Forum Clubic

Mon PC est-il infecté? (SOS)

Bonjour.
Cela fait maintenant plusieurs années que je travaille sur un PC (portable) que je crains infecté. Je découvre par exemple dans la liste des processus des “.exe” suspects, exigeant beaucoup de mémoire… Qui plus est, l’espace-disque de mon PC change fréquemment et étrangement sans que j’y fasse quelque opération qui pourrait requérir autant de place changeante.

Aussi, je supplie tous les connaisseurs an la question de bien vouloir m’aider. Voici mon log HiJackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:38:28, on 02/08/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
c:\progra~1\fichie~1\instal~1\update~1\isuspm.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Program Files\AVG\AVG9\avgscanx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Documents and Settings\Luc MEFFRE\Mes documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = fr.search.yahoo.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM…\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM…\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM…\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM…\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe”
O4 - HKLM…\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM…\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM…\Run: [DVDLauncher] “C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe”
O4 - HKLM…\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM…\Run: [IntelZeroConfig] “C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe”
O4 - HKLM…\Run: [IntelWireless] “C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” /tf Intel PROSet/Wireless
O4 - HKLM…\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM…\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM…\Run: [ISUSScheduler] “C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe” -start
O4 - HKLM…\Run: [Google Desktop Search] “C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup
O4 - HKLM…\Run: [Adobe Photo Downloader] “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKLM…\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM…\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM…\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM…\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU…\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [CTSyncU.exe] “C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe”
O4 - HKCU…\Run: [Skype] “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized
O4 - HKCU…\Run: [Google Update] “C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe” /c
O4 - HKCU…\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SERVICE LOCAL’)
O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SERVICE RÉSEAU’)
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EMBASSY Trust Suite Secure Update.lnk = C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE…
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - picasaweb.google.fr…
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com…
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: wxvault.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Common\DataServer.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe (file missing)
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


End of file - 13564 bytes

Pitié! Cela fait presque cinq ans que je lutte contre toutes ces immondices de malwares, et j’ai vraiment besoin d’aide.:frowning:
Merci d’avance à ceux qui auront l’indulgence de me soutenir.:frown:
Edité le 02/08/2010 à 11:03

:hello:

rien de probant dans ton log:

Clique [ici](http://images.malwareremoval.com/random/RSIT.exe) pour télécharger random's system information tool (RSIT) par random/random et sauvegarde le sur ton [b]Bureau[/b]
  • Double-clique sur RSIT.exe pour l’exécuter.

  • Clique sur le bouton “Continue” sur la fenêtre d’avertissement.

  • Une fois le scan terminé, tu auras deux rapports qui seront ouverts : log.txt et info.txt (c:\rsit)

  • Poste les dans ta prochaine réponse s’il te plait

D’accord. Voici log.txt:

Logfile of random’s system information tool 1.08 (written by random/random)
Run by Luc MEFFRE at 2010-08-02 12:02:17
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 12 GB (16%) free of 76 GB
Total RAM: 1014 MB (18% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:03:28, on 02/08/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
c:\progra~1\fichie~1\instal~1\update~1\isuspm.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Luc MEFFRE\Mes documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Luc MEFFRE.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = fr.search.yahoo.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM…\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM…\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM…\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM…\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe”
O4 - HKLM…\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM…\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM…\Run: [DVDLauncher] “C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe”
O4 - HKLM…\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM…\Run: [IntelZeroConfig] “C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe”
O4 - HKLM…\Run: [IntelWireless] “C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” /tf Intel PROSet/Wireless
O4 - HKLM…\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM…\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM…\Run: [ISUSScheduler] “C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe” -start
O4 - HKLM…\Run: [Google Desktop Search] “C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup
O4 - HKLM…\Run: [Adobe Photo Downloader] “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKLM…\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM…\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM…\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM…\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM…\RunOnce: [KB976002-v5] C:\WINDOWS\system32\browserchoice.exe
O4 - HKCU…\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [CTSyncU.exe] “C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe”
O4 - HKCU…\Run: [Skype] “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized
O4 - HKCU…\Run: [Google Update] “C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe” /c
O4 - HKCU…\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SERVICE LOCAL’)
O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SERVICE RÉSEAU’)
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EMBASSY Trust Suite Secure Update.lnk = C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE…
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - picasaweb.google.fr…
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com…
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: wxvault.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Common\DataServer.exe
O23 - Service: Service d’administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d’aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe (file missing)
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe


End of file - 15832 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3825869345-3750952953-1186466244-1006Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3825869345-3750952953-1186466244-1006UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-09-13 1312040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-21 1619296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 110652]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1119488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\BAE\BAE.dll [2006-08-30 94208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1119488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“Apoint”=C:\Program Files\Apoint\Apoint.exe [2005-10-07 176128]
“igfxtray”=C:\WINDOWS\system32\igfxtray.exe [2005-12-14 98304]
“igfxhkcmd”=C:\WINDOWS\system32\hkcmd.exe [2005-12-14 77824]
“igfxpers”=C:\WINDOWS\system32\igfxpers.exe [2005-12-14 118784]
“SunJavaUpdateSched”=C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]
“SigmatelSysTrayApp”=C:\WINDOWS\stsystra.exe [2006-03-25 282624]
“Document Manager”=C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe [2006-05-16 102400]
“DVDLauncher”=C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [2005-12-09 49152]
“Dell QuickSet”=C:\Program Files\Dell\QuickSet\quickset.exe [2006-06-29 1032192]
“IntelZeroConfig”=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2005-12-28 667718]
“IntelWireless”=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2005-12-28 602182]
“DLA”=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]
“ISUSPM Startup”=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe [2005-02-16 221184]
“ISUSScheduler”=C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
“Google Desktop Search”=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2006-09-14 169984]
“Adobe Photo Downloader”=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-06 57344]
“QuickTime Task”=C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]
“iTunesHelper”=C:\Program Files\iTunes\iTunesHelper.exe [2006-10-30 256576]
“CanonSolutionMenu”=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2008-03-11 689488]
“CanonMyPrinter”=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2008-03-18 1848648]
“Kernel and Hardware Abstraction Layer”=C:\WINDOWS\KHALMNPR.EXE [2007-11-29 55824]
“NPSStartup”= []
“AVG9_TRAY”=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-07-16 2065760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“KB976002-v5”=C:\WINDOWS\system32\browserchoice.exe [2010-02-12 293376]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“ModemOnHold”=C:\Program Files\NetWaiting\netWaiting.exe [2003-09-10 20480]
“MSMSGS”=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
“ctfmon.exe”=C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360]
“CTSyncU.exe”=C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe [2006-08-07 700416]
“Skype”=C:\Program Files\Skype\Phone\Skype.exe [2007-09-13 22880040]
“Google Update”=C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-03 133104]
“AutoStartNPSAgent”=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
EMBASSY Trust Suite Secure Update.lnk - C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
EPSON Status Monitor 3 Environment Check(2).lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
“AppInit_DLLs”=“wxvault.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-07-16 12536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-12-14 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll [2008-01-09 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
“authentication packages”=msv1_0
wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“HonorAutoRunSetting”=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“C:\Program Files\Messenger\msmsgs.exe”="C:\Program Files\Messenger\msmsgs.exe:
:Enabled:Windows Messenger"
“C:\WINDOWS\system32\usmt\migwiz.exe”=“C:\WINDOWS\system32\usmt\migwiz.exe::Enabled:Assistant Transfert de fichiers et de paramètres"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000”
“C:\Program Files\iTunes\iTunes.exe”=“C:\Program Files\iTunes\iTunes.exe::Enabled:iTunes"
“C:\Games\Descent3\main.exe”="C:\Games\Descent3\main.exe:
:Disabled:main”
“C:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\game.dat”=“C:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\game.dat::Enabled:La Bataille pour la Terre du Milieu ™ II"
“C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu™\game.dat”="C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu™\game.dat:
:Enabled:La Bataille pour la Terre du Milieu™”
“C:\Program Files\Electronic Arts\L’Avènement du Roi-sorcier\game.dat”=“C:\Program Files\Electronic Arts\L’Avènement du Roi-sorcier\game.dat::Enabled:LSDA, L’Avènement du Roi-sorcier™"
“C:\WINDOWS\explorer.exe”="C:\WINDOWS\explorer.exe:
:Enabled:Explorateur Windows”
“C:\Program Files\Cyanide\Loki\Loki.exe”=“C:\Program Files\Cyanide\Loki\Loki.exe::Enabled:Loki"
“C:\Program Files\Cyanide\Loki\Autorun\Autorun.exe”="C:\Program Files\Cyanide\Loki\Autorun\Autorun.exe:
:Enabled:Loki - AutoRun”
“C:\Documents and Settings\Luc MEFFRE\Bureau\Félix\Universe at War-Earth Assault\UAWEA.exe”=“C:\Documents and Settings\Luc MEFFRE\Bureau\Félix\Universe at War-Earth Assault\UAWEA.exe::Disabled:Universe at War: Earth Assault Application"
“C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe”="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:
:Enabled:KTF MUSIC AoD Server”
“C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe”=“C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe::Enabled:KTF MUSIC VoD Server"
“C:\Program Files\AVG\AVG9\avgupd.exe”="C:\Program Files\AVG\AVG9\avgupd.exe:
:Enabled:avgupd.exe”
“C:\Program Files\AVG\AVG9\avgnsx.exe”=“C:\Program Files\AVG\AVG9\avgnsx.exe::Enabled:avgnsx.exe"
“C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe”="C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe:
:Disabled:Client”
“C:\Program Files\TrackMania Sunrise Extreme Demo\TmSunriseExtremeDemo.exe”=“C:\Program Files\TrackMania Sunrise Extreme Demo\TmSunriseExtremeDemo.exe::Disabled:TmSunriseExtremeDemo"
“C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe”="C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe:
:Disabled:TmNationsESWC”
“C:\Program Files\TmNationsForever\TmForever.exe”=“C:\Program Files\TmNationsForever\TmForever.exe::Disabled:TmForever"
“C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe”="C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe:
:Enabled:Hellgate : London”
“C:\Program Files\Skype\Phone\Skype.exe”="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 3 months======

2010-08-02 12:02:22 ----D---- C:\Program Files\trend micro
2010-08-02 12:02:17 ----D---- C:\rsit
2010-08-02 11:55:06 ----SHD---- C:\Config.Msi
2010-08-02 11:53:22 ----HDC---- C:\WINDOWS$NtUninstallKB975561$
2010-08-02 11:52:41 ----HDC---- C:\WINDOWS$NtUninstallKB925720$
2010-08-02 11:50:48 ----HDC---- C:\WINDOWS$NtUninstallKB975025$
2010-08-02 11:50:33 ----HDC---- C:\WINDOWS$NtUninstallKB974571$
2010-08-02 11:50:13 ----HDC---- C:\WINDOWS$NtUninstallKB975560$
2010-08-02 11:49:46 ----HDC---- C:\WINDOWS$NtUninstallKB977816$
2010-08-02 11:49:23 ----HDC---- C:\WINDOWS$NtUninstallKB973687$
2010-08-02 11:48:36 ----HDC---- C:\WINDOWS$NtUninstallKB981793$
2010-08-02 11:48:28 ----HDC---- C:\WINDOWS$NtUninstallKB978601$
2010-08-02 11:48:11 ----HDC---- C:\WINDOWS$NtUninstallKB979559$
2010-08-02 11:47:18 ----HDC---- C:\WINDOWS$NtUninstallKB973904$
2010-08-02 11:46:56 ----HDC---- C:\WINDOWS$NtUninstallKB974392$
2010-08-02 11:46:03 ----HDC---- C:\WINDOWS$NtUninstallKB971737$
2010-08-02 11:45:39 ----HDC---- C:\WINDOWS$NtUninstallKB977914$
2010-08-02 11:43:49 ----HDC---- C:\WINDOWS$NtUninstallKB978542$
2010-08-02 11:43:36 ----HDC---- C:\WINDOWS$NtUninstallKB979309$
2010-08-02 11:43:23 ----HDC---- C:\WINDOWS$NtUninstallKB978695_WM9$
2010-08-02 11:43:14 ----HDC---- C:\WINDOWS$NtUninstallKB979482$
2010-08-02 11:43:03 ----HDC---- C:\WINDOWS$NtUninstallKB978706$
2010-08-02 11:42:34 ----HDC---- C:\WINDOWS$NtUninstallKB975562$
2010-08-02 11:10:38 ----HDC---- C:\WINDOWS$NtUninstallKB975467$
2010-08-02 10:12:34 ----A---- C:\WINDOWS\system32\SET7E6.tmp
2010-08-02 10:10:23 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-08-02 09:33:33 ----D---- C:\WINDOWS\LastGood
2010-08-01 22:24:43 ----D---- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2010-08-01 22:24:33 ----D---- C:\Program Files\Security Task Manager
2010-07-24 18:20:35 ----D---- C:\Program Files\THQ
2010-07-21 13:10:37 ----D---- C:\Program Files\Acro Software
2010-07-18 12:04:39 ----A---- C:\Program Files\Readme.txt
2010-07-18 12:04:39 ----A---- C:\Program Files\EULA.txt
2010-07-16 22:59:44 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2010-07-16 22:59:43 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2010-07-16 22:59:41 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-07-16 22:59:40 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-07-16 22:59:39 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2010-07-16 22:59:36 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2010-07-16 22:59:35 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-07-16 22:59:33 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-07-16 22:59:33 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-07-16 22:59:32 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-07-16 22:59:30 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2010-07-16 22:59:30 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-07-16 22:59:29 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2010-07-16 22:59:28 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-07-16 22:59:27 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2010-07-16 22:59:27 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-07-16 22:59:25 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2010-07-16 22:59:23 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2010-07-16 22:59:23 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-07-16 22:59:22 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2010-07-16 22:59:22 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-07-16 22:59:20 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2010-07-16 22:59:20 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-07-16 22:59:19 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2010-07-16 22:59:17 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-07-16 22:59:17 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-07-16 22:59:16 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-07-16 22:59:14 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2010-07-16 22:59:14 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-07-16 22:59:13 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2010-07-16 22:59:13 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-07-16 22:59:11 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-07-16 22:59:11 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-07-16 22:59:10 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-07-16 22:56:11 ----D---- C:\WINDOWS\Logs
2010-07-16 12:57:08 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-07-14 19:09:17 ----D---- C:\Program Files\Flagship Studios
2010-07-12 21:51:20 ----D---- C:\Program Files\Activision
2010-07-07 19:14:51 ----D---- C:\Program Files\Sierra
2010-07-04 19:16:36 ----N---- C:\WINDOWS\Setup1.exe
2010-07-04 19:16:33 ----A---- C:\WINDOWS\ST6UNST.EXE
2010-07-03 14:05:47 ----A---- C:\resetlog.txt
2010-06-28 10:27:27 ----D---- C:\Program Files\Microsoft
2010-05-14 17:05:49 ----D---- C:\Program Files\Notepad++
2010-05-14 17:05:49 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\Notepad++
2010-05-13 11:32:22 ----D---- C:\Program Files\XRECODE
2010-05-08 18:50:22 ----D---- C:\Program Files\StarCraft
2010-05-08 18:50:22 ----D---- C:\Program Files\Fichiers communs\Blizzard Entertainment
2010-05-06 15:26:07 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\XnView
2010-05-06 15:24:09 ----D---- C:\Program Files\XnView
2010-05-04 19:17:47 ----A---- C:\WINDOWS\system32\SET2F4.tmp
2010-05-04 19:17:47 ----A---- C:\WINDOWS\system32\SET2F3.tmp
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\SET2FB.tmp
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\SET2F6.tmp
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\SET2F5.tmp
2010-05-04 19:17:45 ----A---- C:\WINDOWS\system32\SET2FC.tmp
2010-05-04 19:17:44 ----A---- C:\WINDOWS\system32\SET2FE.tmp
2010-05-04 19:17:44 ----A---- C:\WINDOWS\system32\SET2FD.tmp
2010-05-04 19:17:43 ----A---- C:\WINDOWS\system32\SET302.tmp
2010-05-04 19:17:42 ----A---- C:\WINDOWS\system32\SET306.tmp
2010-05-04 19:17:41 ----A---- C:\WINDOWS\system32\SET308.tmp
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\SET311.tmp
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\SET30D.tmp

======List of files/folders modified in the last 3 months======

2010-08-02 12:03:28 ----RSD---- C:\WINDOWS\assembly
2010-08-02 12:02:27 ----SHD---- C:\WINDOWS\Installer
2010-08-02 12:02:22 ----RD---- C:\Program Files
2010-08-02 12:02:17 ----D---- C:\WINDOWS\system32
2010-08-02 12:02:11 ----D---- C:\WINDOWS
2010-08-02 12:02:09 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-02 11:58:00 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-02 11:57:15 ----D---- C:\WINDOWS\WinSxS
2010-08-02 11:53:38 ----HD---- C:\WINDOWS\inf
2010-08-02 11:53:27 ----D---- C:\WINDOWS\system32\dllcache
2010-08-02 11:53:27 ----D---- C:\Program Files\Movie Maker
2010-08-02 11:53:19 ----HD---- C:\WINDOWS$hf_mig$
2010-08-02 11:52:57 ----A---- C:\WINDOWS\imsins.BAK
2010-08-02 11:52:43 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-02 11:43:52 ----D---- C:\Program Files\Outlook Express
2010-08-02 11:43:20 ----A---- C:\WINDOWS\iis6.BAK
2010-08-02 11:42:01 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-02 11:37:18 ----D---- C:\WINDOWS\Temp
2010-08-02 11:16:40 ----D---- C:\WINDOWS\system32\fr-fr
2010-08-02 11:16:40 ----D---- C:\Program Files\Internet Explorer
2010-08-02 10:23:25 ----D---- C:\WINDOWS\Prefetch
2010-08-02 09:57:06 ----D---- C:\WINDOWS\system32\CatRoot_bak
2010-08-02 09:20:37 ----D---- C:\WINDOWS\system32\drivers\Avg
2010-08-01 16:43:10 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\Skype
2010-08-01 16:40:41 ----A---- C:\WINDOWS\ModemLog_Conexant HDA D110 MDC V.92 Modem.txt
2010-07-30 18:37:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-24 18:41:08 ----D---- C:\WINDOWS\system32\DirectX
2010-07-24 18:20:32 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-21 13:10:49 ----D---- C:\WINDOWS\system32\FxsTmp
2010-07-16 22:41:24 ----D---- C:\Program Files\EA GAMES
2010-07-16 22:16:58 ----A---- C:\WINDOWS\system32\CmdLineExt03.dll
2010-07-16 12:58:24 ----D---- C:\WINDOWS\system32\drivers
2010-07-12 17:24:13 ----D---- C:\WINDOWS\Help
2010-07-02 20:13:53 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\U3
2010-06-28 10:31:45 ----D---- C:\Program Files\SPlayer
2010-06-27 22:45:17 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\dvdcss
2010-06-27 22:24:01 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\vlc
2010-06-25 09:03:49 ----D---- C:\Program Files\CAPCOM
2010-06-21 17:47:23 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2010-06-21 17:47:22 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2010-06-13 20:33:29 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2010-06-13 20:33:28 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-13 20:32:57 ----D---- C:\WINDOWS\system32\AGEIA
2010-06-04 18:36:41 ----RSD---- C:\WINDOWS\Fonts
2010-05-08 19:10:51 ----D---- C:\Program Files\Fichiers communs
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\pngfilt.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\occache.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\mstime.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\msrating.dll
2010-05-04 19:17:43 ----A---- C:\WINDOWS\system32\jsproxy.dll
2010-05-04 19:17:42 ----A---- C:\WINDOWS\system32\iernonce.dll
2010-05-04 19:17:42 ----A---- C:\WINDOWS\system32\iepeers.dll
2010-05-04 19:17:41 ----A---- C:\WINDOWS\system32\ieencode.dll
2010-05-04 19:17:41 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\ieaksie.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\ieakeng.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\extmgr.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\dxtrans.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\corpol.dll
2010-05-04 18:46:36 ----D---- C:\Program Files\Ground Control II
2010-05-04 14:39:27 ----A---- C:\WINDOWS\system32\ieudinit.exe
2010-05-04 14:39:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 DRVMCDB;DRVMCDB; C:\WINDOWS\System32\Drivers\DRVMCDB.SYS [2005-09-12 89264]
R0 PBADRV;PBADRV; C:\WINDOWS\system32\drivers\pbadrv.sys [2005-12-09 18816]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2003-10-10 62720]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-01-26 20576]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2006-03-01 51200]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\WINDOWS\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS\System32\drivers\sfsync04.sys [2005-12-12 49664]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-06-19 721904]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-07-16 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-07-03 29584]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-07-16 243024]
R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25 5628]
R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25 22684]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-05 40320]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-07-08 214024]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\system32\DRIVERS\omci.sys [2004-02-13 17153]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2003-10-10 52128]
R1 Tcpip6;Pilote du protocole IPv6 Microsoft; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-06-20 225920]
R2 ACEDRV08;ACEDRV08; ??\C:\WINDOWS\system32\drivers\ACEDRV08.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.9.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-09-14 21275]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-04-19 278984]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08 25628]
R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2005-09-08 2496]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08 86524]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2005-09-08 14684]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08 6364]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08 87036]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08 94332]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12 40544]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-08-24 25416]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
R2 s24trans;Transport RLAN; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-12-28 13568]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2005-09-29 113847]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2005-11-10 142720]
R3 FsUsbExDisk;FsUsbExDisk; ??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-08-12 137728]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys [2005-12-01 936960]
R3 HSXHWAZL;HSXHWAZL; C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys [2005-12-01 192512]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-12-14 1364574]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-11-29 35088]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-11-29 36368]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-03-25 1156648]
R3 tunmp;Pilote de carte miniport Tun Microsoft; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2004-08-05 12416]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 USBCCID;USB Smart Card reader; C:\WINDOWS\system32\DRIVERS\usbccid.sys [2005-05-13 28672]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 w39n51;Intel® PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys [2005-12-05 1428096]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys [2005-12-01 669696]
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
S3 E100B;Pilote de carte Intel ® PRO; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-23 117760]
S3 gAGP440p;gAGP440p; ??\C:\DOCUME~1\LUCMEF~1\LOCALS~1\Temp\gAGP440p.sys []
S3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2009-07-08 79816]
S3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2009-07-08 35272]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2009-07-08 34248]
S3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2009-07-08 40552]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 sony_ssm.sys;sony_ssm.sys; ??\C:\DOCUME~1\LUCMEF~1\LOCALS~1\Temp\sony_ssm.sys []
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 usbprint;Classe d’imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Filtre de bus AGP Intel; C:\WINDOWS\system32\DRIVERS\agp440.sys [2004-08-04 42368]
S4 agpCPQ;Filtre de bus AGP Compaq; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-04 44928]
S4 alim1541;Filtre de bus AGP ALI; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2004-08-04 42752]
S4 amdagp;Pilote de filtre du bus AMD AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2004-08-04 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 sisagp;Filtre de bus AGP SIS; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2004-08-04 41088]
S4 viaagp;Filtre de bus AGP VIA; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-04 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Service d’application d’assistance IPv6; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-07-16 308136]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-12 44032]
R2 DataSvr2;DataSvr2; C:\Program Files\Wave Systems Corp\Common\DataServer.exe [2006-05-15 315392]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe [2003-12-05 73728]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-12-28 114753]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MSSQL$MICROSOFTSMLBIZ;MSSQL$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe [2009-01-03 9158656]
R2 NICCONFIGSVC;NICCONFIGSVC; C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [2006-06-29 376832]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-12-28 217164]
R2 S24EventMonitor;Intel® PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-12-28 540745]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2009-05-02 225280]
R2 WLANKEEPER;Intel® PROSet/Wireless SSO Service; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [2005-12-28 262217]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2006-10-30 492608]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-05 268800]
S2 tcsd_win32.exe;NTRU Hybrid TSS v2.0.25 TCS; C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe [2008-01-09 121360]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2005-05-03 73728]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 SQLAgent$MICROSOFTSMLBIZ;SQLAgent$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE [2005-05-03 323584]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Et voici info.txt:

info.txt logfile of random’s system information tool 1.08 2010-08-02 12:03:49

======Uninstall list======

–>“C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe” /remove /l0x040c
–>“C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe” /remove /l0x040c
–>“C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe” /remove /l0x040c
–>“C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe” /remove /l0x040c
–>“C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe” /remove /l0x040c
–>“C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe” /remove /l0x040c
–>C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
–>C:\WINDOWS\system32\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
–>C:\WINDOWS\system32\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
–>C:\WINDOWS\system32\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
–>C:\WINDOWS\system32\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
–>MsiExec /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe” -l0x40c /remove
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe” -l0x40c /remove
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{7C9F6AF4-E9D9-47FE-BE4B-E637C2FCB410}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{7C9F6AF4-E9D9-47FE-BE4B-E637C2FCB410}\setup.exe” -l0x40c /remove
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe” -l0x40c /remove
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe” -l0x40c /remove
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe” -l0x40c
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe” -l0x40c /remove
–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe” -l0x40c
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7-Zip 4.65–>“C:\Program Files\7-Zip\Uninstall.exe”
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.0.5 Language Support–>MsiExec.exe /I{AC76BA86-7AD7-5464-3428-7050000000A7}
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe® Photoshop® Album Starter Edition 3.0–>MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
AGEIA PhysX v7.11.13–>MsiExec.exe /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
Aliens vs. Predator 2 Tools–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{47D511E4-CF3F-45D4-90A0-B02E086A889C}\Setup.exe”
ALPS Touch Pad Driver–>C:\Program Files\Apoint\Uninstap.exe ADDREMOVE
Apple Software Update–>MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
AVG Free 9.0–>C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
Broadcom Advanced Control Suite–>MsiExec.exe /X{26E1BFB0-E87E-4696-9F89-B467F01F81E5}
Broadcom TPM Driver Installer–>MsiExec.exe /X{35748B06-FCFC-4700-8285-DAD41689E4FE}
Canon iP4600 series Printer Driver–>“C:\WINDOWS\system32\CanonIJ Uninstaller Information{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4600_series\DelDrv.exe” /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4600_series /L0x000c
Canon Utilities Easy-PhotoPrint EX–>C:\Program Files\Canon\Easy-PhotoPrint EX\uninst.exe uninst.ini
Canon Utilities My Printer–>C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
Canon Utilities Solution Menu–>C:\Program Files\Canon\SolutionMenu\uninst.exe uninst.ini
CDDRV_Installer–>MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
CD-LabelPrint–>“C:\Program Files\Canon\CD-LabelPrint\Uninstal.exe” Canon.CDLabelPrint.Application
Command & Conquer Generals–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{06F80017-8F98-4C94-B868-52358569FC32}
Command and Conquer™ Generals - Heure H–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}
Conexant HDA D110 MDC V.92 Modem–>C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3\HXFSETUP.EXE -U -Idel1028p.inf
Correctif Lecteur Windows Media 10 - KB895316–>“C:\WINDOWS$NtUninstallKB895316$\spuninst\spuninst.exe”
Correctif pour Lecteur Windows Media 11 (KB939683)–>“C:\WINDOWS$NtUninstallKB939683$\spuninst\spuninst.exe”
Correctif pour Windows Internet Explorer 7 (KB947864)–>“C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe”
Correctif pour Windows XP (KB914440)–>“C:\WINDOWS$NtUninstallKB914440$\spuninst\spuninst.exe”
Correctif pour Windows XP (KB952287)–>“C:\WINDOWS$NtUninstallKB952287$\spuninst\spuninst.exe”
Correctif pour Windows XP (KB970653-v3)–>“C:\WINDOWS$NtUninstallKB970653-v3$\spuninst\spuninst.exe”
Correctif pour Windows XP (KB981793)–>“C:\WINDOWS$NtUninstallKB981793$\spuninst\spuninst.exe”
Correctif Windows XP - KB885836–>C:\WINDOWS$NtUninstallKB885836$\spuninst\spuninst.exe
Correctif Windows XP - KB886185–>C:\WINDOWS$NtUninstallKB886185$\spuninst\spuninst.exe
Correctif Windows XP - KB888302–>C:\WINDOWS$NtUninstallKB888302$\spuninst\spuninst.exe
Correctif Windows XP - KB890859–>“C:\WINDOWS$NtUninstallKB890859$\spuninst\spuninst.exe”
Creative MediaSource 5–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE” -l0x40c /remove
Creative System Information–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe” -l0x40c /remove
Creative ZEN V Series (R2)–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{9862E0CB-4727-4FFC-963A-E22A9E9EC10C}\SETUP.EXE” -l0x40c /remove
Dawn of War - Soulstorm–>“C:\Program Files\InstallShield Installation Information{20533183-D42D-4261-A125-956736FBEA8C}\setup.exe” -runfromtemp -l0x040c -removeonly
Dell Embassy Trust Suite by Wave Systems–>C:\WINDOWS\Downloaded Installations{ABBA2EA4-740E-4052-902B-9CA70B081E3F}\Installer.exe
Document Manager Lite–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2} /l1036
EMBASSY Security Center–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EEAFE1E5-076B-430A-96D9-B567792AFA88}
Encounter 2000–>“C:\Program Files\Encounter2000\unins000.exe”
Enregistrement utilisateur de Canon iP4600 series–>C:\Program Files\Canon\IJEREG\iP4600 series\UNINST.EXE
EPSON Logiciel imprimante–>C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
erLT–>MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
ETS Launch Pad–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{DD41AC25-61B2-4FC9-90AA-672F32139AC3} /l1036
ETS Upgrade–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{72FECEA1-E87F-4192-89FA-D0FBF92885BB}
Gestionnaire de disques amovible Creative–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe” -l0x40c /remove
Google Desktop–>C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Earth–>MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Ground Control II–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{21C41BAF-6F62-469D-A43B-DDF01628346E}\setup.exe” -l0x40c
GTA2–>RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}\Setup.exe” -l0x9
Guide bourrages ALC1100–>C:\Program Files\EPSON\TPMANUAL\ALC1100\PDF\DOCUNINS.EXE
Guide de référence ALC1100–>C:\Program Files\EPSON\TPMANUAL\ALC1100\REF_G\DOCUNINS.EXE
Hellgate : London–>MsiExec.exe /X{A2B4455D-1046-4732-BFBC-0821BEFC07BC}
High Definition Audio Driver Package - KB835221–>C:\WINDOWS$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2–>“C:\Documents and Settings\Luc MEFFRE\Mes documents\Downloads\HijackThis.exe” /uninstall
Homeworld 2 - Relic Developer’s Network–>C:\Program Files\Relic Developer’s Network\uninstall.exe
Homeworld2–>C:\Program Files\Sierra\Homeworld2\uninstall.exe
Hotfix 2050 for SQL Server 2000 FRA (KB948110)–>“C:\WINDOWS$SQLUninstallSQL2000-KB948110-v8.00.2050-x86-FRA$\spuninst\spuninst.exe”
Hotfix 2055 for SQL Server 2000 FRA (KB960082)–>“C:\WINDOWS$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-FRA$\spuninst\spuninst.exe”
Hotfix for Windows Media Format 11 SDK (KB929399)–>“C:\WINDOWS$NtUninstallKB929399$\spuninst\spuninst.exe”
Hotfix for Windows XP (KB915865)–>“C:\WINDOWS$NtUninstallKB915865$\spuninst\spuninst.exe”
Hotfix for Windows XP (KB926239)–>“C:\WINDOWS$NtUninstallKB926239$\spuninst\spuninst.exe”
HW2 RDN Tools Update–>“C:\Program Files\Relic Developer’s Network\unins000.exe”
IL-2 Sturmovik 1946–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{79438F1E-DEC3-443D-9DCD-FECE2D68C605} /l1036
Intel® Graphics Media Accelerator Driver–>RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_27A6 PCI\VEN_8086&DEV_27A2
iTunes–>MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
J2SE Runtime Environment 5.0 Update 11–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 6–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java™ 6 Update 2–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
KhalInstallWrapper–>MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
KONICA MINOLTA PageScope Box Operator 3.1.05000–>MsiExec.exe /I{2F892D3E-3F96-4518-B715-F8D5A6E256DF}
La Bataille pour la Terre du Milieu™–>C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu™\EAUninstall.exe
Lecteur Windows Media 11–>“C:\Program Files\Windows Media Player\Setup_wm.exe” /Uninstall
Librairies de VB6–>“C:\Program Files\Librairies de VB6\unins000.exe”
Logiciel Intel® PROSet/Wireless–>C:\WINDOWS\Installer\iProInst.exe
LUMIX Simple Viewer–>C:\Program Files\InstallShield Installation Information{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}\setup.exe -runfromtemp -l0x040c -removeonly
mHlpDell–>MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}
Microsoft .NET Framework 1.1 French Language Pack–>MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>“C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe” “C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp”
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2–>MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2–>MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1–>C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft Compression Client Pack 1.0 for Windows XP–>“C:\WINDOWS$NtUninstallMSCompPackV1$\spuninst\spuninst.exe”
Microsoft Games for Windows - LIVE Redistributable–>MsiExec.exe /X{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}
Microsoft Internationalized Domain Names Mitigation APIs–>“C:\WINDOWS$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe”
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5–>“C:\WINDOWS$NtUninstallWdf01005$\spuninst\spuninst.exe”
Microsoft National Language Support Downlevel APIs–>“C:\WINDOWS$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe”
Microsoft Office Outlook 2003 avec Gestionnaire de contacts professionnels (Mise à jour)–>MsiExec.exe /I{BA68600E-96D9-4E92-80F2-26B9681B5A67}
Microsoft Office Small Business Edition 2003–>MsiExec.exe /I{91CA040C-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight–>MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Small Basic v0.8–>MsiExec.exe /I{7AAA27E4-CDB3-49C0-AA2D-41827C001BA3}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>“C:\WINDOWS$NtUninstallWudf01000$\spuninst\spuninst.exe”
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053–>MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148–>MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17–>MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Mise à jour critique pour Lecteur Windows Media 11 (KB959772)–>“C:\WINDOWS$NtUninstallKB959772_WM11$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)–>“C:\WINDOWS$NtUninstallKB952069_WM9$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Lecteur Windows Media (KB968816)–>“C:\WINDOWS$NtUninstallKB968816_WM9$\spuninst\spuninst.exe”
Mise à jour de sécurité pour Lecteur Windows Media (KB973540)–>"C:\WINDOWS$NtUninstallKB973540_WM9L$\spun

Re,

Rien de probant non plus:

Désinstalle Adobe Acrobat reader par Ajout/suppr des programmes du panneau de configuration … c’est une usine à gaz pour lire les fichier PDF. Remplace le par Foxit Reader , plus léger et plus sécurisé

Passe Ccleaner en mode registre ==> recherche les erreurs ==> corrige les erreurs ==> Accepte la sauvegarde du registre ==> fais plusieurs passes

Refuse de la barre Yahoo à l’installation :wink:

Passe Ccleaner en mode nettoyeur

Télécharge, mets à jour Malwarebytes Anti-Malware que tu trouveras ici (pour les intimes il se nomme MBAM), mets le à jour

va dans l’onglet “Recherche”, coche “Exécuter un examen complet” puis “Rechercher

Sélectionnes tes disques durs puis clique sur “Lancer l’examen

A la fin du scan, clique sur Afficher les résultats , sélectionne tous les éléments trouvés puis
cliques sur Supprimer la sélection==>Important à faire

S’il t’ es demandé de redémarrer, clique sur "oui "

Fais Démarrer ==> Exécuter ==> tape: msconfig ==> ouvre l’onglet “Démarrage” ==> décoche toutes les case sauf ton antivirus, ton touch pad si tu es sur un portable ==> appliquer et ok ==> au redémarrage de la machine clique sur ’ Ne plus me prévenir …"

Tu commences à manquer de place sur ton disque il serait bon de faire le tri dans tes logiciels … désinstalle ceux que tu n’utilises plus par ajout/supp des programmes du panneau de configuration.

Passe Ccleaner en mode registre ==> recherches les erreurs ==> corrige les erreurs ==> accepte la sauvegarde du registre ==> fais plusieurs passe

dans ta prochaine réponse poste le rapport de MBAM et 2 nouveaux rapports RSIT
Edité le 02/08/2010 à 14:17

Très bien, je vais faire tout ça. Juste, rien ne risque d’entrer en conflit avec mon antivirus actuel? (AVG 9.0 Free Edition).
Et, si possible, pourrais-tu m’expliquer tout cela? Pourquoi décocher des cases dans l’onglet “Démarrage”? Pourquoi ma machine va m’annoncer quelque chose? En quoi tout cela est-il nécessaire?
Merci beaucoup pour toute ton aide jusqu’ici, mais je voudrais vraiment quelques détails supplémentaires (j’ai horreur de faire des manipulations de cette importance, alors j’aime autant me renseigner).:smiley:

Re,

aucun soucis de conflit avec ton antivirus.

Au démarrage de l’ordi tu as une multitude de log qui se lance, donc perte de temps + chargement de log en mémoire , que tu n’utiliseras certainement pas lors de la session ==> donc on passe par msconfig pour que ces log ne se lancent plus au démarrage de la machine, ce qui provoque gain de temps au démarrage + soulagement de la machine + rapidité d’ exécution.
Au redémarrage, Windows va te prévenir que tu as choisis un “démarrage sélectif” , c’est pour cela que je te demande de cocher la case " Ne plus me prévenir …" sinon à chaque démarrage cette fenêtre va s’ouvrir, ce qui est pénible à la longue :wink:

Aucun soucis pour tes logiciels … ils seront juste un peu plus long à s’ouvrir … mais ta machine sans portera que mieux vu que tu n’as que 1GO de mémoire … c’est déjà bien mais tout juste nécessaire pour faire tourner les log nouveaux, donc autant de pas charger la machine.

J’espère avoir répondu à tes questions … si tu en as d’autres je t’écoute :wink:

J’ai téléchargé Foxit Reader. Jusque là, aucun problème, ça semble être un bon logiciel mais je verrai plus tard.
Je passe CCcleaner en mode “Registre”. Il trouve des milliers de “problèmes”, dont plein d’extensions non utilisées, mais j’en reconnais qui appartiennent à mes jeux! Que fera-t-il si je clique sur “corriger les erreurs”?
Edité le 02/08/2010 à 15:18

Re,

il ne fera que supprimer les erreurs … aucuns soucis pour tes jeux :wink:

et de toute manière si tu fais la sauvegarde du registre comme je te l’ai demandé si soucis on pourra revenir en arrière :wink:

Mais sache que j’utilise ce log depuis sa sortie sur mon ordi ou autre et aucun problème à ce jour
Edité le 02/08/2010 à 15:54

OK. J’ai fait cinq passes. Au final, il ne trouve plus aucun problème. Je m’apprête à le passer en mode “Nettoyeur”. Pourquoi certaines options ne sont-elles pas cochées?
Edité le 02/08/2010 à 15:56

Re,

elle ne sont pas d’une grande utilité voire dans certain cas trop invasive … le réglage par défaut et largement suffisant

mais si tu veux en savoir plus vois ici: jesses.pagesperso-orange.fr…

D’accord, merci. Analyse en cours. Cela dure longtemps, non?


Analyse terminée: dans "détails des fichiers à supprimer", il met mon antivirus (Utilitaires-AVG Antivirus 9.0)! Et Applications-Office 2003 et Office 2007! Qu'est-ce que cela veut dire? Edité le 02/08/2010 à 16:33

Re,

ce sont des reste de fichiers temporaire de mise à jour :wink:

Merci. Jusqu’ici, tout va bien. CCleaner a bien fait son boulot, et le scan de Malwarebytes est en cours. Résultats dans ma prochaine réponse.

Analyse terminée. Je passe CCleaner. 3 passes. Une erreur trouvée à propos de Malwarebytes, rien de grave, corrigée. Puis rien d’autre.

Voici le rapport de Malwarebytes:

Malwarebytes’ Anti-Malware 1.46

Version de la base de données: 4381

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

02/08/2010 18:19:56
mbam-log-2010-08-02 (18-19-56).txt

Type d’examen: Examen complet (C:|)
Elément(s) analysé(s): 219088
Temps écoulé: 1 heure(s), 19 minute(s), 56 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Documents and Settings\Luc MEFFRE\Local Settings\Temp\SystemRequirementsLabx.exe (Spyware.Zbot) -> Quarantined and deleted successfully.

Et voici le log.txt de rsit (c’est le seul qui soit apparu après le scan, pas d’info.txt).

Logfile of random’s system information tool 1.08 (written by random/random)
Run by Luc MEFFRE at 2010-08-02 18:45:03
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 26 GB (34%) free of 76 GB
Total RAM: 1014 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:45:06, on 02/08/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Luc MEFFRE\Bureau\Nouveau dossier (3)\RSIT.exe
C:\Program Files\trend micro\Luc MEFFRE.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=0060914
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = fr.search.yahoo.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM…\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM…\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM…\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM…\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe”
O4 - HKLM…\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM…\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM…\Run: [DVDLauncher] “C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe”
O4 - HKLM…\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM…\Run: [IntelZeroConfig] “C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe”
O4 - HKLM…\Run: [IntelWireless] “C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” /tf Intel PROSet/Wireless
O4 - HKLM…\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM…\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM…\Run: [ISUSScheduler] “C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe” -start
O4 - HKLM…\Run: [Google Desktop Search] “C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup
O4 - HKLM…\Run: [Adobe Photo Downloader] “C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKLM…\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM…\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM…\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM…\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU…\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [CTSyncU.exe] “C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe”
O4 - HKCU…\Run: [Skype] “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized
O4 - HKCU…\Run: [Google Update] “C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe” /c
O4 - HKCU…\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SERVICE LOCAL’)
O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SERVICE RÉSEAU’)
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EMBASSY Trust Suite Secure Update.lnk = C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE…
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - picasaweb.google.fr…
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com…
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: wxvault.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Common\DataServer.exe
O23 - Service: Service d’administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d’aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe (file missing)
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe


End of file - 14570 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3825869345-3750952953-1186466244-1006Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3825869345-3750952953-1186466244-1006UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-09-13 1312040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-21 1619296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 110652]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1119488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\BAE\BAE.dll [2006-08-30 94208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1119488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“Apoint”=C:\Program Files\Apoint\Apoint.exe [2005-10-07 176128]
“igfxtray”=C:\WINDOWS\system32\igfxtray.exe [2005-12-14 98304]
“igfxhkcmd”=C:\WINDOWS\system32\hkcmd.exe [2005-12-14 77824]
“igfxpers”=C:\WINDOWS\system32\igfxpers.exe [2005-12-14 118784]
“SunJavaUpdateSched”=C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]
“SigmatelSysTrayApp”=C:\WINDOWS\stsystra.exe [2006-03-25 282624]
“Document Manager”=C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe [2006-05-16 102400]
“DVDLauncher”=C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [2005-12-09 49152]
“Dell QuickSet”=C:\Program Files\Dell\QuickSet\quickset.exe [2006-06-29 1032192]
“IntelZeroConfig”=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2005-12-28 667718]
“IntelWireless”=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2005-12-28 602182]
“DLA”=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]
“ISUSPM Startup”=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe [2005-02-16 221184]
“ISUSScheduler”=C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
“Google Desktop Search”=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2006-09-14 169984]
“Adobe Photo Downloader”=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-06 57344]
“QuickTime Task”=C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]
“iTunesHelper”=C:\Program Files\iTunes\iTunesHelper.exe [2006-10-30 256576]
“CanonSolutionMenu”=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2008-03-11 689488]
“CanonMyPrinter”=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2008-03-18 1848648]
“Kernel and Hardware Abstraction Layer”=C:\WINDOWS\KHALMNPR.EXE [2007-11-29 55824]
“NPSStartup”= []
“AVG9_TRAY”=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-07-16 2065760]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“ModemOnHold”=C:\Program Files\NetWaiting\netWaiting.exe [2003-09-10 20480]
“MSMSGS”=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
“ctfmon.exe”=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
“CTSyncU.exe”=C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe [2006-08-07 700416]
“Skype”=C:\Program Files\Skype\Phone\Skype.exe [2007-09-13 22880040]
“Google Update”=C:\Documents and Settings\Luc MEFFRE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-03 133104]
“AutoStartNPSAgent”=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
EMBASSY Trust Suite Secure Update.lnk - C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
EPSON Status Monitor 3 Environment Check(2).lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
“AppInit_DLLs”=“wxvault.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-07-16 12536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-12-14 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll [2008-01-09 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
“authentication packages”=msv1_0
wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“HonorAutoRunSetting”=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“C:\Program Files\Messenger\msmsgs.exe”="C:\Program Files\Messenger\msmsgs.exe:
:Enabled:Windows Messenger"
“C:\WINDOWS\system32\usmt\migwiz.exe”=“C:\WINDOWS\system32\usmt\migwiz.exe::Enabled:Assistant Transfert de fichiers et de paramètres"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000”
“C:\Program Files\iTunes\iTunes.exe”=“C:\Program Files\iTunes\iTunes.exe::Enabled:iTunes"
“C:\Games\Descent3\main.exe”="C:\Games\Descent3\main.exe:
:Disabled:main”
“C:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\game.dat”=“C:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\game.dat::Enabled:La Bataille pour la Terre du Milieu ™ II"
“C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu™\game.dat”="C:\Program Files\EA GAMES\La Bataille pour la Terre du Milieu™\game.dat:
:Enabled:La Bataille pour la Terre du Milieu™”
“C:\Program Files\Electronic Arts\L’Avènement du Roi-sorcier\game.dat”=“C:\Program Files\Electronic Arts\L’Avènement du Roi-sorcier\game.dat::Enabled:LSDA, L’Avènement du Roi-sorcier™"
“C:\WINDOWS\explorer.exe”="C:\WINDOWS\explorer.exe:
:Enabled:Explorateur Windows”
“C:\Program Files\Cyanide\Loki\Loki.exe”=“C:\Program Files\Cyanide\Loki\Loki.exe::Enabled:Loki"
“C:\Program Files\Cyanide\Loki\Autorun\Autorun.exe”="C:\Program Files\Cyanide\Loki\Autorun\Autorun.exe:
:Enabled:Loki - AutoRun”
“C:\Documents and Settings\Luc MEFFRE\Bureau\Félix\Universe at War-Earth Assault\UAWEA.exe”=“C:\Documents and Settings\Luc MEFFRE\Bureau\Félix\Universe at War-Earth Assault\UAWEA.exe::Disabled:Universe at War: Earth Assault Application"
“C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe”="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:
:Enabled:KTF MUSIC AoD Server”
“C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe”=“C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe::Enabled:KTF MUSIC VoD Server"
“C:\Program Files\AVG\AVG9\avgupd.exe”="C:\Program Files\AVG\AVG9\avgupd.exe:
:Enabled:avgupd.exe”
“C:\Program Files\AVG\AVG9\avgnsx.exe”=“C:\Program Files\AVG\AVG9\avgnsx.exe::Enabled:avgnsx.exe"
“C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe”="C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe:
:Disabled:Client”
“C:\Program Files\TrackMania Sunrise Extreme Demo\TmSunriseExtremeDemo.exe”=“C:\Program Files\TrackMania Sunrise Extreme Demo\TmSunriseExtremeDemo.exe::Disabled:TmSunriseExtremeDemo"
“C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe”="C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe:
:Disabled:TmNationsESWC”
“C:\Program Files\TmNationsForever\TmForever.exe”=“C:\Program Files\TmNationsForever\TmForever.exe::Disabled:TmForever"
“C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe”="C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe:
:Enabled:Hellgate : London”
“C:\Program Files\Skype\Phone\Skype.exe”="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe:
:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 3 months======

2010-08-02 18:26:28 ----D---- C:\WINDOWS\pss
2010-08-02 16:54:11 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\Malwarebytes
2010-08-02 16:53:52 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-08-02 16:53:51 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-08-02 16:53:49 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2010-08-02 16:53:48 ----D---- C:\Program Files\Malwarebytes’ Anti-Malware
2010-08-02 15:12:57 ----D---- C:\Program Files\CCleaner
2010-08-02 15:07:46 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\Foxit Software
2010-08-02 15:06:03 ----D---- C:\Program Files\Foxit Software
2010-08-02 13:50:57 ----HDC---- C:\WINDOWS$NtUninstallKB980232$
2010-08-02 13:50:38 ----HDC---- C:\WINDOWS$NtUninstallKB980218$
2010-08-02 13:50:21 ----HDC---- C:\WINDOWS$NtUninstallKB979683$
2010-08-02 13:50:01 ----HDC---- C:\WINDOWS$NtUninstallKB979559$
2010-08-02 13:49:48 ----HDC---- C:\WINDOWS$NtUninstallKB979482$
2010-08-02 13:49:38 ----HDC---- C:\WINDOWS$NtUninstallKB979309$
2010-08-02 13:49:24 ----HDC---- C:\WINDOWS$NtUninstallKB978706$
2010-08-02 13:49:13 ----HDC---- C:\WINDOWS$NtUninstallKB978601$
2010-08-02 13:48:58 ----HDC---- C:\WINDOWS$NtUninstallKB978542$
2010-08-02 13:48:47 ----HDC---- C:\WINDOWS$NtUninstallKB978338$
2010-08-02 13:48:33 ----HDC---- C:\WINDOWS$NtUninstallKB978037$
2010-08-02 13:48:21 ----HDC---- C:\WINDOWS$NtUninstallKB977914$
2010-08-02 13:48:04 ----HDC---- C:\WINDOWS$NtUninstallKB975713$
2010-08-02 13:47:52 ----HDC---- C:\WINDOWS$NtUninstallKB975562$
2010-08-02 13:47:39 ----HDC---- C:\WINDOWS$NtUninstallKB975561$
2010-08-02 13:47:29 ----HDC---- C:\WINDOWS$NtUninstallKB975560$
2010-08-02 13:47:16 ----HDC---- C:\WINDOWS$NtUninstallKB975467$
2010-08-02 13:47:05 ----HDC---- C:\WINDOWS$NtUninstallKB975025$
2010-08-02 13:46:53 ----HDC---- C:\WINDOWS$NtUninstallKB974571$
2010-08-02 13:46:41 ----HDC---- C:\WINDOWS$NtUninstallKB974392$
2010-08-02 13:46:29 ----HDC---- C:\WINDOWS$NtUninstallKB974318$
2010-08-02 13:46:17 ----HDC---- C:\WINDOWS$NtUninstallKB974112$
2010-08-02 13:46:05 ----HDC---- C:\WINDOWS$NtUninstallKB973869$
2010-08-02 13:45:55 ----HDC---- C:\WINDOWS$NtUninstallKB973815$
2010-08-02 13:45:41 ----HDC---- C:\WINDOWS$NtUninstallKB973687$
2010-08-02 13:45:31 ----HDC---- C:\WINDOWS$NtUninstallKB973507$
2010-08-02 13:45:19 ----HDC---- C:\WINDOWS$NtUninstallKB973354$
2010-08-02 13:45:06 ----HDC---- C:\WINDOWS$NtUninstallKB972270$
2010-08-02 13:44:52 ----HDC---- C:\WINDOWS$NtUninstallKB971737$
2010-08-02 13:44:40 ----HDC---- C:\WINDOWS$NtUninstallKB971657$
2010-08-02 13:44:27 ----HDC---- C:\WINDOWS$NtUninstallKB971633$
2010-08-02 13:44:16 ----HDC---- C:\WINDOWS$NtUninstallKB971557$
2010-08-02 13:44:05 ----HDC---- C:\WINDOWS$NtUninstallKB971468$
2010-08-02 13:43:49 ----HDC---- C:\WINDOWS$NtUninstallKB970430$
2010-08-02 13:43:39 ----HDC---- C:\WINDOWS$NtUninstallKB970238$
2010-08-02 13:43:25 ----HDC---- C:\WINDOWS$NtUninstallKB969059$
2010-08-02 13:43:14 ----HDC---- C:\WINDOWS$NtUninstallKB968537$
2010-08-02 13:42:55 ----HDC---- C:\WINDOWS$NtUninstallKB968389$
2010-08-02 13:42:36 ----HDC---- C:\WINDOWS$NtUninstallKB967715$
2010-08-02 13:42:24 ----HDC---- C:\WINDOWS$NtUninstallKB961501$
2010-08-02 13:42:11 ----HDC---- C:\WINDOWS$NtUninstallKB961373$
2010-08-02 13:42:02 ----HDC---- C:\WINDOWS$NtUninstallKB961371$
2010-08-02 13:41:35 ----HDC---- C:\WINDOWS$NtUninstallKB961118$
2010-08-02 13:41:26 ----HDC---- C:\WINDOWS$NtUninstallKB960859$
2010-08-02 13:41:15 ----HDC---- C:\WINDOWS$NtUninstallKB960803$
2010-08-02 13:41:05 ----HDC---- C:\WINDOWS$NtUninstallKB960225$
2010-08-02 13:40:50 ----HDC---- C:\WINDOWS$NtUninstallKB959426$
2010-08-02 13:40:39 ----HDC---- C:\WINDOWS$NtUninstallKB958690$
2010-08-02 13:40:27 ----HDC---- C:\WINDOWS$NtUninstallKB958687$
2010-08-02 13:40:17 ----HDC---- C:\WINDOWS$NtUninstallKB958644$
2010-08-02 13:40:07 ----HDC---- C:\WINDOWS$NtUninstallKB957097$
2010-08-02 13:39:58 ----HDC---- C:\WINDOWS$NtUninstallKB957095$
2010-08-02 13:39:48 ----HDC---- C:\WINDOWS$NtUninstallKB956844$
2010-08-02 13:39:39 ----HDC---- C:\WINDOWS$NtUninstallKB956841$
2010-08-02 13:39:23 ----HDC---- C:\WINDOWS$NtUninstallKB956803$
2010-08-02 13:39:14 ----HDC---- C:\WINDOWS$NtUninstallKB956802$
2010-08-02 13:38:46 ----HDC---- C:\WINDOWS$NtUninstallKB956572$
2010-08-02 13:38:24 ----HDC---- C:\WINDOWS$NtUninstallKB955759$
2010-08-02 13:38:10 ----HDC---- C:\WINDOWS$NtUninstallKB973687_1$
2010-08-02 13:38:01 ----HDC---- C:\WINDOWS$NtUninstallKB955069$
2010-08-02 13:37:50 ----HDC---- C:\WINDOWS$NtUninstallKB974112_1$
2010-08-02 13:37:41 ----HDC---- C:\WINDOWS$NtUninstallKB954600$
2010-08-02 13:37:30 ----HDC---- C:\WINDOWS$NtUninstallKB954211$
2010-08-02 13:37:18 ----HDC---- C:\WINDOWS$NtUninstallKB952954$
2010-08-02 13:37:06 ----HDC---- C:\WINDOWS$NtUninstallKB952287$
2010-08-02 13:36:51 ----HDC---- C:\WINDOWS$NtUninstallKB952004$
2010-08-02 13:36:40 ----HDC---- C:\WINDOWS$NtUninstallKB951748$
2010-08-02 13:36:29 ----HDC---- C:\WINDOWS$NtUninstallKB951698$
2010-08-02 13:36:18 ----HDC---- C:\WINDOWS$NtUninstallKB951376-v2$
2010-08-02 13:36:08 ----HDC---- C:\WINDOWS$NtUninstallKB951376$
2010-08-02 13:35:56 ----HDC---- C:\WINDOWS$NtUninstallKB951066$
2010-08-02 13:35:48 ----HDC---- C:\WINDOWS$NtUninstallKB950974$
2010-08-02 13:35:38 ----HDC---- C:\WINDOWS$NtUninstallKB950762$
2010-08-02 13:35:27 ----HDC---- C:\WINDOWS$NtUninstallKB946648$
2010-08-02 13:35:18 ----HDC---- C:\WINDOWS$NtUninstallKB938464$
2010-08-02 13:35:05 ----HDC---- C:\WINDOWS$NtUninstallKB923561$
2010-08-02 13:34:52 ----HDC---- C:\WINDOWS$NtUninstallKB2229593$
2010-08-02 13:26:24 ----D---- C:\WINDOWS\l2schemas
2010-08-02 13:26:22 ----D---- C:\WINDOWS\system32\fr
2010-08-02 13:26:22 ----D---- C:\WINDOWS\system32\bits
2010-08-02 13:02:04 ----HDC---- C:\WINDOWS$NtServicePackUninstall$
2010-08-02 12:37:41 ----HDC---- C:\WINDOWS$NtUninstallKB980218_0$
2010-08-02 12:26:01 ----HDC---- C:\WINDOWS$NtUninstallKB971468_0$
2010-08-02 12:25:20 ----HDC---- C:\WINDOWS$NtUninstallKB979683_0$
2010-08-02 12:24:13 ----HDC---- C:\WINDOWS$NtUninstallKB958869$
2010-08-02 12:21:45 ----HDC---- C:\WINDOWS$NtUninstallKB954155_WM9$
2010-08-02 12:21:34 ----HDC---- C:\WINDOWS$NtUninstallKB980195$
2010-08-02 12:21:21 ----HDC---- C:\WINDOWS$NtUninstallKB970430_0$
2010-08-02 12:20:33 ----HDC---- C:\WINDOWS$NtUninstallKB980232_0$
2010-08-02 12:17:17 ----HDC---- C:\WINDOWS$NtUninstallKB955759_0$
2010-08-02 12:17:03 ----HDC---- C:\WINDOWS$NtUninstallKB974318_0$
2010-08-02 12:16:25 ----HDC---- C:\WINDOWS$NtUninstallKB969059_0$
2010-08-02 12:16:00 ----HDC---- C:\WINDOWS$NtUninstallKB981349$
2010-08-02 12:13:19 ----HDC---- C:\WINDOWS$NtUninstallKB2229593_0$
2010-08-02 12:12:55 ----HDC---- C:\WINDOWS$NtUninstallKB978037_0$
2010-08-02 12:12:09 ----HDC---- C:\WINDOWS$NtUninstallKB975713_0$
2010-08-02 12:11:53 ----HDC---- C:\WINDOWS$NtUninstallKB978338_0$
2010-08-02 12:11:18 ----HDC---- C:\WINDOWS$NtUninstallKB961118_0$
2010-08-02 12:10:55 ----HDC---- C:\WINDOWS$NtUninstallKB972270_0$
2010-08-02 12:05:52 ----HDC---- C:\WINDOWS$NtUninstallKB974112_0$
2010-08-02 12:02:22 ----D---- C:\Program Files\trend micro
2010-08-02 12:02:17 ----D---- C:\rsit
2010-08-02 11:53:22 ----HDC---- C:\WINDOWS$NtUninstallKB975561_0$
2010-08-02 11:52:41 ----HDC---- C:\WINDOWS$NtUninstallKB925720$
2010-08-02 11:50:48 ----HDC---- C:\WINDOWS$NtUninstallKB975025_0$
2010-08-02 11:50:33 ----HDC---- C:\WINDOWS$NtUninstallKB974571_0$
2010-08-02 11:50:13 ----HDC---- C:\WINDOWS$NtUninstallKB975560_0$
2010-08-02 11:49:46 ----HDC---- C:\WINDOWS$NtUninstallKB977816$
2010-08-02 11:49:23 ----HDC---- C:\WINDOWS$NtUninstallKB973687_0$
2010-08-02 11:48:36 ----HDC---- C:\WINDOWS$NtUninstallKB981793$
2010-08-02 11:48:28 ----HDC---- C:\WINDOWS$NtUninstallKB978601_0$
2010-08-02 11:48:11 ----HDC---- C:\WINDOWS$NtUninstallKB979559_0$
2010-08-02 11:47:18 ----HDC---- C:\WINDOWS$NtUninstallKB973904$
2010-08-02 11:46:56 ----HDC---- C:\WINDOWS$NtUninstallKB974392_0$
2010-08-02 11:46:03 ----HDC---- C:\WINDOWS$NtUninstallKB971737_0$
2010-08-02 11:45:39 ----HDC---- C:\WINDOWS$NtUninstallKB977914_0$
2010-08-02 11:43:49 ----HDC---- C:\WINDOWS$NtUninstallKB978542_0$
2010-08-02 11:43:36 ----HDC---- C:\WINDOWS$NtUninstallKB979309_0$
2010-08-02 11:43:23 ----HDC---- C:\WINDOWS$NtUninstallKB978695_WM9$
2010-08-02 11:43:14 ----HDC---- C:\WINDOWS$NtUninstallKB979482_0$
2010-08-02 11:43:03 ----HDC---- C:\WINDOWS$NtUninstallKB978706_0$
2010-08-02 11:42:34 ----HDC---- C:\WINDOWS$NtUninstallKB975562_0$
2010-08-02 11:10:38 ----HDC---- C:\WINDOWS$NtUninstallKB975467_0$
2010-08-02 10:10:23 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-08-01 22:24:43 ----D---- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2010-07-24 18:20:35 ----D---- C:\Program Files\THQ
2010-07-21 13:10:37 ----D---- C:\Program Files\Acro Software
2010-07-18 12:04:39 ----A---- C:\Program Files\Readme.txt
2010-07-18 12:04:39 ----A---- C:\Program Files\EULA.txt
2010-07-16 22:59:44 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2010-07-16 22:59:43 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2010-07-16 22:59:41 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-07-16 22:59:40 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-07-16 22:59:39 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2010-07-16 22:59:36 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2010-07-16 22:59:35 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-07-16 22:59:33 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-07-16 22:59:33 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-07-16 22:59:32 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-07-16 22:59:30 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2010-07-16 22:59:30 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-07-16 22:59:29 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2010-07-16 22:59:28 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-07-16 22:59:27 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2010-07-16 22:59:27 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-07-16 22:59:25 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2010-07-16 22:59:23 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2010-07-16 22:59:23 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-07-16 22:59:22 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2010-07-16 22:59:22 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-07-16 22:59:20 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2010-07-16 22:59:20 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-07-16 22:59:19 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2010-07-16 22:59:17 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-07-16 22:59:17 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-07-16 22:59:16 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-07-16 22:59:14 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2010-07-16 22:59:14 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-07-16 22:59:13 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2010-07-16 22:59:13 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-07-16 22:59:11 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-07-16 22:59:11 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-07-16 22:59:10 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-07-16 22:56:11 ----D---- C:\WINDOWS\Logs
2010-07-16 12:57:08 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2010-07-14 19:09:17 ----D---- C:\Program Files\Flagship Studios
2010-07-12 21:51:20 ----D---- C:\Program Files\Activision
2010-07-07 19:14:51 ----D---- C:\Program Files\Sierra
2010-07-04 19:16:36 ----N---- C:\WINDOWS\Setup1.exe
2010-07-04 19:16:33 ----A---- C:\WINDOWS\ST6UNST.EXE
2010-07-03 14:05:47 ----A---- C:\resetlog.txt
2010-06-28 10:27:27 ----D---- C:\Program Files\Microsoft
2010-05-14 17:05:49 ----D---- C:\Program Files\Notepad++
2010-05-14 17:05:49 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\Notepad++
2010-05-13 11:32:22 ----D---- C:\Program Files\XRECODE
2010-05-08 18:50:22 ----D---- C:\Program Files\StarCraft
2010-05-08 18:50:22 ----D---- C:\Program Files\Fichiers communs\Blizzard Entertainment
2010-05-06 15:26:07 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\XnView
2010-05-06 15:24:09 ----D---- C:\Program Files\XnView

======List of files/folders modified in the last 3 months======

2010-08-02 18:40:10 ----SHD---- C:\WINDOWS\Installer
2010-08-02 18:40:10 ----D---- C:\WINDOWS
2010-08-02 18:40:10 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2010-08-02 18:39:43 ----D---- C:\WINDOWS\system32
2010-08-02 18:31:57 ----D---- C:\WINDOWS\Prefetch
2010-08-02 18:24:36 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\Skype
2010-08-02 18:22:51 ----D---- C:\WINDOWS\Temp
2010-08-02 18:22:38 ----A---- C:\WINDOWS\ModemLog_Conexant HDA D110 MDC V.92 Modem.txt
2010-08-02 18:21:19 ----D---- C:\WINDOWS\system32\drivers
2010-08-02 18:20:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-02 16:53:48 ----RD---- C:\Program Files
2010-08-02 16:47:11 ----D---- C:\WINDOWS\Debug
2010-08-02 16:47:08 ----D---- C:\WINDOWS\Minidump
2010-08-02 15:03:47 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2010-08-02 14:56:40 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-08-02 14:55:45 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-02 14:00:39 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-02 13:58:01 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-02 13:56:53 ----D---- C:\WINDOWS\AppPatch
2010-08-02 13:56:52 ----D---- C:\WINDOWS\system32\Setup
2010-08-02 13:56:51 ----D---- C:\WINDOWS\system32\wbem
2010-08-02 13:56:49 ----RSD---- C:\WINDOWS\Fonts
2010-08-02 13:55:44 ----D---- C:\WINDOWS\security
2010-08-02 13:51:12 ----HD---- C:\WINDOWS\inf
2010-08-02 13:51:04 ----D---- C:\WINDOWS\system32\dllcache
2010-08-02 13:51:04 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-02 13:49:06 ----D---- C:\Program Files\Outlook Express
2010-08-02 13:47:44 ----D---- C:\Program Files\Movie Maker
2010-08-02 13:35:30 ----D---- C:\Program Files\Messenger
2010-08-02 13:27:19 ----D---- C:\WINDOWS\WinSxS
2010-08-02 13:27:03 ----D---- C:\WINDOWS\ehome
2010-08-02 13:27:00 ----D---- C:\WINDOWS\system32\inetsrv
2010-08-02 13:27:00 ----D---- C:\WINDOWS\network diagnostic
2010-08-02 13:27:00 ----D---- C:\WINDOWS\Help
2010-08-02 13:26:59 ----D---- C:\WINDOWS\ime
2010-08-02 13:26:30 ----D---- C:\WINDOWS\system32\fr-fr
2010-08-02 13:26:28 ----D---- C:\WINDOWS\system32\usmt
2010-08-02 13:26:22 ----D---- C:\WINDOWS\PeerNet
2010-08-02 13:26:11 ----RSD---- C:\WINDOWS\assembly
2010-08-02 13:19:57 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-02 13:16:51 ----D---- C:\WINDOWS\ServicePackFiles
2010-08-02 13:16:33 ----D---- C:\WINDOWS\system32\Restore
2010-08-02 13:16:32 ----D---- C:\WINDOWS\system32\npp
2010-08-02 13:16:30 ----D---- C:\WINDOWS\msagent
2010-08-02 13:16:28 ----D---- C:\WINDOWS\srchasst
2010-08-02 13:16:27 ----D---- C:\Program Files\NetMeeting
2010-08-02 13:16:25 ----D---- C:\WINDOWS\system32\Com
2010-08-02 13:16:21 ----D---- C:\Program Files\Windows Media Player
2010-08-02 13:16:20 ----D---- C:\Program Files\Windows NT
2010-08-02 13:16:14 ----D---- C:\Program Files\Fichiers communs\System
2010-08-02 13:15:49 ----D---- C:\WINDOWS\system32\oobe
2010-08-02 13:15:45 ----D---- C:\WINDOWS\system
2010-08-02 13:09:00 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-08-02 12:41:58 ----D---- C:\Program Files\Microsoft Silverlight
2010-08-02 12:25:59 ----HD---- C:\WINDOWS$hf_mig$
2010-08-02 12:23:22 ----A---- C:\WINDOWS\win.ini
2010-08-02 11:16:40 ----D---- C:\Program Files\Internet Explorer
2010-08-02 11:16:09 ----D---- C:\WINDOWS\ie7updates
2010-08-02 09:20:37 ----D---- C:\WINDOWS\system32\drivers\Avg
2010-07-24 18:41:08 ----D---- C:\WINDOWS\system32\DirectX
2010-07-21 13:10:49 ----D---- C:\WINDOWS\system32\FxsTmp
2010-07-16 22:41:24 ----D---- C:\Program Files\EA GAMES
2010-07-16 22:16:58 ----A---- C:\WINDOWS\system32\CmdLineExt03.dll
2010-07-02 20:13:53 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\U3
2010-07-02 12:39:06 ----A---- C:\WINDOWS\system32\MRT.exe
2010-06-28 10:31:45 ----D---- C:\Program Files\SPlayer
2010-06-27 22:45:17 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\dvdcss
2010-06-27 22:24:01 ----D---- C:\Documents and Settings\Luc MEFFRE\Application Data\vlc
2010-06-25 09:03:49 ----D---- C:\Program Files\CAPCOM
2010-06-21 17:47:23 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2010-06-21 17:47:22 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2010-06-13 20:33:28 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-08 19:10:51 ----D---- C:\Program Files\Fichiers communs
2010-05-04 19:17:47 ----A---- C:\WINDOWS\system32\wininet.dll
2010-05-04 19:17:47 ----A---- C:\WINDOWS\system32\webcheck.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\urlmon.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\url.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\pngfilt.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\occache.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\mstime.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\msrating.dll
2010-05-04 19:17:46 ----A---- C:\WINDOWS\system32\mshtmled.dll
2010-05-04 19:17:45 ----A---- C:\WINDOWS\system32\mshtml.dll
2010-05-04 19:17:44 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2010-05-04 19:17:44 ----A---- C:\WINDOWS\system32\msfeeds.dll
2010-05-04 19:17:43 ----A---- C:\WINDOWS\system32\jsproxy.dll
2010-05-04 19:17:43 ----A---- C:\WINDOWS\system32\iertutil.dll
2010-05-04 19:17:42 ----A---- C:\WINDOWS\system32\iernonce.dll
2010-05-04 19:17:42 ----A---- C:\WINDOWS\system32\iepeers.dll
2010-05-04 19:17:42 ----A---- C:\WINDOWS\system32\ieframe.dll
2010-05-04 19:17:41 ----A---- C:\WINDOWS\system32\ieencode.dll
2010-05-04 19:17:41 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2010-05-04 19:17:41 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\ieaksie.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\ieakeng.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\icardie.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\extmgr.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\dxtrans.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\corpol.dll
2010-05-04 19:17:40 ----A---- C:\WINDOWS\system32\advpack.dll
2010-05-04 18:46:36 ----D---- C:\Program Files\Ground Control II
2010-05-04 14:39:27 ----A---- C:\WINDOWS\system32\ieudinit.exe
2010-05-04 14:39:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 DRVMCDB;DRVMCDB; C:\WINDOWS\System32\Drivers\DRVMCDB.SYS [2005-09-12 89264]
R0 PBADRV;PBADRV; C:\WINDOWS\system32\drivers\pbadrv.sys [2005-12-09 18816]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2003-10-10 62720]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-01-26 20576]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2006-03-01 51200]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\WINDOWS\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS\System32\drivers\sfsync04.sys [2005-12-12 49664]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-06-19 721904]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-07-16 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-07-03 29584]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-07-16 243024]
R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25 5628]
R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25 22684]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-07-08 214024]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\system32\DRIVERS\omci.sys [2004-02-13 17153]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2003-10-10 52128]
R1 Tcpip6;Pilote du protocole IPv6 Microsoft; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 ACEDRV08;ACEDRV08; ??\C:\WINDOWS\system32\drivers\ACEDRV08.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.9.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-09-14 21275]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-04-19 278984]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08 25628]
R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2005-09-08 2496]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08 86524]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2005-09-08 14684]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08 6364]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08 87036]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08 94332]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12 40544]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-08-24 25416]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
R2 s24trans;Transport RLAN; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-12-28 13568]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2005-09-29 113847]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2005-11-10 142720]
R3 FsUsbExDisk;FsUsbExDisk; ??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys [2005-12-01 936960]
R3 HSXHWAZL;HSXHWAZL; C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys [2005-12-01 192512]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-12-14 1364574]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-11-29 35088]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-11-29 36368]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-03-25 1156648]
R3 tunmp;Pilote de carte miniport Tun Microsoft; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 USBCCID;USB Smart Card reader; C:\WINDOWS\system32\DRIVERS\usbccid.sys [2005-05-13 28672]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w39n51;Intel® PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys [2005-12-05 1428096]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys [2005-12-01 669696]
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
S3 E100B;Pilote de carte Intel ® PRO; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-23 117760]
S3 gAGP440p;gAGP440p; ??\C:\DOCUME~1\LUCMEF~1\LOCALS~1\Temp\gAGP440p.sys []
S3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2009-07-08 79816]
S3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2009-07-08 35272]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2009-07-08 34248]
S3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2009-07-08 40552]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 sony_ssm.sys;sony_ssm.sys; ??\C:\DOCUME~1\LUCMEF~1\LOCALS~1\Temp\sony_ssm.sys []
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 usbprint;Classe d’imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Filtre de bus AGP Intel; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Filtre de bus AGP Compaq; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;Filtre de bus AGP ALI; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;Pilote de filtre du bus AMD AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 sisagp;Filtre de bus AGP SIS; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;Filtre de bus AGP VIA; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Service d’application d’assistance IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-07-16 308136]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-12 44032]
R2 DataSvr2;DataSvr2; C:\Program Files\Wave Systems Corp\Common\DataServer.exe [2006-05-15 315392]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe [2003-12-05 73728]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-12-28 114753]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MSSQL$MICROSOFTSMLBIZ;MSSQL$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe [2009-01-03 9158656]
R2 NICCONFIGSVC;NICCONFIGSVC; C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [2006-06-29 376832]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-12-28 217164]
R2 S24EventMonitor;Intel® PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-12-28 540745]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2009-05-02 225280]
R2 WLANKEEPER;Intel® PROSet/Wireless SSO Service; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [2005-12-28 262217]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2006-10-30 492608]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
S2 tcsd_win32.exe;NTRU Hybrid TSS v2.0.25 TCS; C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe [2008-01-09 121360]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2005-05-03 73728]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 SQLAgent$MICROSOFTSMLBIZ;SQLAgent$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE [2005-05-03 323584]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Alors? Quel est le verdict?
Edité le 02/08/2010 à 18:48

Re,

bon si tu installes le SP3 pendant que l’on fait la désinfection on va pas s’en sortir … merci de ne rien installer sur l’ordi pendant la procédure :wink:

tu n’as pas virer grand chose au démarrage de ton ordi, il reste:
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
C:\Program Files\QuickTime\qttask.exe" -atboottime
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\stsystra.exe [2006-03-25 282624]
C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

je regarde tes rapports demain

Je ne sais pas ce que je dois virer, j’ai toujours peur de faire une erreur. Pourrais-tu me conseiller?
Je suis navré pour SP3, comme j’ai laissé mon PC connecté longtemps, je l’ai laissé faire ses mises à jour (cela devenait nécessaire, la dernière devait dater de plusieurs années).
D’accord pour que tu regardes mes rapports demain (naturellement), tu m’as déjà beaucoup aidé aujourd’hui.

A demain alors, en espérant un progrès.:slight_smile:
Edité le 02/08/2010 à 19:37

:hello:

tu peux décocher toutes les lignes commençant par:

C:\Program Files
puis
C:\WINDOWS\system32\ctfmon.exe

et de toute manière si un log te manque au démarrage tu pourras le recocher :wink:

Clique [ici](http://www.genproc.com/GenProc.exe) pour télécharger [b]GenProc[/b] sur le bureau


=> lance le et laisse le travailler
=> Enregistre le rapport sur le bureau et poste le ici s'il te plait

Ton lien est brisé. J’ai fait des recherches rapides, pas moyen de trouver ce logiciel. Cela dit, est-ce indispensable? Mon PC n’est-il pas nettoyé? Après, qu’il rame un peu, ce n’est pas si grave, tout ce qui m’inquiétait, c’était qu’il soit infecté.
Ne peut-on en rester là ou n’est-ce pas encore terminé?
Par ailleurs, si tu m’accordes encore un peu de temps, j’aurais quelques simples questions à te poser.:smiley:

Re,

excuse pour le lien va ici: www.tayo.fr…

fait ensuite une défragmentation: Démarrer ==> Accessoires ==> outils système ==> défragmentation

Selon la taille et le bordel dans les fichier cela peut-être long voire trés long

pas de soucis pour tes questions :wink:

Très bien, merci. Si cela n’est pas trop gênant, je préfère éviter Genproc (pour diverses raisons plus ou moins difficiles à expliquer :D).
En revanche, je vais lancer la défragmentation.
Mes questions: -Foxit Reader, il ne permet pas la création de fichiers PDF depuis Word? Il demande de télécharger quelque chose, mais ça ne me rassure pas (j’ai déjà eu des déboires à ce sujet avec cutepdf). Est-ce vraiment fiable? Ou bien existe-t-il un autre logiciel (gratuit) pour cela (“Word to PDF Converter”?). Un peu hors-sujet, mais comme tu m’as présenté Foxit…
-Malwarebytes fournit-il aussi une protection permanente?
-CCleaner n’est qu’un utilitaire de nettoyage?
-Pourrais-tu m’indiquer un site ou autre chose qui me permette de comprendre tout ces logs que tu m’as fait faire?
Merci d’avance.:slight_smile:
Edité le 03/08/2010 à 11:21