Votre question

Probleme internet / virus ?

Tags :
  • Windows
  • Sécurité
Dernière réponse : dans Sécurité et virus
18 Février 2009 15:19:31

Bonjour, j'ai plein de soucis Mozilla et IExplore, tel que google qui est lent, qui ouvre les pages dans des nouveaux onglets, les accents deviennent des signes, quand je met 1 code Html sur mon site cela me met ça /" a la place de " seul etc...
voici mon rapport Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 15:16:18, on 18/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\arservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\KIFFEU~1\APPLIC~1\MICROS~1\clipsrv.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\program files\steam\steam.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\TeamSpeak3\TeamSpeak.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Kiffeur999\Bureau\CSS\HijackThis-fr-Colok.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F3 - REG:win.ini: load=C:\WINDOWS\cisvc.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
O2 - BHO: -Sans nom - {5C255C8A-E604-49b4-9D64-90988571CECB} - -Manquant
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 -BarreOut. PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O3 -BarreOut. eSnips - {ED1184DA-E57E-4480-99D0-A16809037F54} - C:\Program Files\eSnips\SnipBar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [eSnips] "C:\Program Files\eSnips\ClientGW.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O8 - Extra du menu contextuel &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra du menu contextuel &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra du menu contextuel &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra du menu contextuel E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra du menu contextuel Snip to my eSnips account - C:\Program Files\eSnips\res\SnipIt.htm
O9 - Bouton Extra: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Bouton Extra: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Bouton Extra: -Sans nom - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Outil Extra du menu : Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Bouton Extra: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Bouton Extra: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
O9 - Bouton Extra: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Outil Extra du menu : Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986....
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B7D8334-624E-49EA-8B71-3074D52FE898}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{352D4A83-9FC7-4634-BC42-A40EDCB6912F}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{380236EF-DA96-443C-9D0B-9C5B41B6B8B1}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{5068E24F-3914-4C39-964E-F1B020C6BBC5}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{B2D2D4D8-215B-448D-9409-E5F0257F5934}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{C14BF149-EE6A-4E04-9AFA-15B88E7C5262}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{E3860172-C84E-482F-B332-E1C2E400FA08}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer = 85.255.116.43,85.255.112.145
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.43,85.255.112.145
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

Autres pages sur : probleme internet virus

a c 296 8 Sécurité
a b 9 Windows
18 Février 2009 16:09:33

Salut,

  • Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) sur ton Bureau.

  • Double-clique sur SmitfraudFix.exe pour le lancer.

  • Choisis l'option 1 puis Entrée.

  • Un rapport sera généré, poste-le dans ta prochaine réponse.

    /!\ process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus./!\

    ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix.
    19 Février 2009 20:25:51

    SmitFraudFix v2.398

    Rapport fait à 20:24:08,82, 19/02/2009
    Executé à partir de C:\Documents and Settings\Kiffeur999\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\cisvc.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\WINDOWS\system32\lexpps.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\program files\steam\steam.exe
    C:\Program Files\Stardock\CursorFX\CursorFX.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\TeamSpeak3\TeamSpeak.exe
    C:\Program Files\Visicom Media\FTP Expert 3\ftpxpert3.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Kiffeur999\SmitfraudFix\Policies.exe
    C:\WINDOWS\system32\cmd.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    C:\autorun.inf PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kiffeur999


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\KIFFEU~1\LOCALS~1\Temp


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kiffeur999\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\KIFFEU~1\Favoris


    »»»»»»»»»»»»»»»»»»»»»»»» Bureau


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"


    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    o4Patch
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri



    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri



    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    Agent.OMZ.Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~2.0\\adialhk.dll"


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» RK



    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Votre ordinateur est certainement victime d'un détournement de DNS: 85.255.x.x détecté !

    Description: Bluetooth PAN Network Adapter - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 85.255.116.43
    DNS Server Search Order: 85.255.112.145

    Votre ordinateur est certainement victime d'un détournement de DNS: 85.255.x.x détecté !

    Description: NETGEAR RangeMax(TM) Wireless USB 2.0 Adapter WPN111 - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 85.255.116.43
    DNS Server Search Order: 85.255.112.145

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{2B7D8334-624E-49EA-8B71-3074D52FE898}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{352D4A83-9FC7-4634-BC42-A40EDCB6912F}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{380236EF-DA96-443C-9D0B-9C5B41B6B8B1}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{5068E24F-3914-4C39-964E-F1B020C6BBC5}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{B2D2D4D8-215B-448D-9409-E5F0257F5934}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{C14BF149-EE6A-4E04-9AFA-15B88E7C5262}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{E3860172-C84E-482F-B332-E1C2E400FA08}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{2B7D8334-624E-49EA-8B71-3074D52FE898}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{352D4A83-9FC7-4634-BC42-A40EDCB6912F}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{380236EF-DA96-443C-9D0B-9C5B41B6B8B1}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{5068E24F-3914-4C39-964E-F1B020C6BBC5}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{B2D2D4D8-215B-448D-9409-E5F0257F5934}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{C14BF149-EE6A-4E04-9AFA-15B88E7C5262}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{E3860172-C84E-482F-B332-E1C2E400FA08}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{2B7D8334-624E-49EA-8B71-3074D52FE898}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{352D4A83-9FC7-4634-BC42-A40EDCB6912F}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{380236EF-DA96-443C-9D0B-9C5B41B6B8B1}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{5068E24F-3914-4C39-964E-F1B020C6BBC5}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{B2D2D4D8-215B-448D-9409-E5F0257F5934}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{C14BF149-EE6A-4E04-9AFA-15B88E7C5262}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{E3860172-C84E-482F-B332-E1C2E400FA08}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.116.43,85.255.112.145


    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    Contenus similaires
    a c 296 8 Sécurité
    a b 9 Windows
    19 Février 2009 20:28:11

  • Relance SmitfraudFix et choisis l'option 5.

  • Réponds Oui à la question puis poste le rapport.
    19 Février 2009 20:36:10

    SmitFraudFix v2.398

    Rapport fait à 20:34:37,96, 19/02/2009
    Executé à partir de C:\Documents and Settings\Kiffeur999\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» DNS Avant Fix

    Votre ordinateur est certainement victime d'un détournement de DNS: 85.255.x.x détecté !

    Description: Bluetooth PAN Network Adapter - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 85.255.116.43
    DNS Server Search Order: 85.255.112.145

    Votre ordinateur est certainement victime d'un détournement de DNS: 85.255.x.x détecté !

    Description: NETGEAR RangeMax(TM) Wireless USB 2.0 Adapter WPN111 - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 85.255.116.43
    DNS Server Search Order: 85.255.112.145

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{2B7D8334-624E-49EA-8B71-3074D52FE898}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{352D4A83-9FC7-4634-BC42-A40EDCB6912F}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{380236EF-DA96-443C-9D0B-9C5B41B6B8B1}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{5068E24F-3914-4C39-964E-F1B020C6BBC5}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{B2D2D4D8-215B-448D-9409-E5F0257F5934}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{C14BF149-EE6A-4E04-9AFA-15B88E7C5262}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{E3860172-C84E-482F-B332-E1C2E400FA08}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{2B7D8334-624E-49EA-8B71-3074D52FE898}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{352D4A83-9FC7-4634-BC42-A40EDCB6912F}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{380236EF-DA96-443C-9D0B-9C5B41B6B8B1}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{5068E24F-3914-4C39-964E-F1B020C6BBC5}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{B2D2D4D8-215B-448D-9409-E5F0257F5934}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{C14BF149-EE6A-4E04-9AFA-15B88E7C5262}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{E3860172-C84E-482F-B332-E1C2E400FA08}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{2B7D8334-624E-49EA-8B71-3074D52FE898}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{352D4A83-9FC7-4634-BC42-A40EDCB6912F}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{380236EF-DA96-443C-9D0B-9C5B41B6B8B1}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{5068E24F-3914-4C39-964E-F1B020C6BBC5}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{B2D2D4D8-215B-448D-9409-E5F0257F5934}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{BB77BB75-E254-4C80-AACE-06BD69DA02B0}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{C14BF149-EE6A-4E04-9AFA-15B88E7C5262}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{E3860172-C84E-482F-B332-E1C2E400FA08}: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.116.43,85.255.112.145
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.116.43,85.255.112.145

    »»»»»»»»»»»»»»»»»»»»»»»» DNS Après Fix

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243

    a c 296 8 Sécurité
    a b 9 Windows
    19 Février 2009 20:42:50

  • Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
  • Double-clique sur RSIT.exe afin de lancer le programme.
  • Clique sur Continue à l'écran Disclaimer.
  • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparait à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : les rapports sont sauvegardés dans le dossier C:\rsit\.
    19 Février 2009 20:47:55

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Kiffeur999 at 2009-02-19 20:46:21
    Microsoft Windows XP Professionnel Service Pack 2
    System drive C: has 195 GB (84%) free of 232 GB
    Total RAM: 1023 MB (40% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:46:38, on 19/02/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\cisvc.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\WINDOWS\system32\lexpps.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\program files\steam\steam.exe
    C:\Program Files\Stardock\CursorFX\CursorFX.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\TeamSpeak3\TeamSpeak.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\cmd.exe
    C:\Program Files\Windows Live\Mail\wlmail.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Visicom Media\FTP Expert 3\ftpxpert3.exe
    C:\Documents and Settings\Kiffeur999\Bureau\RSIT.exe
    C:\Program Files\trend micro\Kiffeur999.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    F3 - REG:win.ini: load=C:\WINDOWS\cisvc.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
    O3 - Toolbar: eSnips - {ED1184DA-E57E-4480-99D0-A16809037F54} - C:\Program Files\eSnips\SnipBar.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
    O4 - HKLM\..\Run: [eSnips] "C:\Program Files\eSnips\ClientGW.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
    O4 - HKLM\..\Policies\Explorer\Run: [ClipSrv] C:\DOCUME~1\KIFFEU~1\APPLIC~1\MICROS~1\clipsrv.exe /waitservice
    O4 - HKLM\..\Policies\Explorer\Run: [ComRepl] C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\MICROS~1\comrepl.exe /waitservice
    O4 - HKCU\..\Policies\Explorer\Run: [Spool] C:\WINDOWS\spoolsv.exe /waitservice
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-21-1294530902-4232896364-2302500881-1007\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'HP_Administrateur')
    O4 - HKUS\S-1-5-21-1294530902-4232896364-2302500881-1007\..\Policies\Explorer\Run: [Cisvc] C:\WINDOWS\cisvc.exe /waitservice (User 'HP_Administrateur')
    O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [MstInit] C:\DOCUME~1\KIFFEU~1\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe /waitservice (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MstInit] C:\DOCUME~1\KIFFEU~1\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe /waitservice (User 'Default user')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
    O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe
    O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Snip to my eSnips account - C:\Program Files\eSnips\res\SnipIt.htm
    O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986....
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    --
    End of file - 10665 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
    RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-08-09 308856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
    BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll [2008-01-25 496952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-26 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}]
    PDFCreator Toolbar Helper - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll [2008-02-22 806912]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-26 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-26 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - PDFCreator Toolbar - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll [2008-02-22 806912]
    {ED1184DA-E57E-4480-99D0-A16809037F54} - eSnips - C:\Program Files\eSnips\SnipBar.dll [2007-12-10 278528]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2008-08-09 185896]
    "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-11-11 344064]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-26 136600]
    "StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
    "BluetoothAuthenticationAgent"=C:\WINDOWS\system32\bthprops.cpl [2004-08-10 110592]
    "AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe [2007-03-09 200768]
    "ClientGW"= []
    "eSnips"=C:\Program Files\eSnips\ClientGW.exe [2007-12-10 872448]
    "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-07-22 16261632]
    "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-04 69632]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "ClipSrv"=C:\DOCUME~1\KIFFEU~1\APPLIC~1\MICROS~1\clipsrv.exe [2009-01-21 77824]
    "ComRepl"=C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\MICROS~1\comrepl.exe [2009-01-21 77824]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
    "Steam"=c:\program files\steam\steam.exe [2009-01-24 1410296]
    "CursorFX"=C:\Program Files\Stardock\CursorFX\CursorFX.exe [2008-07-07 416768]
    "AdobeBridge"= []

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "Spool"=C:\WINDOWS\spoolsv.exe [2009-01-21 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
    C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
    C:\WINDOWS\ARPWRMSG.EXE [2005-08-03 77312]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
    c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-01-17 486856]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMAScheduler]
    c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe [2006-04-13 90112]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
    C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ftutil2]
    C:\WINDOWS\system32\ftutil2.dll [2004-06-07 106496]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe [2005-02-17 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
    C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2006-02-15 249856]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
    c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {F073BDC9-0D67-4ff0-879E-27241C843828} /MODE CfgWiz /CMDLINE REBOOT []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
    C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe [2002-07-31 57344]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler]
    []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
    C:\WINDOWS\SMINST\RECGUARD.EXE [2005-07-22 237568]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
    C:\Windows\Creator\Remind_XP.exe [2004-12-14 663552]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
    C:\WINDOWS\RTHDCPL.EXE [2006-07-22 16261632]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
    c:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    c:\program files\steam\steam.exe [2009-01-24 1410296]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^RocketDock.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\ROCKET~1\ROCKET~1.EXE [2007-03-18 630784]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^TransBar.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\TransBar\TransBar.exe [2005-06-01 65536]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^UberIcon.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\UberIcon\UBERIC~1.EXE [2006-05-21 180224]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^Y'z Shadow.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\YzShadow\YzShadow.exe [2006-05-21 155648]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "navapsvc"=3
    "Symantec Core LC"=3
    "SPBBCSvc"=3
    "SNDSrvc"=3
    "SAVScan"=3
    "NSCService"=3
    "LightScribeService"=2
    "IDriverT"=3
    "comHost"=3
    "ccSetMgr"=2
    "ccProxy"=2
    "ccISPwdSvc"=3
    "ccEvtMgr"=2
    "Ati HotKey Poller"=2

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe

    C:\Documents and Settings\Kiffeur999\Menu Démarrer\Programmes\Démarrage
    Pin.lnk - C:\hp\bin\CLOAKER.EXE
    PinMcLnk.lnk - C:\hp\bin\cloaker.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\WINDOWS\system32\Ati2evxx.dll [2008-02-26 126976]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    C:\WINDOWS\system32\klogon.dll [2007-06-28 206088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1
    "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
    "EnableLUA"=0

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=36
    "NoSMBalloonTip"=0
    "NoDriveAutoRun"=FFFFFFFF

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoResolveSearch"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:D isabled:Windows Live Messenger"
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:*:Enabled:ActiveSync RAPI Manager"
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:*:Enabled:ActiveSync Application"
    "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    ======List of files/folders created in the last 1 months======

    2009-02-19 20:24:14 ----A---- C:\WINDOWS\system32\tmp.txt
    2009-02-19 20:24:08 ----A---- C:\rapport.txt
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\WS2Fix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\VCCLSID.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\VACFix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\swxcacls.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\swsc.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\swreg.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\SrchSTS.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\Process.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\o4Patch.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\IEDFix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\dumphive.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\Agent.OMZ.Fix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\404Fix.exe
    2009-02-18 11:54:59 ----HD---- C:\WINDOWS\system32\system32
    2009-02-17 19:51:50 ----D---- C:\Program Files\Spybot - Search & Destroy
    2009-02-17 19:51:50 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2009-02-16 07:02:13 ----N---- C:\WINDOWS\system32\dbmsqlgc.dll
    2009-02-16 07:02:13 ----N---- C:\WINDOWS\system32\dbmsgnet.dll
    2009-02-16 07:00:43 ----D---- C:\Program Files\Microsoft SQL Server
    2009-02-16 06:59:04 ----D---- C:\Program Files\Vstplugins
    2009-02-16 06:59:02 ----D---- C:\Documents and Settings\All Users\Application Data\Sony
    2009-02-16 06:58:50 ----D---- C:\Program Files\Sony
    2009-02-16 06:57:06 ----D---- C:\Program Files\Sony Setup
    2009-02-15 18:17:10 ----D---- C:\Program Files\eSnips
    2009-02-15 18:16:59 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2009-02-14 17:36:09 ----A---- C:\WINDOWS\sessmgr.exe
    2009-02-14 15:57:34 ----D---- C:\Program Files\Fichiers communs\Skype
    2009-02-14 15:57:31 ----RD---- C:\Program Files\Skype
    2009-02-14 15:57:24 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
    2009-02-14 14:04:39 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
    2009-02-14 14:02:37 ----D---- C:\Program Files\IVT Corporation
    2009-02-10 21:36:07 ----D---- C:\WINDOWS\ASTULogTemp
    2009-02-10 21:35:55 ----A---- C:\ASLog.txt
    2009-02-09 20:02:19 ----A---- C:\WINDOWS\comrepl.exe
    2009-02-07 11:08:51 ----A---- C:\WINDOWS\logman.exe
    2009-02-04 11:32:25 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\Sites prédéfinis
    2009-02-04 11:31:38 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\Dynamique
    2009-02-04 11:31:22 ----D---- C:\Program Files\Visicom Media
    2009-02-03 20:39:01 ----D---- C:\Program Files\FRAps
    2009-02-01 13:31:34 ----D---- C:\Program Files\TeamSpeak3
    2009-01-28 21:55:26 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\HLSW
    2009-01-28 12:40:54 ----D---- C:\Documents and Settings\All Users\Application Data\FlashFXP
    2009-01-27 18:24:30 ----A---- C:\WINDOWS\system32\WNASPINT.DLL
    2009-01-27 18:19:52 ----D---- C:\Program Files\ejay
    2009-01-26 20:19:46 ----A---- C:\WINDOWS\system32\deploytk.dll
    2009-01-26 19:52:39 ----HD---- C:\autorun.inf
    2009-01-26 19:47:58 ----D---- C:\Program Files\UsbFix
    2009-01-26 19:02:44 ----D---- C:\Program Files\trend micro
    2009-01-26 19:02:43 ----D---- C:\rsit
    2009-01-25 18:01:48 ----D---- C:\Program Files\3GP Player
    2009-01-25 11:19:20 ----HDC---- C:\Documents and Settings\All Users\Application Data\{DE032019-B933-4DF4-9174-48C52613DA13}
    2009-01-25 11:19:18 ----D---- C:\Program Files\Stardock
    2009-01-25 11:15:43 ----D---- C:\WINDOWS\temp
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\system32\vfind.exe
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\system32\moveex.exe
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\nircmd.exe
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\catchme.exe
    2009-01-25 11:03:34 ----D---- C:\Program Files\AxBx
    2009-01-24 17:38:00 ----D---- C:\Program Files\Steam
    2009-01-24 15:47:34 ----D---- C:\Program Files\ZNsoft Corporation
    2009-01-24 14:59:48 ----D---- C:\Program Files\CCleaner
    2009-01-21 20:48:54 ----A---- C:\WINDOWS\cmstp.exe
    2009-01-21 20:48:54 ----A---- C:\WINDOWS\cisvc.exe
    2009-01-21 17:25:18 ----A---- C:\WINDOWS\spoolsv.exe
    2009-01-21 16:54:02 ----D---- C:\Downloads
    2009-01-21 16:30:39 ----A---- C:\WINDOWS\system32\pthread.dll
    2009-01-21 16:30:39 ----A---- C:\WINDOWS\system32\eJayWMExport.dll
    2009-01-21 16:30:39 ----A---- C:\WINDOWS\system32\eJ_Enumerator.dll
    2009-01-21 16:30:39 ----A---- C:\WINDOWS\system32\devil.dll
    2009-01-21 16:30:39 ----A---- C:\WINDOWS\system32\DartWeb.dll
    2009-01-21 16:30:39 ----A---- C:\WINDOWS\system32\DartSock.dll

    ======List of files/folders modified in the last 1 months======

    2009-02-19 20:24:15 ----D---- C:\WINDOWS\system32
    2009-02-19 20:07:27 ----D---- C:\Program Files\Mozilla Firefox
    2009-02-19 17:49:09 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2009-02-19 14:39:23 ----D---- C:\WINDOWS\Prefetch
    2009-02-19 14:39:16 ----AD---- C:\WINDOWS
    2009-02-19 11:08:11 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-19 11:06:24 ----D---- C:\WINDOWS\Registration
    2009-02-18 22:29:48 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-02-18 10:10:50 ----D---- C:\WINDOWS\system32\CatRoot
    2009-02-18 10:09:59 ----D---- C:\WINDOWS\system32\RTCOM
    2009-02-18 10:09:22 ----RSHD---- C:\WINDOWS\system32\dllcache
    2009-02-18 10:09:19 ----D---- C:\WINDOWS\system32\drivers
    2009-02-18 10:08:55 ----HD---- C:\WINDOWS\inf
    2009-02-17 19:51:50 ----RD---- C:\Program Files
    2009-02-17 19:29:29 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-02-17 19:29:13 ----D---- C:\Program Files\Fichiers communs\muvee Technologies
    2009-02-17 19:28:59 ----SHD---- C:\WINDOWS\Installer
    2009-02-17 19:28:44 ----RSD---- C:\WINDOWS\assembly
    2009-02-17 19:28:24 ----D---- C:\Program Files\Fichiers communs\Sonic Shared
    2009-02-17 19:28:21 ----RSD---- C:\WINDOWS\Fonts
    2009-02-17 19:27:56 ----D---- C:\WINDOWS\WinSxS
    2009-02-17 19:27:48 ----D---- C:\Program Files\Fichiers communs\HP
    2009-02-16 20:36:33 ----D---- C:\WINDOWS\system32\config
    2009-02-16 13:45:21 ----D---- C:\Program Files\eMule
    2009-02-16 07:02:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-02-16 07:02:13 ----HD---- C:\Program Files\Uninstall Information
    2009-02-15 18:17:16 ----SD---- C:\Documents and Settings\Kiffeur999\Application Data\Microsoft
    2009-02-15 18:16:59 ----D---- C:\Program Files\Fichiers communs
    2009-02-15 10:05:12 ----A---- C:\WINDOWS\err.txt
    2009-02-15 09:28:58 ----D---- C:\WINDOWS\system32\wbem
    2009-02-14 14:46:02 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-14 08:35:58 ----D---- C:\WINDOWS\security
    2009-02-13 08:54:18 ----D---- C:\WINDOWS\system
    2009-02-11 17:47:09 ----D---- C:\Program Files\Adobe
    2009-02-11 15:16:35 ----D---- C:\WINDOWS\system32\FxsTmp
    2009-02-10 18:25:34 ----D---- C:\WINDOWS\system32\LogFiles
    2009-02-08 14:28:58 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\Adobe
    2009-02-04 10:26:34 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2009-02-03 20:38:09 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\LimeWire
    2009-02-03 20:32:54 ----D---- C:\Program Files\LimeWire
    2009-02-01 12:30:54 ----AD---- C:\WINDOWS\ehome
    2009-02-01 12:29:55 ----A---- C:\WINDOWS\win.ini
    2009-02-01 09:28:22 ----D---- C:\Program Files\Kaspersky Lab
    2009-01-31 12:06:20 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\FileZilla
    2009-01-28 21:55:32 ----SD---- C:\Program Files\HLSW
    2009-01-26 20:20:30 ----D---- C:\Program Files\Java
    2009-01-26 20:19:35 ----A---- C:\WINDOWS\system32\javaws.exe
    2009-01-26 20:19:35 ----A---- C:\WINDOWS\system32\javaw.exe
    2009-01-26 20:19:35 ----A---- C:\WINDOWS\system32\java.exe
    2009-01-24 16:37:17 ----D---- C:\Program Files\SystemRequirementsLab
    2009-01-24 16:30:04 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\SystemRequirementsLab
    2009-01-24 15:50:31 ----D---- C:\Program Files\Creative
    2009-01-24 15:05:46 ----D---- C:\WINDOWS\pss
    2009-01-24 15:00:59 ----D---- C:\WINDOWS\Debug
    2009-01-24 14:48:44 ----SD---- C:\WINDOWS\Downloaded Program Files
    2009-01-24 14:48:44 ----D---- C:\Program Files\Fichiers communs\InstallShield
    2009-01-24 14:46:48 ----D---- C:\Program Files\CyberLink
    2009-01-24 14:45:53 ----D---- C:\Program Files\Mozilla Thunderbird
    2009-01-24 14:40:57 ----D---- C:\Program Files\DivX
    2009-01-24 14:39:38 ----D---- C:\Program Files\ASUS
    2009-01-24 14:21:57 ----D---- C:\WINDOWS\I386
    2009-01-24 14:21:57 ----A---- C:\WINDOWS\system32\uxtheme.dll
    2009-01-23 19:18:31 ----D---- C:\WINDOWS\system32\DirectX

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 40320]
    R1 klif;Klif; \??\C:\WINDOWS\system32\drivers\klif.sys []
    R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
    R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-01-24 278728]
    R2 cdralw2k;cdralw2k; C:\WINDOWS\system32\drivers\cdralw2k.sys [2005-08-19 2560]
    R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
    R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-01-24 25416]
    R3 aracpi;aracpi; C:\WINDOWS\system32\DRIVERS\aracpi.sys [2005-08-03 22784]
    R3 arkbcfltr;Microsoft PS2 Keyboard Filter; C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-03 5376]
    R3 armoucfltr;Microsoft PS2 Mouse Filter; C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-03 4992]
    R3 ARPolicy;ARPolicy; C:\WINDOWS\system32\DRIVERS\arpolicy.sys [2005-08-03 10112]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-02-26 2863616]
    R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
    R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
    R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-05-23 16272]
    R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-25 4353024]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
    R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-13 19072]
    R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-10 5888]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-03-31 27008]
    R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-10 57600]
    R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
    R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 26496]
    R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
    R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
    R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D.sys [2004-07-06 44544]
    R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service; C:\WINDOWS\system32\DRIVERS\WPN111.sys [2005-09-26 362944]
    S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
    S3 amk7wtd7;amk7wtd7; C:\WINDOWS\system32\drivers\amk7wtd7.sys []
    S3 arhidfltr;MS Ar HID Filter Driver; C:\WINDOWS\system32\DRIVERS\arhidfltr.sys [2005-08-03 19200]
    S3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-10 60800]
    S3 atidgllk;atidgllk; \??\C:\Program Files\ASUS\SmartDoctor\atidgllk.sys []
    S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-23 36496]
    S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-03 17024]
    S3 BTHMODEM;Pilote de communication série Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2004-08-03 38016]
    S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
    S3 BTHPORT;Pilote de port Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-04 274944]
    S3 BTHUSB;Pilote USB radio Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
    S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
    S3 HidBth;Miniport HID Microsoft Bluetooth; C:\WINDOWS\system32\DRIVERS\hidbth.sys [2004-08-03 25856]
    S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
    S3 MHNDRV;Pilote MHN; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
    S3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-10 61824]
    S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2005-11-19 20096]
    S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
    S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-02-27 81408]
    S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
    S3 se58bus;Sony Ericsson Device 088 driver (WDM); C:\WINDOWS\system32\DRIVERS\se58bus.sys [2006-09-05 61536]
    S3 se58mdfl;Sony Ericsson Device 088 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\se58mdfl.sys [2006-09-05 9360]
    S3 se58mdm;Sony Ericsson Device 088 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\se58mdm.sys [2006-09-05 97088]
    S3 se58mgmt;Sony Ericsson Device 088 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\se58mgmt.sys [2006-09-05 88624]
    S3 se58nd5;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (NDIS); C:\WINDOWS\system32\DRIVERS\se58nd5.sys [2006-09-05 18704]
    S3 se58obex;Sony Ericsson Device 088 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\se58obex.sys [2006-09-05 86432]
    S3 se58unic;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (WDM); C:\WINDOWS\system32\DRIVERS\se58unic.sys [2006-09-05 90800]
    S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
    S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
    S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
    S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
    S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
    S3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-10 20480]
    S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 ARSVC;ARSVC; C:\WINDOWS\arservice.exe [2005-08-03 58880]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-02-26 520192]
    R2 AVP;Kaspersky Anti-Virus 6.0; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe [2007-03-09 200768]
    R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
    R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
    R2 ehSched;Service de planification Media Center; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 103424]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-26 152984]
    R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2002-07-31 303104]
    R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
    R2 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
    S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-02-25 593920]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-10 268800]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-01 655624]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
    S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2004-08-10 14336]
    S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
    S4 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]

    -----------------EOF-----------------
    19 Février 2009 20:48:27

    Je dois y aller, je reviens demain soir, bonne nuit
    a c 296 8 Sécurité
    a b 9 Windows
    20 Février 2009 18:37:40

    1/

  • Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.
  • Double-clique sur OTMoveIt3.exe afin de le lancer.
  • Copie (Ctrl+C) le texte suivant ci-dessous :

    :processes
    explorer.exe

    :files
    C:\WINDOWS\spoolsv.exe
    C:\WINDOWS\cisvc.exe
    C:\WINDOWS\cmstp.exe
    C:\WINDOWS\logman.exe
    C:\WINDOWS\comrepl.exe
    C:\WINDOWS\sessmgr.exe
    C:\WINDOWS\system32\system32
    C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\MICROS~1\comrepl.exe
    C:\DOCUME~1\KIFFEU~1\APPLIC~1\MICROS~1\clipsrv.exe

    :reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "Spool"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "ClipSrv"=-
    "ComRepl"=-

    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]


  • Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
  • Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

    ---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.

  • Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    ---> Le nom du rapport correspond au moment de sa création : date_heure.log


    2/

  • Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
  • Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
  • Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
  • Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
  • Sélectionne Exécuter un examen rapide.
  • Clique sur Rechercher.
  • L'analyse démarre.
  • A la fin de l'analyse, un message s'affiche :
    Citation :
    L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

  • Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
  • Ferme tes navigateurs.
  • Si des malwares ont été détectés, clique sur Afficher les résultats.
  • Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
  • MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
    21 Février 2009 10:03:44

    Excuses moi hier j'ai eu un probleme j'effectue les opérations demandé et je t'envoie les rapport
    21 Février 2009 10:12:46

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== FILES ==========
    File/Folder C:\WINDOWS\spoolsv.exe not found.
    File/Folder C:\WINDOWS\cisvc.exe not found.
    File/Folder C:\WINDOWS\cmstp.exe not found.
    File/Folder C:\WINDOWS\logman.exe not found.
    File/Folder C:\WINDOWS\comrepl.exe not found.
    File/Folder C:\WINDOWS\sessmgr.exe not found.
    File/Folder C:\WINDOWS\system32\system32 not found.
    File/Folder C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\MICROS~1\comrepl.exe not found.
    File/Folder C:\DOCUME~1\KIFFEU~1\APPLIC~1\MICROS~1\clipsrv.exe not found.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler\\ not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\Spool not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\ClipSrv not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\ComRepl not found.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\KIFFEU~1\LOCALS~1\Temp\etilqs_e0SysnxgXfDADIJK2BMC scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\KIFFEU~1\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\KIFFEU~1\LOCALS~1\Temp\~DF4A75.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\cch~c34fbf81c84.htp scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\cch~c34fc1e2bfb.htp scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\cch~c35b899be7c.htp scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\cch~c35b8bf9c00.htp scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_798.dat scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7dc.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    File delete failed. C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_001_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_002_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_003_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\urlclassifier3.sqlite scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\XUL.mfl scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02212009_100024

    Files moved on Reboot...
    File C:\DOCUME~1\KIFFEU~1\LOCALS~1\Temp\etilqs_e0SysnxgXfDADIJK2BMC not found!
    C:\DOCUME~1\KIFFEU~1\LOCALS~1\Temp\WCESLog.log moved successfully.
    File C:\DOCUME~1\KIFFEU~1\LOCALS~1\Temp\~DF4A75.tmp not found!
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat scheduled to be moved on reboot.
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
    File C:\WINDOWS\temp\cch~c34fbf81c84.htp not found!
    File C:\WINDOWS\temp\cch~c34fc1e2bfb.htp not found!
    File C:\WINDOWS\temp\cch~c35b899be7c.htp not found!
    File C:\WINDOWS\temp\cch~c35b8bf9c00.htp not found!
    File C:\WINDOWS\temp\Perflib_Perfdata_798.dat not found!
    File C:\WINDOWS\temp\Perflib_Perfdata_7dc.dat not found!
    C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_001_ moved successfully.
    C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_002_ moved successfully.
    C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_003_ moved successfully.
    C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\Cache\_CACHE_MAP_ moved successfully.
    C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\urlclassifier3.sqlite moved successfully.
    C:\Documents and Settings\Kiffeur999\Local Settings\Application Data\Mozilla\Firefox\Profiles\jgfjvw8v.Kiffeur999\XUL.mfl moved successfully.
    21 Février 2009 10:24:58

    Malwarebytes' Anti-Malware 1.33
    Version de la base de données: 1654
    Windows 5.1.2600 Service Pack 2

    21/02/2009 10:22:37
    mbam-log-2009-02-21 (10-22-37).txt

    Type de recherche: Examen rapide
    Eléments examinés: 63203
    Temps écoulé: 7 minute(s), 54 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 2
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 3

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Mstsc (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully.

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\Program Files\Mozilla Firefox\components\iamfamous.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\Microsoft\sessmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Kiffeur999\Application Data\addon.dat (Malware.Trace) -> Quarantined and deleted successfully.
    a c 296 8 Sécurité
    a b 9 Windows
    21 Février 2009 13:07:44

  • Relance MBAM, va dans Quarantaine et supprime tout.

  • Refais un scan RSIT et poste le rapport log.
    21 Février 2009 13:55:18

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Kiffeur999 at 2009-02-21 13:54:14
    Microsoft Windows XP Professionnel Service Pack 2
    System drive C: has 195 GB (84%) free of 232 GB
    Total RAM: 1023 MB (28% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:54:23, on 21/02/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\arservice.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\program files\steam\steam.exe
    C:\Program Files\Stardock\CursorFX\CursorFX.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\TeamSpeak3\TeamSpeak.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Documents and Settings\Kiffeur999\Bureau\RSIT.exe
    C:\Program Files\trend micro\Kiffeur999.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
    O3 - Toolbar: eSnips - {ED1184DA-E57E-4480-99D0-A16809037F54} - C:\Program Files\eSnips\SnipBar.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
    O4 - HKLM\..\Run: [eSnips] "C:\Program Files\eSnips\ClientGW.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
    O4 - HKLM\..\Policies\Explorer\Run: [rsvp] C:\DOCUME~1\KIFFEU~1\APPLIC~1\rsvp.exe /waitservice
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [MstInit] C:\DOCUME~1\KIFFEU~1\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe /waitservice (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MstInit] C:\DOCUME~1\KIFFEU~1\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe /waitservice (User 'Default user')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
    O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe
    O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Snip to my eSnips account - C:\Program Files\eSnips\res\SnipIt.htm
    O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986....
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    --
    End of file - 10153 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
    RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-08-09 308856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
    BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll [2008-01-25 496952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-26 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}]
    PDFCreator Toolbar Helper - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll [2008-02-22 806912]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-26 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-26 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - PDFCreator Toolbar - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll [2008-02-22 806912]
    {ED1184DA-E57E-4480-99D0-A16809037F54} - eSnips - C:\Program Files\eSnips\SnipBar.dll [2007-12-10 278528]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2008-08-09 185896]
    "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-11-11 344064]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-26 136600]
    "StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
    "BluetoothAuthenticationAgent"=C:\WINDOWS\system32\bthprops.cpl [2004-08-10 110592]
    "AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe [2007-03-09 200768]
    "ClientGW"= []
    "eSnips"=C:\Program Files\eSnips\ClientGW.exe [2007-12-10 872448]
    "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-07-22 16261632]
    "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-04 69632]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "rsvp"=C:\DOCUME~1\KIFFEU~1\APPLIC~1\rsvp.exe /waitservice []

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
    "Steam"=c:\program files\steam\steam.exe [2009-01-24 1410296]
    "CursorFX"=C:\Program Files\Stardock\CursorFX\CursorFX.exe [2008-07-07 416768]
    "AdobeBridge"= []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
    C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
    C:\WINDOWS\ARPWRMSG.EXE [2005-08-03 77312]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
    c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-01-17 486856]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMAScheduler]
    c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe [2006-04-13 90112]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
    C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ftutil2]
    C:\WINDOWS\system32\ftutil2.dll [2004-06-07 106496]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe [2005-02-17 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
    C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2006-02-15 249856]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
    c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {F073BDC9-0D67-4ff0-879E-27241C843828} /MODE CfgWiz /CMDLINE REBOOT []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
    C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe [2002-07-31 57344]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
    C:\WINDOWS\SMINST\RECGUARD.EXE [2005-07-22 237568]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
    C:\Windows\Creator\Remind_XP.exe [2004-12-14 663552]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
    C:\WINDOWS\RTHDCPL.EXE [2006-07-22 16261632]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
    c:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    c:\program files\steam\steam.exe [2009-01-24 1410296]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^RocketDock.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\ROCKET~1\ROCKET~1.EXE [2007-03-18 630784]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^TransBar.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\TransBar\TransBar.exe [2005-06-01 65536]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^UberIcon.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\UberIcon\UBERIC~1.EXE [2006-05-21 180224]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kiffeur999^Menu Démarrer^Programmes^Démarrage^Y'z Shadow.lnk]
    C:\WINDOWS\BRICOP~1\VISTAI~1\YzShadow\YzShadow.exe [2006-05-21 155648]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "navapsvc"=3
    "Symantec Core LC"=3
    "SPBBCSvc"=3
    "SNDSrvc"=3
    "SAVScan"=3
    "NSCService"=3
    "LightScribeService"=2
    "IDriverT"=3
    "comHost"=3
    "ccSetMgr"=2
    "ccProxy"=2
    "ccISPwdSvc"=3
    "ccEvtMgr"=2
    "Ati HotKey Poller"=2

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
    Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

    C:\Documents and Settings\Kiffeur999\Menu Démarrer\Programmes\Démarrage
    Pin.lnk - C:\hp\bin\CLOAKER.EXE
    PinMcLnk.lnk - C:\hp\bin\cloaker.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\WINDOWS\system32\Ati2evxx.dll [2008-02-26 126976]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
    C:\WINDOWS\system32\klogon.dll [2007-06-28 206088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1
    "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
    "EnableLUA"=0

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=36
    "NoSMBalloonTip"=0
    "NoDriveAutoRun"=FFFFFFFF

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoResolveSearch"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:D isabled:Windows Live Messenger"
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:*:Enabled:ActiveSync RAPI Manager"
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:*:Enabled:ActiveSync Application"
    "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    ======List of files/folders created in the last 1 months======

    2009-02-21 09:59:13 ----D---- C:\_OTMoveIt
    2009-02-21 09:04:14 ----D---- C:\Program Files\mIRC
    2009-02-19 20:24:14 ----A---- C:\WINDOWS\system32\tmp.txt
    2009-02-19 20:24:08 ----A---- C:\rapport.txt
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\WS2Fix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\VCCLSID.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\VACFix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\swxcacls.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\swsc.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\swreg.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\SrchSTS.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\Process.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\o4Patch.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\IEDFix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\dumphive.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\Agent.OMZ.Fix.exe
    2009-02-19 20:23:57 ----A---- C:\WINDOWS\system32\404Fix.exe
    2009-02-17 19:51:50 ----D---- C:\Program Files\Spybot - Search & Destroy
    2009-02-17 19:51:50 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2009-02-16 07:02:13 ----N---- C:\WINDOWS\system32\dbmsqlgc.dll
    2009-02-16 07:02:13 ----N---- C:\WINDOWS\system32\dbmsgnet.dll
    2009-02-16 07:00:43 ----D---- C:\Program Files\Microsoft SQL Server
    2009-02-16 06:59:04 ----D---- C:\Program Files\Vstplugins
    2009-02-16 06:59:02 ----D---- C:\Documents and Settings\All Users\Application Data\Sony
    2009-02-16 06:58:50 ----D---- C:\Program Files\Sony
    2009-02-16 06:57:06 ----D---- C:\Program Files\Sony Setup
    2009-02-15 18:17:10 ----D---- C:\Program Files\eSnips
    2009-02-15 18:16:59 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2009-02-14 15:57:34 ----D---- C:\Program Files\Fichiers communs\Skype
    2009-02-14 15:57:31 ----RD---- C:\Program Files\Skype
    2009-02-14 15:57:24 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
    2009-02-14 14:04:39 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
    2009-02-14 14:02:37 ----D---- C:\Program Files\IVT Corporation
    2009-02-10 21:36:07 ----D---- C:\WINDOWS\ASTULogTemp
    2009-02-10 21:35:55 ----A---- C:\ASLog.txt
    2009-02-04 11:32:25 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\Sites prédéfinis
    2009-02-04 11:31:38 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\Dynamique
    2009-02-04 11:31:22 ----D---- C:\Program Files\Visicom Media
    2009-02-03 20:39:01 ----D---- C:\Program Files\FRAps
    2009-02-01 13:31:34 ----D---- C:\Program Files\TeamSpeak3
    2009-01-28 21:55:26 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\HLSW
    2009-01-28 12:40:54 ----D---- C:\Documents and Settings\All Users\Application Data\FlashFXP
    2009-01-27 18:24:30 ----A---- C:\WINDOWS\system32\WNASPINT.DLL
    2009-01-27 18:19:52 ----D---- C:\Program Files\ejay
    2009-01-26 20:19:46 ----A---- C:\WINDOWS\system32\deploytk.dll
    2009-01-26 19:52:39 ----HD---- C:\autorun.inf
    2009-01-26 19:47:58 ----D---- C:\Program Files\UsbFix
    2009-01-26 19:02:44 ----D---- C:\Program Files\trend micro
    2009-01-26 19:02:43 ----D---- C:\rsit
    2009-01-25 18:01:48 ----D---- C:\Program Files\3GP Player
    2009-01-25 11:19:20 ----HDC---- C:\Documents and Settings\All Users\Application Data\{DE032019-B933-4DF4-9174-48C52613DA13}
    2009-01-25 11:19:18 ----D---- C:\Program Files\Stardock
    2009-01-25 11:15:43 ----D---- C:\WINDOWS\temp
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\system32\vfind.exe
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\system32\moveex.exe
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\nircmd.exe
    2009-01-25 11:15:16 ----A---- C:\WINDOWS\catchme.exe
    2009-01-25 11:03:34 ----D---- C:\Program Files\AxBx
    2009-01-24 17:38:00 ----D---- C:\Program Files\Steam
    2009-01-24 15:47:34 ----D---- C:\Program Files\ZNsoft Corporation
    2009-01-24 14:59:48 ----D---- C:\Program Files\CCleaner

    ======List of files/folders modified in the last 1 months======

    2009-02-21 13:49:19 ----D---- C:\Program Files\Mozilla Firefox
    2009-02-21 10:46:51 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-21 10:46:47 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2009-02-21 10:46:16 ----D---- C:\WINDOWS\Registration
    2009-02-21 10:46:08 ----AD---- C:\WINDOWS
    2009-02-21 10:44:50 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-02-21 10:15:04 ----D---- C:\WINDOWS\Prefetch
    2009-02-21 10:13:59 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-02-21 10:13:58 ----SHD---- C:\WINDOWS\Installer
    2009-02-21 10:13:54 ----D---- C:\WINDOWS\system32
    2009-02-21 10:13:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-02-21 10:13:25 ----D---- C:\WINDOWS\system32\drivers
    2009-02-21 10:05:34 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\mIRC
    2009-02-21 09:59:13 ----SD---- C:\Documents and Settings\Kiffeur999\Application Data\Microsoft
    2009-02-21 09:04:14 ----RD---- C:\Program Files
    2009-02-18 11:02:39 ----D---- C:\WINDOWS\system32\FxsTmp
    2009-02-18 10:10:50 ----D---- C:\WINDOWS\system32\CatRoot
    2009-02-18 10:09:59 ----D---- C:\WINDOWS\system32\RTCOM
    2009-02-18 10:09:22 ----RSHD---- C:\WINDOWS\system32\dllcache
    2009-02-18 10:08:55 ----HD---- C:\WINDOWS\inf
    2009-02-17 19:29:29 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-02-17 19:29:13 ----D---- C:\Program Files\Fichiers communs\muvee Technologies
    2009-02-17 19:28:44 ----RSD---- C:\WINDOWS\assembly
    2009-02-17 19:28:24 ----D---- C:\Program Files\Fichiers communs\Sonic Shared
    2009-02-17 19:28:21 ----RSD---- C:\WINDOWS\Fonts
    2009-02-17 19:27:56 ----D---- C:\WINDOWS\WinSxS
    2009-02-17 19:27:48 ----D---- C:\Program Files\Fichiers communs\HP
    2009-02-16 20:36:33 ----D---- C:\WINDOWS\system32\config
    2009-02-16 13:45:21 ----D---- C:\Program Files\eMule
    2009-02-16 07:02:13 ----HD---- C:\Program Files\Uninstall Information
    2009-02-15 18:16:59 ----D---- C:\Program Files\Fichiers communs
    2009-02-15 10:05:12 ----A---- C:\WINDOWS\err.txt
    2009-02-15 09:28:58 ----D---- C:\WINDOWS\system32\wbem
    2009-02-14 14:46:02 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-14 08:35:58 ----D---- C:\WINDOWS\security
    2009-02-13 08:54:18 ----D---- C:\WINDOWS\system
    2009-02-11 17:47:09 ----D---- C:\Program Files\Adobe
    2009-02-10 18:25:34 ----D---- C:\WINDOWS\system32\LogFiles
    2009-02-08 14:28:58 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\Adobe
    2009-02-04 10:26:34 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2009-02-03 20:38:09 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\LimeWire
    2009-02-03 20:32:54 ----D---- C:\Program Files\LimeWire
    2009-02-01 12:30:54 ----AD---- C:\WINDOWS\ehome
    2009-02-01 12:29:55 ----A---- C:\WINDOWS\win.ini
    2009-02-01 11:46:44 ----D---- C:\Downloads
    2009-02-01 09:28:22 ----D---- C:\Program Files\Kaspersky Lab
    2009-01-31 12:06:20 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\FileZilla
    2009-01-28 21:55:32 ----SD---- C:\Program Files\HLSW
    2009-01-26 20:20:30 ----D---- C:\Program Files\Java
    2009-01-26 20:19:35 ----A---- C:\WINDOWS\system32\javaws.exe
    2009-01-26 20:19:35 ----A---- C:\WINDOWS\system32\javaw.exe
    2009-01-26 20:19:35 ----A---- C:\WINDOWS\system32\java.exe
    2009-01-24 16:37:17 ----D---- C:\Program Files\SystemRequirementsLab
    2009-01-24 16:30:04 ----D---- C:\Documents and Settings\Kiffeur999\Application Data\SystemRequirementsLab
    2009-01-24 15:50:31 ----D---- C:\Program Files\Creative
    2009-01-24 15:05:46 ----D---- C:\WINDOWS\pss
    2009-01-24 15:00:59 ----D---- C:\WINDOWS\Debug
    2009-01-24 14:48:44 ----SD---- C:\WINDOWS\Downloaded Program Files
    2009-01-24 14:48:44 ----D---- C:\Program Files\Fichiers communs\InstallShield
    2009-01-24 14:46:48 ----D---- C:\Program Files\CyberLink
    2009-01-24 14:45:53 ----D---- C:\Program Files\Mozilla Thunderbird
    2009-01-24 14:40:57 ----D---- C:\Program Files\DivX
    2009-01-24 14:39:38 ----D---- C:\Program Files\ASUS
    2009-01-24 14:21:57 ----D---- C:\WINDOWS\I386
    2009-01-24 14:21:57 ----A---- C:\WINDOWS\system32\uxtheme.dll
    2009-01-23 19:18:31 ----D---- C:\WINDOWS\system32\DirectX

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 40320]
    R1 klif;Klif; \??\C:\WINDOWS\system32\drivers\klif.sys []
    R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
    R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-01-24 278728]
    R2 cdralw2k;cdralw2k; C:\WINDOWS\system32\drivers\cdralw2k.sys [2005-08-19 2560]
    R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
    R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-01-24 25416]
    R3 aracpi;aracpi; C:\WINDOWS\system32\DRIVERS\aracpi.sys [2005-08-03 22784]
    R3 arkbcfltr;Microsoft PS2 Keyboard Filter; C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-03 5376]
    R3 armoucfltr;Microsoft PS2 Mouse Filter; C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-03 4992]
    R3 ARPolicy;ARPolicy; C:\WINDOWS\system32\DRIVERS\arpolicy.sys [2005-08-03 10112]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-02-26 2863616]
    R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
    R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
    R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-05-23 16272]
    R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-25 4353024]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
    R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-13 19072]
    R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-10 5888]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-03-31 27008]
    R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-10 57600]
    R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
    R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 26496]
    R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
    R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
    R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D.sys [2004-07-06 44544]
    R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service; C:\WINDOWS\system32\DRIVERS\WPN111.sys [2005-09-26 362944]
    S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
    S3 a9pme3iw;a9pme3iw; C:\WINDOWS\system32\drivers\a9pme3iw.sys []
    S3 arhidfltr;MS Ar HID Filter Driver; C:\WINDOWS\system32\DRIVERS\arhidfltr.sys [2005-08-03 19200]
    S3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-10 60800]
    S3 atidgllk;atidgllk; \??\C:\Program Files\ASUS\SmartDoctor\atidgllk.sys []
    S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-23 36496]
    S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-03 17024]
    S3 BTHMODEM;Pilote de communication série Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2004-08-03 38016]
    S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
    S3 BTHPORT;Pilote de port Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-04 274944]
    S3 BTHUSB;Pilote USB radio Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
    S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
    S3 HidBth;Miniport HID Microsoft Bluetooth; C:\WINDOWS\system32\DRIVERS\hidbth.sys [2004-08-03 25856]
    S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
    S3 MHNDRV;Pilote MHN; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
    S3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-10 61824]
    S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2005-11-19 20096]
    S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
    S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-02-27 81408]
    S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
    S3 se58bus;Sony Ericsson Device 088 driver (WDM); C:\WINDOWS\system32\DRIVERS\se58bus.sys [2006-09-05 61536]
    S3 se58mdfl;Sony Ericsson Device 088 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\se58mdfl.sys [2006-09-05 9360]
    S3 se58mdm;Sony Ericsson Device 088 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\se58mdm.sys [2006-09-05 97088]
    S3 se58mgmt;Sony Ericsson Device 088 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\se58mgmt.sys [2006-09-05 88624]
    S3 se58nd5;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (NDIS); C:\WINDOWS\system32\DRIVERS\se58nd5.sys [2006-09-05 18704]
    S3 se58obex;Sony Ericsson Device 088 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\se58obex.sys [2006-09-05 86432]
    S3 se58unic;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (WDM); C:\WINDOWS\system32\DRIVERS\se58unic.sys [2006-09-05 90800]
    S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
    S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
    S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
    S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
    S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
    S3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-10 20480]
    S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 ARSVC;ARSVC; C:\WINDOWS\arservice.exe [2005-08-03 58880]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-02-26 520192]
    R2 AVP;Kaspersky Anti-Virus 6.0; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe [2007-03-09 200768]
    R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
    R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
    R2 ehSched;Service de planification Media Center; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 103424]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-26 152984]
    R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2002-07-31 303104]
    R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
    R2 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
    S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-02-25 593920]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-10 268800]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-01 655624]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
    S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2004-08-10 14336]
    S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
    S4 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]

    -----------------EOF-----------------
    a c 296 8 Sécurité
    a b 9 Windows
    21 Février 2009 15:03:07

    Tu as payé Kaspersky ?
    21 Février 2009 16:14:21

    Je sais pas c'est mon pere qui se charge de cela
    21 Février 2009 16:14:35

    Je sais pas c'est mon pere qui se charge de cela
    a c 296 8 Sécurité
    a b 9 Windows
    21 Février 2009 17:18:27

    1/

  • Cherche ce fichier : C:\Program Files\trend micro\Kiffeur999.exe
  • Double-clique sur ce fichier.
  • Choisis Do a system scan only.
  • Coche les cases qui sont devant les lignes suivantes :

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O4 - HKLM\..\Policies\Explorer\Run: [rsvp] C:\DOCUME~1\KIFFEU~1\APPLIC~1\rsvp.exe /waitservice

    O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [MstInit] C:\DOCUME~1\KIFFEU~1\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe /waitservice (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MstInit] C:\DOCUME~1\KIFFEU~1\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe /waitservice (User 'Default user')

  • Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
  • Ferme HijackThis.


    2/

  • Fais un scan complet avec Kaspersky et poste le rapport si tu peux.
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS