You are not allowed to do this.
Processus iExplore.exe
Dernière réponse : dans Sécurité
Bonjour,
Voilà j'ai en ce moment un processus occupant pas mal de mémoire vive et qui se relance de lui même régulièrement après l'avoir terminer.
N'utilisant pas IE c'est surement un virus ou autre.
Le log.txt RSIT :
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2009-08-30 21:38:15
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 7 GB (5%) free of 156 GB
Total RAM: 511 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:38:22, on 30/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Saitek\Software\Profiler.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\admin\Bureau\RSIT.exe
C:\Documents and Settings\admin\Bureau\admin.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O2 - BHO: (no name) - {FA29046B-4DAD-D3F2-2FAA-1B68CB4E23E4} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Configuration iTouch.lnk = C:\Program Files\Logitech\iTouch\iTouchcf.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm231YY...
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab312...
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/y...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Cont...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F4EECE8-DF4F-448D-85A3-E04253C377E8}: NameServer = 212.95.68.238,212.95.66.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 9835 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AC6046079187F8D7.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}]
XML Class - C:\WINDOWS\system32\msxml71.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
ST - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll [2004-08-13 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-04-07 2436160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-06-22 669168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
MSNToolBandBHO - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll [2004-08-13 282624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FA29046B-4DAD-D3F2-2FAA-1B68CB4E23E4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - MSN - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll [2004-08-13 282624]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-04-07 2436160]
{381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll [2008-03-05 86016]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Profiler"=C:\Program Files\Saitek\Software\Profiler.exe [2004-01-28 159744]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-06-28 344064]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"zBrowser Launcher"=C:\Program Files\Logitech\iTouch\iTouch.exe [2003-12-01 892928]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-25 29744]
"BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe [2007-10-09 61440]
"BDAgent"=C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe [2008-09-16 368640]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-05 208952]
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE [2004-08-05 44032]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-05 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2009-05-07 75048]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"= []
"MessengerPlus3"=C:\Program Files\MessengerPlus! 3\MsgPlus.exe [2006-09-29 190024]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-04-06 68856]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe []
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bait grey]
C:\DOCUME~1\admin\APPLIC~1\BITSAR~1\4 cast.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
C:\WINDOWS\Logi_MwX.Exe [2003-11-07 19968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe [2004-10-08 196608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2004-09-22 1871872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiSmart]
C:\Program Files\Saitek\Software\SaiSmart.exe [2004-01-28 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^admin^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
C:\Program Files\Softwin\BitDefender9\Quarantine\MWSOEMON.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
C:\Program Files\Softwin\BitDefender9\Quarantine\MWSOEMON.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
C:\PROGRA~1\Google\GOOGLE~2\GOOGLE~1.EXE [2009-03-29 161776]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Configuration iTouch.lnk - C:\Program Files\Logitech\iTouch\iTouchcf.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-06-29 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-05 240128]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoDispBackgroundPage"=1
"NoDispScrSavPage"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe"="C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu(tm)\game.dat"="C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu(tm)\game.dat:*:Enabled:La Bataille pour la Terre du Milieu(tm)"
"C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe"="C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe"="C:\Program Files\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe:*
isabled
andora"
"C:\Program Files\JVTorrent\btdownloadgui.exe"="C:\Program Files\JVTorrent\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\Program Files\Lemoncast\lemoncast.exe"="C:\Program Files\Lemoncast\lemoncast.exe:*:Enabled
neClick"
"C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\0TW34N0J\WoW-frFR-Installer-downloader[1].exe"="C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\0TW34N0J\WoW-frFR-Installer-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:backWeb-8876480"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\StepMania CVS\Program\StepMania.exe"="C:\Program Files\StepMania CVS\Program\StepMania.exe:*:Enabled:StepMania"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled
rb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled
rbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled
rb Stream Client"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe"="C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.2"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe"="C:\Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe:*:Enabled:CyberLink PowerDVD 9.0"
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe"="C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe:*:Enabled:CyberLink PowerDVD 9.0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe"="C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe:*:Enabled:CyberLink PowerDVD 9.0"
======List of files/folders created in the last 1 months======
2099-03-01 03:19:50 ----A---- C:\WINDOWS\system32\h323log.txt
2099-03-01 03:18:14 ----A---- C:\WINDOWS\system32\usbui.dll
2099-03-01 03:17:33 ----SHD---- C:\WINDOWS\Installer
2099-03-01 03:17:33 ----D---- C:\Program Files\Fichiers communs\ODBC
2099-03-01 03:17:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2099-03-01 03:17:33 ----A---- C:\WINDOWS\ODBCINST.INI
2099-03-01 03:17:30 ----D---- C:\Program Files\Fichiers communs\SpeechEngines
2099-03-01 03:17:29 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2099-03-01 03:17:29 ----D---- C:\Program Files\Fichiers communs
2099-03-01 03:17:29 ----D---- C:\Program Files
2099-03-01 03:17:27 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2099-03-01 03:17:27 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2099-03-01 03:17:27 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdur.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdru.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdest.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdro.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2099-03-01 03:17:18 ----A---- C:\WINDOWS\system32\irclass.dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\spxcoins.dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\dgsetup.dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2099-03-01 03:17:15 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2099-03-01 03:17:15 ----A---- C:\WINDOWS\TASKMAN.EXE
2099-03-01 03:17:15 ----A---- C:\WINDOWS\system32\batt.dll
2099-03-01 03:17:14 ----A---- C:\WINDOWS\NOTEPAD.EXE
2099-03-01 03:17:13 ----A---- C:\WINDOWS\system32\storprop.dll
2099-03-01 03:17:09 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2099-03-01 03:17:04 ----RA---- C:\WINDOWS\SET8.tmp
2099-03-01 03:17:02 ----RA---- C:\WINDOWS\SET4.tmp
2099-03-01 03:17:01 ----RA---- C:\WINDOWS\SET3.tmp
2099-03-01 03:16:56 ----D---- C:\WINDOWS\system32\CatRoot2
2099-03-01 03:16:56 ----D---- C:\WINDOWS\system32\CatRoot
2099-03-01 03:16:51 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2099-03-01 03:16:32 ----SHD---- C:\System Volume Information
2099-03-01 03:16:32 ----D---- C:\Documents and Settings
2099-03-01 03:15:43 ----RAH---- C:\boot.ini
2099-03-01 03:09:56 ----D---- C:\WINDOWS\OemDir
2099-03-01 03:09:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2099-03-01 03:09:52 ----RSD---- C:\WINDOWS\Fonts
2099-03-01 03:09:52 ----RD---- C:\WINDOWS\Web
2099-03-01 03:09:52 ----D---- C:\WINDOWS\WinSxS
2099-03-01 03:09:52 ----D---- C:\WINDOWS\twain_32
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Temp
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\wins
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\wbem
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\usmt
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\spool
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\ShellExt
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\Setup
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\ras
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\oobe
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\npp
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\mui
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\inetsrv
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\IME
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\icsxml
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\ias
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\export
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\drivers
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\dhcp
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\config
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\3com_dmi
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\3076
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\2052
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1054
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1042
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1041
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1037
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1036
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1033
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1031
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1028
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1025
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system
2099-03-01 03:09:52 ----D---- C:\WINDOWS\security
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Resources
2099-03-01 03:09:52 ----D---- C:\WINDOWS\repair
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Provisioning
2099-03-01 03:09:52 ----D---- C:\WINDOWS\PeerNet
2099-03-01 03:09:52 ----D---- C:\WINDOWS\pchealth
2099-03-01 03:09:52 ----D---- C:\WINDOWS\mui
2099-03-01 03:09:52 ----D---- C:\WINDOWS\msapps
2099-03-01 03:09:52 ----D---- C:\WINDOWS\msagent
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Media
2099-03-01 03:09:52 ----D---- C:\WINDOWS\java
2099-03-01 03:09:52 ----D---- C:\WINDOWS\ime
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Help
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Driver Cache
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Debug
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Cursors
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Connection Wizard
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Config
2099-03-01 03:09:52 ----D---- C:\WINDOWS\AppPatch
2099-03-01 03:09:52 ----D---- C:\WINDOWS\addins
2009-08-29 22:33:37 ----D---- C:\rsit
2009-08-29 21:14:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-29 21:14:30 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-08-28 18:22:57 ----D---- C:\Documents and Settings\admin\Application Data\vlc
2009-08-28 16:06:24 ----D---- C:\Documents and Settings\admin\Application Data\dvdcss
2009-08-28 15:58:38 ----D---- C:\Program Files\VideoLAN
2009-08-28 14:38:10 ----A---- C:\WINDOWS\ntbtlog.txt
2009-08-25 20:49:21 ----D---- C:\spoolerlogs
======List of files/folders modified in the last 1 months======
2099-03-01 03:17:09 ----ASH---- C:\Documents and Settings\admin\Application Data\desktop.ini
2009-08-30 21:38:00 ----D---- C:\Program Files\Mozilla Firefox
2009-08-30 21:33:39 ----D---- C:\Documents and Settings\admin\Application Data\uTorrent
2009-08-30 21:29:29 ----D---- C:\WINDOWS\system32
2009-08-30 20:03:43 ----D---- C:\WINDOWS\Prefetch
2009-08-30 19:38:58 ----SD---- C:\WINDOWS\Tasks
2009-08-30 15:27:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-08-30 10:53:07 ----A---- C:\WINDOWS\iTouch.ini
2009-08-30 01:02:46 ----A---- C:\WINDOWS\bdagent.INI
2009-08-29 21:50:10 ----A---- C:\WINDOWS\win.ini
2009-08-29 21:50:10 ----A---- C:\WINDOWS\system.ini
2009-08-29 21:36:13 ----SHD---- C:\RECYCLER
2009-08-29 21:31:50 ----A---- C:\WINDOWS\NeroDigital.ini
2009-08-29 20:49:50 ----D---- C:\WINDOWS
2009-08-29 20:02:41 ----D---- C:\WINDOWS\Minidump
2009-08-29 19:45:56 ----HD---- C:\WINDOWS\inf
2009-08-29 19:28:20 ----D---- C:\Config.Msi
2009-08-29 16:28:36 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-08-28 14:21:45 ----D---- C:\Documents and Settings\admin\Application Data\LimeWire
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Athlon64 Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 35840]
R1 bdftdif;bdftdif; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys []
R1 FsVga;FsVga; C:\WINDOWS\system32\DRIVERS\fsvga.sys [2004-08-05 12416]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/07/24 15:46:32]; \??\C:\Program Files\CyberLink\PowerDVD9\000.fcl []
R2 Vcs;Vcs support; \??\C:\WINDOWS\system32\Drivers\Vcs.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-09-21 2278784]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-06-29 1241088]
R3 bdfsfltr;bdfsfltr; 730079007300740065006D00330032005C0044005200490056004500520053005C00620064006600730066006C00740072002E007300790073000000 []
R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys []
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 itchfltr;iTouch Keyboard Filter; C:\WINDOWS\system32\DRIVERS\itchfltr.sys [2003-11-09 12953]
R3 L8042pr2;Logitech PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042pr2.Sys [2003-11-07 51486]
R3 LMouFlt2;Logitech Mouse Class Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys [2003-11-07 70798]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-10-08 22016]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2004-10-08 585824]
R3 SaiMini;SaiMini; C:\WINDOWS\system32\DRIVERS\SaiMini.sys [2004-01-28 15232]
R3 SaiNtBus;SaiNtBus; C:\WINDOWS\system32\drivers\SaiNtBus.sys [2004-01-28 26624]
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-05 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-05 20480]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2001-09-13 10112]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2001-09-13 39328]
S2 FILESpy;FILESpy; \??\C:\Program Files\Softwin\BitDefender9\filespy.sys []
S2 REGSpy;REGSpy; \??\C:\Program Files\Softwin\BitDefender9\regspy.sys []
S3 A_USBETHMP;USB PowerPacket Network Adapter; C:\WINDOWS\System32\Drivers\usbethmp.sys [2002-10-24 14342]
S3 bdfdll;bdfdll; \??\C:\Program Files\Softwin\BitDefender9\bdfdll.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 dump_wmimmc;dump_wmimmc; \??\C:\Program Files\gPotato.eu\Dragonica\FR\Release\GameGuard\dump_wmimmc.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 FETNDIS;Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 LHidFlt2;Logitech HID/USB Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFlt2.Sys [2003-11-07 25502]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NPPTNT2;NPPTNT2; \??\C:\WINDOWS\system32\npptNT2.sys []
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PLCNDIS5.SYS []
S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
S3 PVUSB;CESG502 USB Driver; C:\WINDOWS\system32\DRIVERS\CESG502.sys [2002-06-12 40672]
S3 SaiH0464;SaiH0464; C:\WINDOWS\system32\DRIVERS\SaiH0464.sys [2004-01-30 55808]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2003-12-19 133632]
S3 WmFilter;Logitech WingMan HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2001-09-13 19360]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2001-09-13 5728]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-05 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-06-29 376832]
R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2008-11-27 1179648]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2009-04-27 271760]
R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe [2008-09-15 1261568]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
R2 XCOMM;BitDefender Communicator; C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe [2007-12-03 86016]
R3 scan;BitDefender Threat Scanner; C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-06-28 516096]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-29 183280]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-25 29744]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-03-19 2726941]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
-----------------EOF-----------------
Le info.txt:
info.txt logfile of random's system information tool 1.06 2009-08-29 22:33:54
======Uninstall list======
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 6.0.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Age of Mythology Gold-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /uninstall
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class
ISPLAY -clean
ATI HYDRAVISION-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{083F79E4-6FE9-46FB-A6C6-4F8862742947}\setup.exe"
Barre d'outils MSN-->C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\mtbs.exe c
BitDefender Antivirus 2008-->MsiExec.exe /I{7764592F-FFE0-4292-82B7-9732C66F10E5}
CASIO FA-124-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB47E710-6249-4EFA-BE36-E922B0612AF4}\Setup.exe" -l0x9
Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
CyberLink PowerDVD 9-->"C:\Program Files\InstallShield Installation Information\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\Setup.exe" /z-uninstall
CyberLink PowerDVD 9-->"C:\Program Files\InstallShield Installation Information\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\Setup.exe" /z-uninstall
Desintaller-->"C:\Program Files\FlameOfLegend\unins000.exe"
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dragonica(FR)-->C:\Program Files\gPotato.eu\Dragonica\FR\uninst.exe
DVD Solution-->"C:\Program Files\Uninstall_CDS.exe"
Google Desktop MSN Plugin-->MsiExec.exe /I{DC33D3D7-E641-4F17-A562-D572A1FD579B}
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
greenstreet PowerText3D 2.0-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Common Files\greenstreet\PowerText\PowerText.isu"
greenstreet Publisher 3.13-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\greenstreet\Publisher313.isu" -c"C:\Program Files\greenstreet\_UNODBC.DLL"
greenstreet Utilities-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\greenstreet\Utils.isu"
GUILD WARS-->"C:\Program Files\GUILD WARS\Gw.exe" -uninstall
GW Team Builder 1.1.3-->"C:\Program Files\GW Team Builder\setup\unins000.exe"
GWFreaks 3.5.4.0-->"C:\Program Files\GWFreaks\unins000.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\admin\Bureau\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
Java 2 Runtime Environment, SE v1.4.2_04-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142040}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
La Bataille pour la Terre du Milieu(tm)-->C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu(tm)\EAUninstall.exe
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Les Sims 2 : Nuits de Folie-->C:\Program Files\EA GAMES\Les Sims 2 Nuits de Folie\EAUninstall.exe
Les Sims 2 Académie-->C:\Program Files\EA GAMES\Les Sims 2 Académie\EAUninstall.exe
Les Sims 2-->C:\Program Files\EA GAMES\Les Sims 2\EAUninstall.exe
LimeWire 5.1.2-->"C:\Program Files\LimeWire\uninstall.exe"
Logiciel iTouch de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{036AA4D4-6D32-11D4-9875-00105ACE7734}\setup.exe" -l0x40c UNINSTALL
Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\setup.exe" -l0x40c UNINSTALL
Logitech MouseWare 9.79 -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\setup.exe" -l0x40c -l040c UNINSTALL
Logitech Resource Center-->C:\PROGRA~1\Logitech\RESOUR~1\rem\UNWISE.EXE C:\PROGRA~1\Logitech\RESOUR~1\rem\INSTALL.LOG
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Messenger Plus! 3 & Sponsor-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
Messenger Plus! Live & Sponsor (CiD)-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Windows Application Compatibility Database-->C:\WINDOWS\system32\sdbinst.exe -u "C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb"
Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
Mozilla Firefox (3.0.13)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSI Live Update 3-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\Live Update 3\Uninst.isu"
MSN Messenger 7.5-->MsiExec.exe /I{BAFD3C1E-03EC-11DA-BFBD-00065BBDC0B5}
MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Multimedia Launcher-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
OpenOffice.org 2.4-->MsiExec.exe /I{1E0FF527-971B-4BBF-83D1-987E8DEE437D}
Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
Powerline Adapter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE5AB97C-7B6F-4ABB-BDE2-DA0FE7785BA4}\Setup.exe" -l0x9
Prince of Persia l'Ame du Guerrier-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE5BC0BB-9EDA-423C-8276-48857B735D68}\Setup.exe" -l0x40c
Prince of Persia Les Sables du Temps-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8C453F13-6877-4D34-8816-009ABDE306DB}\setup.exe" -l0x40c
Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
Sony Ericsson Media Manager 1.2-->MsiExec.exe /X{5F1ECBFB-048E-406E-A7AB-A81F9E359961}
Splinter Cell Pandora Tomorrow-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{084A9731-D05B-4ADA-B4A0-0ADD25FD7152}\Setup.exe" -l0x40c
SST Programming Software-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{03ADCA1C-BCF0-4B12-AFCF-8EBF2CB3AB07}\setup.exe" AddRem
TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
TeamSpeak 2 Server RC2-->"C:\Program Files\Teamspeak2_RC2\unins001.exe"
UniChromeII Graphics Driver and Utilities-->C:\PROGRA~1\S3Inc\S3\s3setvga.exe -s -fC:\PROGRA~1\S3Inc\S3\S3.uns
VB Runtime-->C:\WINDOWS\system32\UNINSTAL.EXE /A /R C:\WINDOWS\system32\VBRunTme.LOG
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
VIA Gestionnaire de périphériques de plate-forme-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
Visionneuse Journal Windows Microsoft-->MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}
VLC media player 1.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
WingMan Software-->MsiExec.exe /X{1189284F-0556-47E5-8DCD-F8BF3176F4EA}
????·???????!-->C:\Program Files\???????????\LSUin000.exe "C:\Program Files\???????????\LSUin000.lil"
======Security center information======
AV: Bitdefender Antivirus
======System event log======
Computer Name: LUDOVIC
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Profos.
Record Number: 20040
Source Name: Service Control Manager
Time Written: 20090722030004.000000+120
Event Type: Informations
User: LUDOVIC\admin
Computer Name: LUDOVIC
Event Code: 4226
Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
Record Number: 20039
Source Name: Tcpip
Time Written: 20090722011057.000000+120
Event Type: Avertissement
User:
Computer Name: LUDOVIC
Event Code: 4226
Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
Record Number: 20038
Source Name: Tcpip
Time Written: 20090722003719.000000+120
Event Type: Avertissement
User:
Computer Name: LUDOVIC
Event Code: 36
Message: Le service de temps n'a pas pu synchroniser l'heure système de 49152
secondes car aucun fournisseur de temps n'a pu fournir de datage
utilisable. L'horloge système n'est pas synchronisée.
Record Number: 20037
Source Name: W32Time
Time Written: 20090721235643.000000+120
Event Type: Avertissement
User:
Computer Name: LUDOVIC
Event Code: 4226
Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
Record Number: 20036
Source Name: Tcpip
Time Written: 20090721182244.000000+120
Event Type: Avertissement
User:
=====Application event log=====
Computer Name: LUDOVIC
Event Code: 0
Message:
Record Number: 5
Source Name: gusvc
Time Written: 20090528222625.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 0
Message:
Record Number: 4
Source Name: scan
Time Written: 20090528222531.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.
Record Number: 3
Source Name: SecurityCenter
Time Written: 20090528222530.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 0
Message:
Record Number: 2
Source Name: gusvc
Time Written: 20090528222526.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 105
Message: The service was started.
Record Number: 1
Source Name: ATI Smart
Time Written: 20090528222525.000000+120
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Fichiers communs\GTK\2.0\bin;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\DivX Shared\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 28 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=1c00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"CLASSPATH"=.;®h’|C:\WINDOWS\system32\QTJava.zip;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"LANG"=fr
-----------------EOF-----------------
Voilà j'ai en ce moment un processus occupant pas mal de mémoire vive et qui se relance de lui même régulièrement après l'avoir terminer.
N'utilisant pas IE c'est surement un virus ou autre.
Le log.txt RSIT :
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2009-08-30 21:38:15
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 7 GB (5%) free of 156 GB
Total RAM: 511 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:38:22, on 30/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Saitek\Software\Profiler.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\admin\Bureau\RSIT.exe
C:\Documents and Settings\admin\Bureau\admin.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O2 - BHO: (no name) - {FA29046B-4DAD-D3F2-2FAA-1B68CB4E23E4} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Configuration iTouch.lnk = C:\Program Files\Logitech\iTouch\iTouchcf.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm231YY...
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab312...
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/y...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Cont...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F4EECE8-DF4F-448D-85A3-E04253C377E8}: NameServer = 212.95.68.238,212.95.66.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 9835 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AC6046079187F8D7.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}]
XML Class - C:\WINDOWS\system32\msxml71.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
ST - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll [2004-08-13 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-04-07 2436160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-06-22 669168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
MSNToolBandBHO - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll [2004-08-13 282624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FA29046B-4DAD-D3F2-2FAA-1B68CB4E23E4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - MSN - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll [2004-08-13 282624]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-04-07 2436160]
{381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll [2008-03-05 86016]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Profiler"=C:\Program Files\Saitek\Software\Profiler.exe [2004-01-28 159744]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-06-28 344064]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"zBrowser Launcher"=C:\Program Files\Logitech\iTouch\iTouch.exe [2003-12-01 892928]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-25 29744]
"BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe [2007-10-09 61440]
"BDAgent"=C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe [2008-09-16 368640]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-05 208952]
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE [2004-08-05 44032]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-05 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-05 455168]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2009-05-07 75048]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"= []
"MessengerPlus3"=C:\Program Files\MessengerPlus! 3\MsgPlus.exe [2006-09-29 190024]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-04-06 68856]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe []
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bait grey]
C:\DOCUME~1\admin\APPLIC~1\BITSAR~1\4 cast.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
C:\WINDOWS\Logi_MwX.Exe [2003-11-07 19968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe [2004-10-08 196608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2004-09-22 1871872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiSmart]
C:\Program Files\Saitek\Software\SaiSmart.exe [2004-01-28 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^admin^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
C:\Program Files\Softwin\BitDefender9\Quarantine\MWSOEMON.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
C:\Program Files\Softwin\BitDefender9\Quarantine\MWSOEMON.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
C:\PROGRA~1\Google\GOOGLE~2\GOOGLE~1.EXE [2009-03-29 161776]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Configuration iTouch.lnk - C:\Program Files\Logitech\iTouch\iTouchcf.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-06-29 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-05 240128]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoDispBackgroundPage"=1
"NoDispScrSavPage"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe"="C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu(tm)\game.dat"="C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu(tm)\game.dat:*:Enabled:La Bataille pour la Terre du Milieu(tm)"
"C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe"="C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe"="C:\Program Files\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe:*
isabled
andora""C:\Program Files\JVTorrent\btdownloadgui.exe"="C:\Program Files\JVTorrent\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\Program Files\Lemoncast\lemoncast.exe"="C:\Program Files\Lemoncast\lemoncast.exe:*:Enabled
neClick""C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\0TW34N0J\WoW-frFR-Installer-downloader[1].exe"="C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\0TW34N0J\WoW-frFR-Installer-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*:Enabled:backWeb-8876480"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\StepMania CVS\Program\StepMania.exe"="C:\Program Files\StepMania CVS\Program\StepMania.exe:*:Enabled:StepMania"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled
rb""C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled
rbTray""C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled
rb Stream Client""C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe"="C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.2"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe"="C:\Program Files\CyberLink\PowerDVD9\PowerDVD Cinema\PowerDVDCinema.exe:*:Enabled:CyberLink PowerDVD 9.0"
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe"="C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe:*:Enabled:CyberLink PowerDVD 9.0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe"="C:\Program Files\CyberLink\PowerDVD9\PowerDVD9.exe:*:Enabled:CyberLink PowerDVD 9.0"
======List of files/folders created in the last 1 months======
2099-03-01 03:19:50 ----A---- C:\WINDOWS\system32\h323log.txt
2099-03-01 03:18:14 ----A---- C:\WINDOWS\system32\usbui.dll
2099-03-01 03:17:33 ----SHD---- C:\WINDOWS\Installer
2099-03-01 03:17:33 ----D---- C:\Program Files\Fichiers communs\ODBC
2099-03-01 03:17:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2099-03-01 03:17:33 ----A---- C:\WINDOWS\ODBCINST.INI
2099-03-01 03:17:30 ----D---- C:\Program Files\Fichiers communs\SpeechEngines
2099-03-01 03:17:29 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2099-03-01 03:17:29 ----D---- C:\Program Files\Fichiers communs
2099-03-01 03:17:29 ----D---- C:\Program Files
2099-03-01 03:17:27 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2099-03-01 03:17:27 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2099-03-01 03:17:27 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdur.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdru.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2099-03-01 03:17:25 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2099-03-01 03:17:23 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2099-03-01 03:17:22 ----RA---- C:\WINDOWS\system32\kbdest.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdro.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2099-03-01 03:17:20 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2099-03-01 03:17:18 ----A---- C:\WINDOWS\system32\irclass.dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\spxcoins.dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\dgsetup.dll
2099-03-01 03:17:17 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2099-03-01 03:17:15 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2099-03-01 03:17:15 ----A---- C:\WINDOWS\TASKMAN.EXE
2099-03-01 03:17:15 ----A---- C:\WINDOWS\system32\batt.dll
2099-03-01 03:17:14 ----A---- C:\WINDOWS\NOTEPAD.EXE
2099-03-01 03:17:13 ----A---- C:\WINDOWS\system32\storprop.dll
2099-03-01 03:17:09 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2099-03-01 03:17:04 ----RA---- C:\WINDOWS\SET8.tmp
2099-03-01 03:17:02 ----RA---- C:\WINDOWS\SET4.tmp
2099-03-01 03:17:01 ----RA---- C:\WINDOWS\SET3.tmp
2099-03-01 03:16:56 ----D---- C:\WINDOWS\system32\CatRoot2
2099-03-01 03:16:56 ----D---- C:\WINDOWS\system32\CatRoot
2099-03-01 03:16:51 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2099-03-01 03:16:32 ----SHD---- C:\System Volume Information
2099-03-01 03:16:32 ----D---- C:\Documents and Settings
2099-03-01 03:15:43 ----RAH---- C:\boot.ini
2099-03-01 03:09:56 ----D---- C:\WINDOWS\OemDir
2099-03-01 03:09:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2099-03-01 03:09:52 ----RSD---- C:\WINDOWS\Fonts
2099-03-01 03:09:52 ----RD---- C:\WINDOWS\Web
2099-03-01 03:09:52 ----D---- C:\WINDOWS\WinSxS
2099-03-01 03:09:52 ----D---- C:\WINDOWS\twain_32
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Temp
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\wins
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\wbem
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\usmt
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\spool
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\ShellExt
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\Setup
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\ras
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\oobe
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\npp
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\mui
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\inetsrv
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\IME
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\icsxml
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\ias
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\export
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\drivers
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\dhcp
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\config
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\3com_dmi
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\3076
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\2052
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1054
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1042
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1041
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1037
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1036
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1033
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1031
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1028
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system32\1025
2099-03-01 03:09:52 ----D---- C:\WINDOWS\system
2099-03-01 03:09:52 ----D---- C:\WINDOWS\security
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Resources
2099-03-01 03:09:52 ----D---- C:\WINDOWS\repair
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Provisioning
2099-03-01 03:09:52 ----D---- C:\WINDOWS\PeerNet
2099-03-01 03:09:52 ----D---- C:\WINDOWS\pchealth
2099-03-01 03:09:52 ----D---- C:\WINDOWS\mui
2099-03-01 03:09:52 ----D---- C:\WINDOWS\msapps
2099-03-01 03:09:52 ----D---- C:\WINDOWS\msagent
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Media
2099-03-01 03:09:52 ----D---- C:\WINDOWS\java
2099-03-01 03:09:52 ----D---- C:\WINDOWS\ime
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Help
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Driver Cache
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Debug
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Cursors
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Connection Wizard
2099-03-01 03:09:52 ----D---- C:\WINDOWS\Config
2099-03-01 03:09:52 ----D---- C:\WINDOWS\AppPatch
2099-03-01 03:09:52 ----D---- C:\WINDOWS\addins
2009-08-29 22:33:37 ----D---- C:\rsit
2009-08-29 21:14:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-29 21:14:30 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-08-28 18:22:57 ----D---- C:\Documents and Settings\admin\Application Data\vlc
2009-08-28 16:06:24 ----D---- C:\Documents and Settings\admin\Application Data\dvdcss
2009-08-28 15:58:38 ----D---- C:\Program Files\VideoLAN
2009-08-28 14:38:10 ----A---- C:\WINDOWS\ntbtlog.txt
2009-08-25 20:49:21 ----D---- C:\spoolerlogs
======List of files/folders modified in the last 1 months======
2099-03-01 03:17:09 ----ASH---- C:\Documents and Settings\admin\Application Data\desktop.ini
2009-08-30 21:38:00 ----D---- C:\Program Files\Mozilla Firefox
2009-08-30 21:33:39 ----D---- C:\Documents and Settings\admin\Application Data\uTorrent
2009-08-30 21:29:29 ----D---- C:\WINDOWS\system32
2009-08-30 20:03:43 ----D---- C:\WINDOWS\Prefetch
2009-08-30 19:38:58 ----SD---- C:\WINDOWS\Tasks
2009-08-30 15:27:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-08-30 10:53:07 ----A---- C:\WINDOWS\iTouch.ini
2009-08-30 01:02:46 ----A---- C:\WINDOWS\bdagent.INI
2009-08-29 21:50:10 ----A---- C:\WINDOWS\win.ini
2009-08-29 21:50:10 ----A---- C:\WINDOWS\system.ini
2009-08-29 21:36:13 ----SHD---- C:\RECYCLER
2009-08-29 21:31:50 ----A---- C:\WINDOWS\NeroDigital.ini
2009-08-29 20:49:50 ----D---- C:\WINDOWS
2009-08-29 20:02:41 ----D---- C:\WINDOWS\Minidump
2009-08-29 19:45:56 ----HD---- C:\WINDOWS\inf
2009-08-29 19:28:20 ----D---- C:\Config.Msi
2009-08-29 16:28:36 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-08-28 14:21:45 ----D---- C:\Documents and Settings\admin\Application Data\LimeWire
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Athlon64 Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 35840]
R1 bdftdif;bdftdif; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys []
R1 FsVga;FsVga; C:\WINDOWS\system32\DRIVERS\fsvga.sys [2004-08-05 12416]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/07/24 15:46:32]; \??\C:\Program Files\CyberLink\PowerDVD9\000.fcl []
R2 Vcs;Vcs support; \??\C:\WINDOWS\system32\Drivers\Vcs.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-09-21 2278784]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-06-29 1241088]
R3 bdfsfltr;bdfsfltr; 730079007300740065006D00330032005C0044005200490056004500520053005C00620064006600730066006C00740072002E007300790073000000 []
R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys []
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 itchfltr;iTouch Keyboard Filter; C:\WINDOWS\system32\DRIVERS\itchfltr.sys [2003-11-09 12953]
R3 L8042pr2;Logitech PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042pr2.Sys [2003-11-07 51486]
R3 LMouFlt2;Logitech Mouse Class Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys [2003-11-07 70798]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-10-08 22016]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2004-10-08 585824]
R3 SaiMini;SaiMini; C:\WINDOWS\system32\DRIVERS\SaiMini.sys [2004-01-28 15232]
R3 SaiNtBus;SaiNtBus; C:\WINDOWS\system32\drivers\SaiNtBus.sys [2004-01-28 26624]
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-05 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-05 20480]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2001-09-13 10112]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2001-09-13 39328]
S2 FILESpy;FILESpy; \??\C:\Program Files\Softwin\BitDefender9\filespy.sys []
S2 REGSpy;REGSpy; \??\C:\Program Files\Softwin\BitDefender9\regspy.sys []
S3 A_USBETHMP;USB PowerPacket Network Adapter; C:\WINDOWS\System32\Drivers\usbethmp.sys [2002-10-24 14342]
S3 bdfdll;bdfdll; \??\C:\Program Files\Softwin\BitDefender9\bdfdll.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 dump_wmimmc;dump_wmimmc; \??\C:\Program Files\gPotato.eu\Dragonica\FR\Release\GameGuard\dump_wmimmc.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 FETNDIS;Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 LHidFlt2;Logitech HID/USB Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFlt2.Sys [2003-11-07 25502]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NPPTNT2;NPPTNT2; \??\C:\WINDOWS\system32\npptNT2.sys []
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PLCNDIS5.SYS []
S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
S3 PVUSB;CESG502 USB Driver; C:\WINDOWS\system32\DRIVERS\CESG502.sys [2002-06-12 40672]
S3 SaiH0464;SaiH0464; C:\WINDOWS\system32\DRIVERS\SaiH0464.sys [2004-01-30 55808]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2003-12-19 133632]
S3 WmFilter;Logitech WingMan HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2001-09-13 19360]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2001-09-13 5728]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-05 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-06-29 376832]
R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2008-11-27 1179648]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2009-04-27 271760]
R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe [2008-09-15 1261568]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
R2 XCOMM;BitDefender Communicator; C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe [2007-12-03 86016]
R3 scan;BitDefender Threat Scanner; C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-06-28 516096]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-29 183280]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-25 29744]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-03-19 2726941]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
-----------------EOF-----------------
Le info.txt:
info.txt logfile of random's system information tool 1.06 2009-08-29 22:33:54
======Uninstall list======
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 6.0.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Age of Mythology Gold-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /uninstall
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class
ISPLAY -cleanATI HYDRAVISION-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{083F79E4-6FE9-46FB-A6C6-4F8862742947}\setup.exe"
Barre d'outils MSN-->C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\mtbs.exe c
BitDefender Antivirus 2008-->MsiExec.exe /I{7764592F-FFE0-4292-82B7-9732C66F10E5}
CASIO FA-124-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB47E710-6249-4EFA-BE36-E922B0612AF4}\Setup.exe" -l0x9
Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
CyberLink PowerDVD 9-->"C:\Program Files\InstallShield Installation Information\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\Setup.exe" /z-uninstall
CyberLink PowerDVD 9-->"C:\Program Files\InstallShield Installation Information\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\Setup.exe" /z-uninstall
Desintaller-->"C:\Program Files\FlameOfLegend\unins000.exe"
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dragonica(FR)-->C:\Program Files\gPotato.eu\Dragonica\FR\uninst.exe
DVD Solution-->"C:\Program Files\Uninstall_CDS.exe"
Google Desktop MSN Plugin-->MsiExec.exe /I{DC33D3D7-E641-4F17-A562-D572A1FD579B}
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
greenstreet PowerText3D 2.0-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Common Files\greenstreet\PowerText\PowerText.isu"
greenstreet Publisher 3.13-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\greenstreet\Publisher313.isu" -c"C:\Program Files\greenstreet\_UNODBC.DLL"
greenstreet Utilities-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\greenstreet\Utils.isu"
GUILD WARS-->"C:\Program Files\GUILD WARS\Gw.exe" -uninstall
GW Team Builder 1.1.3-->"C:\Program Files\GW Team Builder\setup\unins000.exe"
GWFreaks 3.5.4.0-->"C:\Program Files\GWFreaks\unins000.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\admin\Bureau\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
Java 2 Runtime Environment, SE v1.4.2_04-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142040}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
La Bataille pour la Terre du Milieu(tm)-->C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu(tm)\EAUninstall.exe
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Les Sims 2 : Nuits de Folie-->C:\Program Files\EA GAMES\Les Sims 2 Nuits de Folie\EAUninstall.exe
Les Sims 2 Académie-->C:\Program Files\EA GAMES\Les Sims 2 Académie\EAUninstall.exe
Les Sims 2-->C:\Program Files\EA GAMES\Les Sims 2\EAUninstall.exe
LimeWire 5.1.2-->"C:\Program Files\LimeWire\uninstall.exe"
Logiciel iTouch de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{036AA4D4-6D32-11D4-9875-00105ACE7734}\setup.exe" -l0x40c UNINSTALL
Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\setup.exe" -l0x40c UNINSTALL
Logitech MouseWare 9.79 -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\setup.exe" -l0x40c -l040c UNINSTALL
Logitech Resource Center-->C:\PROGRA~1\Logitech\RESOUR~1\rem\UNWISE.EXE C:\PROGRA~1\Logitech\RESOUR~1\rem\INSTALL.LOG
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Messenger Plus! 3 & Sponsor-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
Messenger Plus! Live & Sponsor (CiD)-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Windows Application Compatibility Database-->C:\WINDOWS\system32\sdbinst.exe -u "C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb"
Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
Mozilla Firefox (3.0.13)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSI Live Update 3-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\Live Update 3\Uninst.isu"
MSN Messenger 7.5-->MsiExec.exe /I{BAFD3C1E-03EC-11DA-BFBD-00065BBDC0B5}
MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Multimedia Launcher-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
OpenOffice.org 2.4-->MsiExec.exe /I{1E0FF527-971B-4BBF-83D1-987E8DEE437D}
Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
Powerline Adapter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE5AB97C-7B6F-4ABB-BDE2-DA0FE7785BA4}\Setup.exe" -l0x9
Prince of Persia l'Ame du Guerrier-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE5BC0BB-9EDA-423C-8276-48857B735D68}\Setup.exe" -l0x40c
Prince of Persia Les Sables du Temps-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8C453F13-6877-4D34-8816-009ABDE306DB}\setup.exe" -l0x40c
Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
Sony Ericsson Media Manager 1.2-->MsiExec.exe /X{5F1ECBFB-048E-406E-A7AB-A81F9E359961}
Splinter Cell Pandora Tomorrow-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{084A9731-D05B-4ADA-B4A0-0ADD25FD7152}\Setup.exe" -l0x40c
SST Programming Software-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{03ADCA1C-BCF0-4B12-AFCF-8EBF2CB3AB07}\setup.exe" AddRem
TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
TeamSpeak 2 Server RC2-->"C:\Program Files\Teamspeak2_RC2\unins001.exe"
UniChromeII Graphics Driver and Utilities-->C:\PROGRA~1\S3Inc\S3\s3setvga.exe -s -fC:\PROGRA~1\S3Inc\S3\S3.uns
VB Runtime-->C:\WINDOWS\system32\UNINSTAL.EXE /A /R C:\WINDOWS\system32\VBRunTme.LOG
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
VIA Gestionnaire de périphériques de plate-forme-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
Visionneuse Journal Windows Microsoft-->MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}
VLC media player 1.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
WingMan Software-->MsiExec.exe /X{1189284F-0556-47E5-8DCD-F8BF3176F4EA}
????·???????!-->C:\Program Files\???????????\LSUin000.exe "C:\Program Files\???????????\LSUin000.lil"
======Security center information======
AV: Bitdefender Antivirus
======System event log======
Computer Name: LUDOVIC
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Profos.
Record Number: 20040
Source Name: Service Control Manager
Time Written: 20090722030004.000000+120
Event Type: Informations
User: LUDOVIC\admin
Computer Name: LUDOVIC
Event Code: 4226
Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
Record Number: 20039
Source Name: Tcpip
Time Written: 20090722011057.000000+120
Event Type: Avertissement
User:
Computer Name: LUDOVIC
Event Code: 4226
Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
Record Number: 20038
Source Name: Tcpip
Time Written: 20090722003719.000000+120
Event Type: Avertissement
User:
Computer Name: LUDOVIC
Event Code: 36
Message: Le service de temps n'a pas pu synchroniser l'heure système de 49152
secondes car aucun fournisseur de temps n'a pu fournir de datage
utilisable. L'horloge système n'est pas synchronisée.
Record Number: 20037
Source Name: W32Time
Time Written: 20090721235643.000000+120
Event Type: Avertissement
User:
Computer Name: LUDOVIC
Event Code: 4226
Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
Record Number: 20036
Source Name: Tcpip
Time Written: 20090721182244.000000+120
Event Type: Avertissement
User:
=====Application event log=====
Computer Name: LUDOVIC
Event Code: 0
Message:
Record Number: 5
Source Name: gusvc
Time Written: 20090528222625.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 0
Message:
Record Number: 4
Source Name: scan
Time Written: 20090528222531.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.
Record Number: 3
Source Name: SecurityCenter
Time Written: 20090528222530.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 0
Message:
Record Number: 2
Source Name: gusvc
Time Written: 20090528222526.000000+120
Event Type: Informations
User:
Computer Name: LUDOVIC
Event Code: 105
Message: The service was started.
Record Number: 1
Source Name: ATI Smart
Time Written: 20090528222525.000000+120
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Fichiers communs\GTK\2.0\bin;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\DivX Shared\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 28 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=1c00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"CLASSPATH"=.;®h’|C:\WINDOWS\system32\QTJava.zip;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"LANG"=fr
-----------------EOF-----------------
Autres pages sur : processus iexplore exe
Lassé par la pub ? Créez un compte
Bonjour,
1/
Lance ce fichier : C:\Documents and Settings\admin\Bureau\admin.exe
Choisis Do a system scan only.
Coche les cases qui sont devant les lignes suivantes :
Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
Ferme HijackThis.
2/
Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
Sélectionne Exécuter un examen rapide.
Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
1/
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {FA29046B-4DAD-D3F2-2FAA-1B68CB4E23E4} - (no file)
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusea [...] xdm231YYFR
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {FA29046B-4DAD-D3F2-2FAA-1B68CB4E23E4} - (no file)
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusea [...] xdm231YYFR
2/
Citation :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
Pour MBAM, pour je ne sais quel raison j'ai pas mal de problême avec...
J'avais déjà essayé de l'installer, ça a raté plusieurs fois, et quand ça réussissait ça se bloquer sur finalisation de l'installation.
Et maintenant, je n'arrive pas à le faire fonctionner, ni à le desinstaller >.<
Donc si il y a une alternative...
J'avais déjà essayé de l'installer, ça a raté plusieurs fois, et quand ça réussissait ça se bloquer sur finalisation de l'installation.
Et maintenant, je n'arrive pas à le faire fonctionner, ni à le desinstaller >.<
Donc si il y a une alternative...
J'ai vu la trace d'une infection Lop.
Télécharge Lop S&D sur ton Bureau.
Double-clique dessus pour lancer l'installation.
Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
(Sous Vista, il faut cliquer droit sur le raccourci Lop S&D et choisir Exécuter en tant qu'administrateur)
Sélectionne la langue souhaitée, puis choisis l'option 1 (Recherche) .
Patiente jusqu'à la fin du scan.
Poste le rapport généré (C:\lopR.txt).
(Sous Vista, il faut cliquer droit sur le raccourci Lop S&D et choisir Exécuter en tant qu'administrateur)
Le lopR.txt:
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 2800+ )
BIOS : Version 07.00T
USER : admin ( Administrator )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:152 Go (Free:7 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 30/08/2009|22:23 )
--------------------\\ Listing des dossiers dans APPLIC~1
[18/07/2009|22:16] C:\DOCUME~1\admin\APPLIC~1\.minecraft
[07/10/2005|18:13] C:\DOCUME~1\admin\APPLIC~1\32 size slow
[04/04/2008|19:31] C:\DOCUME~1\admin\APPLIC~1\Adobe
[31/01/2009|21:56] C:\DOCUME~1\admin\APPLIC~1\AdobeUM
[14/09/2005|14:50] C:\DOCUME~1\admin\APPLIC~1\Ahead
[26/09/2008|22:25] C:\DOCUME~1\admin\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\admin\APPLIC~1\Bitdefender
[06/03/2006|18:39] C:\DOCUME~1\admin\APPLIC~1\bits army jugs
[01/10/2007|23:18] C:\DOCUME~1\admin\APPLIC~1\BitTorrent
[26/07/2009|18:50] C:\DOCUME~1\admin\APPLIC~1\Cyberlink
[15/10/2007|20:45] C:\DOCUME~1\admin\APPLIC~1\DivX
[28/08/2009|18:35] C:\DOCUME~1\admin\APPLIC~1\dvdcss
[02/12/2008|20:35] C:\DOCUME~1\admin\APPLIC~1\GetRightToGo
[31/12/2008|15:27] C:\DOCUME~1\admin\APPLIC~1\Google
[07/08/2005|16:47] C:\DOCUME~1\admin\APPLIC~1\Help
[04/08/2005|19:18] C:\DOCUME~1\admin\APPLIC~1\Identities
[04/07/2007|17:36] C:\DOCUME~1\admin\APPLIC~1\La Bataille pour la Terre du Milieu
[06/08/2005|18:39] C:\DOCUME~1\admin\APPLIC~1\Lavasoft
[28/08/2009|14:21] C:\DOCUME~1\admin\APPLIC~1\LimeWire
[11/07/2007|20:10] C:\DOCUME~1\admin\APPLIC~1\Macromedia
[08/02/2009|23:01] C:\DOCUME~1\admin\APPLIC~1\Microsoft
[30/08/2008|16:54] C:\DOCUME~1\admin\APPLIC~1\Mozilla
[01/03/2009|10:05] C:\DOCUME~1\admin\APPLIC~1\OpenOffice.org2
[01/03/2009|20:49] C:\DOCUME~1\admin\APPLIC~1\skypePM
[04/02/2009|14:56] C:\DOCUME~1\admin\APPLIC~1\Sony
[21/10/2005|21:24] C:\DOCUME~1\admin\APPLIC~1\Sun
[10/10/2007|14:15] C:\DOCUME~1\admin\APPLIC~1\Talkback
[25/04/2009|22:09] C:\DOCUME~1\admin\APPLIC~1\teamspeak2
[30/08/2009|21:33] C:\DOCUME~1\admin\APPLIC~1\uTorrent
[29/08/2009|02:47] C:\DOCUME~1\admin\APPLIC~1\vlc
[02/11/2008|03:25] C:\DOCUME~1\admin\APPLIC~1\Winamp
[25/01/2009|17:21] C:\DOCUME~1\admin\APPLIC~1\WinAmp Control
[04/10/2007|19:53] C:\DOCUME~1\admin\APPLIC~1\WinRAR
[06/03/2006|18:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[06/03/2006|18:27] C:\DOCUME~1\ADMINI~1.LUD\APPLIC~1\Microsoft
[28/08/2009|14:41] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\BitDefender
[28/08/2009|14:40] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\DivX
[28/08/2009|21:48] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Microsoft
[28/08/2009|14:45] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Mozilla
[28/08/2009|21:55] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\vlc
[05/08/2005|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/09/2008|22:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/09/2008|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[06/03/2006|19:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\bike bleh default delete
[03/12/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[09/06/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[24/07/2009|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[07/04/2007|14:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[30/08/2009|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[11/01/2006|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[16/09/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[29/08/2009|21:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[08/10/2005|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[28/08/2009|14:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[27/12/2005|21:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\POPWWPROFILES
[18/07/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[04/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
[14/03/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[24/07/2009|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Temp
[31/10/2008|03:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Winamp Toolbar
[16/08/2005|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/03/2008|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[04/08/2005|20:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[06/08/2005|18:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[04/08/2005|20:12] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[30/08/2009 19:38][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[18/04/2009 07:59][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[30/08/2009 22:13][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
[29/08/2009 01:46][--ah-----] C:\WINDOWS\tasks\MP Scheduled Scan.job
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\AC6046079187F8D7.job
[30/08/2009 10:52][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( AC6046079187F8D7.job )=( c:\docume~1\admin\applic~1\bitsar~1\FreeBagsChic.exe )
--------------------\\ MsgPlus SPONSOR INSTALLED !
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"DisplayName"="Messenger Plus! 3 & Sponsor"
"SponsorInstalled"=dword:00000000
--------------------\\ Listing des dossiers dans C:\Program Files
[06/03/2006|19:43] C:\Program Files\Ad-Aware SE Personal
[05/08/2005|09:44] C:\Program Files\Adobe
[15/09/2007|13:11] C:\Program Files\Adverts
[07/10/2005|18:10] C:\Program Files\Ahead
[07/08/2005|13:20] C:\Program Files\albums
[26/03/2007|17:54] C:\Program Files\AlfaCleaner(2)
[07/08/2005|13:20] C:\Program Files\animation
[26/09/2008|22:15] C:\Program Files\Apple Software Update
[09/12/2005|18:43] C:\Program Files\ATI Technologies
[15/10/2008|20:35] C:\Program Files\AviSynth 2.5
[03/12/2007|15:44] C:\Program Files\BitDefender
[01/09/2005|12:00] C:\Program Files\bits army jugs
[31/12/2008|15:21] C:\Program Files\BitSpirit
[25/10/2007|19:33] C:\Program Files\BitTorrent
[21/10/2005|19:29] C:\Program Files\Blender Foundation
[07/08/2005|13:21] C:\Program Files\Calendar
[08/09/2008|21:38] C:\Program Files\CASIO
[14/04/2009|23:14] C:\Program Files\Common Files
[04/08/2005|20:09] C:\Program Files\ComPlus Applications
[07/08/2005|13:14] C:\Program Files\config
[24/07/2009|15:41] C:\Program Files\CyberLink
[18/07/2009|16:28] C:\Program Files\CyberLink DVD Solution
[19/06/2009|15:44] C:\Program Files\DivX
[21/04/2009|19:03] C:\Program Files\Ò½ï¢Ö›¶‡
[04/07/2007|17:02] C:\Program Files\EA GAMES
[26/03/2007|17:54] C:\Program Files\Edges
[25/10/2007|19:31] C:\Program Files\EHMINSTALL
[27/12/2005|14:05] C:\Program Files\Eidos
[03/01/2009|23:19] C:\Program Files\eMule
[05/08/2005|15:24] C:\Program Files\EPSON
[15/10/2008|20:34] C:\Program Files\eRightSoft
[07/08/2005|13:14] C:\Program Files\Fantasy
[24/07/2009|15:44] C:\Program Files\Fichiers communs
[26/03/2007|17:54] C:\Program Files\FlameOfLegend
[07/08/2005|13:15] C:\Program Files\Frames
[21/01/2007|19:42] C:\Program Files\Game Cam Lite v1.4
[18/07/2009|16:13] C:\Program Files\Gimp
[14/03/2007|15:19] C:\Program Files\GIMP-2.0
[30/05/2007|17:39] C:\Program Files\Google
[17/06/2009|16:03] C:\Program Files\gPotato.eu
[10/01/2007|17:12] C:\Program Files\greenstreet
[07/08/2005|13:15] C:\Program Files\greeting
[08/05/2009|15:22] C:\Program Files\GUILD WARS
[10/05/2008|19:06] C:\Program Files\GW Team Builder
[03/11/2008|16:39] C:\Program Files\GWFreaks
[24/07/2009|15:44] C:\Program Files\InstallShield Installation Information
[04/02/2009|14:34] C:\Program Files\Internet Explorer
[22/09/2006|16:40] C:\Program Files\Jasc Software Inc
[18/05/2008|22:51] C:\Program Files\Java
[16/09/2008|19:14] C:\Program Files\Lavasoft
[30/08/2006|15:41] C:\Program Files\Lemoncast
[30/04/2009|00:37] C:\Program Files\LimeWire
[30/06/2007|13:27] C:\Program Files\Logitech
[29/08/2009|21:33] C:\Program Files\Malwarebytes' Anti-Malware
[26/03/2007|17:54] C:\Program Files\Messenger
[06/02/2009|21:22] C:\Program Files\Messenger Plus! Live
[29/09/2006|18:59] C:\Program Files\MessengerPlus! 3
[04/08/2005|20:12] C:\Program Files\microsoft frontpage
[18/07/2009|16:16] C:\Program Files\Microsoft Games
[04/08/2005|20:10] C:\Program Files\Movie Maker
[30/08/2009|22:10] C:\Program Files\Mozilla Firefox
[05/08/2005|09:35] C:\Program Files\MSI
[04/08/2005|20:08] C:\Program Files\MSN
[06/03/2006|18:27] C:\Program Files\MSN Apps
[04/08/2005|20:09] C:\Program Files\MSN Gaming Zone
[09/03/2008|13:17] C:\Program Files\MSN Messenger
[03/10/2007|14:33] C:\Program Files\MSN Messenger 2
[06/03/2006|18:27] C:\Program Files\MSN Toolbar Suite
[25/10/2007|19:35] C:\Program Files\MUSICMATCH
[28/08/2005|14:14] C:\Program Files\NetMeeting
[04/08/2005|20:09] C:\Program Files\Online Services
[18/05/2008|22:53] C:\Program Files\OpenOffice.org 2.4
[16/08/2007|15:29] C:\Program Files\otron.net
[04/08/2005|20:10] C:\Program Files\Outlook Express
[13/09/2006|20:16] C:\Program Files\PhotoFiltre
[05/08/2005|15:04] C:\Program Files\Powerline Adapter
[26/09/2008|22:18] C:\Program Files\QuickTime
[05/08/2005|08:37] C:\Program Files\S3Inc
[09/10/2005|21:12] C:\Program Files\Saitek
[22/09/2005|19:46] C:\Program Files\Samples
[11/02/2009|14:13] C:\Program Files\Sarkophage
[04/08/2005|20:11] C:\Program Files\Services en ligne
[05/08/2005|09:34] C:\Program Files\Setup Files
[22/09/2005|19:47] C:\Program Files\shapes
[22/11/2005|21:08] C:\Program Files\Sierra On-Line
[18/07/2009|16:21] C:\Program Files\Skype
[16/06/2006|12:38] C:\Program Files\Slayers Online
[06/03/2006|18:28] C:\Program Files\SnadBoy's Revelation v2
[07/10/2005|18:10] C:\Program Files\Softwin
[04/02/2009|14:52] C:\Program Files\Sony
[04/02/2009|14:52] C:\Program Files\Sony Ericsson
[14/03/2007|22:25] C:\Program Files\Spybot - Search & Destroy
[04/04/2008|22:05] C:\Program Files\StepMania CVS
[07/08/2005|13:16] C:\Program Files\SysAlbum
[02/04/2006|15:25] C:\Program Files\Teamspeak2_RC2
[22/09/2005|19:47] C:\Program Files\Texture
[08/02/2009|22:58] C:\Program Files\TSO
[29/03/2006|16:22] C:\Program Files\UBISOFT
[30/01/2008|23:44] C:\Program Files\UGCP
[07/08/2005|13:19] C:\Program Files\UI
[04/08/2005|19:18] C:\Program Files\Uninstall Information
[13/06/2009|21:21] C:\Program Files\uTorrent
[14/08/2007|19:55] C:\Program Files\UxTheme Multipatcher Fr
[10/10/2007|18:33] C:\Program Files\Veoh Networks
[05/08/2005|09:32] C:\Program Files\VIA
[28/08/2009|15:58] C:\Program Files\VideoLAN
[15/10/2008|17:50] C:\Program Files\Visicom Media
[26/03/2007|17:54] C:\Program Files\Web
[03/01/2009|23:22] C:\Program Files\Winamp
[21/01/2007|19:42] C:\Program Files\Windows Defender
[16/08/2005|11:54] C:\Program Files\Windows Journal Viewer
[09/03/2008|13:19] C:\Program Files\Windows Live
[13/06/2009|21:07] C:\Program Files\Windows Media Connect 2
[06/06/2009|15:47] C:\Program Files\Windows Media Player
[04/08/2005|20:09] C:\Program Files\Windows NT
[04/08/2005|20:11] C:\Program Files\WindowsUpdate
[04/10/2007|19:53] C:\Program Files\WinRAR
[04/08/2005|20:12] C:\Program Files\xerox
[18/07/2009|16:23] C:\Program Files\Yahoo!
[07/02/2009|03:32] C:\Program Files\???????????
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/08/2005|12:19] C:\Program Files\Fichiers communs\Adobe
[05/08/2005|09:41] C:\Program Files\Fichiers communs\Ahead
[26/09/2008|22:17] C:\Program Files\Fichiers communs\Apple
[03/12/2007|15:44] C:\Program Files\Fichiers communs\BitDefender
[24/07/2009|15:44] C:\Program Files\Fichiers communs\CyberLink
[19/06/2009|15:41] C:\Program Files\Fichiers communs\DivX Shared
[29/01/2006|12:49] C:\Program Files\Fichiers communs\greenstreet
[14/03/2007|15:11] C:\Program Files\Fichiers communs\GTK
[11/01/2006|13:48] C:\Program Files\Fichiers communs\InstallShield
[21/10/2005|21:23] C:\Program Files\Fichiers communs\Java
[30/06/2007|13:20] C:\Program Files\Fichiers communs\Logitech
[04/02/2009|14:42] C:\Program Files\Fichiers communs\Microsoft Shared
[04/08/2005|20:10] C:\Program Files\Fichiers communs\MSSoap
[01/03/2099|03:17] C:\Program Files\Fichiers communs\ODBC
[04/08/2005|20:10] C:\Program Files\Fichiers communs\Services
[03/12/2007|15:36] C:\Program Files\Fichiers communs\Softwin
[04/02/2009|14:53] C:\Program Files\Fichiers communs\Sony Shared
[01/03/2099|03:17] C:\Program Files\Fichiers communs\SpeechEngines
[04/08/2005|20:10] C:\Program Files\Fichiers communs\System
[09/03/2008|13:18] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[15/10/2008|16:53] C:\Program Files\Fichiers communs\Xuisoft
--------------------\\ Process
( 45 Processes )
Iexplore.exe ~ [PID:1948]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\admin\APPLIC~1\bitsar~1
C:\Program Files\bitsar~1
C:\DOCUME~1\admin\LOCALS~1\Temp\nsl8F.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nst14A7.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nstA3.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nsv1EC.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nsy8E.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nsz1D.tmp
C:\Program Files\Adverts
C:\DOCUME~1\admin\Cookies\admin@adopt.euroclick[1].txt
C:\DOCUME~1\admin\Cookies\admin@partypoker[1].txt
C:\WINDOWS\Tasks\AC6046079187F8D7.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
--------------------\\ Recherche d'autres infections
--------------------\\ ROOTKIT !!
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV]
Trojan ! .. C:\WINDOWS\system32\TDSSservers.dat
Trojan ! .. C:\WINDOWS\system32\TDSSinit.dll
--------------------\\ Suspect ..
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
[F:5480][D:208]-> C:\DOCUME~1\admin\LOCALS~1\Temp
[F:232][D:0]-> C:\DOCUME~1\admin\Cookies
[F:1424][D:5]-> C:\DOCUME~1\admin\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 30/08/2009|22:48 - Option : [1]
--------------------\\ Fin du rapport a 22:48:47
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 2800+ )
BIOS : Version 07.00T
USER : admin ( Administrator )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:152 Go (Free:7 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 30/08/2009|22:23 )
--------------------\\ Listing des dossiers dans APPLIC~1
[18/07/2009|22:16] C:\DOCUME~1\admin\APPLIC~1\.minecraft
[07/10/2005|18:13] C:\DOCUME~1\admin\APPLIC~1\32 size slow
[04/04/2008|19:31] C:\DOCUME~1\admin\APPLIC~1\Adobe
[31/01/2009|21:56] C:\DOCUME~1\admin\APPLIC~1\AdobeUM
[14/09/2005|14:50] C:\DOCUME~1\admin\APPLIC~1\Ahead
[26/09/2008|22:25] C:\DOCUME~1\admin\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\admin\APPLIC~1\Bitdefender
[06/03/2006|18:39] C:\DOCUME~1\admin\APPLIC~1\bits army jugs
[01/10/2007|23:18] C:\DOCUME~1\admin\APPLIC~1\BitTorrent
[26/07/2009|18:50] C:\DOCUME~1\admin\APPLIC~1\Cyberlink
[15/10/2007|20:45] C:\DOCUME~1\admin\APPLIC~1\DivX
[28/08/2009|18:35] C:\DOCUME~1\admin\APPLIC~1\dvdcss
[02/12/2008|20:35] C:\DOCUME~1\admin\APPLIC~1\GetRightToGo
[31/12/2008|15:27] C:\DOCUME~1\admin\APPLIC~1\Google
[07/08/2005|16:47] C:\DOCUME~1\admin\APPLIC~1\Help
[04/08/2005|19:18] C:\DOCUME~1\admin\APPLIC~1\Identities
[04/07/2007|17:36] C:\DOCUME~1\admin\APPLIC~1\La Bataille pour la Terre du Milieu
[06/08/2005|18:39] C:\DOCUME~1\admin\APPLIC~1\Lavasoft
[28/08/2009|14:21] C:\DOCUME~1\admin\APPLIC~1\LimeWire
[11/07/2007|20:10] C:\DOCUME~1\admin\APPLIC~1\Macromedia
[08/02/2009|23:01] C:\DOCUME~1\admin\APPLIC~1\Microsoft
[30/08/2008|16:54] C:\DOCUME~1\admin\APPLIC~1\Mozilla
[01/03/2009|10:05] C:\DOCUME~1\admin\APPLIC~1\OpenOffice.org2
[01/03/2009|20:49] C:\DOCUME~1\admin\APPLIC~1\skypePM
[04/02/2009|14:56] C:\DOCUME~1\admin\APPLIC~1\Sony
[21/10/2005|21:24] C:\DOCUME~1\admin\APPLIC~1\Sun
[10/10/2007|14:15] C:\DOCUME~1\admin\APPLIC~1\Talkback
[25/04/2009|22:09] C:\DOCUME~1\admin\APPLIC~1\teamspeak2
[30/08/2009|21:33] C:\DOCUME~1\admin\APPLIC~1\uTorrent
[29/08/2009|02:47] C:\DOCUME~1\admin\APPLIC~1\vlc
[02/11/2008|03:25] C:\DOCUME~1\admin\APPLIC~1\Winamp
[25/01/2009|17:21] C:\DOCUME~1\admin\APPLIC~1\WinAmp Control
[04/10/2007|19:53] C:\DOCUME~1\admin\APPLIC~1\WinRAR
[06/03/2006|18:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[06/03/2006|18:27] C:\DOCUME~1\ADMINI~1.LUD\APPLIC~1\Microsoft
[28/08/2009|14:41] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\BitDefender
[28/08/2009|14:40] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\DivX
[28/08/2009|21:48] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Microsoft
[28/08/2009|14:45] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Mozilla
[28/08/2009|21:55] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\vlc
[05/08/2005|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/09/2008|22:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/09/2008|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[06/03/2006|19:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\bike bleh default delete
[03/12/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[09/06/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[24/07/2009|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[07/04/2007|14:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[30/08/2009|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[11/01/2006|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[16/09/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[29/08/2009|21:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[08/10/2005|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[28/08/2009|14:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[27/12/2005|21:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\POPWWPROFILES
[18/07/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[04/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
[14/03/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[24/07/2009|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Temp
[31/10/2008|03:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Winamp Toolbar
[16/08/2005|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/03/2008|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[04/08/2005|20:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[06/08/2005|18:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[04/08/2005|20:12] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[30/08/2009 19:38][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[18/04/2009 07:59][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[30/08/2009 22:13][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
[29/08/2009 01:46][--ah-----] C:\WINDOWS\tasks\MP Scheduled Scan.job
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\AC6046079187F8D7.job
[30/08/2009 10:52][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( AC6046079187F8D7.job )=( c:\docume~1\admin\applic~1\bitsar~1\FreeBagsChic.exe )
--------------------\\ MsgPlus SPONSOR INSTALLED !
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"DisplayName"="Messenger Plus! 3 & Sponsor"
"SponsorInstalled"=dword:00000000
--------------------\\ Listing des dossiers dans C:\Program Files
[06/03/2006|19:43] C:\Program Files\Ad-Aware SE Personal
[05/08/2005|09:44] C:\Program Files\Adobe
[15/09/2007|13:11] C:\Program Files\Adverts
[07/10/2005|18:10] C:\Program Files\Ahead
[07/08/2005|13:20] C:\Program Files\albums
[26/03/2007|17:54] C:\Program Files\AlfaCleaner(2)
[07/08/2005|13:20] C:\Program Files\animation
[26/09/2008|22:15] C:\Program Files\Apple Software Update
[09/12/2005|18:43] C:\Program Files\ATI Technologies
[15/10/2008|20:35] C:\Program Files\AviSynth 2.5
[03/12/2007|15:44] C:\Program Files\BitDefender
[01/09/2005|12:00] C:\Program Files\bits army jugs
[31/12/2008|15:21] C:\Program Files\BitSpirit
[25/10/2007|19:33] C:\Program Files\BitTorrent
[21/10/2005|19:29] C:\Program Files\Blender Foundation
[07/08/2005|13:21] C:\Program Files\Calendar
[08/09/2008|21:38] C:\Program Files\CASIO
[14/04/2009|23:14] C:\Program Files\Common Files
[04/08/2005|20:09] C:\Program Files\ComPlus Applications
[07/08/2005|13:14] C:\Program Files\config
[24/07/2009|15:41] C:\Program Files\CyberLink
[18/07/2009|16:28] C:\Program Files\CyberLink DVD Solution
[19/06/2009|15:44] C:\Program Files\DivX
[21/04/2009|19:03] C:\Program Files\Ò½ï¢Ö›¶‡
[04/07/2007|17:02] C:\Program Files\EA GAMES
[26/03/2007|17:54] C:\Program Files\Edges
[25/10/2007|19:31] C:\Program Files\EHMINSTALL
[27/12/2005|14:05] C:\Program Files\Eidos
[03/01/2009|23:19] C:\Program Files\eMule
[05/08/2005|15:24] C:\Program Files\EPSON
[15/10/2008|20:34] C:\Program Files\eRightSoft
[07/08/2005|13:14] C:\Program Files\Fantasy
[24/07/2009|15:44] C:\Program Files\Fichiers communs
[26/03/2007|17:54] C:\Program Files\FlameOfLegend
[07/08/2005|13:15] C:\Program Files\Frames
[21/01/2007|19:42] C:\Program Files\Game Cam Lite v1.4
[18/07/2009|16:13] C:\Program Files\Gimp
[14/03/2007|15:19] C:\Program Files\GIMP-2.0
[30/05/2007|17:39] C:\Program Files\Google
[17/06/2009|16:03] C:\Program Files\gPotato.eu
[10/01/2007|17:12] C:\Program Files\greenstreet
[07/08/2005|13:15] C:\Program Files\greeting
[08/05/2009|15:22] C:\Program Files\GUILD WARS
[10/05/2008|19:06] C:\Program Files\GW Team Builder
[03/11/2008|16:39] C:\Program Files\GWFreaks
[24/07/2009|15:44] C:\Program Files\InstallShield Installation Information
[04/02/2009|14:34] C:\Program Files\Internet Explorer
[22/09/2006|16:40] C:\Program Files\Jasc Software Inc
[18/05/2008|22:51] C:\Program Files\Java
[16/09/2008|19:14] C:\Program Files\Lavasoft
[30/08/2006|15:41] C:\Program Files\Lemoncast
[30/04/2009|00:37] C:\Program Files\LimeWire
[30/06/2007|13:27] C:\Program Files\Logitech
[29/08/2009|21:33] C:\Program Files\Malwarebytes' Anti-Malware
[26/03/2007|17:54] C:\Program Files\Messenger
[06/02/2009|21:22] C:\Program Files\Messenger Plus! Live
[29/09/2006|18:59] C:\Program Files\MessengerPlus! 3
[04/08/2005|20:12] C:\Program Files\microsoft frontpage
[18/07/2009|16:16] C:\Program Files\Microsoft Games
[04/08/2005|20:10] C:\Program Files\Movie Maker
[30/08/2009|22:10] C:\Program Files\Mozilla Firefox
[05/08/2005|09:35] C:\Program Files\MSI
[04/08/2005|20:08] C:\Program Files\MSN
[06/03/2006|18:27] C:\Program Files\MSN Apps
[04/08/2005|20:09] C:\Program Files\MSN Gaming Zone
[09/03/2008|13:17] C:\Program Files\MSN Messenger
[03/10/2007|14:33] C:\Program Files\MSN Messenger 2
[06/03/2006|18:27] C:\Program Files\MSN Toolbar Suite
[25/10/2007|19:35] C:\Program Files\MUSICMATCH
[28/08/2005|14:14] C:\Program Files\NetMeeting
[04/08/2005|20:09] C:\Program Files\Online Services
[18/05/2008|22:53] C:\Program Files\OpenOffice.org 2.4
[16/08/2007|15:29] C:\Program Files\otron.net
[04/08/2005|20:10] C:\Program Files\Outlook Express
[13/09/2006|20:16] C:\Program Files\PhotoFiltre
[05/08/2005|15:04] C:\Program Files\Powerline Adapter
[26/09/2008|22:18] C:\Program Files\QuickTime
[05/08/2005|08:37] C:\Program Files\S3Inc
[09/10/2005|21:12] C:\Program Files\Saitek
[22/09/2005|19:46] C:\Program Files\Samples
[11/02/2009|14:13] C:\Program Files\Sarkophage
[04/08/2005|20:11] C:\Program Files\Services en ligne
[05/08/2005|09:34] C:\Program Files\Setup Files
[22/09/2005|19:47] C:\Program Files\shapes
[22/11/2005|21:08] C:\Program Files\Sierra On-Line
[18/07/2009|16:21] C:\Program Files\Skype
[16/06/2006|12:38] C:\Program Files\Slayers Online
[06/03/2006|18:28] C:\Program Files\SnadBoy's Revelation v2
[07/10/2005|18:10] C:\Program Files\Softwin
[04/02/2009|14:52] C:\Program Files\Sony
[04/02/2009|14:52] C:\Program Files\Sony Ericsson
[14/03/2007|22:25] C:\Program Files\Spybot - Search & Destroy
[04/04/2008|22:05] C:\Program Files\StepMania CVS
[07/08/2005|13:16] C:\Program Files\SysAlbum
[02/04/2006|15:25] C:\Program Files\Teamspeak2_RC2
[22/09/2005|19:47] C:\Program Files\Texture
[08/02/2009|22:58] C:\Program Files\TSO
[29/03/2006|16:22] C:\Program Files\UBISOFT
[30/01/2008|23:44] C:\Program Files\UGCP
[07/08/2005|13:19] C:\Program Files\UI
[04/08/2005|19:18] C:\Program Files\Uninstall Information
[13/06/2009|21:21] C:\Program Files\uTorrent
[14/08/2007|19:55] C:\Program Files\UxTheme Multipatcher Fr
[10/10/2007|18:33] C:\Program Files\Veoh Networks
[05/08/2005|09:32] C:\Program Files\VIA
[28/08/2009|15:58] C:\Program Files\VideoLAN
[15/10/2008|17:50] C:\Program Files\Visicom Media
[26/03/2007|17:54] C:\Program Files\Web
[03/01/2009|23:22] C:\Program Files\Winamp
[21/01/2007|19:42] C:\Program Files\Windows Defender
[16/08/2005|11:54] C:\Program Files\Windows Journal Viewer
[09/03/2008|13:19] C:\Program Files\Windows Live
[13/06/2009|21:07] C:\Program Files\Windows Media Connect 2
[06/06/2009|15:47] C:\Program Files\Windows Media Player
[04/08/2005|20:09] C:\Program Files\Windows NT
[04/08/2005|20:11] C:\Program Files\WindowsUpdate
[04/10/2007|19:53] C:\Program Files\WinRAR
[04/08/2005|20:12] C:\Program Files\xerox
[18/07/2009|16:23] C:\Program Files\Yahoo!
[07/02/2009|03:32] C:\Program Files\???????????
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/08/2005|12:19] C:\Program Files\Fichiers communs\Adobe
[05/08/2005|09:41] C:\Program Files\Fichiers communs\Ahead
[26/09/2008|22:17] C:\Program Files\Fichiers communs\Apple
[03/12/2007|15:44] C:\Program Files\Fichiers communs\BitDefender
[24/07/2009|15:44] C:\Program Files\Fichiers communs\CyberLink
[19/06/2009|15:41] C:\Program Files\Fichiers communs\DivX Shared
[29/01/2006|12:49] C:\Program Files\Fichiers communs\greenstreet
[14/03/2007|15:11] C:\Program Files\Fichiers communs\GTK
[11/01/2006|13:48] C:\Program Files\Fichiers communs\InstallShield
[21/10/2005|21:23] C:\Program Files\Fichiers communs\Java
[30/06/2007|13:20] C:\Program Files\Fichiers communs\Logitech
[04/02/2009|14:42] C:\Program Files\Fichiers communs\Microsoft Shared
[04/08/2005|20:10] C:\Program Files\Fichiers communs\MSSoap
[01/03/2099|03:17] C:\Program Files\Fichiers communs\ODBC
[04/08/2005|20:10] C:\Program Files\Fichiers communs\Services
[03/12/2007|15:36] C:\Program Files\Fichiers communs\Softwin
[04/02/2009|14:53] C:\Program Files\Fichiers communs\Sony Shared
[01/03/2099|03:17] C:\Program Files\Fichiers communs\SpeechEngines
[04/08/2005|20:10] C:\Program Files\Fichiers communs\System
[09/03/2008|13:18] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[15/10/2008|16:53] C:\Program Files\Fichiers communs\Xuisoft
--------------------\\ Process
( 45 Processes )
Iexplore.exe ~ [PID:1948]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\admin\APPLIC~1\bitsar~1
C:\Program Files\bitsar~1
C:\DOCUME~1\admin\LOCALS~1\Temp\nsl8F.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nst14A7.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nstA3.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nsv1EC.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nsy8E.tmp
C:\DOCUME~1\admin\LOCALS~1\Temp\nsz1D.tmp
C:\Program Files\Adverts
C:\DOCUME~1\admin\Cookies\admin@adopt.euroclick[1].txt
C:\DOCUME~1\admin\Cookies\admin@partypoker[1].txt
C:\WINDOWS\Tasks\AC6046079187F8D7.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
--------------------\\ Recherche d'autres infections
--------------------\\ ROOTKIT !!
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV]
Trojan ! .. C:\WINDOWS\system32\TDSSservers.dat
Trojan ! .. C:\WINDOWS\system32\TDSSinit.dll
--------------------\\ Suspect ..
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
[F:5480][D:208]-> C:\DOCUME~1\admin\LOCALS~1\Temp
[F:232][D:0]-> C:\DOCUME~1\admin\Cookies
[F:1424][D:5]-> C:\DOCUME~1\admin\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 30/08/2009|22:48 - Option : [1]
--------------------\\ Fin du rapport a 22:48:47
Pour Malwarebytes' Anti-Malware, c'est normal qu'il plante, tu as le rootkit TDSS. On s'en occupera après avec ComboFix.
Relance Lop S&D.
(Sous Vista, il faut cliquer droit sur le raccourci Lop S&D et choisir Exécuter en tant qu'administrateur)
Choisis cette fois-ci l'option 2 (Suppression).
Ne ferme pas la fenêtre lors de la suppression !
Poste le rapport généré (C:\lopR.txt).
(Si le Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
(Sous Vista, il faut cliquer droit sur le raccourci Lop S&D et choisir Exécuter en tant qu'administrateur)
(Si le Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
Wah, mon PC était blindé >.<
Juste petite info au cas ou : C:\Program Files\???????????
C'est un jeu vidéo japonais, c'est pour ça le nom bizar
.
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 2800+ )
BIOS : Version 07.00T
USER : admin ( Administrator )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:152 Go (Free:7 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 30/08/2009|22:58 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsl8F.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nst14A7.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nstA3.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsv1EC.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsy8E.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsz1D.tmp
Supprime! - C:\DOCUME~1\admin\Cookies\admin@adopt.euroclick[1].txt
Supprime! - C:\DOCUME~1\admin\Cookies\admin@partypoker[1].txt
Supprime! - C:\WINDOWS\Tasks\AC6046079187F8D7.job
Supprime! - C:\DOCUME~1\admin\APPLIC~1\bitsar~1
Supprime! - C:\Program Files\bitsar~1
Supprime! - C:\Program Files\Adverts
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[18/07/2009|22:16] C:\DOCUME~1\admin\APPLIC~1\.minecraft
[07/10/2005|18:13] C:\DOCUME~1\admin\APPLIC~1\32 size slow
[04/04/2008|19:31] C:\DOCUME~1\admin\APPLIC~1\Adobe
[31/01/2009|21:56] C:\DOCUME~1\admin\APPLIC~1\AdobeUM
[14/09/2005|14:50] C:\DOCUME~1\admin\APPLIC~1\Ahead
[26/09/2008|22:25] C:\DOCUME~1\admin\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\admin\APPLIC~1\Bitdefender
[01/10/2007|23:18] C:\DOCUME~1\admin\APPLIC~1\BitTorrent
[26/07/2009|18:50] C:\DOCUME~1\admin\APPLIC~1\Cyberlink
[15/10/2007|20:45] C:\DOCUME~1\admin\APPLIC~1\DivX
[28/08/2009|18:35] C:\DOCUME~1\admin\APPLIC~1\dvdcss
[02/12/2008|20:35] C:\DOCUME~1\admin\APPLIC~1\GetRightToGo
[31/12/2008|15:27] C:\DOCUME~1\admin\APPLIC~1\Google
[07/08/2005|16:47] C:\DOCUME~1\admin\APPLIC~1\Help
[04/08/2005|19:18] C:\DOCUME~1\admin\APPLIC~1\Identities
[04/07/2007|17:36] C:\DOCUME~1\admin\APPLIC~1\La Bataille pour la Terre du Milieu
[06/08/2005|18:39] C:\DOCUME~1\admin\APPLIC~1\Lavasoft
[28/08/2009|14:21] C:\DOCUME~1\admin\APPLIC~1\LimeWire
[11/07/2007|20:10] C:\DOCUME~1\admin\APPLIC~1\Macromedia
[08/02/2009|23:01] C:\DOCUME~1\admin\APPLIC~1\Microsoft
[30/08/2008|16:54] C:\DOCUME~1\admin\APPLIC~1\Mozilla
[01/03/2009|10:05] C:\DOCUME~1\admin\APPLIC~1\OpenOffice.org2
[01/03/2009|20:49] C:\DOCUME~1\admin\APPLIC~1\skypePM
[04/02/2009|14:56] C:\DOCUME~1\admin\APPLIC~1\Sony
[21/10/2005|21:24] C:\DOCUME~1\admin\APPLIC~1\Sun
[10/10/2007|14:15] C:\DOCUME~1\admin\APPLIC~1\Talkback
[25/04/2009|22:09] C:\DOCUME~1\admin\APPLIC~1\teamspeak2
[30/08/2009|21:33] C:\DOCUME~1\admin\APPLIC~1\uTorrent
[29/08/2009|02:47] C:\DOCUME~1\admin\APPLIC~1\vlc
[02/11/2008|03:25] C:\DOCUME~1\admin\APPLIC~1\Winamp
[25/01/2009|17:21] C:\DOCUME~1\admin\APPLIC~1\WinAmp Control
[04/10/2007|19:53] C:\DOCUME~1\admin\APPLIC~1\WinRAR
[06/03/2006|18:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[06/03/2006|18:27] C:\DOCUME~1\ADMINI~1.LUD\APPLIC~1\Microsoft
[28/08/2009|14:41] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\BitDefender
[28/08/2009|14:40] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\DivX
[28/08/2009|21:48] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Microsoft
[28/08/2009|14:45] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Mozilla
[28/08/2009|21:55] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\vlc
[05/08/2005|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/09/2008|22:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/09/2008|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[06/03/2006|19:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\bike bleh default delete
[03/12/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[09/06/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[24/07/2009|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[07/04/2007|14:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[30/08/2009|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[11/01/2006|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[16/09/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[29/08/2009|21:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[08/10/2005|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[28/08/2009|14:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[27/12/2005|21:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\POPWWPROFILES
[18/07/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[04/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
[14/03/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[24/07/2009|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Temp
[31/10/2008|03:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Winamp Toolbar
[16/08/2005|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/03/2008|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[04/08/2005|20:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[06/08/2005|18:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[04/08/2005|20:12] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[30/08/2009 19:38][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[18/04/2009 07:59][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[30/08/2009 22:58][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
[29/08/2009 01:46][--ah-----] C:\WINDOWS\tasks\MP Scheduled Scan.job
[30/08/2009 10:52][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ MsgPlus SPONSOR INSTALLED !
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"SponsorInstalled"=dword:00000000
--------------------\\ Listing des dossiers dans C:\Program Files
[06/03/2006|19:43] C:\Program Files\Ad-Aware SE Personal
[05/08/2005|09:44] C:\Program Files\Adobe
[07/10/2005|18:10] C:\Program Files\Ahead
[07/08/2005|13:20] C:\Program Files\albums
[26/03/2007|17:54] C:\Program Files\AlfaCleaner(2)
[07/08/2005|13:20] C:\Program Files\animation
[26/09/2008|22:15] C:\Program Files\Apple Software Update
[09/12/2005|18:43] C:\Program Files\ATI Technologies
[15/10/2008|20:35] C:\Program Files\AviSynth 2.5
[03/12/2007|15:44] C:\Program Files\BitDefender
[31/12/2008|15:21] C:\Program Files\BitSpirit
[25/10/2007|19:33] C:\Program Files\BitTorrent
[21/10/2005|19:29] C:\Program Files\Blender Foundation
[07/08/2005|13:21] C:\Program Files\Calendar
[08/09/2008|21:38] C:\Program Files\CASIO
[14/04/2009|23:14] C:\Program Files\Common Files
[04/08/2005|20:09] C:\Program Files\ComPlus Applications
[07/08/2005|13:14] C:\Program Files\config
[24/07/2009|15:41] C:\Program Files\CyberLink
[18/07/2009|16:28] C:\Program Files\CyberLink DVD Solution
[19/06/2009|15:44] C:\Program Files\DivX
[21/04/2009|19:03] C:\Program Files\Ò½ï¢Ö›¶‡
[04/07/2007|17:02] C:\Program Files\EA GAMES
[26/03/2007|17:54] C:\Program Files\Edges
[25/10/2007|19:31] C:\Program Files\EHMINSTALL
[27/12/2005|14:05] C:\Program Files\Eidos
[03/01/2009|23:19] C:\Program Files\eMule
[05/08/2005|15:24] C:\Program Files\EPSON
[15/10/2008|20:34] C:\Program Files\eRightSoft
[07/08/2005|13:14] C:\Program Files\Fantasy
[24/07/2009|15:44] C:\Program Files\Fichiers communs
[26/03/2007|17:54] C:\Program Files\FlameOfLegend
[07/08/2005|13:15] C:\Program Files\Frames
[21/01/2007|19:42] C:\Program Files\Game Cam Lite v1.4
[18/07/2009|16:13] C:\Program Files\Gimp
[14/03/2007|15:19] C:\Program Files\GIMP-2.0
[30/05/2007|17:39] C:\Program Files\Google
[17/06/2009|16:03] C:\Program Files\gPotato.eu
[10/01/2007|17:12] C:\Program Files\greenstreet
[07/08/2005|13:15] C:\Program Files\greeting
[08/05/2009|15:22] C:\Program Files\GUILD WARS
[10/05/2008|19:06] C:\Program Files\GW Team Builder
[03/11/2008|16:39] C:\Program Files\GWFreaks
[24/07/2009|15:44] C:\Program Files\InstallShield Installation Information
[04/02/2009|14:34] C:\Program Files\Internet Explorer
[22/09/2006|16:40] C:\Program Files\Jasc Software Inc
[18/05/2008|22:51] C:\Program Files\Java
[16/09/2008|19:14] C:\Program Files\Lavasoft
[30/08/2006|15:41] C:\Program Files\Lemoncast
[30/04/2009|00:37] C:\Program Files\LimeWire
[30/06/2007|13:27] C:\Program Files\Logitech
[29/08/2009|21:33] C:\Program Files\Malwarebytes' Anti-Malware
[26/03/2007|17:54] C:\Program Files\Messenger
[06/02/2009|21:22] C:\Program Files\Messenger Plus! Live
[29/09/2006|18:59] C:\Program Files\MessengerPlus! 3
[04/08/2005|20:12] C:\Program Files\microsoft frontpage
[18/07/2009|16:16] C:\Program Files\Microsoft Games
[04/08/2005|20:10] C:\Program Files\Movie Maker
[30/08/2009|22:10] C:\Program Files\Mozilla Firefox
[05/08/2005|09:35] C:\Program Files\MSI
[04/08/2005|20:08] C:\Program Files\MSN
[06/03/2006|18:27] C:\Program Files\MSN Apps
[04/08/2005|20:09] C:\Program Files\MSN Gaming Zone
[09/03/2008|13:17] C:\Program Files\MSN Messenger
[03/10/2007|14:33] C:\Program Files\MSN Messenger 2
[06/03/2006|18:27] C:\Program Files\MSN Toolbar Suite
[25/10/2007|19:35] C:\Program Files\MUSICMATCH
[28/08/2005|14:14] C:\Program Files\NetMeeting
[04/08/2005|20:09] C:\Program Files\Online Services
[18/05/2008|22:53] C:\Program Files\OpenOffice.org 2.4
[16/08/2007|15:29] C:\Program Files\otron.net
[04/08/2005|20:10] C:\Program Files\Outlook Express
[13/09/2006|20:16] C:\Program Files\PhotoFiltre
[05/08/2005|15:04] C:\Program Files\Powerline Adapter
[26/09/2008|22:18] C:\Program Files\QuickTime
[05/08/2005|08:37] C:\Program Files\S3Inc
[09/10/2005|21:12] C:\Program Files\Saitek
[22/09/2005|19:46] C:\Program Files\Samples
[11/02/2009|14:13] C:\Program Files\Sarkophage
[04/08/2005|20:11] C:\Program Files\Services en ligne
[05/08/2005|09:34] C:\Program Files\Setup Files
[22/09/2005|19:47] C:\Program Files\shapes
[22/11/2005|21:08] C:\Program Files\Sierra On-Line
[18/07/2009|16:21] C:\Program Files\Skype
[16/06/2006|12:38] C:\Program Files\Slayers Online
[06/03/2006|18:28] C:\Program Files\SnadBoy's Revelation v2
[07/10/2005|18:10] C:\Program Files\Softwin
[04/02/2009|14:52] C:\Program Files\Sony
[04/02/2009|14:52] C:\Program Files\Sony Ericsson
[14/03/2007|22:25] C:\Program Files\Spybot - Search & Destroy
[04/04/2008|22:05] C:\Program Files\StepMania CVS
[07/08/2005|13:16] C:\Program Files\SysAlbum
[02/04/2006|15:25] C:\Program Files\Teamspeak2_RC2
[22/09/2005|19:47] C:\Program Files\Texture
[08/02/2009|22:58] C:\Program Files\TSO
[29/03/2006|16:22] C:\Program Files\UBISOFT
[30/01/2008|23:44] C:\Program Files\UGCP
[07/08/2005|13:19] C:\Program Files\UI
[04/08/2005|19:18] C:\Program Files\Uninstall Information
[13/06/2009|21:21] C:\Program Files\uTorrent
[14/08/2007|19:55] C:\Program Files\UxTheme Multipatcher Fr
[10/10/2007|18:33] C:\Program Files\Veoh Networks
[05/08/2005|09:32] C:\Program Files\VIA
[28/08/2009|15:58] C:\Program Files\VideoLAN
[15/10/2008|17:50] C:\Program Files\Visicom Media
[26/03/2007|17:54] C:\Program Files\Web
[03/01/2009|23:22] C:\Program Files\Winamp
[21/01/2007|19:42] C:\Program Files\Windows Defender
[16/08/2005|11:54] C:\Program Files\Windows Journal Viewer
[09/03/2008|13:19] C:\Program Files\Windows Live
[13/06/2009|21:07] C:\Program Files\Windows Media Connect 2
[06/06/2009|15:47] C:\Program Files\Windows Media Player
[04/08/2005|20:09] C:\Program Files\Windows NT
[04/08/2005|20:11] C:\Program Files\WindowsUpdate
[04/10/2007|19:53] C:\Program Files\WinRAR
[04/08/2005|20:12] C:\Program Files\xerox
[18/07/2009|16:23] C:\Program Files\Yahoo!
[07/02/2009|03:32] C:\Program Files\???????????
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/08/2005|12:19] C:\Program Files\Fichiers communs\Adobe
[05/08/2005|09:41] C:\Program Files\Fichiers communs\Ahead
[26/09/2008|22:17] C:\Program Files\Fichiers communs\Apple
[03/12/2007|15:44] C:\Program Files\Fichiers communs\BitDefender
[24/07/2009|15:44] C:\Program Files\Fichiers communs\CyberLink
[19/06/2009|15:41] C:\Program Files\Fichiers communs\DivX Shared
[29/01/2006|12:49] C:\Program Files\Fichiers communs\greenstreet
[14/03/2007|15:11] C:\Program Files\Fichiers communs\GTK
[11/01/2006|13:48] C:\Program Files\Fichiers communs\InstallShield
[21/10/2005|21:23] C:\Program Files\Fichiers communs\Java
[30/06/2007|13:20] C:\Program Files\Fichiers communs\Logitech
[04/02/2009|14:42] C:\Program Files\Fichiers communs\Microsoft Shared
[04/08/2005|20:10] C:\Program Files\Fichiers communs\MSSoap
[01/03/2099|03:17] C:\Program Files\Fichiers communs\ODBC
[04/08/2005|20:10] C:\Program Files\Fichiers communs\Services
[03/12/2007|15:36] C:\Program Files\Fichiers communs\Softwin
[04/02/2009|14:53] C:\Program Files\Fichiers communs\Sony Shared
[01/03/2099|03:17] C:\Program Files\Fichiers communs\SpeechEngines
[04/08/2005|20:10] C:\Program Files\Fichiers communs\System
[09/03/2008|13:18] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[15/10/2008|16:53] C:\Program Files\Fichiers communs\Xuisoft
--------------------\\ Process
( 44 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
--------------------\\ Recherche d'autres infections
--------------------\\ ROOTKIT !!
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV]
Trojan ! .. C:\WINDOWS\system32\TDSSservers.dat
Trojan ! .. C:\WINDOWS\system32\TDSSinit.dll
--------------------\\ Suspect ..
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
[F:5455][D:203]-> C:\DOCUME~1\admin\LOCALS~1\Temp
[F:230][D:0]-> C:\DOCUME~1\admin\Cookies
[F:1432][D:5]-> C:\DOCUME~1\admin\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 30/08/2009|22:48 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 30/08/2009|23:16 - Option : [2]
--------------------\\ Fin du rapport a 23:16:20
Juste petite info au cas ou : C:\Program Files\???????????
C'est un jeu vidéo japonais, c'est pour ça le nom bizar
.--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 2800+ )
BIOS : Version 07.00T
USER : admin ( Administrator )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:152 Go (Free:7 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 30/08/2009|22:58 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsl8F.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nst14A7.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nstA3.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsv1EC.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsy8E.tmp
Supprime! - C:\DOCUME~1\admin\LOCALS~1\Temp\nsz1D.tmp
Supprime! - C:\DOCUME~1\admin\Cookies\admin@adopt.euroclick[1].txt
Supprime! - C:\DOCUME~1\admin\Cookies\admin@partypoker[1].txt
Supprime! - C:\WINDOWS\Tasks\AC6046079187F8D7.job
Supprime! - C:\DOCUME~1\admin\APPLIC~1\bitsar~1
Supprime! - C:\Program Files\bitsar~1
Supprime! - C:\Program Files\Adverts
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[18/07/2009|22:16] C:\DOCUME~1\admin\APPLIC~1\.minecraft
[07/10/2005|18:13] C:\DOCUME~1\admin\APPLIC~1\32 size slow
[04/04/2008|19:31] C:\DOCUME~1\admin\APPLIC~1\Adobe
[31/01/2009|21:56] C:\DOCUME~1\admin\APPLIC~1\AdobeUM
[14/09/2005|14:50] C:\DOCUME~1\admin\APPLIC~1\Ahead
[26/09/2008|22:25] C:\DOCUME~1\admin\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\admin\APPLIC~1\Bitdefender
[01/10/2007|23:18] C:\DOCUME~1\admin\APPLIC~1\BitTorrent
[26/07/2009|18:50] C:\DOCUME~1\admin\APPLIC~1\Cyberlink
[15/10/2007|20:45] C:\DOCUME~1\admin\APPLIC~1\DivX
[28/08/2009|18:35] C:\DOCUME~1\admin\APPLIC~1\dvdcss
[02/12/2008|20:35] C:\DOCUME~1\admin\APPLIC~1\GetRightToGo
[31/12/2008|15:27] C:\DOCUME~1\admin\APPLIC~1\Google
[07/08/2005|16:47] C:\DOCUME~1\admin\APPLIC~1\Help
[04/08/2005|19:18] C:\DOCUME~1\admin\APPLIC~1\Identities
[04/07/2007|17:36] C:\DOCUME~1\admin\APPLIC~1\La Bataille pour la Terre du Milieu
[06/08/2005|18:39] C:\DOCUME~1\admin\APPLIC~1\Lavasoft
[28/08/2009|14:21] C:\DOCUME~1\admin\APPLIC~1\LimeWire
[11/07/2007|20:10] C:\DOCUME~1\admin\APPLIC~1\Macromedia
[08/02/2009|23:01] C:\DOCUME~1\admin\APPLIC~1\Microsoft
[30/08/2008|16:54] C:\DOCUME~1\admin\APPLIC~1\Mozilla
[01/03/2009|10:05] C:\DOCUME~1\admin\APPLIC~1\OpenOffice.org2
[01/03/2009|20:49] C:\DOCUME~1\admin\APPLIC~1\skypePM
[04/02/2009|14:56] C:\DOCUME~1\admin\APPLIC~1\Sony
[21/10/2005|21:24] C:\DOCUME~1\admin\APPLIC~1\Sun
[10/10/2007|14:15] C:\DOCUME~1\admin\APPLIC~1\Talkback
[25/04/2009|22:09] C:\DOCUME~1\admin\APPLIC~1\teamspeak2
[30/08/2009|21:33] C:\DOCUME~1\admin\APPLIC~1\uTorrent
[29/08/2009|02:47] C:\DOCUME~1\admin\APPLIC~1\vlc
[02/11/2008|03:25] C:\DOCUME~1\admin\APPLIC~1\Winamp
[25/01/2009|17:21] C:\DOCUME~1\admin\APPLIC~1\WinAmp Control
[04/10/2007|19:53] C:\DOCUME~1\admin\APPLIC~1\WinRAR
[06/03/2006|18:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[06/03/2006|18:27] C:\DOCUME~1\ADMINI~1.LUD\APPLIC~1\Microsoft
[28/08/2009|14:41] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\BitDefender
[28/08/2009|14:40] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\DivX
[28/08/2009|21:48] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Microsoft
[28/08/2009|14:45] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Mozilla
[28/08/2009|21:55] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\vlc
[05/08/2005|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/09/2008|22:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/09/2008|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[06/03/2006|19:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\bike bleh default delete
[03/12/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[09/06/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[24/07/2009|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[07/04/2007|14:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[30/08/2009|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[11/01/2006|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[16/09/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[29/08/2009|21:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[08/10/2005|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[28/08/2009|14:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[27/12/2005|21:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\POPWWPROFILES
[18/07/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[04/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
[14/03/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[24/07/2009|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Temp
[31/10/2008|03:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Winamp Toolbar
[16/08/2005|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/03/2008|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[04/08/2005|20:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[06/08/2005|18:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[04/08/2005|20:12] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[30/08/2009 22:00][--ah-----] C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[30/08/2009 19:38][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[18/04/2009 07:59][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[30/08/2009 22:58][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
[29/08/2009 01:46][--ah-----] C:\WINDOWS\tasks\MP Scheduled Scan.job
[30/08/2009 10:52][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ MsgPlus SPONSOR INSTALLED !
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"SponsorInstalled"=dword:00000000
--------------------\\ Listing des dossiers dans C:\Program Files
[06/03/2006|19:43] C:\Program Files\Ad-Aware SE Personal
[05/08/2005|09:44] C:\Program Files\Adobe
[07/10/2005|18:10] C:\Program Files\Ahead
[07/08/2005|13:20] C:\Program Files\albums
[26/03/2007|17:54] C:\Program Files\AlfaCleaner(2)
[07/08/2005|13:20] C:\Program Files\animation
[26/09/2008|22:15] C:\Program Files\Apple Software Update
[09/12/2005|18:43] C:\Program Files\ATI Technologies
[15/10/2008|20:35] C:\Program Files\AviSynth 2.5
[03/12/2007|15:44] C:\Program Files\BitDefender
[31/12/2008|15:21] C:\Program Files\BitSpirit
[25/10/2007|19:33] C:\Program Files\BitTorrent
[21/10/2005|19:29] C:\Program Files\Blender Foundation
[07/08/2005|13:21] C:\Program Files\Calendar
[08/09/2008|21:38] C:\Program Files\CASIO
[14/04/2009|23:14] C:\Program Files\Common Files
[04/08/2005|20:09] C:\Program Files\ComPlus Applications
[07/08/2005|13:14] C:\Program Files\config
[24/07/2009|15:41] C:\Program Files\CyberLink
[18/07/2009|16:28] C:\Program Files\CyberLink DVD Solution
[19/06/2009|15:44] C:\Program Files\DivX
[21/04/2009|19:03] C:\Program Files\Ò½ï¢Ö›¶‡
[04/07/2007|17:02] C:\Program Files\EA GAMES
[26/03/2007|17:54] C:\Program Files\Edges
[25/10/2007|19:31] C:\Program Files\EHMINSTALL
[27/12/2005|14:05] C:\Program Files\Eidos
[03/01/2009|23:19] C:\Program Files\eMule
[05/08/2005|15:24] C:\Program Files\EPSON
[15/10/2008|20:34] C:\Program Files\eRightSoft
[07/08/2005|13:14] C:\Program Files\Fantasy
[24/07/2009|15:44] C:\Program Files\Fichiers communs
[26/03/2007|17:54] C:\Program Files\FlameOfLegend
[07/08/2005|13:15] C:\Program Files\Frames
[21/01/2007|19:42] C:\Program Files\Game Cam Lite v1.4
[18/07/2009|16:13] C:\Program Files\Gimp
[14/03/2007|15:19] C:\Program Files\GIMP-2.0
[30/05/2007|17:39] C:\Program Files\Google
[17/06/2009|16:03] C:\Program Files\gPotato.eu
[10/01/2007|17:12] C:\Program Files\greenstreet
[07/08/2005|13:15] C:\Program Files\greeting
[08/05/2009|15:22] C:\Program Files\GUILD WARS
[10/05/2008|19:06] C:\Program Files\GW Team Builder
[03/11/2008|16:39] C:\Program Files\GWFreaks
[24/07/2009|15:44] C:\Program Files\InstallShield Installation Information
[04/02/2009|14:34] C:\Program Files\Internet Explorer
[22/09/2006|16:40] C:\Program Files\Jasc Software Inc
[18/05/2008|22:51] C:\Program Files\Java
[16/09/2008|19:14] C:\Program Files\Lavasoft
[30/08/2006|15:41] C:\Program Files\Lemoncast
[30/04/2009|00:37] C:\Program Files\LimeWire
[30/06/2007|13:27] C:\Program Files\Logitech
[29/08/2009|21:33] C:\Program Files\Malwarebytes' Anti-Malware
[26/03/2007|17:54] C:\Program Files\Messenger
[06/02/2009|21:22] C:\Program Files\Messenger Plus! Live
[29/09/2006|18:59] C:\Program Files\MessengerPlus! 3
[04/08/2005|20:12] C:\Program Files\microsoft frontpage
[18/07/2009|16:16] C:\Program Files\Microsoft Games
[04/08/2005|20:10] C:\Program Files\Movie Maker
[30/08/2009|22:10] C:\Program Files\Mozilla Firefox
[05/08/2005|09:35] C:\Program Files\MSI
[04/08/2005|20:08] C:\Program Files\MSN
[06/03/2006|18:27] C:\Program Files\MSN Apps
[04/08/2005|20:09] C:\Program Files\MSN Gaming Zone
[09/03/2008|13:17] C:\Program Files\MSN Messenger
[03/10/2007|14:33] C:\Program Files\MSN Messenger 2
[06/03/2006|18:27] C:\Program Files\MSN Toolbar Suite
[25/10/2007|19:35] C:\Program Files\MUSICMATCH
[28/08/2005|14:14] C:\Program Files\NetMeeting
[04/08/2005|20:09] C:\Program Files\Online Services
[18/05/2008|22:53] C:\Program Files\OpenOffice.org 2.4
[16/08/2007|15:29] C:\Program Files\otron.net
[04/08/2005|20:10] C:\Program Files\Outlook Express
[13/09/2006|20:16] C:\Program Files\PhotoFiltre
[05/08/2005|15:04] C:\Program Files\Powerline Adapter
[26/09/2008|22:18] C:\Program Files\QuickTime
[05/08/2005|08:37] C:\Program Files\S3Inc
[09/10/2005|21:12] C:\Program Files\Saitek
[22/09/2005|19:46] C:\Program Files\Samples
[11/02/2009|14:13] C:\Program Files\Sarkophage
[04/08/2005|20:11] C:\Program Files\Services en ligne
[05/08/2005|09:34] C:\Program Files\Setup Files
[22/09/2005|19:47] C:\Program Files\shapes
[22/11/2005|21:08] C:\Program Files\Sierra On-Line
[18/07/2009|16:21] C:\Program Files\Skype
[16/06/2006|12:38] C:\Program Files\Slayers Online
[06/03/2006|18:28] C:\Program Files\SnadBoy's Revelation v2
[07/10/2005|18:10] C:\Program Files\Softwin
[04/02/2009|14:52] C:\Program Files\Sony
[04/02/2009|14:52] C:\Program Files\Sony Ericsson
[14/03/2007|22:25] C:\Program Files\Spybot - Search & Destroy
[04/04/2008|22:05] C:\Program Files\StepMania CVS
[07/08/2005|13:16] C:\Program Files\SysAlbum
[02/04/2006|15:25] C:\Program Files\Teamspeak2_RC2
[22/09/2005|19:47] C:\Program Files\Texture
[08/02/2009|22:58] C:\Program Files\TSO
[29/03/2006|16:22] C:\Program Files\UBISOFT
[30/01/2008|23:44] C:\Program Files\UGCP
[07/08/2005|13:19] C:\Program Files\UI
[04/08/2005|19:18] C:\Program Files\Uninstall Information
[13/06/2009|21:21] C:\Program Files\uTorrent
[14/08/2007|19:55] C:\Program Files\UxTheme Multipatcher Fr
[10/10/2007|18:33] C:\Program Files\Veoh Networks
[05/08/2005|09:32] C:\Program Files\VIA
[28/08/2009|15:58] C:\Program Files\VideoLAN
[15/10/2008|17:50] C:\Program Files\Visicom Media
[26/03/2007|17:54] C:\Program Files\Web
[03/01/2009|23:22] C:\Program Files\Winamp
[21/01/2007|19:42] C:\Program Files\Windows Defender
[16/08/2005|11:54] C:\Program Files\Windows Journal Viewer
[09/03/2008|13:19] C:\Program Files\Windows Live
[13/06/2009|21:07] C:\Program Files\Windows Media Connect 2
[06/06/2009|15:47] C:\Program Files\Windows Media Player
[04/08/2005|20:09] C:\Program Files\Windows NT
[04/08/2005|20:11] C:\Program Files\WindowsUpdate
[04/10/2007|19:53] C:\Program Files\WinRAR
[04/08/2005|20:12] C:\Program Files\xerox
[18/07/2009|16:23] C:\Program Files\Yahoo!
[07/02/2009|03:32] C:\Program Files\???????????
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/08/2005|12:19] C:\Program Files\Fichiers communs\Adobe
[05/08/2005|09:41] C:\Program Files\Fichiers communs\Ahead
[26/09/2008|22:17] C:\Program Files\Fichiers communs\Apple
[03/12/2007|15:44] C:\Program Files\Fichiers communs\BitDefender
[24/07/2009|15:44] C:\Program Files\Fichiers communs\CyberLink
[19/06/2009|15:41] C:\Program Files\Fichiers communs\DivX Shared
[29/01/2006|12:49] C:\Program Files\Fichiers communs\greenstreet
[14/03/2007|15:11] C:\Program Files\Fichiers communs\GTK
[11/01/2006|13:48] C:\Program Files\Fichiers communs\InstallShield
[21/10/2005|21:23] C:\Program Files\Fichiers communs\Java
[30/06/2007|13:20] C:\Program Files\Fichiers communs\Logitech
[04/02/2009|14:42] C:\Program Files\Fichiers communs\Microsoft Shared
[04/08/2005|20:10] C:\Program Files\Fichiers communs\MSSoap
[01/03/2099|03:17] C:\Program Files\Fichiers communs\ODBC
[04/08/2005|20:10] C:\Program Files\Fichiers communs\Services
[03/12/2007|15:36] C:\Program Files\Fichiers communs\Softwin
[04/02/2009|14:53] C:\Program Files\Fichiers communs\Sony Shared
[01/03/2099|03:17] C:\Program Files\Fichiers communs\SpeechEngines
[04/08/2005|20:10] C:\Program Files\Fichiers communs\System
[09/03/2008|13:18] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[15/10/2008|16:53] C:\Program Files\Fichiers communs\Xuisoft
--------------------\\ Process
( 44 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
--------------------\\ Recherche d'autres infections
--------------------\\ ROOTKIT !!
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV]
Trojan ! .. C:\WINDOWS\system32\TDSSservers.dat
Trojan ! .. C:\WINDOWS\system32\TDSSinit.dll
--------------------\\ Suspect ..
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
[F:5455][D:203]-> C:\DOCUME~1\admin\LOCALS~1\Temp
[F:230][D:0]-> C:\DOCUME~1\admin\Cookies
[F:1432][D:5]-> C:\DOCUME~1\admin\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 30/08/2009|22:48 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 30/08/2009|23:16 - Option : [2]
--------------------\\ Fin du rapport a 23:16:20
[#ff0000]/!\ Désactive tes protections résidentes (Antivirus, etc...) /!\[/#f]
Télécharge ComboFix ([#ff0000]sUBs[/#f]) sur ton Bureau.
Double-clique sur ComboFix.exe (le .exe n'est pas forcément visible) afin de le lancer.
Il va te demander d'installer la console de récupération : accepte.
Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.
Pour t'aider : Un guide et un tutoriel sur l'utilisation de ComboFix
Pour t'aider : Un guide et un tutoriel sur l'utilisation de ComboFix
ComboFix 09-08-30.04 - admin 31/08/2009 17:15.1.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.511.93 [GMT 2:00]
Running from: c:\documents and settings\admin\Bureau\IDN.exe
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\admin\Application Data\addon.dat
c:\program files\INSTALL.LOG
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Installer\1648c.msp
c:\windows\Installer\6d93c.msi
c:\windows\run.log
c:\windows\system32\casino1.ico
c:\windows\system32\casino2.ico
c:\windows\system32\casino3.ico
c:\windows\system32\drivers\kbiwkmxorwtvoy.sys
c:\windows\system32\drivers\UACdlmsktqlrr.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\kbiwkmlog.dat
c:\windows\system32\kbiwkmmevdlmgi.dll
c:\windows\system32\kbiwkmorpbrese.dll
c:\windows\system32\kbiwkmtjbotvdt.dat
c:\windows\system32\kbiwkmwxjovvwi.dat
c:\windows\system32\Process.exe
c:\windows\system32\sirenacm(3).dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\UACdfytjcqrru.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjftkjfyyjm.db
c:\windows\system32\UACmsubnsjulo.dat
c:\windows\system32\UACodjkwkpteg.dll
c:\windows\system32\UACxdhbpjokrs.dll
c:\windows\system32\UACxvfmqecyiu.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmxjlbbaim
-------\Legacy_kbiwkmxjlbbaim
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_TDSSSERV
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.
2099-03-01 01:19 . 2001-08-17 21:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2099-03-01 01:18 . 2004-08-04 00:39 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2099-03-01 01:18 . 2001-08-17 20:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
2099-03-01 01:18 . 2004-08-04 00:54 77312 ----a-w- c:\windows\system32\usbui.dll
2099-03-01 01:18 . 2004-08-03 23:07 46464 ----a-w- c:\windows\system32\drivers\GAGP30KX.SYS
2099-03-01 01:16 . 2009-08-31 15:15 -------- d-----w- c:\windows\system32\CatRoot2
2099-03-01 01:16 . 2009-06-06 13:48 -------- d-----w- c:\windows\system32\CatRoot
2099-03-01 01:16 . 2006-03-06 16:59 -------- d-----w- C:\Documents and Settings
2099-03-01 01:16 . 2005-08-04 18:11 -------- d-----w- c:\documents and settings\All Users
2099-03-01 01:16 . 2005-08-04 17:18 -------- d--h--w- c:\documents and settings\Default User
2009-08-30 20:22 . 2009-08-31 11:16 -------- d-----w- C:\Lop SD
2009-08-29 20:33 . 2009-08-29 20:33 -------- d-----w- C:\rsit
2009-08-29 19:14 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-29 19:14 . 2009-08-29 19:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 19:14 . 2009-08-29 19:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-29 19:14 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-29 17:45 . 2009-07-28 14:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-28 19:55 . 2009-08-28 19:55 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Application Data\vlc
2009-08-28 16:22 . 2009-08-30 23:39 -------- d-----w- c:\documents and settings\admin\Application Data\vlc
2009-08-28 14:06 . 2009-08-28 16:35 -------- d-----w- c:\documents and settings\admin\Application Data\dvdcss
2009-08-28 13:58 . 2009-08-28 13:58 -------- d-----w- c:\program files\VideoLAN
2009-08-28 13:01 . 2009-08-28 13:01 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\DoctorWeb
2009-08-28 12:46 . 2004-08-05 12:00 4096 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2009-08-28 12:45 . 2009-08-28 12:45 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Local Settings\Application Data\Mozilla
2009-08-28 12:41 . 2009-08-28 12:41 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Application Data\BitDefender
2009-08-28 12:40 . 2009-08-28 12:40 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Application Data\DivX
2009-08-25 18:49 . 2009-08-25 18:49 -------- d-----w- C:\spoolerlogs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 15:38 . 2006-05-11 20:19 81984 ----a-w- c:\windows\system32\bdod.bin
2009-08-31 14:31 . 2009-06-13 19:04 -------- d-----w- c:\documents and settings\admin\Application Data\uTorrent
2009-08-30 15:32 . 2007-04-06 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-28 12:21 . 2008-11-03 22:18 -------- d-----w- c:\documents and settings\admin\Application Data\LimeWire
2009-07-26 16:50 . 2005-08-05 15:06 -------- d-----w- c:\documents and settings\admin\Application Data\Cyberlink
2009-07-24 13:55 . 2009-07-24 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-07-24 13:44 . 2009-07-24 13:44 -------- d-----w- c:\program files\Fichiers communs\CyberLink
2009-07-24 13:44 . 2005-08-05 07:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 13:41 . 2005-08-05 07:39 -------- d-----w- c:\program files\CyberLink
2009-07-24 13:40 . 2009-07-24 13:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Temp
2009-07-24 13:40 . 2009-07-24 13:40 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-07-18 20:16 . 2009-07-18 20:05 -------- d-----w- c:\documents and settings\admin\Application Data\.minecraft
2009-07-18 14:28 . 2005-08-05 07:39 -------- d-----w- c:\program files\CyberLink DVD Solution
2009-07-18 14:23 . 2006-01-14 14:42 -------- d-----w- c:\program files\Yahoo!
2009-07-18 14:21 . 2009-02-28 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-18 14:21 . 2006-04-26 19:48 -------- d-----r- c:\program files\Skype
2009-07-18 14:16 . 2005-10-26 20:10 -------- d-----w- c:\program files\Microsoft Games
2009-07-18 14:13 . 2007-04-13 16:46 -------- d-----w- c:\program files\Gimp
2009-06-11 19:29 . 2009-06-11 19:29 1878984 ----a-w- c:\documents and settings\admin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2005-11-23 11:38 . 2005-11-23 11:38 97556 ----a-w- c:\program files\60's_Sunglasses.LVF
2005-11-23 11:38 . 2005-11-23 11:38 87721 ----a-w- c:\program files\scuba_mask.LVF
2005-11-23 11:37 . 2005-11-23 11:37 75833 ----a-w- c:\program files\Pacifier.LVF
2005-11-23 11:37 . 2005-11-23 11:37 427484 ----a-w- c:\program files\Stick_Figure.LVA
2005-11-23 11:37 . 2005-11-23 11:37 385233 ----a-w- c:\program files\Cat.LVA
2005-09-06 16:15 . 2005-09-05 17:04 16 ----a-w- c:\program files\ImgCache.pvi
2005-09-05 18:02 . 2005-09-05 17:03 655840 ----a-w- c:\program files\ImgCache.pvd
2005-05-22 13:51 . 2005-08-07 11:20 322707 ----a-w- c:\program files\Uninst.isu
2004-03-11 11:27 . 2005-08-05 07:39 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2001-11-30 07:29 . 2005-08-07 11:20 344064 ----a-w- c:\program files\AlbumBase.dll
2001-11-30 07:29 . 2005-08-07 11:20 172032 ----a-w- c:\program files\abmFind.dll
2001-11-21 14:13 . 2005-08-07 11:20 126976 ----a-w- c:\program files\Res_Pi.dll
2001-11-21 13:28 . 2005-08-07 11:20 10903 ----a-w- c:\program files\Lblspec.ini
2001-08-08 12:08 . 2005-08-07 11:20 114688 ----a-w- c:\program files\MultiPrint.dll
2001-07-19 15:27 . 2005-08-07 11:20 659456 ----a-w- c:\program files\EzDll.dll
2001-07-02 09:30 . 2005-08-07 11:20 53248 ----a-w- c:\program files\wdmcapture.dll
2001-06-19 17:59 . 2005-08-07 11:20 139264 ----a-w- c:\program files\Res_Dll.dll
2001-05-17 14:18 . 2005-08-07 11:20 69632 ----a-w- c:\program files\ASPI.dll
2001-05-14 17:21 . 2005-08-07 11:20 166163 ----a-w- c:\program files\PhotoImpression.HLP
2001-04-26 15:23 . 2005-08-07 11:20 53248 ----a-w- c:\program files\EditWin.dll
2000-11-24 12:43 . 2005-08-07 11:20 28160 ----a-w- c:\program files\ezrgb24.ax
2000-10-16 16:51 . 2005-08-07 11:20 32768 ----a-w- c:\program files\OsWrapperForPI.dll
2000-10-09 13:43 . 2005-08-07 11:20 61440 ----a-w- c:\program files\PiApi.dll
2000-10-04 12:47 . 2005-08-07 11:20 90112 ----a-w- c:\program files\myCtrl.dll
2000-09-26 15:54 . 2005-08-07 11:20 122880 ----a-w- c:\program files\eff_ehn.dll
2000-01-29 07:21 . 2005-08-07 11:20 247844 ----a-w- c:\program files\exif.exf
1999-06-29 14:34 . 2005-08-07 11:20 400 ----a-w- c:\program files\click1.wav
1999-06-29 10:07 . 2005-08-07 11:20 533 ----a-w- c:\program files\click2.wav
1999-05-26 07:46 . 2005-08-07 11:20 212480 ----a-w- c:\program files\pcdlib32.dll
1997-12-23 14:34 . 2005-08-07 11:20 115712 ----a-w- c:\program files\Filefpx.dll
1996-10-17 14:40 . 2005-08-07 11:20 308736 ----a-w- c:\program files\FPXLIB.DLL
1996-09-24 05:13 . 2005-08-07 11:20 91136 ----a-w- c:\program files\JPEGLIB.DLL
2008-09-25 16:46 . 2008-09-25 16:46 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2006-09-29 190024]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Profiler"="c:\program files\Saitek\Software\Profiler.exe" [2004-01-28 159744]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 344064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-25 29744]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-05 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-05-07 75048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Configuration iTouch.lnk - c:\program files\Logitech\iTouch\iTouchcf.exe [2007-6-30 319488]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-6-30 169472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
[HKLM\~\startupfolder\C:^Documents and Settings^admin^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
path=c:\documents and settings\admin\Menu Démarrer\Programmes\Démarrage\MyWebSearch Email Plugin.lnk
backup=c:\windows\pss\MyWebSearch Email Plugin.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\MyWebSearch Email Plugin.lnk
backup=c:\windows\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=c:\windows\pss\Outil de mise à jour Google.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"c:\\Program Files\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"c:\\Program Files\\Lemoncast\\lemoncast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD Cinema\\PowerDVDCinema.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD9.exe"=
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/07/24 15:46];c:\program files\CyberLink\PowerDVD9\000.fcl [07/05/2009 21:05 87536]
R2 Vcs;Vcs support;c:\windows\system32\drivers\Vcs.sys [24/11/2005 18:06 6852]
S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
S3 A_USBETHMP;USB PowerPacket Network Adapter;c:\windows\system32\drivers\usbethmp.sys [05/08/2005 15:04 14342]
S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\gPotato.eu\Dragonica\FR\Release\GameGuard\dump_wmimmc.sys --> c:\program files\gPotato.eu\Dragonica\FR\Release\GameGuard\dump_wmimmc.sys [?]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [30/05/2007 17:39 29744]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;c:\windows\system32\PLCNDIS5.SYS [05/08/2005 15:04 17018]
S3 PVUSB;CESG502 USB Driver;c:\windows\system32\drivers\CESG502.sys [08/09/2008 21:38 40672]
S3 SaiH0464;SaiH0464;c:\windows\system32\drivers\SaiH0464.sys [09/10/2005 21:09 55808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder
2009-04-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-08-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-06 09:02]
2009-08-31 c:\windows\Tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 10:58]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
HKCU-Run-PowerBar - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = localhost
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
TCP: {3F4EECE8-DF4F-448D-85A3-E04253C377E8} = 212.95.68.238,212.95.66.1
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\dbfzbbsv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-31 17:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(416)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(700)
c:\program files\Logitech\iTouch\iTchHk.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
c:\program files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
c:\program files\BitDefender\BitDefender 2008\vsserv.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Java\jre1.6.0_05\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-08-31 17:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 15:43
Pre-Run: 7 615 426 560 octets libres
Post-Run: 8 796 577 792 octets libres
275
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.511.93 [GMT 2:00]
Running from: c:\documents and settings\admin\Bureau\IDN.exe
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\admin\Application Data\addon.dat
c:\program files\INSTALL.LOG
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Installer\1648c.msp
c:\windows\Installer\6d93c.msi
c:\windows\run.log
c:\windows\system32\casino1.ico
c:\windows\system32\casino2.ico
c:\windows\system32\casino3.ico
c:\windows\system32\drivers\kbiwkmxorwtvoy.sys
c:\windows\system32\drivers\UACdlmsktqlrr.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\kbiwkmlog.dat
c:\windows\system32\kbiwkmmevdlmgi.dll
c:\windows\system32\kbiwkmorpbrese.dll
c:\windows\system32\kbiwkmtjbotvdt.dat
c:\windows\system32\kbiwkmwxjovvwi.dat
c:\windows\system32\Process.exe
c:\windows\system32\sirenacm(3).dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\UACdfytjcqrru.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjftkjfyyjm.db
c:\windows\system32\UACmsubnsjulo.dat
c:\windows\system32\UACodjkwkpteg.dll
c:\windows\system32\UACxdhbpjokrs.dll
c:\windows\system32\UACxvfmqecyiu.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmxjlbbaim
-------\Legacy_kbiwkmxjlbbaim
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_TDSSSERV
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.
2099-03-01 01:19 . 2001-08-17 21:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2099-03-01 01:18 . 2004-08-04 00:39 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2099-03-01 01:18 . 2001-08-17 20:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
2099-03-01 01:18 . 2004-08-04 00:54 77312 ----a-w- c:\windows\system32\usbui.dll
2099-03-01 01:18 . 2004-08-03 23:07 46464 ----a-w- c:\windows\system32\drivers\GAGP30KX.SYS
2099-03-01 01:16 . 2009-08-31 15:15 -------- d-----w- c:\windows\system32\CatRoot2
2099-03-01 01:16 . 2009-06-06 13:48 -------- d-----w- c:\windows\system32\CatRoot
2099-03-01 01:16 . 2006-03-06 16:59 -------- d-----w- C:\Documents and Settings
2099-03-01 01:16 . 2005-08-04 18:11 -------- d-----w- c:\documents and settings\All Users
2099-03-01 01:16 . 2005-08-04 17:18 -------- d--h--w- c:\documents and settings\Default User
2009-08-30 20:22 . 2009-08-31 11:16 -------- d-----w- C:\Lop SD
2009-08-29 20:33 . 2009-08-29 20:33 -------- d-----w- C:\rsit
2009-08-29 19:14 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-29 19:14 . 2009-08-29 19:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 19:14 . 2009-08-29 19:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-29 19:14 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-29 17:45 . 2009-07-28 14:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-28 19:55 . 2009-08-28 19:55 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Application Data\vlc
2009-08-28 16:22 . 2009-08-30 23:39 -------- d-----w- c:\documents and settings\admin\Application Data\vlc
2009-08-28 14:06 . 2009-08-28 16:35 -------- d-----w- c:\documents and settings\admin\Application Data\dvdcss
2009-08-28 13:58 . 2009-08-28 13:58 -------- d-----w- c:\program files\VideoLAN
2009-08-28 13:01 . 2009-08-28 13:01 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\DoctorWeb
2009-08-28 12:46 . 2004-08-05 12:00 4096 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2009-08-28 12:45 . 2009-08-28 12:45 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Local Settings\Application Data\Mozilla
2009-08-28 12:41 . 2009-08-28 12:41 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Application Data\BitDefender
2009-08-28 12:40 . 2009-08-28 12:40 -------- d-----w- c:\documents and settings\Administrateur.LUDOVIC.000\Application Data\DivX
2009-08-25 18:49 . 2009-08-25 18:49 -------- d-----w- C:\spoolerlogs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 15:38 . 2006-05-11 20:19 81984 ----a-w- c:\windows\system32\bdod.bin
2009-08-31 14:31 . 2009-06-13 19:04 -------- d-----w- c:\documents and settings\admin\Application Data\uTorrent
2009-08-30 15:32 . 2007-04-06 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-28 12:21 . 2008-11-03 22:18 -------- d-----w- c:\documents and settings\admin\Application Data\LimeWire
2009-07-26 16:50 . 2005-08-05 15:06 -------- d-----w- c:\documents and settings\admin\Application Data\Cyberlink
2009-07-24 13:55 . 2009-07-24 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-07-24 13:44 . 2009-07-24 13:44 -------- d-----w- c:\program files\Fichiers communs\CyberLink
2009-07-24 13:44 . 2005-08-05 07:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 13:41 . 2005-08-05 07:39 -------- d-----w- c:\program files\CyberLink
2009-07-24 13:40 . 2009-07-24 13:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Temp
2009-07-24 13:40 . 2009-07-24 13:40 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-07-18 20:16 . 2009-07-18 20:05 -------- d-----w- c:\documents and settings\admin\Application Data\.minecraft
2009-07-18 14:28 . 2005-08-05 07:39 -------- d-----w- c:\program files\CyberLink DVD Solution
2009-07-18 14:23 . 2006-01-14 14:42 -------- d-----w- c:\program files\Yahoo!
2009-07-18 14:21 . 2009-02-28 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-18 14:21 . 2006-04-26 19:48 -------- d-----r- c:\program files\Skype
2009-07-18 14:16 . 2005-10-26 20:10 -------- d-----w- c:\program files\Microsoft Games
2009-07-18 14:13 . 2007-04-13 16:46 -------- d-----w- c:\program files\Gimp
2009-06-11 19:29 . 2009-06-11 19:29 1878984 ----a-w- c:\documents and settings\admin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2005-11-23 11:38 . 2005-11-23 11:38 97556 ----a-w- c:\program files\60's_Sunglasses.LVF
2005-11-23 11:38 . 2005-11-23 11:38 87721 ----a-w- c:\program files\scuba_mask.LVF
2005-11-23 11:37 . 2005-11-23 11:37 75833 ----a-w- c:\program files\Pacifier.LVF
2005-11-23 11:37 . 2005-11-23 11:37 427484 ----a-w- c:\program files\Stick_Figure.LVA
2005-11-23 11:37 . 2005-11-23 11:37 385233 ----a-w- c:\program files\Cat.LVA
2005-09-06 16:15 . 2005-09-05 17:04 16 ----a-w- c:\program files\ImgCache.pvi
2005-09-05 18:02 . 2005-09-05 17:03 655840 ----a-w- c:\program files\ImgCache.pvd
2005-05-22 13:51 . 2005-08-07 11:20 322707 ----a-w- c:\program files\Uninst.isu
2004-03-11 11:27 . 2005-08-05 07:39 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2001-11-30 07:29 . 2005-08-07 11:20 344064 ----a-w- c:\program files\AlbumBase.dll
2001-11-30 07:29 . 2005-08-07 11:20 172032 ----a-w- c:\program files\abmFind.dll
2001-11-21 14:13 . 2005-08-07 11:20 126976 ----a-w- c:\program files\Res_Pi.dll
2001-11-21 13:28 . 2005-08-07 11:20 10903 ----a-w- c:\program files\Lblspec.ini
2001-08-08 12:08 . 2005-08-07 11:20 114688 ----a-w- c:\program files\MultiPrint.dll
2001-07-19 15:27 . 2005-08-07 11:20 659456 ----a-w- c:\program files\EzDll.dll
2001-07-02 09:30 . 2005-08-07 11:20 53248 ----a-w- c:\program files\wdmcapture.dll
2001-06-19 17:59 . 2005-08-07 11:20 139264 ----a-w- c:\program files\Res_Dll.dll
2001-05-17 14:18 . 2005-08-07 11:20 69632 ----a-w- c:\program files\ASPI.dll
2001-05-14 17:21 . 2005-08-07 11:20 166163 ----a-w- c:\program files\PhotoImpression.HLP
2001-04-26 15:23 . 2005-08-07 11:20 53248 ----a-w- c:\program files\EditWin.dll
2000-11-24 12:43 . 2005-08-07 11:20 28160 ----a-w- c:\program files\ezrgb24.ax
2000-10-16 16:51 . 2005-08-07 11:20 32768 ----a-w- c:\program files\OsWrapperForPI.dll
2000-10-09 13:43 . 2005-08-07 11:20 61440 ----a-w- c:\program files\PiApi.dll
2000-10-04 12:47 . 2005-08-07 11:20 90112 ----a-w- c:\program files\myCtrl.dll
2000-09-26 15:54 . 2005-08-07 11:20 122880 ----a-w- c:\program files\eff_ehn.dll
2000-01-29 07:21 . 2005-08-07 11:20 247844 ----a-w- c:\program files\exif.exf
1999-06-29 14:34 . 2005-08-07 11:20 400 ----a-w- c:\program files\click1.wav
1999-06-29 10:07 . 2005-08-07 11:20 533 ----a-w- c:\program files\click2.wav
1999-05-26 07:46 . 2005-08-07 11:20 212480 ----a-w- c:\program files\pcdlib32.dll
1997-12-23 14:34 . 2005-08-07 11:20 115712 ----a-w- c:\program files\Filefpx.dll
1996-10-17 14:40 . 2005-08-07 11:20 308736 ----a-w- c:\program files\FPXLIB.DLL
1996-09-24 05:13 . 2005-08-07 11:20 91136 ----a-w- c:\program files\JPEGLIB.DLL
2008-09-25 16:46 . 2008-09-25 16:46 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2006-09-29 190024]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Profiler"="c:\program files\Saitek\Software\Profiler.exe" [2004-01-28 159744]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 344064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2003-12-01 892928]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-25 29744]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-05 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-05-07 75048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Configuration iTouch.lnk - c:\program files\Logitech\iTouch\iTouchcf.exe [2007-6-30 319488]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-6-30 169472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
[HKLM\~\startupfolder\C:^Documents and Settings^admin^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
path=c:\documents and settings\admin\Menu Démarrer\Programmes\Démarrage\MyWebSearch Email Plugin.lnk
backup=c:\windows\pss\MyWebSearch Email Plugin.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\MyWebSearch Email Plugin.lnk
backup=c:\windows\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=c:\windows\pss\Outil de mise à jour Google.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"c:\\Program Files\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"c:\\Program Files\\Lemoncast\\lemoncast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD Cinema\\PowerDVDCinema.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD9.exe"=
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/07/24 15:46];c:\program files\CyberLink\PowerDVD9\000.fcl [07/05/2009 21:05 87536]
R2 Vcs;Vcs support;c:\windows\system32\drivers\Vcs.sys [24/11/2005 18:06 6852]
S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
S3 A_USBETHMP;USB PowerPacket Network Adapter;c:\windows\system32\drivers\usbethmp.sys [05/08/2005 15:04 14342]
S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\gPotato.eu\Dragonica\FR\Release\GameGuard\dump_wmimmc.sys --> c:\program files\gPotato.eu\Dragonica\FR\Release\GameGuard\dump_wmimmc.sys [?]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [30/05/2007 17:39 29744]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;c:\windows\system32\PLCNDIS5.SYS [05/08/2005 15:04 17018]
S3 PVUSB;CESG502 USB Driver;c:\windows\system32\drivers\CESG502.sys [08/09/2008 21:38 40672]
S3 SaiH0464;SaiH0464;c:\windows\system32\drivers\SaiH0464.sys [09/10/2005 21:09 55808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder
2009-04-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-08-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-06 09:02]
2009-08-31 c:\windows\Tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 10:58]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
HKCU-Run-PowerBar - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = localhost
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
TCP: {3F4EECE8-DF4F-448D-85A3-E04253C377E8} = 212.95.68.238,212.95.66.1
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\dbfzbbsv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-31 17:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(416)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(700)
c:\program files\Logitech\iTouch\iTchHk.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
c:\program files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
c:\program files\BitDefender\BitDefender 2008\vsserv.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Java\jre1.6.0_05\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-08-31 17:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 15:43
Pre-Run: 7 615 426 560 octets libres
Post-Run: 8 796 577 792 octets libres
275
/!\ Seul Choco_22 peut suivre cette procédure /!\
Désactive toute protection résidente (Antivirus...) !
---> Copie (CTRL+C) le texte se situant dans le cadre ci-dessous :
---> Ouvre le Bloc-notes : Démarrer > Tous les programmes > Accessoires > Bloc-notes.
- Colle (CTRL+V) le texte dans le Bloc-notes.
- Enregistre ce fichier dans : Bureau
- Nom du fichier : CFScript
- Type du fichier : tous les fichiers !!
- Clique sur Enregistrer.
- Quitte le Bloc-notes.
---> Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
![]()
Cela va relancer Combofix : au message qui apparaît, accepte.
Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal !
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher, copie/colle son contenu sur le forum.
Si le fichier ne s'ouvre pas, il se trouve ici : C:\ComboFix.txt
Désactive toute protection résidente (Antivirus...) !
---> Copie (CTRL+C) le texte se situant dans le cadre ci-dessous :
KillAll::
Folder::
C:\DOCUME~1\admin\APPLIC~1\32 size slow
C:\DOCUME~1\ALLUSE~1\APPLIC~1\bike bleh default delete
Registry::
[-HKLM\~\startupfolder\C:^Documents and Settings^admin^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
[-HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
Folder::
C:\DOCUME~1\admin\APPLIC~1\32 size slow
C:\DOCUME~1\ALLUSE~1\APPLIC~1\bike bleh default delete
Registry::
[-HKLM\~\startupfolder\C:^Documents and Settings^admin^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
[-HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
---> Ouvre le Bloc-notes : Démarrer > Tous les programmes > Accessoires > Bloc-notes.
- Colle (CTRL+V) le texte dans le Bloc-notes.
- Enregistre ce fichier dans : Bureau
- Nom du fichier : CFScript
- Type du fichier : tous les fichiers !!
- Clique sur Enregistrer.
- Quitte le Bloc-notes.
---> Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :

Bah l'ordi rien de spécial.
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 2800+ )
BIOS : Version 07.00T
USER : admin ( Administrator )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:152 Go (Free:8 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 02/09/2009|20:33 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[18/07/2009|22:16] C:\DOCUME~1\admin\APPLIC~1\.minecraft
[04/04/2008|19:31] C:\DOCUME~1\admin\APPLIC~1\Adobe
[31/01/2009|21:56] C:\DOCUME~1\admin\APPLIC~1\AdobeUM
[14/09/2005|14:50] C:\DOCUME~1\admin\APPLIC~1\Ahead
[26/09/2008|22:25] C:\DOCUME~1\admin\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\admin\APPLIC~1\Bitdefender
[01/10/2007|23:18] C:\DOCUME~1\admin\APPLIC~1\BitTorrent
[26/07/2009|18:50] C:\DOCUME~1\admin\APPLIC~1\Cyberlink
[15/10/2007|20:45] C:\DOCUME~1\admin\APPLIC~1\DivX
[28/08/2009|18:35] C:\DOCUME~1\admin\APPLIC~1\dvdcss
[02/12/2008|20:35] C:\DOCUME~1\admin\APPLIC~1\GetRightToGo
[31/12/2008|15:27] C:\DOCUME~1\admin\APPLIC~1\Google
[07/08/2005|16:47] C:\DOCUME~1\admin\APPLIC~1\Help
[04/08/2005|19:18] C:\DOCUME~1\admin\APPLIC~1\Identities
[04/07/2007|17:36] C:\DOCUME~1\admin\APPLIC~1\La Bataille pour la Terre du Milieu
[06/08/2005|18:39] C:\DOCUME~1\admin\APPLIC~1\Lavasoft
[28/08/2009|14:21] C:\DOCUME~1\admin\APPLIC~1\LimeWire
[11/07/2007|20:10] C:\DOCUME~1\admin\APPLIC~1\Macromedia
[08/02/2009|23:01] C:\DOCUME~1\admin\APPLIC~1\Microsoft
[30/08/2008|16:54] C:\DOCUME~1\admin\APPLIC~1\Mozilla
[01/03/2009|10:05] C:\DOCUME~1\admin\APPLIC~1\OpenOffice.org2
[01/03/2009|20:49] C:\DOCUME~1\admin\APPLIC~1\skypePM
[04/02/2009|14:56] C:\DOCUME~1\admin\APPLIC~1\Sony
[21/10/2005|21:24] C:\DOCUME~1\admin\APPLIC~1\Sun
[10/10/2007|14:15] C:\DOCUME~1\admin\APPLIC~1\Talkback
[25/04/2009|22:09] C:\DOCUME~1\admin\APPLIC~1\teamspeak2
[01/09/2009|02:25] C:\DOCUME~1\admin\APPLIC~1\uTorrent
[01/09/2009|02:23] C:\DOCUME~1\admin\APPLIC~1\vlc
[02/11/2008|03:25] C:\DOCUME~1\admin\APPLIC~1\Winamp
[25/01/2009|17:21] C:\DOCUME~1\admin\APPLIC~1\WinAmp Control
[04/10/2007|19:53] C:\DOCUME~1\admin\APPLIC~1\WinRAR
[06/03/2006|18:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[06/03/2006|18:27] C:\DOCUME~1\ADMINI~1.LUD\APPLIC~1\Microsoft
[28/08/2009|14:41] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\BitDefender
[28/08/2009|14:40] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\DivX
[28/08/2009|21:48] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Microsoft
[28/08/2009|14:45] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Mozilla
[28/08/2009|21:55] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\vlc
[05/08/2005|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/09/2008|22:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/09/2008|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[09/06/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[24/07/2009|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[07/04/2007|14:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[02/09/2009|10:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[11/01/2006|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[16/09/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[29/08/2009|21:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[08/10/2005|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[28/08/2009|14:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[27/12/2005|21:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\POPWWPROFILES
[18/07/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[04/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
[14/03/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[24/07/2009|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Temp
[31/10/2008|03:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Winamp Toolbar
[16/08/2005|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/03/2008|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[04/08/2005|20:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[06/08/2005|18:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[04/08/2005|20:12] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[02/09/2009 18:28][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[18/04/2009 07:59][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[02/09/2009 20:30][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
[02/09/2009 18:28][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ MsgPlus SPONSOR INSTALLED !
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"SponsorInstalled"=dword:00000000
--------------------\\ Listing des dossiers dans C:\Program Files
[06/03/2006|19:43] C:\Program Files\Ad-Aware SE Personal
[05/08/2005|09:44] C:\Program Files\Adobe
[07/10/2005|18:10] C:\Program Files\Ahead
[07/08/2005|13:20] C:\Program Files\albums
[26/03/2007|17:54] C:\Program Files\AlfaCleaner(2)
[07/08/2005|13:20] C:\Program Files\animation
[26/09/2008|22:15] C:\Program Files\Apple Software Update
[09/12/2005|18:43] C:\Program Files\ATI Technologies
[15/10/2008|20:35] C:\Program Files\AviSynth 2.5
[03/12/2007|15:44] C:\Program Files\BitDefender
[31/12/2008|15:21] C:\Program Files\BitSpirit
[25/10/2007|19:33] C:\Program Files\BitTorrent
[21/10/2005|19:29] C:\Program Files\Blender Foundation
[07/08/2005|13:21] C:\Program Files\Calendar
[08/09/2008|21:38] C:\Program Files\CASIO
[14/04/2009|23:14] C:\Program Files\Common Files
[04/08/2005|20:09] C:\Program Files\ComPlus Applications
[07/08/2005|13:14] C:\Program Files\config
[24/07/2009|15:41] C:\Program Files\CyberLink
[18/07/2009|16:28] C:\Program Files\CyberLink DVD Solution
[19/06/2009|15:44] C:\Program Files\DivX
[21/04/2009|19:03] C:\Program Files\Ê¢´óÍøÂç
[04/07/2007|17:02] C:\Program Files\EA GAMES
[26/03/2007|17:54] C:\Program Files\Edges
[25/10/2007|19:31] C:\Program Files\EHMINSTALL
[27/12/2005|14:05] C:\Program Files\Eidos
[03/01/2009|23:19] C:\Program Files\eMule
[05/08/2005|15:24] C:\Program Files\EPSON
[15/10/2008|20:34] C:\Program Files\eRightSoft
[07/08/2005|13:14] C:\Program Files\Fantasy
[02/09/2009|18:23] C:\Program Files\Fichiers communs
[26/03/2007|17:54] C:\Program Files\FlameOfLegend
[07/08/2005|13:15] C:\Program Files\Frames
[21/01/2007|19:42] C:\Program Files\Game Cam Lite v1.4
[18/07/2009|16:13] C:\Program Files\Gimp
[14/03/2007|15:19] C:\Program Files\GIMP-2.0
[30/05/2007|17:39] C:\Program Files\Google
[17/06/2009|16:03] C:\Program Files\gPotato.eu
[10/01/2007|17:12] C:\Program Files\greenstreet
[07/08/2005|13:15] C:\Program Files\greeting
[08/05/2009|15:22] C:\Program Files\GUILD WARS
[10/05/2008|19:06] C:\Program Files\GW Team Builder
[03/11/2008|16:39] C:\Program Files\GWFreaks
[24/07/2009|15:44] C:\Program Files\InstallShield Installation Information
[04/02/2009|14:34] C:\Program Files\Internet Explorer
[22/09/2006|16:40] C:\Program Files\Jasc Software Inc
[18/05/2008|22:51] C:\Program Files\Java
[16/09/2008|19:14] C:\Program Files\Lavasoft
[30/08/2006|15:41] C:\Program Files\Lemoncast
[30/04/2009|00:37] C:\Program Files\LimeWire
[30/06/2007|13:27] C:\Program Files\Logitech
[29/08/2009|21:33] C:\Program Files\Malwarebytes' Anti-Malware
[26/03/2007|17:54] C:\Program Files\Messenger
[06/02/2009|21:22] C:\Program Files\Messenger Plus! Live
[29/09/2006|18:59] C:\Program Files\MessengerPlus! 3
[04/08/2005|20:12] C:\Program Files\microsoft frontpage
[18/07/2009|16:16] C:\Program Files\Microsoft Games
[04/08/2005|20:10] C:\Program Files\Movie Maker
[02/09/2009|18:51] C:\Program Files\Mozilla Firefox
[05/08/2005|09:35] C:\Program Files\MSI
[04/08/2005|20:08] C:\Program Files\MSN
[06/03/2006|18:27] C:\Program Files\MSN Apps
[04/08/2005|20:09] C:\Program Files\MSN Gaming Zone
[09/03/2008|13:17] C:\Program Files\MSN Messenger
[03/10/2007|14:33] C:\Program Files\MSN Messenger 2
[06/03/2006|18:27] C:\Program Files\MSN Toolbar Suite
[25/10/2007|19:35] C:\Program Files\MUSICMATCH
[28/08/2005|14:14] C:\Program Files\NetMeeting
[04/08/2005|20:09] C:\Program Files\Online Services
[18/05/2008|22:53] C:\Program Files\OpenOffice.org 2.4
[16/08/2007|15:29] C:\Program Files\otron.net
[04/08/2005|20:10] C:\Program Files\Outlook Express
[13/09/2006|20:16] C:\Program Files\PhotoFiltre
[05/08/2005|15:04] C:\Program Files\Powerline Adapter
[26/09/2008|22:18] C:\Program Files\QuickTime
[05/08/2005|08:37] C:\Program Files\S3Inc
[09/10/2005|21:12] C:\Program Files\Saitek
[22/09/2005|19:46] C:\Program Files\Samples
[11/02/2009|14:13] C:\Program Files\Sarkophage
[04/08/2005|20:11] C:\Program Files\Services en ligne
[05/08/2005|09:34] C:\Program Files\Setup Files
[22/09/2005|19:47] C:\Program Files\shapes
[22/11/2005|21:08] C:\Program Files\Sierra On-Line
[18/07/2009|16:21] C:\Program Files\Skype
[16/06/2006|12:38] C:\Program Files\Slayers Online
[06/03/2006|18:28] C:\Program Files\SnadBoy's Revelation v2
[07/10/2005|18:10] C:\Program Files\Softwin
[04/02/2009|14:52] C:\Program Files\Sony
[04/02/2009|14:52] C:\Program Files\Sony Ericsson
[14/03/2007|22:25] C:\Program Files\Spybot - Search & Destroy
[04/04/2008|22:05] C:\Program Files\StepMania CVS
[07/08/2005|13:16] C:\Program Files\SysAlbum
[02/04/2006|15:25] C:\Program Files\Teamspeak2_RC2
[22/09/2005|19:47] C:\Program Files\Texture
[08/02/2009|22:58] C:\Program Files\TSO
[29/03/2006|16:22] C:\Program Files\UBISOFT
[30/01/2008|23:44] C:\Program Files\UGCP
[07/08/2005|13:19] C:\Program Files\UI
[04/08/2005|19:18] C:\Program Files\Uninstall Information
[13/06/2009|21:21] C:\Program Files\uTorrent
[14/08/2007|19:55] C:\Program Files\UxTheme Multipatcher Fr
[10/10/2007|18:33] C:\Program Files\Veoh Networks
[05/08/2005|09:32] C:\Program Files\VIA
[28/08/2009|15:58] C:\Program Files\VideoLAN
[15/10/2008|17:50] C:\Program Files\Visicom Media
[26/03/2007|17:54] C:\Program Files\Web
[03/01/2009|23:22] C:\Program Files\Winamp
[21/01/2007|19:42] C:\Program Files\Windows Defender
[16/08/2005|11:54] C:\Program Files\Windows Journal Viewer
[09/03/2008|13:19] C:\Program Files\Windows Live
[13/06/2009|21:07] C:\Program Files\Windows Media Connect 2
[06/06/2009|15:47] C:\Program Files\Windows Media Player
[04/08/2005|20:09] C:\Program Files\Windows NT
[04/08/2005|20:11] C:\Program Files\WindowsUpdate
[04/10/2007|19:53] C:\Program Files\WinRAR
[04/08/2005|20:12] C:\Program Files\xerox
[18/07/2009|16:23] C:\Program Files\Yahoo!
[07/02/2009|03:32] C:\Program Files\???????????
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/08/2005|12:19] C:\Program Files\Fichiers communs\Adobe
[05/08/2005|09:41] C:\Program Files\Fichiers communs\Ahead
[26/09/2008|22:17] C:\Program Files\Fichiers communs\Apple
[03/12/2007|15:44] C:\Program Files\Fichiers communs\BitDefender
[24/07/2009|15:44] C:\Program Files\Fichiers communs\CyberLink
[19/06/2009|15:41] C:\Program Files\Fichiers communs\DivX Shared
[29/01/2006|12:49] C:\Program Files\Fichiers communs\greenstreet
[14/03/2007|15:11] C:\Program Files\Fichiers communs\GTK
[11/01/2006|13:48] C:\Program Files\Fichiers communs\InstallShield
[21/10/2005|21:23] C:\Program Files\Fichiers communs\Java
[30/06/2007|13:20] C:\Program Files\Fichiers communs\Logitech
[04/02/2009|14:42] C:\Program Files\Fichiers communs\Microsoft Shared
[04/08/2005|20:10] C:\Program Files\Fichiers communs\MSSoap
[01/03/2099|03:17] C:\Program Files\Fichiers communs\ODBC
[04/08/2005|20:10] C:\Program Files\Fichiers communs\Services
[03/12/2007|15:36] C:\Program Files\Fichiers communs\Softwin
[04/02/2009|14:53] C:\Program Files\Fichiers communs\Sony Shared
[01/03/2099|03:17] C:\Program Files\Fichiers communs\SpeechEngines
[04/08/2005|20:10] C:\Program Files\Fichiers communs\System
[09/03/2008|13:18] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[15/10/2008|16:53] C:\Program Files\Fichiers communs\Xuisoft
--------------------\\ Process
( 42 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 20:35:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 153
--------------------\\ Recherche d'autres infections
Trojan ! .. C:\WINDOWS\system32\TDSSservers.dat
Trojan ! .. C:\WINDOWS\system32\TDSSinit.dll
--------------------\\ Suspect ..
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
[F:22][D:6]-> C:\DOCUME~1\admin\LOCALS~1\Temp
[F:234][D:0]-> C:\DOCUME~1\admin\Cookies
[F:12][D:4]-> C:\DOCUME~1\admin\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 30/08/2009|22:48 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 30/08/2009|23:16 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 02/09/2009|20:37 - Option : [2]
--------------------\\ Fin du rapport a 20:37:47
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 2800+ )
BIOS : Version 07.00T
USER : admin ( Administrator )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:152 Go (Free:8 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 02/09/2009|20:33 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[18/07/2009|22:16] C:\DOCUME~1\admin\APPLIC~1\.minecraft
[04/04/2008|19:31] C:\DOCUME~1\admin\APPLIC~1\Adobe
[31/01/2009|21:56] C:\DOCUME~1\admin\APPLIC~1\AdobeUM
[14/09/2005|14:50] C:\DOCUME~1\admin\APPLIC~1\Ahead
[26/09/2008|22:25] C:\DOCUME~1\admin\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\admin\APPLIC~1\Bitdefender
[01/10/2007|23:18] C:\DOCUME~1\admin\APPLIC~1\BitTorrent
[26/07/2009|18:50] C:\DOCUME~1\admin\APPLIC~1\Cyberlink
[15/10/2007|20:45] C:\DOCUME~1\admin\APPLIC~1\DivX
[28/08/2009|18:35] C:\DOCUME~1\admin\APPLIC~1\dvdcss
[02/12/2008|20:35] C:\DOCUME~1\admin\APPLIC~1\GetRightToGo
[31/12/2008|15:27] C:\DOCUME~1\admin\APPLIC~1\Google
[07/08/2005|16:47] C:\DOCUME~1\admin\APPLIC~1\Help
[04/08/2005|19:18] C:\DOCUME~1\admin\APPLIC~1\Identities
[04/07/2007|17:36] C:\DOCUME~1\admin\APPLIC~1\La Bataille pour la Terre du Milieu
[06/08/2005|18:39] C:\DOCUME~1\admin\APPLIC~1\Lavasoft
[28/08/2009|14:21] C:\DOCUME~1\admin\APPLIC~1\LimeWire
[11/07/2007|20:10] C:\DOCUME~1\admin\APPLIC~1\Macromedia
[08/02/2009|23:01] C:\DOCUME~1\admin\APPLIC~1\Microsoft
[30/08/2008|16:54] C:\DOCUME~1\admin\APPLIC~1\Mozilla
[01/03/2009|10:05] C:\DOCUME~1\admin\APPLIC~1\OpenOffice.org2
[01/03/2009|20:49] C:\DOCUME~1\admin\APPLIC~1\skypePM
[04/02/2009|14:56] C:\DOCUME~1\admin\APPLIC~1\Sony
[21/10/2005|21:24] C:\DOCUME~1\admin\APPLIC~1\Sun
[10/10/2007|14:15] C:\DOCUME~1\admin\APPLIC~1\Talkback
[25/04/2009|22:09] C:\DOCUME~1\admin\APPLIC~1\teamspeak2
[01/09/2009|02:25] C:\DOCUME~1\admin\APPLIC~1\uTorrent
[01/09/2009|02:23] C:\DOCUME~1\admin\APPLIC~1\vlc
[02/11/2008|03:25] C:\DOCUME~1\admin\APPLIC~1\Winamp
[25/01/2009|17:21] C:\DOCUME~1\admin\APPLIC~1\WinAmp Control
[04/10/2007|19:53] C:\DOCUME~1\admin\APPLIC~1\WinRAR
[06/03/2006|18:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[06/03/2006|18:27] C:\DOCUME~1\ADMINI~1.LUD\APPLIC~1\Microsoft
[28/08/2009|14:41] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\BitDefender
[28/08/2009|14:40] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\DivX
[28/08/2009|21:48] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Microsoft
[28/08/2009|14:45] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\Mozilla
[28/08/2009|21:55] C:\DOCUME~1\ADMINI~1.000\APPLIC~1\vlc
[05/08/2005|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[26/09/2008|22:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[26/09/2008|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[03/12/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
[09/06/2008|21:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[24/07/2009|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[07/04/2007|14:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[02/09/2009|10:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[11/01/2006|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[16/09/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[29/08/2009|21:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[08/10/2005|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[28/08/2009|14:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[27/12/2005|21:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\POPWWPROFILES
[18/07/2009|16:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[04/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
[14/03/2007|22:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[24/07/2009|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Temp
[31/10/2008|03:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Winamp Toolbar
[16/08/2005|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[09/03/2008|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[04/08/2005|20:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[06/08/2005|18:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[04/08/2005|20:12] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[02/09/2009 18:28][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[18/04/2009 07:59][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[02/09/2009 20:30][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{F6C0D96A-F21F-480C-A90D-F5DE4232B279}.job
[02/09/2009 18:28][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ MsgPlus SPONSOR INSTALLED !
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MsgPlus! Plugin]
"SponsorInstalled"=dword:00000000
--------------------\\ Listing des dossiers dans C:\Program Files
[06/03/2006|19:43] C:\Program Files\Ad-Aware SE Personal
[05/08/2005|09:44] C:\Program Files\Adobe
[07/10/2005|18:10] C:\Program Files\Ahead
[07/08/2005|13:20] C:\Program Files\albums
[26/03/2007|17:54] C:\Program Files\AlfaCleaner(2)
[07/08/2005|13:20] C:\Program Files\animation
[26/09/2008|22:15] C:\Program Files\Apple Software Update
[09/12/2005|18:43] C:\Program Files\ATI Technologies
[15/10/2008|20:35] C:\Program Files\AviSynth 2.5
[03/12/2007|15:44] C:\Program Files\BitDefender
[31/12/2008|15:21] C:\Program Files\BitSpirit
[25/10/2007|19:33] C:\Program Files\BitTorrent
[21/10/2005|19:29] C:\Program Files\Blender Foundation
[07/08/2005|13:21] C:\Program Files\Calendar
[08/09/2008|21:38] C:\Program Files\CASIO
[14/04/2009|23:14] C:\Program Files\Common Files
[04/08/2005|20:09] C:\Program Files\ComPlus Applications
[07/08/2005|13:14] C:\Program Files\config
[24/07/2009|15:41] C:\Program Files\CyberLink
[18/07/2009|16:28] C:\Program Files\CyberLink DVD Solution
[19/06/2009|15:44] C:\Program Files\DivX
[21/04/2009|19:03] C:\Program Files\Ê¢´óÍøÂç
[04/07/2007|17:02] C:\Program Files\EA GAMES
[26/03/2007|17:54] C:\Program Files\Edges
[25/10/2007|19:31] C:\Program Files\EHMINSTALL
[27/12/2005|14:05] C:\Program Files\Eidos
[03/01/2009|23:19] C:\Program Files\eMule
[05/08/2005|15:24] C:\Program Files\EPSON
[15/10/2008|20:34] C:\Program Files\eRightSoft
[07/08/2005|13:14] C:\Program Files\Fantasy
[02/09/2009|18:23] C:\Program Files\Fichiers communs
[26/03/2007|17:54] C:\Program Files\FlameOfLegend
[07/08/2005|13:15] C:\Program Files\Frames
[21/01/2007|19:42] C:\Program Files\Game Cam Lite v1.4
[18/07/2009|16:13] C:\Program Files\Gimp
[14/03/2007|15:19] C:\Program Files\GIMP-2.0
[30/05/2007|17:39] C:\Program Files\Google
[17/06/2009|16:03] C:\Program Files\gPotato.eu
[10/01/2007|17:12] C:\Program Files\greenstreet
[07/08/2005|13:15] C:\Program Files\greeting
[08/05/2009|15:22] C:\Program Files\GUILD WARS
[10/05/2008|19:06] C:\Program Files\GW Team Builder
[03/11/2008|16:39] C:\Program Files\GWFreaks
[24/07/2009|15:44] C:\Program Files\InstallShield Installation Information
[04/02/2009|14:34] C:\Program Files\Internet Explorer
[22/09/2006|16:40] C:\Program Files\Jasc Software Inc
[18/05/2008|22:51] C:\Program Files\Java
[16/09/2008|19:14] C:\Program Files\Lavasoft
[30/08/2006|15:41] C:\Program Files\Lemoncast
[30/04/2009|00:37] C:\Program Files\LimeWire
[30/06/2007|13:27] C:\Program Files\Logitech
[29/08/2009|21:33] C:\Program Files\Malwarebytes' Anti-Malware
[26/03/2007|17:54] C:\Program Files\Messenger
[06/02/2009|21:22] C:\Program Files\Messenger Plus! Live
[29/09/2006|18:59] C:\Program Files\MessengerPlus! 3
[04/08/2005|20:12] C:\Program Files\microsoft frontpage
[18/07/2009|16:16] C:\Program Files\Microsoft Games
[04/08/2005|20:10] C:\Program Files\Movie Maker
[02/09/2009|18:51] C:\Program Files\Mozilla Firefox
[05/08/2005|09:35] C:\Program Files\MSI
[04/08/2005|20:08] C:\Program Files\MSN
[06/03/2006|18:27] C:\Program Files\MSN Apps
[04/08/2005|20:09] C:\Program Files\MSN Gaming Zone
[09/03/2008|13:17] C:\Program Files\MSN Messenger
[03/10/2007|14:33] C:\Program Files\MSN Messenger 2
[06/03/2006|18:27] C:\Program Files\MSN Toolbar Suite
[25/10/2007|19:35] C:\Program Files\MUSICMATCH
[28/08/2005|14:14] C:\Program Files\NetMeeting
[04/08/2005|20:09] C:\Program Files\Online Services
[18/05/2008|22:53] C:\Program Files\OpenOffice.org 2.4
[16/08/2007|15:29] C:\Program Files\otron.net
[04/08/2005|20:10] C:\Program Files\Outlook Express
[13/09/2006|20:16] C:\Program Files\PhotoFiltre
[05/08/2005|15:04] C:\Program Files\Powerline Adapter
[26/09/2008|22:18] C:\Program Files\QuickTime
[05/08/2005|08:37] C:\Program Files\S3Inc
[09/10/2005|21:12] C:\Program Files\Saitek
[22/09/2005|19:46] C:\Program Files\Samples
[11/02/2009|14:13] C:\Program Files\Sarkophage
[04/08/2005|20:11] C:\Program Files\Services en ligne
[05/08/2005|09:34] C:\Program Files\Setup Files
[22/09/2005|19:47] C:\Program Files\shapes
[22/11/2005|21:08] C:\Program Files\Sierra On-Line
[18/07/2009|16:21] C:\Program Files\Skype
[16/06/2006|12:38] C:\Program Files\Slayers Online
[06/03/2006|18:28] C:\Program Files\SnadBoy's Revelation v2
[07/10/2005|18:10] C:\Program Files\Softwin
[04/02/2009|14:52] C:\Program Files\Sony
[04/02/2009|14:52] C:\Program Files\Sony Ericsson
[14/03/2007|22:25] C:\Program Files\Spybot - Search & Destroy
[04/04/2008|22:05] C:\Program Files\StepMania CVS
[07/08/2005|13:16] C:\Program Files\SysAlbum
[02/04/2006|15:25] C:\Program Files\Teamspeak2_RC2
[22/09/2005|19:47] C:\Program Files\Texture
[08/02/2009|22:58] C:\Program Files\TSO
[29/03/2006|16:22] C:\Program Files\UBISOFT
[30/01/2008|23:44] C:\Program Files\UGCP
[07/08/2005|13:19] C:\Program Files\UI
[04/08/2005|19:18] C:\Program Files\Uninstall Information
[13/06/2009|21:21] C:\Program Files\uTorrent
[14/08/2007|19:55] C:\Program Files\UxTheme Multipatcher Fr
[10/10/2007|18:33] C:\Program Files\Veoh Networks
[05/08/2005|09:32] C:\Program Files\VIA
[28/08/2009|15:58] C:\Program Files\VideoLAN
[15/10/2008|17:50] C:\Program Files\Visicom Media
[26/03/2007|17:54] C:\Program Files\Web
[03/01/2009|23:22] C:\Program Files\Winamp
[21/01/2007|19:42] C:\Program Files\Windows Defender
[16/08/2005|11:54] C:\Program Files\Windows Journal Viewer
[09/03/2008|13:19] C:\Program Files\Windows Live
[13/06/2009|21:07] C:\Program Files\Windows Media Connect 2
[06/06/2009|15:47] C:\Program Files\Windows Media Player
[04/08/2005|20:09] C:\Program Files\Windows NT
[04/08/2005|20:11] C:\Program Files\WindowsUpdate
[04/10/2007|19:53] C:\Program Files\WinRAR
[04/08/2005|20:12] C:\Program Files\xerox
[18/07/2009|16:23] C:\Program Files\Yahoo!
[07/02/2009|03:32] C:\Program Files\???????????
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[06/08/2005|12:19] C:\Program Files\Fichiers communs\Adobe
[05/08/2005|09:41] C:\Program Files\Fichiers communs\Ahead
[26/09/2008|22:17] C:\Program Files\Fichiers communs\Apple
[03/12/2007|15:44] C:\Program Files\Fichiers communs\BitDefender
[24/07/2009|15:44] C:\Program Files\Fichiers communs\CyberLink
[19/06/2009|15:41] C:\Program Files\Fichiers communs\DivX Shared
[29/01/2006|12:49] C:\Program Files\Fichiers communs\greenstreet
[14/03/2007|15:11] C:\Program Files\Fichiers communs\GTK
[11/01/2006|13:48] C:\Program Files\Fichiers communs\InstallShield
[21/10/2005|21:23] C:\Program Files\Fichiers communs\Java
[30/06/2007|13:20] C:\Program Files\Fichiers communs\Logitech
[04/02/2009|14:42] C:\Program Files\Fichiers communs\Microsoft Shared
[04/08/2005|20:10] C:\Program Files\Fichiers communs\MSSoap
[01/03/2099|03:17] C:\Program Files\Fichiers communs\ODBC
[04/08/2005|20:10] C:\Program Files\Fichiers communs\Services
[03/12/2007|15:36] C:\Program Files\Fichiers communs\Softwin
[04/02/2009|14:53] C:\Program Files\Fichiers communs\Sony Shared
[01/03/2099|03:17] C:\Program Files\Fichiers communs\SpeechEngines
[04/08/2005|20:10] C:\Program Files\Fichiers communs\System
[09/03/2008|13:18] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[15/10/2008|16:53] C:\Program Files\Fichiers communs\Xuisoft
--------------------\\ Process
( 42 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 20:35:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 153
--------------------\\ Recherche d'autres infections
Trojan ! .. C:\WINDOWS\system32\TDSSservers.dat
Trojan ! .. C:\WINDOWS\system32\TDSSinit.dll
--------------------\\ Suspect ..
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
[F:22][D:6]-> C:\DOCUME~1\admin\LOCALS~1\Temp
[F:234][D:0]-> C:\DOCUME~1\admin\Cookies
[F:12][D:4]-> C:\DOCUME~1\admin\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 30/08/2009|22:48 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 30/08/2009|23:16 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 02/09/2009|20:37 - Option : [2]
--------------------\\ Fin du rapport a 20:37:47
Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2735
Windows 5.1.2600 Service Pack 2
03/09/2009 17:30:01
mbam-log-2009-09-03 (17-30-01).txt
Type de recherche: Examen rapide
Eléments examinés: 106944
Temps écoulé: 8 minute(s), 15 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Program Files\JPEGLIB.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdsspopup1.url (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdsspopup2.url (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdsspopup3.url (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> Quarantined and deleted successfully.
Version de la base de données: 2735
Windows 5.1.2600 Service Pack 2
03/09/2009 17:30:01
mbam-log-2009-09-03 (17-30-01).txt
Type de recherche: Examen rapide
Eléments examinés: 106944
Temps écoulé: 8 minute(s), 15 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Program Files\JPEGLIB.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdsspopup1.url (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdsspopup2.url (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdsspopup3.url (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> Quarantined and deleted successfully.
- Java 2 Runtime Environment, SE v1.4.2_04
- Java 6 Update 2
- Java 6 Update 3
- Java 6 Update 4
- Java 6 Update 5
- Java SE Runtime Environment 6 Update 1
Lassé par la pub ? Créez un compte
- Contenus similaires :
- Forumiexplore.exe ou chrome.exe dans processus utilise la memoir de mon pc
- Forumiexplore.exe dans processus utilise la memoir de mon pc [résolu]
- Forumhelp !Plusieurs Processus IEXPLORE.EXE dans le gestionnaire des taches
- ForumPlusieurs processus iexplore.exe tout seul [Résolu]
- ForumProcessus iexplore.exe gênants [Résolu]
- ForumProcessus iexplore.exe se lance tout seul
- ForumDeux iexplorer.exe dans mon processus
- ForumProblème avec iexplore.exe qui se lance tout seul
- Forum[RESOLU] Iexplore.exe bloqué à 100 %
- Voir plus