Merci beaucoup pour ta reponse
J'ai suivi les instructions et apres rebooté mon PC les symptomes demeurent les memes : Pas
de Ctrl/Alt/del et impossible
de lancer regedit...
Ci dessous le fichier main.txt
de dss et je mets le fichier extra.txt dans un autre message.
Merci d'avance
Raphael
Deckard's System Scanner v20071014.68
Run by Raphael Perez on 2008-08-05 11:42:46
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
12: 2008-08-05 09:42:58 UTC - RP458 - Deckard's System Scanner Restore Point
11: 2008-08-04 16:30:27 UTC - RP457 - Kaspersky Internet Security 2009 a été supprimé.
10: 2008-08-04 13:21:50 UTC - RP456 - Opération
de restauration
9: 2008-08-04 12:07:17 UTC - RP455 - Installé VAIO Media Integrated Server Update
8: 2008-07-26 20:42:20 UTC - RP454 - Point
de vérification système
-- First Restore Point --
1: 2008-07-16 12:17:47 UTC - RP447 - Point
de vérification système
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Raphael Perez.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:53, on 05/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Raphael Perez\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\Bidule\Raphael Perez.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://fr.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://fr.rd.yahoo.com/customize/ie/def ... .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://fr.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://fr.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0B497AE8-3F6C-440C-AB87-52ED0182464A} - C:\Program Files\Internet Explorer\IEXPLORE32.Dat (file missing)
O2 - BHO: (no name) - {1FD4696C-E95A-44E2-A03A-FDBDF4CCC305} - C:\Program Files\Internet Explorer\IEXPLORE32.win (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {74381DEC-D78B-43E4-BA5D-5244F669EBE4} - C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\GoogleAFE.dll
O2 - BHO: (no name) - {E6C0D0E3-9E9A-489D-AE19-BBCFC7047A59} - C:\Program Files\Internet Explorer\IEXPLORE32.Sys (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Agematis FAM] "C:\Program Files\steek\steekUP\FAM\fileAccessManager.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [AskSBar Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -3
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Transfert par Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll (file missing)
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll (file missing)
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/softwareupdate/ ... TSUEng.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) -
http://a516.g.akamai.net/f/516/25175/7d ... o-eula.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) -
http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) -
http://www.linkedin.com/cab/LinkedInCon ... ontrol.cab
O16 - DPF: {6531D99C-0D0E-4293-B3CB-A3E1D0D41847} (AhnASP Control) -
http://aspglobal.ahnlab.com/asp/cab/AhnASP.cab
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} (YbUploadFavsCtl Class) -
http://us.bookmarks.yahoo.com/YbConvFav.CAB
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) -
http://as.photoprintit.de/ips-opdata/la ... loader.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/softwareupdate/ ... /CTPID.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Service
de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
--
End of file - 14831 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\Bidule\backups\) -------------
backup-20080804-184913-942 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
backup-20080804-184914-776 O23 - Service: 831E1E90 - Unknown owner - C:\WINDOWS\system32\9754E5F0.EXE (file missing)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 FileCloner - c:\windows\system32\drivers\famfd.sys <Not>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not>
R2 s24trans (Transport RLAN) - c:\windows\system32\drivers\s24trans.sys <Not>
R2 ZDCNDIS5 (ZDCNDIS5 NDIS Protocol Driver) - c:\windows\zdcndis5.sys <Not>
S2 LMIInfo (LogMeIn Kernel Information Provider) - c:\program files\logmein\x86\rainfo.sys (file missing)
S2 ME102RB (NETGEAR ME102 Access Point) - c:\windows\system32\drivers\me102rb.sys
S3 axyoqpxay - c:\windows\system32\drivers\axyoqpxay.sys
S3 axyoqrxab - c:\windows\system32\drivers\axyoqrxab.sys
S3 axyoqrxyb - c:\windows\system32\drivers\axyoqrxyb.sys
S3 c - c:\docume~1\raphae~1\locals~1\temp\_tmp.bat (file missing)
S3 vsqnn - c:\docume~1\raphae~1\locals~1\temp\_tmp.bat (file missing)
S3 vsqqn - c:\docume~1\raphae~1\locals~1\temp\_tmp.bat (file missing)
S3 ZDPSp50 (ZDPSp50 NDIS Protocol Driver) - c:\windows\system32\drivers\zdpsp50.sys <Not>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\fichiers communs\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not>
R2 RegSrvc - c:\program files\intel\wireless\bin\regsrvc.exe <Not>
S4 831E1E90 - c:\windows\system32\9754e5f0.exe -d (file missing)
S4 F-Secure Gatekeeper Handler Starter - "c:\program files\securitoo\av_fw\anti-virus\fsgk32st.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Codecs audio
Device ID: ROOT\MEDIA\MS_MMACM
Manufacturer: (Périphériques système standard)
Name: Codecs audio
PNP Device ID: ROOT\MEDIA\MS_MMACM
Service: audstub
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Pilotes audio hérités
Device ID: ROOT\MEDIA\MS_MMDRV
Manufacturer: (Périphériques système standard)
Name: Pilotes audio hérités
PNP Device ID: ROOT\MEDIA\MS_MMDRV
Service: audstub
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Périphériques MCI
Device ID: ROOT\MEDIA\MS_MMMCI
Manufacturer: (Périphériques système standard)
Name: Périphériques MCI
PNP Device ID: ROOT\MEDIA\MS_MMMCI
Service: audstub
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Périphériques
de capture vidéo hérités
Device ID: ROOT\MEDIA\MS_MMVCD
Manufacturer: (Périphériques système standard)
Name: Périphériques
de capture vidéo hérités
PNP Device ID: ROOT\MEDIA\MS_MMVCD
Service: audstub
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Codecs vidéo
Device ID: ROOT\MEDIA\MS_MMVID
Manufacturer: (Périphériques système standard)
Name: Codecs vidéo
PNP Device ID: ROOT\MEDIA\MS_MMVID
Service: audstub
-- Scheduled Tasks -------------------------------------------------------------
2008-08-05 10:59:23 438 --ah----- C:\WINDOWS\Tasks\User_Feed_Synchronization-{F4B4AF75-DC69-4CEC-B01F-A53B845397F9}.job
2008-07-25 10:40:11 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-07-05 and 2008-08-05 -----------------------------
2008-08-05 11:41:09 262144 --a------ C:\Program Files\Uninstall Ask Toolbar.dll <Not>
2008-08-05 11:38:07 0 dr-h----- C:\Documents and Settings\Raphael Perez\Recent
2008-08-05 11:28:54 0 d-------- C:\Program Files\CCleaner
2008-08-05 11:28:02 0 d-------- C:\ccleaner
2008-08-04 19:32:01 70528 --a------ C:\WINDOWS\system32\drivers\ahnsze.sys <Not>
2008-08-04 19:11:12 0 d-------- C:\Program Files\AhnLab
2008-08-04 15:52:02 0 d-------- C:\Program Files\Trend Micro
2008-08-04 15:25:23 0 d-------- C:\Program Files\APLI Paper
2008-08-04 14:43:27 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Lavasoft
2008-08-04 14:35:31 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Skype
2008-07-23 17:43:39 0 d-------- C:\WINDOWS\ERUNT
2008-07-23 15:27:54 0 d-------- C:\WINDOWS\BDOSCAN8
2008-07-23 02:46:01 0 d-------- C:\WINDOWS\system32\GroupPolicy
2008-07-22 12:37:04 0 d-------- C:\WINDOWS\Prefetch
2008-07-22 11:07:26 0 d-------- C:\WINDOWS\l2schemas
2008-07-22 10:59:19 0 d-------- C:\WINDOWS\ServicePackFiles
2008-07-16 14:17:40 9510912 --a------ C:\Documents and Settings\Raphael Perez\ntuser.dat
2008-07-15 16:15:25 0 d-------- C:\Program Files\Alwil Software
2008-07-15 15:24:55 0 d-a------ C:\Program Files\AskSBar
2008-07-15 15:23:50 0 d-------- C:\Program Files\Vuze
2008-07-15 15:12:56 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-15 15:12:53 0 d-------- C:\Program Files\SpywareBlaster
2008-07-15 13:40:58 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-15 01:34:23 130 --a------ C:\_uninsep.bat
2008-07-11 16:41:55 0 --a------ C:\WINDOWS\system32\wcomepk.exe
2008-07-07 20:01:01 1520128 -ra------ C:\WINDOWS\system32\BrWia06b.dll <Not>
2008-07-07 20:00:28 50 --a------ C:\WINDOWS\system32\bd9840cn.dat
2008-07-07 19:59:11 56832 --a------ C:\WINDOWS\system32\brinsstr.dll <Not>
2008-07-07 19:57:54 34816 -----n--- C:\WINDOWS\system32\BrWiaNCp.dll <Not>
2008-07-07 19:57:54 37376 -----n--- C:\WINDOWS\system32\Brnsplg.dll <Not>
2008-07-07 19:57:54 58368 -----n--- C:\WINDOWS\system32\BrNetSti.dll <Not>
2008-07-07 19:57:50 0 d-------- C:\Brother
2008-07-07 19:57:49 0 --a------ C:\WINDOWS\brdfxspd.dat
2008-07-07 19:57:48 163840 -----n--- C:\WINDOWS\system32\NSSearch.dll <Not>
2008-07-07 19:57:48 106496 -----n--- C:\WINDOWS\system32\BrMuSNMP.dll
2008-07-07 19:57:48 61440 -----n--- C:\WINDOWS\system32\BrMfNt.dll <Not>
2008-07-07 19:57:48 126976 -----n--- C:\WINDOWS\system32\BrfxD05a.dll <Not>
2008-07-07 19:57:48 73728 -----n--- C:\WINDOWS\system32\BRCrypt.dll <Not>
2008-07-07 19:57:47 147456 -----n--- C:\WINDOWS\brunin03.dll <Not>
2008-07-07 19:55:19 0 d-------- C:\Program Files\Nuance
2008-07-07 19:52:26 0 d-------- C:\Program Files\Fichiers communs\ScanSoft Shared
2008-07-07 19:52:07 0 d-------- C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-07-07 19:51:51 0 d-------- C:\Program Files\ScanSoft
2008-07-07 19:47:48 0 d-------- C:\Documents and Settings\Raphael Perez\Application Data\Research In Motion
2008-07-07 19:20:23 0 d-------- C:\Documents and Settings\Raphael Perez\Application Data\Blackberry Desktop
2008-07-07 19:20:03 0 d-------- C:\Program Files\Fichiers communs\Research In Motion
2008-07-07 19:19:45 0 d-------- C:\Program Files\Research In Motion
-- Find3M Report ---------------------------------------------------------------
2008-08-04 18:09:37 0 d-------- C:\Program Files\AAAMicrosoft ActiveSync
2008-08-04 17:47:22 0 d-------- C:\Documents and Settings\Raphael Perez\Application Data\Skype
2008-08-04 15:28:28 0 d-------- C:\Program Files\Windows NT
2008-08-04 15:28:19 0 d-------- C:\Program Files\Movie Maker
2008-08-04 15:26:41 0 d-------- C:\Program Files\Messenger
2008-08-04 15:24:21 0 d-------- C:\Program Files\MSN Messenger
2008-08-04 15:23:45 0 d-------- C:\Program Files\Fichiers communs\Adobe
2008-08-04 13:52:06 256 --a------ C:\WINDOWS\system32\pool.bin
2008-07-22 14:18:27 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-22 14:09:36 473896 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-07-22 14:09:36 77592 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-07-22 10:51:42 252240 -rahs---- C:\ntldr
2008-07-15 09:59:36 0 d-------- C:\Documents and Settings\Raphael Perez\Application Data\InstallShield
2008-07-09 16:53:16 0 d-------- C:\Program Files\Roxio
2008-07-09 11:23:55 0 d-------- C:\Program Files\Fichiers communs\Sonic Shared
2008-07-09 11:20:01 0 d-------- C:\Program Files\Fichiers communs\Roxio Shared
2008-07-07 20:02:04 34 --a------ C:\WINDOWS\system32\bd9840cd.dat
2008-07-07 19:59:14 0 d-------- C:\Program Files\Brother
2008-07-07 19:52:26 0 d-------- C:\Program Files\Fichiers communs
2008-07-04 13:57:18 0 dr------- C:\Documents and Settings\Raphael Perez\Application Data\Brother
2008-07-04 13:54:04 0 --a------ C:\Program Files\error.dat
2008-06-10 20:06:30 0 d-------- C:\Program Files\DivX
2008-06-10 20:06:30 0 d-------- C:\Program Files\DartyBox
2008-06-10 12:25:41 0 d-------- C:\Documents and Settings\Raphael Perez\Application Data\APLI Master
2008-06-08 01:13:45 0 d-------- C:\Program Files\Apple Software Update
2008-06-06 16:12:09 0 d-------- C:\Program Files\iTunes
2008-06-06 16:11:53 0 d-------- C:\Program Files\iPod
2008-06-06 16:09:55 0 d-------- C:\Program Files\QuickTime
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0B497AE8-3F6C-440C-AB87-52ED0182464A}]
C:\Program Files\Internet Explorer\IEXPLORE32.Dat
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1FD4696C-E95A-44E2-A03A-FDBDF4CCC305}]
C:\Program Files\Internet Explorer\IEXPLORE32.win
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74381DEC-D78B-43E4-BA5D-5244F669EBE4}]
C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E6C0D0E3-9E9A-489D-AE19-BBCFC7047A59}]
C:\Program Files\Internet Explorer\IEXPLORE32.Sys
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [07/11/2003 10:21]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [05/08/2005 03:57]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [05/08/2005 03:56]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [05/08/2005 03:56]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [19/10/2005 23:07]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [20/02/2004 15:12]
"RTHDCPL"="RTHDCPL.EXE" [29/06/2005 06:25 C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 11:43 C:\WINDOWS\ALCMTR.EXE]
"Agematis FAM"="C:\Program Files\steek\steekUP\FAM\fileAccessManager.exe" [14/02/2007 19:51]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [28/03/2008 23:37]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/03/2008 10:36]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [16/12/2006 12:43]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [25/10/2006 09:03]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [29/01/2007 21:12]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [29/01/2007 21:10]
"PPort11reminder"="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" [01/02/2007 13:46]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [05/03/2007 12:00]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [07/11/2006 19:03]
"@"="" []
"RoxWatchTray"="C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [16/08/2007 08:56]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [07/01/2006 02:36]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [19/07/2008 16:38]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" []
"ISUSPM"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [11/09/2006 05:40]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"AskSBar Uninstall"=rundll32 C:\PROGRA~1\UNINST~1.DLL,O -3
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}"= C:\WINDOWS\system32\wklsdd.dll [ ]
"{C0595A7E-2E2F-4B34-A83A-019270A0A464}"= C:\WINDOWS\system32\tdffdl.dll [ ]
"{8C41B7F7-3168-400D-A702-0E7EFE0BA304}"= C:\WINDOWS\system32\sgdewg.dll [ ]
"{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}"= C:\WINDOWS\system32\hhrdxd.dll [ ]
"{45AADFAA-DD36-42AB-83AD-0521BBF58C24}"= C:\WINDOWS\system32\zycdex.dll [ ]
"{461D2AB4-29A5-45C2-9134-D52272D3DE38}"= C:\WINDOWS\system32\rfdswc.dll [ ]
"{A9895933-6636-4281-BC58-EE6DE2AF96E3}"= C:\WINDOWS\system32\ddserh.dll [ ]
"{841529CB-7F77-4B99-A895-B5441E0D302F}"= C:\WINDOWS\system32\jfrwdh.dll [ ]
"{B29583D8-033A-4B9F-8553-7C5458F3FB8E}"= C:\WINDOWS\system32\jdsaex.dll [ ]
"{7914E0AA-ECCB-4311-B584-C49538227824}"= C:\WINDOWS\system32\jhfrxz.dll [ ]
"{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}"= C:\WINDOWS\system32\fmcvxy.dll [ ]
"{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}"= C:\WINDOWS\system32\fsrgeb.dll [ ]
"{5E907A48-400E-4EA8-9792-FFAE052D59E9}"= C:\WINDOWS\system32\pedadt.dll [ ]
"{CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068}"= C:\WINDOWS\system32\jggtsr.dll [ ]
"{84143967-B645-4BFF-B873-DA1DC886E9A7}"= C:\WINDOWS\system32\cedafb.dll [ ]
"{F99DEFDD-200B-4410-B572-E90883D527D2}"= C:\WINDOWS\system32\wrqszl.dll [ ]
"{6E6CA8A1-81BC-4707-A54C-F4903DD70BAD}"= C:\WINDOWS\system32\zgxfdx.dll [ ]
"{EB71E0B3-E97D-4D30-8733-E28266467617}"= C:\WINDOWS\system32\wyhesm.dll [ ]
"{28EB3777-3E23-4E72-8449-A992D09D24C3}"= C:\WINDOWS\system32\zefdst.dll [ ]
"{259BF3CF-194D-4FE6-9ADB-DE6544B098B6}"= C:\WINDOWS\system32\dndsaf.dll [ ]
"{74381DEC-D78B-43E4-BA5D-5244F669EBE4}"= C:\Program Files\Internet Explorer\PLUGINS\UnixSys08.Sys [ ]
"{E6C0D0E3-9E9A-489D-AE19-BBCFC7047A59}"= C:\Program Files\Internet Explorer\IEXPLORE32.Sys [ ]
"{0B497AE8-3F6C-440C-AB87-52ED0182464A}"= C:\Program Files\Internet Explorer\IEXPLORE32.Dat [ ]
"{1FD4696C-E95A-44E2-A03A-FDBDF4CCC305}"= C:\Program Files\Internet Explorer\IEXPLORE32.win [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 15/11/2007 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 20/05/2005 18:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreativeTaskScheduler]
"C:\Program Files\Creative\Shared Files\CTSched.exe" /logon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy PDF Creator]
C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPWT myPrintMileage Agent]
C:\Program Files\Hewlett-Packard\HP Business Inkjet 1000\Toolbox\mpm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\L'Assistant DartyBox]
C:\Program Files\Assistant Dartybox\Upgrade_Manager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
ICO.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfw]
C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMDeviceManager]
"C:\Program Files\Fichiers communs\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe" -RunServer
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
"C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\V0400Mon.exe]
C:\WINDOWS\V0400Mon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 3]
"C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FSMA"=2 (0x2)
"F-Secure Gatekeeper Handler Starter"=2 (0x2)
"FSAUA"=3 (0x3)
"FSDFWD"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1942b54c-af2f-11db-807a-00166f8c528f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NoLimit.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60cffbfb-4a32-11db-bf81-00166f8c528f}]
AutoRun\command- G:\WD_Windows_Tools\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{75a4bec8-d65e-11db-80cd-00166f8c528f}]
AutoRun\command- G:\AutoRun\AutoRun.exe
-- End of Deckard's System Scanner: finished at 2008-08-05 11:49:11 ------------