Bonsoir Bernard,
Voilà j'ai fais le scan avec OTL dont voici le rapport. Merci de ton aide.
OTL logfile created on: 27/03/2010 16:54:06 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Franck.FRANCKPC\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 82,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111,78 Gb Total Space | 51,00 Gb Free Space | 45,62% Space Free | Partition Type: NTFS
Drive D: | 111,76 Gb Total Space | 49,67 Gb Free Space | 44,45% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: FRANCKPC
Current User Name: Franck
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Franck.FRANCKPC\Bureau\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe (TuneUp Software GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\OrangeHSS\Systray\SystrayApp.exe (France Telecom SA)
PRC - C:\Program Files\Fichiers communs\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe (France Telecom SA)
PRC - C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\CAPRPCSK.EXE (CANON INC.)
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Franck.FRANCKPC\Bureau\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll (Nuance Communications, Inc.)
MOD - C:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)
========== Win32 Services (SafeList) ========== SRV - (ioloSystemService) -- File not found
SRV - (ioloFileInfoList) -- File not found
SRV - (IOLO_SRV) -- File not found
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirWebService) -- C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira GmbH)
SRV - (AntiVirFirewallService) -- C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe (Avira GmbH)
SRV - (AntiVirMailService) -- C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (TuneUp.Defrag) -- C:\WINDOWS\system32\TuneUpDefragService.exe (TuneUp Software GmbH)
SRV - (vsmon) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Zone Labs, LLC)
SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (FTRTSVC) -- C:\Program Files\Fichiers communs\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe (France Telecom SA)
SRV - (IDriverT) -- C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ose) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (MDM) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (avfwot) -- C:\WINDOWS\system32\drivers\avfwot.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PCAMPR5) -- C:\WINDOWS\system32\pcampr5.sys ()
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (avfwim) -- C:\WINDOWS\system32\drivers\avfwim.sys (Avira GmbH)
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (Changer) -- C:\WINDOWS\system32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) -- C:\WINDOWS\system32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (usbaudio) Pilote USB audio (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Zone Labs, LLC)
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (LMouKE) -- C:\WINDOWS\system32\drivers\LMouKE.Sys (Logitech Inc.)
DRV - (L8042mou) -- C:\WINDOWS\system32\drivers\L8042mou.Sys (Logitech Inc.)
DRV - (L8042Kbd) -- C:\WINDOWS\system32\drivers\L8042Kbd.sys (Logitech Inc.)
DRV - (PCANDIS5) -- C:\WINDOWS\system32\pcandis5.sys.bak (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) -- C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys ()
DRV - (prohlp02) -- C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) -- C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (sfhlp01) -- C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prosync1) -- C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (tfsnudfa) -- C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) -- C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) -- C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) -- C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) -- C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) -- C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) -- C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) -- C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) -- C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (sscdbhk5) -- C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) -- C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (drvnddm) -- C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (ctdvda2k) -- C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) -- C:\WINDOWS\system32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) -- C:\WINDOWS\system32\drivers\pfmodnt.sys (Creative Technology Ltd.)
DRV - (emupia) -- C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) -- C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (OMCI) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (RapidPort) -- C:\WINDOWS\system32\drivers\CAPLPTN.SYS (CANON INC.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\..\URLSearchHook: {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/25 08:54:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2pre\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/25 08:54:46 | 000,000,000 | ---D | M]
[2008/09/08 17:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Franck.FRANCKPC\Application Data\Mozilla\Extensions
[2010/03/27 12:47:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Franck.FRANCKPC\Application Data\Mozilla\Firefox\Profiles\4nm87isg.default\extensions
[2009/08/30 21:12:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Franck.FRANCKPC\Application Data\Mozilla\Firefox\Profiles\4nm87isg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/30 08:14:40 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Franck.FRANCKPC\Application Data\Mozilla\Firefox\Profiles\4nm87isg.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/08/07 06:57:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Franck.FRANCKPC\Application Data\Mozilla\Firefox\Profiles\4nm87isg.default\extensions\fr@dictionaries.addons.mozilla.org
[2010/03/27 12:47:32 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2006/10/08 10:38:11 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2007/03/30 15:55:03 | 000,180,305 | ---- | M] (Exent Technologies Ltd) -- C:\Program Files\Mozilla Firefox\plugins\npExentCtl.dll
[2010/01/16 02:10:07 | 000,001,516 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
[2010/01/16 02:10:07 | 000,001,822 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010/01/16 02:10:07 | 000,000,757 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
[2010/01/16 02:10:07 | 000,001,426 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
[2010/03/25 08:54:41 | 000,000,956 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: ([2010/03/25 21:24:58 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Programme d'aide de l'Assistant de connexion Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\ctasio.dll (Creative Technology Ltd)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CAPON] C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPONN.EXE (CANON INC.)
O4 - HKLM..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [StorageGuard] C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [SystrayORAHSS] C:\Program Files\OrangeHSS\Systray\SystrayApp.exe (France Telecom SA)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Orange Desktop Search] C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe (France Telecom SA)
O4 - HKCU..\Run: [pdfSaver3] C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe (Tracker Software Products Ltd.)
O4 - HKCU..\Run: [TuneUp MemOptimizer] C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe (TuneUp Software GmbH)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715}
http://www.creative.com/su/ocx/15026/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/pub/sh ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupda ... 9794853046 (WUWebControl Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftup ... 4287604140 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://www.creative.com/su/ocx/15026/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/FRANCK~1.FRA/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:1 (Ma page d'accueil) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/02 13:38:34 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (autocheck smrgdf C:\Documents and Settings\Franck.FRANCKPC\Application Data\iolo) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ========== [2010/03/27 16:50:35 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\OTL.exe
[2010/03/27 14:17:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/03/27 14:12:48 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/03/27 14:12:23 | 000,000,000 | --SD | C] -- C:\ComboFix
[2010/03/27 05:45:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Franck.FRANCKPC\Recent
[2010/03/25 21:16:19 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asyncmac.sys
[2010/03/25 21:09:36 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/03/25 21:07:30 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/03/25 21:07:30 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/03/25 21:07:30 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/03/25 21:07:30 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/03/25 21:06:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/03/25 20:50:26 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/03/25 12:01:37 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/03/22 09:42:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Franck.FRANCKPC\Application Data\Avira
[2010/03/22 09:09:44 | 000,097,608 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avfwot.sys
[2010/03/22 09:09:44 | 000,096,104 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/03/22 09:09:44 | 000,056,816 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/03/22 09:09:44 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/03/22 09:09:44 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/03/22 09:09:43 | 000,069,632 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avfwim.sys
[2010/03/22 09:09:43 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/03/22 09:09:36 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2010/03/22 09:09:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2010/03/22 08:02:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Franck.FRANCKPC\Application Data\Malwarebytes
[2010/03/22 08:01:59 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/22 08:01:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
[2010/03/22 08:01:55 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/22 08:01:55 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/21 09:15:37 | 000,015,840 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\drivers\pfmodnt.sys
[2010/03/21 09:15:36 | 000,141,536 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\hap16v2k.sys
[2010/03/21 09:15:35 | 000,823,616 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ha10kx2k.sys
[2010/03/21 09:15:34 | 000,116,000 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\emupia2k.sys
[2010/03/21 09:15:33 | 000,135,248 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctsfm2k.sys
[2010/03/21 09:15:33 | 000,006,144 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctprxy2k.sys
[2010/03/21 09:15:32 | 000,189,504 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\drivers\ctoss2k.sys
[2010/03/21 09:15:29 | 000,498,688 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctaud2k.sys
[2010/03/21 09:15:29 | 000,135,040 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctac32k.sys
[2010/03/21 09:15:23 | 000,049,152 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\CTDCRES.DLL
[2010/03/21 09:15:20 | 000,270,336 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\sfms32.dll
[2010/03/21 09:15:20 | 000,036,864 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\sfman32.dll
[2010/03/21 09:15:19 | 000,176,128 | ---- | C] (Creative Technology Limited) -- C:\WINDOWS\READREG.EXE
[2010/03/21 09:15:18 | 000,159,744 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\OpenAL32.dll
[2010/03/21 09:15:18 | 000,110,592 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\piaproxy.dll
[2010/03/21 09:15:18 | 000,049,152 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\MIDIDEF.EXE
[2010/03/21 09:15:17 | 000,077,824 | ---- | C] (Creative Labs) -- C:\WINDOWS\System32\eaxac3.dll
[2010/03/21 09:15:17 | 000,020,480 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ENSDEF.EXE
[2010/03/21 09:15:16 | 000,094,208 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\DEVREG.DLL
[2010/03/21 09:15:13 | 000,045,056 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctspkhlp.dll
[2010/03/21 09:15:12 | 000,110,592 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctscal.dll
[2010/03/21 09:15:11 | 000,655,360 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctsblfx.dll
[2010/03/21 09:15:10 | 000,155,648 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctosuser.dll
[2010/03/21 09:15:10 | 000,036,864 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctemupia.dll
[2010/03/21 09:15:10 | 000,028,672 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\CtHelper.exe
[2010/03/21 09:15:03 | 000,139,264 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctdcifce.dll
[2010/03/21 09:15:03 | 000,110,592 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctdproxy.dll
[2010/03/21 09:15:02 | 000,393,216 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctdc0001.dll
[2010/03/21 09:15:01 | 000,319,488 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctdc0000.dll
[2010/03/21 09:15:00 | 000,495,616 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctaudfx.dll
[2010/03/21 09:15:00 | 000,110,592 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctasio.dll
[2010/03/21 09:15:00 | 000,061,440 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctagent.dll
[2010/03/21 09:14:55 | 000,126,976 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\commonfx.dll
[2010/03/21 09:14:55 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\dllcache\a3d.dll
[2010/03/21 09:14:55 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2010/03/21 09:14:55 | 000,053,248 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ac3api.dll
[2010/03/21 09:13:49 | 000,287,920 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctdvda2k.sys
[2010/03/21 09:13:49 | 000,077,824 | ---- | C] (Creative Technology Ltd) -- C:\WINDOWS\System32\ctdvda32.dll
[2010/03/21 09:12:57 | 000,012,288 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\AHQCpURes.dll
[2010/03/21 09:12:55 | 000,032,768 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\AudioHQU.cpl
[2010/03/21 09:05:29 | 000,065,536 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\CTDetres.dll
[2010/03/21 09:05:18 | 000,331,776 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\CTMEDENG.DLL
[2010/03/21 09:05:11 | 000,139,264 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\Video.skn
[2010/03/21 09:05:11 | 000,024,576 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\CTMERes.DLL
[2010/03/17 12:21:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\Threat Expert
[2010/03/17 07:42:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\NICOLAS
[2010/03/16 17:51:00 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll.old
[2010/03/16 17:43:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/03/16 04:59:50 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\drivers\lbrtfdc.sys
[2010/03/16 04:59:43 | 000,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2010/03/16 04:59:26 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\changer.sys
[2010/03/16 04:59:26 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\changer.sys
[2010/03/13 06:07:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\Real
[2010/03/13 06:06:55 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010/03/13 06:06:44 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010/03/13 06:06:44 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010/03/13 06:06:24 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\xing shared
[2010/03/12 13:41:20 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe
[2010/03/09 09:12:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Real
[2006/10/02 12:06:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/10/02 12:06:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/10/02 12:06:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2006/10/02 12:06:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/03/27 16:56:40 | 000,860,672 | ---- | M] () -- C:\WINDOWS\System32\drivers\fnigkty.sys
[2010/03/27 16:50:36 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\OTL.exe
[2010/03/27 16:22:58 | 004,481,358 | ---- | M] () -- C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2010/03/27 16:00:00 | 000,000,542 | ---- | M] () -- C:\WINDOWS\tasks\Maintenance automatique.job
[2010/03/27 15:56:22 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\World of Warcraft.lnk
[2010/03/27 14:24:05 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/03/27 14:23:00 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-117609710-2139871995-725345543-1004.job
[2010/03/27 14:22:57 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/03/27 14:22:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/03/27 14:17:20 | 000,060,416 | ---- | M] () -- C:\WINDOWS\System32\drivers\Combo-Fix.sys
[2010/03/27 14:08:29 | 000,001,032 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\Raccourci vers ComboFix.exe.lnk
[2010/03/27 14:03:29 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/03/27 12:59:35 | 000,031,560 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/27 12:59:35 | 000,031,560 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/27 12:59:35 | 000,031,440 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/27 12:59:35 | 000,031,440 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/27 12:59:35 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010/03/27 12:59:35 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010/03/27 12:59:35 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/03/27 12:59:35 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/03/27 12:59:33 | 000,000,284 | -HS- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\ntuser.ini
[2010/03/27 12:59:32 | 018,612,224 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\NTUSER.DAT
[2010/03/27 06:08:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-2139871995-725345543-1004.job
[2010/03/26 05:55:51 | 308,823,040 | ---- | M] () -- C:\WINDOWS\outlook.pst
[2010/03/26 05:53:36 | 000,002,501 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\Microsoft Office Outlook 2003.lnk
[2010/03/25 21:24:58 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/03/25 21:09:43 | 000,000,286 | RHS- | M] () -- C:\boot.ini
[2010/03/25 12:01:39 | 000,001,748 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\HijackThis.com.lnk
[2010/03/24 22:16:00 | 004,268,032 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\Jardin_de_Balata-1-bebey.pps
[2010/03/23 16:42:04 | 003,786,624 | -H-- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\IconCache.db
[2010/03/22 09:28:50 | 000,097,608 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avfwot.sys
[2010/03/22 09:28:50 | 000,056,816 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/03/22 09:28:50 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/03/22 09:27:11 | 000,003,072 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/03/22 09:10:14 | 000,001,721 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2010/03/22 08:13:11 | 000,004,416 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\rapport Malwarebytes
[2010/03/22 08:02:01 | 000,000,710 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Malwarebytes' Anti-Malware.lnk
[2010/03/21 18:26:07 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\Cher Amis.doc
[2010/03/21 18:22:29 | 000,001,570 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\intlname.ols
[2010/03/21 09:06:36 | 000,000,136 | ---- | M] () -- C:\WINDOWS\SBWIN.INI
[2010/03/21 08:54:28 | 000,008,683 | ---- | M] () -- C:\WINDOWS\System32\CTHELPER.RPT
[2010/03/19 20:07:06 | 000,000,332 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\Mes documents.lnk
[2010/03/19 18:16:26 | 000,380,826 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100320-093543.backup
[2010/03/17 15:43:25 | 000,296,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/17 14:30:20 | 000,082,048 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/17 14:07:14 | 000,380,826 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100319-181626.backup
[2010/03/16 21:33:39 | 000,010,828 | -HS- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\icMtWSjHcWRiY
[2010/03/16 21:33:39 | 000,010,828 | -HS- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\icMtWSjHcWRiY
[2010/03/16 17:39:56 | 000,348,672 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\Remove Antivirus XP 2010.doc
[2010/03/16 16:00:51 | 000,380,758 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100317-140714.backup
[2010/03/16 05:00:14 | 000,823,296 | ---- | M] () -- C:\WINDOWS\System32\pcampr5.sys
[2010/03/16 04:57:19 | 000,000,126 | ---- | M] () -- C:\WINDOWS\System32\bopk.bat
[2010/03/13 06:06:55 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010/03/13 06:06:44 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010/03/13 06:06:44 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010/03/13 06:05:53 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2010/03/12 18:02:38 | 000,261,632 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010/03/10 10:22:56 | 000,001,562 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\CCleaner.lnk
[2010/03/10 10:13:24 | 001,096,282 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/10 10:13:24 | 000,503,690 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2010/03/10 10:13:24 | 000,435,700 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/10 10:13:24 | 000,080,956 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2010/03/10 10:13:24 | 000,068,214 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/10 09:07:24 | 000,000,915 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/03/10 08:17:52 | 000,355,584 | ---- | M] (TuneUp Software GmbH) -- C:\WINDOWS\System32\TuneUpDefragService.exe
[2010/03/09 19:54:22 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\synthese.doc
[2010/03/09 19:13:29 | 000,029,259 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\RECUP.DOC
[2010/03/08 17:27:22 | 000,380,375 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100316-160051.backup
[2010/03/01 20:30:36 | 000,000,862 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Paint.NET.lnk
[2010/02/28 21:53:28 | 000,380,375 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100308-172722.backup
[2010/02/28 21:53:06 | 000,380,375 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100228-215328.backup
[2010/02/26 14:07:00 | 000,752,576 | ---- | M] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\epouse infidele.wmv
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/03/27 14:17:20 | 000,060,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\Combo-Fix.sys
[2010/03/27 14:08:29 | 000,001,032 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\Raccourci vers ComboFix.exe.lnk
[2010/03/25 21:09:43 | 000,000,216 | ---- | C] () -- C:\Boot.bak
[2010/03/25 21:09:38 | 000,263,488 | ---- | C] () -- C:\cmldr
[2010/03/25 21:07:30 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/03/25 21:07:30 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/03/25 21:07:30 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/03/25 21:07:30 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/03/25 21:07:30 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/03/25 12:01:39 | 000,001,748 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\HijackThis.com.lnk
[2010/03/24 22:16:39 | 004,268,032 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\Jardin_de_Balata-1-bebey.pps
[2010/03/22 09:10:14 | 000,001,721 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Avira AntiVir Control Center.lnk
[2010/03/22 08:13:11 | 000,004,416 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Bureau\rapport Malwarebytes
[2010/03/22 08:02:01 | 000,000,710 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Bureau\Malwarebytes' Anti-Malware.lnk
[2010/03/21 18:26:07 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\Cher Amis.doc
[2010/03/21 10:03:43 | 004,481,358 | ---- | C] () -- C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2010/03/21 09:16:44 | 000,031,560 | ---- | C] () -- C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/21 09:16:44 | 000,031,560 | ---- | C] () -- C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/21 09:16:44 | 000,031,440 | ---- | C] () -- C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/21 09:16:44 | 000,031,440 | ---- | C] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/03/21 09:16:44 | 000,000,288 | ---- | C] () -- C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/03/21 09:16:44 | 000,000,288 | ---- | C] () -- C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/03/21 09:15:34 | 000,232,723 | ---- | C] () -- C:\WINDOWS\System32\ctstatic.dat
[2010/03/21 09:15:31 | 000,190,842 | ---- | C] () -- C:\WINDOWS\System32\ctdlang.dat
[2010/03/21 09:15:31 | 000,110,720 | ---- | C] () -- C:\WINDOWS\System32\CTBASICW.DAT
[2010/03/21 09:15:31 | 000,053,674 | ---- | C] () -- C:\WINDOWS\System32\ctdaught.dat
[2010/03/21 09:15:30 | 000,138,716 | ---- | C] () -- C:\WINDOWS\System32\ctbas2w.dat
[2010/03/21 09:15:20 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\regplib.exe
[2010/03/21 09:15:19 | 000,184,320 | ---- | C] () -- C:\WINDOWS\PSCONV.EXE
[2010/03/21 09:15:18 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\killapps.exe
[2010/03/21 09:15:17 | 000,005,515 | ---- | C] () -- C:\WINDOWS\System32\ENSDEF.INI
[2010/03/21 09:15:17 | 000,000,180 | ---- | C] () -- C:\WINDOWS\System32\kill.ini
[2010/03/21 09:15:16 | 000,000,059 | ---- | C] () -- C:\WINDOWS\System32\default8.sfm
[2010/03/21 09:15:16 | 000,000,059 | ---- | C] () -- C:\WINDOWS\System32\default4.sfm
[2010/03/21 09:15:16 | 000,000,059 | ---- | C] () -- C:\WINDOWS\System32\default.sfm
[2010/03/21 09:15:13 | 002,259,067 | ---- | C] () -- C:\WINDOWS\System32\DEFAULT.ECW
[2010/03/21 09:15:04 | 004,481,358 | ---- | C] () -- C:\WINDOWS\CTDVAUDY.CDF
[2010/03/21 09:14:57 | 002,167,684 | ---- | C] () -- C:\WINDOWS\System32\CT2MGM.SF2
[2010/03/21 09:14:55 | 001,048,576 | ---- | C] () -- C:\WINDOWS\System32\CT1MGM.ROM
[2010/03/21 09:13:49 | 000,831,600 | ---- | C] () -- C:\WINDOWS\System32\Ctaa1.dat
[2010/03/21 09:05:29 | 000,019,132 | ---- | C] () -- C:\WINDOWS\System32\CTDetect.hlp
[2010/03/21 09:05:29 | 000,000,727 | ---- | C] () -- C:\WINDOWS\System32\CTDetect.cnt
[2010/03/19 20:07:12 | 000,000,332 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\Mes documents.lnk
[2010/03/18 22:19:53 | 000,860,672 | ---- | C] () -- C:\WINDOWS\System32\drivers\fnigkty.sys
[2010/03/16 17:51:02 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old
[2010/03/16 17:39:55 | 000,348,672 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\Remove Antivirus XP 2010.doc
[2010/03/16 04:59:50 | 000,034,688 | ---- | C] () -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2010/03/16 04:57:19 | 000,000,126 | ---- | C] () -- C:\WINDOWS\System32\bopk.bat
[2010/03/16 04:55:33 | 000,010,828 | -HS- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\icMtWSjHcWRiY
[2010/03/16 04:55:33 | 000,010,828 | -HS- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\icMtWSjHcWRiY
[2010/03/13 06:07:07 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-117609710-2139871995-725345543-1004.job
[2010/03/13 06:07:06 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-2139871995-725345543-1004.job
[2010/03/11 18:04:10 | 016,855,552 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\LE FEU 05 26 Novembre 2009.doc
[2010/03/09 19:48:11 | 000,023,552 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\synthese.doc
[2010/03/09 19:13:28 | 000,029,259 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\RECUP.DOC
[2010/03/08 08:31:23 | 000,000,542 | ---- | C] () -- C:\WINDOWS\tasks\Maintenance automatique.job
[2010/02/26 14:07:23 | 000,752,576 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Mes documents\epouse infidele.wmv
[2009/12/07 07:49:17 | 000,000,288 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2009/07/16 00:40:19 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/01/11 20:43:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PCFriend.INI
[2008/10/22 06:24:36 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CTBurst.dll
[2008/10/22 06:24:35 | 000,071,680 | ---- | C] () -- C:\WINDOWS\System32\ctmmactl.dll
[2008/10/22 06:24:32 | 000,105,728 | ---- | C] () -- C:\WINDOWS\System32\APOMgrH.dll
[2008/10/22 06:24:22 | 000,097,785 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2008/10/22 06:24:22 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2008/04/22 08:15:32 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2008/04/22 08:14:24 | 000,066,807 | ---- | C] () -- C:\WINDOWS\System32\Aud2_Del.ini
[2008/04/22 08:09:57 | 000,000,136 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2008/04/21 19:00:38 | 000,024,576 | ---- | C] () -- C:\WINDOWS\CTXFIFRN.DLL
[2007/12/21 18:27:03 | 000,021,904 | ---- | C] () -- C:\WINDOWS\System32\imsinstall_loc040c.dll
[2007/12/21 18:27:03 | 000,017,808 | ---- | C] () -- C:\WINDOWS\System32\imslsp_install_loc040c.dll
[2007/12/21 18:26:23 | 000,796,048 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2007/12/15 19:45:31 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2007/12/04 22:07:12 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ezsid.dat
[2007/09/16 16:03:42 | 000,000,040 | ---- | C] () -- C:\WINDOWS\NAVIGMA.INI
[2007/08/31 18:02:55 | 000,138,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/06/06 07:37:39 | 000,000,084 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2007/02/20 14:14:48 | 000,000,469 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/02/10 12:32:32 | 000,823,296 | ---- | C] () -- C:\WINDOWS\System32\pcampr5.sys
[2007/01/27 23:35:14 | 000,437,096 | ---- | C] () -- C:\WINDOWS\System32\Incinerator.dll
[2007/01/25 20:05:32 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2007/01/25 20:05:32 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2007/01/25 20:05:32 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2007/01/25 20:04:04 | 000,000,196 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/01/24 12:22:18 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2007/01/24 12:22:17 | 000,696,320 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2007/01/23 18:44:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2007/01/20 13:40:35 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\QTSBandwidthCache
[2006/11/11 21:04:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2006/10/30 07:00:28 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2006/10/30 07:00:28 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2006/10/05 10:54:19 | 000,290,919 | ---- | C] () -- C:\WINDOWS\System32\pythoncom21.dll
[2006/10/05 10:54:19 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes21.dll
[2006/10/05 10:52:33 | 000,096,768 | ---- | C] () -- C:\WINDOWS\SlantAdj.dll
[2006/10/05 10:52:33 | 000,000,072 | ---- | C] () -- C:\WINDOWS\System32\epDPE.ini
[2006/10/05 10:29:36 | 000,000,861 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/10/05 10:10:16 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE P3170EIF.ini
[2006/10/04 12:58:59 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2006/10/03 14:48:25 | 000,174,592 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/10/03 12:50:48 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/10/02 16:32:00 | 000,000,138 | ---- | C] () -- C:\Documents and Settings\Franck.FRANCKPC\Local Settings\Application Data\fusioncache.dat
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2006/06/12 20:43:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/09/21 15:53:52 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\imhost8.dll
[2004/09/15 12:18:50 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\msvcrt10.dll
[2004/08/04 06:29:54 | 001,897,408 | ---- | C] () -- C:\WINDOWS\System32\drivers\nv4_mini.sys
[2003/11/20 22:39:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/04/01 10:58:02 | 000,005,260 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[1999/12/15 21:16:06 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\LPNG.DLL
[1999/07/05 11:00:00 | 000,075,464 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[1998/10/11 01:07:38 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
[1996/12/16 23:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1996/12/16 23:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1996/12/16 23:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\VAFR232.DLL
[1996/12/16 23:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
========== Custom Scans ========== < %SYSTEMDRIVE%\cdrom.sys /s /md5 >[2004/08/04 06:59:52 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
[2008/04/13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2010/03/19 08:55:36 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
< %SYSTEMDRIVE%\atapi.sys /s /md5 >[2004/08/04 07:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 06:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\atapi.sys
[2004/08/04 07:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0016\DriverFiles\i386\atapi.sys
< %SYSTEMDRIVE%\ACPI.sys /s /md5 >[2004/08/19 23:51:54 | 000,188,672 | ---- | M] (Microsoft Corporation) MD5=0BD94FBFC14EA3606CD6CA4C0255BAA3 -- C:\WINDOWS\$NtServicePackUninstall$\acpi.sys
[2008/04/14 02:52:42 | 000,188,672 | ---- | M] (Microsoft Corporation) MD5=E5E6DBFC41EA8AAD005CB9A57A96B43B -- C:\WINDOWS\ServicePackFiles\i386\acpi.sys
[2008/04/14 02:52:42 | 000,188,672 | ---- | M] (Microsoft Corporation) MD5=E5E6DBFC41EA8AAD005CB9A57A96B43B -- C:\WINDOWS\system32\drivers\acpi.sys
< %SYSTEMDRIVE%\*.exe > < %SYSTEMDRIVE%\iaStor.sys /s /md5 > < %SYSTEMDRIVE%\nvstor.sys /s /md5 > < %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 > < %SYSTEMDRIVE%\viasraid.sys /s /md5 > < %SYSTEMDRIVE%\AGP440.sys /s /md5 >[2004/08/04 08:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2008/04/13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 07:07:41 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\ReinstallBackups\0019\DriverFiles\i386\AGP440.SYS
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 > < %SYSTEMDRIVE%\nvatabus.sys /s /md5 > < %systemdrive%\fnigkty.* /s /md5 >[2010/03/27 17:00:06 | 000,860,672 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\fnigkty.sys
========== Alternate Data Streams ========== @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A8ADE5D8
< End of report >
Heu... j'ai bien vu que dans les dernieres lignes cela parle du dossier infecté (systeme 32/drivers/fnigkty.sys) mais c'est a peu prés tout ce que j'ai compris. Merci de ton aide.