08-05 22:00:50 ----SD---- C:\Documents and Settings\marco\Application Data\Microsoft
2009-08-05 20:53:57 ----D---- C:\windows\Prefetch
2009-08-05 20:53:57 ----A---- C:\windows\SchedLgU.Txt
2009-08-05 20:52:41 ----SD---- C:\windows\system32\Microsoft
2009-08-05 20:52:31 ----N---- C:\windows\system32\spmsg.dll
2009-08-05 20:52:31 ----A---- C:\windows\system32\spupdsvc.exe
2009-08-05 20:52:30 ----HDC---- C:\windows\$NtServicePackUninstallNLSDownlevelMapping$
2009-08-05 20:52:25 ----D---- C:\Program Files\Alky for Applications
2009-08-05 20:52:19 ----D---- C:\Program Files\Microsoft Silverlight
2009-08-05 20:52:13 ----D---- C:\Program Files\Movie Maker 2.6
2009-08-05 20:52:08 ----D---- C:\windows\system32\Macromed
2009-08-05 20:50:52 ----RSD---- C:\windows\assembly
2009-08-05 20:50:42 ----D---- C:\windows\Microsoft.NET
2009-08-05 20:50:13 ----A---- C:\windows\control.ini
2009-08-05 20:49:47 ----DC---- C:\windows\system32\DRVSTORE
2009-08-05 20:49:37 ----A---- C:\windows\system32\mapi32.dll
2009-08-05 20:48:59 ----RAH---- C:\windows\system32\logonui.exe.manifest
2009-08-05 20:48:56 ----RAH---- C:\windows\system32\cdplayer.exe.manifest
2009-08-05 20:48:52 ----HD---- C:\Program Files\WindowsUpdate
2009-08-05 20:48:48 ----D---- C:\Program Files\Services en ligne
2009-08-05 20:48:40 ----D---- C:\windows\system32\DirectX
2009-08-05 20:48:36 ----A---- C:\windows\system32\atrace.dll
2009-08-05 20:48:35 ----A---- C:\windows\system32\desktop.ini
2009-08-05 20:48:35 ----A---- C:\windows\desktop.ini
2009-08-05 20:48:30 ----A---- C:\windows\system32\acctres.dll
2009-08-05 20:48:29 ----D---- C:\Program Files\Fichiers communs\Services
2009-08-05 20:48:28 ----SD---- C:\windows\Tasks
2009-08-05 20:48:28 ----A---- C:\windows\system32\icfgnt5.dll
2009-08-05 20:48:27 ----D---- C:\Program Files\Fichiers communs\MSSoap
2009-08-05 20:48:24 ----A---- C:\windows\system32\wuweb.dll
2009-08-05 20:48:24 ----A---- C:\windows\system32\wucltui.dll
2009-08-05 20:48:24 ----A---- C:\windows\system32\wuauserv.dll
2009-08-05 20:48:24 ----A---- C:\windows\system32\wuaueng1.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\wups.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuaueng.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuauclt1.exe
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuauclt.exe
2009-08-05 20:48:23 ----A---- C:\windows\system32\wuapi.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\qmgrprxy.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\qmgr.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\bitsprx4.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\bitsprx3.dll
2009-08-05 20:48:23 ----A---- C:\windows\system32\bitsprx2.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\safrslv.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\safrdm.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\safrcdlg.dll
2009-08-05 20:48:11 ----A---- C:\windows\system32\racpldlg.dll
2009-08-05 20:48:08 ----A---- C:\windows\system32\fltMc.exe
2009-08-05 20:48:08 ----A---- C:\windows\system32\fltlib.dll
2009-08-05 20:48:07 ----D---- C:\windows\system32\Restore
2009-08-05 20:48:07 ----A---- C:\windows\system32\srsvc.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\srrstr.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\srclient.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\msoert2.dll
2009-08-05 20:48:07 ----A---- C:\windows\system32\msoeacct.dll
2009-08-05 20:48:06 ----A---- C:\windows\system32\inetres.dll
2009-08-05 20:48:06 ----A---- C:\windows\system32\inetcomm.dll
2009-08-05 20:48:05 ----D---- C:\Program Files\Outlook Express
2009-08-05 20:48:05 ----A---- C:\windows\system32\schedsvc.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\mstinit.exe
2009-08-05 20:48:04 ----A---- C:\windows\system32\mstask.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\isign32.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\inetcfg.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\icwphbk.dll
2009-08-05 20:48:04 ----A---- C:\windows\system32\icwdial.dll
2009-08-05 20:48:00 ----D---- C:\Program Files\Fichiers communs\System
2009-08-05 20:47:22 ----D---- C:\Program Files\ComPlus Applications
2009-08-05 20:47:20 ----A---- C:\windows\vbaddin.ini
2009-08-05 20:47:20 ----A---- C:\windows\vb.ini
2009-08-05 20:47:16 ----D---- C:\windows\Registration
2009-08-05 20:46:34 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-08-05 20:46:16 ----D---- C:\Program Files\Windows Live
2009-08-05 20:46:11 ----SD---- C:\windows\Downloaded Program Files
2009-08-05 20:46:11 ----RD---- C:\windows\Offline Web Pages
2009-08-05 20:46:07 ----D---- C:\Program Files\Internet Explorer
2009-08-05 20:43:30 ----D---- C:\Program Files\Windows Sidebar
2009-08-05 20:43:25 ----D---- C:\Program Files\VistaExperience.org
2009-08-05 20:43:18 ----D---- C:\Program Files\Windows Media Player
2009-08-05 20:43:18 ----D---- C:\Program Files\Windows Media Connect 2
2009-08-05 20:43:13 ----A---- C:\windows\system32\usrlogon.cmd
2009-08-05 20:43:13 ----A---- C:\windows\system32\tsshutdn.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\tslabels.ini
2009-08-05 20:43:13 ----A---- C:\windows\system32\tskill.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\tsdiscon.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\tscon.exe
2009-08-05 20:43:13 ----A---- C:\windows\system32\reset.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\shadow.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\rwinsta.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\regini.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\rdpcfgex.dll
2009-08-05 20:43:12 ----A---- C:\windows\system32\qwinsta.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\qappsrv.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\msg.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\msdtcprf.ini
2009-08-05 20:43:12 ----A---- C:\windows\system32\logoff.exe
2009-08-05 20:43:12 ----A---- C:\windows\system32\cdmodem.dll
2009-08-05 20:43:08 ----A---- C:\windows\system32\wmimgmt.msc
2009-08-05 20:43:07 ----D---- C:\Program Files\Windows NT
2009-08-05 20:43:06 ----A---- C:\windows\system32\tsgqec.dll
2009-08-05 20:43:06 ----A---- C:\windows\system32\tscfgwmi.dll
2009-08-05 20:43:06 ----A---- C:\windows\system32\rhttpaa.dll
2009-08-05 20:43:06 ----A---- C:\windows\system32\aaclient.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\sessmgr.exe
2009-08-05 20:43:05 ----A---- C:\windows\system32\remotepg.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\rdshost.exe
2009-08-05 20:43:05 ----A---- C:\windows\system32\rdsaddin.exe
2009-08-05 20:43:05 ----A---- C:\windows\system32\rdchost.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\mstscax.dll
2009-08-05 20:43:05 ----A---- C:\windows\system32\mstsc.exe
2009-08-05 20:43:04 ----D---- C:\windows\system32\MsDtc
2009-08-05 20:43:04 ----A---- C:\windows\system32\termsrv.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\rdpwsx.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\rdpsnd.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\rdpclip.exe
2009-08-05 20:43:04 ----A---- C:\windows\system32\qprocess.exe
2009-08-05 20:43:04 ----A---- C:\windows\system32\mtxoci.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\msdtcuiu.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\icaapi.dll
2009-08-05 20:43:04 ----A---- C:\windows\system32\cfgbkend.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\xolehlp.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtctm.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtcprx.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtclog.dll
2009-08-05 20:43:03 ----A---- C:\windows\system32\msdtc.exe
2009-08-05 20:43:02 ----D---- C:\windows\system32\Com
2009-08-05 20:43:02 ----A---- C:\windows\system32\stclient.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\mtxlegih.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\mtxex.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\mtxdm.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\dcomcnfg.exe
2009-08-05 20:43:02 ----A---- C:\windows\system32\comrepl.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\comaddin.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\colbact.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\clbcatex.dll
2009-08-05 20:43:02 ----A---- C:\windows\system32\catsrvps.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\comuid.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\comsvcs.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\comsnap.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\clbcatq.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\catsrvut.dll
2009-08-05 20:43:01 ----A---- C:\windows\system32\catsrv.dll
2009-08-05 20:42:57 ----A---- C:\windows\system32\servdeps.dll
2009-08-05 20:42:56 ----A---- C:\windows\system32\mmfutil.dll
2009-08-05 20:42:56 ----A---- C:\windows\system32\licwmi.dll
2009-08-05 20:42:56 ----A---- C:\windows\system32\cmprops.dll
======List of files/folders modified in the last 1 months======
2009-08-19 04:56:35 ----A---- C:\windows\win.ini
2009-08-19 04:56:35 ----A---- C:\windows\system.ini
2009-08-05 11:00:38 ----A---- C:\windows\system32\mswebdvd.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Pilote de processeur Intel; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 ssmdrv;ssmdrv; C:\windows\system32\DRIVERS\ssmdrv.sys [2009-08-05 28520]
R2 avgntflt;avgntflt; C:\windows\system32\DRIVERS\avgntflt.sys [2009-08-18 55656]
R2 rspndr;Répondeur de découverte de topologie de la couche de liaison; C:\windows\system32\DRIVERS\rspndr.sys [2008-05-29 62848]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Pilote de classe HID Microsoft; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\windows\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\windows\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\windows\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
R3 mouhid;Pilote HID de souris; C:\windows\system32\DRIVERS\mouhid.sys [2008-04-14 12288]
R3 NuidFltr;NUID filter driver; C:\windows\system32\DRIVERS\NuidFltr.sys [2009-05-09 14736]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\windows\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\windows\system32\drivers\sthda.sys [2007-05-06 1222840]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-24 30336]
R3 usbhub;Concentrateur USB2; C:\windows\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Classe d'imprimantes USB Microsoft; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Pilote de scanneur USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\windows\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Wdf01000; C:\windows\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 ads63bja;ads63bja; C:\windows\system32\drivers\ads63bja.sys []
S3 cpuz132;cpuz132; \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys []
S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\windows\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 nmwcdc;Nokia USB Generic; C:\windows\system32\drivers\ccdcmbo.sys [2008-05-02 20864]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2008-05-02 8064]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-02 8064]
S3 USBSTOR;Pilote de stockage de masse USB; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\windows\system32\DRIVERS\WudfPf.sys [2009-03-27 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2009-03-27 82944]
S4 exFat;exFat; C:\windows\system32\drivers\exFat.sys [2008-09-29 133632]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-08-05 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-18 185089]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-08-06 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-08-15 1029456]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\windows\system32\nvsvc32.exe [2008-10-07 163908]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-08-06 66872]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
S2 ASKUpgrade;ASKUpgrade; C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe []
S2 STacSV;Audio Service; c:\d\s\zi\STacSV.exe []
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-06 182768]
S3 hpqcxs08;hpqcxs08; C:\windows\system32\svchost.exe [2008-04-14 14336]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-05-29 234864]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
voila j'ai refais un scan. je suis toujours pollué par les sites porno qui s'ouvrent en permanence meme sans que je navigue sur le net. par contre je n'ai pas ce probleme sur mozilla firefox.
merci pour tout. ci le problème ne peut se résoudre je pense formater le dd. @+
Tu as des pubs sur tous les sites ou juste des sites précis ?
Répondre à Angeldark
oui il y a des pub sur ces sites si tu me dis comment on fait je peut t'envoyer l'historique.
salut et @+ marco
petit rectificatif. y a pas de pub sur ses sites
salut et @+ marco
Je te demande juste si tu as juste des pubs sur quelques sites ou tu as des pubs partout (genre même sur Google).
Répondre à Angeldark
non uniquement sur quelques site. au début javais un problème sur google. quand je cliquait sur le lien de la page google sa me redirigait sur un autre site. j'ai réglé se problème en réinitialisant internet explorer. depuis j'ai les pages qui s'ouvrent toutes seules sur IE.
salut et @+ marco
Donc ce n'est pas un problème de virus, c'est lié au site.
Répondre à Angeldark
surement mais qu'es ce qu'il faut que je fasse. c'est plus de 50 pages qui s'ouvre tous les jours sans mon intervention. il y a pas un moyen pour supprimer IE sa résoudrai peut etre mon probleme. en ce moment, mon anti virus est tres actif. voici les quelques virus qui se promènent je peux juste refuser leur accès ou les mettre en quarantaine mais pas les supprimer.
C:\Dociment and setting\marco\Local settings\tempory Internet Files\Content.IE5\2ENU89XJ\adultsex_ws[1].htm
C:\Dociment and setting\marco\Local settings\tempory Internet Files\Content.IE5\V45A90E\sexrazvrat_com[1].htm
C:\Dociment and setting\marco\Local settings\tempory Internet Files\Content.IE5\WC645AEI\eighteenmovs_com[1].htm
en espérant que sa t'éclaire un peu salut et @+
salut angeldark
voila hier soir j'ai résolu mon problème avec malwarebytes dont voici le rapport suivant.
Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2706
Windows 5.1.2600 Service Pack 3
27/08/2009 23:23:29
mbam-log-2009-08-27 (23-23-29).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 133137
Temps écoulé: 23 minute(s), 50 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 8
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 3
Processus mémoire infecté(s):
C:\Program Files\Target Web ADS\TargetWebADSh.exe (Adware.TargetWebADS) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\targetwebads.targetwebads (Adware.TargetWebADS) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8152a0b9-deb6-476e-bc67-175b19080a8a} (Adware.TargetWebADS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8152a0b9-deb6-476e-bc67-175b19080a8a} (Adware.TargetWebADS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8152a0b9-deb6-476e-bc67-175b19080a8a} (Adware.TargetWebADS) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\targetwebads.targetwebads.1 (Adware.TargetWebADS) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{dfb2e345-ad44-462d-b07a-a513718fabdb} (Adware.TargetWebADS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7233cf20-0ba7-4fc2-879e-04cef6439f90} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\TargetWebADS (Adware.TargetWebADS) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hblock (Adware.TargetWebADS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:\Program Files\Target Web ADS (Adware.TargetWebADS) -> Delete on reboot.
Fichier(s) infecté(s):
C:\Program Files\Target Web ADS\TargetWebADS.dll (Adware.TargetWebADS) -> Quarantined and deleted successfully.
C:\Documents and Settings\marco\Bureau\torrent\Alcohol.120.v1.9.6.5429.WinAll.Cracked.Multi-APF\crack\Alcohol.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Target Web ADS\TargetWebADSh.exe (Adware.TargetWebADS) -> Delete on reboot
merci pour tout et @+
Erreur de ma part, désolé.
Fais une analyse antivirus en ligne sur Kaspersky avec Internet Explorer.
- Autorise les Active x.
- Clique sur Démarrer Online Scanner.
- Sélectionne le poste de travail comme analyse. Enregistres sous le rapport en format .txt.
- Colle son rapport ici.
- Poste un nouveau rapport Hijackthis.
Répondre à Angeldark
salut
je n'ai pas pu faire un scan avec kaspersky en ligne car il ne voulait pas faire la mise a jour donc j'ai téléchargé la version dévalution et j'ai fait un scan rapide et aucun virus n'a été décelé.
maintenant voici le rapport Hijackthis.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:16:18, on 28/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\windows\System32\svchost.exe
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\windows\system32\svchost.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tropal.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: (no name) - {8152A0B9-DEB6-476e-BC67-175B19080A8A} - (no file)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\DOCUME~1\marco\LOCALS~1\Temp\cceA2D.html
O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\marco\LOCALS~1\Temp\cceA29.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\marco\LOCALS~1\Temp\cceA2B.html
O9 - Extra button: (no name) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Analyse des &liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe (file missing)
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Audio Service (STacSV) - Unknown owner - c:\d\s\zi\STacSV.exe (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 8933 bytes
salut et @+ marco
salut
j'ai supprimer la version d'évaluation de kaspersky et reinstallé antivir (la version gratuite). selon le scan que j'ai effectué cette nuit 2 cheveaux de troie ont été placé en quarantaine.
C:\System Volume information\_restore{c3ff6231-a054-446e-9f2e-5166752a8a71}\rp21\a000580.exe
C:\System Volume information\_restore{c3ff6231-a054-446e-9f2e-5166752a8a71}\rp21\a000579.dll
dans la foulée je te relance un rapport d'HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:54:31, on 29/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\windows\System32\svchost.exe
C:\windows\system32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\windows\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tropal.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
O2 - BHO: (no name) - {8152A0B9-DEB6-476e-BC67-175B19080A8A} - (no file)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: barre d'outils Orange - {D3028143-6145-4318-99D3-3EDCE54A95A9} - C:\Program Files\Orange\ToolbarFR\ToolbarContainer101000314.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\DOCUME~1\marco\LOCALS~1\Temp\cce132.html
O8 - Extra context menu item: traduire la page - C:\DOCUME~1\marco\LOCALS~1\Temp\cce130.html
O8 - Extra context menu item: traduire le texte sélectionné - C:\DOCUME~1\marco\LOCALS~1\Temp\cce131.html
O9 - Extra button: (no name) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Audio Service (STacSV) - Unknown owner - c:\d\s\zi\STacSV.exe (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 8149 bytes
pour info kaspersky en ligne na pas pus faire ses mise a jour. ca me disait que je n'avais pas une connexion internet permanente.
salut et @+
Ça me semble ok, encore des soucis ?
Choisis do a system scan only, coche ces lignes (si toujours présentes) :
R3 - URLSearchHook: (no name) - {AEEC3B59-CA98-4EBA-A140-57B94E283583} - (no file)
|
Ferme toutes les applications en cours (particulièrement ton navigateur Internet).
Puis Fix Checked !
Répondre à Angeldark
le probleme est résolu
merci pour tout salut et @+ marco
Bon surf
Répondre à Angeldark
Il y a 1758 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
