Merci Dédétraqué de ton aide, même les jours fériés!voici les 3 rapports:
############################## | UsbFix V6.046 |
User : JEF (Administrateurs) # PB-4YNAEK9UWABO
Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
Start at: 13:28:06 | 03/11/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Contact :
FindyKill.Contact@gmail.com
Intel(R) Celeron(R) CPU 2.40GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1356 [VPS 091102-0] 4.8.1356 [ Enabled | Updated ]
A:\ -> Lecteur de disquettes 3 ½ pouces
B:\ -> Lecteur de disquettes 3 ½ pouces # 1,39 Mo (0,23 Mo free) [PKBACK# 001] # FAT
C:\ -> Disque fixe local # 25,65 Go (10,66 Go free) # NTFS
D:\ -> Disque fixe local # 14,65 Go (10,36 Go free) [2_Vide exWin] # NTFS
E:\ -> Disque fixe local # 25,39 Go (22,07 Go free) [1_Mam] # NTFS
F:\ -> Disque fixe local # 25,65 Go (5,43 Go free) [1-SAV-Photos-Vdos] # NTFS
G:\ -> Disque fixe local # 14,65 Go (3,78 Go free) [2_ SAV] # NTFS
H:\ -> Disque fixe local # 9,03 Go (3,93 Go free) [2_PROGRAMME] # NTFS
I:\ -> Disque CD-ROM
J:\ -> Disque amovible # 979,22 Mo (972,14 Mo free) [ EDITH SES] # FAT
K:\ -> Disque amovible
L:\ -> Disque amovible
M:\ -> Disque amovible # 488,25 Mo (478,81 Mo free) [CANON_DC] # FAT
N:\ -> Disque amovible
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## | Fichiers # Dossiers infectieux |
C:\autorun.inf -> fichier appelé : "C:\b00ijwpu.exe" ( Absent ! )
Supprimé ! C:\autorun.inf
D:\autorun.inf -> fichier appelé : "D:\b00ijwpu.exe" ( Absent ! )
Supprimé ! D:\autorun.inf
E:\autorun.inf -> fichier appelé : "E:\b00ijwpu.exe" ( Absent ! )
Supprimé ! E:\autorun.inf
F:\autorun.inf -> fichier appelé : "F:\b00ijwpu.exe" ( Absent ! )
Supprimé ! F:\autorun.inf
G:\autorun.inf -> fichier appelé : "G:\b00ijwpu.exe" ( Absent ! )
Supprimé ! G:\autorun.inf
H:\autorun.inf -> fichier appelé : "H:\b00ijwpu.exe" ( Absent ! )
Supprimé ! H:\autorun.inf
J:\autorun.inf -> fichier appelé : "J:\b00ijwpu.exe" ( Absent ! )
Supprimé ! J:\autorun.inf
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
################## | Listing des fichiers présent |
[03/11/2009 13:27|--a------|3886] C:\aaw7boot.log
[20/12/2008 18:47|--a------|0] C:\AUTOEXEC.BAT
[24/04/2009 16:47|-rahs----|212] C:\boot.ini
[28/08/2001 08:00|-rahs----|4952] C:\Bootfont.bin
[20/12/2008 18:47|--a------|0] C:\CONFIG.SYS
[20/12/2008 18:47|-rahs----|0] C:\IO.SYS
[21/12/2008 11:49|--a------|3301] C:\lvcoinst.log
[20/12/2008 18:47|-rahs----|0] C:\MSDOS.SYS
[21/12/2008 11:20|-rahs----|47564] C:\NTDETECT.COM
[21/12/2008 11:20|-rahs----|251712] C:\ntldr
[?|?|?] C:\pagefile.sys
[21/12/2008 14:45|--ah-----|268] C:\sqmdata00.sqm
[21/12/2008 14:45|--ah-----|244] C:\sqmnoopt00.sqm
[03/11/2009 13:37|--a------|4049] C:\UsbFix.txt
[24/12/2008 14:52|--a------|2586214912] E:\Sauvegarde 12-08.tib
[06/12/2006 02:13|--a------|540966912] F:\ABJpb Soph 6.mpg
[06/12/2006 02:16|--ah-----|2082] F:\ABJpb Soph 6.mpg.scn
[06/12/2006 01:04|--a------|1337425920] F:\Doucy 24-12-92.mpg
[06/12/2006 01:11|--ah-----|4820] F:\Doucy 24-12-92.mpg.scn
[06/12/2006 01:39|--a------|1264648192] F:\D‚guis‚ 1.mpg
[06/12/2006 01:46|--ah-----|3502] F:\D‚guis‚ 1.mpg.scn
[06/12/2006 01:56|--a------|459669504] F:\D‚guis‚ 2 suite.mpg
[06/12/2006 01:59|--ah-----|1077] F:\D‚guis‚ 2 suite.mpg.scn
[12/10/2004 03:25|--a------|1012] G:\bookmark.htm
[28/09/2004 10:30|--a------|83256] G:\bookmark0.htm
[09/06/2004 11:06|--a------|220994] G:\carnet d'a idp.WAB
[06/08/2009 12:39|--a------|22429] J:\SES 2Šme trim.nbp
[07/08/2009 06:17|--a------|22846] J:\nouveau SES 2‚me trim .nbp
[24/10/2009 07:53|--a------|24882] J:\SES 3Šme trim.nbp
[28/10/2009 13:13|--a------|4045528] J:\malwarebytes-anti-malware_malwarebytes_anti-malware_1.41_francais_215092.exe
[01/11/2009 06:26|--a------|806921] J:\UsbFix.exe
[01/11/2009 06:50|--a------|15078] J:\UsbFix.txt
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par UsbFix.
# D:\autorun.inf -> Dossier créé par UsbFix.
# E:\autorun.inf -> Dossier créé par UsbFix.
# F:\autorun.inf -> Dossier créé par UsbFix.
# G:\autorun.inf -> Dossier créé par UsbFix.
# H:\autorun.inf -> Dossier créé par UsbFix.
# J:\autorun.inf -> Dossier créé par UsbFix.
# M:\autorun.inf -> Dossier créé par UsbFix.
################## | Suspect |
http://www.virustotal.com |
################## | Cracks / Keygens / Serials |
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports1.exe"
12/02/2004 03:40 |Size 1264330 |Crc32 5d5419e7 |Md5 81c98c1dc713e37718a2f1b13fc564cc
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports2.exe"
15/02/2004 23:11 |Size 1663739 |Crc32 889ae5d8 |Md5 8d5f823d7b010c3d7782dc200f282a49
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports3.exe"
19/03/2004 11:07 |Size 1742605 |Crc32 8abbbc15 |Md5 37fff27c2550cfaa55a57680f01fba04
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports4.exe"
23/04/2004 23:33 |Size 1853411 |Crc32 9edac369 |Md5 991352f79c855ce21497c39f73312ba0
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports5.exe"
23/06/2004 05:37 |Size 2372514 |Crc32 e5387d8a |Md5 ce97e1cad85e4cbdb5ed8f092679b0e6
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports6.exe"
29/08/2004 10:11 |Size 2509804 |Crc32 45c573c3 |Md5 a0f208c1ca47608d8be746fe535d15c2
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports7.exe"
22/10/2004 08:06 |Size 2926679 |Crc32 5666c28e |Md5 865ecf17f006918a3b0aa408b4b0ce28
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\05 Lyon yetisport\yetisports8.exe"
14/05/2005 23:06 |Size 2383633 |Crc32 4ba09ec0 |Md5 8edc792766288ceaa332ddb29b5bb8ff
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\0K ACDSee 3.0 fr\acdsee300-fr.exe"
02/05/2000 06:53 |Size 3702800 |Crc32 46b93063 |Md5 8ebf154b8b2a06a865731bd93e5cc70e
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\0K Winzip 7.0 fr\wz70fr32.exe"
25/01/1999 10:46 |Size 955065 |Crc32 c4dc7a2f |Md5 3be4d43ab5499a6fdab3ff9619c2a4e5
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\0K Winzip 7.0 fr\crack\crack.exe"
29/01/1999 12:26 |Size 9984 |Crc32 201ecd93 |Md5 dc78b017f3964e194c7e37e8562c631c
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\CloneCD\clone4.0.1.10 + keygen\damn_CloneCD3042_kg.exe"
04/07/2001 04:10 |Size 40516 |Crc32 c2189b4d |Md5 4d8b621d97f9f106d6668b57de6098aa
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\CloneCD\clone4.0.1.10 + keygen\SetupCloneCD4.0.1.10.exe"
17/07/2002 18:23 |Size 2431079 |Crc32 556365b9 |Md5 5a224568382bdfecf5d9ec797e7e5dd2
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\eMule 0.30a\eMule0.30a.exe"
28/08/2003 14:24 |Size 4006106 |Crc32 6cce4586 |Md5 7a621c86190c0080a342f4d4055cb8cb
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\GetRight\getright.exe"
04/04/2000 09:39 |Size 1885696 |Crc32 901a19cd |Md5 f8b7ed7299adb40f039609b385e8b10a
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\GetRight\gr_fr.exe"
18/04/2000 04:14 |Size 160218 |Crc32 43f0633c |Md5 cbd8a3bebe17ce912550bbcc50707839
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\GetRight\keygen.exe"
05/04/2000 14:39 |Size 109568 |Crc32 57d76f19 |Md5 146f8b1cc9be67e99e0ccc5ad10acfd2
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\GetRight\unwise.exe"
25/06/1999 04:55 |Size 149504 |Crc32 30fdd633 |Md5 443e13846997c537e8f5ed61130ab705
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\GetRight 4.2\gr_fr.exe"
18/04/2000 04:14 |Size 160218 |Crc32 43f0633c |Md5 cbd8a3bebe17ce912550bbcc50707839
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\maj Windows M‚dia Player 9\wmp7.exe"
15/07/2000 12:58 |Size 9593488 |Crc32 b35b48cf |Md5 c1be453eb79163699ae621b26ceaa731
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\MPEG Scissors\MPEGScis.exe"
01/11/1999 12:55 |Size 532480 |Crc32 8c80fe66 |Md5 b48c1b8ff80aeba2280005cab5afd54a
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\MPEG Scissors\unins000.exe"
06/10/1999 02:20 |Size 49664 |Crc32 4a8da439 |Md5 16924c232af1f513612959d1f7546310
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Drivers_ Util_Virus\Utilitaires+cracks\OK TZ Connection Booster\tzcb26.exe"
17/05/2004 01:27 |Size 578497 |Crc32 545c0343 |Md5 12c3fd43a6e072a3ee9739a6eee8819e
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Clone CD 4.0\clone4.0.1.10 + keygen\damn_CloneCD3042_kg.exe"
04/07/2001 04:10 |Size 40516 |Crc32 c2189b4d |Md5 4d8b621d97f9f106d6668b57de6098aa
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Clone CD 4.0\clone4.0.1.10 + keygen\SetupCloneCD4.0.1.10.exe"
17/07/2002 18:23 |Size 2431079 |Crc32 556365b9 |Md5 5a224568382bdfecf5d9ec797e7e5dd2
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe"
25/07/2003 19:22 |Size 7000205 |Crc32 49e85e1a |Md5 54006073bbef937a126398cda940259a
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe"
01/08/2003 06:50 |Size 6549299 |Crc32 0ff42a04 |Md5 c31891e5d9b59dd9f51539b9ec1abe23
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe"
02/08/2003 05:38 |Size 21110882 |Crc32 f4af7bf3 |Md5 9fa84bebd3b6fdc1b77a058c9fc1e907
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe"
25/07/2003 19:20 |Size 8488997 |Crc32 f7c3f9b7 |Md5 67d6124f59848223cb5027dcdaaafe15
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe"
17/07/2003 07:22 |Size 4425524 |Crc32 2bd49468 |Md5 3c2d4b5b1acb1b9ca2a5edee0dea9219
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe"
02/08/2003 05:39 |Size 5353530 |Crc32 430849af |Md5 f3c667704c8e0b5619e46c60be2f2760
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe"
01/08/2003 06:24 |Size 218966 |Crc32 0b712ad0 |Md5 ff6c848c18927f6dec83cc132e4f9bf6
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe"
02/08/2003 05:32 |Size 15690755 |Crc32 217f452a |Md5 37ce1a3252198d662e9735acaf9bd1aa
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Old Nero 6.0.0.11 Full FR de O\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe"
01/08/2003 17:18 |Size 3936576 |Crc32 8b15c724 |Md5 42bb0e494d9d924cd53341c951f18420
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\Win Zip V.7.0 de M\Crack … ‚x‚cuter ds le dossier PF-WZ\crack.exe"
29/01/1999 11:26 |Size 9984 |Crc32 201ecd93 |Md5 dc78b017f3964e194c7e37e8562c631c
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\WinRAR 3.2 de O\WinRAR v3.20 fr+Crack\Crack_WinRAR_v32b2f.exe"
19/03/2003 06:58 |Size 14336 |Crc32 62d1d5f5 |Md5 831398ae8ffe287af2a232b1f7382989
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\WinRAR 3.2 de O\WinRAR v3.20 fr+Crack\Keyfilemaker.exe"
16/03/2003 10:38 |Size 169984 |Crc32 778cbd5d |Md5 41ddff6e0c2b186b7bb981c9c5026a19
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\04-05 Outils s‚l‚ction\WinRAR 3.2 de O\WinRAR v3.20 fr+Crack\WinRAR_v32b2fr.exe"
18/03/2003 19:05 |Size 1027097 |Crc32 47fb7e37 |Md5 97119fefab2139c536ff8a5ad16429be
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Henri outils\Adobe Photoshop Elements v3.0 multilangue + crack.iso\Setup.exe"
03/08/2004 00:34 |Size 159744 |Crc32 7d40e599 |Md5 a2c6003ddcd8d9b5a79f94660e607099
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Henri outils\Adobe Photoshop Elements v3.0 multilangue + crack.iso\Adobe Photoshop Elements\Setup.exe"
04/10/2004 04:34 |Size 151552 |Crc32 c36573f5 |Md5 5f2b9e5450c171823df78a8a5b1af6e3
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Henri outils\Adobe Photoshop Elements v3.0 multilangue + crack.iso\Adobe Photoshop Elements\directx9\dxsetup.exe"
16/12/2003 05:10 |Size 467456 |Crc32 f1f4c75c |Md5 50ca7683aca3e726583aa99f1621decc
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Henri outils\Adobe Photoshop Elements v3.0 multilangue + crack.iso\Adobe Reader 6.0.1\AdbeRdr60_enu_full.exe"
19/07/2004 17:26 |Size 16706160 |Crc32 1ac0127b |Md5 7f40197629c6d709958ed81dbea06216
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Henri outils\Adobe Photoshop Elements v3.0 multilangue + crack.iso\Common\DirectX 9.0\dxsetup.exe"
16/12/2003 05:10 |Size 467456 |Crc32 91a62fed |Md5 b6c3e0fa41ca9f2da411a8a55068a21a
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Henri outils\Adobe Photoshop Elements v3.0 multilangue + crack.iso\CRACK\keygen.exe"
30/07/2005 10:17 |Size 34816 |Crc32 f5688690 |Md5 84ea382abd99a2345abec4e2baeae453
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Lyon logiciels\install_studio_MX\KeyGens\keygen.exe"
30/09/2004 15:56 |Size 7168 |Crc32 4ff1e4c3 |Md5 dd13e62cab5d68ed92eb9e9f07dc7770
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Lyon logiciels\Vegas 5.0\Sony Vegas Video 5(With Mpg Plugin) Dvdarchitect2\VegasVideo5(with MPG plugin)+DVDarchitect2\DVD Architect 2.0\KEYGEN\DVDArchitect2_keygen.exe"
09/02/2003 17:53 |Size 65024 |Crc32 61e4d0eb |Md5 f557652d94cc2104c7578b90d45777c5
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\05 Lyon logiciels\WinRAR\WinRarKeygen.exe"
14/05/2003 22:20 |Size 19970 |Crc32 bf922564 |Md5 ad8a991736b1de3e500b77cc5bd8b604
"G:\DOSSIER logiciels Lyon, Henri,outis,drivers\jf divers … copier\Dynomite\DynomiteCrack.exe"
09/05/2002 09:23 |Size 5120 |Crc32 669bfff4 |Md5 9154bfb901999c2274b5b7ec41a4d3be
################## | Upload |
Veuillez envoyer le fichier : C:\DOCUME~1\JEF\Bureau\UsbFix_Upload_Me_PB-4YNAEK9UWABO.zip :
http://forum-aide-contre-virus.be/usbfix/choix_fichier.php
Merci pour votre contribution .
ensuite log.txt
Logfile of random's system information tool 1.06 (written by random/random)
Run by JEF at 2009-11-03 13:45:35
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 11 GB (42%) free of 26 GB
Total RAM: 503 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:45:48, on 03/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\JEF\Bureau\RSIT.exe
C:\Documents and Settings\JEF\Bureau\JEF.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Activer le Poste de Travail Sans Fil Labtec.lnk = C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
--
End of file - 5666 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-09-29 1082880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-10-27 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-10-27 256112]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd []
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-09-15 81000]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2007-10-07 2620336]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2007-10-07 904880]
"Acronis Scheduler2 Service"=C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe [2007-10-07 140568]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-31 68856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-04-03 1603152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
C:\WINDOWS\System32\hkcmd.exe [2005-09-19 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
C:\WINDOWS\System32\igfxpers.exe [2005-09-19 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
C:\WINDOWS\System32\igfxtray.exe [2005-09-19 94208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe [2006-06-26 497200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe [2006-06-26 614960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe [2006-06-26 243248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Photo Express SE Calendar Checker.lnk]
C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe []
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Activer le Poste de Travail Sans Fil Labtec.lnk - C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-09-19 135168]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=128
"NoDriveAutoRun"=128
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
======List of files/folders created in the last 1 months======
2009-11-03 13:45:35 ----D---- C:\rsit
2009-11-03 13:37:54 ----RASHD---- C:\autorun.inf
2009-11-03 13:27:45 ----A---- C:\UsbFix.txt
2009-11-01 06:45:10 ----D---- C:\UsbFix
2009-10-31 11:45:38 ----D---- C:\WINDOWS\BDOSCAN8
2009-10-28 18:12:34 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-10-28 17:08:26 ----HDC---- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-28 17:07:57 ----D---- C:\Program Files\Lavasoft
2009-10-28 17:07:57 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-10-28 15:14:25 ----D---- C:\Program Files\CCleaner
2009-10-28 14:57:26 ----D---- C:\Program Files\ToniArts
2009-10-28 13:14:59 ----D---- C:\Documents and Settings\JEF\Application Data\Malwarebytes
2009-10-28 13:14:50 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-10-28 13:14:49 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-24 11:34:43 ----D---- C:\Program Files\NBCONS
2009-10-22 14:02:09 ----D---- C:\Documents and Settings\JEF\Application Data\Google
2009-10-22 13:45:41 ----D---- C:\Documents and Settings\JEF\Application Data\vlc
======List of files/folders modified in the last 1 months======
2009-11-03 13:45:39 ----D---- C:\WINDOWS\Prefetch
2009-11-03 13:39:58 ----D---- C:\WINDOWS\Temp
2009-11-03 13:37:01 ----SHD---- C:\RECYCLER
2009-11-03 13:33:40 ----SHD---- C:\$RECYCLE.BIN
2009-11-03 13:03:13 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-03 13:03:10 ----HD---- C:\WINDOWS\inf
2009-11-03 08:17:50 ----A---- C:\WINDOWS\ULEAD32.INI
2009-11-01 18:54:29 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-01 18:34:12 ----D---- C:\Program Files\SpeedFan
2009-11-01 16:58:33 ----D---- C:\Documents and Settings\JEF\Application Data\Skype
2009-10-31 12:18:03 ----D---- C:\WINDOWS
2009-10-31 11:45:41 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-28 18:12:34 ----D---- C:\WINDOWS\system32
2009-10-28 17:32:00 ----D---- C:\WINDOWS\system32\drivers
2009-10-28 17:31:39 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-10-28 17:08:26 ----SHD---- C:\WINDOWS\Installer
2009-10-28 17:07:57 ----RD---- C:\Program Files
2009-10-28 17:07:50 ----D---- C:\WINDOWS\WinSxS
2009-10-28 14:57:25 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-27 16:56:09 ----D---- C:\Program Files\Google
2009-10-27 16:15:54 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-10-24 17:01:32 ----D---- C:\WINDOWS\system32\NtmsData
2009-10-24 17:01:32 ----D---- C:\WINDOWS\Minidump
2009-10-24 16:48:38 ----SHD---- C:\System Volume Information
2009-10-24 16:48:38 ----D---- C:\WINDOWS\system32\Restore
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-09-15 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-09-15 52368]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-19 40320]
R1 kbfilter;Keyboard Filter Driver; C:\WINDOWS\system32\drivers\kbfilter.sys [2002-10-15 12964]
R1 moufiltr;Mouse Filter Driver; C:\WINDOWS\system32\drivers\moufiltr.sys [2003-01-23 9548]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-09-15 94160]
R2 irda;Protocole IrDA; C:\WINDOWS\System32\DRIVERS\irda.sys [2004-08-04 87424]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2008-12-24 44384]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-09-15 23152]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2005-05-12 1332544]
R3 FilterService;UVC Filter Service; C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys [2006-06-22 20272]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2005-09-19 1302332]
R3 LVcKap;Logitech AEC Driver; C:\WINDOWS\system32\DRIVERS\LVcKap.sys [2006-06-26 1587632]
R3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys [2006-06-26 1952816]
R3 lvpopflt;Logitech POP Suppression Filter; C:\WINDOWS\system32\DRIVERS\lvpopflt.sys [2006-06-22 1413424]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\drivers\LVPr2Mon.sys [2006-06-26 23472]
R3 lvselsus;Logitech Selective Suspend Filter; C:\WINDOWS\system32\DRIVERS\lvselsus.sys [2006-06-22 55984]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2006-06-22 38960]
R3 LVUVC;Logitech QuickCam Pro 5000(UVC); C:\WINDOWS\system32\DRIVERS\lvuvc.sys [2006-06-22 961072]
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [2005-03-03 74496]
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Pilote miniport de contrôleur hôte amélioré USB 2.0 Microsoft; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 irsir;Pilote série infrarouge Microsoft; C:\WINDOWS\System32\DRIVERS\irsir.sys [2001-08-17 18688]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe [2007-10-07 427288]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-09-15 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-09-15 138680]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\System32\svchost.exe [2004-08-19 14336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-10-28 1179232]
R2 LVPrcSrv;Logitech Process Monitor; c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe [2006-06-26 99888]
R2 TryAndDecideService;Acronis Try And Decide Service; C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-08 493200]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-09-15 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-09-15 352920]
R3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe [2006-06-26 91696]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
-----------------EOF-----------------
et en 3 info.txt:
info.txt logfile of random's system information tool 1.06 2009-11-03 13:45:53
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ACDSee (version d’évaluation)-->C:\PROGRA~1\ACDSYS~1\ACDSEE~1\UNWISE.EXE C:\PROGRA~1\ACDSYS~1\ACDSEE~1\INSTALL.LOG
Acronis True Image Home-->MsiExec.exe /X{E5343B27-55DF-40BD-9FCF-A643C1331E8A}
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Ahead Nero Burning ROM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Assistant de connexion Windows Live-->MsiExec.exe /I{D6E592B3-67DA-4BBB-9783-E1838FB253A2}
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Canon MP Navigator EX 1.0-->"C:\Program Files\Canon\MP Navigator EX 1.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX 1.0\uninst.ini
Canon MP210 series-->"C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP210_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP210_series /L0x000c
Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
C-Media 3D Audio-->C:\WINDOWS\CMIUnInstall.exe
EasyCleaner-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
HijackThis 2.0.2-->"C:\Documents and Settings\JEF\Bureau\HijackThis.exe" /uninstall
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{3CCB732A-E472-4CF9-B1EE-F18365341FE0}
Intel(R) Extreme Graphics 2 Driver-->RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
Logitech Audio Echo Cancellation Component-->MsiExec.exe /X{BEF726DD-4037-4214-8C6A-E625C02D2870}
Logitech QuickCam-->MsiExec.exe /X{EC42ED6A-751D-45C0-A4F9-8CD00E4690FC}
Logitech Video Enumerator-->MsiExec.exe /X{EA516024-D84D-41F1-814F-83175A6188F2}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Poste de Travail Sans Fil Labtec-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A369B607-5BAF-4AB3-B18A-1017ED19902D}\Setup.exe" -l0x040c
PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
REALTEK Gigabit and Fast Ethernet NIC Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\Setup.exe" -l0x40c REMOVE
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe"
Ulead Photo Express 3.0 SE-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\IS32Inst.dll"
UMVPLStandalone-->MsiExec.exe /X{8AC049F7-1383-45C3-9E7D-F93CA667F9E1}
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 0.9.4-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{01523985-2098-43AF-9C97-12B07BE02A9B}
Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
=====HijackThis Backups=====
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [2009-10-29]
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-10-29]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = [2009-10-29]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens [2009-10-29]
======Security center information======
AV: avast! antivirus 4.8.1356 [VPS 091102-0]
======System event log======
Computer Name: PB-4YNAEK9UWABO
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service aswRdr.
Record Number: 1099
Source Name: Service Control Manager
Time Written: 20081223185416.000000-240
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: PB-4YNAEK9UWABO
Event Code: 7036
Message: Le service avast! Web Scanner est entré dans l'état : en cours d'exécution.
Record Number: 1098
Source Name: Service Control Manager
Time Written: 20081223185415.000000-240
Event Type: Informations
User:
Computer Name: PB-4YNAEK9UWABO
Event Code: 7036
Message: Le service NLA (Network Location Awareness) est entré dans l'état : en cours d'exécution.
Record Number: 1097
Source Name: Service Control Manager
Time Written: 20081223185415.000000-240
Event Type: Informations
User:
Computer Name: PB-4YNAEK9UWABO
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).
Record Number: 1096
Source Name: Service Control Manager
Time Written: 20081223185415.000000-240
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: PB-4YNAEK9UWABO
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service avast! Web Scanner.
Record Number: 1095
Source Name: Service Control Manager
Time Written: 20081223185415.000000-240
Event Type: Informations
User: AUTORITE NT\SYSTEM
=====Application event log=====
Computer Name: PB-4YNAEK9UWABO
Event Code: 100
Message: wuauclt (1888) Le moteur de base de données 5.01.2600.2180 est démarré.
Record Number: 705
Source Name: ESENT
Time Written: 20091103132848.000000-240
Event Type: Informations
User:
Computer Name: PB-4YNAEK9UWABO
Event Code: 1800
Message: Le service Centre de sécurité Windows a démarré.
Record Number: 704
Source Name: SecurityCenter
Time Written: 20091103132800.000000-240
Event Type: Informations
User:
Computer Name: PB-4YNAEK9UWABO
Event Code: 101
Message: wuauclt (2376) Le moteur de base de données est arrêté.
Record Number: 703
Source Name: ESENT
Time Written: 20091103061749.000000-240
Event Type: Informations
User:
Computer Name: PB-4YNAEK9UWABO
Event Code: 103
Message: wuaueng.dll (2376) SUS20ClientDataStore: Le moteur de base de données a arrêté une instance (0).
Record Number: 702
Source Name: ESENT
Time Written: 20091103061749.000000-240
Event Type: Informations
User:
Computer Name: PB-4YNAEK9UWABO
Event Code: 102
Message: wuaueng.dll (2376) SUS20ClientDataStore: Le moteur de base de données a démarré une nouvelle instance (0).
Record Number: 701
Source Name: ESENT
Time Written: 20091103061246.000000-240
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
-----------------EOF-----------------
Merci encore de "desosser" tout ça...

pour en venir...
about