> Tous les forums > Forum Sécurité
 résultat de scan incompréhensibleSujet résolu
Ajouter un message à la discussion
Pages : [1] 2 3 ... Fin
Page 1 sur 3 [Fin]
Sunchild
  Posté le 06/02/2009 @ 16:32 
Aller en bas de la page 
Astucien

bonjour a tous,

je viens de faire un scan avec mcafee security center 2009 et je comprend pas quelque chose...

il m'a détecter 2 chevaux de trois (je pense) et me les a mis en quarantaine... hors ce n'est pas mon souhait ! je veus les supprimer définitivement de l'ordinateur !

habituellement je fais un scan toute les semaines avec malwarebytes, spyware terminator et mcafee. et tout les jours je passe un coup ccleaner et tuneup utilities 2009...

pourriez-vous m'aider a vérifier que mon ordinateur est propre s'il vous plait ?

dois-je vous fournir un rapport hitjacthis ?

merci pour votre aide et bonne fin de journée...

Publicité
philae
 Posté le 06/02/2009 à 17:02 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

bonjour,

il a mis en quarantaine, mais personne ne t'empêche maintenant de supprimer ta quarantaine (la vider en fait)

pour vérifier que ton pc est propre fait ceci :

Télécharge random's system information tool (RSIT) par random/random
TUTO

et sauvegarde-le sur le Bureau.

  • Double-clique sur RSIT.exe afin de lancer RSIT
  • Clique Continue à l'écran Disclaimer.
  • Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSITle téléchargera et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

Malwarebyte's ..........as tu fait un scan récemment ? a t il trouvé quelque chose ?

Sunchild
 Posté le 06/02/2009 à 17:37 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

ok merci mais je ne trouve pas ou se est le dossier des quarantaines ?

voici le rapport :

Logfile of random's system information tool 1.05 (written by random/random)
Run by Sunchild at 2009-02-06 17:32:09
Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
System drive C: has 63 GB (63%) free of 100 GB
Total RAM: 2047 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:32:46, on 06/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Sunchild\AppData\Local\Temp\installer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRA~2\Stardock\XGF\XGFRuntimeServer.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Sunchild\Desktop\RSIT.exe
C:\Program Files\trend micro\Sunchild.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Glass2k] C:\Users\Sunchild\AppData\Local\Temp\installer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-2075412193-173588390-2415456530-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Accès Limité')
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\sunchild\appdata\local\temp\WLZ1FB0.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\sunchild\appdata\local\temp\WLZ1FB0.SH! (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe

--
End of file - 8170 bytes

======Scheduled tasks folder======

C:\Windows\tasks\défragmentation.job
C:\Windows\tasks\Maintenance en 1 clic.job
C:\Windows\tasks\Malwarebytes' Scheduled Scan for Sunchild.job
C:\Windows\tasks\Malwarebytes' Scheduled Update for Sunchild.job
C:\Windows\tasks\McDefragTask.job
C:\Windows\tasks\McQcTask.job
C:\Windows\tasks\quickclean.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2008-10-29 1193984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\PROGRA~1\mcafee\msk\mskapbho.dll [2008-10-17 247312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll [2008-06-20 58688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-11-14 150032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-11-14 150032]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Barre d'outils &Crawler - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2008-10-29 1193984]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Glass2k"=C:\Users\Sunchild\AppData\Local\Temp\installer.exe [2009-01-31 56325]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-01-15 13683232]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-01-15 92704]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-01-14 399504]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2009-01-30 1783808]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-09-18 333120]
"WPCUMI"=C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-04-11 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-03-19 630784]
"ccleaner"=C:\Program Files\CCleaner\ccleaner.exe [2008-12-19 1434864]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-04-11 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2007-07-20 233888]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26717980-efb6-11dd-8ca6-001d7d79cfc9}]
shell\AutoRun\command - H:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a71b11fd-eef7-11dd-847c-001d7d79cfc9}]
shell\AutoRun\command - a1.bat
shell\explore\command - a1.bat
shell\open\command - a1.bat


======List of files/folders created in the last 1 months======

2009-02-06 17:32:09 ----D---- C:\rsit
2009-02-06 17:32:09 ----D---- C:\Program Files\trend micro
2009-02-06 14:33:20 ----A---- C:\Windows\ntbtlog.txt
2009-02-05 15:46:04 ----D---- C:\Program Files\OpenOffice.org 3
2009-02-03 20:03:15 ----D---- C:\Windows\Easy CD-DA Extractor
2009-02-03 20:03:14 ----D---- C:\Program Files\Easy CD-DA Extractor 10
2009-02-03 16:05:27 ----D---- C:\ProgramData\Stardock
2009-02-03 13:06:27 ----D---- C:\Program Files\adslTV
2009-02-01 17:46:58 ----D---- C:\Users\Sunchild\AppData\Roaming\Thunderbird
2009-02-01 17:46:50 ----D---- C:\Program Files\Mozilla Thunderbird
2009-02-01 13:57:45 ----D---- C:\ProgramData\LightScribe
2009-02-01 13:57:14 ----D---- C:\Users\Sunchild\AppData\Roaming\Nero
2009-01-31 23:52:43 ----D---- C:\Program Files\VDOWNLOADER
2009-01-31 23:10:44 ----D---- C:\Windows\system32\AGEIA
2009-01-31 23:10:10 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-31 23:09:53 ----A---- C:\Windows\system32\nvcpluir.dll
2009-01-31 23:09:53 ----A---- C:\Windows\system32\nvcplui.exe
2009-01-31 23:06:56 ----D---- C:\NVIDIA
2009-01-31 22:20:38 ----D---- C:\Program Files\CodeGazer
2009-01-31 20:48:00 ----D---- C:\ProgramData\Messenger Plus!
2009-01-31 20:47:09 ----D---- C:\Program Files\Circle Developement
2009-01-31 20:47:07 ----D---- C:\Program Files\Messenger Plus! Live
2009-01-31 20:27:48 ----D---- C:\ProgramData\eMule
2009-01-31 20:18:12 ----D---- C:\Users\Sunchild\AppData\Roaming\Adobe
2009-01-31 19:26:21 ----D---- C:\Program Files\AGEIA Technologies
2009-01-31 19:24:53 ----A---- C:\Windows\system32\NVUNINST.EXE
2009-01-31 19:04:41 ----D---- C:\ProgramData\ma-config.com
2009-01-31 19:04:41 ----D---- C:\Program Files\ma-config.com
2009-01-31 17:58:11 ----A---- C:\Windows\system32\uxtuneup.dll
2009-01-31 17:58:11 ----A---- C:\Windows\system32\TUProgSt.exe
2009-01-31 17:58:11 ----A---- C:\Windows\system32\authuitu.dll
2009-01-31 17:58:08 ----A---- C:\Windows\system32\TuneUpDefragService.exe
2009-01-31 17:56:01 ----D---- C:\Users\Sunchild\AppData\Roaming\TuneUp Software
2009-01-31 17:55:38 ----D---- C:\Program Files\TuneUp Utilities 2009
2009-01-31 17:55:36 ----D---- C:\ProgramData\TuneUp Software
2009-01-31 17:54:53 ----SHD---- C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
2009-01-31 17:46:11 ----D---- C:\Program Files\eMule
2009-01-31 17:43:16 ----D---- C:\Program Files\Alcohol Soft
2009-01-31 17:33:26 ----D---- C:\Program Files\MSXML 4.0
2009-01-31 12:37:16 ----D---- C:\Users\Sunchild\AppData\Roaming\vlc
2009-01-30 22:31:20 ----D---- C:\Users\Sunchild\AppData\Roaming\Macromedia
2009-01-30 22:31:16 ----D---- C:\Users\Sunchild\AppData\Roaming\ItsLabel
2009-01-30 22:17:31 ----D---- C:\Program Files\RocketDock
2009-01-30 22:09:39 ----D---- C:\Program Files\WinRAR
2009-01-30 22:02:54 ----D---- C:\Users\Sunchild\AppData\Roaming\Mozilla
2009-01-30 22:02:29 ----D---- C:\Program Files\Mozilla Firefox
2009-01-30 21:51:00 ----N---- C:\Windows\system32\vxblock.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxwave.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxsfs.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxmas.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxinsa64.exe
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxhpinst.exe
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxdrv.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxcpya64.exe
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxafs.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\px.dll
2009-01-30 21:50:58 ----D---- C:\Users\Sunchild\AppData\Roaming\Winamp
2009-01-30 21:50:58 ----D---- C:\Program Files\Winamp
2009-01-30 21:48:05 ----D---- C:\Windows\system32\Macromed
2009-01-30 21:47:59 ----D---- C:\Users\Sunchild\AppData\Roaming\EoRezo
2009-01-30 21:00:07 ----A---- C:\Windows\Irremote.ini
2009-01-30 20:29:08 ----D---- C:\Program Files\Nero
2009-01-30 20:28:10 ----D---- C:\ProgramData\Nero
2009-01-30 20:28:09 ----D---- C:\Program Files\Common Files\Nero
2009-01-30 20:27:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-01-30 20:26:37 ----D---- C:\Program Files\Common Files\LightScribe
2009-01-30 19:26:40 ----D---- C:\Program Files\Microsoft Silverlight
2009-01-30 19:12:22 ----D---- C:\Users\Sunchild\AppData\Roaming\WinPatrol
2009-01-30 19:12:14 ----D---- C:\Program Files\BillP Studios
2009-01-30 19:09:19 ----D---- C:\Program Files\Crawler
2009-01-30 19:09:00 ----D---- C:\Users\Sunchild\AppData\Roaming\Spyware Terminator
2009-01-30 19:09:00 ----D---- C:\ProgramData\Spyware Terminator
2009-01-30 19:08:57 ----D---- C:\Program Files\Spyware Terminator
2009-01-30 19:08:23 ----D---- C:\Program Files\CCleaner
2009-01-30 19:07:03 ----D---- C:\Users\Sunchild\AppData\Roaming\Malwarebytes
2009-01-30 19:06:58 ----D---- C:\ProgramData\Malwarebytes
2009-01-30 19:06:58 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-30 18:55:24 ----D---- C:\ProgramData\SiteAdvisor
2009-01-30 18:53:09 ----D---- C:\Program Files\Common Files\McAfee
2009-01-30 18:53:08 ----D---- C:\Program Files\McAfee.com
2009-01-30 18:53:07 ----D---- C:\Program Files\McAfee
2009-01-30 18:47:22 ----A---- C:\Windows\system32\DreamScene.dll
2009-01-30 18:45:24 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-01-30 18:44:49 ----D---- C:\Program Files\BitLocker
2009-01-30 18:44:14 ----A---- C:\Windows\system32\SecureKeyBackupCPL.dll
2009-01-30 18:42:25 ----A---- C:\Windows\system32\gpprefcl.dll
2009-01-30 18:40:07 ----D---- C:\ProgramData\McAfee
2009-01-30 18:29:53 ----D---- C:\Program Files\Microsoft
2009-01-30 18:29:38 ----D---- C:\Program Files\Windows Live SkyDrive
2009-01-30 18:29:21 ----D---- C:\Program Files\Windows Live
2009-01-30 18:29:06 ----D---- C:\Windows\PCHEALTH
2009-01-30 18:25:44 ----D---- C:\Program Files\Common Files\Windows Live
2009-01-30 18:06:57 ----A---- C:\Windows\system32\mshtml.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-01-30 18:02:44 ----A---- C:\Windows\system32\propdefs.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msstrc.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\mssprxy.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\mssitlb.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msshsq.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msshooks.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msscb.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\xmlfilter.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\wsepno.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\tquery.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\thawbrkr.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\srchadmin.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-01-30 18:02:43 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-01-30 18:02:43 ----A---- C:\Windows\system32\rtffilt.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\propsys.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\offfilt.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\nlhtml.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\msscntrs.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\mimefilt.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\korwbrkr.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\chtbrkr.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\chsbrkr.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssvp.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssrch.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssphtb.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssph.dll
2009-01-30 18:02:01 ----A---- C:\Windows\system32\tzres.dll
2009-01-30 17:49:49 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-01-30 17:49:49 ----A---- C:\Windows\system32\infocardapi.dll
2009-01-30 17:49:48 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-01-30 17:49:48 ----A---- C:\Windows\system32\icardres.dll
2009-01-30 17:49:48 ----A---- C:\Windows\system32\icardagt.exe
2009-01-30 17:49:47 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-01-30 17:49:46 ----A---- C:\Windows\system32\PresentationHost.exe
2009-01-30 17:46:23 ----A---- C:\Windows\system32\dfshim.dll
2009-01-30 17:46:22 ----A---- C:\Windows\system32\netfxperf.dll
2009-01-30 17:46:22 ----A---- C:\Windows\system32\mscoree.dll
2009-01-30 17:46:19 ----A---- C:\Windows\system32\mscorier.dll
2009-01-30 17:46:17 ----A---- C:\Windows\system32\mscories.dll
2009-01-30 17:44:47 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-01-30 17:44:46 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-01-30 17:44:46 ----A---- C:\Windows\system32\gameux.dll
2009-01-30 17:44:43 ----A---- C:\Windows\system32\ieframe.dll
2009-01-30 17:44:42 ----A---- C:\Windows\system32\wininet.dll
2009-01-30 17:44:42 ----A---- C:\Windows\system32\urlmon.dll
2009-01-30 17:44:41 ----A---- C:\Windows\system32\mstime.dll
2009-01-30 17:44:41 ----A---- C:\Windows\system32\jsproxy.dll
2009-01-30 17:44:41 ----A---- C:\Windows\system32\iertutil.dll
2009-01-30 17:44:35 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-01-30 17:44:33 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-01-30 17:44:26 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-01-30 17:43:35 ----A---- C:\Windows\explorer.exe
2009-01-30 17:43:33 ----A---- C:\Windows\system32\EncDec.dll
2009-01-30 17:43:32 ----A---- C:\Windows\system32\psisdecd.dll
2009-01-30 17:43:30 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-01-30 17:43:26 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-01-30 17:43:26 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-01-30 17:43:26 ----A---- C:\Windows\system32\mf.dll
2009-01-30 17:43:26 ----A---- C:\Windows\system32\logagent.exe
2009-01-30 17:43:22 ----A---- C:\Windows\system32\kd1394.dll
2009-01-30 17:43:21 ----A---- C:\Windows\system32\winresume.exe
2009-01-30 17:43:21 ----A---- C:\Windows\system32\winload.exe
2009-01-30 17:43:21 ----A---- C:\Windows\system32\ci.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\srdelayed.exe
2009-01-30 17:43:20 ----A---- C:\Windows\system32\srcore.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\srclient.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\setbcdlocale.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\rstrui.exe
2009-01-30 17:43:20 ----A---- C:\Windows\system32\kbd106n.dll
2009-01-30 17:43:12 ----A---- C:\Windows\system32\rpcrt4.dll
2009-01-30 17:43:11 ----A---- C:\Windows\system32\pacerprf.dll
2009-01-30 17:43:10 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-01-30 17:43:10 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-01-30 17:43:10 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-01-30 17:43:07 ----A---- C:\Windows\system32\msxml3.dll
2009-01-30 17:43:06 ----A---- C:\Windows\system32\emdmgmt.dll
2009-01-30 17:43:05 ----A---- C:\Windows\system32\dataclen.dll
2009-01-30 17:43:05 ----A---- C:\Windows\system32\cdd.dll
2009-01-30 17:43:04 ----A---- C:\Windows\system32\win32spl.dll
2009-01-30 17:43:02 ----A---- C:\Windows\system32\shell32.dll
2009-01-30 17:42:59 ----A---- C:\Windows\system32\es.dll
2009-01-30 17:42:55 ----A---- C:\Windows\system32\netapi32.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\wshext.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\wscript.exe
2009-01-30 17:42:51 ----A---- C:\Windows\system32\vbscript.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\scrrun.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\scrobj.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\jscript.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\cscript.exe
2009-01-30 17:42:49 ----A---- C:\Windows\system32\wmpeffects.dll
2009-01-30 17:42:48 ----A---- C:\Windows\system32\wersvc.dll
2009-01-30 17:42:48 ----A---- C:\Windows\system32\Faultrep.dll
2009-01-30 17:42:47 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-01-30 17:42:46 ----A---- C:\Windows\system32\gdi32.dll
2009-01-30 17:42:45 ----A---- C:\Windows\system32\inetcomm.dll
2009-01-30 17:42:43 ----A---- C:\Windows\system32\quartz.dll
2009-01-30 17:42:38 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-01-30 17:42:38 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-01-30 17:42:36 ----A---- C:\Windows\system32\connect.dll
2009-01-30 17:38:25 ----A---- C:\Windows\system32\msxml6.dll
2009-01-30 17:29:00 ----D---- C:\ProgramData\NVIDIA
2009-01-30 17:25:24 ----D---- C:\Program Files\My Company Name
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wups2.dll
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wucltux.dll
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wuaueng.dll
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wuauclt.exe
2009-01-30 17:23:31 ----SHD---- C:\Windows\Installer
2009-01-30 17:23:31 ----A---- C:\Windows\system32\wups.dll
2009-01-30 17:23:31 ----A---- C:\Windows\system32\wudriver.dll
2009-01-30 17:23:31 ----A---- C:\Windows\system32\wuapi.dll
2009-01-30 17:23:26 ----A---- C:\Windows\system32\wuwebv.dll
2009-01-30 17:23:26 ----A---- C:\Windows\system32\wuapp.exe
2009-01-30 17:20:32 ----D---- C:\Users\Sunchild\AppData\Roaming\InstallShield
2009-01-30 17:18:43 ----A---- C:\Windows\RTKAUDIOSERVICE.EXE
2009-01-30 17:18:37 ----D---- C:\Windows\system32\RTCOM
2009-01-30 17:18:07 ----A---- C:\Windows\DIFxAPI.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSWOW.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSTSXT.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSTSHD.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSHP360.dll
2009-01-30 17:18:05 ----A---- C:\Windows\SkyTel.exe
2009-01-30 17:18:05 ----A---- C:\Windows\RtlUpd.exe
2009-01-30 17:18:04 ----A---- C:\Windows\system32\RtkPgExt.dll
2009-01-30 17:18:04 ----A---- C:\Windows\system32\RtkCoInst.dll
2009-01-30 17:18:04 ----A---- C:\Windows\system32\RtkApoApi.dll
2009-01-30 17:18:00 ----A---- C:\Windows\system32\RtkAPO.dll
2009-01-30 17:17:55 ----A---- C:\Windows\RtHDVCpl.exe
2009-01-30 17:17:52 ----A---- C:\Windows\system32\maxxaudioapo.dll
2009-01-30 17:17:51 ----D---- C:\Program Files\Realtek
2009-01-30 17:17:49 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-30 17:17:48 ----R---- C:\Windows\RtlExUpd.dll
2009-01-30 17:17:48 ----A---- C:\Windows\HideWin.exe
2009-01-30 17:17:42 ----D---- C:\Program Files\Common Files\InstallShield
2009-01-30 17:15:16 ----D---- C:\Program Files\Intel
2009-01-30 17:14:51 ----A---- C:\Windows\GSetup.ini
2009-01-30 17:06:35 ----D---- C:\Users\Sunchild\AppData\Roaming\Identities
2009-01-30 17:06:30 ----SD---- C:\Users\Sunchild\AppData\Roaming\Microsoft
2009-01-30 17:06:30 ----D---- C:\Users\Sunchild\AppData\Roaming\Media Center Programs
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Modèles
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Menu Démarrer
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Favoris
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Bureau
2009-01-30 17:04:39 ----SHD---- C:\Program Files\Fichiers communs
2009-01-30 17:04:04 ----D---- C:\Windows\Debug
2009-01-30 16:43:23 ----D---- C:\Windows\SoftwareDistribution
2009-01-30 16:41:22 ----D---- C:\Windows\system32\catroot2
2009-01-30 16:41:11 ----D---- C:\Windows\CSC
2009-01-30 16:36:55 ----D---- C:\Windows\Panther
2009-01-30 15:05:00 ----RASH---- C:\Boot.ini.saved
2009-01-30 14:49:15 ----SH---- C:\Boot.BAK
2009-01-30 14:49:12 ----SHD---- C:\Boot
2009-01-29 20:18:07 ----SHD---- C:\RECYCLER
2009-01-29 18:40:52 ----SHD---- C:\System Volume Information
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvwssr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvwss.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvwgf2um.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvvsvc.exe
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvvitvsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvvitvs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvudisp.exe
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvcr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvc.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvoglv32.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmoblsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmobls.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmctray.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccssr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccss.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccsrs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvgamesr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvgames.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvdispsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvdisps.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvd3dum.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcuda.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcpl.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcod137.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcod.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvapi.dll

======List of files/folders modified in the last 1 months======

2009-02-06 17:32:44 ----D---- C:\Windows\Temp
2009-02-06 17:32:30 ----D---- C:\Windows\Prefetch
2009-02-06 17:32:09 ----RD---- C:\Program Files
2009-02-06 16:24:26 ----D---- C:\Windows\System32
2009-02-06 16:24:26 ----D---- C:\Windows\inf
2009-02-06 16:24:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-02-06 16:21:55 ----D---- C:\Windows
2009-02-05 15:47:43 ----RSD---- C:\Windows\assembly
2009-02-05 15:46:29 ----RSD---- C:\Windows\Fonts
2009-02-04 07:15:20 ----D---- C:\Windows\system32\WDI
2009-02-03 16:05:27 ----HD---- C:\ProgramData
2009-02-03 15:19:29 ----D---- C:\Windows\Cursors
2009-02-02 11:22:28 ----SHD---- C:\$Recycle.Bin
2009-02-02 11:21:45 ----RD---- C:\Users
2009-02-02 00:32:45 ----HD---- C:\Windows\system32\GroupPolicyUsers
2009-02-02 00:32:45 ----HD---- C:\Windows\system32\GroupPolicy
2009-02-01 19:44:14 ----A---- C:\Windows\system32\uxtheme.dll
2009-02-01 19:44:14 ----A---- C:\Windows\system32\themeui.dll
2009-02-01 19:44:14 ----A---- C:\Windows\system32\shsvcs.dll
2009-02-01 00:55:34 ----D---- C:\Windows\Tasks
2009-02-01 00:55:34 ----D---- C:\Windows\system32\Tasks
2009-02-01 00:41:25 ----SD---- C:\ProgramData\Microsoft
2009-02-01 00:30:27 ----D---- C:\Windows\system32\drivers
2009-01-31 23:10:10 ----D---- C:\Program Files\Common Files
2009-01-31 23:09:30 ----D---- C:\Windows\system32\catroot
2009-01-31 22:52:56 ----D---- C:\Windows\system32\wbem
2009-01-31 22:51:57 ----D---- C:\Windows\system32\config
2009-01-31 22:51:51 ----D---- C:\Windows\system32\spool
2009-01-31 22:51:51 ----D---- C:\Windows\system32\Msdtc
2009-01-31 22:51:50 ----D---- C:\Windows\system32\CodeIntegrity
2009-01-31 22:51:50 ----D---- C:\Windows\registration
2009-01-31 18:11:19 ----D---- C:\Windows\system32\fr-FR
2009-01-31 18:11:19 ----D---- C:\Windows\system32\en-US
2009-01-31 17:33:39 ----D---- C:\Windows\winsxs
2009-01-31 17:05:43 ----D---- C:\Windows\rescache
2009-01-31 13:07:00 ----D---- C:\Windows\Logs
2009-01-30 20:25:56 ----D---- C:\Program Files\Common Files\microsoft shared
2009-01-30 19:26:57 ----D---- C:\Program Files\Microsoft Games
2009-01-30 18:58:06 ----D---- C:\Windows\Web
2009-01-30 18:44:09 ----D---- C:\Windows\system32\zh-TW
2009-01-30 18:44:09 ----D---- C:\Windows\system32\zh-CN
2009-01-30 18:44:09 ----D---- C:\Windows\system32\uk-UA
2009-01-30 18:44:09 ----D---- C:\Windows\system32\tr-TR
2009-01-30 18:44:09 ----D---- C:\Windows\system32\th-TH
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sv-SE
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sr-Latn-CS
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sl-SI
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sk-SK
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ru-RU
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ro-RO
2009-01-30 18:44:08 ----D---- C:\Windows\system32\pt-PT
2009-01-30 18:44:08 ----D---- C:\Windows\system32\pt-BR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\pl-PL
2009-01-30 18:44:08 ----D---- C:\Windows\system32\nl-NL
2009-01-30 18:44:08 ----D---- C:\Windows\system32\nb-NO
2009-01-30 18:44:08 ----D---- C:\Windows\system32\lv-LV
2009-01-30 18:44:08 ----D---- C:\Windows\system32\lt-LT
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ko-KR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ja-JP
2009-01-30 18:44:08 ----D---- C:\Windows\system32\it-IT
2009-01-30 18:44:08 ----D---- C:\Windows\system32\hu-HU
2009-01-30 18:44:08 ----D---- C:\Windows\system32\hr-HR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\he-IL
2009-01-30 18:44:08 ----D---- C:\Windows\system32\fi-FI
2009-01-30 18:44:08 ----D---- C:\Windows\system32\et-EE
2009-01-30 18:44:08 ----D---- C:\Windows\system32\es-ES
2009-01-30 18:44:08 ----D---- C:\Windows\system32\el-GR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\de-DE
2009-01-30 18:44:08 ----D---- C:\Windows\system32\da-DK
2009-01-30 18:44:08 ----D---- C:\Windows\system32\cs-CZ
2009-01-30 18:44:08 ----D---- C:\Windows\system32\bg-BG
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ar-SA
2009-01-30 18:41:54 ----RSD---- C:\Windows\Media
2009-01-30 18:22:31 ----D---- C:\Windows\Microsoft.NET
2009-01-30 18:17:11 ----D---- C:\Windows\PolicyDefinitions
2009-01-30 18:17:11 ----D---- C:\Windows\ehome
2009-01-30 18:17:11 ----D---- C:\Windows\AppPatch
2009-01-30 18:17:11 ----D---- C:\Program Files\Windows Mail
2009-01-30 18:17:10 ----D---- C:\Windows\system32\migration
2009-01-30 18:17:10 ----D---- C:\Windows\system32\Boot
2009-01-30 18:17:08 ----D---- C:\Windows\system32\XPSViewer
2009-01-30 17:25:06 ----D---- C:\Windows\Help
2009-01-30 17:15:17 ----D---- C:\Windows\system32\restore
2009-01-30 17:04:39 ----D---- C:\Program Files\Windows NT
2009-01-30 16:45:57 ----ASH---- C:\Program Files\desktop.ini
2009-01-09 17:35:30 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-04-11 350720]
R1 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\Windows\System32\Drivers\Mpfp.sys [2008-06-02 130424]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2009-01-30 141312]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-02-14 2061528]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2009-01-14 15504]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\Windows\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\Windows\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-01-15 7740320]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-01-25 106496]
S3 a5qjb14s;a5qjb14s; C:\Windows\system32\drivers\a5qjb14s.sys []
S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2009-01-24 14336]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-04-11 5632]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-01-30 8059]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 mferkdk;McAfee Inc. mferkdk; C:\Windows\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-04-11 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-04-11 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-04-11 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-04-11 6016]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-04-11 83328]
S4 ErrDev;Pilote de périphérique d’erreur matérielle Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-04-11 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-04-11 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-04-11 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-04-11 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-14 170640]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-12-05 206096]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-10-10 792696]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-01-15 207392]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-01-30 570880]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TuneUp.ProgramStatisticsSvc;@%SystemRoot%\System32\TUProgSt.exe,-1; C:\Windows\System32\TUProgSt.exe [2009-01-31 603904]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-04-11 21504]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-09-16 605512]
R3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2009-01-31 360192]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-04-11 21504]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-04-11 523776]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-01-24 216232]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-04-11 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-04-11 917504]

-----------------EOF-----------------

Sunchild
 Posté le 06/02/2009 à 17:38 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

le second

info.txt logfile of random's system information tool 1.05 2009-02-06 17:32:48

======Uninstall list======

-->MsiExec /X{8AAB4176-A747-493A-A42C-B63CFADFD8E3}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
adsl TV-->C:\Program Files\adslTV\Uninstal.exe
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{D6E592B3-67DA-4BBB-9783-E1838FB253A2}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Crawler Toolbar with Web Security Guard-->C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe uninst
Easy CD-DA Extractor 10-->"C:\Windows\Easy CD-DA Extractor\uninstall.exe" "/U:C:\Program Files\Easy CD-DA Extractor 10\irunin.xml"
eMule-->"C:\Program Files\eMule\Uninstall.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{3CCB732A-E472-4CF9-B1EE-F18365341FE0}
Installeur de themes aero-->C:\Windows\Resources\Themes\Uninstal.exe
Installeur de themes-->C:\Windows\Resources\Themes\Uninstal.exe
LightScribe System Software 1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
Ma-Config.com-->MsiExec.exe /X{8AFB8FC4-3EBA-4C67-943F-CF43DB2180F1}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter-->C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Modèles de sons Windows-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\UltSound.inf,Uninstall
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.19)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Nero 9-->C:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
NVIDIA PhysX-->MsiExec.exe /X{8AAB4176-A747-493A-A42C-B63CFADFD8E3}
OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Pack themes tytynono-->C:\Windows\Resources\Themes\Uninstal.exe
Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\SETUP.EXE -runfromtemp -l0x040c -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -l0x40c -removeonly
RocketDock 1.3.1-->"C:\Program Files\RocketDock\unins000.exe"
Spyware Terminator-->"C:\Program Files\Spyware Terminator\unins000.exe"
TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
Ultimate Extras sounds from Microsoft® Tinker™-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\UltSound2.inf,Uninstall
VDownloader 0.77-->"C:\Program Files\VDOWNLOADER\unins000.exe"
VistaGlazz 1.1-->"C:\Program Files\CodeGazer\VistaGlazz\unins000.exe"
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Call-->MsiExec.exe /I{01523985-2098-43AF-9C97-12B07BE02A9B}
Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
WinPatrol 2008-->C:\PROGRA~1\BILLPS~1\WINPAT~1\Setup.exe /remove /q0

======Security center information======

AS: Windows Defender

System event log

Computer Name: Sunchild-Prod
Event Code: 1
Message: L’heure du système est passée à 2009-02-06T16:20:09.520Z à partir de 2009-02-06T16:20:00.411Z.
Record Number: 20843
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20090206162009.520363-000
Event Type: Information
User: AUTORITE NT\SERVICE LOCAL

Computer Name: Sunchild-Prod
Event Code: 1
Message: L’heure du système est passée à 2009-02-06T16:20:09.520Z à partir de 2009-02-06T16:20:09.520Z.
Record Number: 20844
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20090206162009.520000-000
Event Type: Information
User: AUTORITE NT\SERVICE LOCAL

Computer Name: Sunchild-Prod
Event Code: 33
Message: L'ancien cliché instantané du volume C: a été abandonné pour conserver l'utilisation d'espace disque pour les clichés instantanés de volume C: sous la limite définie par l'utilisateur.
Record Number: 20845
Source Name: volsnap
Time Written: 20090206162123.791600-000
Event Type: Information
User:

Computer Name: Sunchild-Prod
Event Code: 7036
Message: Le service TuneUp Drive Defrag Service est entré dans l'état : en cours d'exécution.
Record Number: 20846
Source Name: Service Control Manager
Time Written: 20090206162529.000000-000
Event Type: Information
User:

Computer Name: Sunchild-Prod
Event Code: 10000
Message: Le démarrage d'un serveur DCOM : {7323885B-407F-4839-9695-96F545FF6286} n'est pas possible. L'erreur :
"786"
s'est produite lors du démarrage de la commande :
"c:\PROGRA~1\mcafee\msc\mcupdmgr.exe" -Embedding
Record Number: 20847
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20090206162755.000000-000
Event Type: Erreur
User:

Application event log

Computer Name: Sunchild-Prod
Event Code: 8194
Message: Point de restauration correctement créé (Processus = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation ; Description = Point de contrôle planifié).
Record Number: 1792
Source Name: System Restore
Time Written: 20090206161208.000000-000
Event Type: Information
User:

Computer Name: Sunchild-Prod
Event Code: 8211
Message: Le point de restauration planifié a été correctement créé.
Record Number: 1793
Source Name: System Restore
Time Written: 20090206161208.000000-000
Event Type: Information
User:

Computer Name: Sunchild-Prod
Event Code: 8224
Message: Le service VSS s’arrête, car le délai d’inactivité est dépassé.
Record Number: 1794
Source Name: VSS
Time Written: 20090206161508.000000-000
Event Type: Information
User:

Computer Name: Sunchild-Prod
Event Code: 102
Message: WinMail (2964) WindowsMail0: Le moteur de la base de données (6.00.6001.0000) a démarré une nouvelle instance (0).
Record Number: 1795
Source Name: ESENT
Time Written: 20090206162547.000000-000
Event Type: Information
User:

Computer Name: Sunchild-Prod
Event Code: 5
Message: Unsupported service control request (see data below)
Record Number: 1796
Source Name: LightScribeService
Time Written: 20090206163247.000000-000
Event Type: Information
User:

Security event log

Computer Name: Sunchild-Prod
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 3003
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206163246.010000-000
Event Type: Échec de l'audit
User:

Computer Name: Sunchild-Prod
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 3004
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206163246.035000-000
Event Type: Échec de l'audit
User:

Computer Name: Sunchild-Prod
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 3005
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206163246.053000-000
Event Type: Échec de l'audit
User:

Computer Name: Sunchild-Prod
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 3006
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206163246.076000-000
Event Type: Échec de l'audit
User:

Computer Name: Sunchild-Prod
Event Code: 5038
Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 3007
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206163246.102000-000
Event Type: Échec de l'audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2

-----------------EOF-----------------

philae
 Posté le 06/02/2009 à 17:43 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

macafee securite center 2009, ce n'es tpas un antivirus gratuit j'imagine....Tu dois bien avoir un mode d'emploi ...

je ne le connais pas et ne peut te dire où se situe la quarantaine de ton AV

je regarde ton rapport, à première vue, il y a bien infection

pour MBAM ??? tu n'as pas répondu

edit :

* si tu n'as pas utilisé aujourd'hui malwarebyte's, fait un scan et poste le rapport stp

et

* Télécharge LOP S&D d'Eric71
Tuto

* Double-clique dessus pour lancer l'installation.
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
* Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
* Patiente jusqu'à la fin du scan.
* Poste le rapport généré (situé aussi ici C:\lopR.txt )



Modifié par philae le 06/02/2009 17:45
Sunchild
 Posté le 06/02/2009 à 18:12 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

je vais a nouveau cherche dans mcafee pour trouver l'aide

je possède bien la license pour 1 an mais malheureusement les explication ne sont pas toujours bien expliquées...

voici le rapport malwarebytes

Malwarebytes' Anti-Malware 1.33
Version de la base de données: 1733
Windows 6.0.6001 Service Pack 1

06/02/2009 18:08:12
mbam-log-2009-02-06 (18-08-12).txt

Type de recherche: Examen rapide
Eléments examinés: 47597
Temps écoulé: 2 minute(s), 46 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

philae
 Posté le 06/02/2009 à 18:15 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

je verrais si je peux trouver qq chose pr mc afee

fait le scan avec lop s & d

Sunchild
 Posté le 06/02/2009 à 18:29 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

c'est bien spybot search and destroy ? dont tu parles ?

philae
 Posté le 06/02/2009 à 19:05 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

re

non pas vraiment j'avais écrit ceci :

et

* Télécharge LOP S&D d'Eric71
Tuto

* Double-clique dessus pour lancer l'installation.
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
* Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
* Patiente jusqu'à la fin du scan.
* Poste le rapport généré (situé aussi ici C:\lopR.txt )

Publicité
Sunchild
 Posté le 06/02/2009 à 19:24 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

dsl j'avais mal lu (je suis déficient visuel)

donc voici le rapport


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Édition Intégrale ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : Award Modular BIOS v6.00PG
USER : Sunchild ( Not Administrator ! )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:97 Go (Free:60 Go)
D:\ (Local Disk) - NTFS - Total:368 Go (Free:50 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (CD or DVD)
H:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 06/02/2009|19:22 )

[ UAC => 0 ]

--------------------\\ Listing des dossiers dans Local

[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Application Data
[31/01/2009|23:06] C:\Users\Sunchild\AppData\Local\d3d9caps.dat
[05/02/2009|11:27] C:\Users\Sunchild\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[31/01/2009|17:46] C:\Users\Sunchild\AppData\Local\eMule
[05/02/2009|19:49] C:\Users\Sunchild\AppData\Local\GDIPFONTCACHEV1.DAT
[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Historique
[06/02/2009|17:40] C:\Users\Sunchild\AppData\Local\IconCache.db
[31/01/2009|19:53] C:\Users\Sunchild\AppData\Local\Microsoft
[04/02/2009|08:00] C:\Users\Sunchild\AppData\Local\Microsoft Games
[30/01/2009|22:02] C:\Users\Sunchild\AppData\Local\Mozilla
[03/02/2009|16:05] C:\Users\Sunchild\AppData\Local\Stardock
[06/02/2009|19:19] C:\Users\Sunchild\AppData\Local\Temp
[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Temporary Internet Files
[01/02/2009|17:47] C:\Users\Sunchild\AppData\Local\Thunderbird
[01/02/2009|13:44] C:\Users\Sunchild\AppData\Local\vdownloader
[30/01/2009|21:27] C:\Users\Sunchild\AppData\Local\VirtualStore

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[01/02/2009 11:04][--a------] C:\Windows\tasks\d‚fragmentation.job
[06/02/2009 10:30][--a------] C:\Windows\tasks\quickclean.job
[06/02/2009 08:00][--a------] C:\Windows\tasks\Malwarebytes' Scheduled Update for Sunchild.job
[06/02/2009 09:03][--a------] C:\Windows\tasks\Malwarebytes' Scheduled Scan for Sunchild.job
[06/02/2009 19:00][--a------] C:\Windows\tasks\Maintenance en 1 clic.job
[30/01/2009 18:59][--a------] C:\Windows\tasks\McDefragTask.job
[01/02/2009 01:00][--a------] C:\Windows\tasks\McQcTask.job
[06/02/2009 17:41][--ah-----] C:\Windows\tasks\SA.DAT
[06/02/2009 17:40][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[31/01/2009|17:54] C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
[02/11/2006|14:00] C:\ProgramData\Application Data
[30/01/2009|17:04] C:\ProgramData\Bureau
[02/11/2006|14:00] C:\ProgramData\Desktop
[02/11/2006|14:00] C:\ProgramData\Documents
[31/01/2009|20:27] C:\ProgramData\eMule
[30/01/2009|17:04] C:\ProgramData\Favoris
[02/11/2006|14:00] C:\ProgramData\Favorites
[01/02/2009|13:57] C:\ProgramData\LightScribe
[31/01/2009|19:04] C:\ProgramData\ma-config.com
[30/01/2009|19:06] C:\ProgramData\Malwarebytes
[30/01/2009|18:55] C:\ProgramData\McAfee
[30/01/2009|17:04] C:\ProgramData\Menu D‚marrer
[31/01/2009|20:48] C:\ProgramData\Messenger Plus!
[01/02/2009|00:41] C:\ProgramData\Microsoft
[30/01/2009|17:04] C:\ProgramData\ModŠles
[30/01/2009|20:46] C:\ProgramData\Nero
[31/01/2009|23:14] C:\ProgramData\NVIDIA
[30/01/2009|18:55] C:\ProgramData\SiteAdvisor
[01/02/2009|00:21] C:\ProgramData\Spyware Terminator
[03/02/2009|16:05] C:\ProgramData\Stardock
[02/11/2006|14:00] C:\ProgramData\Start Menu
[02/11/2006|14:00] C:\ProgramData\Templates
[31/01/2009|17:55] C:\ProgramData\TuneUp Software

--------------------\\ Listing des dossiers dans C:\Program Files

[05/02/2009|19:02] C:\Program Files\adslTV
[31/01/2009|23:10] C:\Program Files\AGEIA Technologies
[31/01/2009|17:43] C:\Program Files\Alcohol Soft
[30/01/2009|19:12] C:\Program Files\BillP Studios
[30/01/2009|18:44] C:\Program Files\BitLocker
[30/01/2009|19:08] C:\Program Files\CCleaner
[31/01/2009|20:47] C:\Program Files\Circle Developement
[31/01/2009|22:20] C:\Program Files\CodeGazer
[31/01/2009|23:10] C:\Program Files\Common Files
[30/01/2009|19:09] C:\Program Files\Crawler
[03/02/2009|20:06] C:\Program Files\Easy CD-DA Extractor 10
[31/01/2009|17:46] C:\Program Files\eMule
[30/01/2009|17:04] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[30/01/2009|17:25] C:\Program Files\InstallShield Installation Information
[30/01/2009|17:15] C:\Program Files\Intel
[06/02/2009|19:11] C:\Program Files\Internet Explorer
[31/01/2009|19:04] C:\Program Files\ma-config.com
[30/01/2009|19:07] C:\Program Files\Malwarebytes' Anti-Malware
[31/01/2009|19:21] C:\Program Files\McAfee
[30/01/2009|18:53] C:\Program Files\McAfee.com
[31/01/2009|22:01] C:\Program Files\Messenger Plus! Live
[30/01/2009|18:29] C:\Program Files\Microsoft
[30/01/2009|19:26] C:\Program Files\Microsoft Games
[30/01/2009|19:26] C:\Program Files\Microsoft Silverlight
[02/11/2006|13:41] C:\Program Files\Movie Maker
[06/02/2009|18:59] C:\Program Files\Mozilla Firefox
[01/02/2009|17:46] C:\Program Files\Mozilla Thunderbird
[02/11/2006|13:35] C:\Program Files\MSBuild
[31/01/2009|17:33] C:\Program Files\MSXML 4.0
[30/01/2009|17:25] C:\Program Files\My Company Name
[30/01/2009|20:57] C:\Program Files\Nero
[05/02/2009|15:46] C:\Program Files\OpenOffice.org 3
[30/01/2009|17:20] C:\Program Files\Realtek
[02/11/2006|13:35] C:\Program Files\Reference Assemblies
[30/01/2009|22:17] C:\Program Files\RocketDock
[03/02/2009|12:07] C:\Program Files\Spyware Terminator
[06/02/2009|17:32] C:\Program Files\trend micro
[31/01/2009|17:58] C:\Program Files\TuneUp Utilities 2009
[02/11/2006|14:00] C:\Program Files\Uninstall Information
[31/01/2009|23:52] C:\Program Files\VDOWNLOADER
[30/01/2009|21:51] C:\Program Files\Winamp
[02/11/2006|13:41] C:\Program Files\Windows Calendar
[02/11/2006|13:41] C:\Program Files\Windows Collaboration
[02/11/2006|13:41] C:\Program Files\Windows Defender
[02/11/2006|13:41] C:\Program Files\Windows Journal
[30/01/2009|18:29] C:\Program Files\Windows Live
[30/01/2009|18:29] C:\Program Files\Windows Live SkyDrive
[30/01/2009|18:17] C:\Program Files\Windows Mail
[02/11/2006|13:41] C:\Program Files\Windows Media Player
[30/01/2009|17:04] C:\Program Files\Windows NT
[02/11/2006|13:41] C:\Program Files\Windows Photo Gallery
[02/11/2006|13:41] C:\Program Files\Windows Sidebar
[30/01/2009|22:09] C:\Program Files\WinRAR

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[30/01/2009|17:23] C:\Program Files\Common Files\InstallShield
[30/01/2009|20:26] C:\Program Files\Common Files\LightScribe
[30/01/2009|18:53] C:\Program Files\Common Files\McAfee
[30/01/2009|20:25] C:\Program Files\Common Files\microsoft shared
[30/01/2009|21:18] C:\Program Files\Common Files\Nero
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[02/11/2006|13:41] C:\Program Files\Common Files\System
[30/01/2009|18:25] C:\Program Files\Common Files\Windows Live
[31/01/2009|23:10] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 66 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\Program Files\Circle Developement

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 19:22:50
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:22][D:4]-> C:\Users\Sunchild\AppData\Local\Temp
[F:1][D:1]-> C:\Users\Sunchild\AppData\Roaming\MICROS~1\Windows\Cookies
[F:9][D:4]-> C:\Users\Sunchild\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:3][D:3]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 06/02/2009|19:23 - Option : [1]

--------------------\\ Fin du rapport a 19:23:22
[ UAC => 1 ]

philae
 Posté le 06/02/2009 à 19:39 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

ok

on poursuit

* Relance LOP S&D d'Eric71
* Choisis cette fois ci l'Option 3 ( Suppression )
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (situé aussi ici C:\lopR.txt )

( Si le Bureau ne réapparaît pas , lance le gestionnaire des tâches en cliquant sur Ctrl + Alt + Suppr , puis Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )

reposte un nouveau rapport RSIT ensuite stp

Sunchild
 Posté le 07/02/2009 à 11:48 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Édition Intégrale ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : Award Modular BIOS v6.00PG
USER : Sunchild ( Not Administrator ! )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:97 Go (Free:60 Go)
D:\ (Local Disk) - NTFS - Total:368 Go (Free:50 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (CD or DVD)
H:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [3] ( 07/02/2009|11:40 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\Circle Developement

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans Local

[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Application Data
[31/01/2009|23:06] C:\Users\Sunchild\AppData\Local\d3d9caps.dat
[05/02/2009|11:27] C:\Users\Sunchild\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[31/01/2009|17:46] C:\Users\Sunchild\AppData\Local\eMule
[05/02/2009|19:49] C:\Users\Sunchild\AppData\Local\GDIPFONTCACHEV1.DAT
[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Historique
[06/02/2009|17:40] C:\Users\Sunchild\AppData\Local\IconCache.db
[31/01/2009|19:53] C:\Users\Sunchild\AppData\Local\Microsoft
[04/02/2009|08:00] C:\Users\Sunchild\AppData\Local\Microsoft Games
[30/01/2009|22:02] C:\Users\Sunchild\AppData\Local\Mozilla
[03/02/2009|16:05] C:\Users\Sunchild\AppData\Local\Stardock
[07/02/2009|11:40] C:\Users\Sunchild\AppData\Local\Temp
[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Temporary Internet Files
[01/02/2009|17:47] C:\Users\Sunchild\AppData\Local\Thunderbird
[01/02/2009|13:44] C:\Users\Sunchild\AppData\Local\vdownloader
[30/01/2009|21:27] C:\Users\Sunchild\AppData\Local\VirtualStore

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[01/02/2009 11:04][--a------] C:\Windows\tasks\d‚fragmentation.job
[07/02/2009 10:30][--a------] C:\Windows\tasks\quickclean.job
[07/02/2009 08:00][--a------] C:\Windows\tasks\Malwarebytes' Scheduled Update for Sunchild.job
[07/02/2009 09:02][--a------] C:\Windows\tasks\Malwarebytes' Scheduled Scan for Sunchild.job
[07/02/2009 11:00][--a------] C:\Windows\tasks\Maintenance en 1 clic.job
[30/01/2009 18:59][--a------] C:\Windows\tasks\McDefragTask.job
[01/02/2009 01:00][--a------] C:\Windows\tasks\McQcTask.job
[06/02/2009 17:41][--ah-----] C:\Windows\tasks\SA.DAT
[06/02/2009 17:40][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[31/01/2009|17:54] C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
[02/11/2006|14:00] C:\ProgramData\Application Data
[30/01/2009|17:04] C:\ProgramData\Bureau
[02/11/2006|14:00] C:\ProgramData\Desktop
[02/11/2006|14:00] C:\ProgramData\Documents
[31/01/2009|20:27] C:\ProgramData\eMule
[30/01/2009|17:04] C:\ProgramData\Favoris
[02/11/2006|14:00] C:\ProgramData\Favorites
[01/02/2009|13:57] C:\ProgramData\LightScribe
[31/01/2009|19:04] C:\ProgramData\ma-config.com
[30/01/2009|19:06] C:\ProgramData\Malwarebytes
[30/01/2009|18:55] C:\ProgramData\McAfee
[30/01/2009|17:04] C:\ProgramData\Menu D‚marrer
[31/01/2009|20:48] C:\ProgramData\Messenger Plus!
[01/02/2009|00:41] C:\ProgramData\Microsoft
[30/01/2009|17:04] C:\ProgramData\ModŠles
[30/01/2009|20:46] C:\ProgramData\Nero
[31/01/2009|23:14] C:\ProgramData\NVIDIA
[30/01/2009|18:55] C:\ProgramData\SiteAdvisor
[01/02/2009|00:21] C:\ProgramData\Spyware Terminator
[03/02/2009|16:05] C:\ProgramData\Stardock
[02/11/2006|14:00] C:\ProgramData\Start Menu
[02/11/2006|14:00] C:\ProgramData\Templates
[31/01/2009|17:55] C:\ProgramData\TuneUp Software

--------------------\\ Listing des dossiers dans C:\Program Files

[05/02/2009|19:02] C:\Program Files\adslTV
[31/01/2009|23:10] C:\Program Files\AGEIA Technologies
[31/01/2009|17:43] C:\Program Files\Alcohol Soft
[30/01/2009|19:12] C:\Program Files\BillP Studios
[30/01/2009|18:44] C:\Program Files\BitLocker
[30/01/2009|19:08] C:\Program Files\CCleaner
[31/01/2009|22:20] C:\Program Files\CodeGazer
[31/01/2009|23:10] C:\Program Files\Common Files
[30/01/2009|19:09] C:\Program Files\Crawler
[03/02/2009|20:06] C:\Program Files\Easy CD-DA Extractor 10
[31/01/2009|17:46] C:\Program Files\eMule
[30/01/2009|17:04] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[30/01/2009|17:25] C:\Program Files\InstallShield Installation Information
[30/01/2009|17:15] C:\Program Files\Intel
[06/02/2009|19:11] C:\Program Files\Internet Explorer
[31/01/2009|19:04] C:\Program Files\ma-config.com
[30/01/2009|19:07] C:\Program Files\Malwarebytes' Anti-Malware
[31/01/2009|19:21] C:\Program Files\McAfee
[30/01/2009|18:53] C:\Program Files\McAfee.com
[31/01/2009|22:01] C:\Program Files\Messenger Plus! Live
[30/01/2009|18:29] C:\Program Files\Microsoft
[30/01/2009|19:26] C:\Program Files\Microsoft Games
[30/01/2009|19:26] C:\Program Files\Microsoft Silverlight
[02/11/2006|13:41] C:\Program Files\Movie Maker
[07/02/2009|11:38] C:\Program Files\Mozilla Firefox
[01/02/2009|17:46] C:\Program Files\Mozilla Thunderbird
[02/11/2006|13:35] C:\Program Files\MSBuild
[31/01/2009|17:33] C:\Program Files\MSXML 4.0
[30/01/2009|17:25] C:\Program Files\My Company Name
[30/01/2009|20:57] C:\Program Files\Nero
[05/02/2009|15:46] C:\Program Files\OpenOffice.org 3
[30/01/2009|17:20] C:\Program Files\Realtek
[02/11/2006|13:35] C:\Program Files\Reference Assemblies
[30/01/2009|22:17] C:\Program Files\RocketDock
[03/02/2009|12:07] C:\Program Files\Spyware Terminator
[06/02/2009|17:32] C:\Program Files\trend micro
[31/01/2009|17:58] C:\Program Files\TuneUp Utilities 2009
[02/11/2006|14:00] C:\Program Files\Uninstall Information
[31/01/2009|23:52] C:\Program Files\VDOWNLOADER
[30/01/2009|21:51] C:\Program Files\Winamp
[02/11/2006|13:41] C:\Program Files\Windows Calendar
[02/11/2006|13:41] C:\Program Files\Windows Collaboration
[02/11/2006|13:41] C:\Program Files\Windows Defender
[02/11/2006|13:41] C:\Program Files\Windows Journal
[30/01/2009|18:29] C:\Program Files\Windows Live
[30/01/2009|18:29] C:\Program Files\Windows Live SkyDrive
[30/01/2009|18:17] C:\Program Files\Windows Mail
[02/11/2006|13:41] C:\Program Files\Windows Media Player
[30/01/2009|17:04] C:\Program Files\Windows NT
[02/11/2006|13:41] C:\Program Files\Windows Photo Gallery
[02/11/2006|13:41] C:\Program Files\Windows Sidebar
[30/01/2009|22:09] C:\Program Files\WinRAR

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[30/01/2009|17:23] C:\Program Files\Common Files\InstallShield
[30/01/2009|20:26] C:\Program Files\Common Files\LightScribe
[30/01/2009|18:53] C:\Program Files\Common Files\McAfee
[30/01/2009|20:25] C:\Program Files\Common Files\microsoft shared
[30/01/2009|21:18] C:\Program Files\Common Files\Nero
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[02/11/2006|13:41] C:\Program Files\Common Files\System
[30/01/2009|18:25] C:\Program Files\Common Files\Windows Live
[31/01/2009|23:10] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 69 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-07 11:41:07
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:7][D:2]-> C:\Users\Sunchild\AppData\Local\Temp
[F:1][D:1]-> C:\Users\Sunchild\AppData\Roaming\MICROS~1\Windows\Cookies
[F:20][D:4]-> C:\Users\Sunchild\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:3][D:3]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 06/02/2009|19:23 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 07/02/2009|11:41 - Option : [3]

--------------------\\ Fin du rapport a 11:41:43
[ UAC => 1 ]

Sunchild
 Posté le 07/02/2009 à 11:48 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Édition Intégrale ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : Award Modular BIOS v6.00PG
USER : Sunchild ( Not Administrator ! )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:97 Go (Free:60 Go)
D:\ (Local Disk) - NTFS - Total:368 Go (Free:50 Go)
E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (CD or DVD)
H:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [3] ( 07/02/2009|11:40 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\Circle Developement

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans Local

[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Application Data
[31/01/2009|23:06] C:\Users\Sunchild\AppData\Local\d3d9caps.dat
[05/02/2009|11:27] C:\Users\Sunchild\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[31/01/2009|17:46] C:\Users\Sunchild\AppData\Local\eMule
[05/02/2009|19:49] C:\Users\Sunchild\AppData\Local\GDIPFONTCACHEV1.DAT
[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Historique
[06/02/2009|17:40] C:\Users\Sunchild\AppData\Local\IconCache.db
[31/01/2009|19:53] C:\Users\Sunchild\AppData\Local\Microsoft
[04/02/2009|08:00] C:\Users\Sunchild\AppData\Local\Microsoft Games
[30/01/2009|22:02] C:\Users\Sunchild\AppData\Local\Mozilla
[03/02/2009|16:05] C:\Users\Sunchild\AppData\Local\Stardock
[07/02/2009|11:40] C:\Users\Sunchild\AppData\Local\Temp
[30/01/2009|17:06] C:\Users\Sunchild\AppData\Local\Temporary Internet Files
[01/02/2009|17:47] C:\Users\Sunchild\AppData\Local\Thunderbird
[01/02/2009|13:44] C:\Users\Sunchild\AppData\Local\vdownloader
[30/01/2009|21:27] C:\Users\Sunchild\AppData\Local\VirtualStore

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[01/02/2009 11:04][--a------] C:\Windows\tasks\d‚fragmentation.job
[07/02/2009 10:30][--a------] C:\Windows\tasks\quickclean.job
[07/02/2009 08:00][--a------] C:\Windows\tasks\Malwarebytes' Scheduled Update for Sunchild.job
[07/02/2009 09:02][--a------] C:\Windows\tasks\Malwarebytes' Scheduled Scan for Sunchild.job
[07/02/2009 11:00][--a------] C:\Windows\tasks\Maintenance en 1 clic.job
[30/01/2009 18:59][--a------] C:\Windows\tasks\McDefragTask.job
[01/02/2009 01:00][--a------] C:\Windows\tasks\McQcTask.job
[06/02/2009 17:41][--ah-----] C:\Windows\tasks\SA.DAT
[06/02/2009 17:40][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[31/01/2009|17:54] C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
[02/11/2006|14:00] C:\ProgramData\Application Data
[30/01/2009|17:04] C:\ProgramData\Bureau
[02/11/2006|14:00] C:\ProgramData\Desktop
[02/11/2006|14:00] C:\ProgramData\Documents
[31/01/2009|20:27] C:\ProgramData\eMule
[30/01/2009|17:04] C:\ProgramData\Favoris
[02/11/2006|14:00] C:\ProgramData\Favorites
[01/02/2009|13:57] C:\ProgramData\LightScribe
[31/01/2009|19:04] C:\ProgramData\ma-config.com
[30/01/2009|19:06] C:\ProgramData\Malwarebytes
[30/01/2009|18:55] C:\ProgramData\McAfee
[30/01/2009|17:04] C:\ProgramData\Menu D‚marrer
[31/01/2009|20:48] C:\ProgramData\Messenger Plus!
[01/02/2009|00:41] C:\ProgramData\Microsoft
[30/01/2009|17:04] C:\ProgramData\ModŠles
[30/01/2009|20:46] C:\ProgramData\Nero
[31/01/2009|23:14] C:\ProgramData\NVIDIA
[30/01/2009|18:55] C:\ProgramData\SiteAdvisor
[01/02/2009|00:21] C:\ProgramData\Spyware Terminator
[03/02/2009|16:05] C:\ProgramData\Stardock
[02/11/2006|14:00] C:\ProgramData\Start Menu
[02/11/2006|14:00] C:\ProgramData\Templates
[31/01/2009|17:55] C:\ProgramData\TuneUp Software

--------------------\\ Listing des dossiers dans C:\Program Files

[05/02/2009|19:02] C:\Program Files\adslTV
[31/01/2009|23:10] C:\Program Files\AGEIA Technologies
[31/01/2009|17:43] C:\Program Files\Alcohol Soft
[30/01/2009|19:12] C:\Program Files\BillP Studios
[30/01/2009|18:44] C:\Program Files\BitLocker
[30/01/2009|19:08] C:\Program Files\CCleaner
[31/01/2009|22:20] C:\Program Files\CodeGazer
[31/01/2009|23:10] C:\Program Files\Common Files
[30/01/2009|19:09] C:\Program Files\Crawler
[03/02/2009|20:06] C:\Program Files\Easy CD-DA Extractor 10
[31/01/2009|17:46] C:\Program Files\eMule
[30/01/2009|17:04] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[30/01/2009|17:25] C:\Program Files\InstallShield Installation Information
[30/01/2009|17:15] C:\Program Files\Intel
[06/02/2009|19:11] C:\Program Files\Internet Explorer
[31/01/2009|19:04] C:\Program Files\ma-config.com
[30/01/2009|19:07] C:\Program Files\Malwarebytes' Anti-Malware
[31/01/2009|19:21] C:\Program Files\McAfee
[30/01/2009|18:53] C:\Program Files\McAfee.com
[31/01/2009|22:01] C:\Program Files\Messenger Plus! Live
[30/01/2009|18:29] C:\Program Files\Microsoft
[30/01/2009|19:26] C:\Program Files\Microsoft Games
[30/01/2009|19:26] C:\Program Files\Microsoft Silverlight
[02/11/2006|13:41] C:\Program Files\Movie Maker
[07/02/2009|11:38] C:\Program Files\Mozilla Firefox
[01/02/2009|17:46] C:\Program Files\Mozilla Thunderbird
[02/11/2006|13:35] C:\Program Files\MSBuild
[31/01/2009|17:33] C:\Program Files\MSXML 4.0
[30/01/2009|17:25] C:\Program Files\My Company Name
[30/01/2009|20:57] C:\Program Files\Nero
[05/02/2009|15:46] C:\Program Files\OpenOffice.org 3
[30/01/2009|17:20] C:\Program Files\Realtek
[02/11/2006|13:35] C:\Program Files\Reference Assemblies
[30/01/2009|22:17] C:\Program Files\RocketDock
[03/02/2009|12:07] C:\Program Files\Spyware Terminator
[06/02/2009|17:32] C:\Program Files\trend micro
[31/01/2009|17:58] C:\Program Files\TuneUp Utilities 2009
[02/11/2006|14:00] C:\Program Files\Uninstall Information
[31/01/2009|23:52] C:\Program Files\VDOWNLOADER
[30/01/2009|21:51] C:\Program Files\Winamp
[02/11/2006|13:41] C:\Program Files\Windows Calendar
[02/11/2006|13:41] C:\Program Files\Windows Collaboration
[02/11/2006|13:41] C:\Program Files\Windows Defender
[02/11/2006|13:41] C:\Program Files\Windows Journal
[30/01/2009|18:29] C:\Program Files\Windows Live
[30/01/2009|18:29] C:\Program Files\Windows Live SkyDrive
[30/01/2009|18:17] C:\Program Files\Windows Mail
[02/11/2006|13:41] C:\Program Files\Windows Media Player
[30/01/2009|17:04] C:\Program Files\Windows NT
[02/11/2006|13:41] C:\Program Files\Windows Photo Gallery
[02/11/2006|13:41] C:\Program Files\Windows Sidebar
[30/01/2009|22:09] C:\Program Files\WinRAR

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[30/01/2009|17:23] C:\Program Files\Common Files\InstallShield
[30/01/2009|20:26] C:\Program Files\Common Files\LightScribe
[30/01/2009|18:53] C:\Program Files\Common Files\McAfee
[30/01/2009|20:25] C:\Program Files\Common Files\microsoft shared
[30/01/2009|21:18] C:\Program Files\Common Files\Nero
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[02/11/2006|13:41] C:\Program Files\Common Files\System
[30/01/2009|18:25] C:\Program Files\Common Files\Windows Live
[31/01/2009|23:10] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 69 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-07 11:41:07
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:7][D:2]-> C:\Users\Sunchild\AppData\Local\Temp
[F:1][D:1]-> C:\Users\Sunchild\AppData\Roaming\MICROS~1\Windows\Cookies
[F:20][D:4]-> C:\Users\Sunchild\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:3][D:3]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 06/02/2009|19:23 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 07/02/2009|11:41 - Option : [3]

--------------------\\ Fin du rapport a 11:41:43
[ UAC => 1 ]

philae
 Posté le 07/02/2009 à 14:43 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

bonjour,

j'avais demandé également un nouveau rapport RSIT, ne l'oublie pas stp

Sunchild
 Posté le 07/02/2009 à 15:03 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

désoler j'avais oublié toute mes excuse

le voici

Logfile of random's system information tool 1.05 (written by random/random)
Run by Sunchild at 2009-02-07 15:02:09
Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
System drive C: has 61 GB (61%) free of 100 GB
Total RAM: 2047 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:02:22, on 07/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Users\Sunchild\AppData\Local\Temp\installer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\conime.exe
C:\Program Files\adslTV\adsltv.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Users\Sunchild\Desktop\RSIT.exe
C:\Program Files\trend micro\Sunchild.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Glass2k] C:\Users\Sunchild\AppData\Local\Temp\installer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [McAfee Backup] "C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\sunchild\appdata\local\temp\WLZ1FB0.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\sunchild\appdata\local\temp\WLZ1FB0.SH! (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe

--
End of file - 8337 bytes

======Scheduled tasks folder======

C:\Windows\tasks\défragmentation.job
C:\Windows\tasks\Maintenance en 1 clic.job
C:\Windows\tasks\Malwarebytes' Scheduled Scan for Sunchild.job
C:\Windows\tasks\Malwarebytes' Scheduled Update for Sunchild.job
C:\Windows\tasks\McDefragTask.job
C:\Windows\tasks\McQcTask.job
C:\Windows\tasks\quickclean.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2008-10-29 1193984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\PROGRA~1\mcafee\msk\mskapbho.dll [2008-10-17 247312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll [2008-06-20 58688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-11-14 150032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-11-14 150032]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - Barre d'outils &Crawler - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2008-10-29 1193984]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Glass2k"=C:\Users\Sunchild\AppData\Local\Temp\installer.exe [2009-01-31 56325]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-01-15 13683232]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-01-15 92704]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-01-14 399504]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2009-01-30 1783808]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-09-18 333120]
"WPCUMI"=C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]
"McAfee Backup"=C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe [2008-07-10 5129504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-04-11 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-03-19 630784]
"ccleaner"=C:\Program Files\CCleaner\ccleaner.exe [2008-12-19 1434864]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-04-11 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2007-07-20 233888]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26717980-efb6-11dd-8ca6-001d7d79cfc9}]
shell\AutoRun\command - H:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a71b11fd-eef7-11dd-847c-001d7d79cfc9}]
shell\AutoRun\command - a1.bat
shell\explore\command - a1.bat
shell\open\command - a1.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc63ff9b-f46c-11dd-9039-001d7d79cfc9}]
shell\AutoRun\command - G:\a1.bat
shell\explore\command - G:\a1.bat
shell\open\command - G:\a1.bat


======List of files/folders created in the last 1 months======

2009-02-07 09:00:05 ----A---- C:\Windows\ntbtlog.txt
2009-02-06 19:22:14 ----A---- C:\lopR.txt
2009-02-06 19:20:37 ----D---- C:\Lop SD
2009-02-06 19:11:22 ----D---- C:\Windows\system32\URTTEMP
2009-02-06 17:32:09 ----D---- C:\rsit
2009-02-06 17:32:09 ----D---- C:\Program Files\trend micro
2009-02-05 15:46:04 ----D---- C:\Program Files\OpenOffice.org 3
2009-02-03 20:03:15 ----D---- C:\Windows\Easy CD-DA Extractor
2009-02-03 20:03:14 ----D---- C:\Program Files\Easy CD-DA Extractor 10
2009-02-03 16:05:27 ----D---- C:\ProgramData\Stardock
2009-02-03 13:06:27 ----D---- C:\Program Files\adslTV
2009-02-01 17:46:58 ----D---- C:\Users\Sunchild\AppData\Roaming\Thunderbird
2009-02-01 17:46:50 ----D---- C:\Program Files\Mozilla Thunderbird
2009-02-01 13:57:45 ----D---- C:\ProgramData\LightScribe
2009-02-01 13:57:14 ----D---- C:\Users\Sunchild\AppData\Roaming\Nero
2009-01-31 23:52:43 ----D---- C:\Program Files\VDOWNLOADER
2009-01-31 23:10:44 ----D---- C:\Windows\system32\AGEIA
2009-01-31 23:10:10 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-31 23:09:53 ----A---- C:\Windows\system32\nvcpluir.dll
2009-01-31 23:09:53 ----A---- C:\Windows\system32\nvcplui.exe
2009-01-31 23:06:56 ----D---- C:\NVIDIA
2009-01-31 22:20:38 ----D---- C:\Program Files\CodeGazer
2009-01-31 20:48:00 ----D---- C:\ProgramData\Messenger Plus!
2009-01-31 20:47:07 ----D---- C:\Program Files\Messenger Plus! Live
2009-01-31 20:27:48 ----D---- C:\ProgramData\eMule
2009-01-31 20:18:12 ----D---- C:\Users\Sunchild\AppData\Roaming\Adobe
2009-01-31 19:26:21 ----D---- C:\Program Files\AGEIA Technologies
2009-01-31 19:24:53 ----A---- C:\Windows\system32\NVUNINST.EXE
2009-01-31 19:04:41 ----D---- C:\ProgramData\ma-config.com
2009-01-31 19:04:41 ----D---- C:\Program Files\ma-config.com
2009-01-31 17:58:11 ----A---- C:\Windows\system32\uxtuneup.dll
2009-01-31 17:58:11 ----A---- C:\Windows\system32\TUProgSt.exe
2009-01-31 17:58:11 ----A---- C:\Windows\system32\authuitu.dll
2009-01-31 17:58:08 ----A---- C:\Windows\system32\TuneUpDefragService.exe
2009-01-31 17:56:01 ----D---- C:\Users\Sunchild\AppData\Roaming\TuneUp Software
2009-01-31 17:55:38 ----D---- C:\Program Files\TuneUp Utilities 2009
2009-01-31 17:55:36 ----D---- C:\ProgramData\TuneUp Software
2009-01-31 17:54:53 ----SHD---- C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
2009-01-31 17:46:11 ----D---- C:\Program Files\eMule
2009-01-31 17:43:16 ----D---- C:\Program Files\Alcohol Soft
2009-01-31 17:33:26 ----D---- C:\Program Files\MSXML 4.0
2009-01-31 12:37:16 ----D---- C:\Users\Sunchild\AppData\Roaming\vlc
2009-01-30 22:31:20 ----D---- C:\Users\Sunchild\AppData\Roaming\Macromedia
2009-01-30 22:31:16 ----D---- C:\Users\Sunchild\AppData\Roaming\ItsLabel
2009-01-30 22:17:31 ----D---- C:\Program Files\RocketDock
2009-01-30 22:09:39 ----D---- C:\Program Files\WinRAR
2009-01-30 22:02:54 ----D---- C:\Users\Sunchild\AppData\Roaming\Mozilla
2009-01-30 22:02:29 ----D---- C:\Program Files\Mozilla Firefox
2009-01-30 21:51:00 ----N---- C:\Windows\system32\vxblock.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxwave.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxsfs.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxmas.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxinsa64.exe
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxhpinst.exe
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxdrv.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxcpya64.exe
2009-01-30 21:51:00 ----N---- C:\Windows\system32\pxafs.dll
2009-01-30 21:51:00 ----N---- C:\Windows\system32\px.dll
2009-01-30 21:50:58 ----D---- C:\Users\Sunchild\AppData\Roaming\Winamp
2009-01-30 21:50:58 ----D---- C:\Program Files\Winamp
2009-01-30 21:48:05 ----D---- C:\Windows\system32\Macromed
2009-01-30 21:47:59 ----D---- C:\Users\Sunchild\AppData\Roaming\EoRezo
2009-01-30 21:00:07 ----A---- C:\Windows\Irremote.ini
2009-01-30 20:29:08 ----D---- C:\Program Files\Nero
2009-01-30 20:28:10 ----D---- C:\ProgramData\Nero
2009-01-30 20:28:09 ----D---- C:\Program Files\Common Files\Nero
2009-01-30 20:27:16 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-01-30 20:26:37 ----D---- C:\Program Files\Common Files\LightScribe
2009-01-30 19:26:40 ----D---- C:\Program Files\Microsoft Silverlight
2009-01-30 19:12:22 ----D---- C:\Users\Sunchild\AppData\Roaming\WinPatrol
2009-01-30 19:12:14 ----D---- C:\Program Files\BillP Studios
2009-01-30 19:09:19 ----D---- C:\Program Files\Crawler
2009-01-30 19:09:00 ----D---- C:\Users\Sunchild\AppData\Roaming\Spyware Terminator
2009-01-30 19:09:00 ----D---- C:\ProgramData\Spyware Terminator
2009-01-30 19:08:57 ----D---- C:\Program Files\Spyware Terminator
2009-01-30 19:08:23 ----D---- C:\Program Files\CCleaner
2009-01-30 19:07:03 ----D---- C:\Users\Sunchild\AppData\Roaming\Malwarebytes
2009-01-30 19:06:58 ----D---- C:\ProgramData\Malwarebytes
2009-01-30 19:06:58 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-30 18:55:24 ----D---- C:\ProgramData\SiteAdvisor
2009-01-30 18:53:09 ----D---- C:\Program Files\Common Files\McAfee
2009-01-30 18:53:08 ----D---- C:\Program Files\McAfee.com
2009-01-30 18:53:07 ----D---- C:\Program Files\McAfee
2009-01-30 18:47:22 ----A---- C:\Windows\system32\DreamScene.dll
2009-01-30 18:45:24 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-01-30 18:44:49 ----D---- C:\Program Files\BitLocker
2009-01-30 18:44:14 ----A---- C:\Windows\system32\SecureKeyBackupCPL.dll
2009-01-30 18:42:25 ----A---- C:\Windows\system32\gpprefcl.dll
2009-01-30 18:40:07 ----D---- C:\ProgramData\McAfee
2009-01-30 18:29:53 ----D---- C:\Program Files\Microsoft
2009-01-30 18:29:38 ----D---- C:\Program Files\Windows Live SkyDrive
2009-01-30 18:29:21 ----D---- C:\Program Files\Windows Live
2009-01-30 18:29:06 ----D---- C:\Windows\PCHEALTH
2009-01-30 18:25:44 ----D---- C:\Program Files\Common Files\Windows Live
2009-01-30 18:06:57 ----A---- C:\Windows\system32\mshtml.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-01-30 18:02:44 ----A---- C:\Windows\system32\propdefs.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msstrc.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\mssprxy.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\mssitlb.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msshsq.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msshooks.dll
2009-01-30 18:02:44 ----A---- C:\Windows\system32\msscb.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\xmlfilter.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\wsepno.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\tquery.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\thawbrkr.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\srchadmin.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-01-30 18:02:43 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-01-30 18:02:43 ----A---- C:\Windows\system32\rtffilt.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\propsys.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\offfilt.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\nlhtml.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\msscntrs.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\mimefilt.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\korwbrkr.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\chtbrkr.dll
2009-01-30 18:02:43 ----A---- C:\Windows\system32\chsbrkr.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssvp.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssrch.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssphtb.dll
2009-01-30 18:02:42 ----A---- C:\Windows\system32\mssph.dll
2009-01-30 18:02:01 ----A---- C:\Windows\system32\tzres.dll
2009-01-30 17:49:49 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-01-30 17:49:49 ----A---- C:\Windows\system32\infocardapi.dll
2009-01-30 17:49:48 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-01-30 17:49:48 ----A---- C:\Windows\system32\icardres.dll
2009-01-30 17:49:48 ----A---- C:\Windows\system32\icardagt.exe
2009-01-30 17:49:47 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-01-30 17:49:46 ----A---- C:\Windows\system32\PresentationHost.exe
2009-01-30 17:46:23 ----A---- C:\Windows\system32\dfshim.dll
2009-01-30 17:46:22 ----A---- C:\Windows\system32\netfxperf.dll
2009-01-30 17:46:22 ----A---- C:\Windows\system32\mscoree.dll
2009-01-30 17:46:19 ----A---- C:\Windows\system32\mscorier.dll
2009-01-30 17:46:17 ----A---- C:\Windows\system32\mscories.dll
2009-01-30 17:44:47 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-01-30 17:44:46 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-01-30 17:44:46 ----A---- C:\Windows\system32\gameux.dll
2009-01-30 17:44:43 ----A---- C:\Windows\system32\ieframe.dll
2009-01-30 17:44:42 ----A---- C:\Windows\system32\wininet.dll
2009-01-30 17:44:42 ----A---- C:\Windows\system32\urlmon.dll
2009-01-30 17:44:41 ----A---- C:\Windows\system32\mstime.dll
2009-01-30 17:44:41 ----A---- C:\Windows\system32\jsproxy.dll
2009-01-30 17:44:41 ----A---- C:\Windows\system32\iertutil.dll
2009-01-30 17:44:35 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-01-30 17:44:33 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-01-30 17:44:26 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-01-30 17:43:35 ----A---- C:\Windows\explorer.exe
2009-01-30 17:43:33 ----A---- C:\Windows\system32\EncDec.dll
2009-01-30 17:43:32 ----A---- C:\Windows\system32\psisdecd.dll
2009-01-30 17:43:30 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-01-30 17:43:26 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-01-30 17:43:26 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-01-30 17:43:26 ----A---- C:\Windows\system32\mf.dll
2009-01-30 17:43:26 ----A---- C:\Windows\system32\logagent.exe
2009-01-30 17:43:22 ----A---- C:\Windows\system32\kd1394.dll
2009-01-30 17:43:21 ----A---- C:\Windows\system32\winresume.exe
2009-01-30 17:43:21 ----A---- C:\Windows\system32\winload.exe
2009-01-30 17:43:21 ----A---- C:\Windows\system32\ci.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\srdelayed.exe
2009-01-30 17:43:20 ----A---- C:\Windows\system32\srcore.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\srclient.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\setbcdlocale.dll
2009-01-30 17:43:20 ----A---- C:\Windows\system32\rstrui.exe
2009-01-30 17:43:20 ----A---- C:\Windows\system32\kbd106n.dll
2009-01-30 17:43:12 ----A---- C:\Windows\system32\rpcrt4.dll
2009-01-30 17:43:11 ----A---- C:\Windows\system32\pacerprf.dll
2009-01-30 17:43:10 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-01-30 17:43:10 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-01-30 17:43:10 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-01-30 17:43:07 ----A---- C:\Windows\system32\msxml3.dll
2009-01-30 17:43:06 ----A---- C:\Windows\system32\emdmgmt.dll
2009-01-30 17:43:05 ----A---- C:\Windows\system32\dataclen.dll
2009-01-30 17:43:05 ----A---- C:\Windows\system32\cdd.dll
2009-01-30 17:43:04 ----A---- C:\Windows\system32\win32spl.dll
2009-01-30 17:43:02 ----A---- C:\Windows\system32\shell32.dll
2009-01-30 17:42:59 ----A---- C:\Windows\system32\es.dll
2009-01-30 17:42:55 ----A---- C:\Windows\system32\netapi32.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\wshext.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\wscript.exe
2009-01-30 17:42:51 ----A---- C:\Windows\system32\vbscript.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\scrrun.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\scrobj.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\jscript.dll
2009-01-30 17:42:51 ----A---- C:\Windows\system32\cscript.exe
2009-01-30 17:42:49 ----A---- C:\Windows\system32\wmpeffects.dll
2009-01-30 17:42:48 ----A---- C:\Windows\system32\wersvc.dll
2009-01-30 17:42:48 ----A---- C:\Windows\system32\Faultrep.dll
2009-01-30 17:42:47 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-01-30 17:42:46 ----A---- C:\Windows\system32\gdi32.dll
2009-01-30 17:42:45 ----A---- C:\Windows\system32\inetcomm.dll
2009-01-30 17:42:43 ----A---- C:\Windows\system32\quartz.dll
2009-01-30 17:42:38 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-01-30 17:42:38 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-01-30 17:42:36 ----A---- C:\Windows\system32\connect.dll
2009-01-30 17:38:25 ----A---- C:\Windows\system32\msxml6.dll
2009-01-30 17:29:00 ----D---- C:\ProgramData\NVIDIA
2009-01-30 17:25:24 ----D---- C:\Program Files\My Company Name
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wups2.dll
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wucltux.dll
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wuaueng.dll
2009-01-30 17:23:38 ----A---- C:\Windows\system32\wuauclt.exe
2009-01-30 17:23:31 ----SHD---- C:\Windows\Installer
2009-01-30 17:23:31 ----A---- C:\Windows\system32\wups.dll
2009-01-30 17:23:31 ----A---- C:\Windows\system32\wudriver.dll
2009-01-30 17:23:31 ----A---- C:\Windows\system32\wuapi.dll
2009-01-30 17:23:26 ----A---- C:\Windows\system32\wuwebv.dll
2009-01-30 17:23:26 ----A---- C:\Windows\system32\wuapp.exe
2009-01-30 17:20:32 ----D---- C:\Users\Sunchild\AppData\Roaming\InstallShield
2009-01-30 17:18:43 ----A---- C:\Windows\RTKAUDIOSERVICE.EXE
2009-01-30 17:18:37 ----D---- C:\Windows\system32\RTCOM
2009-01-30 17:18:07 ----A---- C:\Windows\DIFxAPI.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSWOW.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSTSXT.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSTSHD.dll
2009-01-30 17:18:05 ----A---- C:\Windows\system32\SRSHP360.dll
2009-01-30 17:18:05 ----A---- C:\Windows\SkyTel.exe
2009-01-30 17:18:05 ----A---- C:\Windows\RtlUpd.exe
2009-01-30 17:18:04 ----A---- C:\Windows\system32\RtkPgExt.dll
2009-01-30 17:18:04 ----A---- C:\Windows\system32\RtkCoInst.dll
2009-01-30 17:18:04 ----A---- C:\Windows\system32\RtkApoApi.dll
2009-01-30 17:18:00 ----A---- C:\Windows\system32\RtkAPO.dll
2009-01-30 17:17:55 ----A---- C:\Windows\RtHDVCpl.exe
2009-01-30 17:17:52 ----A---- C:\Windows\system32\maxxaudioapo.dll
2009-01-30 17:17:51 ----D---- C:\Program Files\Realtek
2009-01-30 17:17:49 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-30 17:17:48 ----R---- C:\Windows\RtlExUpd.dll
2009-01-30 17:17:48 ----A---- C:\Windows\HideWin.exe
2009-01-30 17:17:42 ----D---- C:\Program Files\Common Files\InstallShield
2009-01-30 17:15:16 ----D---- C:\Program Files\Intel
2009-01-30 17:14:51 ----A---- C:\Windows\GSetup.ini
2009-01-30 17:06:35 ----D---- C:\Users\Sunchild\AppData\Roaming\Identities
2009-01-30 17:06:30 ----SD---- C:\Users\Sunchild\AppData\Roaming\Microsoft
2009-01-30 17:06:30 ----D---- C:\Users\Sunchild\AppData\Roaming\Media Center Programs
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Modèles
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Menu Démarrer
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Favoris
2009-01-30 17:04:39 ----SHD---- C:\ProgramData\Bureau
2009-01-30 17:04:39 ----SHD---- C:\Program Files\Fichiers communs
2009-01-30 17:04:04 ----D---- C:\Windows\Debug
2009-01-30 16:43:23 ----D---- C:\Windows\SoftwareDistribution
2009-01-30 16:41:22 ----D---- C:\Windows\system32\catroot2
2009-01-30 16:41:11 ----D---- C:\Windows\CSC
2009-01-30 16:36:55 ----D---- C:\Windows\Panther
2009-01-30 15:05:00 ----RASH---- C:\Boot.ini.saved
2009-01-30 14:49:15 ----SH---- C:\Boot.BAK
2009-01-30 14:49:12 ----SHD---- C:\Boot
2009-01-29 20:18:07 ----SHD---- C:\RECYCLER
2009-01-29 18:40:52 ----SHD---- C:\System Volume Information
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvwssr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvwss.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvwgf2um.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvvsvc.exe
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvvitvsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvvitvs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvudisp.exe
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvcr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvsvc.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvoglv32.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmoblsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmobls.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmctray.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccssr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccss.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccsrs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvmccs.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvgamesr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvgames.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvdispsr.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvdisps.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvd3dum.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcuda.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcpl.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcod137.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvcod.dll
2009-01-15 08:19:00 ----A---- C:\Windows\system32\nvapi.dll

======List of files/folders modified in the last 1 months======

2009-02-07 15:02:22 ----D---- C:\Windows\Prefetch
2009-02-07 15:02:15 ----D---- C:\Windows\Temp
2009-02-07 14:50:29 ----D---- C:\Windows\System32
2009-02-07 14:50:29 ----D---- C:\Windows\inf
2009-02-07 14:50:29 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-02-07 14:49:16 ----D---- C:\Windows
2009-02-07 12:08:18 ----D---- C:\Windows\registration
2009-02-07 12:06:22 ----D---- C:\Program Files\Internet Explorer
2009-02-07 11:40:55 ----RD---- C:\Program Files
2009-02-06 19:12:20 ----RSD---- C:\Windows\assembly
2009-02-05 15:46:29 ----RSD---- C:\Windows\Fonts
2009-02-04 07:15:20 ----D---- C:\Windows\system32\WDI
2009-02-03 16:05:27 ----HD---- C:\ProgramData
2009-02-03 15:19:29 ----D---- C:\Windows\Cursors
2009-02-02 11:22:28 ----SHD---- C:\$Recycle.Bin
2009-02-02 11:21:45 ----RD---- C:\Users
2009-02-02 00:32:45 ----HD---- C:\Windows\system32\GroupPolicyUsers
2009-02-02 00:32:45 ----HD---- C:\Windows\system32\GroupPolicy
2009-02-01 19:44:14 ----A---- C:\Windows\system32\uxtheme.dll
2009-02-01 19:44:14 ----A---- C:\Windows\system32\themeui.dll
2009-02-01 19:44:14 ----A---- C:\Windows\system32\shsvcs.dll
2009-02-01 00:55:34 ----D---- C:\Windows\Tasks
2009-02-01 00:55:34 ----D---- C:\Windows\system32\Tasks
2009-02-01 00:41:25 ----SD---- C:\ProgramData\Microsoft
2009-02-01 00:30:27 ----D---- C:\Windows\system32\drivers
2009-01-31 23:10:10 ----D---- C:\Program Files\Common Files
2009-01-31 23:09:30 ----D---- C:\Windows\system32\catroot
2009-01-31 22:52:56 ----D---- C:\Windows\system32\wbem
2009-01-31 22:51:57 ----D---- C:\Windows\system32\config
2009-01-31 22:51:51 ----D---- C:\Windows\system32\spool
2009-01-31 22:51:51 ----D---- C:\Windows\system32\Msdtc
2009-01-31 22:51:50 ----D---- C:\Windows\system32\CodeIntegrity
2009-01-31 18:11:19 ----D---- C:\Windows\system32\fr-FR
2009-01-31 18:11:19 ----D---- C:\Windows\system32\en-US
2009-01-31 17:33:39 ----D---- C:\Windows\winsxs
2009-01-31 17:05:43 ----D---- C:\Windows\rescache
2009-01-31 13:07:00 ----D---- C:\Windows\Logs
2009-01-30 20:25:56 ----D---- C:\Program Files\Common Files\microsoft shared
2009-01-30 19:26:57 ----D---- C:\Program Files\Microsoft Games
2009-01-30 18:58:06 ----D---- C:\Windows\Web
2009-01-30 18:44:09 ----D---- C:\Windows\system32\zh-TW
2009-01-30 18:44:09 ----D---- C:\Windows\system32\zh-CN
2009-01-30 18:44:09 ----D---- C:\Windows\system32\uk-UA
2009-01-30 18:44:09 ----D---- C:\Windows\system32\tr-TR
2009-01-30 18:44:09 ----D---- C:\Windows\system32\th-TH
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sv-SE
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sr-Latn-CS
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sl-SI
2009-01-30 18:44:09 ----D---- C:\Windows\system32\sk-SK
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ru-RU
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ro-RO
2009-01-30 18:44:08 ----D---- C:\Windows\system32\pt-PT
2009-01-30 18:44:08 ----D---- C:\Windows\system32\pt-BR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\pl-PL
2009-01-30 18:44:08 ----D---- C:\Windows\system32\nl-NL
2009-01-30 18:44:08 ----D---- C:\Windows\system32\nb-NO
2009-01-30 18:44:08 ----D---- C:\Windows\system32\lv-LV
2009-01-30 18:44:08 ----D---- C:\Windows\system32\lt-LT
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ko-KR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ja-JP
2009-01-30 18:44:08 ----D---- C:\Windows\system32\it-IT
2009-01-30 18:44:08 ----D---- C:\Windows\system32\hu-HU
2009-01-30 18:44:08 ----D---- C:\Windows\system32\hr-HR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\he-IL
2009-01-30 18:44:08 ----D---- C:\Windows\system32\fi-FI
2009-01-30 18:44:08 ----D---- C:\Windows\system32\et-EE
2009-01-30 18:44:08 ----D---- C:\Windows\system32\es-ES
2009-01-30 18:44:08 ----D---- C:\Windows\system32\el-GR
2009-01-30 18:44:08 ----D---- C:\Windows\system32\de-DE
2009-01-30 18:44:08 ----D---- C:\Windows\system32\da-DK
2009-01-30 18:44:08 ----D---- C:\Windows\system32\cs-CZ
2009-01-30 18:44:08 ----D---- C:\Windows\system32\bg-BG
2009-01-30 18:44:08 ----D---- C:\Windows\system32\ar-SA
2009-01-30 18:41:54 ----RSD---- C:\Windows\Media
2009-01-30 18:22:31 ----D---- C:\Windows\Microsoft.NET
2009-01-30 18:17:11 ----D---- C:\Windows\PolicyDefinitions
2009-01-30 18:17:11 ----D---- C:\Windows\ehome
2009-01-30 18:17:11 ----D---- C:\Windows\AppPatch
2009-01-30 18:17:11 ----D---- C:\Program Files\Windows Mail
2009-01-30 18:17:10 ----D---- C:\Windows\system32\migration
2009-01-30 18:17:10 ----D---- C:\Windows\system32\Boot
2009-01-30 18:17:08 ----D---- C:\Windows\system32\XPSViewer
2009-01-30 17:25:06 ----D---- C:\Windows\Help
2009-01-30 17:15:17 ----D---- C:\Windows\system32\restore
2009-01-30 17:04:39 ----D---- C:\Program Files\Windows NT
2009-01-30 16:45:57 ----ASH---- C:\Program Files\desktop.ini
2009-01-09 17:35:30 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-04-11 350720]
R1 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\Windows\System32\Drivers\Mpfp.sys [2008-06-02 130424]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2009-01-30 141312]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-02-14 2061528]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2009-01-14 15504]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\Windows\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\Windows\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-01-15 7740320]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-01-25 106496]
S3 ajkybjzl;ajkybjzl; C:\Windows\system32\drivers\ajkybjzl.sys []
S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2009-01-24 14336]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-04-11 5632]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-01-30 8059]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 mferkdk;McAfee Inc. mferkdk; C:\Windows\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-04-11 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-04-11 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-04-11 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-04-11 6016]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-04-11 83328]
S4 ErrDev;Pilote de périphérique d’erreur matérielle Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-04-11 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-04-11 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-04-11 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-04-11 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-14 170640]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-12-05 206096]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-10-10 792696]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-01-15 207392]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-01-30 570880]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TuneUp.ProgramStatisticsSvc;@%SystemRoot%\System32\TUProgSt.exe,-1; C:\Windows\System32\TUProgSt.exe [2009-01-31 603904]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-04-11 21504]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-09-16 605512]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-04-11 21504]
S3 aspnet_state;Service d'état ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-27 34312]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-04-11 523776]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-01-24 216232]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2009-01-31 360192]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-04-11 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-04-11 917504]

-----------------EOF-----------------

philae
 Posté le 07/02/2009 à 15:16 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

re

ok merci

* lance hijacktis "do a system scan only" puis coche ces lignes :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll

O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll

O4 - HKLM\..\Run: [Glass2k] C:\Users\Sunchild\AppData\Local\Temp\installer.exe

O8 - Extra context menu item: Crawler Search - tbr:iemenu

O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll

* toutes applications fermées, clique sur FIX CHECKED

et

* via ajout et suppression de programmes, supprime

Crawler

Roaming\EoRezo

* supprime également

C:\Users\Sunchild\AppData\Roaming\EoRezo

C:\Program Files\Crawler

ensuite

* fait un scan antivirus en ligne ici

Kaspersky

* poste le rapport ensuite


Sunchild
 Posté le 07/02/2009 à 16:42 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

re

a la suite des manip, l'ordinateur m'a demander de redémarrer et j'ai le message d'erreur suivant :

est-ce normal ??

je vais lancer le scan kaspersky....

Publicité
philae
 Posté le 07/02/2009 à 16:51 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

j'avoue que je ne vois pas le rapport avec les manips faites

Sunchild
 Posté le 07/02/2009 à 17:16 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

dsl voici le rp hitjackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:13:04, on 07/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\System32\wpcumi.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Winamp\winamp.exe
D:\2 - Logiciels\Antivirus\Hitjackthis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O1 - Hosts: ::1 localhost
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [McAfee Backup] "C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\sunchild\appdata\local\temp\WLZ1FB0.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\sunchild\appdata\local\temp\WLZ1FB0.SH! (User 'Default user')
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe

--
End of file - 6718 bytes

philae
 Posté le 07/02/2009 à 17:26 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

ce n'est pas le rapport du scan de kaspersky....

Sunchild
 Posté le 07/02/2009 à 17:42 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

le scan est en cour.... je posterai le rapport dans mon prochain post

philae
 Posté le 07/02/2009 à 18:02 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

OK à plus tard donc

Sunchild
 Posté le 07/02/2009 à 18:14 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

hum un imprévu !!!

j'ai eu ceci :

philae
 Posté le 07/02/2009 à 18:16 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

bizarre...........à quel moment exactement ?

.ré essaye pour voir, sinon essaye celui ci de scan

Bitdefender

Sunchild
 Posté le 07/02/2009 à 18:28 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Astucien

il m'a afficher ce message a la fin de l'installation des mise-à-jour

jessaye avec bitdefender

ça m'arrangerai un log compatible firefox... si possible

philae
 Posté le 07/02/2009 à 18:34 
Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Grande Maîtresse astucienne

Publicité
Pages : [1] 2 3 ... Fin
Page 1 sur 3 [Fin]

Vous devez être connecté pour poster des messages. Cliquez ici pour vous identifier.

Vous n'avez pas de compte ? Créez-en un gratuitement !


Sujets relatifs
Résultat d'un scan avec ZHPCleaner .
Résultat scan ADW Cleaner 4.109
adwcleaner scan résultat
résultat du scan en ligne Kapersky
resultat scan
résultat scan anti rootkits
virus détecté- résultat scan hijackthis
Résultat scan en ligne
résultat de 2 scan en mode sans échec !
resultat du scan
Plus de sujets relatifs à résultat de scan incompréhensible
 > Tous les forums > Forum Sécurité