Mon bureau ne s'affiche plus !
Hors ligneMister_masque Le 31/03/2009 à 17:51 Profil de Mister_masque Configuration de Mister_masque

Erf, je ne vois pas pourquoi tu te fermes, j'apprécie que les autres essaye d'aider, je te faisais seulement une remarque sur les liens.
Enfin bon, prend le comme tu veux, mais je n'avais pas du tout un ton moralisateur ou didactique, seulement en petite remarque.

Dommage que ce topic finisse en grande bataille

@+
--
Hors ligneRemi3211 Le 31/03/2009 à 17:54 Profil de Remi3211 Configuration de Remi3211

Ya que le fichier log !

Logfile of random's system information tool 1.06 (written by random/random)
Run by Rémi at 2009-03-31 17:46:54
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 173 GB (73%) free of 238 GB
Total RAM: 1023 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:53:28, on 31/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\Rémi\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Rémi\Bureau\RSIT.exe
C:\Program Files\trend micro\Rémi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SoftwareHelper] C:\Documents and Settings\Rémi\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mauewso] "c:\documents and settings\rémi\local settings\application data\mauewso.exe" mauewso
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Java S1] \\?\globalroot\systemroot\system32\mschr.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Download All Files by HiDownload - C:\Program Files\StreamingStar\HiDownload\HDGetAll.htm
O8 - Extra context menu item: Download by HiDownload - C:\Program Files\StreamingStar\HiDownload\HDGet.htm
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - C:\Program Files\StreamingStar\HiDownload\hidownload.exe (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C06439F4-A9EC-433E-A511-08C6186E6ADE}: NameServer = 212.30.96.108,213.203.124.146
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ElevatorService - Unknown owner - C:\Program Files\RipTiger\ElevatorService.exe
O23 - Service: Google Update Service (gupdate1c98b9abbe953e8) (gupdate1c98b9abbe953e8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe

--
End of file - 12256 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2849272039-2815165872-511180383-1007.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{DB3B6BB2-ECA4-41D1-B49F-871B7E2B8C20}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-27 312928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-21 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{955BE0B8-BC85-4CAF-856E-8E0D8B610560}]
BHO pour Compagnon Web Encarta - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL [2005-06-04 228048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-03-24 251504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-03-24 657904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C56CB6B0-0D96-11D6-8C65-B2868B609932}]
NTIECatcher Class - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll [2003-12-15 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-03-24 522224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-21 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-21 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{147D6308-0614-4112-89B1-31402F9B82C4} - Compagnon Web Encarta - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL [2005-06-04 228048]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-09-26 352256]
{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - Veoh Web Player Video Finder - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll [2008-10-10 463872]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-03-24 251504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-12-01 7311360]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-03-12 342312]
"EoEngine"= []
"SoftwareHelper"=C:\Documents and Settings\Rémi\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe [2008-12-09 368224]
"EoDesk3d"= []
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-03-27 198160]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"mauewso"=c:\documents and settings\rémi\local settings\application data\mauewso.exe mauewso []
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-24 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe [2007-03-16 63712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-03-12 342312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-10 67128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
C:\WINDOWS\KHALMNPR.EXE [2005-05-20 28160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2005-12-01 7311360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2005-11-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
C:\Program Files\Spyware Doctor\swdoctor.exe /Q []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STICAP]
C:\WINDOWS\Twain_32\USB2.0Camera\SnapTrap.exe [2004-11-05 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-21 136600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-24 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-03-27 198160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe [2008-09-26 3660848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [2008-10-10 3502840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2005-05-11 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE  []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LOGITE~1.EXE [2007-03-10 67128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
C:\PROGRA~1\Logitech\SetPoint\SetPoint.exe [2005-05-25 450560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Rémi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
C:\PROGRA~1\OPENOF~1.3\program\QUICKS~1.EXE  []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Rémi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2008-09-12 384000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
C:\WINDOWS\system32\LMIinit.dll [2008-10-16 87352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-02-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"legalnoticecaption"=
"legalnoticetext"=

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Disabled:eMule"
"C:\Program Files\FrostWire\FrostWire.exe"="C:\Program Files\FrostWire\FrostWire.exe:*:Disabled:FrostWire"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3e8462a-baec-11dc-93ba-0015f2585dd2}]
shell\AutoRun\command - D:\Imageviewer.exe


======File associations======

.scr - config - "%1" /S

======List of files/folders created in the last 1 months======

2009-03-31 16:56:48 ----A---- C:\WINDOWS\system32\VACFix.exe
2009-03-31 16:56:48 ----A---- C:\WINDOWS\system32\o4Patch.exe
2009-03-31 16:56:48 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
2009-03-31 16:56:48 ----A---- C:\WINDOWS\system32\Agent.OMZ.Fix.exe
2009-03-31 16:56:48 ----A---- C:\WINDOWS\system32\404Fix.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\WS2Fix.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\VCCLSID.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\swxcacls.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\swsc.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\swreg.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\SrchSTS.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\Process.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\IEDFix.exe
2009-03-31 16:56:47 ----A---- C:\WINDOWS\system32\dumphive.exe
2009-03-31 16:51:22 ----D---- C:\Program Files\MessengerDiscovery
2009-03-31 16:45:16 ----D---- C:\Program Files\Online Services
2009-03-31 15:47:56 ----A---- C:\WINDOWS\ntbtlog.txt
2009-03-31 08:48:01 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-31 08:46:07 ----D---- C:\Program Files\SUPERAntiSpyware
2009-03-31 08:46:07 ----D---- C:\Documents and Settings\Rémi\Application Data\SUPERAntiSpyware.com
2009-03-28 18:00:27 ----D---- C:\Documents and Settings\All Users\Application Data\LogMeIn
2009-03-28 18:00:11 ----A---- C:\WINDOWS\system32\LMIport.dll
2009-03-28 18:00:10 ----A---- C:\WINDOWS\system32\LMIRfsClientNP.dll
2009-03-28 17:59:35 ----A---- C:\WINDOWS\system32\LMIinit.dll
2009-03-27 17:15:59 ----D---- C:\hidownload
2009-03-27 17:13:18 ----D---- C:\Program Files\StreamingStar
2009-03-27 13:03:48 ----D---- C:\Program Files\Fichiers communs\xing shared
2009-03-27 11:54:53 ----D---- C:\Documents and Settings\Rémi\Application Data\Stardock
2009-03-27 11:54:33 ----HDC---- C:\Documents and Settings\All Users\Application Data\{2C0895CF-C7CF-4FF0-B3B8-C0518C9E3418}
2009-03-27 11:54:26 ----D---- C:\Program Files\Stardock
2009-03-27 11:54:26 ----D---- C:\Documents and Settings\All Users\Application Data\Stardock
2009-03-26 16:17:43 ----D---- C:\Documents and Settings\Rémi\Application Data\live-player
2009-03-26 16:17:37 ----D---- C:\Program Files\Fichiers communs\DivX Shared
2009-03-26 16:07:22 ----D---- C:\Documents and Settings\Rémi\Application Data\Flock
2009-03-26 16:04:43 ----D---- C:\Program Files\Flock
2009-03-26 16:03:47 ----D---- C:\Documents and Settings\Rémi\Application Data\OpenCandy
2009-03-26 15:57:22 ----D---- C:\Program Files\FLVCodec
2009-03-26 15:57:06 ----D---- C:\Program Files\WinPcap
2009-03-26 15:57:00 ----D---- C:\Program Files\RipTiger
2009-03-26 15:54:56 ----D---- C:\Program Files\Xi
2009-03-26 11:57:21 ----A---- C:\WINDOWS\BricoPackUninst.cmd
2009-03-26 11:55:25 ----A---- C:\WINDOWS\BricoPackUninst.txt
2009-03-26 11:55:24 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
2009-03-26 11:54:49 ----D---- C:\WINDOWS\BricoPacks
2009-03-26 10:03:49 ----D---- C:\Documents and Settings\Rémi\Application Data\EoRezo
2009-03-26 09:57:22 ----D---- C:\Program Files\TGTSoft
2009-03-25 16:15:23 ----D---- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2009-03-25 14:44:31 ----D---- C:\Program Files\Messenger Plus! Live
2009-03-24 16:29:50 ----D---- C:\WINDOWS\ie8updates
2009-03-24 16:28:04 ----HDC---- C:\WINDOWS\ie8
2009-03-24 16:26:23 ----D---- C:\Documents and Settings\Rémi\Application Data\Opera
2009-03-24 16:25:52 ----D---- C:\Program Files\Opera
2009-03-24 12:52:00 ----D---- C:\Program Files\iPod
2009-03-24 12:51:46 ----D---- C:\Program Files\iTunes
2009-03-24 12:51:46 ----D---- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-24 12:38:43 ----D---- C:\Program Files\Safari
2009-03-24 10:59:27 ----D---- C:\Documents and Settings\Rémi\Application Data\FrostWire
2009-03-24 10:58:17 ----D---- C:\Program Files\FrostWire
2009-03-24 09:48:59 ----D---- C:\Program Files\Avira
2009-03-24 09:43:08 ----D---- C:\Program Files\Windows Live SkyDrive
2009-03-23 21:08:03 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-03-23 20:37:45 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-03-23 20:37:45 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-03-23 20:37:45 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-03-23 20:37:45 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-03-23 20:37:29 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-03-23 20:37:28 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-03-23 20:37:28 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-03-23 20:37:24 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-03-23 20:37:24 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-03-23 20:37:22 ----A---- C:\WINDOWS\system32\pthreadGC2.dll
2009-03-23 20:37:21 ----D---- C:\Program Files\K-Lite Codec Pack
2009-03-23 20:37:21 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2009-03-23 20:33:16 ----D---- C:\Program Files\a-squared Free
2009-03-23 20:13:34 ----D---- C:\WINDOWS\SxsCaPendDel
2009-03-23 17:14:27 ----D---- C:\Program Files\Panda Security
2009-03-23 16:55:12 ----SHD---- C:\RECYCLER
2009-03-23 16:54:37 ----D---- C:\_OTMoveIt
2009-03-23 16:33:46 ----D---- C:\WINDOWS\BDOSCAN8
2009-03-23 16:02:36 ----A---- C:\ComboFix.txt
2009-03-23 15:41:16 ----A---- C:\Boot.bak
2009-03-23 15:41:08 ----D---- C:\cmdcons
2009-03-23 15:39:59 ----A---- C:\WINDOWS\zip.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\VFIND.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\SWSC.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\SWREG.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\sed.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\NIRCMD.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\grep.exe
2009-03-23 15:39:59 ----A---- C:\WINDOWS\fdsv.exe
2009-03-23 15:39:52 ----D---- C:\WINDOWS\ERDNT
2009-03-23 15:39:37 ----D---- C:\Qoobox
2009-03-23 10:18:04 ----D---- C:\WINDOWS\system32\NtmsData
2009-03-22 16:37:16 ----A---- C:\FindyKill.txt
2009-03-20 19:43:44 ----D---- C:\Documents and Settings\Rémi\Application Data\Malwarebytes
2009-03-20 19:43:36 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-03-20 19:43:36 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-03-17 21:52:07 ----A---- C:\fixnavi.txt
2009-03-17 21:48:50 ----D---- C:\Program Files\Navilog1
2009-03-17 21:42:45 ----A---- C:\WINDOWS\system32\tmp.txt
2009-03-17 21:42:31 ----A---- C:\rapport.txt
2009-03-17 20:38:47 ----D---- C:\Program Files\trend micro
2009-03-17 20:38:42 ----D---- C:\rsit
2009-03-13 21:32:54 ----A---- C:\WINDOWS\msnfix.txt
2009-03-13 21:32:04 ----D---- C:\Program Files\MSNFix
2009-03-13 21:05:39 ----D---- C:\Program Files\Fichiers communs\Windows Live
2009-03-08 15:17:46 ----N---- C:\WINDOWS\system32\msrating.dll.mui
2009-03-08 15:17:30 ----N---- C:\WINDOWS\system32\mshta.exe.mui
2009-03-08 15:16:06 ----N---- C:\WINDOWS\system32\ie4uinit.exe.mui
2009-03-08 15:15:48 ----N---- C:\WINDOWS\system32\iedkcs32.dll.mui

======List of files/folders modified in the last 1 months======

2009-03-31 17:50:04 ----A---- C:\MDL 2.0 Debug.txt
2009-03-31 17:47:06 ----D---- C:\WINDOWS\Prefetch
2009-03-31 17:43:04 ----D---- C:\Program Files\Mozilla Firefox
2009-03-31 17:42:35 ----D---- C:\WINDOWS\Temp
2009-03-31 17:41:54 ----D---- C:\WINDOWS\system32\ias
2009-03-31 17:41:49 ----A---- C:\WINDOWS\ModemLog_Modem 56000 bps Standard.txt
2009-03-31 17:41:41 ----D---- C:\WINDOWS
2009-03-31 17:38:44 ----AD---- C:\WINDOWS\system32
2009-03-31 17:34:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-03-31 17:18:22 ----HD---- C:\WINDOWS\inf
2009-03-31 17:18:10 ----D---- C:\WINDOWS\system32\CatRoot2
2009-03-31 17:14:02 ----AD---- C:\Program Files
2009-03-31 16:46:32 ----D---- C:\WINDOWS\system32\drivers
2009-03-31 16:46:11 ----D---- C:\WINDOWS\system32\config
2009-03-31 16:45:35 ----D---- C:\WINDOWS\system32\wbem
2009-03-31 16:45:35 ----D---- C:\WINDOWS\Registration
2009-03-31 16:45:17 ----HD---- C:\Config.Msi
2009-03-31 16:45:16 ----SHD---- C:\WINDOWS\Installer
2009-03-31 16:45:13 ----D---- C:\Documents and Settings
2009-03-31 16:45:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-03-31 15:53:25 ----A---- C:\WINDOWS\system.ini
2009-03-31 15:08:27 ----A---- C:\WINDOWS\win.ini
2009-03-31 13:43:45 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-03-31 11:35:35 ----D---- C:\FAUXVIRUS
2009-03-31 09:33:28 ----D---- C:\WINDOWS\Debug
2009-03-31 09:24:27 ----AC---- C:\WINDOWS\tsc.ini
2009-03-31 09:22:59 ----D---- C:\WINDOWS\report
2009-03-31 09:11:01 ----A---- C:\WINDOWS\NeroDigital.ini
2009-03-31 09:04:10 ----D---- C:\Documents and Settings\Rémi\Application Data\codeblocks
2009-03-31 08:45:44 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2009-03-29 17:52:12 ----D---- C:\Program Files\LimeWire
2009-03-29 16:49:53 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-28 18:10:16 ----ASH---- C:\boot.ini
2009-03-28 17:49:24 ----D---- C:\Documents and Settings\Rémi\Application Data\TeamViewer
2009-03-28 15:28:33 ----D---- C:\Program Files\Fichiers communs
2009-03-28 12:15:46 ----D---- C:\Program Files\Outlook Express
2009-03-28 12:15:46 ----D---- C:\Program Files\Movie Maker
2009-03-28 12:15:45 ----D---- C:\WINDOWS\system32\usmt
2009-03-27 16:10:06 ----D---- C:\Program Files\Notepad++
2009-03-27 15:59:48 ----D---- C:\Program Files\Wakfu
2009-03-27 15:49:32 ----D---- C:\Documents and Settings\Rémi\Application Data\LimeWire
2009-03-27 13:04:12 ----D---- C:\Documents and Settings\Rémi\Application Data\Real
2009-03-27 13:03:43 ----D---- C:\Program Files\Fichiers communs\Real
2009-03-27 13:03:26 ----A---- C:\WINDOWS\system32\msvcr71.dll
2009-03-27 13:03:26 ----A---- C:\WINDOWS\system32\msvcp71.dll
2009-03-27 12:02:38 ----D---- C:\WINDOWS\Resources
2009-03-27 11:56:13 ----D---- C:\WINDOWS\Microsoft.NET
2009-03-27 11:56:03 ----RSD---- C:\WINDOWS\assembly
2009-03-27 09:20:15 ----SD---- C:\WINDOWS\Tasks
2009-03-26 17:27:20 ----D---- C:\Program Files\Fichiers communs\Apple
2009-03-26 16:29:27 ----D---- C:\Program Files\DivX
2009-03-26 15:57:18 ----D---- C:\Program Files\Apowersoft
2009-03-26 15:20:40 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-03-26 13:01:37 ----D---- C:\WINDOWS\SHELLNEW
2009-03-26 13:01:36 ----RD---- C:\WINDOWS\Web
2009-03-26 12:04:23 ----RSD---- C:\WINDOWS\Fonts
2009-03-26 11:57:20 ----A---- C:\WINDOWS\system32\uxtheme.dll
2009-03-26 11:56:29 ----D---- C:\WINDOWS\Cursors
2009-03-26 11:56:15 ----D---- C:\WINDOWS\Media
2009-03-25 16:24:23 ----D---- C:\Program Files\MSN Messenger
2009-03-25 16:20:52 ----D---- C:\Program Files\Windows Live
2009-03-24 16:32:23 ----D---- C:\WINDOWS\system32\fr-fr
2009-03-24 16:32:22 ----D---- C:\WINDOWS\Help
2009-03-24 16:32:22 ----D---- C:\Program Files\Internet Explorer
2009-03-24 16:29:39 ----HD---- C:\WINDOWS\$hf_mig$
2009-03-24 16:27:53 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-24 15:03:39 ----D---- C:\Documents and Settings\Rémi\Application Data\Apple Computer
2009-03-24 12:48:56 ----D---- C:\Program Files\QuickTime
2009-03-24 09:30:27 ----D---- C:\Program Files\Google
2009-03-24 09:30:27 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-03-24 08:29:14 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-03-24 08:29:14 ----D---- C:\Program Files\Triogical2
2009-03-24 08:29:14 ----AD---- C:\WINDOWS\I386
2009-03-23 21:45:25 ----D---- C:\WINDOWS\Minidump
2009-03-23 21:42:12 ----D---- C:\Documents and Settings\All Users\Application Data\WLInstaller
2009-03-23 21:29:02 ----D---- C:\Documents and Settings\Rémi\Application Data\Mozilla
2009-03-23 21:15:06 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-03-23 21:07:22 ----D---- C:\WINDOWS\WinSxS
2009-03-23 20:59:16 ----D---- C:\Program Files\Fichiers communs\DVDVideoSoft
2009-03-23 20:47:04 ----D---- C:\Program Files\Sinistar
2009-03-23 20:46:08 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-23 20:41:17 ----D---- C:\Program Files\Replay Converter 3
2009-03-23 20:37:50 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-03-23 20:35:31 ----D---- C:\Program Files\Norton Security Scan
2009-03-23 20:35:25 ----D---- C:\Program Files\Fichiers communs\Symantec Shared
2009-03-23 20:32:16 ----D---- C:\Program Files\CCleaner
2009-03-23 20:27:11 ----D---- C:\Program Files\NCH Swift Sound
2009-03-23 20:25:53 ----D---- C:\Program Files\MUSICMATCH
2009-03-23 20:22:18 ----D---- C:\Program Files\Microsoft Works
2009-03-23 20:22:11 ----D---- C:\Program Files\Microsoft Office
2009-03-23 20:13:49 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-03-23 20:08:25 ----D---- C:\Program Files\WebSite X5 Evolution
2009-03-23 20:08:17 ----D---- C:\Program Files\BoontyGames
2009-03-23 20:05:30 ----D---- C:\Program Files\Spyware Doctor
2009-03-23 20:05:28 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-03-23 20:04:38 ----D---- C:\Program Files\Hitman Pro
2009-03-23 20:02:59 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-23 19:59:52 ----D---- C:\Program Files\Cimaware
2009-03-23 19:59:44 ----D---- C:\Program Files\Cheat Engine
2009-03-23 19:58:51 ----D---- C:\Program Files\boxes
2009-03-23 18:37:45 ----SD---- C:\Documents and Settings\Rémi\Application Data\Microsoft
2009-03-23 18:29:36 ----D---- C:\WINDOWS\system32\DirectX
2009-03-23 17:39:16 ----SHD---- C:\System Volume Information
2009-03-23 17:39:16 ----D---- C:\WINDOWS\system32\Restore
2009-03-23 15:51:10 ----D---- C:\WINDOWS\AppPatch
2009-03-22 11:45:42 ----D---- C:\WINDOWS\network diagnostic
2009-03-21 21:57:42 ----D---- C:\Documents and Settings\All Users\Application Data\TrackMania
2009-03-20 21:07:36 ----AC---- C:\WINDOWS\system32\MRT.INI
2009-03-20 19:52:23 ----D---- C:\Program Files\Microsoft SQL Server
2009-03-19 19:19:54 ----D---- C:\Program Files\adslTV
2009-03-19 14:30:14 ----D---- C:\wamp
2009-03-17 18:53:38 ----D---- C:\Program Files\Alexandra Ledermann - La colline aux chevaux sauvages
2009-03-10 18:41:18 ----D---- C:\Program Files\eMule
2009-03-08 15:18:02 ----A---- C:\WINDOWS\system32\ieframe.dll.mui
2009-03-08 15:16:06 ----A---- C:\WINDOWS\system32\advpack.dll.mui
2009-03-08 15:09:26 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-03-08 05:41:16 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-03-08 05:39:48 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-03-08 05:34:58 ----A---- C:\WINDOWS\system32\wininet.dll
2009-03-08 05:34:56 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-03-08 05:34:48 ----A---- C:\WINDOWS\system32\WinFXDocObj.exe
2009-03-08 05:34:48 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-03-08 05:34:30 ----A---- C:\WINDOWS\system32\licmgr10.dll
2009-03-08 05:34:28 ----A---- C:\WINDOWS\system32\url.dll
2009-03-08 05:34:18 ----A---- C:\WINDOWS\system32\occache.dll
2009-03-08 05:34:18 ----A---- C:\WINDOWS\system32\msrating.dll
2009-03-08 05:33:40 ----A---- C:\WINDOWS\system32\corpol.dll
2009-03-08 05:33:26 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-03-08 05:33:16 ----A---- C:\WINDOWS\system32\jscript.dll
2009-03-08 05:33:08 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-03-08 05:33:06 ----A---- C:\WINDOWS\system32\vbscript.dll
2009-03-08 05:33:02 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-03-08 05:32:56 ----A---- C:\WINDOWS\system32\admparse.dll
2009-03-08 05:32:54 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-03-08 05:32:52 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-03-08 05:32:52 ----A---- C:\WINDOWS\system32\ieakui.dll
2009-03-08 05:32:50 ----A---- C:\WINDOWS\system32\iesetup.dll
2009-03-08 05:32:50 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-03-08 05:32:48 ----A---- C:\WINDOWS\system32\advpack.dll
2009-03-08 05:32:46 ----A---- C:\WINDOWS\system32\inseng.dll
2009-03-08 05:32:26 ----A---- C:\WINDOWS\system32\msfeeds.dll
2009-03-08 05:32:22 ----A---- C:\WINDOWS\system32\iertutil.dll
2009-03-08 05:32:04 ----A---- C:\WINDOWS\system32\mstime.dll
2009-03-08 05:31:56 ----A---- C:\WINDOWS\system32\iepeers.dll
2009-03-08 05:31:54 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2009-03-08 05:31:52 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-03-08 05:31:52 ----A---- C:\WINDOWS\system32\icardie.dll
2009-03-08 05:31:44 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-03-08 05:31:38 ----A---- C:\WINDOWS\system32\imgutil.dll
2009-03-08 05:31:38 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-03-08 05:31:36 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-03-08 05:31:26 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-03-08 05:31:18 ----A---- C:\WINDOWS\system32\mshtmler.dll
2009-03-08 05:31:02 ----A---- C:\WINDOWS\system32\mshta.exe
2009-03-08 05:22:46 ----A---- C:\WINDOWS\system32\ieui.dll
2009-03-08 05:22:38 ----A---- C:\WINDOWS\system32\msls31.dll
2009-03-08 05:11:12 ----A---- C:\WINDOWS\system32\ieapfltr.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-24 75072]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-11-08 21248]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-01-14 5632]
R2 irda;Protocole IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-11-22 3804416]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2009-01-15 23848]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 LHidKe;Logitech SetPoint HID Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidKE.Sys [2005-05-20 25600]
R3 LHidUsbK;Logitech SetPoint USB Receiver device driver; C:\WINDOWS\System32\Drivers\LHidUsbK.Sys [2005-05-20 36480]
R3 lmimirr;lmimirr; C:\WINDOWS\system32\DRIVERS\lmimirr.sys [2008-07-24 10144]
R3 LMouKE;Logitech SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2005-05-20 68352]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-12-01 3535424]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-06-30 33664]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-06-30 12928]
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-05 5888]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\System32\Drivers\L8042Kbd.sys [2005-05-20 13056]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nm;Pilote du Moniteur réseau; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 PLCMP532;PLCMP532 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PLCMP532.sys []
S3 PLCND532;PLCND532 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PLCND532.sys [2007-02-07 26656]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SDVC05;USB SDVC05; C:\WINDOWS\System32\Drivers\SDVC05.sys [2003-07-22 18088]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SONYPVU1;Pilote de filtrage Sony USB (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 SQTECH930B;USB 2.0 PC CAMERA; C:\WINDOWS\System32\Drivers\Capt930b.sys [2005-01-26 247325]
S3 STIrUsb;STIrUsb.sys iRwave 520US USB-IrDA Adapter; C:\WINDOWS\system32\DRIVERS\irstusb.sys [2001-09-24 30088]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 LMIRfsClientNP;LMIRfsClientNP; C:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []
S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-05 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2009-02-25 425080]
R2 AntiVirScheduler;Planificateur Avira AntiVir Personal - Free Antivirus; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-21 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-12-01 131139]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;Enregistreur VSS SQL Server; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-03-12 656168]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
S2 gupdate1c98b9abbe953e8;Google Update Service (gupdate1c98b9abbe953e8); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-10 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 ElevatorService;ElevatorService; C:\Program Files\RipTiger\ElevatorService.exe [2009-02-11 180224]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 137200]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe [2008-12-10 24636]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe [2008-11-15 6447744]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------
Hors ligneUsualsuspect Le 31/03/2009 à 18:02 Profil de Usualsuspect Configuration de Usualsuspect

En condensation
Mister-masque, tu n'as pas à te justifier. A mon avis tu fais un super travail ici et ton intervention était on ne peut plus normale et pondérée.

Hug.
Salut les visages pales.
Hors ligneRemi3211 Le 31/03/2009 à 18:04 Profil de Remi3211 Configuration de Remi3211

Bon pour moi ?
Hors ligneMister_masque Le 31/03/2009 à 18:20 Profil de Mister_masque Configuration de Mister_masque

Ben pour toi, on commence

Infection Navipromo et EoRezo

T'a trop de protection, sa va nous gêner.

Désinstalle :

  • A-Squared Free Anti-malware
  • PCTools Spyware Doctor
  • SUPERAntiSpyware
  • Panda Antivirus
  • Spybot Search & Destroy
  • Norton Security Scan




En gros, garde seulement Antivir et MalwareBytes.



# 1 - NAVILOG




Télécharge Navilog.exe par IL-MAFIOSO.

  • Clique Droit sur Navilog.exe et Navilog.bat >> Exécuter en tant qu'administrateur (Sous Vista, si sous XP, ignorer cette étape).
  • Installe Navilog, en cliquant sur "Suivant", "Installer" et "Terminé".
  • Une fois installé, Navilog se lance automatiquement (Si ce n'es pas le cas, double clique sur l'icône présente sur le Bureau)
  • Tape "f", valide avec la touche "Entrée" du clavier, fait défiler grâce à la touche "Espace", sélectionne l'option 1 (Recherche)valide avec la touche "Entrée" du clavier, Patiente et poste le rapport.


Aide: Tutoriel Navilog, si tu es perdu.




# 2 - AD-REMOVER



Télécharge AdRemover de Cyrildu17

  • Exécute le et installe le en cliquant sur suivant et en laissant les options par défaut
  • Exécute la nouvelle icône qui est apparu sur ton Bureau, clique sur "Ok" si une fenêtre apparait, pour choisir la langue tape F puis tape Entrée
  • Sélectionne l'option A(Recherche) avec la touche A et tape Entrée
  • Patiente, quand le scan et finit, appuie sur une touche pour afficher le rapport et psote le sur le forum



NB: Le rapport se trouve dans C:\Ad-Report-Date.log




~~~~~~~~~~


Ce fichier me semble infecté :

Scanner C:\Windows\system32\mschr.exe
sur :

Virus Total

Poster le rapport de Scan.


Rapport attendu:

  1. Rapport Navilog
  2. Rapport Ad-Remover
  3. Scan Virus total




@+

--
Hors ligneRemi3211 Le 31/03/2009 à 18:51 Profil de Remi3211 Configuration de Remi3211

Le fichir que tu dis n'existe pas ils disent sur Virus total
Hors ligneMister_masque Le 31/03/2009 à 18:52 Profil de Mister_masque Configuration de Mister_masque

On vérifiera cela plus tard alors.
Poste les rapports demandés sans le rapport Virus Total.

@+
--
Hors ligneRemi3211 Le 31/03/2009 à 18:54 Profil de Remi3211 Configuration de Remi3211

Le premier rapport
------- LOGFILE OF AD-REMOVER 1.1.2.4 | ONLY XP/VISTA -------

Updated by C_XX on 29/03/2009 at 19:20
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/

Start at: 18:47:07, Mar 31/03/2009 | Boot mode: Normal Boot
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™  Service Pack 3 (version 5.1.2600)
Computer Name: NOM-2D74BF4DA8B
Current User: R‚mi - Administrator
Drive(s):
- C:\  (File System: NTFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 48

+-----------------| Boonty/Boonty Games Elements Found:

.
HKCR\boontybox
HKLM\Software\Boonty
HKLM\Software\Classes\boontybox
.
C:\Program Files\BoontyGames
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Documents and Settings\All Users\Application Data\BOONTY

+-----------------| Eorezo Elements Found:

HKCU\Software\EoRezo
HKLM\Software\EoRezo
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eodesk3d
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Softwarehelper
.
C:\Documents and Settings\R‚mi\Application Data\EoRezo
C:\Documents and Settings\R‚mi\Application Data\Eorezo
C:\WINDOWS\Prefetch\SOFTWAREUPDATEHP.EXE-1425B579.pf
C:\Documents and Settings\R‚mi\Cookies\r‚mi@eorezo[1].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@eorezo[2].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@eorezo[3].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@eorezo[1].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@eorezo[2].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@eorezo[3].txt

+-----------------| Infected Poker Softwares Elements Found:

.

+-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

.
.

+-----------------| It's TV Elements Found:

.

+-----------------| Sweetim Elements Found:

.

============ Other Adwares Found ============

.
.
C:\Documents and Settings\R‚mi\Cookies\r‚mi@atdmt[2].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@atdmt[3].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@bs.serving-sys[2].txt
C:\Documents and Settings\R‚mi\Cookies\r‚mi@bs.serving-sys[3].txt

+-----------------| Added Scan:

---- Mozilla FireFox Version 3.0.8 ----

ProfilePath: riy9y0th.default (R‚mi)
.
.
.
.
.
.

---- Internet Explorer Version 8.0.6001.18702 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896

+-[HKEY_USERS\S-1-5-21-2849272039-2815165872-511180383-1009\..\Internet Explorer\Main]

Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search bar: hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://y.lo.st

+---------------------------------------------------------------------------+

3376 Byte(s) - C:\Ad-Report-Scan-31.03.2009.log

0 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
0 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

End at: 18:58:56 | 31/03/2009
.
+-----------------| E.O.F - 80 Lines
.
Hors ligneMister_masque Le 31/03/2009 à 19:01 Profil de Mister_masque Configuration de Mister_masque

N'oublie pas que sur ce forum, on ne peut poster qu'un message à la fois, tu ne peux pas en envoyé 2 d'affilés.
Pour éditer :



Il faut cliquer sur le petit calepin.

Ok, j'attend le rapport de Navilog.

@+
--
Hors ligneRemi3211 Le 31/03/2009 à 19:06 Profil de Remi3211 Configuration de Remi3211

Le rapport :

Search Navipromo version 3.7.6 commencé le 31/03/2009 à 18:46:50,95

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3500+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Rémi ( Administrator )
BOOT : Normal boot

Antivirus : Avira AntiVir PersonalEdition Classic 8.0.1.30 (Activated)


C:\ (Local Disk) - NTFS - Total:232 Go (Free:168 Go)
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (CD or DVD)
J:\ (USB)


Recherche executé en mode normal


*** Recherche dossiers dans "C:\WINDOWS" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\RÚmi\applic~1" ***

...\Live-Player trouvé !

*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\Laurane\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\LOGMEI~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\RÚmi\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\Laurane\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\LOGMEI~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\RÚmi\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\Laurane\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\LOGMEI~1\menudm~1\progra~1" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "C:\Documents and Settings\RÚmi\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\Laurane\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\LOGMEI~1\locals~1\applic~1" *



*** Recherche fichiers ***



*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mauewso"="\"c:\\documents and settings\\rémi\\local settings\\application data\\mauewso.exe\" mauewso"


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :


* Dans "C:\Documents and Settings\RÚmi\locals~1\applic~1" :


* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :


* Dans "C:\DOCUME~1\Laurane\locals~1\applic~1" :


* Dans "C:\DOCUME~1\LOGMEI~1\locals~1\applic~1" :


3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche autres dossiers et fichiers connus :



*** Analyse terminée le 31/03/2009 à 19:18:54,37 ***
Vous avez résolu votre problème avec VIC ? Faites-le savoir sur les réseaux sociaux !
Vulgarisation-informatique.com
Cours en informatique & tutoriels