Infecté par Trojan-Downloader:W32/Agent.IFD, demande de l'aide

Re, désolé du retard…
Voila le nouveau rapport :

ComboFix 08-12-15.08 - Florian 2008-12-18 21:20:38.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2047.1569 [GMT 1:00]
Lancé depuis: c:\documents and settings\Florian\Bureau\flobo.exe
Commutateurs utilisés :: c:\documents and settings\Florian\Bureau\CFScript.txt.txt

  • Un nouveau point de restauration a été créé

FILE ::
c:\documents and settings\all users\application data\microsoft\network\downloader\qmgr0.dat
c:\documents and settings\all users\application data\microsoft\network\downloader\qmgr1.dat
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
c:\documents and settings\all users\application data\microsoft\network\downloader\qmgr0.dat
c:\documents and settings\all users\application data\microsoft\network\downloader\qmgr1.dat
c:\windows\system32\8c1D3ya5.dll

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-18 au 2008-12-18 ))))))))))))))))))))))))))))))))))))
.

2008-12-16 20:27 . 2008-12-16 20:27 dr------- c:\documents and settings\NetworkService\Favoris
2008-12-16 19:57 . 2008-12-16 19:57 d-------- c:\documents and settings\Florian\Application Data\Malwarebytes
2008-12-16 19:57 . 2008-12-16 19:57 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-16 19:57 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-16 19:57 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-14 15:24 . 2008-12-14 15:23 31,744 --a------ c:\windows\system32\Q23Jc8P5.exe
2008-12-13 12:53 . 2008-12-13 12:53 1,700,352 --a------ c:\windows\system32\gdiplus.dll
2008-12-06 21:25 . 2008-12-06 21:25 d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-06 21:21 . 2008-12-06 21:21 d-------- c:\windows\nview
2008-12-06 21:21 . 2008-12-02 10:13 453,152 --a------ c:\windows\system32\NVUNINST.EXE
2008-12-06 21:21 . 2008-12-02 23:11 453,152 --a------ c:\windows\system32\nvudisp.exe
2008-12-06 21:21 . 2008-12-18 21:23 205,242 --a------ c:\windows\system32\nvapps.xml
2008-12-06 21:21 . 2008-12-02 23:11 18,696 --a------ c:\windows\system32\nvdisp.nvu
2008-12-05 18:09 . 2008-12-05 18:09 212 --a------ c:\windows\system32\spupdsvc.inf
2008-12-05 18:07 . 2008-12-05 18:14 d-------- c:\windows\SxsCaPendDel
2008-12-03 15:11 . 2008-12-02 23:11 6,209,536 --a------ c:\windows\system32\drivers\nv4_mini.sys
2008-12-03 15:11 . 2008-12-02 23:11 6,166,272 --a------ c:\windows\system32\nv4_disp.dll
2008-12-03 14:44 . 2008-12-03 14:45 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-03 13:22 . 2008-12-03 13:22 dr-h----- c:\documents and settings\Florian\Application Data\SecuROM
2008-12-03 13:17 . 2008-12-03 13:17 d-------- c:\windows\system32\xlive
2008-12-03 13:17 . 2008-12-03 13:30 d-------- c:\program files\Microsoft Games for Windows - LIVE
2008-12-03 12:31 . 2008-12-03 12:31 d-------- c:\program files\MSBuild
2008-12-03 12:30 . 2008-12-05 18:12 d-------- c:\windows\system32\XPSViewer
2008-12-03 12:30 . 2008-12-03 12:30 d-------- c:\program files\Reference Assemblies
2008-12-03 12:29 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 19:23 --------- d-----w c:\program files\Wanadoo
2008-12-14 14:47 --------- d-----w c:\documents and settings\Florian\Application Data\LimeWire
2008-12-03 13:09 --------- d–h--w c:\program files\InstallShield Installation Information
2008-11-12 17:36 --------- d-----w c:\documents and settings\Florian\Application Data\Canon
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-07-31 10:25 22,328 ----a-w c:\documents and settings\Florian\Application Data\PnkBstrK.sys
2008-01-11 22:06 1,602 ----a-w c:\documents and settings\Florian\Application Data\filterclsid.dat
2006-05-03 09:06 163,328 --sh–r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh–r c:\windows\system32\msfDX.dll
2008-09-16 14:32 61,440 --sha-w c:\windows\system32\wuyojogi.dll
.

((((((((((((((((((((((((((((( snapshot@2008-12-17_14.27.01,60 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\ctfmon.exe” [2008-04-14 15360]
“MSMSGS”=“c:\program files\Messenger\msmsgs.exe” [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“F-Secure Manager”=“c:\program files\Securitoo\av_fw\Common\FSM32.EXE” [2007-06-13 176177]
“F-Secure TNB”=“c:\program files\Securitoo\av_fw\FSGUI\TNBUtil.exe” [2007-06-13 733184]
“JMB36X IDE Setup”=“c:\windows\RaidTool\xInsIDE.exe” [2007-03-20 36864]
“36X Raid Configurer”=“c:\windows\system32\xRaidSetup.exe” [2007-11-19 1970176]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-12-02 13680640]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-12-02 86016]
“nwiz”=“nwiz.exe” [2008-12-02 c:\windows\system32\nwiz.exe]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.I420”= i420vfw.dll

[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d’Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d’Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d’Adobe Reader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a------ 2006-11-12 11:48 157592 d:\daemon tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
–a------ 2003-05-08 10:00 49152 d:\omnipage\opwareSE2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--------- 2004-08-23 14:49 20480 c:\progra~1\Wanadoo\Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2006-07-21 09:56 16261632 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 2006-05-16 11:04 2879488 c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“UpdatesDisableNotify”=dword:00000001
“AntiVirusOverride”=dword:00000001
“FirewallOverride”=dword:00000001

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“c:\WINDOWS\system32\PnkBstrA.exe”=
“c:\WINDOWS\system32\PnkBstrB.exe”=
“c:\Program Files\Bonjour\mDNSResponder.exe”=
“d:\CoH opposing fronts\RelicCOH.exe”=
“c:\WINDOWS\system32\muzapp.exe”=
“d:\Crysis\Bin32\Crysis.exe”=
“d:\Crysis\Bin32\CrysisDedicatedServer.exe”=
“c:\Program Files\Windows Live\Messenger\msnmsgr.exe”=
“c:\Program Files\Windows Live\Messenger\livecall.exe”=
“d:\PES 2009\pes2009.exe”=
“d:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe”=
“d:\GTA IV\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe”=

R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-01-03 51072]
R1 F-Secure HIPS;F-Secure HIPS;??\c:\program files\Securitoo\av_fw\HIPS\fshs.sys [2008-01-03 41184]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;??\c:\program files\Securitoo\av_fw\Anti-Virus\minifilter\fsgk.sys [2008-01-03 52736]
S3 DigiCellDriver;DigiCellDriver;??\c:\program files\MSI\DigiCell\NTGLM7X.sys []
S3 RushTopDevice2;RushTopDevice2;??\c:\program files\MSI\DualCoreCenter\RushTop.sys []
S4 F-Secure Filter;F-Secure File System Filter;??\c:\program files\Securitoo\av_fw\Anti-Virus\Win2K\FSfilter.sys [2008-01-03 33024]
S4 F-Secure Recognizer;F-Secure File System Recognizer;??\c:\program files\Securitoo\av_fw\Anti-Virus\Win2K\FSrec.sys [2008-01-03 18432]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{43b964d2-8ff3-11dd-9ab8-0019db4ab03e}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NoLimit.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5a131ac2-41c0-11dc-bd7d-806d6172696f}]
\Shell\AutoRun\command - F:\Livebox.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{b2342196-5146-11dc-ba8e-806d6172696f}]
\Shell\AutoRun\command - F:\FarCryAutoCD.exe
.
Contenu du dossier ‘Tâches planifiées’

2008-12-14 c:\windows\Tasks\At1.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At10.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At11.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At12.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-17 c:\windows\Tasks\At13.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-17 c:\windows\Tasks\At14.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-17 c:\windows\Tasks\At15.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-17 c:\windows\Tasks\At16.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-17 c:\windows\Tasks\At17.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-18 c:\windows\Tasks\At18.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-18 c:\windows\Tasks\At19.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At2.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-18 c:\windows\Tasks\At20.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-18 c:\windows\Tasks\At21.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-18 c:\windows\Tasks\At22.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-17 c:\windows\Tasks\At23.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-17 c:\windows\Tasks\At24.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At3.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At4.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At5.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At6.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At7.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At8.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]

2008-12-14 c:\windows\Tasks\At9.job

  • c:\windows\system32\Q23Jc8P5.exe [2008-12-14 15:23]
    .
    .
    ------- Examen supplémentaire -------
    .
    uSearchMigratedDefaultURL = www.google.com…
    uStart Page = www.google.fr…
    uSearchURL,(Default) = www.google.com…
    IE: E&xporter vers Microsoft Excel - d:\office\OFFICE11\EXCEL.EXE/3000
    IE: Easy-WebPrint Ajouter à la liste d’impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O16 -: {5AEF5128-FE70-49E8-9E86-45F0A2D7E4EE} - go.opendisc.net…
c:\windows\Downloaded Program Files\OpendiscLight.inf

O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - fichiers.touslesdrivers.com…
c:\windows\Downloaded Program Files\hardwaredetection.inf
.


catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-12-18 21:23:34
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


.
--------------------- DLLs chargées dans les processus actifs ---------------------

              • ‘winlogon.exe’(808)
                c:\program files\Securitoo\av_fw\FWES\Program\fsdc.dll

              • ‘lsass.exe’(864)
                c:\program files\Securitoo\av_fw\FWES\Program\fsdc.dll

              • ‘csrss.exe’(780)
                c:\program files\Securitoo\av_fw\FWES\Program\fsdc.dll
                .
                ------------------------ Autres processus actifs ------------------------
                .
                c:\program files\Bonjour\mDNSResponder.exe
                c:\program files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
                c:\program files\Securitoo\av_fw\Common\FSMA32.EXE
                c:\program files\Securitoo\av_fw\Anti-Virus\fsgk32.exe
                c:\windows\system32\FTRTSVC.exe
                c:\windows\system32\nvsvc32.exe
                c:\program files\Securitoo\av_fw\Common\FSMB32.EXE
                c:\windows\system32\PnkBstrA.exe
                c:\program files\Securitoo\av_fw\Common\FCH32.EXE
                c:\program files\Securitoo\av_fw\Anti-Virus\fssm32.exe
                c:\program files\Securitoo\av_fw\FSAUA\program\fsaua.exe
                c:\program files\Securitoo\av_fw\Anti-Virus\fsqh.exe
                c:\program files\Securitoo\av_fw\Common\FAMEH32.EXE
                c:\program files\Securitoo\av_fw\FWES\program\fsdfwd.exe
                c:\program files\Securitoo\av_fw\FSAUA\program\fsus.exe
                c:\progra~1\SECURI~1\av_fw\ANTI-V~1\fsav32.exe
                c:\progra~1\SECURI~1\av_fw\Common\FSM32.EXE
                c:\windows\system32\rundll32.exe
                c:\progra~1\SECURI~1\av_fw\FSGUI\fsguidll.exe
                .


.
Heure de fin: 2008-12-18 21:25:07 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-18 20:25:05
ComboFix2.txt 2008-12-17 13:27:30

Avant-CF: 4 201 332 736 octets libres
Après-CF: 4,250,980,352 octets libres

244 — E O F — 2008-12-12 16:44:54

Re,

Comment va ton pc?

Refait un hijackthis.

@+

RE, bin avant de faire le nouveau scan ComboFix il allait pas très bien :s (Securitoo qui me dit qu’il y a un virus toutes les 2h00, utilisation de l’UC à 0%, utilisation de la mémoire vive a 90% avec pas une seule application en cours) Maintenant je croise les doigts… :wink:

Voila le rapport Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:38:31, on 18/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsus.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
D:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d’aide de l’Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM…\Run: [F-Secure Manager] “C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE” /splash
O4 - HKLM…\Run: [F-Secure TNB] “C:\Program Files\Securitoo\av_fw\FSGUI\TNBUtil.exe” /CHECKALL /WAITFORSW
O4 - HKLM…\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM…\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - D:\OFFICE\OFFICE11\EXCEL.EXE…
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d’impressions - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.orange.fr… (file missing) (HKCU)
O16 - DPF: {5AEF5128-FE70-49E8-9E86-45F0A2D7E4EE} (OpendiscLight Control) - go.opendisc.net…
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - download.divx.com…
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - fichiers.touslesdrivers.com…
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - sdlc-esd.sun.com…
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - messenger.zone.msn.com…
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - messenger.zone.msn.com…
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe


End of file - 8254 bytes

Re,

==>Télécharge random’s system information tool (RSIT) et enregistre le sur ton bureau.

==>Double clique sur RSIT.exe pour lancer l’outil.

==>Clique sur ’ continue ’ à l’écran Disclaimer.

==>Si l’outil HIjackThis (version à jour) n’est pas présent ou non détecté sur l’ordinateur,RSIT le téléchargera et tu devras accepter la licence.

==>Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports
( log.txt & info.txt )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Voila le rapport log.txt :

Logfile of random’s system information tool 1.05 (written by random/random)
Run by Florian at 2008-12-18 21:47:27
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 4 GB (20%) free of 20 GB
Total RAM: 2047 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:47:28, on 18/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsus.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Florian\Bureau\RSIT.exe
D:\Hijackthis\Florian.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d’aide de l’Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM…\Run: [F-Secure Manager] “C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE” /splash
O4 - HKLM…\Run: [F-Secure TNB] “C:\Program Files\Securitoo\av_fw\FSGUI\TNBUtil.exe” /CHECKALL /WAITFORSW
O4 - HKLM…\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM…\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - D:\OFFICE\OFFICE11\EXCEL.EXE…
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d’impressions - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.orange.fr… (file missing) (HKCU)
O16 - DPF: {5AEF5128-FE70-49E8-9E86-45F0A2D7E4EE} (OpendiscLight Control) - go.opendisc.net…
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - download.divx.com…
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - fichiers.touslesdrivers.com…
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - sdlc-esd.sun.com…
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - messenger.zone.msn.com…
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - messenger.zone.msn.com…
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe


End of file - 8335 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At10.job
C:\WINDOWS\tasks\At11.job
C:\WINDOWS\tasks\At12.job
C:\WINDOWS\tasks\At13.job
C:\WINDOWS\tasks\At14.job
C:\WINDOWS\tasks\At15.job
C:\WINDOWS\tasks\At16.job
C:\WINDOWS\tasks\At17.job
C:\WINDOWS\tasks\At18.job
C:\WINDOWS\tasks\At19.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At20.job
C:\WINDOWS\tasks\At21.job
C:\WINDOWS\tasks\At22.job
C:\WINDOWS\tasks\At23.job
C:\WINDOWS\tasks\At24.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\At5.job
C:\WINDOWS\tasks\At6.job
C:\WINDOWS\tasks\At7.job
C:\WINDOWS\tasks\At8.job
C:\WINDOWS\tasks\At9.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d’aide de l’Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{988B07F5-7392-455A-8A1F-64935CB8B6ED}]
BHO Barre de Confiance - C:\Program Files\BarreConfCMCIC\TAPBar.dll [2007-09-14 225280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - Barre de confiance - C:\Program Files\BarreConfCMCIC\TAPBar.dll [2007-09-14 225280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“F-Secure Manager”=C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE [2007-06-13 176177]
“F-Secure TNB”=C:\Program Files\Securitoo\av_fw\FSGUI\TNBUtil.exe [2007-06-13 733184]
“JMB36X IDE Setup”=C:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
“36X Raid Configurer”=C:\WINDOWS\system32\xRaidSetup.exe [2007-11-19 1970176]
“NvCplDaemon”=C:\WINDOWS\system32\NvCpl.dll [2008-12-02 13680640]
“nwiz”=nwiz.exe /install []
“NvMediaCenter”=C:\WINDOWS\system32\NvMcTray.dll [2008-12-02 86016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
“MSMSGS”=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
D:\Daemon Tools\daemon.exe [2006-11-12 157592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
D:\OMNIPAGE\OpwareSE2.exe [2003-05-08 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2006-07-21 16261632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
C:\PROGRA~1\Wanadoo\Watch.exe [2004-08-23 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d’Adobe Reader.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=323
“NoDrives”=0
“NoDriveAutoRun”=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=
“NoDrives”=
“NoDriveAutoRun”=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000"
“C:\WINDOWS\system32\PnkBstrA.exe”=“C:\WINDOWS\system32\PnkBstrA.exe::Enabled:PnkBstrA"
“C:\WINDOWS\system32\PnkBstrB.exe”="C:\WINDOWS\system32\PnkBstrB.exe:
:Enabled:PnkBstrB”
“C:\Program Files\Bonjour\mDNSResponder.exe”=“C:\Program Files\Bonjour\mDNSResponder.exe::Enabled:Bonjour"
“D:\CoH opposing fronts\RelicCOH.exe”="D:\CoH opposing fronts\RelicCOH.exe:
:Enabled:Company of Heroes - Opposing Fronts”
“C:\WINDOWS\system32\muzapp.exe”=“C:\WINDOWS\system32\muzapp.exe::Enabled:MUZ AOD APP player"
“D:\Crysis\Bin32\Crysis.exe”="D:\Crysis\Bin32\Crysis.exe:
:Enabled:Crysis_32”
“D:\Crysis\Bin32\CrysisDedicatedServer.exe”=“D:\Crysis\Bin32\CrysisDedicatedServer.exe::Enabled:CrysisDedicatedServer_32"
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:
:Enabled:Windows Live Messenger”
“C:\Program Files\Windows Live\Messenger\livecall.exe”=“C:\Program Files\Windows Live\Messenger\livecall.exe::Enabled:Windows Live Messenger (Phone)"
“D:\PES 2009\pes2009.exe”="D:\PES 2009\pes2009.exe:
:Enabled:Pro Evolution Soccer 2009”
“D:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe”=“D:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe::Enabled:Rockstar Games Social Club"
“D:\GTA IV\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe”="D:\GTA IV\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe:
:Enabled:Grand Theft Auto IV”

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000"
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger"
“C:\Program Files\Windows Live\Messenger\livecall.exe”="C:\Program Files\Windows Live\Messenger\livecall.exe:
:Enabled:Windows Live Messenger (Phone)”

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{43b964d2-8ff3-11dd-9ab8-0019db4ab03e}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NoLimit.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5a131ac2-41c0-11dc-bd7d-806d6172696f}]
shell\AutoRun\command - F:\Livebox.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{b2342196-5146-11dc-ba8e-806d6172696f}]
shell\AutoRun\command - F:\FarCryAutoCD.exe

======List of files/folders created in the last 1 months======

2008-12-18 21:47:27 ----D---- C:\rsit
2008-12-18 21:25:08 ----A---- C:\ComboFix.txt
2008-12-18 21:20:01 ----D---- C:\flobo
2008-12-17 14:25:28 ----A---- C:\Boot.bak
2008-12-17 14:25:25 ----RASHD---- C:\cmdcons
2008-12-17 14:23:38 ----A---- C:\WINDOWS\zip.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\VFIND.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\SWXCACLS.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\SWSC.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\SWREG.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\sed.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\NIRCMD.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\grep.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\fdsv.exe
2008-12-16 22:17:16 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-16 21:30:21 ----D---- C:\WINDOWS\ERDNT
2008-12-16 21:30:21 ----D---- C:\Qoobox
2008-12-16 19:57:22 ----D---- C:\Documents and Settings\Florian\Application Data\Malwarebytes
2008-12-16 19:57:15 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-14 15:24:40 ----A---- C:\WINDOWS\system32\Q23Jc8P5.exe
2008-12-13 12:53:21 ----A---- C:\WINDOWS\system32\gdiplus.dll
2008-12-12 17:44:49 ----HDC---- C:\WINDOWS$NtUninstallKB955839$
2008-12-12 17:42:09 ----HDC---- C:\WINDOWS$NtUninstallKB952069_WM9$
2008-12-12 17:41:40 ----HDC---- C:\WINDOWS$NtUninstallKB954600$
2008-12-12 17:41:32 ----HDC---- C:\WINDOWS$NtUninstallKB956802$
2008-12-09 17:59:22 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2008-12-09 17:59:22 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2008-12-09 17:59:22 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2008-12-09 17:59:20 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2008-12-09 17:59:20 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2008-12-09 17:59:20 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2008-12-09 17:59:19 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2008-12-09 17:59:19 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2008-12-09 17:59:19 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2008-12-06 21:25:39 ----D---- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-12-06 21:21:22 ----D---- C:\WINDOWS\nview
2008-12-06 21:21:22 ----A---- C:\WINDOWS\system32\nvudisp.exe
2008-12-06 21:21:01 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2008-12-05 18:08:43 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-12-05 18:07:00 ----D---- C:\WINDOWS\SxsCaPendDel
2008-12-03 15:11:34 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2008-12-03 14:44:52 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2008-12-03 13:22:49 ----RHD---- C:\Documents and Settings\Florian\Application Data\SecuROM
2008-12-03 13:17:30 ----D---- C:\WINDOWS\system32\xlive
2008-12-03 13:17:28 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2008-12-03 12:33:32 ----HDC---- C:\WINDOWS$NtUninstallXPSEPSCLP$
2008-12-03 12:31:50 ----D---- C:\Program Files\MSBuild
2008-12-03 12:30:44 ----D---- C:\WINDOWS\system32\XPSViewer
2008-12-03 12:30:42 ----D---- C:\WINDOWS\system32\en-us
2008-12-03 12:30:12 ----D---- C:\Program Files\Reference Assemblies
2008-12-03 12:29:56 ----N---- C:\WINDOWS\system32\spmsg2.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nwiz.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwss.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwimg.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvvitvs.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvshell.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmobls.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmccss.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmccs.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nview.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvgames.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvdisps.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcplui.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcodins.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcod.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvappbar.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\keystone.exe

======List of files/folders modified in the last 1 months======

2008-12-18 21:47:28 ----D---- C:\WINDOWS\Temp
2008-12-18 21:25:11 ----D---- C:\WINDOWS\system32\drivers
2008-12-18 21:25:11 ----D---- C:\WINDOWS\system32
2008-12-18 21:25:10 ----D---- C:\WINDOWS
2008-12-18 21:25:00 ----D---- C:\WINDOWS\Prefetch
2008-12-18 21:23:35 ----A---- C:\WINDOWS\system.ini
2008-12-18 21:23:11 ----D---- C:\WINDOWS\system32\CatRoot2
2008-12-18 21:21:14 ----D---- C:\WINDOWS\AppPatch
2008-12-18 21:21:14 ----D---- C:\Program Files\Fichiers communs
2008-12-18 21:20:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-12-18 20:23:37 ----D---- C:\Program Files\Wanadoo
2008-12-17 14:25:28 ----RASH---- C:\boot.ini
2008-12-16 16:32:38 ----ASH---- C:\WINDOWS\system32\lanadata.dll
2008-12-14 15:53:33 ----HD---- C:\WINDOWS\inf
2008-12-14 15:50:32 ----D---- C:\WINDOWS\Debug
2008-12-14 15:47:16 ----D---- C:\Documents and Settings\Florian\Application Data\LimeWire
2008-12-14 15:24:41 ----SD---- C:\WINDOWS\Tasks
2008-12-12 17:44:43 ----SHD---- C:\WINDOWS\Installer
2008-12-12 17:44:36 ----A---- C:\WINDOWS\win.ini
2008-12-12 17:43:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-12 17:43:55 ----D---- C:\Program Files\Internet Explorer
2008-12-12 17:43:47 ----D---- C:\WINDOWS\ie7updates
2008-12-12 17:43:39 ----HD---- C:\WINDOWS$hf_mig$
2008-12-09 17:59:04 ----RSD---- C:\WINDOWS\assembly
2008-12-09 17:58:47 ----D---- C:\WINDOWS\system32\DirectX
2008-12-06 21:21:25 ----D---- C:\WINDOWS\Help
2008-12-05 19:59:30 ----D---- C:\WINDOWS\Microsoft.NET
2008-12-05 18:16:45 ----D---- C:\WINDOWS\system32\CatRoot
2008-12-05 18:12:03 ----D---- C:\WINDOWS\system32\fr-fr
2008-12-05 18:09:25 ----RSD---- C:\WINDOWS\Fonts
2008-12-05 18:05:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-05 18:05:07 ----D---- C:\WINDOWS\WinSxS
2008-12-03 14:09:18 ----HD---- C:\Program Files\InstallShield Installation Information
2008-12-03 13:18:44 ----D---- C:\Program Files\Windows Media Player
2008-12-03 13:17:30 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-12-03 13:17:28 ----D---- C:\Program Files
2008-12-03 12:33:25 ----D---- C:\WINDOWS\system32\mui
2008-12-03 12:30:01 ----D---- C:\WINDOWS\system32\spool

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 F-Secure HIPS;F-Secure HIPS; ??\C:\Program Files\Securitoo\av_fw\HIPS\fshs.sys []
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; ??\C:\Program Files\Securitoo\av_fw\Anti-Virus\minifilter\fsgk.sys []
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-12-02 6209536]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-07-21 82432]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Pilote miniport de contrôleur d’hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 apcixy8z;apcixy8z; C:\WINDOWS\system32\drivers\apcixy8z.sys []
S3 DigiCellDriver;DigiCellDriver; ??\C:\Program Files\MSI\DigiCell\NTGLM7X.sys []
S3 driverhardwarev2;driverhardwarev2; ??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys []
S3 GMSIPCI;GMSIPCI; ??\F:\INSTALL\GMSIPCI.SYS []
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; ??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; ??\C:\WINDOWS\system32\PCANDIS5.SYS []
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys []
S3 RushTopDevice2;RushTopDevice2; ??\C:\Program Files\MSI\DualCoreCenter\RushTop.sys []
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336]
S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000]
S3 usbprint;Classe d’imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 F-Secure Filter;F-Secure File System Filter; ??\C:\Program Files\Securitoo\av_fw\Anti-Virus\Win2K\FSfilter.sys []
S4 F-Secure Recognizer;F-Secure File System Recognizer; ??\C:\Program Files\Securitoo\av_fw\Anti-Virus\Win2K\FSrec.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS; C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe [2007-06-13 41043]
R2 FSMA;F-Secure Management Agent; C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE [2007-06-13 106546]
R2 FTRTSVC;France Telecom Routing Table Service; C:\WINDOWS\System32\FTRTSVC.exe [2004-08-23 40960]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-12-02 163908]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-07-31 66872]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 FSAUA;F-Secure Automatic Update Agent; C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe [2007-06-13 450560]
R3 FSDFWD;F-Secure Anti-Virus Firewall Daemon; C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe [2007-06-13 446464]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 aspnet_state;Service d’état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2007-12-28 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 918016]
S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Et voila le rapport info.txt :

info.txt logfile of random’s system information tool 1.05 2008-12-18 21:47:29

======Uninstall list======

–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Anti-Spyware Scanner”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Anti-Spyware”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Anti-Virus Client Security Installer”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Anti-Virus”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Automatic Update Agent”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure DAAS”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Diagnostics”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure E-mail Scanning”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure FWES”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure GateKeeper Interface”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Gemini”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure GUI”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Help”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure HIPS”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Internet Shield”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Localization API”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Management Agent”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Pegasus Engine”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Spam Control”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Spam Scanner”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure TNB”
–>“C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe” /UninstRegKey:“F-Secure Uninstall”
–>C:\WINDOWS\UNIN040C.EXE -fd:\photoshop\imageready\DeIsL1.isu
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Anchor Service CS3–>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3–>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3–>MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting–>MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0–>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps–>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific–>MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings–>MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Recommended Settings–>MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
Adobe Color JA Extra Settings–>MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Extra Settings–>MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
Adobe Default Language CS3–>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3–>MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2–>MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All–>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3–>MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3–>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files–>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3–>C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
Adobe Photoshop CS3–>MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
Adobe Reader 7.0 - Français–>MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
Adobe Setup–>MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
Adobe Stock Photos CS3–>MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support–>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3–>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client–>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin–>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3–>MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AIDA32 v3.93–>“D:\AIDA32 - Personal System Information\unins000.exe”
Archiveur WinRAR–>D:\WinRAR\uninstall.exe
ArcSoft PhotoStudio 5.5–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{85309D89-7BE9-4094-BB17-24999C6118FC}\SETUP.EXE” -l0x40c
Assistant de connexion Windows Live–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Barre de confiance CM-CIC–>“C:\Program Files\BarreConfCMCIC\Setup.exe” -u
Canon MP Navigator 2.0–>“C:\Program Files\Canon\MP Navigator 2.0\Maint.exe” /UninstallRemove C:\Program Files\Canon\MP Navigator 2.0\uninst.ini
Canon MP170–>“C:\WINDOWS\system32\CanonMP Uninstaller Information{91175441-4E5D-4e13-B116-828FD352CDB2}\DelDrv.exe” /U:{91175441-4E5D-4e13-B116-828FD352CDB2} /L0x000c
Canon Utilities Easy-PhotoPrint–>C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
CCleaner (remove only)–>“D:\CC Cleaner\CCleaner\uninst.exe”
Company of Heroes - FAKEMSI–>MsiExec.exe /I{14574B7F-75D1-4718-B7F2-EBF6E2862A35}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{199E6632-EB28-4F73-AECB-3E192EB92D18}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{25724802-CC14-4B90-9F3B-3D6955EE27B1}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{50193078-F553-4EBA-AA77-64C9FAA12F98}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{51D718D1-DA81-4FAD-919F-5C1CE3C33379}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{66F78C51-D108-4F0C-A93C-1CBE74CE338F}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{80D03817-7943-4839-8E96-B9F924C5E67D}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{97E5205F-EA4F-438F-B211-F1846419F1C1}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{99A7722D-9ACB-43F3-A222-ABC7133F159E}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{BA801B94-C28D-46EE-B806-E1E021A3D519}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{D4D244D1-05E0-4D24-86A2-B2433C435671}
Company of Heroes - FAKEMSI–>MsiExec.exe /I{EAF636A9-F664-4703-A659-85A894DA264F}
Company of Heroes–>“D:\CoH opposing fronts\Uninstall_French.exe”
Correctif pour Lecteur Windows Media 11 (KB939683)–>“C:\WINDOWS$NtUninstallKB939683$\spuninst\spuninst.exe”
Correctif pour Windows Internet Explorer 7 (KB947864)–>“C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe”
Correctif pour Windows XP (KB952287)–>“C:\WINDOWS$NtUninstallKB952287$\spuninst\spuninst.exe”
Crysis®–>MsiExec.exe /I{000E79B7-E725-4F01-870A-C12942B7F8E4}
DeepBurner v1.9.0.228–>“D:\DeepBurner\Uninstall.exe” “D:\DeepBurner\install.log” -u
Easy-WebPrint–>C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
EAX Unified–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\EAX Unified\Uninst.isu"
EmoDio–>“C:\Program Files\InstallShield Installation Information{C20CE592-B0F8-4D20-BF31-0151CA6331A6}\setup.exe” -runfromtemp -l0x040c -removeonly
EmoDio–>MsiExec.exe /X{C20CE592-B0F8-4D20-BF31-0151CA6331A6}
Free Mp3 Wma Converter V 1.6.0–>“D:\Convertisseur audio\Free Audio Pack\unins000.exe”
Galerie de photos Windows Live–>MsiExec.exe /X{A70FA218-6598-4AC9-813D-63597C5DD068}
Gestionnaire Internet–>C:\PROGRA~1\Wanadoo\uninstall.exe
Grand Theft Auto IV–>“C:\Program Files\InstallShield Installation Information{579BA58C-F33D-4970-9953-B94B43768AC3}\setup.exe” -runfromtemp -l0x040c -removeonly
High Definition Audio Driver Package - KB888111–>“C:\WINDOWS$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe”
HijackThis 2.0.2–>“D:\Hijackthis\HijackThis.exe” /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)–>C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)–>“C:\WINDOWS$NtUninstallKB929399$\spuninst\spuninst.exe”
Java™ 6 Update 5–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
JMB36X Raid Configurer–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}\setup.exe” -l0x40c -removeonly
K-Lite Codec Pack 3.8.0 Full–>“E:\Codecs\K-Lite Codec Pack\unins000.exe”
Lecteur Windows Media 11–>“C:\Program Files\Windows Media Player\Setup_wm.exe” /Uninstall
Ma-Config.com plugin–>MsiExec.exe /I{D2D7529F-6B55-4C1C-BC9C-D6F1BCC066B6}
Mafia Game–>C:\WINDOWS\system32\MafiaSetup.exe
Mafia–>D:\Mafia\Mafia\patch.exe
Malwarebytes’ Anti-Malware–>“D:\MalwareByte’s Anti-Malware\Malwarebytes’ Anti-Malware\unins000.exe”
Messenger Plus! Live–>“C:\Program Files\Messenger Plus! Live\Uninstall.exe”
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA–>MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
Microsoft .NET Framework 2.0 Service Pack 2–>MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 French Language Pack–>MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA–>MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
Microsoft .NET Framework 3.0 Service Pack 2–>MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 Language Pack SP1 - fra–>MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1–>C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1–>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP–>“C:\WINDOWS$NtUninstallMSCompPackV1$\spuninst\spuninst.exe”
Microsoft Games for Windows - LIVE -->MsiExec.exe /X{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}
Microsoft Games for Windows - LIVE Redistributable–>MsiExec.exe /X{FD052FB9-FE90-4438-B355-15EDC89D8FB1}
Microsoft Internationalized Domain Names Mitigation APIs–>“C:\WINDOWS$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe”
Microsoft National Language Support Downlevel APIs–>“C:\WINDOWS$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe”
Microsoft Office Standard Edition 2003–>MsiExec.exe /I{9112040C-6000-11D3-8CFE-0150048383C9}
Microsoft SQL Server 2005 Compact Edition [ENU]–>MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>“C:\WINDOWS$NtUninstallWudf01000$\spuninst\spuninst.exe”
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)–>“C:\WINDOWS$NtUninstallKB952069_WM9$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)–>“C:\WINDOWS$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)–>“C:\WINDOWS$NtUninstallKB954154_WM11$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)–>“C:\WINDOWS$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)–>“C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)–>“C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)–>“C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)–>“C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)–>“C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)–>“C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB938464)–>“C:\WINDOWS$NtUninstallKB938464$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB941569)–>“C:\WINDOWS$NtUninstallKB941569$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB946648)–>“C:\WINDOWS$NtUninstallKB946648$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB950760)–>“C:\WINDOWS$NtUninstallKB950760$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB950762)–>“C:\WINDOWS$NtUninstallKB950762$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB950974)–>“C:\WINDOWS$NtUninstallKB950974$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB951066)–>“C:\WINDOWS$NtUninstallKB951066$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB951376)–>“C:\WINDOWS$NtUninstallKB951376$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB951376-v2)–>“C:\WINDOWS$NtUninstallKB951376-v2$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB951698)–>“C:\WINDOWS$NtUninstallKB951698$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB951748)–>“C:\WINDOWS$NtUninstallKB951748$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB952954)–>“C:\WINDOWS$NtUninstallKB952954$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB953839)–>“C:\WINDOWS$NtUninstallKB953839$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB954211)–>“C:\WINDOWS$NtUninstallKB954211$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB954459)–>“C:\WINDOWS$NtUninstallKB954459$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB954600)–>“C:\WINDOWS$NtUninstallKB954600$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB955069)–>“C:\WINDOWS$NtUninstallKB955069$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB956391)–>“C:\WINDOWS$NtUninstallKB956391$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB956802)–>“C:\WINDOWS$NtUninstallKB956802$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB956803)–>“C:\WINDOWS$NtUninstallKB956803$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB956841)–>“C:\WINDOWS$NtUninstallKB956841$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB957095)–>“C:\WINDOWS$NtUninstallKB957095$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB957097)–>“C:\WINDOWS$NtUninstallKB957097$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Windows XP (KB958644)–>“C:\WINDOWS$NtUninstallKB958644$\spuninst\spuninst.exe”
Mise à jour pour Windows XP (KB951072-v2)–>“C:\WINDOWS$NtUninstallKB951072-v2$\spuninst\spuninst.exe”
Mise à jour pour Windows XP (KB951978)–>“C:\WINDOWS$NtUninstallKB951978$\spuninst\spuninst.exe”
Mise à jour pour Windows XP (KB955839)–>“C:\WINDOWS$NtUninstallKB955839$\spuninst\spuninst.exe”
Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0–>C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
Module linguistique Microsoft .NET Framework 3.5 SP1- fra–>C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mp3tag v2.41–>D:\MP3tag\Mp3tagUninstall.EXE
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB925673)–>MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
MyFreeCodec–>D:\MyFreeCodecPack\09c beta\uninstall.exe
Navigateur Orange–>C:\PROGRA~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl
NVIDIA Drivers–>C:\WINDOWS\system32\nvuninst.exe UninstallGUI
OmniPage SE 2.0–>MsiExec.exe /I{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}
Opendisc Light ActiveX Control 1.0–>RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\OpendiscLight.inf,DefaultUninstall,5
PDF Settings–>MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Pro Evolution Soccer 2009–>MsiExec.exe /X{A8DB611A-D80E-450D-85F6-3ACDD164BE31}
PunkBuster Services–>C:\WINDOWS\system32\pbsvc.exe -u
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe” -l0x40c -removeonly
Rockstar Games Social Club–>“C:\Program Files\InstallShield Installation Information{08B3869E-D282-424C-9AFC-870E04A4BA14}\setup.exe” -runfromtemp -l0x040c -removeonly
SAMSUNG CDMA Modem Driver Set–>C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
SAMSUNG Mobile USB Modem ^^–>C:\WINDOWS\system32\Samsung_USB_Drivers\4\SSVDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software–>C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software–>C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Samsung PC Studio–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe” -l0x40c -removeonly
Samsung Samples Installer–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{7AC15160-A49B-4A89-B181-D4619C025FFF}\setup.exe” -l0x40c -removeonly
Securitoo AntiVirus Firewall–>“C:\Program Files\Securitoo\av_fw\FSGUI\PostInstall.exe” /tUnInstall
Twin USB Vibration Gamepad–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{BA12FD6D-169A-11D7-A6A9-00C026281E5A}\setup.exe” -l0x9
VideoLAN VLC media player 0.8.5–>C:\Program Files\VideoLAN\VLC\uninstall.exe
Wanadoo Messager–>C:\PROGRA~1\WANADO~1\UNWISE.EXE C:\PROGRA~1\WANADO~1\INSTALL.LOG
Windows Imaging Component–>“C:\WINDOWS$NtUninstallWIC$\spuninst\spuninst.exe”
Windows Live installer–>MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger–>MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Format 11 runtime–>“C:\Program Files\Windows Media Player\wmsetsdk.exe” /UninstallAll
Windows Media Format 11 runtime–>“C:\WINDOWS$NtUninstallWMFDist11$\spuninst\spuninst.exe”
Windows Media Player 11–>“C:\WINDOWS$NtUninstallwmp11$\spuninst\spuninst.exe”
Windows Presentation Foundation Language Pack (FRA)–>MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
Windows Presentation Foundation–>MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows XP Service Pack 3–>“C:\WINDOWS$NtServicePackUninstall$\spuninst\spuninst.exe”
XML Paper Specification Shared Components Language Pack 1.0–>“C:\WINDOWS$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe”

======Security center information======

AV: Securitoo AntiVirus Firewall 7.00
FW: Securitoo AntiVirus Firewall 7.00

System event log

Computer Name: PC-3257AB58FDE9
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service F-Secure Automatic Update Agent.

Record Number: 32600
Source Name: Service Control Manager
Time Written: 20081127180017.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: PC-3257AB58FDE9
Event Code: 7036
Message: Le service F-Secure Automatic Update Agent est entré dans l’état : en cours d’exécution.

Record Number: 32599
Source Name: Service Control Manager
Time Written: 20081127180017.000000+060
Event Type: Informations
User:

Computer Name: PC-3257AB58FDE9
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Service de découvertes SSDP.

Record Number: 32598
Source Name: Service Control Manager
Time Written: 20081127180017.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: PC-3257AB58FDE9
Event Code: 7036
Message: Le service NLA (Network Location Awareness) est entré dans l’état : en cours d’exécution.

Record Number: 32597
Source Name: Service Control Manager
Time Written: 20081127180017.000000+060
Event Type: Informations
User:

Computer Name: PC-3257AB58FDE9
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

Record Number: 32596
Source Name: Service Control Manager
Time Written: 20081127180017.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Application event log

Computer Name: PC-3257AB58FDE9
Event Code: 100
Message: msnmsgr (3876) Le moteur de base de données 5.01.2600.2780 est démarré.

Record Number: 12286
Source Name: ESENT
Time Written: 20081003230318.000000+120
Event Type: Informations
User:

Computer Name: PC-3257AB58FDE9
Event Code: 101
Message: msnmsgr (3876) Le moteur de base de données est arrêté.

Record Number: 12285
Source Name: ESENT
Time Written: 20081003230203.000000+120
Event Type: Informations
User:

Computer Name: PC-3257AB58FDE9
Event Code: 103
Message: msnmsgr (3876) \.\C:\Documents and Settings\Florian\Local Settings\Application Data\Microsoft\Messenger\flobo.44@hotmail.fr\SharingMetadata\Working\database_9AFC_2573_FC25_4B39\dfsr.db: Le moteur de base de données a arrêté une instance (0).

Record Number: 12284
Source Name: ESENT
Time Written: 20081003230203.000000+120
Event Type: Informations
User:

Computer Name: PC-3257AB58FDE9
Event Code: 102
Message: msnmsgr (3876) \.\C:\Documents and Settings\Florian\Local Settings\Application Data\Microsoft\Messenger\flobo.44@hotmail.fr\SharingMetadata\Working\database_9AFC_2573_FC25_4B39\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

Record Number: 12283
Source Name: ESENT
Time Written: 20081003225747.000000+120
Event Type: Informations
User:

Computer Name: PC-3257AB58FDE9
Event Code: 100
Message: msnmsgr (3876) Le moteur de base de données 5.01.2600.2780 est démarré.

Record Number: 12282
Source Name: ESENT
Time Written: 20081003225747.000000+120
Event Type: Informations
User:

======Environment variables======

“ComSpec”=%SystemRoot%\system32\cmd.exe
“Path”=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files;C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727
“windir”=%SystemRoot%
“FP_NO_HOST_CHECK”=NO
“OS”=Windows_NT
“PROCESSOR_ARCHITECTURE”=x86
“PROCESSOR_LEVEL”=6
“PROCESSOR_IDENTIFIER”=x86 Family 6 Model 15 Stepping 6, GenuineIntel
“PROCESSOR_REVISION”=0f06
“NUMBER_OF_PROCESSORS”=2
“PATHEXT”=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
“TEMP”=%SystemRoot%\TEMP
“TMP”=%SystemRoot%\TEMP
“RGSCLauncher”=D:\GTA IV\Rockstar Games Social Club
“RGSC”=D:\GTA IV\Rockstar Games Social Club\1_0_0_0

-----------------EOF-----------------

Re,

Télécharge Lop S&D :

LOPSD

Double-clique dessus pour lancer l’installation

Puis double-clique sur le raccourci Lop S&D présent sur ton bureau

Séléctionne la langue souhaitée

Puis choisis l’Option 1 ( Recherche )

Patiente jusqu’à la fin du scan

Poste le rapport généré ( C:lopR.txt )

Voici le rapport Lop S&D :

--------------------\ Lop S&D 4.2.4-9c XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 CPU 6600 @ 2.40GHz )
BIOS : Default System BIOS
USER : Florian ( Administrator )
BOOT : Normal boot
Antivirus : Securitoo AntiVirus Firewall 7.00 7.00 (Activated)
Firewall : Securitoo AntiVirus Firewall 7.00 7.00 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:19 Go (Free:3 Go)
D:\ (Local Disk) - NTFS - Total:48 Go (Free:2 Go)
E:\ (Local Disk) - NTFS - Total:211 Go (Free:172 Go)
F:\ (CD or DVD) - UDF - Total:7 Go (Free:0 Go)
G:\ (CD or DVD)
H:\ (CD or DVD)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (USB)

“C:\Lop SD” ( MAJ : 01-11-2008|16:30 )
Option : [1] ( 18/12/2008|21:57 )

--------------------\ Listing des dossiers dans APPLIC~1

[20/03/2008|22:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[04/08/2007|15:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[28/12/2007|17:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
[03/01/2008|13:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
[03/01/2008|13:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[25/01/2008|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[16/10/2008|17:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\KONAMI
[16/12/2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[03/08/2007|18:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[03/12/2008|13:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[01/02/2008|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[06/12/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[06/08/2007|18:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[04/08/2007|15:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanAppDataDir
[04/08/2007|15:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanWizard
[06/08/2007|09:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/11/2007|13:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[28/01/2008|18:05] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Adobe
[10/03/2008|18:20] C:\DOCUME~1\BOUSSE~1\APPLIC~1\AdobeUM
[04/03/2008|20:38] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Canon
[11/08/2007|17:26] C:\DOCUME~1\BOUSSE~1\APPLIC~1\DeepBurner
[28/08/2008|18:05] C:\DOCUME~1\BOUSSE~1\APPLIC~1\F-Secure
[05/08/2007|11:16] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Google
[05/08/2007|09:19] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Help
[03/08/2007|15:09] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Identities
[05/08/2007|08:57] C:\DOCUME~1\BOUSSE~1\APPLIC~1\ispnews
[05/08/2007|09:19] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Macromedia
[05/03/2008|14:38] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Microsoft
[15/08/2007|08:52] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Sun
[19/07/2008|17:30] C:\DOCUME~1\BOUSSE~1\APPLIC~1\WinRAR

[03/08/2007|12:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[25/07/2008|17:48] C:\DOCUME~1\Florian\APPLIC~1\Adobe
[20/03/2008|22:40] C:\DOCUME~1\Florian\APPLIC~1\AdobeUM
[12/11/2008|18:36] C:\DOCUME~1\Florian\APPLIC~1\Canon
[10/06/2008|19:18] C:\DOCUME~1\Florian\APPLIC~1\DataCast
[11/08/2007|16:56] C:\DOCUME~1\Florian\APPLIC~1\DeepBurner
[30/03/2008|17:36] C:\DOCUME~1\Florian\APPLIC~1\dvdcss
[18/03/2008|22:23] C:\DOCUME~1\Florian\APPLIC~1\FrostWire
[03/01/2008|18:06] C:\DOCUME~1\Florian\APPLIC~1\F-Secure
[04/08/2007|10:36] C:\DOCUME~1\Florian\APPLIC~1\Google
[02/02/2008|20:16] C:\DOCUME~1\Florian\APPLIC~1\Help
[03/08/2007|12:28] C:\DOCUME~1\Florian\APPLIC~1\Identities
[10/06/2008|19:16] C:\DOCUME~1\Florian\APPLIC~1\InstallShield
[03/08/2007|15:55] C:\DOCUME~1\Florian\APPLIC~1\ispnews
[14/12/2008|15:47] C:\DOCUME~1\Florian\APPLIC~1\LimeWire
[02/03/2008|21:36] C:\DOCUME~1\Florian\APPLIC~1\ma-config.com
[03/08/2007|15:19] C:\DOCUME~1\Florian\APPLIC~1\Macromedia
[16/12/2008|19:57] C:\DOCUME~1\Florian\APPLIC~1\Malwarebytes
[31/07/2008|10:50] C:\DOCUME~1\Florian\APPLIC~1\Microsoft
[07/06/2008|16:54] C:\DOCUME~1\Florian\APPLIC~1\Mp3tag
[29/12/2007|18:14] C:\DOCUME~1\Florian\APPLIC~1\Nero
[03/08/2007|15:57] C:\DOCUME~1\Florian\APPLIC~1\PEX
[04/10/2007|09:38] C:\DOCUME~1\Florian\APPLIC~1\Samsung
[04/08/2007|15:10] C:\DOCUME~1\Florian\APPLIC~1\ScanSoft
[03/12/2008|13:22] C:\DOCUME~1\Florian\APPLIC~1\SecuROM
[04/08/2007|10:31] C:\DOCUME~1\Florian\APPLIC~1\Sun
[09/12/2007|16:23] C:\DOCUME~1\Florian\APPLIC~1\vlc
[09/09/2007|17:15] C:\DOCUME~1\Florian\APPLIC~1\Wannadoo
[08/05/2008|10:01] C:\DOCUME~1\Florian\APPLIC~1\WinRAR

[06/08/2007|10:58] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[16/12/2008|20:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Adobe
[16/12/2008|20:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\ Tâches planifiées dans C:\WINDOWS\tasks

[17/12/2008 23:00][–a------] C:\WINDOWS\tasks\At24.job
[17/12/2008 22:00][–a------] C:\WINDOWS\tasks\At23.job
[18/12/2008 21:00][–a------] C:\WINDOWS\tasks\At22.job
[18/12/2008 19:00][–a------] C:\WINDOWS\tasks\At20.job
[18/12/2008 20:00][–a------] C:\WINDOWS\tasks\At21.job
[18/12/2008 18:00][–a------] C:\WINDOWS\tasks\At19.job
[18/12/2008 17:00][–a------] C:\WINDOWS\tasks\At18.job
[17/12/2008 14:00][–a------] C:\WINDOWS\tasks\At15.job
[17/12/2008 15:00][–a------] C:\WINDOWS\tasks\At16.job
[17/12/2008 16:00][–a------] C:\WINDOWS\tasks\At17.job
[17/12/2008 12:00][–a------] C:\WINDOWS\tasks\At13.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At12.job
[17/12/2008 13:00][–a------] C:\WINDOWS\tasks\At14.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At9.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At10.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At11.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At7.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At8.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At6.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At5.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At4.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At3.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At2.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At1.job
[18/12/2008 21:22][–ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\ Listing des dossiers dans C:\Program Files

[30/07/2008|14:56] C:\Program Files\Adobe
[19/05/2008|18:18] C:\Program Files\AviSynth 2.5
[23/02/2008|11:19] C:\Program Files\BarreConfCMCIC
[28/12/2007|17:24] C:\Program Files\Bonjour
[04/08/2007|15:06] C:\Program Files\Canon
[12/03/2008|20:32] C:\Program Files\Creative
[13/03/2008|10:38] C:\Program Files\Electronic Arts
[25/01/2008|22:30] C:\Program Files\eRightSoft
[18/12/2008|21:21] C:\Program Files\Fichiers communs
[03/12/2008|14:09] C:\Program Files\InstallShield Installation Information
[03/08/2007|14:52] C:\Program Files\Intel
[12/12/2008|17:43] C:\Program Files\Internet Explorer
[03/01/2008|12:05] C:\Program Files\Inventel
[19/03/2008|18:02] C:\Program Files\Java
[10/06/2008|19:18] C:\Program Files\MarkAny
[05/10/2008|16:42] C:\Program Files\Messenger
[05/09/2008|18:14] C:\Program Files\Messenger Plus! Live
[03/08/2007|12:22] C:\Program Files\microsoft frontpage
[03/12/2008|13:30] C:\Program Files\Microsoft Games for Windows - LIVE
[07/11/2007|13:44] C:\Program Files\Microsoft SQL Server Compact Edition
[03/08/2007|18:53] C:\Program Files\Microsoft.NET
[05/10/2008|14:50] C:\Program Files\Movie Maker
[03/12/2008|12:31] C:\Program Files\MSBuild
[08/12/2007|13:35] C:\Program Files\MSI
[03/08/2007|12:18] C:\Program Files\MSN
[03/08/2007|12:18] C:\Program Files\MSN Gaming Zone
[24/03/2008|23:06] C:\Program Files\MSXML 4.0
[05/10/2008|14:47] C:\Program Files\NetMeeting
[03/08/2007|12:18] C:\Program Files\Online Services
[05/10/2008|14:47] C:\Program Files\Outlook Express
[03/08/2007|14:50] C:\Program Files\Realtek
[03/12/2008|12:30] C:\Program Files\Reference Assemblies
[02/02/2008|20:19] C:\Program Files\Samsung
[03/01/2008|13:12] C:\Program Files\Securitoo
[03/08/2007|12:20] C:\Program Files\Services en ligne
[26/12/2007|15:22] C:\Program Files\Ubisoft
[03/08/2007|12:28] C:\Program Files\Uninstall Information
[03/08/2007|18:12] C:\Program Files\VideoLAN
[18/12/2008|20:23] C:\Program Files\Wanadoo
[03/08/2007|15:16] C:\Program Files\Wanadoo Messager
[24/03/2008|23:08] C:\Program Files\Windows Live
[21/08/2007|13:41] C:\Program Files\Windows Media Connect 2
[03/12/2008|13:18] C:\Program Files\Windows Media Player
[05/10/2008|14:47] C:\Program Files\Windows NT
[03/08/2007|12:20] C:\Program Files\WindowsUpdate
[08/05/2008|08:54] C:\Program Files\WinRAR
[03/08/2007|12:22] C:\Program Files\xerox

--------------------\ Listing des dossiers dans C:\Program Files\Fichiers communs

[25/07/2008|16:25] C:\Program Files\Fichiers communs\Adobe
[03/08/2007|18:54] C:\Program Files\Fichiers communs\DESIGNER
[04/08/2007|15:07] C:\Program Files\Fichiers communs\InstallShield
[19/03/2008|18:00] C:\Program Files\Fichiers communs\Java
[28/12/2007|17:17] C:\Program Files\Fichiers communs\Macrovision Shared
[21/08/2008|22:59] C:\Program Files\Fichiers communs\Microsoft Shared
[03/08/2007|12:20] C:\Program Files\Fichiers communs\MSSoap
[03/08/2007|13:55] C:\Program Files\Fichiers communs\ODBC
[02/02/2008|20:16] C:\Program Files\Fichiers communs\ScanSoft Shared
[03/08/2007|12:20] C:\Program Files\Fichiers communs\Services
[03/08/2007|13:54] C:\Program Files\Fichiers communs\SpeechEngines
[05/10/2008|14:47] C:\Program Files\Fichiers communs\System
[07/11/2007|13:39] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\ Process

( 45 Processes )

iexplore.exe ~ [PID:1316]

--------------------\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\ Verification du Registre

… OK !

--------------------\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-12-18 21:58:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 595

--------------------\ Recherche d’autres infections

C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job

[F:13][D:2]-> C:\DOCUME~1\Florian\LOCALS~1\Temp
[F:90][D:0]-> C:\DOCUME~1\Florian\Cookies
[F:836][D:4]-> C:\DOCUME~1\Florian\LOCALS~1\TEMPOR~1\content.IE5

1 - “C:\Lop SD\LopR_1.txt” - 18/12/2008|21:59 - Option : [1]

--------------------\ Fin du rapport a 21:59:19

Re,

Relance Lop S&D

Choisis cette fois ci l’Option 2 ( Suppression )

/!\Ne ferme pas la fenêtre lors de la suppression /!\

Poste le rapport généré ( C:\lopR.txt )

( Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr, Onglet Fichier,

Nouvelle tâche, tape explorer.exe et valide )

Voici le rapport Lop S&D : Je précise que mon antivirus vient encore de me dire que j’avais un virus :frowning:

--------------------\ Lop S&D 4.2.4-9c XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 CPU 6600 @ 2.40GHz )
BIOS : Default System BIOS
USER : Florian ( Administrator )
BOOT : Normal boot
Antivirus : Securitoo AntiVirus Firewall 7.00 7.00 (Activated)
Firewall : Securitoo AntiVirus Firewall 7.00 7.00 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:19 Go (Free:3 Go)
D:\ (Local Disk) - NTFS - Total:48 Go (Free:2 Go)
E:\ (Local Disk) - NTFS - Total:211 Go (Free:172 Go)
F:\ (CD or DVD) - UDF - Total:7 Go (Free:0 Go)
G:\ (CD or DVD)
H:\ (CD or DVD)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (USB)

“C:\Lop SD” ( MAJ : 01-11-2008|16:30 )
Option : [2] ( 18/12/2008|22:07 )

\\\\\\\\\\\\\\\

--------------------\ Listing des dossiers dans APPLIC~1

[20/03/2008|22:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[04/08/2007|15:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[28/12/2007|17:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
[03/01/2008|13:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
[03/01/2008|13:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[25/01/2008|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[16/10/2008|17:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\KONAMI
[16/12/2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[03/08/2007|18:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[03/12/2008|13:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[01/02/2008|20:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[06/12/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[06/08/2007|18:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[04/08/2007|15:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanAppDataDir
[04/08/2007|15:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanWizard
[06/08/2007|09:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/11/2007|13:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[28/01/2008|18:05] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Adobe
[10/03/2008|18:20] C:\DOCUME~1\BOUSSE~1\APPLIC~1\AdobeUM
[04/03/2008|20:38] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Canon
[11/08/2007|17:26] C:\DOCUME~1\BOUSSE~1\APPLIC~1\DeepBurner
[28/08/2008|18:05] C:\DOCUME~1\BOUSSE~1\APPLIC~1\F-Secure
[05/08/2007|11:16] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Google
[05/08/2007|09:19] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Help
[03/08/2007|15:09] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Identities
[05/08/2007|08:57] C:\DOCUME~1\BOUSSE~1\APPLIC~1\ispnews
[05/08/2007|09:19] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Macromedia
[05/03/2008|14:38] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Microsoft
[15/08/2007|08:52] C:\DOCUME~1\BOUSSE~1\APPLIC~1\Sun
[19/07/2008|17:30] C:\DOCUME~1\BOUSSE~1\APPLIC~1\WinRAR

[03/08/2007|12:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[25/07/2008|17:48] C:\DOCUME~1\Florian\APPLIC~1\Adobe
[20/03/2008|22:40] C:\DOCUME~1\Florian\APPLIC~1\AdobeUM
[12/11/2008|18:36] C:\DOCUME~1\Florian\APPLIC~1\Canon
[10/06/2008|19:18] C:\DOCUME~1\Florian\APPLIC~1\DataCast
[11/08/2007|16:56] C:\DOCUME~1\Florian\APPLIC~1\DeepBurner
[30/03/2008|17:36] C:\DOCUME~1\Florian\APPLIC~1\dvdcss
[18/03/2008|22:23] C:\DOCUME~1\Florian\APPLIC~1\FrostWire
[03/01/2008|18:06] C:\DOCUME~1\Florian\APPLIC~1\F-Secure
[04/08/2007|10:36] C:\DOCUME~1\Florian\APPLIC~1\Google
[02/02/2008|20:16] C:\DOCUME~1\Florian\APPLIC~1\Help
[03/08/2007|12:28] C:\DOCUME~1\Florian\APPLIC~1\Identities
[10/06/2008|19:16] C:\DOCUME~1\Florian\APPLIC~1\InstallShield
[03/08/2007|15:55] C:\DOCUME~1\Florian\APPLIC~1\ispnews
[14/12/2008|15:47] C:\DOCUME~1\Florian\APPLIC~1\LimeWire
[02/03/2008|21:36] C:\DOCUME~1\Florian\APPLIC~1\ma-config.com
[03/08/2007|15:19] C:\DOCUME~1\Florian\APPLIC~1\Macromedia
[16/12/2008|19:57] C:\DOCUME~1\Florian\APPLIC~1\Malwarebytes
[31/07/2008|10:50] C:\DOCUME~1\Florian\APPLIC~1\Microsoft
[07/06/2008|16:54] C:\DOCUME~1\Florian\APPLIC~1\Mp3tag
[29/12/2007|18:14] C:\DOCUME~1\Florian\APPLIC~1\Nero
[03/08/2007|15:57] C:\DOCUME~1\Florian\APPLIC~1\PEX
[04/10/2007|09:38] C:\DOCUME~1\Florian\APPLIC~1\Samsung
[04/08/2007|15:10] C:\DOCUME~1\Florian\APPLIC~1\ScanSoft
[03/12/2008|13:22] C:\DOCUME~1\Florian\APPLIC~1\SecuROM
[04/08/2007|10:31] C:\DOCUME~1\Florian\APPLIC~1\Sun
[09/12/2007|16:23] C:\DOCUME~1\Florian\APPLIC~1\vlc
[09/09/2007|17:15] C:\DOCUME~1\Florian\APPLIC~1\Wannadoo
[08/05/2008|10:01] C:\DOCUME~1\Florian\APPLIC~1\WinRAR

[06/08/2007|10:58] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[16/12/2008|20:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Adobe
[16/12/2008|20:27] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\ Tâches planifiées dans C:\WINDOWS\tasks

[17/12/2008 23:00][–a------] C:\WINDOWS\tasks\At24.job
[18/12/2008 22:00][–a------] C:\WINDOWS\tasks\At23.job
[18/12/2008 21:00][–a------] C:\WINDOWS\tasks\At22.job
[18/12/2008 19:00][–a------] C:\WINDOWS\tasks\At20.job
[18/12/2008 20:00][–a------] C:\WINDOWS\tasks\At21.job
[18/12/2008 18:00][–a------] C:\WINDOWS\tasks\At19.job
[18/12/2008 17:00][–a------] C:\WINDOWS\tasks\At18.job
[17/12/2008 14:00][–a------] C:\WINDOWS\tasks\At15.job
[17/12/2008 15:00][–a------] C:\WINDOWS\tasks\At16.job
[17/12/2008 16:00][–a------] C:\WINDOWS\tasks\At17.job
[17/12/2008 12:00][–a------] C:\WINDOWS\tasks\At13.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At12.job
[17/12/2008 13:00][–a------] C:\WINDOWS\tasks\At14.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At9.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At10.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At11.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At7.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At8.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At6.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At5.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At4.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At3.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At2.job
[14/12/2008 15:24][–a------] C:\WINDOWS\tasks\At1.job
[18/12/2008 21:22][–ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\ Listing des dossiers dans C:\Program Files

[30/07/2008|14:56] C:\Program Files\Adobe
[19/05/2008|18:18] C:\Program Files\AviSynth 2.5
[23/02/2008|11:19] C:\Program Files\BarreConfCMCIC
[28/12/2007|17:24] C:\Program Files\Bonjour
[04/08/2007|15:06] C:\Program Files\Canon
[12/03/2008|20:32] C:\Program Files\Creative
[13/03/2008|10:38] C:\Program Files\Electronic Arts
[25/01/2008|22:30] C:\Program Files\eRightSoft
[18/12/2008|21:21] C:\Program Files\Fichiers communs
[03/12/2008|14:09] C:\Program Files\InstallShield Installation Information
[03/08/2007|14:52] C:\Program Files\Intel
[12/12/2008|17:43] C:\Program Files\Internet Explorer
[03/01/2008|12:05] C:\Program Files\Inventel
[19/03/2008|18:02] C:\Program Files\Java
[10/06/2008|19:18] C:\Program Files\MarkAny
[05/10/2008|16:42] C:\Program Files\Messenger
[05/09/2008|18:14] C:\Program Files\Messenger Plus! Live
[03/08/2007|12:22] C:\Program Files\microsoft frontpage
[03/12/2008|13:30] C:\Program Files\Microsoft Games for Windows - LIVE
[07/11/2007|13:44] C:\Program Files\Microsoft SQL Server Compact Edition
[03/08/2007|18:53] C:\Program Files\Microsoft.NET
[05/10/2008|14:50] C:\Program Files\Movie Maker
[03/12/2008|12:31] C:\Program Files\MSBuild
[08/12/2007|13:35] C:\Program Files\MSI
[03/08/2007|12:18] C:\Program Files\MSN
[03/08/2007|12:18] C:\Program Files\MSN Gaming Zone
[24/03/2008|23:06] C:\Program Files\MSXML 4.0
[05/10/2008|14:47] C:\Program Files\NetMeeting
[03/08/2007|12:18] C:\Program Files\Online Services
[05/10/2008|14:47] C:\Program Files\Outlook Express
[03/08/2007|14:50] C:\Program Files\Realtek
[03/12/2008|12:30] C:\Program Files\Reference Assemblies
[02/02/2008|20:19] C:\Program Files\Samsung
[03/01/2008|13:12] C:\Program Files\Securitoo
[03/08/2007|12:20] C:\Program Files\Services en ligne
[26/12/2007|15:22] C:\Program Files\Ubisoft
[03/08/2007|12:28] C:\Program Files\Uninstall Information
[03/08/2007|18:12] C:\Program Files\VideoLAN
[18/12/2008|20:23] C:\Program Files\Wanadoo
[03/08/2007|15:16] C:\Program Files\Wanadoo Messager
[24/03/2008|23:08] C:\Program Files\Windows Live
[21/08/2007|13:41] C:\Program Files\Windows Media Connect 2
[03/12/2008|13:18] C:\Program Files\Windows Media Player
[05/10/2008|14:47] C:\Program Files\Windows NT
[03/08/2007|12:20] C:\Program Files\WindowsUpdate
[08/05/2008|08:54] C:\Program Files\WinRAR
[03/08/2007|12:22] C:\Program Files\xerox

--------------------\ Listing des dossiers dans C:\Program Files\Fichiers communs

[25/07/2008|16:25] C:\Program Files\Fichiers communs\Adobe
[03/08/2007|18:54] C:\Program Files\Fichiers communs\DESIGNER
[04/08/2007|15:07] C:\Program Files\Fichiers communs\InstallShield
[19/03/2008|18:00] C:\Program Files\Fichiers communs\Java
[28/12/2007|17:17] C:\Program Files\Fichiers communs\Macrovision Shared
[21/08/2008|22:59] C:\Program Files\Fichiers communs\Microsoft Shared
[03/08/2007|12:20] C:\Program Files\Fichiers communs\MSSoap
[03/08/2007|13:55] C:\Program Files\Fichiers communs\ODBC
[02/02/2008|20:16] C:\Program Files\Fichiers communs\ScanSoft Shared
[03/08/2007|12:20] C:\Program Files\Fichiers communs\Services
[03/08/2007|13:54] C:\Program Files\Fichiers communs\SpeechEngines
[05/10/2008|14:47] C:\Program Files\Fichiers communs\System
[07/11/2007|13:39] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\ Process

( 44 Processes )

… OK !

--------------------\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\ Verification du Registre

… OK !

--------------------\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-12-18 22:09:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 595

--------------------\ Recherche d’autres infections

C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job

[F:13][D:2]-> C:\DOCUME~1\Florian\LOCALS~1\Temp
[F:90][D:0]-> C:\DOCUME~1\Florian\Cookies
[F:849][D:4]-> C:\DOCUME~1\Florian\LOCALS~1\TEMPOR~1\content.IE5

1 - “C:\Lop SD\LopR_1.txt” - 18/12/2008|21:59 - Option : [1]
2 - “C:\Lop SD\LopR_2.txt” - 18/12/2008|22:09 - Option : [2]

--------------------\ Fin du rapport a 22:09:57

Re,

Il m’ennerve celui la:

  1. Fermez tous les navigateurs ouverts.

  2. Fermez/désactivez tous les programmes anti-virus, anti-malware ou anti-spyware afin qu’ils n’interfèrent pas avec le travail de ComboFix.

  3. Ouvrez le Bloc-notes et faites un copier/coller du texte en gras situé dans la boîte Citation ci-dessous dans le Bloc-notes:


File::
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job

Enregistrez le fichier sous le nom CFScript.txt, au même endroit que ComboFix.exe

img.photobucket.com…

Comme sur l’image ci-dessus, faites glisser CFScript puis déposez-le sur ComboFix.exe

Lorsque l’outil aura terminé, il vous affichera un rapport nommé C:\ComboFix.txt que vous devez m’envoyer dans votre prochain message.

Voila le rapport ComboFix : (Je précise que lorsque la fenêtre qui dit de patientez car le rapport est en cours d’écriture, il est aussi écrit : " FINDSTR : impossible d’ouvrir Temp01 " C’est normal ?)

ComboFix 08-12-15.08 - Florian 2008-12-18 22:25:07.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2047.1509 [GMT 1:00]
Lancé depuis: c:\documents and settings\Florian\Bureau\flobo.exe
Commutateurs utilisés :: c:\documents and settings\Florian\Bureau\CFScript.txt.txt

  • Un nouveau point de restauration a été créé

FILE ::
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-18 au 2008-12-18 ))))))))))))))))))))))))))))))))))))
.

2008-12-18 21:56 . 2008-12-18 22:09 d-------- C:\Lop SD
2008-12-18 21:47 . 2008-12-18 21:47 d-------- C:\rsit
2008-12-16 20:27 . 2008-12-16 20:27 dr------- c:\documents and settings\NetworkService\Favoris
2008-12-16 19:57 . 2008-12-16 19:57 d-------- c:\documents and settings\Florian\Application Data\Malwarebytes
2008-12-16 19:57 . 2008-12-16 19:57 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-16 19:57 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-16 19:57 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-14 15:24 . 2008-12-14 15:23 31,744 --a------ c:\windows\system32\Q23Jc8P5.exe
2008-12-13 12:53 . 2008-12-13 12:53 1,700,352 --a------ c:\windows\system32\gdiplus.dll
2008-12-06 21:25 . 2008-12-06 21:25 d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-06 21:21 . 2008-12-06 21:21 d-------- c:\windows\nview
2008-12-06 21:21 . 2008-12-02 10:13 453,152 --a------ c:\windows\system32\NVUNINST.EXE
2008-12-06 21:21 . 2008-12-02 23:11 453,152 --a------ c:\windows\system32\nvudisp.exe
2008-12-06 21:21 . 2008-12-18 21:23 205,242 --a------ c:\windows\system32\nvapps.xml
2008-12-06 21:21 . 2008-12-02 23:11 18,696 --a------ c:\windows\system32\nvdisp.nvu
2008-12-05 18:09 . 2008-12-05 18:09 212 --a------ c:\windows\system32\spupdsvc.inf
2008-12-05 18:07 . 2008-12-05 18:14 d-------- c:\windows\SxsCaPendDel
2008-12-03 15:11 . 2008-12-02 23:11 6,209,536 --a------ c:\windows\system32\drivers\nv4_mini.sys
2008-12-03 15:11 . 2008-12-02 23:11 6,166,272 --a------ c:\windows\system32\nv4_disp.dll
2008-12-03 14:44 . 2008-12-03 14:45 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-03 13:22 . 2008-12-03 13:22 dr-h----- c:\documents and settings\Florian\Application Data\SecuROM
2008-12-03 13:17 . 2008-12-03 13:17 d-------- c:\windows\system32\xlive
2008-12-03 13:17 . 2008-12-03 13:30 d-------- c:\program files\Microsoft Games for Windows - LIVE
2008-12-03 12:31 . 2008-12-03 12:31 d-------- c:\program files\MSBuild
2008-12-03 12:30 . 2008-12-05 18:12 d-------- c:\windows\system32\XPSViewer
2008-12-03 12:30 . 2008-12-03 12:30 d-------- c:\program files\Reference Assemblies
2008-12-03 12:29 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 19:23 --------- d-----w c:\program files\Wanadoo
2008-12-16 15:32 93,782 --sha-w c:\windows\system32\lanadata.dll
2008-12-14 14:47 --------- d-----w c:\documents and settings\Florian\Application Data\LimeWire
2008-12-03 13:09 --------- d–h--w c:\program files\InstallShield Installation Information
2008-11-12 17:36 --------- d-----w c:\documents and settings\Florian\Application Data\Canon
2008-10-28 16:41 14,303,392 ----a-w c:\windows\system32\xlive.dll
2008-10-28 16:41 13,643,936 ----a-w c:\windows\system32\xlivefnt.dll
2008-10-27 09:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-10 03:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-07-31 10:25 22,328 ----a-w c:\documents and settings\Florian\Application Data\PnkBstrK.sys
2008-01-11 22:06 1,602 ----a-w c:\documents and settings\Florian\Application Data\filterclsid.dat
2006-05-03 09:06 163,328 --sh–r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh–r c:\windows\system32\msfDX.dll
2008-09-16 14:32 61,440 --sha-w c:\windows\system32\wuyojogi.dll
.

((((((((((((((((((((((((((((( snapshot@2008-12-17_14.27.01,60 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\ctfmon.exe” [2008-04-14 15360]
“MSMSGS”=“c:\program files\Messenger\msmsgs.exe” [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“F-Secure Manager”=“c:\program files\Securitoo\av_fw\Common\FSM32.EXE” [2007-06-13 176177]
“F-Secure TNB”=“c:\program files\Securitoo\av_fw\FSGUI\TNBUtil.exe” [2007-06-13 733184]
“JMB36X IDE Setup”=“c:\windows\RaidTool\xInsIDE.exe” [2007-03-20 36864]
“36X Raid Configurer”=“c:\windows\system32\xRaidSetup.exe” [2007-11-19 1970176]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-12-02 13680640]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-12-02 86016]
“nwiz”=“nwiz.exe” [2008-12-02 c:\windows\system32\nwiz.exe]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.I420”= i420vfw.dll

[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d’Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d’Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d’Adobe Reader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a------ 2006-11-12 11:48 157592 d:\daemon tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
–a------ 2003-05-08 10:00 49152 d:\omnipage\opwareSE2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--------- 2004-08-23 14:49 20480 c:\progra~1\Wanadoo\Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2006-07-21 09:56 16261632 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 2006-05-16 11:04 2879488 c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“UpdatesDisableNotify”=dword:00000001
“AntiVirusOverride”=dword:00000001
“FirewallOverride”=dword:00000001

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“c:\WINDOWS\system32\PnkBstrA.exe”=
“c:\WINDOWS\system32\PnkBstrB.exe”=
“c:\Program Files\Bonjour\mDNSResponder.exe”=
“d:\CoH opposing fronts\RelicCOH.exe”=
“c:\WINDOWS\system32\muzapp.exe”=
“d:\Crysis\Bin32\Crysis.exe”=
“d:\Crysis\Bin32\CrysisDedicatedServer.exe”=
“c:\Program Files\Windows Live\Messenger\msnmsgr.exe”=
“c:\Program Files\Windows Live\Messenger\livecall.exe”=
“d:\PES 2009\pes2009.exe”=
“d:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe”=
“d:\GTA IV\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe”=

R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-01-03 51072]
R1 F-Secure HIPS;F-Secure HIPS;??\c:\program files\Securitoo\av_fw\HIPS\fshs.sys [2008-01-03 41184]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;??\c:\program files\Securitoo\av_fw\Anti-Virus\minifilter\fsgk.sys [2008-01-03 52736]
S3 DigiCellDriver;DigiCellDriver;??\c:\program files\MSI\DigiCell\NTGLM7X.sys []
S3 RushTopDevice2;RushTopDevice2;??\c:\program files\MSI\DualCoreCenter\RushTop.sys []
S4 F-Secure Filter;F-Secure File System Filter;??\c:\program files\Securitoo\av_fw\Anti-Virus\Win2K\FSfilter.sys [2008-01-03 33024]
S4 F-Secure Recognizer;F-Secure File System Recognizer;??\c:\program files\Securitoo\av_fw\Anti-Virus\Win2K\FSrec.sys [2008-01-03 18432]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{43b964d2-8ff3-11dd-9ab8-0019db4ab03e}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NoLimit.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5a131ac2-41c0-11dc-bd7d-806d6172696f}]
\Shell\AutoRun\command - F:\Livebox.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{b2342196-5146-11dc-ba8e-806d6172696f}]
\Shell\AutoRun\command - F:\FarCryAutoCD.exe
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = www.google.com…
uStart Page = www.google.fr…
uSearchURL,(Default) = www.google.com…
IE: E&xporter vers Microsoft Excel - d:\office\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Ajouter à la liste d’impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O16 -: {5AEF5128-FE70-49E8-9E86-45F0A2D7E4EE} - go.opendisc.net…
c:\windows\Downloaded Program Files\OpendiscLight.inf

O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - fichiers.touslesdrivers.com…
c:\windows\Downloaded Program Files\hardwaredetection.inf
.


catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-12-18 22:25:45
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


.
--------------------- DLLs chargées dans les processus actifs ---------------------

              • ‘winlogon.exe’(808)
                c:\program files\Securitoo\av_fw\FWES\Program\fsdc.dll

              • ‘lsass.exe’(864)
                c:\program files\Securitoo\av_fw\FWES\Program\fsdc.dll

              • ‘csrss.exe’(780)
                c:\program files\Securitoo\av_fw\FWES\Program\fsdc.dll
                .
                Heure de fin: 2008-12-18 22:26:20
                ComboFix-quarantined-files.txt 2008-12-18 21:26:07
                ComboFix2.txt 2008-12-18 20:25:08
                ComboFix3.txt 2008-12-17 13:27:30

Avant-CF: 4 465 356 800 octets libres
Après-CF: 4,461,998,080 octets libres

240 — E O F — 2008-12-12 16:44:54

Re,

Fait un rsit de contrôle.

@+

Voila le rapport RSIT :

Logfile of random’s system information tool 1.05 (written by random/random)
Run by Florian at 2008-12-18 23:17:06
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 4 GB (21%) free of 20 GB
Total RAM: 2047 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:17:36, on 18/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsus.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Florian\Bureau\RSIT.exe
D:\Hijackthis\Florian.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d’aide de l’Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM…\Run: [F-Secure Manager] “C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE” /splash
O4 - HKLM…\Run: [F-Secure TNB] “C:\Program Files\Securitoo\av_fw\FSGUI\TNBUtil.exe” /CHECKALL /WAITFORSW
O4 - HKLM…\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM…\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - D:\OFFICE\OFFICE11\EXCEL.EXE…
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d’impressions - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - C:\Program… Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.orange.fr… (file missing) (HKCU)
O16 - DPF: {5AEF5128-FE70-49E8-9E86-45F0A2D7E4EE} (OpendiscLight Control) - go.opendisc.net…
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - download.divx.com…
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - fichiers.touslesdrivers.com…
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - sdlc-esd.sun.com…
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - messenger.zone.msn.com…
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - messenger.zone.msn.com…
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe


End of file - 8176 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d’aide de l’Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{988B07F5-7392-455A-8A1F-64935CB8B6ED}]
BHO Barre de Confiance - C:\Program Files\BarreConfCMCIC\TAPBar.dll [2007-09-14 225280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - Barre de confiance - C:\Program Files\BarreConfCMCIC\TAPBar.dll [2007-09-14 225280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“F-Secure Manager”=C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE [2007-06-13 176177]
“F-Secure TNB”=C:\Program Files\Securitoo\av_fw\FSGUI\TNBUtil.exe [2007-06-13 733184]
“JMB36X IDE Setup”=C:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
“36X Raid Configurer”=C:\WINDOWS\system32\xRaidSetup.exe [2007-11-19 1970176]
“NvCplDaemon”=C:\WINDOWS\system32\NvCpl.dll [2008-12-02 13680640]
“nwiz”=nwiz.exe /install []
“NvMediaCenter”=C:\WINDOWS\system32\NvMcTray.dll [2008-12-02 86016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
“MSMSGS”=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
D:\Daemon Tools\daemon.exe [2006-11-12 157592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
D:\OMNIPAGE\OpwareSE2.exe [2003-05-08 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2006-07-21 16261632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
C:\PROGRA~1\Wanadoo\Watch.exe [2004-08-23 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d’Adobe Reader.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=323
“NoDrives”=0
“NoDriveAutoRun”=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=
“NoDrives”=
“NoDriveAutoRun”=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000"
“C:\WINDOWS\system32\PnkBstrA.exe”=“C:\WINDOWS\system32\PnkBstrA.exe::Enabled:PnkBstrA"
“C:\WINDOWS\system32\PnkBstrB.exe”="C:\WINDOWS\system32\PnkBstrB.exe:
:Enabled:PnkBstrB”
“C:\Program Files\Bonjour\mDNSResponder.exe”=“C:\Program Files\Bonjour\mDNSResponder.exe::Enabled:Bonjour"
“D:\CoH opposing fronts\RelicCOH.exe”="D:\CoH opposing fronts\RelicCOH.exe:
:Enabled:Company of Heroes - Opposing Fronts”
“C:\WINDOWS\system32\muzapp.exe”=“C:\WINDOWS\system32\muzapp.exe::Enabled:MUZ AOD APP player"
“D:\Crysis\Bin32\Crysis.exe”="D:\Crysis\Bin32\Crysis.exe:
:Enabled:Crysis_32”
“D:\Crysis\Bin32\CrysisDedicatedServer.exe”=“D:\Crysis\Bin32\CrysisDedicatedServer.exe::Enabled:CrysisDedicatedServer_32"
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:
:Enabled:Windows Live Messenger”
“C:\Program Files\Windows Live\Messenger\livecall.exe”=“C:\Program Files\Windows Live\Messenger\livecall.exe::Enabled:Windows Live Messenger (Phone)"
“D:\PES 2009\pes2009.exe”="D:\PES 2009\pes2009.exe:
:Enabled:Pro Evolution Soccer 2009”
“D:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe”=“D:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe::Enabled:Rockstar Games Social Club"
“D:\GTA IV\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe”="D:\GTA IV\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe:
:Enabled:Grand Theft Auto IV”

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000"
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger"
“C:\Program Files\Windows Live\Messenger\livecall.exe”="C:\Program Files\Windows Live\Messenger\livecall.exe:
:Enabled:Windows Live Messenger (Phone)”

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{43b964d2-8ff3-11dd-9ab8-0019db4ab03e}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NoLimit.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5a131ac2-41c0-11dc-bd7d-806d6172696f}]
shell\AutoRun\command - F:\Livebox.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{b2342196-5146-11dc-ba8e-806d6172696f}]
shell\AutoRun\command - F:\FarCryAutoCD.exe

======List of files/folders created in the last 1 months======

2008-12-18 22:26:21 ----A---- C:\ComboFix.txt
2008-12-18 22:24:31 ----D---- C:\flobo
2008-12-18 21:57:46 ----A---- C:\lopR.txt
2008-12-18 21:56:50 ----D---- C:\Lop SD
2008-12-18 21:47:27 ----D---- C:\rsit
2008-12-17 14:25:28 ----A---- C:\Boot.bak
2008-12-17 14:25:25 ----RASHD---- C:\cmdcons
2008-12-17 14:23:38 ----A---- C:\WINDOWS\zip.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\VFIND.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\SWXCACLS.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\SWSC.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\SWREG.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\sed.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\NIRCMD.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\grep.exe
2008-12-17 14:23:38 ----A---- C:\WINDOWS\fdsv.exe
2008-12-16 22:17:16 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-16 21:30:21 ----D---- C:\WINDOWS\ERDNT
2008-12-16 21:30:21 ----D---- C:\Qoobox
2008-12-16 19:57:22 ----D---- C:\Documents and Settings\Florian\Application Data\Malwarebytes
2008-12-16 19:57:15 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-14 15:24:40 ----A---- C:\WINDOWS\system32\Q23Jc8P5.exe
2008-12-13 12:53:21 ----A---- C:\WINDOWS\system32\gdiplus.dll
2008-12-12 17:44:49 ----HDC---- C:\WINDOWS$NtUninstallKB955839$
2008-12-12 17:42:09 ----HDC---- C:\WINDOWS$NtUninstallKB952069_WM9$
2008-12-12 17:41:40 ----HDC---- C:\WINDOWS$NtUninstallKB954600$
2008-12-12 17:41:32 ----HDC---- C:\WINDOWS$NtUninstallKB956802$
2008-12-09 17:59:22 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2008-12-09 17:59:22 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2008-12-09 17:59:22 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2008-12-09 17:59:21 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2008-12-09 17:59:20 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2008-12-09 17:59:20 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2008-12-09 17:59:20 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2008-12-09 17:59:19 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2008-12-09 17:59:19 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2008-12-09 17:59:19 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2008-12-06 21:25:39 ----D---- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-12-06 21:21:22 ----D---- C:\WINDOWS\nview
2008-12-06 21:21:22 ----A---- C:\WINDOWS\system32\nvudisp.exe
2008-12-06 21:21:01 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2008-12-05 18:08:43 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-12-05 18:07:00 ----D---- C:\WINDOWS\SxsCaPendDel
2008-12-03 15:11:34 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2008-12-03 14:44:52 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2008-12-03 13:22:49 ----RHD---- C:\Documents and Settings\Florian\Application Data\SecuROM
2008-12-03 13:17:30 ----D---- C:\WINDOWS\system32\xlive
2008-12-03 13:17:28 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2008-12-03 12:33:32 ----HDC---- C:\WINDOWS$NtUninstallXPSEPSCLP$
2008-12-03 12:31:50 ----D---- C:\Program Files\MSBuild
2008-12-03 12:30:44 ----D---- C:\WINDOWS\system32\XPSViewer
2008-12-03 12:30:42 ----D---- C:\WINDOWS\system32\en-us
2008-12-03 12:30:12 ----D---- C:\Program Files\Reference Assemblies
2008-12-03 12:29:56 ----N---- C:\WINDOWS\system32\spmsg2.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nwiz.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwss.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwimg.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvvitvs.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvshell.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmobls.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmccss.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvmccs.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nview.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvgames.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvdisps.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcplui.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcodins.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvcod.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvappbar.exe
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2008-12-02 23:11:00 ----A---- C:\WINDOWS\system32\keystone.exe

======List of files/folders modified in the last 1 months======

2008-12-18 23:17:32 ----D---- C:\WINDOWS\Temp
2008-12-18 23:17:19 ----D---- C:\WINDOWS\Prefetch
2008-12-18 22:26:22 ----D---- C:\WINDOWS\system32
2008-12-18 22:26:21 ----D---- C:\WINDOWS
2008-12-18 22:25:46 ----A---- C:\WINDOWS\system.ini
2008-12-18 22:25:27 ----D---- C:\WINDOWS\system32\drivers
2008-12-18 22:25:27 ----D---- C:\WINDOWS\AppPatch
2008-12-18 22:25:27 ----D---- C:\Program Files\Fichiers communs
2008-12-18 22:25:11 ----SD---- C:\WINDOWS\Tasks
2008-12-18 22:24:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-12-18 21:23:11 ----D---- C:\WINDOWS\system32\CatRoot2
2008-12-18 20:23:37 ----D---- C:\Program Files\Wanadoo
2008-12-17 14:25:28 ----RASH---- C:\boot.ini
2008-12-16 16:32:38 ----ASH---- C:\WINDOWS\system32\lanadata.dll
2008-12-14 15:53:33 ----HD---- C:\WINDOWS\inf
2008-12-14 15:50:32 ----D---- C:\WINDOWS\Debug
2008-12-14 15:47:16 ----D---- C:\Documents and Settings\Florian\Application Data\LimeWire
2008-12-12 17:44:43 ----SHD---- C:\WINDOWS\Installer
2008-12-12 17:44:36 ----A---- C:\WINDOWS\win.ini
2008-12-12 17:43:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-12 17:43:55 ----D---- C:\Program Files\Internet Explorer
2008-12-12 17:43:47 ----D---- C:\WINDOWS\ie7updates
2008-12-12 17:43:39 ----HD---- C:\WINDOWS$hf_mig$
2008-12-09 17:59:04 ----RSD---- C:\WINDOWS\assembly
2008-12-09 17:58:47 ----D---- C:\WINDOWS\system32\DirectX
2008-12-06 21:21:25 ----D---- C:\WINDOWS\Help
2008-12-05 19:59:30 ----D---- C:\WINDOWS\Microsoft.NET
2008-12-05 18:16:45 ----D---- C:\WINDOWS\system32\CatRoot
2008-12-05 18:12:03 ----D---- C:\WINDOWS\system32\fr-fr
2008-12-05 18:09:25 ----RSD---- C:\WINDOWS\Fonts
2008-12-05 18:05:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-05 18:05:07 ----D---- C:\WINDOWS\WinSxS
2008-12-03 14:09:18 ----HD---- C:\Program Files\InstallShield Installation Information
2008-12-03 13:18:44 ----D---- C:\Program Files\Windows Media Player
2008-12-03 13:17:30 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-12-03 13:17:28 ----D---- C:\Program Files
2008-12-03 12:33:25 ----D---- C:\WINDOWS\system32\mui
2008-12-03 12:30:01 ----D---- C:\WINDOWS\system32\spool

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 F-Secure HIPS;F-Secure HIPS; ??\C:\Program Files\Securitoo\av_fw\HIPS\fshs.sys []
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; ??\C:\Program Files\Securitoo\av_fw\Anti-Virus\minifilter\fsgk.sys []
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-12-02 6209536]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-07-21 82432]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Pilote miniport de contrôleur d’hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 apcixy8z;apcixy8z; C:\WINDOWS\system32\drivers\apcixy8z.sys []
S3 DigiCellDriver;DigiCellDriver; ??\C:\Program Files\MSI\DigiCell\NTGLM7X.sys []
S3 driverhardwarev2;driverhardwarev2; ??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys []
S3 GMSIPCI;GMSIPCI; ??\F:\INSTALL\GMSIPCI.SYS []
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; ??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; ??\C:\WINDOWS\system32\PCANDIS5.SYS []
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys []
S3 RushTopDevice2;RushTopDevice2; ??\C:\Program Files\MSI\DualCoreCenter\RushTop.sys []
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336]
S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000]
S3 usbprint;Classe d’imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 F-Secure Filter;F-Secure File System Filter; ??\C:\Program Files\Securitoo\av_fw\Anti-Virus\Win2K\FSfilter.sys []
S4 F-Secure Recognizer;F-Secure File System Recognizer; ??\C:\Program Files\Securitoo\av_fw\Anti-Virus\Win2K\FSrec.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS; C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe [2007-06-13 41043]
R2 FSMA;F-Secure Management Agent; C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE [2007-06-13 106546]
R2 FTRTSVC;France Telecom Routing Table Service; C:\WINDOWS\System32\FTRTSVC.exe [2004-08-23 40960]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-12-02 163908]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-07-31 66872]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 FSAUA;F-Secure Automatic Update Agent; C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe [2007-06-13 450560]
R3 FSDFWD;F-Secure Anti-Virus Firewall Daemon; C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe [2007-06-13 446464]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 aspnet_state;Service d’état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2007-12-28 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 918016]
S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re,
Je ne peux pas lancer USBFix, quand je fais un double clique dessus Securitoo m’indique que USBFix est contaminé par B2E.exe et ne veut donc pas l’ouvrir.
Je précise aussi que je n’ai pas de périphérique externe.
Edité le 19/12/2008 à 09:52

Re,

Désactive ton antivirus ou ignore l’alerte de celui ci…

@+

MBAM n’a rien détécté, mais j’ai toujours Securitoo qui m’envoie ses alertes… :frowning:
Edité le 19/12/2008 à 10:41

Re,

Essai de nouveau usbfix et dit moi comment va ton pc?

@+

Re,
J’ai bien utilisé USBFix, mais aucun rapport ne s’est créé ! Il était écrit qu’il ne trouvait pas le chemin de destination du rapport…

Re,

Relance le encore…

Voila le rapport :

-------------- UsbFix V2.413.5 ---------------

  • User : Florian - PC-3257AB58FDE9
  • Outils mis a jours le 17/12/2008 par Chiquitine29 et Chimay8
  • Recherche effectuée à 11:22:53 le 19/12/2008
  • Windows Xp - Internet Explorer 7.0.5730.11

--------------- [ Processus actifs ] ----------------

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
C:\Program Files\Securitoo\av_fw\FSGUI\fsstm.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
C:\DOCUME~1\Florian\LOCALS~1\Temp\1.tmp\b2e.exe
C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\licmgr.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsus.exe

--------------- [ Informations lecteurs ] ----------------

C: - Lecteur fixe

D: - Lecteur fixe

E: - Lecteur fixe

F: - Lecteur de CD-ROM

± Contenu de l’autorun : F:\autorun.inf

[autorun]
icon=Autorun.exe,0
open=Autorun.exe

--------------- [ Lecteur C ] ----------------

C: - Lecteur fixe

± Listing des fichiers présents :

[03/08/2007 12:21][–a------] C:\AUTOEXEC.BAT
[05/08/2004 13:00][-rahs----] C:\NTDETECT.COM
[17/12/2008 14:25][-rahs----] C:\boot.ini
[18/12/2008 22:26][–a------] C:\ComboFix.txt
[18/12/2008 22:26][–a------] C:\lopR.txt
[18/12/2008 22:26][–a------] C:\mp4log.txt
[18/12/2008 22:26][–a------] C:\UsbFix.txt
[03/08/2007 12:21][–a------] C:\CONFIG.SYS
[03/08/2007 12:21][–a------] C:\IO.SYS
[03/08/2007 12:21][–a------] C:\MSDOS.SYS
[03/08/2007 12:21][–a------] C:\pagefile.sys
[03/08/2007 12:21][–a------] C:\pjvfao30.sys

--------------- [ Lecteur D ] ----------------

D: - Lecteur fixe

± Listing des fichiers présents :

--------------- [ Lecteur E ] ----------------

E: - Lecteur fixe

± Listing des fichiers présents :

--------------- [ Lecteur F ] ----------------

F: - Lecteur de CD-ROM

± Listing des fichiers présents :

[15/11/2008 10:52][-r-------] F:\Autorun.exe
[11/10/2008 18:03][-r-------] F:\Autorun.inf

--------------- [ Registre / Startup ] ----------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Userinit”=“C:\WINDOWS\system32\userinit.exe,”

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
“Search Page”=“http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
“Start Page”=“http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
MSMSGS=“C:\Program Files\Messenger\msmsgs.exe” /background
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater=
=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
F-Secure Manager=“C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE” /splash
F-Secure TNB=“C:\Program Files\Securitoo\av_fw\FSGUI\TNBUtil.exe” /CHECKALL /WAITFORSW
JMB36X IDE Setup=C:\WINDOWS\RaidTool\xInsIDE.exe
36X Raid Configurer=C:\WINDOWS\system32\xRaidSetup.exe boot
NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz=nwiz.exe /install
NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
Installed=1
NoChange=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1

--------------- [ Registre / Mountpoint2 ] ----------------

Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{43b964d2-8ff3-11dd-9ab8-0019db4ab03e}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{5a131ac2-41c0-11dc-bd7d-806d6172696f}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{b2342196-5146-11dc-ba8e-806d6172696f}\Shell\AutoRun\command

--------------- [ Nettoyage des disques ] ----------------

Echec de la supression !! - [11/10/2008 18:03] F:\autorun.inf
Echec de la supression !! - [15/11/2008 10:52] F:\autorun.exe
Echec de la supression !! - [11/10/2008 18:03] F:\autorun.inf
Echec de la supression !! - [11/10/2008 18:03] F:\autorun.inf
Edité le 19/12/2008 à 11:26