|
|
|
|
Salut
Télécharge sur ton bureau DSS (ex Comboscan) de Deckard: http://deckard.geekstogo.com/dss.exe (choisis enregistrer, puis Bureau comme emplacement) Ferme toutes les applications en cours. Double-clic sur DSS.exe pour lancer l'outil. Une fenêtre s'ouvre, invitant à fermer toutes les applications, clique sur OK. A la fin de l'analyse, une fenêtre s'ouvre, clique sur OK. Le rapport main.txt va s'afficher, copie le dans ta prochaine réponse. Si un rapport complémentaire a été créé ( extra.txt ), poste le aussi dans ta réponse. Les rapports sont ici : (!) C:\Deckard\System Scanner\main.txt (!) C:\Deckard\System Scanner\extra.txt (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller ) A découvrir : Estopa, Rosario Flores, La Oreja De Van Gogh Bonne écoute @ + TChiki.
|
-;)
ça wouach ?? A découvrir : Estopa, Rosario Flores, La Oreja De Van Gogh Bonne écoute @ + TChiki.
|
Alors tout d'abord un enorme me semble de mise pour une telle reactivitée comme l as dit sKe69
alors voici le main.txt Deckard's System Scanner v20071014.68 Run by Admin 2 on 2008-07-31 09:46:34 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 7: 2008-07-31 07:46:51 UTC - RP11 - Deckard's System Scanner Restore Point 6: 2008-07-30 19:09:16 UTC - RP10 - Point de vérification système 5: 2008-07-29 19:04:48 UTC - RP9 - Point de vérification système 4: 2008-07-28 18:54:07 UTC - RP8 - Installé Nero 8 3: 2008-07-28 18:25:13 UTC - RP7 - DirectX est installé -- First Restore Point -- 1: 2008-07-27 17:48:12 UTC - RP5 - Point de vérification système Backed up registry hives. Performed disk cleanup. [color=red]Total Physical Memory: 254 MiB (512 MiB recommended)./color -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2008-07-31 09:47:54 Platform: Windows XP (5.01.2600) MSIE: Internet Explorer (6.00.2600.0000) Boot mode: Normal Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe D:\logiciel\sécurité\anti-spywares\instalation\aawservice.exe C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe D:\logiciel\sécurité\antivirus\instalation\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe D:\logiciel\sécurité\antivirus\instalation\aswUpdSv.exe D:\logiciel\sécurité\antivirus\instalation\ashServ.exe C:\WINDOWS\system32\spoolsv.exe D:\logiciel\sécurité\anti-trojans\instalation\a-squared Free\a2service.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files\Intel\Intel(R) Active Monitor\imonNT.exe C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Admin 2\Bureau\dss.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe O4 - HKLM\..\Run: [avast!] D:\logiciel\SCURIT~1\ANTIVI~1\INSTAL~1\ashDisp.exe O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\logiciel\sécurité\pare feu\instalation\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O9 - Extra button: Liens apparentés - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - D:\logiciel\sécurité\anti-trojans\instalation\a-squared Free\a2service.exe O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\logiciel\sécurité\anti-spywares\instalation\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\ashWebSv.exe O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel(R) Active Monitor\imonNT.exe O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe End of file - 4777 bytes -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R2 iSMBIOS - c:\windows\system32\drivers\ismbios.sys <Not Verified; Intel Corporation; Intel(R) Active Monitor> R2 SIODRV - c:\windows\system32\drivers\siodrv.sys <Not Verified; Intel Corporation; Intel(R) Active Monitor> R3 smbusp (Intel(R) SMBus 2.0 Driver) - c:\windows\system32\drivers\smb.sys <Not Verified; Intel Corporation; Intel(R) SMBus Controller> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 imonNT (Intel(R) Active Monitor) - c:\program files\intel\intel(r) active monitor\imonnt.exe <Not Verified; Intel Corp.; Intel(R) Active Monitor> R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe -- Device Manager: Disabled ---------------------------------------------------- Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Contrôleur vidéo multimédia Device ID: PCI\VEN_121A&DEV_0002&SUBSYS_00000000&REV_02\4&29817089&0&08F0 Manufacturer: Name: Contrôleur vidéo multimédia PNP Device ID: PCI\VEN_121A&DEV_0002&SUBSYS_00000000&REV_02\4&29817089&0&08F0 Service: -- Files created between 2008-06-30 and 2008-07-31 ----------------------------- 2008-07-31 08:15:47 0 drahs---- C:\autorun.inf 2008-07-30 23:43:02 0 d-------- C:\WINDOWS\Caps 2008-07-30 23:42:54 0 d-------- C:\Program Files\RapidLeecher Ultimate 2007 2008-07-30 01:13:23 0 d-------- C:\Documents and Settings\Oli\Application Data\Macromedia 2008-07-30 01:13:21 0 d-------- C:\Documents and Settings\Oli\Application Data\Adobe 2008-07-29 23:40:42 0 d-------- C:\Documents and Settings\Admin 2\Application Data\Macromedia 2008-07-29 23:40:41 0 d-------- C:\Documents and Settings\Admin 2\Application Data\Adobe 2008-07-28 21:49:39 0 d-------- C:\Documents and Settings\Oli\Application Data\Nero 2008-07-28 21:03:14 0 d-------- C:\Documents and Settings\Admin 2\Application Data\Nero 2008-07-28 20:54:37 0 d-------- C:\Program Files\Nero 2008-07-28 20:54:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero 2008-07-28 20:54:36 0 d-------- C:\Program Files\Fichiers communs\Nero 2008-07-28 20:25:24 1703936 --a------ C:\WINDOWS\System32\d3d9.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System> 2008-07-28 20:25:23 1769472 --a------ C:\WINDOWS\System32\dxdiagn.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System> 2008-07-28 20:25:22 80896 --a------ C:\WINDOWS\System32\dxdllreg.exe <Not Verified; Microsoft Corporation; Microsoft® DirectX for Windows®> 2008-07-28 20:24:46 0 d-------- C:\WINDOWS\Logs 2008-07-28 19:58:26 0 d-------- C:\WINDOWS\RegisteredPackages 2008-07-28 19:49:40 0 d--h---c- C:\WINDOWS\$MSI30UninstallMSI30-KB884016$ 2008-07-28 15:12:33 0 d-------- C:\Documents and Settings\Oli\Application Data\Media Player Classic 2008-07-28 15:09:25 157696 --a------ C:\WINDOWS\System32\unrar.dll 2008-07-28 15:09:19 568850 --a------ C:\WINDOWS\System32\x264vfw.dll 2008-07-28 15:09:19 286720 --a------ C:\WINDOWS\System32\3ivxVfWCodec.dll <Not Verified; 3ivx.com; 3ivx D4 4.5.1 Pro> 2008-07-28 15:09:19 1024000 --a------ C:\WINDOWS\System32\3ivx.dll <Not Verified; 3ivx.com; 3ivx D4 4.5.1 Pro> 2008-07-28 15:09:18 856064 --a------ C:\WINDOWS\System32\xvidcore.dll 2008-07-28 15:09:18 1415680 --a------ C:\WINDOWS\System32\WMV9VCM.dll <Not Verified; Microsoft Corporation; Windows Media Video 9 VCM> 2008-07-28 15:09:17 217088 --a------ C:\WINDOWS\System32\xvidvfw.dll 2008-07-28 15:09:16 3596288 --a------ C:\WINDOWS\System32\qt-dx331.dll 2008-07-28 15:09:14 619156 --a------ C:\WINDOWS\System32\divx.dll <Not Verified; DivX, Inc.; DivX®> 2008-07-28 15:09:12 5120 --a------ C:\WINDOWS\System32\ff_vfw.dll 2008-07-27 12:43:33 0 d-------- C:\WINDOWS\System32\appmgmt 2008-07-27 12:41:35 351232 --a------ C:\WINDOWS\System32\winhttp.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System> 2008-07-26 16:21:58 81920 --a------ C:\WINDOWS\System32\404Fix.exe <Not Verified; S!Ri.URZ; 404Fix> 2008-07-26 16:21:57 25600 --a------ C:\WINDOWS\System32\WS2Fix.exe 2008-07-26 16:21:57 289144 --a------ C:\WINDOWS\System32\VCCLSID.exe <Not Verified; S!Ri; > 2008-07-26 16:21:57 86528 --a------ C:\WINDOWS\System32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix> 2008-07-26 16:21:57 288417 --a------ C:\WINDOWS\System32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS> 2008-07-26 16:21:57 82944 --a------ C:\WINDOWS\System32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix> 2008-07-26 16:21:57 51200 --a------ C:\WINDOWS\System32\dumphive.exe 2008-07-26 16:21:56 53248 --a------ C:\WINDOWS\System32\Process.exe <Not Verified; Command Line Process Utility> 2008-07-26 16:21:22 796703 --a------ C:\WINDOWS\System32\SFMJLJCG 2008-07-26 16:15:08 0 d---s---- C:\WINDOWS\System32\Microsoft 2008-07-26 16:14:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-07-26 16:13:08 0 d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard 2008-07-26 15:50:17 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier 2008-07-26 15:50:06 4212 ---h----- C:\WINDOWS\System32\zllictbl.dat 2008-07-26 15:49:41 11264 --a------ C:\WINDOWS\System32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(TM) Operating System> 2008-07-26 15:49:17 0 d-------- C:\WINDOWS\System32\ZoneLabs 2008-07-26 15:48:05 0 d-------- C:\WINDOWS\Internet Logs 2008-07-26 13:46:07 16480 --a------ C:\WINDOWS\System32\drivers\iSMBIOS.SYS <Not Verified; Intel Corporation; Intel(R) Active Monitor> 2008-07-26 13:46:06 7424 --a------ C:\WINDOWS\System32\drivers\SIODRV.SYS <Not Verified; Intel Corporation; Intel(R) Active Monitor> 2008-07-26 13:46:05 118784 --a------ C:\WINDOWS\System32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library> 2008-07-26 13:46:04 101888 --a------ C:\WINDOWS\System32\VB6STKIT.DLL <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows> 2008-07-26 13:46:04 1044480 --a------ C:\WINDOWS\System32\ROBOEX32.DLL <Not Verified; eHelp Corporation.; RoboHELP for WinHelp 9> 2008-07-26 13:46:04 26896 --a------ C:\WINDOWS\System32\HH.EXE <Not Verified; Microsoft Corporation; HTML Help> 2008-07-26 13:46:03 122880 --a------ C:\WINDOWS\System32\SensorDLL.dll <Not Verified; Intel Corp.; Intel(R) Active Monitor> 2008-07-26 13:46:03 49152 --a------ C:\WINDOWS\System32\iSMBiosVB.dll <Not Verified; Intel Corp.; Intel(R) Active Monitor> 2008-07-26 13:46:03 57344 --a------ C:\WINDOWS\System32\iSmbios.dll <Not Verified; Intel Corp.; Intel Corp. SmbiosDLL> 2008-07-26 13:45:51 30811 --a------ C:\WINDOWS\System32\drivers\smb.sys <Not Verified; Intel Corporation; Intel(R) SMBus Controller> 2008-07-26 13:30:13 0 d-------- C:\WINDOWS\Drivers 2008-07-26 13:18:46 30208 --a------ C:\WINDOWS\System32\wdmioctl.dll <Not Verified; Analog Devices Inc.; Analog Devices Inc. wdmioctl> 2008-07-26 13:18:45 1285632 --a------ C:\WINDOWS\System32\SMMedia.dll <Not Verified; Analog Devices; SoundMAX Integrated Digital Audio> 2008-07-26 13:18:44 962560 --a------ C:\WINDOWS\SynthCoreA.Dll <Not Verified; Analog Devices, Inc.; SoundMAX Wavetable> 2008-07-26 13:18:43 368640 --a------ C:\WINDOWS\SynCor.exe <Not Verified; Analog Devices, Inc.; SynthCore> 2008-07-26 13:18:42 45056 --a------ C:\WINDOWS\System32\SynthCore11Resources.dll <Not Verified; Staccato Systems, Inc.; Staccato Systems, Inc. SynthCore11Resources> 2008-07-26 13:18:42 40820 --a------ C:\WINDOWS\System32\Syncor11.dll <Not Verified; SoundMAX; Staccato Systems SynthCore R2.0 Synthesizer> 2008-07-26 13:18:42 49152 --a------ C:\WINDOWS\System32\S11thk32.dll <Not Verified; SoundMAX; Staccato Systems SynthCore R2.0 Synthesizer> 2008-07-26 13:18:40 765952 --a------ C:\WINDOWS\system\crlds3d.dll <Not Verified; Sensaura Ltd; Sensaura 3DPA> 2008-07-26 13:18:39 0 d-------- C:\WINDOWS\VirtualEar 2008-07-26 13:18:36 45056 --a------ C:\WINDOWS\System32\CleanUp.exe <Not Verified; adi; adi CleanUp> 2008-07-26 13:18:36 0 d-------- C:\Program Files\Analog Devices 2008-07-26 13:18:35 44 --a------ C:\WINDOWS\System32\msssc.dll 2008-07-26 13:18:35 45056 --a------ C:\WINDOWS\System32\DSndUp.exe <Not Verified; Analog Devices Inc.; adi DSndUp> 2008-07-26 13:16:22 0 d-------- C:\Program Files\Intel 2008-07-26 13:15:24 0 d-------- C:\WINDOWS\System32\ReinstallBackups 2008-07-26 13:15:12 0 d--h----- C:\Program Files\InstallShield Installation Information 2008-07-26 13:15:07 0 d-------- C:\Program Files\Fichiers communs\InstallShield 2008-07-26 13:13:29 0 d-------- C:\Documents and Settings\Admin 2\Application Data\Identities 2008-07-26 13:13:19 0 d--h----- C:\Documents and Settings\Admin 2\Local Settings 2008-07-26 13:13:19 0 dr------- C:\Documents and Settings\Admin 2\Favoris 2008-07-26 13:13:19 0 d---s---- C:\Documents and Settings\Admin 2\Cookies 2008-07-26 13:13:19 0 d-------- C:\Documents and Settings\Admin 2\Bureau 2008-07-26 13:13:19 0 dr-h----- C:\Documents and Settings\Admin 2\Application Data 2008-07-26 13:13:18 0 d--h----- C:\Documents and Settings\Admin 2\Voisinage réseau 2008-07-26 13:13:18 0 d--h----- C:\Documents and Settings\Admin 2\Voisinage d'impression 2008-07-26 13:13:18 0 dr-h----- C:\Documents and Settings\Admin 2\SendTo 2008-07-26 13:13:18 0 dr-h----- C:\Documents and Settings\Admin 2\Recent 2008-07-26 13:13:18 1572864 --ah----- C:\Documents and Settings\Admin 2\NTUSER.DAT 2008-07-26 13:13:18 0 d--h----- C:\Documents and Settings\Admin 2\Modèles 2008-07-26 13:13:18 0 dr------- C:\Documents and Settings\Admin 2\Mes documents 2008-07-26 13:13:18 0 dr------- C:\Documents and Settings\Admin 2\Menu Démarrer 2008-07-26 13:03:44 0 d-------- C:\Documents and Settings\Oli\Application Data\Identities 2008-07-26 13:03:35 0 dr------- C:\Documents and Settings\Oli\Favoris 2008-07-26 13:03:35 0 d---s---- C:\Documents and Settings\Oli\Cookies 2008-07-26 13:03:35 0 d-------- C:\Documents and Settings\Oli\Bureau 2008-07-26 13:03:35 0 dr-h----- C:\Documents and Settings\Oli\Application Data 2008-07-26 13:03:35 0 d---s---- C:\Documents and Settings\Oli\Application Data\Microsoft 2008-07-26 13:03:34 0 d--h----- C:\Documents and Settings\Oli\Voisinage réseau 2008-07-26 13:03:34 0 d--h----- C:\Documents and Settings\Oli\Voisinage d'impression 2008-07-26 13:03:34 0 dr-h----- C:\Documents and Settings\Oli\SendTo 2008-07-26 13:03:34 0 dr-h----- C:\Documents and Settings\Oli\Recent 2008-07-26 13:03:34 1048576 --ah----- C:\Documents and Settings\Oli\NTUSER.DAT 2008-07-26 13:03:34 0 d--h----- C:\Documents and Settings\Oli\Modèles 2008-07-26 13:03:34 0 dr------- C:\Documents and Settings\Oli\Mes documents 2008-07-26 13:03:34 0 dr------- C:\Documents and Settings\Oli\Menu Démarrer 2008-07-26 13:03:34 0 d--h----- C:\Documents and Settings\Oli\Local Settings 2008-07-26 12:54:33 0 d--hs---- C:\WINDOWS\Installer 2008-07-26 12:54:25 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Identities 2008-07-26 12:53:57 0 dr------- C:\Documents and Settings\Administrateur\Favoris 2008-07-26 12:53:57 0 d---s---- C:\Documents and Settings\Administrateur\Cookies 2008-07-26 12:53:57 0 d-------- C:\Documents and Settings\Administrateur\Bureau 2008-07-26 12:53:57 0 dr-h----- C:\Documents and Settings\Administrateur\Application Data 2008-07-26 12:53:57 0 d---s---- C:\Documents and Settings\Administrateur\Application Data\Microsoft 2008-07-26 12:53:56 0 dr------- C:\Documents and Settings\Administrateur\Menu Démarrer 2008-07-26 12:53:56 0 d--h----- C:\Documents and Settings\Administrateur\Local Settings 2008-07-26 12:53:55 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau 2008-07-26 12:53:55 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression 2008-07-26 12:53:55 0 dr-h----- C:\Documents and Settings\Administrateur\SendTo 2008-07-26 12:53:55 0 dr-h----- C:\Documents and Settings\Administrateur\Recent 2008-07-26 12:53:55 524288 --ah----- C:\Documents and Settings\Administrateur\NTUSER.DAT 2008-07-26 12:53:55 0 d--h----- C:\Documents and Settings\Administrateur\Modèles 2008-07-26 12:53:55 0 dr------- C:\Documents and Settings\Administrateur\Mes documents 2008-07-26 12:52:33 0 d--hs---- C:\System Volume Information 2008-07-26 12:52:31 0 d-------- C:\WINDOWS\Prefetch 2008-07-26 12:52:28 237568 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT 2008-07-26 12:52:28 0 d--h----- C:\Documents and Settings\LocalService\Local Settings 2008-07-26 12:52:28 0 d---s---- C:\Documents and Settings\LocalService\Cookies 2008-07-26 12:52:28 0 d-------- C:\Documents and Settings\LocalService\Application Data 2008-07-26 12:52:28 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft 2008-07-26 12:52:26 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings 2008-07-26 12:52:26 0 d---s---- C:\Documents and Settings\NetworkService\Cookies 2008-07-26 12:52:26 0 d-------- C:\Documents and Settings\NetworkService\Application Data 2008-07-26 12:52:26 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft 2008-07-26 12:52:25 237568 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT 2008-07-26 12:50:46 0 d-------- C:\Program Files\Fichiers communs\ODBC 2008-07-26 12:50:41 0 d-------- C:\Program Files\Fichiers communs\SpeechEngines 2008-07-26 12:50:40 0 dr------- C:\Program Files 2008-07-26 12:50:40 0 d-------- C:\Program Files\Fichiers communs 2008-07-26 12:49:51 0 d--h----- C:\Documents and Settings\Default User\Voisinage réseau 2008-07-26 12:49:51 0 d--h----- C:\Documents and Settings\Default User\Voisinage d'impression 2008-07-26 12:49:51 0 dr-h----- C:\Documents and Settings\Default User\SendTo 2008-07-26 12:49:51 0 d--h----- C:\Documents and Settings\Default User\Recent 2008-07-26 12:49:51 0 d--h----- C:\Documents and Settings\Default User\Modèles 2008-07-26 12:49:51 0 d-------- C:\Documents and Settings\Default User\Mes documents 2008-07-26 12:49:51 0 dr------- C:\Documents and Settings\Default User\Menu Démarrer 2008-07-26 12:49:51 0 dr-h----- C:\Documents and Settings\Default User\Local Settings 2008-07-26 12:49:51 0 d-------- C:\Documents and Settings\Default User\Favoris 2008-07-26 12:49:51 0 d---s---- C:\Documents and Settings\Default User\Cookies 2008-07-26 12:49:51 0 d-------- C:\Documents and Settings\Default User\Bureau 2008-07-26 12:49:51 0 d--h----- C:\Documents and Settings\All Users\Modèles 2008-07-26 12:49:51 0 dr------- C:\Documents and Settings\All Users\Menu Démarrer 2008-07-26 12:49:51 0 d-------- C:\Documents and Settings\All Users\Favoris 2008-07-26 12:49:51 0 dr------- C:\Documents and Settings\All Users\Documents 2008-07-26 12:49:51 0 d-------- C:\Documents and Settings\All Users\Bureau 2008-07-26 12:49:28 0 d-------- C:\WINDOWS\System32\CatRoot2 2008-07-26 12:49:28 0 d-------- C:\WINDOWS\System32\CatRoot 2008-07-26 12:49:22 0 dr-h----- C:\Documents and Settings\Default User\Application Data 2008-07-26 12:49:22 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft 2008-07-26 12:49:21 0 dr-h----- C:\Documents and Settings\All Users\Application Data 2008-07-26 12:49:21 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft 2008-07-26 12:19:50 0 d-------- C:\WINDOWS\System32\xircom 2008-07-26 12:19:50 0 d-------- C:\Program Files\microsoft frontpage 2008-07-26 12:19:09 237568 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT 2008-07-26 12:18:43 0 -rahs---- C:\MSDOS.SYS 2008-07-26 12:18:43 0 -rahs---- C:\IO.SYS 2008-07-26 12:18:43 0 --a------ C:\CONFIG.SYS 2008-07-26 12:18:43 0 --a------ C:\AUTOEXEC.BAT 2008-07-26 12:16:05 0 d--hs---- C:\Documents and Settings\All Users\DRM 2008-07-26 12:15:37 0 dr------- C:\WINDOWS\Offline Web Pages 2008-07-26 12:15:37 0 d---s---- C:\WINDOWS\Downloaded Program Files 2008-07-26 12:14:30 0 d-------- C:\WINDOWS\srchasst 2008-07-26 12:14:15 0 d-------- C:\WINDOWS\System32\Macromed 2008-07-26 12:14:15 0 d-------- C:\WINDOWS\System32\DirectX 2008-07-26 12:13:59 0 d-------- C:\Program Files\Movie Maker 2008-07-26 12:10:38 0 d-------- C:\WINDOWS\System32\Restore 2008-07-26 12:10:28 0 d-------- C:\WINDOWS\PCHEALTH 2008-07-26 12:10:19 0 d---s---- C:\WINDOWS\Tasks 2008-07-26 12:10:14 0 d-------- C:\Program Files\Fichiers communs\MSSoap 2008-07-26 12:08:45 21892 --a------ C:\WINDOWS\System32\emptyregdb.dat 2008-07-26 12:07:37 0 d-------- C:\WINDOWS\Registration 2008-07-26 12:07:10 0 d--h----- C:\Program Files\WindowsUpdate 2008-07-26 12:07:10 0 d-------- C:\Program Files\Services en ligne 2008-07-26 12:06:41 0 d-------- C:\Program Files\Messenger 2008-07-26 12:06:26 0 d-------- C:\Program Files\MSN Gaming Zone 2008-07-26 12:06:05 0 d-------- C:\Program Files\Windows NT 2008-07-26 12:05:43 0 d-------- C:\WINDOWS\System32\MsDtc 2008-07-26 12:05:39 0 d-------- C:\WINDOWS\System32\Com 2008-07-25 22:19:33 0 d-------- C:\WINDOWS 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\WinSxS 2008-07-25 22:19:33 0 dr------- C:\WINDOWS\Web 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\twain_32 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\system32 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\wins 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\wbem 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\usmt 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\spool 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\ShellExt 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\Setup 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\ras 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\oobe 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\npp 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\mui 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\inetsrv 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\IME 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\icsxml 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\ias 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\export 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\drivers 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\drivers\etc 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\drivers\disdn 2008-07-25 22:19:33 0 dr-hs--c- C:\WINDOWS\System32\dllcache 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\dhcp 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\config 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\3com_dmi 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\3076 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\2052 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1054 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1042 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1041 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1037 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1036 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1033 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1031 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1028 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\System32\1025 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\system 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\security 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Resources 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\repair 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\mui 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\msapps 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\msagent 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Media 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\java 2008-07-25 22:19:33 0 d--h----- C:\WINDOWS\inf 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\ime 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Help 2008-07-25 22:19:33 0 dr--s---- C:\WINDOWS\Fonts 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Driver Cache 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Debug 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Cursors 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Connection Wizard 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\Config 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\AppPatch 2008-07-25 22:19:33 0 d-------- C:\WINDOWS\addins 2008-07-25 21:28:25 0 d-------- C:\Documents and Settings -- Find3M Report --------------------------------------------------------------- 2008-07-31 07:07:40 367988 --a------ C:\WINDOWS\System32\perfh00C.dat 2008-07-31 07:07:40 48820 --a------ C:\WINDOWS\System32\perfc00C.dat 2008-07-26 12:49:51 62 --ahs---- C:\Documents and Settings\Admin 2\Application Data\desktop.ini -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Smapp"="C:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [19/03/2002 11:01] "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [26/07/2002 09:05] "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [26/07/2002 08:45] "IMONTRAY"="C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe" [03/05/2002 15:10] "avast!"="D:\logiciel\SCURIT~1\ANTIVI~1\INSTAL~1\ashDisp.exe" [19/07/2008 16:38] "ZoneAlarm Client"="D:\logiciel\sécurité\pare feu\instalation\ZoneAlarm\zlclient.exe" [] "NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [01/03/2007 14:57] "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [20/09/2007 08:51] "KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [24/08/2001 14:00] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [02/08/2001 07:14] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [23/10/2007 14:18] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" *Newly Created Service* - ALG *Newly Created Service* - IPNAT *Newly Created Service* - SHAREDACCESS -- End of Deckard's System Scanner: finished at 2008-07-31 09:49:45 ------------ et voila le extra.txt Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professionnel (build 2600) Architecture: X86; Language: French CPU 0: Intel(R) Celeron(R) CPU 1.70GHz Percentage of Memory in Use: 69% Physical Memory (total/avail): 253.8 MiB / 78.41 MiB Pagefile Memory (total/avail): 625.02 MiB / 372.08 MiB Virtual Memory (total/avail): 2047.88 MiB / 1940.1 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 7.86 GiB total, 4.27 GiB free. D: is Fixed (NTFS) - 76.33 GiB total, 4.89 GiB free. E: is CDROM (CDFS) F: is CDROM (No Media) \\.\PHYSICALDRIVE1 - Maxtor 6Y080L0 - 76.33 GiB - 1 partition \PARTITION0 - Système de fichiers installable - 76.33 GiB - D: \\.\PHYSICALDRIVE0 - WDC AC28400R - 7.87 GiB - 1 partition \PARTITION0 (bootable) - Système de fichiers installable - 7.86 GiB - C: -- Security Center ------------------------------------------------------------- AUState says computer is in an unknown state. -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Admin 2\Application Data CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Fichiers communs COMPUTERNAME=BORGUET-UORX55S ComSpec=C:\WINDOWS\system32\cmd.exe HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Admin 2 LOGONSERVER=\\BORGUET-UORX55S NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Fichiers communs\Nero\Lib\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 1 Stepping 3, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0103 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\ADMIN2~1\LOCALS~1\Temp TMP=C:\DOCUME~1\ADMIN2~1\LOCALS~1\Temp tvdumpflags=8 USERDOMAIN=BORGUET-UORX55S USERNAME=Admin 2 USERPROFILE=C:\Documents and Settings\Admin 2 windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Admin 2 [I](admin) Oli Administrateur [I](new local, admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL --> C:\WINDOWS\UNRecode.exe /UNINSTALL --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf a-squared Free 3.5 --> "D:\logiciel\sécurité\anti-trojans\instalation\a-squared Free\unins000.exe" Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player Plugin --> C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe Archiveur WinRAR --> C:\Program Files\WinRAR\uninstall.exe avast! Antivirus --> D:\logiciel\sécurité\antivirus\instalation\aswRunDll.exe "D:\logiciel\sécurité\antivirus\instalation\Setup\setiface.dll",RunSetup Intel Application Accelerator --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9984DF60-1C5B-11D3-ACA1-908A4FC10801}\Setup.exe" -INTELUNINST Intel(R) 82845G Graphics Driver Software --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8A708DD8-A5E6-11D4-A706-000629E95E20}\setup.exe" -inteluninstall Intel(R) Active Monitor --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E861EC9-FCB8-11D3-939A-00A0C9BA5A55}\setup.exe" Intel(R) PRO Ethernet Adapter and Software --> Prounstl.exe K-Lite Codec Pack 2.72 Full --> "D:\logiciel\K-Lite Codec Pack Full\instalation\K-Lite Codec Pack\unins000.exe" Nero 8 --> MsiExec.exe /X{9EDBB857-8028-49CD-B9C9-0B4D10CD1036} neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} RapidLeecher Ultimate 2007 --> "C:\Program Files\RapidLeecher Ultimate 2007\Uninstall.exe" SoundMAX --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe" VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027} Windows Installer 3.0 (KB884016) --> C:\WINDOWS\$MSI30UninstallMSI30-KB884016$\spuninst\spuninst.exe ZoneAlarm --> D:\logiciel\sécurité\pare feu\instalation\ZoneAlarm\zauninst.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type141 / Warning Event Submitted/Written: 07/31/2008 07:06:44 AM Event ID/Source: 4354 / EventSystem Event Description: Le système d'événements de COM+ n'a pas pu déclencher la méthode StartShell de l'abonnement {A5978620-5B3F-F1D1-8ED2-00FA0035B753}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80004001. Event Record #/Type137 / Warning Event Submitted/Written: 07/31/2008 03:06:09 AM Event ID/Source: 4354 / EventSystem Event Description: Le système d'événements de COM+ n'a pas pu déclencher la méthode StartShell de l'abonnement {A5978620-5B3F-F1D1-8ED2-00FA0035B753}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80004001. Event Record #/Type133 / Warning Event Submitted/Written: 07/31/2008 02:22:35 AM Event ID/Source: 4354 / EventSystem Event Description: Le système d'événements de COM+ n'a pas pu déclencher la méthode StartShell de l'abonnement {A5978620-5B3F-F1D1-8ED2-00FA0035B753}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80004001. Event Record #/Type129 / Warning Event Submitted/Written: 07/31/2008 01:32:41 AM Event ID/Source: 4354 / EventSystem Event Description: Le système d'événements de COM+ n'a pas pu déclencher la méthode StartShell de l'abonnement {A5978620-5B3F-F1D1-8ED2-00FA0035B753}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80004001. Event Record #/Type125 / Warning Event Submitted/Written: 07/31/2008 01:16:14 AM Event ID/Source: 4354 / EventSystem Event Description: Le système d'événements de COM+ n'a pas pu déclencher la méthode StartShell de l'abonnement {A5978620-5B3F-F1D1-8ED2-00FA0035B753}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80004001. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type1993 / Error Event Submitted/Written: 07/31/2008 02:14:48 AM Event ID/Source: 9 / IdeChnDr Event Description: Le périphérique \Device\Ide\IdeDeviceP1T0L0 n'a pas répondu dans le délai imparti. Event Record #/Type1992 / Error Event Submitted/Written: 07/31/2008 02:14:28 AM Event ID/Source: 9 / IdeChnDr Event Description: Le périphérique \Device\Ide\IdeDeviceP1T0L0 n'a pas répondu dans le délai imparti. Event Record #/Type1991 / Warning Event Submitted/Written: 07/31/2008 02:14:28 AM Event ID/Source: 51 / Cdrom Event Description: Une erreur a été détectée sur le périphérique \Device\CdRom0 au cours d'une opération de pagination. Event Record #/Type1990 / Error Event Submitted/Written: 07/31/2008 02:14:18 AM Event ID/Source: 9 / IdeChnDr Event Description: Le périphérique \Device\Ide\IdeDeviceP1T0L0 n'a pas répondu dans le délai imparti. Event Record #/Type1989 / Error Event Submitted/Written: 07/31/2008 02:13:58 AM Event ID/Source: 9 / IdeChnDr Event Description: Le périphérique \Device\Ide\IdeDeviceP1T0L0 n'a pas répondu dans le délai imparti. -- End of Deckard's System Scanner: finished at 2008-07-31 09:49:45 ------------ |
telecharge ce fichier :
http://perso.orange.fr/-Gof/DL/VaccinUSB.exe tu l enregistre a la racine du disque C il faut l executer et cliquer sur fix puis post le raport (copié/collé) A découvrir : Estopa, Rosario Flores, La Oreja De Van Gogh Bonne écoute @ + TChiki. |
voila voila:
------------------------------------------------------- - Operation: 1 Supprimer fichier %CURRENT_DIRECTORY%\adober.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 2 Supprimer fichier %CURRENT_DIRECTORY%\autorun.inf Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 3 Supprimer fichier %CURRENT_DIRECTORY%\comment.htt Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 4 Supprimer fichier %CURRENT_DIRECTORY%\copy.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 5 Supprimer fichier %CURRENT_DIRECTORY%\host.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 6 Supprimer fichier %CURRENT_DIRECTORY%\msvcr71.dll Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 7 Supprimer fichier %CURRENT_DIRECTORY%\ravmon.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 8 Supprimer fichier %CURRENT_DIRECTORY%\ravmon.log Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 9 Supprimer fichier %CURRENT_DIRECTORY%\temp.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 10 Supprimer fichier %CURRENT_DIRECTORY%\temp1.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 11 Supprimer fichier %CURRENT_DIRECTORY%\temp2.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 12 Supprimer fichier %CURRENT_DIRECTORY%\winfile.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 13 Créer dossier %CURRENT_DIRECTORY%\adober.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 14 Créer dossier %CURRENT_DIRECTORY%\comment.htt Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 15 Créer dossier %CURRENT_DIRECTORY%\copy.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 16 Créer dossier %CURRENT_DIRECTORY%\host.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 17 Créer dossier %CURRENT_DIRECTORY%\ravmon.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 18 Créer dossier %CURRENT_DIRECTORY%\msvcr71.dll Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 19 Créer dossier %CURRENT_DIRECTORY%\ravmon.log Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 20 Créer dossier %CURRENT_DIRECTORY%\temp.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 21 Créer dossier %CURRENT_DIRECTORY%\temp1.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 22 Créer dossier %CURRENT_DIRECTORY%\temp2.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 23 Créer dossier %CURRENT_DIRECTORY%\winfile.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 24 Créer dossier %CURRENT_DIRECTORY%\autorun.inf Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 25 Executer C:\Documents and Settings\Admin 2\Local Settings\Temporary Internet Files\Vaccin_USB-Lisez_moi.html Result: Success ------------------------------------------------------- |
Tu repete l opération sur tout tes disque fixe clé usb disque externe
A découvrir : Estopa, Rosario Flores, La Oreja De Van Gogh
Bonne écoute @ + TChiki. |
alors voila sur le d:
------------------------------------------------------- - Operation: 1 Supprimer fichier %CURRENT_DIRECTORY%\adober.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 2 Supprimer fichier %CURRENT_DIRECTORY%\autorun.inf Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 3 Supprimer fichier %CURRENT_DIRECTORY%\comment.htt Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 4 Supprimer fichier %CURRENT_DIRECTORY%\copy.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 5 Supprimer fichier %CURRENT_DIRECTORY%\host.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 6 Supprimer fichier %CURRENT_DIRECTORY%\msvcr71.dll Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 7 Supprimer fichier %CURRENT_DIRECTORY%\ravmon.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 8 Supprimer fichier %CURRENT_DIRECTORY%\ravmon.log Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 9 Supprimer fichier %CURRENT_DIRECTORY%\temp.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 10 Supprimer fichier %CURRENT_DIRECTORY%\temp1.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 11 Supprimer fichier %CURRENT_DIRECTORY%\temp2.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 12 Supprimer fichier %CURRENT_DIRECTORY%\winfile.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 13 Créer dossier %CURRENT_DIRECTORY%\adober.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 14 Créer dossier %CURRENT_DIRECTORY%\comment.htt Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 15 Créer dossier %CURRENT_DIRECTORY%\copy.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 16 Créer dossier %CURRENT_DIRECTORY%\host.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 17 Créer dossier %CURRENT_DIRECTORY%\ravmon.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 18 Créer dossier %CURRENT_DIRECTORY%\msvcr71.dll Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 19 Créer dossier %CURRENT_DIRECTORY%\ravmon.log Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 20 Créer dossier %CURRENT_DIRECTORY%\temp.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 21 Créer dossier %CURRENT_DIRECTORY%\temp1.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 22 Créer dossier %CURRENT_DIRECTORY%\temp2.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 23 Créer dossier %CURRENT_DIRECTORY%\winfile.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 24 Créer dossier %CURRENT_DIRECTORY%\autorun.inf Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 25 Executer C:\Documents and Settings\Admin 2\Local Settings\Temporary Internet Files\Vaccin_USB-Lisez_moi.html Result: Success ------------------------------------------------------- et voila sur h: (qui est une clef usb sandisck cruzer 4Gb qui as pas mal circuler chez les amis pour receptioner des photos) ------------------------------------------------------- - Operation: 1 Supprimer fichier %CURRENT_DIRECTORY%\adober.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 2 Supprimer fichier %CURRENT_DIRECTORY%\autorun.inf Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 3 Supprimer fichier %CURRENT_DIRECTORY%\comment.htt Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 4 Supprimer fichier %CURRENT_DIRECTORY%\copy.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 5 Supprimer fichier %CURRENT_DIRECTORY%\host.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 6 Supprimer fichier %CURRENT_DIRECTORY%\msvcr71.dll Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 7 Supprimer fichier %CURRENT_DIRECTORY%\ravmon.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 8 Supprimer fichier %CURRENT_DIRECTORY%\ravmon.log Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 9 Supprimer fichier %CURRENT_DIRECTORY%\temp.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 10 Supprimer fichier %CURRENT_DIRECTORY%\temp1.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 11 Supprimer fichier %CURRENT_DIRECTORY%\temp2.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 12 Supprimer fichier %CURRENT_DIRECTORY%\winfile.exe Result: Error! Fichier introuvable ------------------------------------------------------- ------------------------------------------------------- - Operation: 13 Créer dossier %CURRENT_DIRECTORY%\adober.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 14 Créer dossier %CURRENT_DIRECTORY%\comment.htt Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 15 Créer dossier %CURRENT_DIRECTORY%\copy.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 16 Créer dossier %CURRENT_DIRECTORY%\host.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 17 Créer dossier %CURRENT_DIRECTORY%\ravmon.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 18 Créer dossier %CURRENT_DIRECTORY%\msvcr71.dll Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 19 Créer dossier %CURRENT_DIRECTORY%\ravmon.log Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 20 Créer dossier %CURRENT_DIRECTORY%\temp.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 21 Créer dossier %CURRENT_DIRECTORY%\temp1.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 22 Créer dossier %CURRENT_DIRECTORY%\temp2.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 23 Créer dossier %CURRENT_DIRECTORY%\winfile.exe Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 24 Créer dossier %CURRENT_DIRECTORY%\autorun.inf Result: Success ------------------------------------------------------- ------------------------------------------------------- - Operation: 25 Executer C:\Documents and Settings\Admin 2\Local Settings\Temporary Internet Files\Vaccin_USB-Lisez_moi.html Result: Success ------------------------------------------------------- |
redémarre le pc
et test pour win32 non valide A découvrir : Estopa, Rosario Flores, La Oreja De Van Gogh Bonne écoute @ + TChiki. |
apres tu refais un scan DSS et tu post le rapport main.txt stp
A découvrir : Estopa, Rosario Flores, La Oreja De Van Gogh
Bonne écoute @ + TChiki. |
win32 toujours non valide
main.txt: Deckard's System Scanner v20071014.68 Run by Admin 2 on 2008-07-31 10:38:05 Computer is in Normal Mode. -------------------------------------------------------------------------------- [color=red]Total Physical Memory: 254 MiB (512 MiB recommended)./color -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2008-07-31 10:38:35 Platform: Windows XP (5.01.2600) MSIE: Internet Explorer (6.00.2600.0000) Boot mode: Normal Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe D:\logiciel\sécurité\anti-spywares\instalation\aawservice.exe D:\logiciel\sécurité\antivirus\instalation\aswUpdSv.exe D:\logiciel\sécurité\antivirus\instalation\ashServ.exe C:\WINDOWS\explorer.exe C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe D:\logiciel\sécurité\antivirus\instalation\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe C:\WINDOWS\system32\spoolsv.exe D:\logiciel\sécurité\anti-trojans\instalation\a-squared Free\a2service.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files\Intel\Intel(R) Active Monitor\imonNT.exe C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Admin 2\Bureau\dss.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe O4 - HKLM\..\Run: [avast!] D:\logiciel\SCURIT~1\ANTIVI~1\INSTAL~1\ashDisp.exe O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\logiciel\sécurité\pare feu\instalation\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O9 - Extra button: Liens apparentés - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - D:\logiciel\sécurité\anti-trojans\instalation\a-squared Free\a2service.exe O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\logiciel\sécurité\anti-spywares\instalation\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - D:\logiciel\sécurité\antivirus\instalation\ashWebSv.exe O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel(R) Active Monitor\imonNT.exe O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe End of file - 4787 bytes -- Files created between 2008-06-30 and 2008-07-31 ----------------------------- 2008-07-31 10:12:34 0 d-------- C:\winfile.exe 2008-07-31 10:12:34 0 d-------- C:\temp2.exe 2008-07-31 10:12:34 0 d-------- C:\temp1.exe 2008-07-31 10:12:34 0 d-------- C:\temp.exe 2008-07-31 10:12:34 0 d-------- C:\ravmon.log 2008-07-31 10:12:34 0 d-------- C:\ravmon.exe 2008-07-31 10:12:34 0 d-------- C:\msvcr71.dll 2008-07-31 10:12:34 0 d-------- C:\host.exe 2008-07-31 10:12:34 0 d-------- C:\copy.exe 2008-07-31 10:12:34 0 d-------- C:\comment.htt 2008-07-31 10:12:34 0 d-------- C:\adober.exe 2008-07-31 10:12:10 167936 --a------ C:\VaccinUSB.exe <Not Verified; Auteur; Zeb-Fix_> 2008-07-31 08:15:47 0 d-------- C:\autorun.inf 2008-07-30 23:43:02 0 d-------- C:\WINDOWS\Caps 2008-07-30 23:42:54 0 d-------- C: |