Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)
j'ai plus de pubs mais l'ordi est un poil lent!

 

 

• telecharge sur ton bureau:

 

- AtfCleaner --> http://www.atribune.org/ccount/click.php?id=1

 

ATF Cleaner

Double-clique ATF-Cleaner.exe afin de lancer le programme.

Sous l'onglet Main, choisis : Select All

Clique sur le bouton Empty Selected, patiente le temp du nettoyage, ok

Si tu utilises le navigateur Firefox :

Clique Firefox au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Si tu utilises le navigateur Opera :

Clique Opera au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Clique Exit, du menu prinicipal, afin de fermer le programme.

 

• effectue une defragmentation de ton disk

Posté(e)

l'ordi marche nickel merci angélique!

 

mais antivir à quand même dépister ça:

 

Virus or unwanted program 'TR/Dldr.Swizzor.Gen [trojan]'

detected in file 'E:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP83\A0050108.exe.

 

je l'ai virer donc y'a plus de soucis?

à croire que y'a quelqu'un qui m'en veut à force! lol

Posté(e)

Nop!! juste un point de restauration infecté \o_, si quarantaine c'est ok, il ne te reste plus qu'à vider la quarantaine d'antivir ^^

 

onglet administration\quarantaine\selectionne la_les instance(s) et clic la poubelle .

 

T'as toujours des pubs ?? on a pas vraiement fait grand chose depuis ton 1er message pour "éradiquer" le probleme . mais si tu dis que tu n'as plus de pubs , ça doit etre ok.

 

• on peut fouiller plus si tu en ressents la necessitée ??? si oui , ci dessous:

 

Télécharge Deckard's System Scanner http://deckard.geekstogo.com/dss.exe sur ton bureau

 

Ferme toutes les applications en cours

Doublie clique sur dss.exe. Tu auras deux messages qui vont apparaitre à l'écran, clique sur OK pour les deux.

 

Sois patient, le scan peut être long.

 

A la fin tu auras de nouveau un message disant que bloc-notes va s'ouvrir clique sur OK puis fais un copier/coller de tout son contenu.

Posté(e)

Virus or unwanted program 'TR/Dldr.Swizzor.Gen [trojan]'

detected in file 'E:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP83\A0050108.exe.

 

Virus or unwanted program 'TR/Dldr.Swizzor.Gen [trojan]'

detected in file 'E:\Program Files\Circle Developement\Uninstall.exe.

Action performed: Delete file

 

Virus or unwanted program 'TR/Dldr.Swizzor.Gen [trojan]'

detected in file 'E:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP83\A0050108.exe.

Action performed: Delete file

 

Virus or unwanted program 'TR/Dldr.Swizzor.Gen [trojan]'

detected in file 'E:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP83\A0050109.exe.

Action performed: Delete file

 

Virus or unwanted program 'TR/Dldr.Swizzor.Gen [trojan]'

detected in file 'E:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050208.exe.

Action performed: Delete file

 

Virus or unwanted program 'TR/Dldr.Swizzor.Gen [trojan]'

detected in file 'E:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050209.exe.

Action performed: Delete file

 

 

 

comme tu vois c'est pas fini heureusement que c'est ma fête aujourd'hui!

 

je fais quand même ce que tu m'a dit?

Posté(e)

Deckard's System Scanner v20071014.68

Run by florent on 2008-07-05 14:14:06

Computer is in Normal Mode.

--------------------------------------------------------------------------------

 

-- System Restore --------------------------------------------------------------

 

Successfully created a Deckard's System Scanner Restore Point.

 

 

-- Last 4 Restore Point(s) --

4: 2008-07-05 12:14:12 UTC - RP86 - Deckard's System Scanner Restore Point

3: 2008-07-05 12:10:04 UTC - RP85 - Installé Windows Live Toolbar

2: 2008-07-03 18:40:25 UTC - RP84 - Point de vérification système

1: 2008-07-02 17:48:01 UTC - RP83 - Point de vérification système

 

 

Backed up registry hives.

Performed disk cleanup.

 

Total Physical Memory: 448 MiB (512 MiB recommended).

 

 

-- HijackThis (run as florent.exe) ---------------------------------------------

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:15:33, on 05/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

E:\WINDOWS\system32\spoolsv.exe

E:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

E:\WINDOWS\Explorer.EXE

E:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

E:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe

E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

E:\Program Files\HP\HP Software Update\HPWuSchd2.exe

E:\WINDOWS\SOUNDMAN.EXE

E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

E:\Program Files\Orange HSS\Systray\SystrayApp.exe

E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

E:\WINDOWS\system32\ctfmon.exe

E:\Program Files\Free Download Manager\fdm.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe

E:\Program Files\Windows Live\Messenger\msnmsgr.exe

E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

E:\WINDOWS\system32\nvsvc32.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\system32\rundll32.exe

E:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe

E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe

E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe

E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

E:\WINDOWS\system32\msiexec.exe

E:\Documents and Settings\florent\Bureau\dss.exe

E:\DOCUME~1\florent\Bureau\florent.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - E:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [avgnt] "E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [sunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [systrayORAHSS] "E:\Program Files\Orange HSS\Systray\SystrayApp.exe"

O4 - HKLM\..\Run: [ORAHSSSessionManager] E:\Program Files\Orange HSS\SessionManager\SessionManager.exe

O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP000.TMP\"

O4 - HKLM\..\RunOnce: [wextract_cleanup1] rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP001.TMP\"

O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Free Download Manager] E:\Program Files\Free Download Manager\fdm.exe -autorun

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [Free Download Manager] E:\Program Files\Free Download Manager\fdm.exe -autorun (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: &Windows Live Search - res://E:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Download all with Free Download Manager - file://E:\Program Files\Free Download Manager\dlall.htm

O8 - Extra context menu item: Download selected with Free Download Manager - file://E:\Program Files\Free Download Manager\dlselected.htm

O8 - Extra context menu item: Download web site with Free Download Manager - file://E:\Program Files\Free Download Manager\dlpage.htm

O8 - Extra context menu item: Download with Free Download Manager - file://E:\Program Files\Free Download Manager\dllink.htm

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.orange.fr

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -

O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O17 - HKLM\System\CS1\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O17 - HKLM\System\CS2\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - E:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - E:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Boonty Games - BOONTY - E:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - E:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe

O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe

 

--

End of file - 11852 bytes

 

-- HijackThis Fixed Entries (E:\DOCUME~1\florent\Bureau\backups\) --------------

 

backup-20080602-210825-695 O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

backup-20080701-173205-202 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

backup-20080701-173205-588 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

backup-20080701-173205-808 O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe

backup-20080701-173205-983 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\bdoscandel.exe (file missing)

backup-20080701-173206-219 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -

backup-20080701-173206-327 O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -

backup-20080701-173206-376 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\bdoscandel.exe (file missing)

backup-20080701-173206-637 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - E:\Program Files\Yahoo!\Common\yinsthelper.dll

backup-20080701-173207-397 O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -

 

-- File Associations -----------------------------------------------------------

 

.reg - regfile - shell\open\command - regedit.exe "%1" %*

.scr - scrfile - shell\open\command - "%1" %*

 

 

-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

 

S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - e:\windows\system32\pcampr5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - e:\windows\system32\pcandis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

 

 

-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

 

R2 AntiVirScheduler (Avira AntiVir Personal – Free Antivirus Scheduler) - "e:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>

R2 FTRTSVC (France Telecom Routing Table Service) - "e:\progra~1\fichie~1\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe" <Not Verified; France Telecom SA; CSS-Corporate>

 

S3 Boonty Games - "e:\program files\fichiers communs\boonty shared\service\boonty.exe" <Not Verified; BOONTY; Boonty Games>

S3 NBService - e:\program files\nero\nero 7\nero backitup\nbservice.exe

 

 

-- Device Manager: Disabled ----------------------------------------------------

 

No disabled devices found.

 

 

-- Scheduled Tasks -------------------------------------------------------------

 

2008-07-05 14:10:16 258 --a------ E:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job

2008-07-05 02:00:00 276 --ah----- E:\WINDOWS\Tasks\A8723A5C9171AF64.job

 

 

-- Files created between 2008-06-05 and 2008-07-05 -----------------------------

 

2008-07-05 13:28:27 0 dr-h----- E:\Documents and Settings\Kevin\Recent

2008-07-04 20:46:29 0 dr-h----- E:\Documents and Settings\florent\Recent

2008-07-02 14:11:54 0 d-------- E:\Documents and Settings\All Users\Application Data\Kaspersky Lab

2008-07-02 14:11:52 0 d-------- E:\WINDOWS\system32\Kaspersky Lab

2008-07-01 20:44:53 0 d-------- E:\Documents and Settings\All Users\Application Data\Sandlot Games

2008-07-01 20:44:31 0 d--hs---- E:\WINDOWS\ftpcache

2008-07-01 20:44:15 0 d-a------ E:\Documents and Settings\All Users\Application Data\TEMP

2008-07-01 20:41:46 0 d-------- E:\Documents and Settings\All Users\Application Data\GamesBar

2008-07-01 20:40:53 0 d-------- E:\Program Files\GamesBar

2008-07-01 20:40:43 0 d-------- E:\Program Files\Fichiers communs\Oberon Media

2008-07-01 20:40:42 0 d-------- E:\Program Files\orange

2008-06-30 18:03:28 0 dr-h----- E:\Documents and Settings\Utilisateur1\Recent

2008-06-28 21:59:31 0 d-------- E:\Program Files\seconddoesboob

2008-06-28 18:36:45 0 d-------- E:\Documents and Settings\Kevin\Bluetooth Software

2008-06-28 17:31:48 0 d-------- E:\WINDOWS\system32\LogFiles

2008-06-28 10:56:23 0 d-------- E:\WINDOWS\BDOSCAN8

2008-06-28 10:37:04 0 d-------- E:\Program Files\Panda Security

2008-06-27 20:35:03 0 d-------- E:\WINDOWS\Sof??are????????tio???er????r?ceTe????re?????Tr?@eTe??M?i??Tr?@e????

2008-06-27 20:24:49 0 d-------- E:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site

2008-06-23 10:55:54 0 d-------- E:\Program Files\Windows Live Safety Center

2008-06-22 18:09:03 335 --a------ E:\WINDOWS\mozregistry.dat

2008-06-21 16:48:54 0 d-------- E:\327882R2FWJFW

2008-06-17 16:51:36 0 d-------- E:\Program Files\JoWooD

2008-06-14 13:23:54 0 d-------- E:\Program Files\Fichiers communs\Vbox

2008-06-14 13:12:37 0 d-------- E:\Documents and Settings\Kevin\Application Data\WinRAR

2008-06-12 09:11:28 0 d-------- E:\Documents and Settings\Kevin\Application Data\DivX

2008-06-12 09:11:26 0 d-------- E:\Documents and Settings\Kevin\Application Data\Media Player Classic

2008-06-11 22:52:18 0 d-------- E:\Program Files\Copernic Desktop Search 2

 

 

-- Find3M Report ---------------------------------------------------------------

 

2008-07-05 14:14:21 0 d-------- E:\Documents and Settings\florent\Application Data\Free Download Manager

2008-07-05 14:10:11 0 d-------- E:\Program Files\Windows Live Toolbar

2008-07-05 13:02:30 0 d-------- E:\Program Files\eMule

2008-07-01 20:40:43 0 d-------- E:\Program Files\Fichiers communs

2008-06-29 18:11:45 0 d-------- E:\Program Files\BoontyGames

2008-06-28 21:59:08 0 d-------- E:\Program Files\Messenger Plus! Live

2008-06-27 13:56:56 0 d-------- E:\Documents and Settings\florent\Application Data\Mozilla

2008-06-19 20:07:54 0 d-------- E:\Program Files\Malwarebytes' Anti-Malware

2008-06-15 17:22:44 0 d-------- E:\Program Files\Fichiers communs\Adobe

2008-06-15 17:22:23 0 d-------- E:\Documents and Settings\florent\Application Data\Adobe

2008-06-06 23:18:07 0 d-------- E:\Documents and Settings\florent\Application Data\HP

2008-06-02 19:38:49 0 d-------- E:\Documents and Settings\florent\Application Data\Malwarebytes

2008-06-01 22:50:50 0 d-------- E:\Documents and Settings\florent\Application Data\Ahead

2008-05-31 01:25:37 0 d-------- E:\Program Files\ToniArts

2008-05-31 01:25:35 0 d--h----- E:\Program Files\InstallShield Installation Information

2008-05-30 14:36:02 0 d-------- E:\Program Files\Lavasoft

2008-05-30 14:35:15 0 d-------- E:\Program Files\Fichiers communs\Wise Installation Wizard

2008-05-30 00:52:15 1409 --a------ E:\WINDOWS\mozver.dat

2008-05-29 16:29:44 0 d-------- E:\Program Files\PhotoFiltre

2008-05-29 14:03:52 0 d-------- E:\Program Files\Fichiers communs\Ahead

2008-05-29 13:59:36 0 d-------- E:\Program Files\Nero

2008-05-29 13:24:14 0 d-------- E:\Program Files\AskTBar

2008-05-29 03:11:24 0 d-------- E:\Program Files\Belkin

2008-05-28 17:25:22 0 d-------- E:\Program Files\Orange HSS

2008-05-28 17:22:41 0 d-------- E:\Program Files\Fichiers communs\France Telecom

2008-05-28 17:19:15 0 d-------- E:\Program Files\SAGEM

2008-05-28 17:19:04 0 d-------- E:\Documents and Settings\florent\Application Data\InstallShield

2008-05-28 17:18:45 0 d-------- E:\Program Files\Securitoo

2008-05-28 00:28:39 500894 --a------ E:\WINDOWS\system32\perfh00C.dat

2008-05-28 00:28:39 80800 --a------ E:\WINDOWS\system32\perfc00C.dat

2008-05-28 00:28:02 0 d-------- E:\Program Files\Zylom Games

2008-05-25 23:59:08 0 d--hs--c- E:\Program Files\Fichiers communs\WindowsLiveInstaller

2008-05-25 23:58:55 0 d-------- E:\Program Files\Windows Live

2008-05-25 22:05:13 0 d-------- E:\Program Files\CCleaner

2008-05-25 22:05:09 0 d-------- E:\Program Files\Yahoo!

2008-05-25 21:53:37 0 d-------- E:\Program Files\Windows Live Favorites

2008-05-25 12:44:59 0 d-------- E:\Program Files\Java

2008-05-25 12:44:11 0 d-------- E:\Program Files\Fichiers communs\Java

2008-05-25 11:46:02 0 d-------- E:\Program Files\AMD

2008-05-25 11:42:15 0 d-------- E:\Program Files\Realtek Sound Manager

2008-05-25 11:42:15 0 d-------- E:\Program Files\AvRack

2008-05-25 11:42:13 0 d-------- E:\Program Files\Realtek AC97

2008-05-25 11:39:26 0 d-------- E:\Program Files\Fichiers communs\InstallShield

2008-05-24 13:47:59 0 d-------- E:\Program Files\Fichiers communs\BOONTY Shared

2008-05-24 13:46:11 0 d-------- E:\Program Files\Boonty

2008-05-24 11:50:45 0 d-------- E:\Documents and Settings\florent\Application Data\Sun

2008-05-24 10:24:41 0 d-------- E:\Documents and Settings\florent\Application Data\WinRAR

2008-05-24 04:02:41 129310 --a------ E:\WINDOWS\hpoins11.dat

2008-05-24 04:01:57 0 d-------- E:\Program Files\Fichiers communs\HP

2008-05-24 04:01:54 0 d-------- E:\Program Files\HP

2008-05-24 03:57:34 0 d-------- E:\Program Files\Hewlett-Packard

2008-05-24 03:56:53 0 d-------- E:\Program Files\Fichiers communs\Hewlett-Packard

2008-05-24 01:50:28 0 d-------- E:\Program Files\Fichiers communs\Real

2008-05-24 01:50:27 0 d-------- E:\Documents and Settings\florent\Application Data\Real

2008-05-24 01:18:06 0 d-------- E:\Program Files\Avira

2008-05-24 00:29:07 0 d-------- E:\Documents and Settings\florent\Application Data\vlc

2008-05-24 00:24:54 0 d-------- E:\Program Files\VideoLAN

2008-05-23 23:58:23 60416 --a------ E:\WINDOWS\ALCFDRTM.EXE <Not Verified; Realtek Semiconductor Corp.; Realtek ALCFDRTM>

2008-05-23 23:45:33 0 d-------- E:\Program Files\DivX

2008-05-23 23:43:00 0 d-------- E:\Documents and Settings\florent\Application Data\Media Player Classic

2008-05-23 23:43:00 0 d-------- E:\Documents and Settings\florent\Application Data\DivX

2008-05-23 23:39:21 0 d-------- E:\Documents and Settings\florent\Application Data\CyberLink

2008-05-23 23:35:55 0 d-------- E:\Documents and Settings\florent\Application Data\Macromedia

2008-05-23 23:19:15 0 d-------- E:\Documents and Settings\florent\Application Data\Talkback

2008-05-23 23:18:02 0 d-------- E:\Documents and Settings\florent\Application Data\Identities

2008-05-23 22:44:14 0 --a------ E:\WINDOWS\nsreg.dat

2008-05-23 21:10:37 0 d-------- E:\Program Files\Fichiers communs\Nero

2008-05-23 20:33:30 0 d-------- E:\Program Files\msn gaming zone

2008-05-23 20:31:13 0 d-------- E:\Program Files\Movie Maker

2008-05-23 20:29:07 23032 --a------ E:\WINDOWS\system32\emptyregdb.dat

2008-05-23 20:28:35 0 d-------- E:\Program Files\Windows NT

2008-05-23 20:19:08 62 --ahs---- E:\Documents and Settings\florent\Application Data\desktop.ini

2008-05-23 18:53:33 0 d-------- E:\Program Files\AVG

2008-05-23 18:41:03 0 d-------- E:\Program Files\Xvid

2008-05-23 16:40:50 0 d-------- E:\Program Files\Fichiers communs\ODBC

2008-05-23 16:40:47 0 d-------- E:\Program Files\Fichiers communs\SpeechEngines

2008-05-23 15:40:56 0 d-------- E:\Program Files\Microsoft Works

2008-05-23 15:40:05 0 d-------- E:\Program Files\Microsoft.NET

2008-05-23 15:34:04 0 d-------- E:\Program Files\MSBuild

2008-05-23 15:28:28 0 d-------- E:\Program Files\Reference Assemblies

2008-05-23 15:12:42 0 d-------- E:\Program Files\microsoft frontpage

2008-05-23 15:12:10 0 d-------- E:\Program Files\Media Player Classic

2008-05-23 15:11:49 0 d-------- E:\Program Files\CyberLink

2008-05-23 15:09:12 0 d-------- E:\Program Files\Free Download Manager

2008-05-23 15:04:40 0 d-------- E:\Program Files\MSXML 6.0

2008-05-23 15:04:25 0 d-------- E:\Program Files\MSXML 4.0

2008-05-23 14:56:30 0 d-------- E:\Program Files\Windows Media Connect 2

2008-05-23 14:51:05 0 d--h----- E:\Program Files\WindowsUpdate

2008-05-23 14:51:00 0 d-------- E:\Program Files\Services en ligne

2008-05-23 14:50:10 0 d-------- E:\Program Files\Fichiers communs\MSSoap

2008-05-23 14:48:29 0 d-------- E:\Program Files\Messenger

2008-05-13 03:53:16 3596288 --a------ E:\WINDOWS\system32\qt-dx331.dll

2008-05-13 03:50:16 196608 --a------ E:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>

2008-05-13 03:50:16 81920 --a------ E:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>

2008-05-13 03:50:08 802816 --a------ E:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>

2008-05-13 03:50:08 823296 --a------ E:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:50:08 831488 --a------ E:\WINDOWS\system32\divx_xx0a.dll

2008-05-13 03:50:08 823296 --a------ E:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:50:06 682496 --a------ E:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:49:02 12288 --a------ E:\WINDOWS\system32\DivXWMPExtType.dll

 

 

-- Registry Dump ---------------------------------------------------------------

 

*Note* empty entries & legit default entries are not shown

 

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]

19/06/2007 17:09 380928 --a------ E:\Program Files\GamesBar\oberontb.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [10/10/2005 15:49]

"nwiz"="nwiz.exe" [10/10/2005 15:49 E:\WINDOWS\system32\nwiz.exe]

"avgnt"="E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [12/02/2008 10:06]

"HP Software Update"="E:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [19/02/2006 02:41]

"SoundMan"="SOUNDMAN.EXE" [22/09/2005 10:42 E:\WINDOWS\SOUNDMAN.EXE]

"NvMediaCenter"="E:\WINDOWS\system32\NvMcTray.dll" [10/10/2005 15:49]

"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [25/03/2008 04:28]

"SystrayORAHSS"="E:\Program Files\Orange HSS\Systray\SystrayApp.exe" [24/07/2007 19:55]

"ORAHSSSessionManager"="E:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [24/07/2007 19:03]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="E:\WINDOWS\system32\ctfmon.exe" [05/08/2004 14:00]

"Free Download Manager"="E:\Program Files\Free Download Manager\fdm.exe" [29/04/2006 10:22]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [22/01/2008 10:13]

"msnmsgr"="E:\Program Files\Windows Live\Messenger\msnmsgr.exe" [18/10/2007 11:34]

"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]

"wextract_cleanup0"=rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP000.TMP\"

"wextract_cleanup1"=rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP001.TMP\"

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]

"TSClientMSIUninstaller"=cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"

"tscuninstall"=%systemroot%\system32\tscupgrd.exe

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

"Free Download Manager"=E:\Program Files\Free Download Manager\fdm.exe -autorun

 

E:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

BTTray.lnk - E:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe [24/08/2005 14:06:54]

HP Digital Imaging Monitor.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [19/02/2006 04:21:22]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoRecentDocsHistory"=1 (0x1)

"ClearRecentDocsOnExit"=1 (0x1)

"NoRecentDocsMenu"=1 (0x1)

"NoInternetIcon"=1 (0x1)

"ForceClassicControlPanel"=1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NoRecentDocsHistory"=1 (0x1)

"ClearRecentDocsOnExit"=1 (0x1)

"NoRecentDocsMenu"=1 (0x1)

"NoInternetIcon"=1 (0x1)

"ForceClassicControlPanel"=1 (0x1)

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

"E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

E:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]

E:\Program Files\Free Download Manager\fdm.exe -autorun

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"E:\Program Files\iTunes\iTunesHelper.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]

"E:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

"E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

E:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

nwiz.exe /install

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

"E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

SOUNDMAN.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SRFirstRun]

rundll32 srclient.dll,CreateFirstRunRp

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"MDM"=2 (0x2)

"odserv"=3 (0x3)

"ose"=3 (0x3)

"idsvc"=3 (0x3)

"NMIndexingService"=3 (0x3)

"Nero BackItUp Scheduler 3"=2 (0x2)

"WMPNetworkSvc"=3 (0x3)

"RichVideo"=2 (0x2)

"NVSvc"=2 (0x2)

"iPod Service"=3 (0x3)

 

 

 

 

-- Hosts -----------------------------------------------------------------------

 

127.0.0.1 www.007guard.com

127.0.0.1 007guard.com

127.0.0.1 008i.com

127.0.0.1 www.008k.com

127.0.0.1 008k.com

127.0.0.1 www.00hq.com

127.0.0.1 00hq.com

127.0.0.1 010402.com

127.0.0.1 www.032439.com

127.0.0.1 032439.com

 

8684 more entries in hosts file.

 

 

-- End of Deckard's System Scanner: finished at 2008-07-05 14:16:28 ------------

 

Deckard's System Scanner v20071014.68

Extra logfile - please post this as an attachment with your post.

--------------------------------------------------------------------------------

 

-- System Information ----------------------------------------------------------

 

Microsoft Windows XP Professionnel (build 2600) SP 2.0

Architecture: X86; Language: French

 

CPU 0: AMD Sempron Processor 2600+

Percentage of Memory in Use: 67%

Physical Memory (total/avail): 447.23 MiB / 146.52 MiB

Pagefile Memory (total/avail): 1055.54 MiB / 656.95 MiB

Virtual Memory (total/avail): 2047.88 MiB / 1928.36 MiB

 

A: is Removable (No Media)

C: is Fixed (NTFS) - 24.45 GiB total, 17.62 GiB free.

D: is CDROM (No Media)

E: is Fixed (NTFS) - 51.87 GiB total, 36.04 GiB free.

 

\\.\PHYSICALDRIVE0 - Maxtor 6Y080P0 - 76.33 GiB - 2 partitions

\PARTITION0 - Étendu avec Inter. 13 étendue - 51.87 GiB - E:

\PARTITION1 (bootable) - Système de fichiers installable - 24.45 GiB - C:

 

 

 

-- Security Center -------------------------------------------------------------

 

AUOptions is scheduled to auto-install.

Windows Internal Firewall is enabled.

 

FirstRunDisabled is set.

AntiVirusDisableNotify is set.

FirewallDisableNotify is set.

UpdatesDisableNotify is set.

 

AV: Avira AntiVir PersonalEdition v8.0.1.15 (Avira GmbH)

 

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"E:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="E:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

 

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"E:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"="E:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"

"E:\\Program Files\\Mozilla Firefox\\firefox.exe"="E:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

"E:\\Program Files\\Steam\\steamapps\\ju_l_ia\\counter-strike source\\hl2.exe"="E:\\Program Files\\Steam\\steamapps\\ju_l_ia\\counter-strike source\\hl2.exe:*:Enabled:hl2"

"E:\\Program Files\\Steam\\Steam.exe"="E:\\Program Files\\Steam\\Steam.exe:*:Enabled:Steam"

"E:\\Program Files\\Steam\\steamapps\\pierrestar66\\counter-strike source\\hl2.exe"="E:\\Program Files\\Steam\\steamapps\\pierrestar66\\counter-strike source\\hl2.exe:*:Enabled:hl2"

"E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"E:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="E:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"E:\\WINDOWS\\system32\\dpvsetup.exe"="E:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"

"E:\\Program Files\\eMule\\eMule.exe"="E:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule"

"E:\\Program Files\\Orange HSS\\Connectivity\\ConnectivityManager.exe"="E:\\Program Files\\Orange HSS\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"

 

 

-- Environment Variables -------------------------------------------------------

 

ALLUSERSPROFILE=E:\Documents and Settings\All Users

APPDATA=E:\Documents and Settings\florent\Application Data

CLIENTNAME=Console

CommonProgramFiles=E:\Program Files\Fichiers communs

COMPUTERNAME=INTEGRA

ComSpec=E:\WINDOWS\system32\cmd.exe

FP_NO_HOST_CHECK=NO

HOMEDRIVE=E:

HOMEPATH=\Documents and Settings\florent

LOGONSERVER=\\INTEGRA

NUMBER_OF_PROCESSORS=1

OS=Windows_NT

Path=E:\WINDOWS\system32;E:\WINDOWS;E:\WINDOWS\system32\WBEM;E:\Program Files\Fichiers communs\Ahead\Lib\

PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

PROCESSOR_ARCHITECTURE=x86

PROCESSOR_IDENTIFIER=x86 Family 15 Model 44 Stepping 2, AuthenticAMD

PROCESSOR_LEVEL=15

PROCESSOR_REVISION=2c02

ProgramFiles=E:\Program Files

PROMPT=$P$G

SESSIONNAME=Console

SystemDrive=E:

SystemRoot=E:\WINDOWS

TEMP=E:\DOCUME~1\florent\LOCALS~1\Temp

TMP=E:\DOCUME~1\florent\LOCALS~1\Temp

USERDOMAIN=INTEGRA

USERNAME=florent

USERPROFILE=E:\Documents and Settings\florent

windir=E:\WINDOWS

 

 

-- User Profiles ---------------------------------------------------------------

 

Utilisateur1 (admin)

florent (admin)

Cindy (admin)

Kevin (admin)

Cindy_2 (admin)

 

 

-- Add/Remove Programs ---------------------------------------------------------

 

--> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER

--> E:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL

--> E:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL

--> E:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL

--> E:\WINDOWS\UNNeroShowTime.exe /UNINSTALL

--> E:\WINDOWS\UNNeroVision.exe /UNINSTALL

--> E:\WINDOWS\UNRecode.exe /UNINSTALL

--> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {957E4620-59C2-4D3E-9B6D-5F024803E7D8}

--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 E:\WINDOWS\INF\PCHealth.inf

Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}

Adobe Flash Player 9 ActiveX --> E:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete

Adobe Flash Player ActiveX --> E:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Reader 8.1.2 - Français --> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}

Adobe Shockwave Player --> E:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE E:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log

Assistant de connexion Windows Live --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}

Athlon 64 Processor Driver --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c

Avira AntiVir Personal – Free Antivirus --> E:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE

Barre d'outils Outlook de Windows Live (Windows Live Toolbar) --> MsiExec.exe /X{4002F73D-EBB3-4EA1-A2FF-DBCB4529759E}

Belkin Bluetooth Software --> MsiExec.exe /X{3F4EC965-28EF-45C3-B063-04B25D4E9679}

Bloqueur de fenêtres pop-up (Windows Live Toolbar) --> MsiExec.exe /X{51F366F4-C2E4-429A-866A-59C885ED42FD}

CCleaner (remove only) --> "E:\Program Files\CCleaner\uninst.exe"

DivX Codec --> E:\Program Files\DivX\DivXCodecUninstall.exe /CODEC

DivX Converter --> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER

DivX Player --> E:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER

DivX Web Player --> E:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN

Détecteur de flux Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{175B7C4A-CAF8-437A-B597-73E0D2D970FE}

EasyCleaner --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly

eMule --> "E:\Program Files\eMule\Uninstall.exe"

Extension de Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{D518AD32-C710-4616-BA0D-D4B1FA5F82E8}

Free Download Manager 2.0 --> "E:\Program Files\Free Download Manager\unins000.exe"

GamesBar 1.1.0.5 --> E:\Program Files\GamesBar\uninst.exe

HijackThis 2.0.2 --> "E:\Documents and Settings\florent\Bureau\HijackThis.exe" /uninstall

HP Customer Participation Program 7.0 --> E:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat

HP Imaging Device Functions 7.0 --> E:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat

HP Photosmart Essential --> MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}

HP Photosmart, Officejet and Deskjet 7.0.A --> E:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat

HP Software Update --> MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}

HP Solution Center 7.0 --> E:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat

Java 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}

Kaspersky Online Scanner --> E:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe

livebox --> E:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly

Malwarebytes' Anti-Malware --> "E:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"

Menus intelligents (Windows Live Toolbar) --> MsiExec.exe /X{3585ED1C-74C5-43B0-A232-831B96A12A2B}

Messenger Plus! Live & Sponsor (CiD) --> "E:\Program Files\Messenger Plus! Live\Uninstall.exe"

Microsoft Compression Client Pack 1.0 for Windows XP --> "E:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"

Microsoft Office Access MUI (French) 2007 --> MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}

Microsoft Office Excel MUI (French) 2007 --> MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (French) 2007 --> MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}

Microsoft Office Outlook MUI (French) 2007 --> MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (French) 2007 --> MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}

Microsoft Office Professional Plus 2007 --> "E:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL

Microsoft Office Professional Plus 2007 --> MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}

Microsoft Office Proof (Arabic) 2007 --> MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}

Microsoft Office Proof (Dutch) 2007 --> MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}

Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (German) 2007 --> MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (French) 2007 --> MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}

Microsoft Office Publisher MUI (French) 2007 --> MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}

Microsoft Office Shared MUI (French) 2007 --> MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}

Microsoft Office Word MUI (French) 2007 --> MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}

Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "E:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"

Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}

Mise à jour de sécurité pour Windows XP (KB923789) --> E:\WINDOWS\system32\MacroMed\Flash\genuinst.exe E:\WINDOWS\system32\MacroMed\Flash\KB923789.inf

Mozilla Firefox (3.0) --> E:\Program Files\Mozilla Firefox\uninstall\helper.exe

MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{1787603C-E6E3-42D4-8034-55F358486F1D}

Navigateur Orange --> E:\Program Files\Orange HSS\Uninstall\Browser\Shell.exe MainUninstall.shl

Navigation par onglets (Windows Live Toolbar) --> MsiExec.exe /X{E74559C2-BB47-45AD-83DD-0D66B67E7811}

Nero 7 Premium --> MsiExec.exe /X{22FB6750-ADDF-4726-B67F-6901E1991036}

neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}

NVIDIA Drivers --> E:\WINDOWS\system32\nvudisp.exe UninstallGUI

OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{F242B06B-517F-4D62-B654-16B11564A912}

Orange - Logiciels Internet --> E:\Program Files\Orange HSS\installation\core\Installgui.exe -u

PhotoFiltre --> "E:\Program Files\PhotoFiltre\Uninst.exe"

PowerDVD --> "E:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -l0x00040c /z-uninstall

Realtek AC'97 Audio --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly

Security Update for Excel 2007 (KB946974) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}

Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}

Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}

Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}

Security Update for Office 2007 (KB934062) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {305D509B-F194-4638-9F0F-D9E4C05F9D33}

Security Update for Office 2007 (KB947801) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}

Security Update for Outlook 2007 (KB946983) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}

Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86}

Spellforce - Diamond Edition --> MsiExec.exe /I{2CA13178-C16D-47A4-AA91-5441F57FF63E}

Spybot - Search & Destroy --> "E:\Program Files\Spybot - Search & Destroy\unins000.exe"

Update for Office 2007 (KB932080) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {EDC9CA29-6BC1-471C-828C-7A36109005D7}

Update for Office 2007 (KB934391) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5}

Update for Office 2007 (KB946691) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}

Update for Outlook 2007 Junk Email Filter (kb950378) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F6296086-AED5-4EC0-938B-08EA0254F20E}

VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}

VideoLAN VLC media player 0.8.6f --> E:\Program Files\VideoLAN\VLC\uninstall.exe

Windows Communication Foundation --> MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}

Windows Live Favorites pour Windows Live Toolbar --> MsiExec.exe /X{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}

Windows Live installer --> MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}

Windows Live Messenger --> MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

Windows Live OneCare safety scanner --> RunDll32.exe "E:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT

Windows Live Toolbar --> "E:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}

Windows Live Toolbar --> MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}

Windows Media Format 11 runtime -->

Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}

Windows Presentation Foundation Language Pack (FRA) --> MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}

Windows Workflow Foundation --> MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}

Windows Workflow Foundation FR Language Pack --> MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}

WinRAR archiver --> E:\Program Files\WinRar\uninstall.exe

XML Paper Specification Shared Components Language Pack 1.0 --> "E:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

XML Paper Specification Shared Components Pack 1.0 -->

Xvid 1.1.3 final uninstall --> "E:\Program Files\Xvid\unins000.exe"

Yahoo! Toolbar avec bloqueur de fenêtres pop-up --> E:\PROGRA~1\Yahoo!\Common\unyt.exe

 

 

-- Application Event Log -------------------------------------------------------

 

Event Record #/Type1314 / Success

Event Submitted/Written: 07/05/2008 01:03:54 PM

Event ID/Source: 12001 / usnjsvc

Event Description:

The Messenger Sharing USN Journal Reader service started successfully.

 

Event Record #/Type1305 / Success

Event Submitted/Written: 07/05/2008 00:06:13 PM

Event ID/Source: 12001 / usnjsvc

Event Description:

The Messenger Sharing USN Journal Reader service started successfully.

 

Event Record #/Type1289 / Warning

Event Submitted/Written: 07/04/2008 08:18:55 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050209.exe

 

Event Record #/Type1288 / Warning

Event Submitted/Written: 07/04/2008 08:18:49 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050208.exe

 

Event Record #/Type1287 / Warning

Event Submitted/Written: 07/04/2008 08:18:33 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP83\A0050109.exe

 

 

 

-- Security Event Log ----------------------------------------------------------

 

No Errors/Warnings found.

 

 

-- System Event Log ------------------------------------------------------------

 

Event Record #/Type6603 / Error

Event Submitted/Written: 07/05/2008 02:05:53 PM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6515 / Error

Event Submitted/Written: 07/05/2008 01:01:52 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6514 / Error

Event Submitted/Written: 07/05/2008 01:01:50 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6513 / Error

Event Submitted/Written: 07/05/2008 00:35:04 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6512 / Error

Event Submitted/Written: 07/05/2008 00:30:11 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

 

 

-- End of Deckard's System Scanner: finished at 2008-07-05 14:16:28 ------------

 

 

 

Deckard's System Scanner v20071014.68

Run by florent on 2008-07-05 14:14:06

Computer is in Normal Mode.

--------------------------------------------------------------------------------

 

-- System Restore --------------------------------------------------------------

 

Successfully created a Deckard's System Scanner Restore Point.

 

 

-- Last 4 Restore Point(s) --

4: 2008-07-05 12:14:12 UTC - RP86 - Deckard's System Scanner Restore Point

3: 2008-07-05 12:10:04 UTC - RP85 - Installé Windows Live Toolbar

2: 2008-07-03 18:40:25 UTC - RP84 - Point de vérification système

1: 2008-07-02 17:48:01 UTC - RP83 - Point de vérification système

 

 

Backed up registry hives.

Performed disk cleanup.

 

Total Physical Memory: 448 MiB (512 MiB recommended).

 

 

-- HijackThis (run as florent.exe) ---------------------------------------------

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:15:33, on 05/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

E:\WINDOWS\system32\spoolsv.exe

E:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

E:\WINDOWS\Explorer.EXE

E:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

E:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe

E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

E:\Program Files\HP\HP Software Update\HPWuSchd2.exe

E:\WINDOWS\SOUNDMAN.EXE

E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

E:\Program Files\Orange HSS\Systray\SystrayApp.exe

E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

E:\WINDOWS\system32\ctfmon.exe

E:\Program Files\Free Download Manager\fdm.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe

E:\Program Files\Windows Live\Messenger\msnmsgr.exe

E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

E:\WINDOWS\system32\nvsvc32.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\system32\rundll32.exe

E:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe

E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe

E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe

E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

E:\WINDOWS\system32\msiexec.exe

E:\Documents and Settings\florent\Bureau\dss.exe

E:\DOCUME~1\florent\Bureau\florent.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - E:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [avgnt] "E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [sunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [systrayORAHSS] "E:\Program Files\Orange HSS\Systray\SystrayApp.exe"

O4 - HKLM\..\Run: [ORAHSSSessionManager] E:\Program Files\Orange HSS\SessionManager\SessionManager.exe

O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP000.TMP\"

O4 - HKLM\..\RunOnce: [wextract_cleanup1] rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP001.TMP\"

O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Free Download Manager] E:\Program Files\Free Download Manager\fdm.exe -autorun

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [Free Download Manager] E:\Program Files\Free Download Manager\fdm.exe -autorun (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: &Windows Live Search - res://E:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Download all with Free Download Manager - file://E:\Program Files\Free Download Manager\dlall.htm

O8 - Extra context menu item: Download selected with Free Download Manager - file://E:\Program Files\Free Download Manager\dlselected.htm

O8 - Extra context menu item: Download web site with Free Download Manager - file://E:\Program Files\Free Download Manager\dlpage.htm

O8 - Extra context menu item: Download with Free Download Manager - file://E:\Program Files\Free Download Manager\dllink.htm

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.orange.fr

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -

O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O17 - HKLM\System\CS1\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O17 - HKLM\System\CS2\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - E:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - E:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Boonty Games - BOONTY - E:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - E:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe

O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe

 

--

End of file - 11852 bytes

 

-- HijackThis Fixed Entries (E:\DOCUME~1\florent\Bureau\backups\) --------------

 

backup-20080602-210825-695 O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

backup-20080701-173205-202 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

backup-20080701-173205-588 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

backup-20080701-173205-808 O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe

backup-20080701-173205-983 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\bdoscandel.exe (file missing)

backup-20080701-173206-219 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -

backup-20080701-173206-327 O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -

backup-20080701-173206-376 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\bdoscandel.exe (file missing)

backup-20080701-173206-637 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - E:\Program Files\Yahoo!\Common\yinsthelper.dll

backup-20080701-173207-397 O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -

 

-- File Associations -----------------------------------------------------------

 

.reg - regfile - shell\open\command - regedit.exe "%1" %*

.scr - scrfile - shell\open\command - "%1" %*

 

 

-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

 

S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - e:\windows\system32\pcampr5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - e:\windows\system32\pcandis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

 

 

-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

 

R2 AntiVirScheduler (Avira AntiVir Personal – Free Antivirus Scheduler) - "e:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>

R2 FTRTSVC (France Telecom Routing Table Service) - "e:\progra~1\fichie~1\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe" <Not Verified; France Telecom SA; CSS-Corporate>

 

S3 Boonty Games - "e:\program files\fichiers communs\boonty shared\service\boonty.exe" <Not Verified; BOONTY; Boonty Games>

S3 NBService - e:\program files\nero\nero 7\nero backitup\nbservice.exe

 

 

-- Device Manager: Disabled ----------------------------------------------------

 

No disabled devices found.

 

 

-- Scheduled Tasks -------------------------------------------------------------

 

2008-07-05 14:10:16 258 --a------ E:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job

2008-07-05 02:00:00 276 --ah----- E:\WINDOWS\Tasks\A8723A5C9171AF64.job

 

 

-- Files created between 2008-06-05 and 2008-07-05 -----------------------------

 

2008-07-05 13:28:27 0 dr-h----- E:\Documents and Settings\Kevin\Recent

2008-07-04 20:46:29 0 dr-h----- E:\Documents and Settings\florent\Recent

2008-07-02 14:11:54 0 d-------- E:\Documents and Settings\All Users\Application Data\Kaspersky Lab

2008-07-02 14:11:52 0 d-------- E:\WINDOWS\system32\Kaspersky Lab

2008-07-01 20:44:53 0 d-------- E:\Documents and Settings\All Users\Application Data\Sandlot Games

2008-07-01 20:44:31 0 d--hs---- E:\WINDOWS\ftpcache

2008-07-01 20:44:15 0 d-a------ E:\Documents and Settings\All Users\Application Data\TEMP

2008-07-01 20:41:46 0 d-------- E:\Documents and Settings\All Users\Application Data\GamesBar

2008-07-01 20:40:53 0 d-------- E:\Program Files\GamesBar

2008-07-01 20:40:43 0 d-------- E:\Program Files\Fichiers communs\Oberon Media

2008-07-01 20:40:42 0 d-------- E:\Program Files\orange

2008-06-30 18:03:28 0 dr-h----- E:\Documents and Settings\Utilisateur1\Recent

2008-06-28 21:59:31 0 d-------- E:\Program Files\seconddoesboob

2008-06-28 18:36:45 0 d-------- E:\Documents and Settings\Kevin\Bluetooth Software

2008-06-28 17:31:48 0 d-------- E:\WINDOWS\system32\LogFiles

2008-06-28 10:56:23 0 d-------- E:\WINDOWS\BDOSCAN8

2008-06-28 10:37:04 0 d-------- E:\Program Files\Panda Security

2008-06-27 20:35:03 0 d-------- E:\WINDOWS\Sof??are????????tio???er????r?ceTe????re?????Tr?@eTe??M?i??Tr?@e????

2008-06-27 20:24:49 0 d-------- E:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site

2008-06-23 10:55:54 0 d-------- E:\Program Files\Windows Live Safety Center

2008-06-22 18:09:03 335 --a------ E:\WINDOWS\mozregistry.dat

2008-06-21 16:48:54 0 d-------- E:\327882R2FWJFW

2008-06-17 16:51:36 0 d-------- E:\Program Files\JoWooD

2008-06-14 13:23:54 0 d-------- E:\Program Files\Fichiers communs\Vbox

2008-06-14 13:12:37 0 d-------- E:\Documents and Settings\Kevin\Application Data\WinRAR

2008-06-12 09:11:28 0 d-------- E:\Documents and Settings\Kevin\Application Data\DivX

2008-06-12 09:11:26 0 d-------- E:\Documents and Settings\Kevin\Application Data\Media Player Classic

2008-06-11 22:52:18 0 d-------- E:\Program Files\Copernic Desktop Search 2

 

 

-- Find3M Report ---------------------------------------------------------------

 

2008-07-05 14:14:21 0 d-------- E:\Documents and Settings\florent\Application Data\Free Download Manager

2008-07-05 14:10:11 0 d-------- E:\Program Files\Windows Live Toolbar

2008-07-05 13:02:30 0 d-------- E:\Program Files\eMule

2008-07-01 20:40:43 0 d-------- E:\Program Files\Fichiers communs

2008-06-29 18:11:45 0 d-------- E:\Program Files\BoontyGames

2008-06-28 21:59:08 0 d-------- E:\Program Files\Messenger Plus! Live

2008-06-27 13:56:56 0 d-------- E:\Documents and Settings\florent\Application Data\Mozilla

2008-06-19 20:07:54 0 d-------- E:\Program Files\Malwarebytes' Anti-Malware

2008-06-15 17:22:44 0 d-------- E:\Program Files\Fichiers communs\Adobe

2008-06-15 17:22:23 0 d-------- E:\Documents and Settings\florent\Application Data\Adobe

2008-06-06 23:18:07 0 d-------- E:\Documents and Settings\florent\Application Data\HP

2008-06-02 19:38:49 0 d-------- E:\Documents and Settings\florent\Application Data\Malwarebytes

2008-06-01 22:50:50 0 d-------- E:\Documents and Settings\florent\Application Data\Ahead

2008-05-31 01:25:37 0 d-------- E:\Program Files\ToniArts

2008-05-31 01:25:35 0 d--h----- E:\Program Files\InstallShield Installation Information

2008-05-30 14:36:02 0 d-------- E:\Program Files\Lavasoft

2008-05-30 14:35:15 0 d-------- E:\Program Files\Fichiers communs\Wise Installation Wizard

2008-05-30 00:52:15 1409 --a------ E:\WINDOWS\mozver.dat

2008-05-29 16:29:44 0 d-------- E:\Program Files\PhotoFiltre

2008-05-29 14:03:52 0 d-------- E:\Program Files\Fichiers communs\Ahead

2008-05-29 13:59:36 0 d-------- E:\Program Files\Nero

2008-05-29 13:24:14 0 d-------- E:\Program Files\AskTBar

2008-05-29 03:11:24 0 d-------- E:\Program Files\Belkin

2008-05-28 17:25:22 0 d-------- E:\Program Files\Orange HSS

2008-05-28 17:22:41 0 d-------- E:\Program Files\Fichiers communs\France Telecom

2008-05-28 17:19:15 0 d-------- E:\Program Files\SAGEM

2008-05-28 17:19:04 0 d-------- E:\Documents and Settings\florent\Application Data\InstallShield

2008-05-28 17:18:45 0 d-------- E:\Program Files\Securitoo

2008-05-28 00:28:39 500894 --a------ E:\WINDOWS\system32\perfh00C.dat

2008-05-28 00:28:39 80800 --a------ E:\WINDOWS\system32\perfc00C.dat

2008-05-28 00:28:02 0 d-------- E:\Program Files\Zylom Games

2008-05-25 23:59:08 0 d--hs--c- E:\Program Files\Fichiers communs\WindowsLiveInstaller

2008-05-25 23:58:55 0 d-------- E:\Program Files\Windows Live

2008-05-25 22:05:13 0 d-------- E:\Program Files\CCleaner

2008-05-25 22:05:09 0 d-------- E:\Program Files\Yahoo!

2008-05-25 21:53:37 0 d-------- E:\Program Files\Windows Live Favorites

2008-05-25 12:44:59 0 d-------- E:\Program Files\Java

2008-05-25 12:44:11 0 d-------- E:\Program Files\Fichiers communs\Java

2008-05-25 11:46:02 0 d-------- E:\Program Files\AMD

2008-05-25 11:42:15 0 d-------- E:\Program Files\Realtek Sound Manager

2008-05-25 11:42:15 0 d-------- E:\Program Files\AvRack

2008-05-25 11:42:13 0 d-------- E:\Program Files\Realtek AC97

2008-05-25 11:39:26 0 d-------- E:\Program Files\Fichiers communs\InstallShield

2008-05-24 13:47:59 0 d-------- E:\Program Files\Fichiers communs\BOONTY Shared

2008-05-24 13:46:11 0 d-------- E:\Program Files\Boonty

2008-05-24 11:50:45 0 d-------- E:\Documents and Settings\florent\Application Data\Sun

2008-05-24 10:24:41 0 d-------- E:\Documents and Settings\florent\Application Data\WinRAR

2008-05-24 04:02:41 129310 --a------ E:\WINDOWS\hpoins11.dat

2008-05-24 04:01:57 0 d-------- E:\Program Files\Fichiers communs\HP

2008-05-24 04:01:54 0 d-------- E:\Program Files\HP

2008-05-24 03:57:34 0 d-------- E:\Program Files\Hewlett-Packard

2008-05-24 03:56:53 0 d-------- E:\Program Files\Fichiers communs\Hewlett-Packard

2008-05-24 01:50:28 0 d-------- E:\Program Files\Fichiers communs\Real

2008-05-24 01:50:27 0 d-------- E:\Documents and Settings\florent\Application Data\Real

2008-05-24 01:18:06 0 d-------- E:\Program Files\Avira

2008-05-24 00:29:07 0 d-------- E:\Documents and Settings\florent\Application Data\vlc

2008-05-24 00:24:54 0 d-------- E:\Program Files\VideoLAN

2008-05-23 23:58:23 60416 --a------ E:\WINDOWS\ALCFDRTM.EXE <Not Verified; Realtek Semiconductor Corp.; Realtek ALCFDRTM>

2008-05-23 23:45:33 0 d-------- E:\Program Files\DivX

2008-05-23 23:43:00 0 d-------- E:\Documents and Settings\florent\Application Data\Media Player Classic

2008-05-23 23:43:00 0 d-------- E:\Documents and Settings\florent\Application Data\DivX

2008-05-23 23:39:21 0 d-------- E:\Documents and Settings\florent\Application Data\CyberLink

2008-05-23 23:35:55 0 d-------- E:\Documents and Settings\florent\Application Data\Macromedia

2008-05-23 23:19:15 0 d-------- E:\Documents and Settings\florent\Application Data\Talkback

2008-05-23 23:18:02 0 d-------- E:\Documents and Settings\florent\Application Data\Identities

2008-05-23 22:44:14 0 --a------ E:\WINDOWS\nsreg.dat

2008-05-23 21:10:37 0 d-------- E:\Program Files\Fichiers communs\Nero

2008-05-23 20:33:30 0 d-------- E:\Program Files\msn gaming zone

2008-05-23 20:31:13 0 d-------- E:\Program Files\Movie Maker

2008-05-23 20:29:07 23032 --a------ E:\WINDOWS\system32\emptyregdb.dat

2008-05-23 20:28:35 0 d-------- E:\Program Files\Windows NT

2008-05-23 20:19:08 62 --ahs---- E:\Documents and Settings\florent\Application Data\desktop.ini

2008-05-23 18:53:33 0 d-------- E:\Program Files\AVG

2008-05-23 18:41:03 0 d-------- E:\Program Files\Xvid

2008-05-23 16:40:50 0 d-------- E:\Program Files\Fichiers communs\ODBC

2008-05-23 16:40:47 0 d-------- E:\Program Files\Fichiers communs\SpeechEngines

2008-05-23 15:40:56 0 d-------- E:\Program Files\Microsoft Works

2008-05-23 15:40:05 0 d-------- E:\Program Files\Microsoft.NET

2008-05-23 15:34:04 0 d-------- E:\Program Files\MSBuild

2008-05-23 15:28:28 0 d-------- E:\Program Files\Reference Assemblies

2008-05-23 15:12:42 0 d-------- E:\Program Files\microsoft frontpage

2008-05-23 15:12:10 0 d-------- E:\Program Files\Media Player Classic

2008-05-23 15:11:49 0 d-------- E:\Program Files\CyberLink

2008-05-23 15:09:12 0 d-------- E:\Program Files\Free Download Manager

2008-05-23 15:04:40 0 d-------- E:\Program Files\MSXML 6.0

2008-05-23 15:04:25 0 d-------- E:\Program Files\MSXML 4.0

2008-05-23 14:56:30 0 d-------- E:\Program Files\Windows Media Connect 2

2008-05-23 14:51:05 0 d--h----- E:\Program Files\WindowsUpdate

2008-05-23 14:51:00 0 d-------- E:\Program Files\Services en ligne

2008-05-23 14:50:10 0 d-------- E:\Program Files\Fichiers communs\MSSoap

2008-05-23 14:48:29 0 d-------- E:\Program Files\Messenger

2008-05-13 03:53:16 3596288 --a------ E:\WINDOWS\system32\qt-dx331.dll

2008-05-13 03:50:16 196608 --a------ E:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>

2008-05-13 03:50:16 81920 --a------ E:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>

2008-05-13 03:50:08 802816 --a------ E:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>

2008-05-13 03:50:08 823296 --a------ E:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:50:08 831488 --a------ E:\WINDOWS\system32\divx_xx0a.dll

2008-05-13 03:50:08 823296 --a------ E:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:50:06 682496 --a------ E:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:49:02 12288 --a------ E:\WINDOWS\system32\DivXWMPExtType.dll

 

 

-- Registry Dump ---------------------------------------------------------------

 

*Note* empty entries & legit default entries are not shown

 

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]

19/06/2007 17:09 380928 --a------ E:\Program Files\GamesBar\oberontb.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [10/10/2005 15:49]

"nwiz"="nwiz.exe" [10/10/2005 15:49 E:\WINDOWS\system32\nwiz.exe]

"avgnt"="E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [12/02/2008 10:06]

"HP Software Update"="E:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [19/02/2006 02:41]

"SoundMan"="SOUNDMAN.EXE" [22/09/2005 10:42 E:\WINDOWS\SOUNDMAN.EXE]

"NvMediaCenter"="E:\WINDOWS\system32\NvMcTray.dll" [10/10/2005 15:49]

"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [25/03/2008 04:28]

"SystrayORAHSS"="E:\Program Files\Orange HSS\Systray\SystrayApp.exe" [24/07/2007 19:55]

"ORAHSSSessionManager"="E:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [24/07/2007 19:03]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="E:\WINDOWS\system32\ctfmon.exe" [05/08/2004 14:00]

"Free Download Manager"="E:\Program Files\Free Download Manager\fdm.exe" [29/04/2006 10:22]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [22/01/2008 10:13]

"msnmsgr"="E:\Program Files\Windows Live\Messenger\msnmsgr.exe" [18/10/2007 11:34]

"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]

"wextract_cleanup0"=rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP000.TMP\"

"wextract_cleanup1"=rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP001.TMP\"

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]

"TSClientMSIUninstaller"=cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"

"tscuninstall"=%systemroot%\system32\tscupgrd.exe

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

"Free Download Manager"=E:\Program Files\Free Download Manager\fdm.exe -autorun

 

E:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

BTTray.lnk - E:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe [24/08/2005 14:06:54]

HP Digital Imaging Monitor.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [19/02/2006 04:21:22]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoRecentDocsHistory"=1 (0x1)

"ClearRecentDocsOnExit"=1 (0x1)

"NoRecentDocsMenu"=1 (0x1)

"NoInternetIcon"=1 (0x1)

"ForceClassicControlPanel"=1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NoRecentDocsHistory"=1 (0x1)

"ClearRecentDocsOnExit"=1 (0x1)

"NoRecentDocsMenu"=1 (0x1)

"NoInternetIcon"=1 (0x1)

"ForceClassicControlPanel"=1 (0x1)

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

"E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

E:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]

E:\Program Files\Free Download Manager\fdm.exe -autorun

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"E:\Program Files\iTunes\iTunesHelper.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]

"E:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

"E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

E:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

nwiz.exe /install

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

"E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

SOUNDMAN.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SRFirstRun]

rundll32 srclient.dll,CreateFirstRunRp

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"MDM"=2 (0x2)

"odserv"=3 (0x3)

"ose"=3 (0x3)

"idsvc"=3 (0x3)

"NMIndexingService"=3 (0x3)

"Nero BackItUp Scheduler 3"=2 (0x2)

"WMPNetworkSvc"=3 (0x3)

"RichVideo"=2 (0x2)

"NVSvc"=2 (0x2)

"iPod Service"=3 (0x3)

 

 

 

 

-- Hosts -----------------------------------------------------------------------

 

127.0.0.1 www.007guard.com

127.0.0.1 007guard.com

127.0.0.1 008i.com

127.0.0.1 www.008k.com

127.0.0.1 008k.com

127.0.0.1 www.00hq.com

127.0.0.1 00hq.com

127.0.0.1 010402.com

127.0.0.1 www.032439.com

127.0.0.1 032439.com

 

8684 more entries in hosts file.

 

 

-- End of Deckard's System Scanner: finished at 2008-07-05 14:16:28 ------------

 

Deckard's System Scanner v20071014.68

Extra logfile - please post this as an attachment with your post.

--------------------------------------------------------------------------------

 

-- System Information ----------------------------------------------------------

 

Microsoft Windows XP Professionnel (build 2600) SP 2.0

Architecture: X86; Language: French

 

CPU 0: AMD Sempron Processor 2600+

Percentage of Memory in Use: 67%

Physical Memory (total/avail): 447.23 MiB / 146.52 MiB

Pagefile Memory (total/avail): 1055.54 MiB / 656.95 MiB

Virtual Memory (total/avail): 2047.88 MiB / 1928.36 MiB

 

A: is Removable (No Media)

C: is Fixed (NTFS) - 24.45 GiB total, 17.62 GiB free.

D: is CDROM (No Media)

E: is Fixed (NTFS) - 51.87 GiB total, 36.04 GiB free.

 

\\.\PHYSICALDRIVE0 - Maxtor 6Y080P0 - 76.33 GiB - 2 partitions

\PARTITION0 - Étendu avec Inter. 13 étendue - 51.87 GiB - E:

\PARTITION1 (bootable) - Système de fichiers installable - 24.45 GiB - C:

 

 

 

-- Security Center -------------------------------------------------------------

 

AUOptions is scheduled to auto-install.

Windows Internal Firewall is enabled.

 

FirstRunDisabled is set.

AntiVirusDisableNotify is set.

FirewallDisableNotify is set.

UpdatesDisableNotify is set.

 

AV: Avira AntiVir PersonalEdition v8.0.1.15 (Avira GmbH)

 

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"E:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="E:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

 

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"E:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"="E:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"

"E:\\Program Files\\Mozilla Firefox\\firefox.exe"="E:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

"E:\\Program Files\\Steam\\steamapps\\ju_l_ia\\counter-strike source\\hl2.exe"="E:\\Program Files\\Steam\\steamapps\\ju_l_ia\\counter-strike source\\hl2.exe:*:Enabled:hl2"

"E:\\Program Files\\Steam\\Steam.exe"="E:\\Program Files\\Steam\\Steam.exe:*:Enabled:Steam"

"E:\\Program Files\\Steam\\steamapps\\pierrestar66\\counter-strike source\\hl2.exe"="E:\\Program Files\\Steam\\steamapps\\pierrestar66\\counter-strike source\\hl2.exe:*:Enabled:hl2"

"E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"E:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="E:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"E:\\WINDOWS\\system32\\dpvsetup.exe"="E:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"

"E:\\Program Files\\eMule\\eMule.exe"="E:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule"

"E:\\Program Files\\Orange HSS\\Connectivity\\ConnectivityManager.exe"="E:\\Program Files\\Orange HSS\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"

 

 

-- Environment Variables -------------------------------------------------------

 

ALLUSERSPROFILE=E:\Documents and Settings\All Users

APPDATA=E:\Documents and Settings\florent\Application Data

CLIENTNAME=Console

CommonProgramFiles=E:\Program Files\Fichiers communs

COMPUTERNAME=INTEGRA

ComSpec=E:\WINDOWS\system32\cmd.exe

FP_NO_HOST_CHECK=NO

HOMEDRIVE=E:

HOMEPATH=\Documents and Settings\florent

LOGONSERVER=\\INTEGRA

NUMBER_OF_PROCESSORS=1

OS=Windows_NT

Path=E:\WINDOWS\system32;E:\WINDOWS;E:\WINDOWS\system32\WBEM;E:\Program Files\Fichiers communs\Ahead\Lib\

PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

PROCESSOR_ARCHITECTURE=x86

PROCESSOR_IDENTIFIER=x86 Family 15 Model 44 Stepping 2, AuthenticAMD

PROCESSOR_LEVEL=15

PROCESSOR_REVISION=2c02

ProgramFiles=E:\Program Files

PROMPT=$P$G

SESSIONNAME=Console

SystemDrive=E:

SystemRoot=E:\WINDOWS

TEMP=E:\DOCUME~1\florent\LOCALS~1\Temp

TMP=E:\DOCUME~1\florent\LOCALS~1\Temp

USERDOMAIN=INTEGRA

USERNAME=florent

USERPROFILE=E:\Documents and Settings\florent

windir=E:\WINDOWS

 

 

-- User Profiles ---------------------------------------------------------------

 

Utilisateur1 (admin)

florent (admin)

Cindy (admin)

Kevin (admin)

Cindy_2 (admin)

 

 

-- Add/Remove Programs ---------------------------------------------------------

 

--> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER

--> E:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL

--> E:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL

--> E:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL

--> E:\WINDOWS\UNNeroShowTime.exe /UNINSTALL

--> E:\WINDOWS\UNNeroVision.exe /UNINSTALL

--> E:\WINDOWS\UNRecode.exe /UNINSTALL

--> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {957E4620-59C2-4D3E-9B6D-5F024803E7D8}

--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 E:\WINDOWS\INF\PCHealth.inf

Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}

Adobe Flash Player 9 ActiveX --> E:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete

Adobe Flash Player ActiveX --> E:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Reader 8.1.2 - Français --> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}

Adobe Shockwave Player --> E:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE E:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log

Assistant de connexion Windows Live --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}

Athlon 64 Processor Driver --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c

Avira AntiVir Personal – Free Antivirus --> E:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE

Barre d'outils Outlook de Windows Live (Windows Live Toolbar) --> MsiExec.exe /X{4002F73D-EBB3-4EA1-A2FF-DBCB4529759E}

Belkin Bluetooth Software --> MsiExec.exe /X{3F4EC965-28EF-45C3-B063-04B25D4E9679}

Bloqueur de fenêtres pop-up (Windows Live Toolbar) --> MsiExec.exe /X{51F366F4-C2E4-429A-866A-59C885ED42FD}

CCleaner (remove only) --> "E:\Program Files\CCleaner\uninst.exe"

DivX Codec --> E:\Program Files\DivX\DivXCodecUninstall.exe /CODEC

DivX Converter --> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER

DivX Player --> E:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER

DivX Web Player --> E:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN

Détecteur de flux Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{175B7C4A-CAF8-437A-B597-73E0D2D970FE}

EasyCleaner --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly

eMule --> "E:\Program Files\eMule\Uninstall.exe"

Extension de Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{D518AD32-C710-4616-BA0D-D4B1FA5F82E8}

Free Download Manager 2.0 --> "E:\Program Files\Free Download Manager\unins000.exe"

GamesBar 1.1.0.5 --> E:\Program Files\GamesBar\uninst.exe

HijackThis 2.0.2 --> "E:\Documents and Settings\florent\Bureau\HijackThis.exe" /uninstall

HP Customer Participation Program 7.0 --> E:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat

HP Imaging Device Functions 7.0 --> E:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat

HP Photosmart Essential --> MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}

HP Photosmart, Officejet and Deskjet 7.0.A --> E:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat

HP Software Update --> MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}

HP Solution Center 7.0 --> E:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat

Java 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}

Kaspersky Online Scanner --> E:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe

livebox --> E:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly

Malwarebytes' Anti-Malware --> "E:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"

Menus intelligents (Windows Live Toolbar) --> MsiExec.exe /X{3585ED1C-74C5-43B0-A232-831B96A12A2B}

Messenger Plus! Live & Sponsor (CiD) --> "E:\Program Files\Messenger Plus! Live\Uninstall.exe"

Microsoft Compression Client Pack 1.0 for Windows XP --> "E:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"

Microsoft Office Access MUI (French) 2007 --> MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}

Microsoft Office Excel MUI (French) 2007 --> MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (French) 2007 --> MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}

Microsoft Office Outlook MUI (French) 2007 --> MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (French) 2007 --> MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}

Microsoft Office Professional Plus 2007 --> "E:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL

Microsoft Office Professional Plus 2007 --> MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}

Microsoft Office Proof (Arabic) 2007 --> MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}

Microsoft Office Proof (Dutch) 2007 --> MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}

Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (German) 2007 --> MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (French) 2007 --> MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}

Microsoft Office Publisher MUI (French) 2007 --> MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}

Microsoft Office Shared MUI (French) 2007 --> MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}

Microsoft Office Word MUI (French) 2007 --> MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}

Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "E:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"

Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}

Mise à jour de sécurité pour Windows XP (KB923789) --> E:\WINDOWS\system32\MacroMed\Flash\genuinst.exe E:\WINDOWS\system32\MacroMed\Flash\KB923789.inf

Mozilla Firefox (3.0) --> E:\Program Files\Mozilla Firefox\uninstall\helper.exe

MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{1787603C-E6E3-42D4-8034-55F358486F1D}

Navigateur Orange --> E:\Program Files\Orange HSS\Uninstall\Browser\Shell.exe MainUninstall.shl

Navigation par onglets (Windows Live Toolbar) --> MsiExec.exe /X{E74559C2-BB47-45AD-83DD-0D66B67E7811}

Nero 7 Premium --> MsiExec.exe /X{22FB6750-ADDF-4726-B67F-6901E1991036}

neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}

NVIDIA Drivers --> E:\WINDOWS\system32\nvudisp.exe UninstallGUI

OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{F242B06B-517F-4D62-B654-16B11564A912}

Orange - Logiciels Internet --> E:\Program Files\Orange HSS\installation\core\Installgui.exe -u

PhotoFiltre --> "E:\Program Files\PhotoFiltre\Uninst.exe"

PowerDVD --> "E:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -l0x00040c /z-uninstall

Realtek AC'97 Audio --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly

Security Update for Excel 2007 (KB946974) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}

Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}

Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}

Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}

Security Update for Office 2007 (KB934062) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {305D509B-F194-4638-9F0F-D9E4C05F9D33}

Security Update for Office 2007 (KB947801) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}

Security Update for Outlook 2007 (KB946983) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}

Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86}

Spellforce - Diamond Edition --> MsiExec.exe /I{2CA13178-C16D-47A4-AA91-5441F57FF63E}

Spybot - Search & Destroy --> "E:\Program Files\Spybot - Search & Destroy\unins000.exe"

Update for Office 2007 (KB932080) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {EDC9CA29-6BC1-471C-828C-7A36109005D7}

Update for Office 2007 (KB934391) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5}

Update for Office 2007 (KB946691) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}

Update for Outlook 2007 Junk Email Filter (kb950378) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F6296086-AED5-4EC0-938B-08EA0254F20E}

VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}

VideoLAN VLC media player 0.8.6f --> E:\Program Files\VideoLAN\VLC\uninstall.exe

Windows Communication Foundation --> MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}

Windows Live Favorites pour Windows Live Toolbar --> MsiExec.exe /X{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}

Windows Live installer --> MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}

Windows Live Messenger --> MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

Windows Live OneCare safety scanner --> RunDll32.exe "E:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT

Windows Live Toolbar --> "E:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}

Windows Live Toolbar --> MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}

Windows Media Format 11 runtime -->

Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}

Windows Presentation Foundation Language Pack (FRA) --> MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}

Windows Workflow Foundation --> MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}

Windows Workflow Foundation FR Language Pack --> MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}

WinRAR archiver --> E:\Program Files\WinRar\uninstall.exe

XML Paper Specification Shared Components Language Pack 1.0 --> "E:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

XML Paper Specification Shared Components Pack 1.0 -->

Xvid 1.1.3 final uninstall --> "E:\Program Files\Xvid\unins000.exe"

Yahoo! Toolbar avec bloqueur de fenêtres pop-up --> E:\PROGRA~1\Yahoo!\Common\unyt.exe

 

 

-- Application Event Log -------------------------------------------------------

 

Event Record #/Type1314 / Success

Event Submitted/Written: 07/05/2008 01:03:54 PM

Event ID/Source: 12001 / usnjsvc

Event Description:

The Messenger Sharing USN Journal Reader service started successfully.

 

Event Record #/Type1305 / Success

Event Submitted/Written: 07/05/2008 00:06:13 PM

Event ID/Source: 12001 / usnjsvc

Event Description:

The Messenger Sharing USN Journal Reader service started successfully.

 

Event Record #/Type1289 / Warning

Event Submitted/Written: 07/04/2008 08:18:55 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050209.exe

 

Event Record #/Type1288 / Warning

Event Submitted/Written: 07/04/2008 08:18:49 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050208.exe

 

Event Record #/Type1287 / Warning

Event Submitted/Written: 07/04/2008 08:18:33 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP83\A0050109.exe

 

 

 

-- Security Event Log ----------------------------------------------------------

 

No Errors/Warnings found.

 

 

-- System Event Log ------------------------------------------------------------

 

Event Record #/Type6603 / Error

Event Submitted/Written: 07/05/2008 02:05:53 PM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6515 / Error

Event Submitted/Written: 07/05/2008 01:01:52 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6514 / Error

Event Submitted/Written: 07/05/2008 01:01:50 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6513 / Error

Event Submitted/Written: 07/05/2008 00:35:04 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6512 / Error

Event Submitted/Written: 07/05/2008 00:30:11 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

 

 

-- End of Deckard's System Scanner: finished at 2008-07-05 14:16:28 ------------

 

 

 

Deckard's System Scanner v20071014.68

Run by florent on 2008-07-05 14:14:06

Computer is in Normal Mode.

--------------------------------------------------------------------------------

 

-- System Restore --------------------------------------------------------------

 

Successfully created a Deckard's System Scanner Restore Point.

 

 

-- Last 4 Restore Point(s) --

4: 2008-07-05 12:14:12 UTC - RP86 - Deckard's System Scanner Restore Point

3: 2008-07-05 12:10:04 UTC - RP85 - Installé Windows Live Toolbar

2: 2008-07-03 18:40:25 UTC - RP84 - Point de vérification système

1: 2008-07-02 17:48:01 UTC - RP83 - Point de vérification système

 

 

Backed up registry hives.

Performed disk cleanup.

 

Total Physical Memory: 448 MiB (512 MiB recommended).

 

 

-- HijackThis (run as florent.exe) ---------------------------------------------

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:15:33, on 05/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

E:\WINDOWS\system32\spoolsv.exe

E:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

E:\WINDOWS\Explorer.EXE

E:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

E:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe

E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

E:\Program Files\HP\HP Software Update\HPWuSchd2.exe

E:\WINDOWS\SOUNDMAN.EXE

E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

E:\Program Files\Orange HSS\Systray\SystrayApp.exe

E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

E:\WINDOWS\system32\ctfmon.exe

E:\Program Files\Free Download Manager\fdm.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe

E:\Program Files\Windows Live\Messenger\msnmsgr.exe

E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

E:\WINDOWS\system32\nvsvc32.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\system32\rundll32.exe

E:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe

E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe

E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe

E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe

E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

E:\WINDOWS\system32\msiexec.exe

E:\Documents and Settings\florent\Bureau\dss.exe

E:\DOCUME~1\florent\Bureau\florent.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - E:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [avgnt] "E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [sunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [systrayORAHSS] "E:\Program Files\Orange HSS\Systray\SystrayApp.exe"

O4 - HKLM\..\Run: [ORAHSSSessionManager] E:\Program Files\Orange HSS\SessionManager\SessionManager.exe

O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP000.TMP\"

O4 - HKLM\..\RunOnce: [wextract_cleanup1] rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP001.TMP\"

O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Free Download Manager] E:\Program Files\Free Download Manager\fdm.exe -autorun

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [Free Download Manager] E:\Program Files\Free Download Manager\fdm.exe -autorun (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: &Windows Live Search - res://E:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Download all with Free Download Manager - file://E:\Program Files\Free Download Manager\dlall.htm

O8 - Extra context menu item: Download selected with Free Download Manager - file://E:\Program Files\Free Download Manager\dlselected.htm

O8 - Extra context menu item: Download web site with Free Download Manager - file://E:\Program Files\Free Download Manager\dlpage.htm

O8 - Extra context menu item: Download with Free Download Manager - file://E:\Program Files\Free Download Manager\dllink.htm

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)

O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - E:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.orange.fr

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -

O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O17 - HKLM\System\CS1\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O17 - HKLM\System\CS2\Services\Tcpip\..\{428C57B4-15BD-4570-B36A-E56FF8477C09}: NameServer = 80.10.246.2,80.10.246.129

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - E:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - E:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Boonty Games - BOONTY - E:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - E:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe

O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - E:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe

O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe

 

--

End of file - 11852 bytes

 

-- HijackThis Fixed Entries (E:\DOCUME~1\florent\Bureau\backups\) --------------

 

backup-20080602-210825-695 O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)

backup-20080701-173205-202 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

backup-20080701-173205-588 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

backup-20080701-173205-808 O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe

backup-20080701-173205-983 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\bdoscandel.exe (file missing)

backup-20080701-173206-219 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -

backup-20080701-173206-327 O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -

backup-20080701-173206-376 O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - E:\WINDOWS\bdoscandel.exe (file missing)

backup-20080701-173206-637 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - E:\Program Files\Yahoo!\Common\yinsthelper.dll

backup-20080701-173207-397 O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -

 

-- File Associations -----------------------------------------------------------

 

.reg - regfile - shell\open\command - regedit.exe "%1" %*

.scr - scrfile - shell\open\command - "%1" %*

 

 

-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

 

S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - e:\windows\system32\pcampr5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - e:\windows\system32\pcandis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

 

 

-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

 

R2 AntiVirScheduler (Avira AntiVir Personal – Free Antivirus Scheduler) - "e:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>

R2 FTRTSVC (France Telecom Routing Table Service) - "e:\progra~1\fichie~1\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe" <Not Verified; France Telecom SA; CSS-Corporate>

 

S3 Boonty Games - "e:\program files\fichiers communs\boonty shared\service\boonty.exe" <Not Verified; BOONTY; Boonty Games>

S3 NBService - e:\program files\nero\nero 7\nero backitup\nbservice.exe

 

 

-- Device Manager: Disabled ----------------------------------------------------

 

No disabled devices found.

 

 

-- Scheduled Tasks -------------------------------------------------------------

 

2008-07-05 14:10:16 258 --a------ E:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job

2008-07-05 02:00:00 276 --ah----- E:\WINDOWS\Tasks\A8723A5C9171AF64.job

 

 

-- Files created between 2008-06-05 and 2008-07-05 -----------------------------

 

2008-07-05 13:28:27 0 dr-h----- E:\Documents and Settings\Kevin\Recent

2008-07-04 20:46:29 0 dr-h----- E:\Documents and Settings\florent\Recent

2008-07-02 14:11:54 0 d-------- E:\Documents and Settings\All Users\Application Data\Kaspersky Lab

2008-07-02 14:11:52 0 d-------- E:\WINDOWS\system32\Kaspersky Lab

2008-07-01 20:44:53 0 d-------- E:\Documents and Settings\All Users\Application Data\Sandlot Games

2008-07-01 20:44:31 0 d--hs---- E:\WINDOWS\ftpcache

2008-07-01 20:44:15 0 d-a------ E:\Documents and Settings\All Users\Application Data\TEMP

2008-07-01 20:41:46 0 d-------- E:\Documents and Settings\All Users\Application Data\GamesBar

2008-07-01 20:40:53 0 d-------- E:\Program Files\GamesBar

2008-07-01 20:40:43 0 d-------- E:\Program Files\Fichiers communs\Oberon Media

2008-07-01 20:40:42 0 d-------- E:\Program Files\orange

2008-06-30 18:03:28 0 dr-h----- E:\Documents and Settings\Utilisateur1\Recent

2008-06-28 21:59:31 0 d-------- E:\Program Files\seconddoesboob

2008-06-28 18:36:45 0 d-------- E:\Documents and Settings\Kevin\Bluetooth Software

2008-06-28 17:31:48 0 d-------- E:\WINDOWS\system32\LogFiles

2008-06-28 10:56:23 0 d-------- E:\WINDOWS\BDOSCAN8

2008-06-28 10:37:04 0 d-------- E:\Program Files\Panda Security

2008-06-27 20:35:03 0 d-------- E:\WINDOWS\Sof??are????????tio???er????r?ceTe????re?????Tr?@eTe??M?i??Tr?@e????

2008-06-27 20:24:49 0 d-------- E:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site

2008-06-23 10:55:54 0 d-------- E:\Program Files\Windows Live Safety Center

2008-06-22 18:09:03 335 --a------ E:\WINDOWS\mozregistry.dat

2008-06-21 16:48:54 0 d-------- E:\327882R2FWJFW

2008-06-17 16:51:36 0 d-------- E:\Program Files\JoWooD

2008-06-14 13:23:54 0 d-------- E:\Program Files\Fichiers communs\Vbox

2008-06-14 13:12:37 0 d-------- E:\Documents and Settings\Kevin\Application Data\WinRAR

2008-06-12 09:11:28 0 d-------- E:\Documents and Settings\Kevin\Application Data\DivX

2008-06-12 09:11:26 0 d-------- E:\Documents and Settings\Kevin\Application Data\Media Player Classic

2008-06-11 22:52:18 0 d-------- E:\Program Files\Copernic Desktop Search 2

 

 

-- Find3M Report ---------------------------------------------------------------

 

2008-07-05 14:14:21 0 d-------- E:\Documents and Settings\florent\Application Data\Free Download Manager

2008-07-05 14:10:11 0 d-------- E:\Program Files\Windows Live Toolbar

2008-07-05 13:02:30 0 d-------- E:\Program Files\eMule

2008-07-01 20:40:43 0 d-------- E:\Program Files\Fichiers communs

2008-06-29 18:11:45 0 d-------- E:\Program Files\BoontyGames

2008-06-28 21:59:08 0 d-------- E:\Program Files\Messenger Plus! Live

2008-06-27 13:56:56 0 d-------- E:\Documents and Settings\florent\Application Data\Mozilla

2008-06-19 20:07:54 0 d-------- E:\Program Files\Malwarebytes' Anti-Malware

2008-06-15 17:22:44 0 d-------- E:\Program Files\Fichiers communs\Adobe

2008-06-15 17:22:23 0 d-------- E:\Documents and Settings\florent\Application Data\Adobe

2008-06-06 23:18:07 0 d-------- E:\Documents and Settings\florent\Application Data\HP

2008-06-02 19:38:49 0 d-------- E:\Documents and Settings\florent\Application Data\Malwarebytes

2008-06-01 22:50:50 0 d-------- E:\Documents and Settings\florent\Application Data\Ahead

2008-05-31 01:25:37 0 d-------- E:\Program Files\ToniArts

2008-05-31 01:25:35 0 d--h----- E:\Program Files\InstallShield Installation Information

2008-05-30 14:36:02 0 d-------- E:\Program Files\Lavasoft

2008-05-30 14:35:15 0 d-------- E:\Program Files\Fichiers communs\Wise Installation Wizard

2008-05-30 00:52:15 1409 --a------ E:\WINDOWS\mozver.dat

2008-05-29 16:29:44 0 d-------- E:\Program Files\PhotoFiltre

2008-05-29 14:03:52 0 d-------- E:\Program Files\Fichiers communs\Ahead

2008-05-29 13:59:36 0 d-------- E:\Program Files\Nero

2008-05-29 13:24:14 0 d-------- E:\Program Files\AskTBar

2008-05-29 03:11:24 0 d-------- E:\Program Files\Belkin

2008-05-28 17:25:22 0 d-------- E:\Program Files\Orange HSS

2008-05-28 17:22:41 0 d-------- E:\Program Files\Fichiers communs\France Telecom

2008-05-28 17:19:15 0 d-------- E:\Program Files\SAGEM

2008-05-28 17:19:04 0 d-------- E:\Documents and Settings\florent\Application Data\InstallShield

2008-05-28 17:18:45 0 d-------- E:\Program Files\Securitoo

2008-05-28 00:28:39 500894 --a------ E:\WINDOWS\system32\perfh00C.dat

2008-05-28 00:28:39 80800 --a------ E:\WINDOWS\system32\perfc00C.dat

2008-05-28 00:28:02 0 d-------- E:\Program Files\Zylom Games

2008-05-25 23:59:08 0 d--hs--c- E:\Program Files\Fichiers communs\WindowsLiveInstaller

2008-05-25 23:58:55 0 d-------- E:\Program Files\Windows Live

2008-05-25 22:05:13 0 d-------- E:\Program Files\CCleaner

2008-05-25 22:05:09 0 d-------- E:\Program Files\Yahoo!

2008-05-25 21:53:37 0 d-------- E:\Program Files\Windows Live Favorites

2008-05-25 12:44:59 0 d-------- E:\Program Files\Java

2008-05-25 12:44:11 0 d-------- E:\Program Files\Fichiers communs\Java

2008-05-25 11:46:02 0 d-------- E:\Program Files\AMD

2008-05-25 11:42:15 0 d-------- E:\Program Files\Realtek Sound Manager

2008-05-25 11:42:15 0 d-------- E:\Program Files\AvRack

2008-05-25 11:42:13 0 d-------- E:\Program Files\Realtek AC97

2008-05-25 11:39:26 0 d-------- E:\Program Files\Fichiers communs\InstallShield

2008-05-24 13:47:59 0 d-------- E:\Program Files\Fichiers communs\BOONTY Shared

2008-05-24 13:46:11 0 d-------- E:\Program Files\Boonty

2008-05-24 11:50:45 0 d-------- E:\Documents and Settings\florent\Application Data\Sun

2008-05-24 10:24:41 0 d-------- E:\Documents and Settings\florent\Application Data\WinRAR

2008-05-24 04:02:41 129310 --a------ E:\WINDOWS\hpoins11.dat

2008-05-24 04:01:57 0 d-------- E:\Program Files\Fichiers communs\HP

2008-05-24 04:01:54 0 d-------- E:\Program Files\HP

2008-05-24 03:57:34 0 d-------- E:\Program Files\Hewlett-Packard

2008-05-24 03:56:53 0 d-------- E:\Program Files\Fichiers communs\Hewlett-Packard

2008-05-24 01:50:28 0 d-------- E:\Program Files\Fichiers communs\Real

2008-05-24 01:50:27 0 d-------- E:\Documents and Settings\florent\Application Data\Real

2008-05-24 01:18:06 0 d-------- E:\Program Files\Avira

2008-05-24 00:29:07 0 d-------- E:\Documents and Settings\florent\Application Data\vlc

2008-05-24 00:24:54 0 d-------- E:\Program Files\VideoLAN

2008-05-23 23:58:23 60416 --a------ E:\WINDOWS\ALCFDRTM.EXE <Not Verified; Realtek Semiconductor Corp.; Realtek ALCFDRTM>

2008-05-23 23:45:33 0 d-------- E:\Program Files\DivX

2008-05-23 23:43:00 0 d-------- E:\Documents and Settings\florent\Application Data\Media Player Classic

2008-05-23 23:43:00 0 d-------- E:\Documents and Settings\florent\Application Data\DivX

2008-05-23 23:39:21 0 d-------- E:\Documents and Settings\florent\Application Data\CyberLink

2008-05-23 23:35:55 0 d-------- E:\Documents and Settings\florent\Application Data\Macromedia

2008-05-23 23:19:15 0 d-------- E:\Documents and Settings\florent\Application Data\Talkback

2008-05-23 23:18:02 0 d-------- E:\Documents and Settings\florent\Application Data\Identities

2008-05-23 22:44:14 0 --a------ E:\WINDOWS\nsreg.dat

2008-05-23 21:10:37 0 d-------- E:\Program Files\Fichiers communs\Nero

2008-05-23 20:33:30 0 d-------- E:\Program Files\msn gaming zone

2008-05-23 20:31:13 0 d-------- E:\Program Files\Movie Maker

2008-05-23 20:29:07 23032 --a------ E:\WINDOWS\system32\emptyregdb.dat

2008-05-23 20:28:35 0 d-------- E:\Program Files\Windows NT

2008-05-23 20:19:08 62 --ahs---- E:\Documents and Settings\florent\Application Data\desktop.ini

2008-05-23 18:53:33 0 d-------- E:\Program Files\AVG

2008-05-23 18:41:03 0 d-------- E:\Program Files\Xvid

2008-05-23 16:40:50 0 d-------- E:\Program Files\Fichiers communs\ODBC

2008-05-23 16:40:47 0 d-------- E:\Program Files\Fichiers communs\SpeechEngines

2008-05-23 15:40:56 0 d-------- E:\Program Files\Microsoft Works

2008-05-23 15:40:05 0 d-------- E:\Program Files\Microsoft.NET

2008-05-23 15:34:04 0 d-------- E:\Program Files\MSBuild

2008-05-23 15:28:28 0 d-------- E:\Program Files\Reference Assemblies

2008-05-23 15:12:42 0 d-------- E:\Program Files\microsoft frontpage

2008-05-23 15:12:10 0 d-------- E:\Program Files\Media Player Classic

2008-05-23 15:11:49 0 d-------- E:\Program Files\CyberLink

2008-05-23 15:09:12 0 d-------- E:\Program Files\Free Download Manager

2008-05-23 15:04:40 0 d-------- E:\Program Files\MSXML 6.0

2008-05-23 15:04:25 0 d-------- E:\Program Files\MSXML 4.0

2008-05-23 14:56:30 0 d-------- E:\Program Files\Windows Media Connect 2

2008-05-23 14:51:05 0 d--h----- E:\Program Files\WindowsUpdate

2008-05-23 14:51:00 0 d-------- E:\Program Files\Services en ligne

2008-05-23 14:50:10 0 d-------- E:\Program Files\Fichiers communs\MSSoap

2008-05-23 14:48:29 0 d-------- E:\Program Files\Messenger

2008-05-13 03:53:16 3596288 --a------ E:\WINDOWS\system32\qt-dx331.dll

2008-05-13 03:50:16 196608 --a------ E:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>

2008-05-13 03:50:16 81920 --a------ E:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>

2008-05-13 03:50:08 802816 --a------ E:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>

2008-05-13 03:50:08 823296 --a------ E:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:50:08 831488 --a------ E:\WINDOWS\system32\divx_xx0a.dll

2008-05-13 03:50:08 823296 --a------ E:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:50:06 682496 --a------ E:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>

2008-05-13 03:49:02 12288 --a------ E:\WINDOWS\system32\DivXWMPExtType.dll

 

 

-- Registry Dump ---------------------------------------------------------------

 

*Note* empty entries & legit default entries are not shown

 

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]

19/06/2007 17:09 380928 --a------ E:\Program Files\GamesBar\oberontb.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [10/10/2005 15:49]

"nwiz"="nwiz.exe" [10/10/2005 15:49 E:\WINDOWS\system32\nwiz.exe]

"avgnt"="E:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [12/02/2008 10:06]

"HP Software Update"="E:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [19/02/2006 02:41]

"SoundMan"="SOUNDMAN.EXE" [22/09/2005 10:42 E:\WINDOWS\SOUNDMAN.EXE]

"NvMediaCenter"="E:\WINDOWS\system32\NvMcTray.dll" [10/10/2005 15:49]

"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [25/03/2008 04:28]

"SystrayORAHSS"="E:\Program Files\Orange HSS\Systray\SystrayApp.exe" [24/07/2007 19:55]

"ORAHSSSessionManager"="E:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [24/07/2007 19:03]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="E:\WINDOWS\system32\ctfmon.exe" [05/08/2004 14:00]

"Free Download Manager"="E:\Program Files\Free Download Manager\fdm.exe" [29/04/2006 10:22]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="E:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [22/01/2008 10:13]

"msnmsgr"="E:\Program Files\Windows Live\Messenger\msnmsgr.exe" [18/10/2007 11:34]

"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]

"wextract_cleanup0"=rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP000.TMP\"

"wextract_cleanup1"=rundll32.exe E:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\florent\LOCALS~1\Temp\IXP001.TMP\"

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]

"TSClientMSIUninstaller"=cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"

"tscuninstall"=%systemroot%\system32\tscupgrd.exe

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

"Free Download Manager"=E:\Program Files\Free Download Manager\fdm.exe -autorun

 

E:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

BTTray.lnk - E:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe [24/08/2005 14:06:54]

HP Digital Imaging Monitor.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [19/02/2006 04:21:22]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoRecentDocsHistory"=1 (0x1)

"ClearRecentDocsOnExit"=1 (0x1)

"NoRecentDocsMenu"=1 (0x1)

"NoInternetIcon"=1 (0x1)

"ForceClassicControlPanel"=1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NoRecentDocsHistory"=1 (0x1)

"ClearRecentDocsOnExit"=1 (0x1)

"NoRecentDocsMenu"=1 (0x1)

"NoInternetIcon"=1 (0x1)

"ForceClassicControlPanel"=1 (0x1)

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

"E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

E:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]

E:\Program Files\Free Download Manager\fdm.exe -autorun

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

"E:\Program Files\iTunes\iTunesHelper.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]

"E:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

"E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

E:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

nwiz.exe /install

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

"E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

SOUNDMAN.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SRFirstRun]

rundll32 srclient.dll,CreateFirstRunRp

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"MDM"=2 (0x2)

"odserv"=3 (0x3)

"ose"=3 (0x3)

"idsvc"=3 (0x3)

"NMIndexingService"=3 (0x3)

"Nero BackItUp Scheduler 3"=2 (0x2)

"WMPNetworkSvc"=3 (0x3)

"RichVideo"=2 (0x2)

"NVSvc"=2 (0x2)

"iPod Service"=3 (0x3)

 

 

 

 

-- Hosts -----------------------------------------------------------------------

 

127.0.0.1 www.007guard.com

127.0.0.1 007guard.com

127.0.0.1 008i.com

127.0.0.1 www.008k.com

127.0.0.1 008k.com

127.0.0.1 www.00hq.com

127.0.0.1 00hq.com

127.0.0.1 010402.com

127.0.0.1 www.032439.com

127.0.0.1 032439.com

 

8684 more entries in hosts file.

 

 

-- End of Deckard's System Scanner: finished at 2008-07-05 14:16:28 ------------

 

Deckard's System Scanner v20071014.68

Extra logfile - please post this as an attachment with your post.

--------------------------------------------------------------------------------

 

-- System Information ----------------------------------------------------------

 

Microsoft Windows XP Professionnel (build 2600) SP 2.0

Architecture: X86; Language: French

 

CPU 0: AMD Sempron Processor 2600+

Percentage of Memory in Use: 67%

Physical Memory (total/avail): 447.23 MiB / 146.52 MiB

Pagefile Memory (total/avail): 1055.54 MiB / 656.95 MiB

Virtual Memory (total/avail): 2047.88 MiB / 1928.36 MiB

 

A: is Removable (No Media)

C: is Fixed (NTFS) - 24.45 GiB total, 17.62 GiB free.

D: is CDROM (No Media)

E: is Fixed (NTFS) - 51.87 GiB total, 36.04 GiB free.

 

\\.\PHYSICALDRIVE0 - Maxtor 6Y080P0 - 76.33 GiB - 2 partitions

\PARTITION0 - Étendu avec Inter. 13 étendue - 51.87 GiB - E:

\PARTITION1 (bootable) - Système de fichiers installable - 24.45 GiB - C:

 

 

 

-- Security Center -------------------------------------------------------------

 

AUOptions is scheduled to auto-install.

Windows Internal Firewall is enabled.

 

FirstRunDisabled is set.

AntiVirusDisableNotify is set.

FirewallDisableNotify is set.

UpdatesDisableNotify is set.

 

AV: Avira AntiVir PersonalEdition v8.0.1.15 (Avira GmbH)

 

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"E:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="E:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

 

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"E:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"="E:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"

"E:\\Program Files\\Mozilla Firefox\\firefox.exe"="E:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"

"E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

"E:\\Program Files\\Steam\\steamapps\\ju_l_ia\\counter-strike source\\hl2.exe"="E:\\Program Files\\Steam\\steamapps\\ju_l_ia\\counter-strike source\\hl2.exe:*:Enabled:hl2"

"E:\\Program Files\\Steam\\Steam.exe"="E:\\Program Files\\Steam\\Steam.exe:*:Enabled:Steam"

"E:\\Program Files\\Steam\\steamapps\\pierrestar66\\counter-strike source\\hl2.exe"="E:\\Program Files\\Steam\\steamapps\\pierrestar66\\counter-strike source\\hl2.exe:*:Enabled:hl2"

"E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"E:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="E:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"E:\\WINDOWS\\system32\\dpvsetup.exe"="E:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"

"E:\\Program Files\\eMule\\eMule.exe"="E:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule"

"E:\\Program Files\\Orange HSS\\Connectivity\\ConnectivityManager.exe"="E:\\Program Files\\Orange HSS\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"

 

 

-- Environment Variables -------------------------------------------------------

 

ALLUSERSPROFILE=E:\Documents and Settings\All Users

APPDATA=E:\Documents and Settings\florent\Application Data

CLIENTNAME=Console

CommonProgramFiles=E:\Program Files\Fichiers communs

COMPUTERNAME=INTEGRA

ComSpec=E:\WINDOWS\system32\cmd.exe

FP_NO_HOST_CHECK=NO

HOMEDRIVE=E:

HOMEPATH=\Documents and Settings\florent

LOGONSERVER=\\INTEGRA

NUMBER_OF_PROCESSORS=1

OS=Windows_NT

Path=E:\WINDOWS\system32;E:\WINDOWS;E:\WINDOWS\system32\WBEM;E:\Program Files\Fichiers communs\Ahead\Lib\

PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

PROCESSOR_ARCHITECTURE=x86

PROCESSOR_IDENTIFIER=x86 Family 15 Model 44 Stepping 2, AuthenticAMD

PROCESSOR_LEVEL=15

PROCESSOR_REVISION=2c02

ProgramFiles=E:\Program Files

PROMPT=$P$G

SESSIONNAME=Console

SystemDrive=E:

SystemRoot=E:\WINDOWS

TEMP=E:\DOCUME~1\florent\LOCALS~1\Temp

TMP=E:\DOCUME~1\florent\LOCALS~1\Temp

USERDOMAIN=INTEGRA

USERNAME=florent

USERPROFILE=E:\Documents and Settings\florent

windir=E:\WINDOWS

 

 

-- User Profiles ---------------------------------------------------------------

 

Utilisateur1 (admin)

florent (admin)

Cindy (admin)

Kevin (admin)

Cindy_2 (admin)

 

 

-- Add/Remove Programs ---------------------------------------------------------

 

--> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER

--> E:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL

--> E:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL

--> E:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL

--> E:\WINDOWS\UNNeroShowTime.exe /UNINSTALL

--> E:\WINDOWS\UNNeroVision.exe /UNINSTALL

--> E:\WINDOWS\UNRecode.exe /UNINSTALL

--> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {957E4620-59C2-4D3E-9B6D-5F024803E7D8}

--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 E:\WINDOWS\INF\PCHealth.inf

Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}

Adobe Flash Player 9 ActiveX --> E:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete

Adobe Flash Player ActiveX --> E:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Reader 8.1.2 - Français --> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}

Adobe Shockwave Player --> E:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE E:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log

Assistant de connexion Windows Live --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}

Athlon 64 Processor Driver --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c

Avira AntiVir Personal – Free Antivirus --> E:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE

Barre d'outils Outlook de Windows Live (Windows Live Toolbar) --> MsiExec.exe /X{4002F73D-EBB3-4EA1-A2FF-DBCB4529759E}

Belkin Bluetooth Software --> MsiExec.exe /X{3F4EC965-28EF-45C3-B063-04B25D4E9679}

Bloqueur de fenêtres pop-up (Windows Live Toolbar) --> MsiExec.exe /X{51F366F4-C2E4-429A-866A-59C885ED42FD}

CCleaner (remove only) --> "E:\Program Files\CCleaner\uninst.exe"

DivX Codec --> E:\Program Files\DivX\DivXCodecUninstall.exe /CODEC

DivX Converter --> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER

DivX Player --> E:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER

DivX Web Player --> E:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN

Détecteur de flux Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{175B7C4A-CAF8-437A-B597-73E0D2D970FE}

EasyCleaner --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly

eMule --> "E:\Program Files\eMule\Uninstall.exe"

Extension de Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{D518AD32-C710-4616-BA0D-D4B1FA5F82E8}

Free Download Manager 2.0 --> "E:\Program Files\Free Download Manager\unins000.exe"

GamesBar 1.1.0.5 --> E:\Program Files\GamesBar\uninst.exe

HijackThis 2.0.2 --> "E:\Documents and Settings\florent\Bureau\HijackThis.exe" /uninstall

HP Customer Participation Program 7.0 --> E:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat

HP Imaging Device Functions 7.0 --> E:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat

HP Photosmart Essential --> MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}

HP Photosmart, Officejet and Deskjet 7.0.A --> E:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat

HP Software Update --> MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}

HP Solution Center 7.0 --> E:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat

Java 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}

Kaspersky Online Scanner --> E:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe

livebox --> E:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly

Malwarebytes' Anti-Malware --> "E:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"

Menus intelligents (Windows Live Toolbar) --> MsiExec.exe /X{3585ED1C-74C5-43B0-A232-831B96A12A2B}

Messenger Plus! Live & Sponsor (CiD) --> "E:\Program Files\Messenger Plus! Live\Uninstall.exe"

Microsoft Compression Client Pack 1.0 for Windows XP --> "E:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"

Microsoft Office Access MUI (French) 2007 --> MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}

Microsoft Office Excel MUI (French) 2007 --> MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (French) 2007 --> MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}

Microsoft Office Outlook MUI (French) 2007 --> MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (French) 2007 --> MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}

Microsoft Office Professional Plus 2007 --> "E:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL

Microsoft Office Professional Plus 2007 --> MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}

Microsoft Office Proof (Arabic) 2007 --> MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}

Microsoft Office Proof (Dutch) 2007 --> MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}

Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (German) 2007 --> MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (French) 2007 --> MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}

Microsoft Office Publisher MUI (French) 2007 --> MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}

Microsoft Office Shared MUI (French) 2007 --> MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}

Microsoft Office Word MUI (French) 2007 --> MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}

Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "E:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"

Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}

Mise à jour de sécurité pour Windows XP (KB923789) --> E:\WINDOWS\system32\MacroMed\Flash\genuinst.exe E:\WINDOWS\system32\MacroMed\Flash\KB923789.inf

Mozilla Firefox (3.0) --> E:\Program Files\Mozilla Firefox\uninstall\helper.exe

MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{1787603C-E6E3-42D4-8034-55F358486F1D}

Navigateur Orange --> E:\Program Files\Orange HSS\Uninstall\Browser\Shell.exe MainUninstall.shl

Navigation par onglets (Windows Live Toolbar) --> MsiExec.exe /X{E74559C2-BB47-45AD-83DD-0D66B67E7811}

Nero 7 Premium --> MsiExec.exe /X{22FB6750-ADDF-4726-B67F-6901E1991036}

neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}

NVIDIA Drivers --> E:\WINDOWS\system32\nvudisp.exe UninstallGUI

OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{F242B06B-517F-4D62-B654-16B11564A912}

Orange - Logiciels Internet --> E:\Program Files\Orange HSS\installation\core\Installgui.exe -u

PhotoFiltre --> "E:\Program Files\PhotoFiltre\Uninst.exe"

PowerDVD --> "E:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -l0x00040c /z-uninstall

Realtek AC'97 Audio --> RunDll32 E:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly

Security Update for Excel 2007 (KB946974) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}

Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}

Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}

Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}

Security Update for Office 2007 (KB934062) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {305D509B-F194-4638-9F0F-D9E4C05F9D33}

Security Update for Office 2007 (KB947801) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}

Security Update for Outlook 2007 (KB946983) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}

Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86}

Spellforce - Diamond Edition --> MsiExec.exe /I{2CA13178-C16D-47A4-AA91-5441F57FF63E}

Spybot - Search & Destroy --> "E:\Program Files\Spybot - Search & Destroy\unins000.exe"

Update for Office 2007 (KB932080) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {EDC9CA29-6BC1-471C-828C-7A36109005D7}

Update for Office 2007 (KB934391) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5}

Update for Office 2007 (KB946691) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}

Update for Outlook 2007 Junk Email Filter (kb950378) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F6296086-AED5-4EC0-938B-08EA0254F20E}

VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}

VideoLAN VLC media player 0.8.6f --> E:\Program Files\VideoLAN\VLC\uninstall.exe

Windows Communication Foundation --> MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}

Windows Live Favorites pour Windows Live Toolbar --> MsiExec.exe /X{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}

Windows Live installer --> MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}

Windows Live Messenger --> MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

Windows Live OneCare safety scanner --> RunDll32.exe "E:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT

Windows Live Toolbar --> "E:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}

Windows Live Toolbar --> MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}

Windows Media Format 11 runtime -->

Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}

Windows Presentation Foundation Language Pack (FRA) --> MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}

Windows Workflow Foundation --> MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}

Windows Workflow Foundation FR Language Pack --> MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}

WinRAR archiver --> E:\Program Files\WinRar\uninstall.exe

XML Paper Specification Shared Components Language Pack 1.0 --> "E:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

XML Paper Specification Shared Components Pack 1.0 -->

Xvid 1.1.3 final uninstall --> "E:\Program Files\Xvid\unins000.exe"

Yahoo! Toolbar avec bloqueur de fenêtres pop-up --> E:\PROGRA~1\Yahoo!\Common\unyt.exe

 

 

-- Application Event Log -------------------------------------------------------

 

Event Record #/Type1314 / Success

Event Submitted/Written: 07/05/2008 01:03:54 PM

Event ID/Source: 12001 / usnjsvc

Event Description:

The Messenger Sharing USN Journal Reader service started successfully.

 

Event Record #/Type1305 / Success

Event Submitted/Written: 07/05/2008 00:06:13 PM

Event ID/Source: 12001 / usnjsvc

Event Description:

The Messenger Sharing USN Journal Reader service started successfully.

 

Event Record #/Type1289 / Warning

Event Submitted/Written: 07/04/2008 08:18:55 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050209.exe

 

Event Record #/Type1288 / Warning

Event Submitted/Written: 07/04/2008 08:18:49 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP84\A0050208.exe

 

Event Record #/Type1287 / Warning

Event Submitted/Written: 07/04/2008 08:18:33 PM

Event ID/Source: 4113 / Avira AntiVir

Event Description:

TR/Dldr.Swizzor.GenE:\System Volume Information\_restore{85CE1B43-63F5-469A-9D90-2B103B807E25}\RP83\A0050109.exe

 

 

 

-- Security Event Log ----------------------------------------------------------

 

No Errors/Warnings found.

 

 

-- System Event Log ------------------------------------------------------------

 

Event Record #/Type6603 / Error

Event Submitted/Written: 07/05/2008 02:05:53 PM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6515 / Error

Event Submitted/Written: 07/05/2008 01:01:52 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6514 / Error

Event Submitted/Written: 07/05/2008 01:01:50 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6513 / Error

Event Submitted/Written: 07/05/2008 00:35:04 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

Event Record #/Type6512 / Error

Event Submitted/Written: 07/05/2008 00:30:11 AM

Event ID/Source: 10005 / DCOM

Event Description:

DCOM a reçu l'erreur "%%1058" lors de la mise en route du service MDM avec les arguments ""

pour démarrer le serveur :

{0C0A3666-30C9-11D0-8F20-00805F2CD064}

 

 

 

-- End of Deckard's System Scanner: finished at 2008-07-05 14:16:28 ------------

 

 

Posté(e)

t'avais pas besoin de poster 2 fois le rapport à suivre :P

 

Ok , j'ai vu les intrus !

 

• désactiver TeaTimer::

 

Pour désactiver TeaTimer :

 

Afficher d'abord le Mode Avancé dans SpyBot

 

Options Avancées :

- menu Mode, Mode Avancé.

 

Une colonne de menus apparaît dans la partie gauche :

 

- cliquer sur Outils,

- cliquer sur Résident,

Dans Résident :

- décocher Résident "TeaTimer" pour le désactiver. Ne le réactive plus , il sert à rien et au contraire empeche toutes desinfections car tu ne sais pas quoi autoriser ou refuser!!!!!!!!!!!!!!

 

 

• desinstalle Gamesbar via ajout\suppression de programmes ainsi que Kaspersky Online Scanner

 

• relance HijackThis "do a system scan only" ,coche les lignes ci dessous et clic Fixchecked;

 

 

O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - E:\Program Files\GamesBar\oberontb.dll

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -

O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} -

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -

 

==> clic Fixchecked

 

• Télécharger OTMoveIt2 par OldTimer.

 

http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

 

* Enregistrer ce fichier sur le Bureau.

* Faire un double clic sur OTMoveIt2.exe pour lancer l'exécution de l'outil. (Note: Si vous utilisez Vista, faire un clic droit sur le fichier puis choisir Exécuter en tant qu'administrateur).

* Copier les lignes de la zone "Code" ci-dessous dans le Presse-papiers en les sélectionnant TOUTES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier):

E:\WINDOWS\Tasks\A8723A5C9171AF64.job
E:\Documents and Settings\All Users\Application Data\GamesBar
E:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site
E:\Program Files\AskTBar
E:\Program Files\GamesBar
EmptyTemp

* Retourner dans la fenêtre de OTMoveIt2, faire un clic droit dans la zone "Paste List of Files/Folders to Move" ) puis choisir Coller.

* Cliquer sur le bouton rouge Moveit!.

* Copier tout ce qui se trouve dans la zone Results (sous la barre verte) dans le Presse-papiers en sélectionnant TOUTES LES LIGNES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier), et coller ces résulats en réponse sur le forum.

* Fermer OTMoveIt2

 

Note: Si un fichier ou un dossier ne peut pas être déplacé immédiatement, un redémarrage sera peut-être nécessaire afin de terminer le processus de déplacement. Si le redémarrage de la machine vous est demandé, choisir Oui/Yes. Dans ce cas, après le redémarrage, ouvrir le Bloc-notes (Démarrer->Tous les programmes->Accessoires->Bloc-notes), cliquer sur Fichier->Ouvrir, dans la zone "Nom du fichier" taper *.log et appuyer sur la touche Entrée, naviguer jusqu'au dossier C:\_OTMoveIt\MovedFiles, puis ouvrir le fichier .log le plus récent; ensuite faire un copier/coller du contenu de ce document en réponse sur le forum avec un nouveau rapport DSS(1 seule fois :P )

Posté(e)

E:\WINDOWS\Tasks\A8723A5C9171AF64.job moved successfully.

E:\Documents and Settings\All Users\Application Data\GamesBar\08-07-05-12-12-22 moved successfully.

E:\Documents and Settings\All Users\Application Data\GamesBar moved successfully.

E:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site moved successfully.

E:\Program Files\AskTBar\bar\History moved successfully.

E:\Program Files\AskTBar\bar moved successfully.

E:\Program Files\AskTBar moved successfully.

File/Folder E:\Program Files\GamesBar not found.

< EmptyTemp >

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\MPC8.tmp scheduled to be deleted on reboot.

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\~DFF0E6.tmp scheduled to be deleted on reboot.

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\~DFF0F8.tmp scheduled to be deleted on reboot.

Temp folders emptied.

IE temp folders emptied.

 

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07052008_165847

Posté(e)

E:\WINDOWS\Tasks\A8723A5C9171AF64.job moved successfully.

E:\Documents and Settings\All Users\Application Data\GamesBar\08-07-05-12-12-22 moved successfully.

E:\Documents and Settings\All Users\Application Data\GamesBar moved successfully.

E:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site moved successfully.

E:\Program Files\AskTBar\bar\History moved successfully.

E:\Program Files\AskTBar\bar moved successfully.

E:\Program Files\AskTBar moved successfully.

File/Folder E:\Program Files\GamesBar not found.

< EmptyTemp >

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\MPC8.tmp scheduled to be deleted on reboot.

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\~DFF0E6.tmp scheduled to be deleted on reboot.

File delete failed. E:\DOCUME~1\florent\LOCALS~1\Temp\~DFF0F8.tmp scheduled to be deleted on reboot.

Temp folders emptied.

IE temp folders emptied.

 

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07052008_165847

 

Files moved on Reboot...

E:\DOCUME~1\florent\LOCALS~1\Temp\hpodvd09.log moved successfully.

File E:\DOCUME~1\florent\LOCALS~1\Temp\MPC8.tmp not found!

File E:\DOCUME~1\florent\LOCALS~1\Temp\~DFF0E6.tmp not found!

File E:\DOCUME~1\florent\LOCALS~1\Temp\~DFF0F8.tmp not found!

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...