salut cricri58
voilà le log :
Logfile of random’s system information tool 1.06 (written by random/random)
Run by Compaq_Propriétaire at 2009-10-29 14:52:40
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 54 GB (37%) free of 146 GB
Total RAM: 1534 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:52:45, on 29/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdeserv.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\lxdecoms.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Lexmark 4800 Series\lxdemon.exe
C:\Program Files\Lexmark 4800 Series\lxdeamon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\OrangeHSS\Launcher\Launcher.exe
C:\Program Files\DNA\btdna.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\1\AlertModule.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OrangeHSS\systray\systrayapp.exe
C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\1\FTCOMModule.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\cyril\roms nes\01men\RSIT(2).exe
C:\Program Files\trend micro\Compaq_Propriétaire.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = fr.msn.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O2 - BHO: Lexmark Barre d’outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d’aide de l’Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMin1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Lexmark Barre d’outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMin1.dll
O4 - HKLM…\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM…\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM…\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM…\Run: [InstantAccess] C:\Program Files\ScannerU\TBRIDGE\BIN\InstantAccess.EXE /h
O4 - HKLM…\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM…\Run: [ZoneAlarm Client] “C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”
O4 - HKLM…\Run: [lxdemon.exe] “C:\Program Files\Lexmark 4800 Series\lxdemon.exe”
O4 - HKLM…\Run: [lxdeamon] “C:\Program Files\Lexmark 4800 Series\lxdeamon.exe”
O4 - HKLM…\Run: [Reminder] “C:\Windows\Creator\Remind_XP.exe”
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [ORAHSSSessionManager] “C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe”
O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
O4 - HKLM…\Run: [Adobe ARM] “C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe”
O4 - HKLM…\Run: [Malwarebytes Anti-Malware (reboot)] “C:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe” /runcleanupscript
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe”
O4 - HKCU…\Run: [msnmsgr] “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background
O4 - HKCU…\Run: [swg] “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”
O4 - HKCU…\Run: [BitTorrent DNA] “C:\Program Files\DNA\btdna.exe”
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra ‘Tools’ menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator2_8_2\Ghost (file missing)
O9 - Extra ‘Tools’ menuitem: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator2_8_2\Ghost (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: .mappy.com…
O15 - Trusted Zone: .orange.fr…
O15 - Trusted Zone: rw.search.ke.voila.fr…
O15 - Trusted Zone: orange.weborama.fr…
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - gfx1.hotmail.com…
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com…
O16 - DPF: {BFB5F154-9212-46F3-B547-AC6106030A54} - cyrilt.carrefourinternet.com…
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxdeCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdeserv.exe
O23 - Service: lxde_device - - C:\WINDOWS\system32\lxdecoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
–
End of file - 9453 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{1017A80C-6F09-4548-A84D-EDD6AC9525F0}]
Lexmark Barre d’outils - C:\Program Files\Lexmark Toolbar\toolband.dll [2009-05-06 372736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d’aide de l’Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-22 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-09-22 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-09-22 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
Mininova-Vuze Toolbar - C:\Program Files\Mininova-Vuze\tbMin1.dll [2009-09-22 2215960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-31 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-07-31 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1017A80C-6F09-4548-A84D-EDD6AC9525F0} - Lexmark Barre d’outils - C:\Program Files\Lexmark Toolbar\toolband.dll [2009-05-06 372736]
{d51d388b-f5dc-471a-a1ce-5e2d671091c0} - Mininova-Vuze Toolbar - C:\Program Files\Mininova-Vuze\tbMin1.dll [2009-09-22 2215960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“AlcxMonitor”=C:\WINDOWS\ALCXMNTR.EXE [2004-09-07 57344]
“LSBWatcher”=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2005-05-11 253952]
“avast!”=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
“InstantAccess”=C:\Program Files\ScannerU\TBRIDGE\BIN\InstantAccess.EXE [1998-07-07 37376]
“ArcSoft Connection Service”=C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe [2007-10-11 31232]
“ZoneAlarm Client”=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2008-07-09 919016]
“lxdemon.exe”=C:\Program Files\Lexmark 4800 Series\lxdemon.exe [2007-06-11 455600]
“lxdeamon”=C:\Program Files\Lexmark 4800 Series\lxdeamon.exe [2007-06-01 20480]
“Reminder”=C:\Windows\Creator\Remind_XP.exe [2004-12-14 663552]
“nwiz”=nwiz.exe /install []
“NvCplDaemon”=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
“ORAHSSSessionManager”=C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe [2008-12-01 107248]
“Adobe Reader Speed Launcher”=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
“Adobe ARM”=C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
“Malwarebytes Anti-Malware (reboot)”=C:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe [2009-09-10 1312080]
“SunJavaUpdateSched”=C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-31 149280]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“msnmsgr”=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
“swg”=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-07 39408]
“BitTorrent DNA”=C:\Program Files\DNA\btdna.exe [2009-05-29 321344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=323
“NoFavoritesMenu”=0
“NoSMMyPictures”=0
“NoStartMenuMyMusic”=0
“NoRecentDocsNetHood”=0
“NoUserNameInStartMenu”=1
“NoInstrumentation”=0
“NoStartMenuPinnedList”=0
“ForceStartMenuLogoff”=0
“NoSharedDocuments”=1
“NoDriveAutoRun”=67108863
“HonorAutoRunSetting”=1
“NoDrives”=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=
“NoFavoritesMenu”=
“NoSMMyPictures”=
“NoStartMenuMyMusic”=
“NoRecentDocsNetHood”=
“NoInstrumentation”=
“NoSimpleStartMenu”=
“HonorAutoRunSetting”=
“NoDriveAutoRun”=
“NoDrives”=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“C:\Program Files\iTunes\iTunes.exe”="C:\Program Files\iTunes\iTunes.exe::Enabled:iTunes"
“C:\Program Files\Services en ligne\wanadoo\kitwanadoo.exe”=“C:\Program Files\Services en ligne\wanadoo\kitwanadoo.exe::Enabled:Wanadoo"
“C:\Program Files\DNA\btdna.exe”="C:\Program Files\DNA\btdna.exe::Enabled:DNA”
“C:\Program Files\LimeWire\LimeWire.exe”=“C:\Program Files\LimeWire\LimeWire.exe::Enabled:LimeWire"
“C:\WINDOWS\system32\lxdecoms.exe”="C:\WINDOWS\system32\lxdecoms.exe::Enabled:Lexmark Communications System”
“C:\Program Files\Lexmark 4800 Series\lxdeamon.exe”=“C:\Program Files\Lexmark 4800 Series\lxdeamon.exe::Enabled:Lexmark Device Monitor"
“C:\Program Files\Lexmark 4800 Series\frun.exe”="C:\Program Files\Lexmark 4800 Series\frun.exe::Enabled:Lexmark Productivity Studio”
“C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe”=“C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe::Enabled:ABBYY FineReader"
“C:\Program Files\Lexmark Fax Solutions\FaxCtr.exe”="C:\Program Files\Lexmark Fax Solutions\FaxCtr.exe::Enabled:Fax software”
“C:\Program Files\Lexmark 4800 Series\lxdemon.exe”=“C:\Program Files\Lexmark 4800 Series\lxdemon.exe::Enabled:Printer Device Monitor"
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdepswx.exe”="C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdepswx.exe::Enabled:Printer Status Window Interface”
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdetime.exe”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdetime.exe::Enabled:Lexmark Connect Time Executable"
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdejswx.exe”="C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdejswx.exe::Enabled:Job Status Window Interface”
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdewbgw.exe”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdewbgw.exe::Enabled:Lexmark Web Gateway"
“C:\Program Files\Windows Live\Messenger\wlcsdk.exe”="C:\Program Files\Windows Live\Messenger\wlcsdk.exe::Enabled:Windows Live Call”
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger"
“C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe”="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe::enabled:CSS”
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%ProgramFiles%\iTunes\iTunes.exe”="%ProgramFiles%\iTunes\iTunes.exe::enabled:iTunes"
“C:\Program Files\Windows Live\Messenger\wlcsdk.exe”=“C:\Program Files\Windows Live\Messenger\wlcsdk.exe::Enabled:Windows Live Call"
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”="C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger”
======List of files/folders created in the last 1 months======
2009-10-29 12:05:24 ----A---- C:\ComboFix.txt
2009-10-29 11:42:24 ----A---- C:\WINDOWS\PEV.exe
2009-10-29 11:42:24 ----A---- C:\WINDOWS\NIRCMD.exe
2009-10-29 11:42:24 ----A---- C:\WINDOWS\MBR.exe
2009-10-29 11:42:23 ----A---- C:\WINDOWS\zip.exe
2009-10-29 11:42:23 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-10-29 11:42:23 ----A---- C:\WINDOWS\SWSC.exe
2009-10-29 11:42:23 ----A---- C:\WINDOWS\SWREG.exe
2009-10-29 11:42:23 ----A---- C:\WINDOWS\sed.exe
2009-10-29 11:42:23 ----A---- C:\WINDOWS\grep.exe
2009-10-29 11:42:09 ----D---- C:\WINDOWS\ERDNT
2009-10-29 11:41:45 ----D---- C:\Qoobox
2009-10-29 00:14:34 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-29 00:14:34 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-29 00:14:34 ----A---- C:\WINDOWS\system32\java.exe
2009-10-28 23:54:15 ----D---- C:\Program Files\CCleaner
2009-10-28 23:28:13 ----RAD---- C:\autorun.inf
2009-10-28 23:20:12 ----A---- C:\UsbFix.txt
2009-10-28 19:54:07 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\calgwpoo
2009-10-28 18:55:12 ----D---- C:\Program Files\AskBardis
2009-10-28 18:43:18 ----A---- C:\cleannavi.txt
2009-10-28 18:42:48 ----D---- C:\Program Files\Navilog1
2009-10-28 13:12:03 ----D---- C:\Program Files\Malwarebytes’ Anti-Malware
2009-10-28 11:27:37 ----D---- C:\UsbFix
2009-10-28 11:19:40 ----A---- C:\TB.txt
2009-10-28 11:19:02 ----D---- C:\ToolBar SD
2009-10-28 10:42:31 ----D---- C:\rsit
2009-10-28 10:42:31 ----D---- C:\Program Files\trend micro
2009-10-27 14:02:05 ----D---- C:\Program Files\EMCO
2009-10-26 14:31:53 ----D---- C:\Program Files\a-squared Free
2009-10-26 14:26:31 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Uniblue
2009-10-26 14:26:25 ----D---- C:\Program Files\Uniblue
2009-10-22 22:36:38 ----D---- C:\Program Files\Spyware Doctor
2009-10-22 17:19:41 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Malwarebytes
2009-10-22 17:19:32 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-10-16 12:13:37 ----HDC---- C:\WINDOWS$NtUninstallKB958869$
2009-10-16 12:13:24 ----HDC---- C:\WINDOWS$NtUninstallKB954155_WM9$
2009-10-16 12:10:59 ----HDC---- C:\WINDOWS$NtUninstallKB969059$
2009-10-16 12:10:45 ----HDC---- C:\WINDOWS$NtUninstallKB974112$
2009-10-16 12:10:31 ----HDC---- C:\WINDOWS$NtUninstallKB975025$
2009-10-16 12:09:52 ----HDC---- C:\WINDOWS$NtUninstallKB974571$
2009-10-16 12:08:14 ----HDC---- C:\WINDOWS$NtUninstallKB971486$
2009-10-16 12:07:58 ----HDC---- C:\WINDOWS$NtUninstallKB973525$
2009-10-16 12:07:40 ----HDC---- C:\WINDOWS$NtUninstallKB975467$
======List of files/folders modified in the last 1 months======
2009-10-29 14:52:45 ----D---- C:\WINDOWS\Prefetch
2009-10-29 14:51:13 ----D---- C:\WINDOWS\Internet Logs
2009-10-29 14:51:12 ----D---- C:\Program Files\Mozilla Firefox
2009-10-29 14:50:31 ----D---- C:\WINDOWS\Debug
2009-10-29 14:50:31 ----D---- C:\WINDOWS
2009-10-29 14:48:49 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\DNA
2009-10-29 13:10:03 ----D---- C:\Program Files\1st Tarot
2009-10-29 12:32:41 ----D---- C:\WINDOWS\system32
2009-10-29 12:05:29 ----D---- C:\WINDOWS\system32\drivers
2009-10-29 12:04:48 ----D---- C:\WINDOWS\Temp
2009-10-29 11:59:28 ----D---- C:\WINDOWS\system32\dllcache
2009-10-29 11:58:30 ----D---- C:\Program Files\DNA
2009-10-29 11:57:59 ----D---- C:\WINDOWS\system32\CatRoot2
2009-10-29 11:57:29 ----A---- C:\WINDOWS\system.ini
2009-10-29 11:55:09 ----D---- C:\WINDOWS\system32\config
2009-10-29 11:49:56 ----D---- C:\WINDOWS\AppPatch
2009-10-29 11:49:48 ----D---- C:\Program Files\Fichiers communs
2009-10-29 11:45:01 ----SHD---- C:\System Volume Information
2009-10-29 11:45:01 ----D---- C:\WINDOWS\system32\Restore
2009-10-29 11:42:47 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-10-29 11:24:48 ----HD---- C:\WINDOWS\inf
2009-10-29 11:24:48 ----D---- C:\WINDOWS\Help
2009-10-29 00:14:40 ----SHD---- C:\WINDOWS\Installer
2009-10-29 00:14:39 ----D---- C:\Config.Msi
2009-10-29 00:14:26 ----D---- C:\Program Files\Java
2009-10-28 23:55:50 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Azureus
2009-10-28 23:55:16 ----D---- C:\WINDOWS\Minidump
2009-10-28 23:54:15 ----D---- C:\Program Files
2009-10-28 23:28:07 ----SHD---- C:\RECYCLER
2009-10-27 16:29:11 ----D---- C:\Program Files\LimeWire
2009-10-27 16:22:32 ----D---- C:\Program Files\Vuze
2009-10-27 14:05:03 ----D---- C:\WINDOWS\WinSxS
2009-10-26 20:38:10 ----D---- C:\Program Files\Fichiers communs\Real
2009-10-26 20:37:36 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Real
2009-10-26 20:25:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-23 11:35:46 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-10-20 11:59:17 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2009-10-18 16:15:14 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-18 16:12:19 ----D---- C:\Program Files\Fichiers communs\Adobe
2009-10-18 16:11:54 ----D---- C:\Program Files\Adobe
2009-10-16 18:17:36 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-16 18:17:23 ----RSD---- C:\WINDOWS\assembly
2009-10-16 12:14:03 ----D---- C:\Program Files\Internet Explorer
2009-10-16 12:13:54 ----D---- C:\WINDOWS\ie8updates
2009-10-16 12:13:43 ----HD---- C:\WINDOWS$hf_mig$
2009-10-02 19:01:57 ----A---- C:\WINDOWS\system32\MRT.exe
2009-09-30 22:39:05 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-08-17 26944]
R1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 43008]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-08-17 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-08-17 51376]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 KLIF;KLIF; C:\WINDOWS\system32\DRIVERS\klif.sys [2007-07-19 127768]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2008-07-09 394952]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-08-17 94160]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-20 2317696]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-08-17 23152]
R3 catchme;catchme; ??\C:\sweins.com\catchme.sys []
R3 GEARAspiWDM;GEAR CDRom Filter; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2005-03-07 14408]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; ??\C:\WINDOWS\system32\PCANDIS5.SYS []
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Pilote miniport de contrôleur d’hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-05 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 usbprint;Classe d’imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S2 BulkUsb;Plustek USB Scanner; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 atapi_2;atapi_2; ??\C:\WINDOWS\system32\drivers\atapi_2.sys []
S3 CheckFSD;Antiy Labs FSD Service; ??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\7zO2E.tmp\CheckFSD.sys []
S3 CheckSSDT;Antiy Labs SSDT Service; ??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\7zO2E.tmp\SSDT.sys []
S3 CLASSPNP_2;CLASSPNP_2; ??\C:\WINDOWS\system32\drivers\CLASSPNP_2.sys []
S3 disk_2;disk_2; ??\C:\WINDOWS\system32\drivers\disk_2.sys []
S3 HookMsg;Antiy Labs MsgHook Service; ??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\7zO2E.tmp\ABaseDrv.sys []
S3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-04 607452]
S3 mbr;mbr; ??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\mbr.sys []
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; ??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 pciide_2;pciide_2; ??\C:\WINDOWS\system32\drivers\pciide_2.sys []
S3 Proc;Antiy Labs Process Service; ??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\7zO2E.tmp\Proc.sys []
S3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-07-04 26624]
S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 SANDRA;SANDRA; ??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP3\WNt500x86\Sandra.sys []
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver; C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2005-12-22 402432]
S3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-05 20480]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZDCndis5;ZDCndis5 Protocol Driver; ??\C:\WINDOWS\system32\ZDCndis5.SYS []
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys []
S4 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe [2007-10-11 51712]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-08-17 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-08-17 138680]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe [2008-12-01 65536]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-07-31 153376]
R2 lxde_device;lxde_device; C:\WINDOWS\system32\lxdecoms.exe [2007-05-29 598960]
R2 lxdeCATSCustConnectService;lxdeCATSCustConnectService; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdeserv.exe [2007-05-29 99248]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2008-07-09 75304]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-08-17 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-08-17 352920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-05 268800]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-18 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPodService;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2005-05-05 327680]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------